π¨ CVE-2026-47304
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
π¨ CVE-2026-50524
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
π@cveNotify
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-50525
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
π@cveNotify
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-50526
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
π@cveNotify
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to perform tampering locally.
π@cveNotify
π¨ CVE-2026-50527
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
π@cveNotify
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-50528
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
π@cveNotify
π¨ CVE-2026-50648
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
π@cveNotify
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-50651
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
π@cveNotify
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.
π@cveNotify
π¨ CVE-2026-50659
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
π@cveNotify
Improper encoding or escaping of output in .NET allows an authorized attacker to perform spoofing over a network.
π@cveNotify
π¨ CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
π@cveNotify
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
π@cveNotify
Checkpoint
sk185169 - CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token
Applies to: Multi-Domain Security Management, Security Management
π¨ CVE-2025-44089
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
π@cveNotify
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
π@cveNotify
GitHub
Public-references/CVE-2025-44089.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2025-44090
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
π@cveNotify
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
π@cveNotify
GitHub
Public-references/CVE-2025-44090.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2025-50324
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
π@cveNotify
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
π@cveNotify
GitHub
Public-references/CVE-2025-50324.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2025-50327
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
π@cveNotify
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
π@cveNotify
GitHub
Public-references/CVE-2025-50327.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2025-50329
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
π@cveNotify
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
π@cveNotify
GitHub
Public-references/CVE-2025-50329.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2025-50330
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
π@cveNotify
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
π@cveNotify
GitHub
Public-references/CVE-2025-50330.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2025-60835
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
π@cveNotify
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
π@cveNotify
GitHub
Public-references/CVE-2025-60835.md at main Β· OV-0-VO/Public-references
References required for CVE publication. Contribute to OV-0-VO/Public-references development by creating an account on GitHub.
π¨ CVE-2026-13089
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify.
When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own header and then calls decode_jwt(token, key, 1, [$self->alg]), handing JSON::WebToken an accepted-algorithm allowlist taken from the untrusted token. A token with alg=none yields ['none'], so decode_jwt returns the claims with no signature check, and a token with alg=HS256 is verified with the RP's RSA public key as the HMAC secret (RS to HS confusion).
The ID Token is the OpenID Connect authentication assertion delivered to the Relying Party. Any caller that verifies an ID Token through the unpinned load(token)->verify path, or load(token, key) with only the key pinned, accepts a forged token carrying attacker-chosen claims such as sub and is authenticated as any user. Passing an explicit algorithm so $self->alg is already set bypasses the header-derived allowlist and is not affected.
Note that the latest version uploaded to CPAN is 0.10. Later versions are available in the git repository.
π@cveNotify
OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify.
When the caller does not pin an algorithm, OIDC::Lite::Model::IDToken::verify sets $self->alg($self->header->{alg}) from the token's own header and then calls decode_jwt(token, key, 1, [$self->alg]), handing JSON::WebToken an accepted-algorithm allowlist taken from the untrusted token. A token with alg=none yields ['none'], so decode_jwt returns the claims with no signature check, and a token with alg=HS256 is verified with the RP's RSA public key as the HMAC secret (RS to HS confusion).
The ID Token is the OpenID Connect authentication assertion delivered to the Relying Party. Any caller that verifies an ID Token through the unpinned load(token)->verify path, or load(token, key) with only the key pinned, accepts a forged token carrying attacker-chosen claims such as sub and is authenticated as any user. Passing an explicit algorithm so $self->alg is already set bypasses the header-derived allowlist and is not affected.
Note that the latest version uploaded to CPAN is 0.10. Later versions are available in the git repository.
π@cveNotify
IETF Datatracker
RFC 8725: JSON Web Token Best Current Practices
JSON Web Tokens, also known as JWTs, are URL-safe JSON-based security tokens that contain a set of claims that can be signed and/or encrypted. JWTs are being widely used and deployed as a simple security token format in numerous protocols and applicationsβ¦
π¨ CVE-2026-63265
Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.
π@cveNotify
Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.
π@cveNotify
Regularlabs
Regular Labs - Extensions for Joomla! - Regular Labs
Regular Labs offers you the best and highest rated Joomla extensions: Advanced Module Manager, Modals, Articles Anywhere, Modules Anywhere, Sourcerer en ReReplacer and many more.
π¨ CVE-2026-63280
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
π@cveNotify
Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
π@cveNotify
Regularlabs
Regular Labs - Extensions for Joomla! - Regular Labs
Regular Labs offers you the best and highest rated Joomla extensions: Advanced Module Manager, Modals, Articles Anywhere, Modules Anywhere, Sourcerer en ReReplacer and many more.
π¨ CVE-2026-63281
Stored condition values could also execute HTML/JavaScript in administrator summaries.
π@cveNotify
Stored condition values could also execute HTML/JavaScript in administrator summaries.
π@cveNotify
Regularlabs
Regular Labs - Extensions for Joomla! - Regular Labs
Regular Labs offers you the best and highest rated Joomla extensions: Advanced Module Manager, Modals, Articles Anywhere, Modules Anywhere, Sourcerer en ReReplacer and many more.