π¨ CVE-2026-10722
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
π@cveNotify
A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipulation of the argument offset leads to integer overflow. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The name of the patch is 533dfc82fd228bfadf42ea7180c39de7d9af47fa. A patch should be applied to remediate this issue.
π@cveNotify
Gist
Systemic BTF String-Table Offset Validation Flaw in cilium/ebpf Causes Parser Panic and Denial of Service
Systemic BTF String-Table Offset Validation Flaw in cilium/ebpf Causes Parser Panic and Denial of Service - EVIDENCE.md
π¨ CVE-2026-35075
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
π@cveNotify
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35076
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35077
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35078
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35079
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35080
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35081
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
π@cveNotify
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35082
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
π@cveNotify
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35083
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
π@cveNotify
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35084
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
π@cveNotify
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2022-49036
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
Synology
Release Notes for Synology Active Backup for Business Recovery Media Creator | Synology Inc.
π¨ CVE-2022-49042
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
Synology
Release Notes for Synology Hyper Backup Explorer | Synology Inc.
π¨ CVE-2023-52951
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
π@cveNotify
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
π@cveNotify
Synology
Release Notes for Synology Note Station Client | Synology Inc.
π¨ CVE-2024-47263
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
π@cveNotify
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
π@cveNotify
Synology
Release Notes for Hyper Backup | Synology Inc.
π¨ CVE-2024-47273
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
π@cveNotify
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
π@cveNotify
Synology
Release Notes for Hyper Backup | Synology Inc.
π¨ CVE-2025-60477
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
π@cveNotify
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
π@cveNotify
GitHub
more ac4 and fuzzing fixes: Β· gpac/gpac@13eb5b7
- fixes #3301, fixes #3302, #3303
- autofuzz ref bsYSHNFQpzEF8w
- autofuzz ref bsYSHNFQpzEF8w
π¨ CVE-2025-70100
A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.
π@cveNotify
A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.
π@cveNotify
GitHub
[security] lwext4/src/ext4_blockdev.c FPE in ext4_block_set_lb_size Β· Issue #90 Β· gkostka/lwext4
lwext4/src/ext4_blockdev.c FPE in ext4_block_set_lb_size Description: When processing a crafted ext4-image, "ext4_mount()" may pass an invalid logical block size (lb_size == 0) into "...
π¨ CVE-2025-70101
An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.
π@cveNotify
An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.
π@cveNotify
GitHub
[security] lwext4/include/ext4_dir.h Out-of-Bounds Read in ext4_ext_binsearch_idx Β· Issue #91 Β· gkostka/lwext4
lwext4/include/ext4_dir.h Out-of-Bounds Read in ext4_ext_binsearch_idx Description: Probably, when traversing an inodeβs extent tree, the function "ext4_ext_binsearch_idx()" assumes that ...
π¨ CVE-2026-10729
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
π@cveNotify
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
π@cveNotify
GitHub
HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens
# Summary
An HTML injection vulnerability was identified in the "Slow Redirect" and "Cloned Website" Canarytokens, whereby the an attacker can introduce unescaped HTML into the...
An HTML injection vulnerability was identified in the "Slow Redirect" and "Cloned Website" Canarytokens, whereby the an attacker can introduce unescaped HTML into the...
π¨ CVE-2026-37460
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
π@cveNotify
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
π@cveNotify
GitHub
GitHub - FRRouting/frr: The FRRouting Protocol Suite
The FRRouting Protocol Suite. Contribute to FRRouting/frr development by creating an account on GitHub.