๐จ CVE-2026-10649
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
๐@cveNotify
A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of service (DoS) in the CIB remote listener. This can result in the affected service crashing.
๐@cveNotify
๐จ CVE-2026-50522
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-56170
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-57108
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-47300
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-47302
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-47303
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
๐@cveNotify
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
๐@cveNotify
๐จ CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
๐@cveNotify
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
๐@cveNotify
๐จ CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
๐@cveNotify
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
๐@cveNotify
๐จ CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
๐@cveNotify
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
๐@cveNotify
๐จ CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
๐@cveNotify
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
๐@cveNotify
๐จ CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
๐@cveNotify
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
๐@cveNotify
Checkpoint
sk185169 - CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token
Applies to: Multi-Domain Security Management, Security Management
๐จ CVE-2025-44089
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
๐@cveNotify
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
๐@cveNotify
GitHub
Public-references/CVE-2025-44089.md at main ยท OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
๐จ CVE-2025-44090
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
๐@cveNotify
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
๐@cveNotify
GitHub
Public-references/CVE-2025-44090.md at main ยท OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
๐จ CVE-2025-50324
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
๐@cveNotify
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
๐@cveNotify
GitHub
Public-references/CVE-2025-50324.md at main ยท OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
๐จ CVE-2025-50327
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
๐@cveNotify
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
๐@cveNotify
GitHub
Public-references/CVE-2025-50327.md at main ยท OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.