๐จ CVE-2026-50425
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Internal System User Profile allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50426
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
๐@cveNotify
Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.
๐@cveNotify
๐จ CVE-2025-5318
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
๐@cveNotify
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authenticated remote attacker to potentially read unintended memory regions, exposing sensitive information or affect service behavior.
๐@cveNotify
๐จ CVE-2026-50460
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
๐@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an unauthorized attacker to elevate privileges over a network.
๐@cveNotify
โค1
๐จ CVE-2026-50461
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-50462
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
๐@cveNotify
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50465
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
๐@cveNotify
Improper access control in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.
๐@cveNotify
๐จ CVE-2026-50466
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Brokering File System allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50469
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Improper link resolution before file access ('link following') in Windows Projected File System allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-50470
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
Out-of-bounds read in Windows Network Policy Server SNMP allows an unauthorized attacker to disclose information over a network.
๐@cveNotify
๐จ CVE-2026-50471
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-50473
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
๐@cveNotify
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-50474
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-50476
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Microsoft Windows allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-15457
The Kirki โ Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.
๐@cveNotify
The Kirki โ Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability.
๐@cveNotify
๐จ CVE-2026-16014
A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
๐@cveNotify
A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
๐@cveNotify
๐จ CVE-2026-63094
SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
๐@cveNotify
SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
๐@cveNotify
GitHub
Open Redirect via Unvalidated OAuth State URL Leads to Token Exfiltration ยท Issue #11746 ยท SigNoz/signoz
(emails sent to security@signoz.io on 23 May and 6 June with no response) There's a potential vulnerability in the SSO authentication flow that allows an unauthenticated attacker to steal sessi...
๐จ CVE-2026-63100
Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsController, where the before_action ensure_admin filter is applied only to the clear_cache action. Attackers can read the operator's Synth API key rendered in plaintext via a form field value attribute, overwrite it with an attacker-controlled value, toggle public registration settings, and disable email confirmation requirements to disrupt the entire instance.
๐@cveNotify
Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsController, where the before_action ensure_admin filter is applied only to the clear_cache action. Attackers can read the operator's Synth API key rendered in plaintext via a form field value attribute, overwrite it with an attacker-controlled value, toggle public registration settings, and disable email confirmation requirements to disrupt the entire instance.
๐@cveNotify
GitHub
oss/maybe.md at main ยท geo-chen/oss
securing oss responsibly. Contribute to geo-chen/oss development by creating an account on GitHub.
๐จ CVE-2026-16093
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
๐@cveNotify
Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a fake, unsigned assertion header that tricks the system into thinking the policy requirements have been met. This allows the attacker to authenticate using simpler methods like a client secret even when the administrator has mandated more secure, signed assertions.
๐@cveNotify
๐จ CVE-2026-49208
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied relative strings such as now, tomorrow, or +10 years to move a writable, format-less date prop past time-based business logic checks. This issue is fixed in versions 2.36.0 and 3.1.0.
๐@cveNotify
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied relative strings such as now, tomorrow, or +10 years to move a writable, format-less date prop past time-based business logic checks. This issue is fixed in versions 2.36.0 and 3.1.0.
๐@cveNotify
GitHub
[LiveComponent] Parse format-less date LiveProps strictly with RFC 3339 ยท symfony/ux@d24d78f
`LiveComponentHydrator::hydrateObjectValue()` fell back to
`new $className($value)` for `DateTimeInterface`-typed `LiveProp`s
without an explicit `format`. The `DateTime` constructor accepts
relati...
`new $className($value)` for `DateTimeInterface`-typed `LiveProp`s
without an explicit `format`. The `DateTime` constructor accepts
relati...
๐จ CVE-2026-49216
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (<div>${item[labelField]}</div>) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed in versions 2.36.0 and 3.1.0.
๐@cveNotify
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals (<div>${item[labelField]}</div>) rather than text, allowing attacker-controlled markup from user-supplied dropdown values to execute in the browser of any user who opens an autocomplete widget backed by the same data. This issue is fixed in versions 2.36.0 and 3.1.0.
๐@cveNotify
GitHub
[Autocomplete] Fix XSS via unescaped AJAX response data ยท symfony/ux@842ae54
## Summary
Fix stored XSS in `symfony/ux-autocomplete`: the Stimulus controller previously rendered the `text` field of AJAX responses directly inside HTML template literals
(`<div>$...
Fix stored XSS in `symfony/ux-autocomplete`: the Stimulus controller previously rendered the `text` field of AJAX responses directly inside HTML template literals
(`<div>$...