π¨ CVE-2026-35077
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35078
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35079
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35080
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35081
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
π@cveNotify
The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35082
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
π@cveNotify
The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35083
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
π@cveNotify
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2026-35084
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
π@cveNotify
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
π@cveNotify
Certvde
MBS: Several security vulnerabilities in the UGW web GUI
π¨ CVE-2022-49036
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
Synology
Release Notes for Synology Active Backup for Business Recovery Media Creator | Synology Inc.
π¨ CVE-2022-49042
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
π@cveNotify
Synology
Release Notes for Synology Hyper Backup Explorer | Synology Inc.
π¨ CVE-2023-52951
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
π@cveNotify
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
π@cveNotify
Synology
Release Notes for Synology Note Station Client | Synology Inc.
π¨ CVE-2024-47263
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
π@cveNotify
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users with administrator privileges to write specific files containing non-sensitive information via unspecified vectors.
π@cveNotify
Synology
Release Notes for Hyper Backup | Synology Inc.
π¨ CVE-2024-47273
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
π@cveNotify
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated users to write specific files via unspecified vectors.
π@cveNotify
Synology
Release Notes for Hyper Backup | Synology Inc.
π¨ CVE-2025-60477
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
π@cveNotify
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.
π@cveNotify
GitHub
more ac4 and fuzzing fixes: Β· gpac/gpac@13eb5b7
- fixes #3301, fixes #3302, #3303
- autofuzz ref bsYSHNFQpzEF8w
- autofuzz ref bsYSHNFQpzEF8w
π¨ CVE-2025-70100
A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.
π@cveNotify
A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that results in a zero logical block size. The vulnerability is triggered during mount or image processing and leads to a Floating-Point Exception (FPE) under sanitizers or a runtime crash in standard builds due to missing validation of lb_size.
π@cveNotify
GitHub
[security] lwext4/src/ext4_blockdev.c FPE in ext4_block_set_lb_size Β· Issue #90 Β· gkostka/lwext4
lwext4/src/ext4_blockdev.c FPE in ext4_block_set_lb_size Description: When processing a crafted ext4-image, "ext4_mount()" may pass an invalid logical block size (lb_size == 0) into "...
π¨ CVE-2025-70101
An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.
π@cveNotify
An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vulnerability occurs due to insufficient validation of extent header fields before performing a binary search over extent index entries, which can result in invalid pointer calculations and an out-of-bounds memory read during extent tree traversal.
π@cveNotify
GitHub
[security] lwext4/include/ext4_dir.h Out-of-Bounds Read in ext4_ext_binsearch_idx Β· Issue #91 Β· gkostka/lwext4
lwext4/include/ext4_dir.h Out-of-Bounds Read in ext4_ext_binsearch_idx Description: Probably, when traversing an inodeβs extent tree, the function "ext4_ext_binsearch_idx()" assumes that ...
π¨ CVE-2026-10729
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
π@cveNotify
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTML emails.
This issue affects Canarytokens: from Docker tag sha-c42435e before sha-bfda4df, from Git commit c42435e before bfda4df.
π@cveNotify
GitHub
HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens
# Summary
An HTML injection vulnerability was identified in the "Slow Redirect" and "Cloned Website" Canarytokens, whereby the an attacker can introduce unescaped HTML into the...
An HTML injection vulnerability was identified in the "Slow Redirect" and "Cloned Website" Canarytokens, whereby the an attacker can introduce unescaped HTML into the...
π¨ CVE-2026-37460
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
π@cveNotify
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
π@cveNotify
GitHub
GitHub - FRRouting/frr: The FRRouting Protocol Suite
The FRRouting Protocol Suite. Contribute to FRRouting/frr development by creating an account on GitHub.
π¨ CVE-2026-44545
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
π@cveNotify
daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote attacker could send arbitrarily large WebSocket messages or frames, causing excessive memory consumption and a denial of service.
π@cveNotify
GitHub
daphne/CHANGELOG.txt at main Β· django/daphne
Django Channels HTTP/WebSocket server. Contribute to django/daphne development by creating an account on GitHub.
π¨ CVE-2026-44546
daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 as header line separators, but autobahn decodes header values to str and calls splitlines(). An attacker can exploit this parser differential to inject additional headers into the ASGI scope passed to the application. daphne now rejects requests with these bytes in any header value with a 400 response.
π@cveNotify
daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or \x85 as header line separators, but autobahn decodes header values to str and calls splitlines(). An attacker can exploit this parser differential to inject additional headers into the ASGI scope passed to the application. daphne now rejects requests with these bytes in any header value with a 400 response.
π@cveNotify
GitHub
daphne/CHANGELOG.txt at main Β· django/daphne
Django Channels HTTP/WebSocket server. Contribute to django/daphne development by creating an account on GitHub.
π¨ CVE-2026-47324
ProjectsAndPrograms school-management-system is vulnerable to Stored CrossβSite Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other usersβ browsers.
Critically, when chained with CVEβ2025β11661, which allows unauthenticated access to backend endpoints, this vulnerability can be exploited by a remote attacker without privileges to inject and execute arbitrary JavaScript.
The maintainers were notified early about this vulnerability but did not provide details regarding affected versions. The version corresponding to commit 6b6fae5 was tested and confirmed vulnerable; other versions were not tested and may also be affected.
π@cveNotify
ProjectsAndPrograms school-management-system is vulnerable to Stored CrossβSite Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or administrator) can inject malicious JavaScript that is subsequently executed in other usersβ browsers.
Critically, when chained with CVEβ2025β11661, which allows unauthenticated access to backend endpoints, this vulnerability can be exploited by a remote attacker without privileges to inject and execute arbitrary JavaScript.
The maintainers were notified early about this vulnerability but did not provide details regarding affected versions. The version corresponding to commit 6b6fae5 was tested and confirmed vulnerable; other versions were not tested and may also be affected.
π@cveNotify
cert.pl
Vulnerabilities in school-management-system software
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-47324 and CVE-2026-47325) found in school-management-system software.