π¨ CVE-2026-47308
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation.
This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.
π@cveNotify
NULL pointer dereference vulnerability in Samsung Open Source Walrus allows Pointer Manipulation.
This issue affects Walrus: f339b8ee4ea701772e8ae640b3d1b12ac02b1ae9.
π@cveNotify
GitHub
Improve error throwing by zherczeg Β· Pull Request #409 Β· Samsung/walrus
WebAssembly Lightweight RUntime. Contribute to Samsung/walrus development by creating an account on GitHub.
π¨ CVE-2025-15609
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.
π@cveNotify
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.
π@cveNotify
WPScan
Fortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure
See details on Fortis For WooCommerce < 1.3.1 - Sensitive API Key Disclosure CVE 2025-15609. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-47309
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Oversized Serialized Data Payloads.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47310
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47311
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47313
Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47314
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47315
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47316
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-47317
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation.
This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.
π@cveNotify
GitHub
Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
Escargot is a lightweight JavaScript engine designed specifically for resource-constrained environments. - Fix crash issues by ksh8281 Β· Pull Request #1565 Β· Samsung/escargot
π¨ CVE-2026-4885
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.
π@cveNotify
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The exploit can only be exploited if a file field is added to the form.
π@cveNotify
Piotnet Addons For Elementor - PAFE
Powerful Elementor Addons - Piotnet Addons For Elementor (PAFE)
More advanced features for your Elementor. Build WordPress websites easily. 100+ Elementor Addons + Widgets + Form Builder
π¨ CVE-2026-44408
There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface.
π@cveNotify
There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can modify configuration through the interface.
π@cveNotify
π¨ CVE-2025-51427
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
π@cveNotify
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
π@cveNotify
GitHub
vulnerability-disclosure/CVE-2025-51427/CVE_2025_51427.md at main Β· JIRUWOZHI/vulnerability-disclosure
Security disclosures and PoCs for vulnerabilities in AI/ML systems. - JIRUWOZHI/vulnerability-disclosure
π¨ CVE-2025-70950
An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
π@cveNotify
An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
π@cveNotify
Gist
gohttp Path Traversal Arbitrary File Read via Request URI
gohttp Path Traversal Arbitrary File Read via Request URI - gist:202127ae5f4dcc4b39909ce7ac1c8466
π¨ CVE-2026-2586
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
π@cveNotify
An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands with the privileges of the application service user. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
π@cveNotify
GitLab
Remote Code Execution via EL Injection [CVE Reservation for issue 327] (#87) Β· Issues Β· Eclipse Projects Security / cve-assignmentβ¦
The Eclipse Foundation is a Common Vulnerabilities and Exposures (CVE) Numbering Authority. This issue it used to request and track the progress...
π¨ CVE-2026-2587
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) βexpressionsβ are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
π@cveNotify
A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and evaluates user-supplied values within a context where Expression Language (EL) βexpressionsβ are processed without proper sanitization or escaping. By injecting expressions such as #{7*7}, the server returns 49, confirming server-side EL evaluation. This issue allows a remote attacker to fully compromise the underlying host, enabling capabilities as reading/modifying data, executing arbitrary commands, persistence, and lateral movement. This issue affects Eclipse GlassFish: from 8.0.0 to 8.0.1, fixed in 8.0.2; 7.1.0, fixed in 7.1.1; from 7.0.0 to 7.0.25, fixed in 7.0.26. Impact on versions from 5.1.0 to 6.2.5 is unknown.
π@cveNotify
GitLab
Remote Code Execution via EL Injection + CSRF [CVE Reservation for Issue 329] (#86) Β· Issues Β· Eclipse Projects Security / cveβ¦
The Eclipse Foundation is a Common Vulnerabilities and Exposures (CVE) Numbering Authority. This issue it used to request and track the progress...
π¨ CVE-2026-34883
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with elevated privileges. Because the installer does not properly validate symbolic links or reparse points at the destination path, an attacker can create a malicious link that redirects the write operation to an arbitrary system location, enabling arbitrary file creation or overwrite with elevated privileges.
π@cveNotify
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate privileges to Administrator. During installation, the software writes the file CCFLFamily_07Feb11.edr to C:\ProgramData\Portrait Displays\CW\data\i1D3\ while running with elevated privileges. Because the installer does not properly validate symbolic links or reparse points at the destination path, an attacker can create a malicious link that redirects the write operation to an arbitrary system location, enabling arbitrary file creation or overwrite with elevated privileges.
π@cveNotify
Portrait Displays
Dell Color Management
Dell Color Management is a free app that allows users to swiftly validate or calibrate their supported Dell UltraSharp monitor connected to a Windows and/or macOS machine.
π¨ CVE-2026-43634
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.
π@cveNotify
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address in the CF-Connecting-IP HTTP header without verifying the request originated from Cloudflare's network. Attackers can exploit this to circumvent fail2ban brute-force protection, bypass per-user IP allowlists, and poison authentication audit logs by spoofing trusted IP addresses on each request.
π@cveNotify
GitHub
Stop trusting unauthenticated proxy headers (#5273) Β· hestiacp/hestiacp@f381e29
* Stop trusting unauthenticated proxy headers
* pin version
cus the other libs do the same
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-aut...
* pin version
cus the other libs do the same
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
---------
Co-aut...
π¨ CVE-2026-44159
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021.
π@cveNotify
Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 2020, and has not been supported since 2021.
π@cveNotify
π¨ CVE-2026-45557
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.
π@cveNotify
Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.
π@cveNotify
π¨ CVE-2026-47100
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.
π@cveNotify
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.
π@cveNotify