π¨ CVE-2026-48032
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.
π@cveNotify
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.
π@cveNotify
GitHub
security: fix 4 HIGH + 15 MEDIUM Codex findings (8 root-cause clusters) β DCO-signed replacement for #177 by kerberosmansour Β·β¦
Replacement for #177 β identical changes, but every commit now carries a Signed-off-by (the cherry-picked worktree commits were missing DCO sign-off in #177). Opened as a fresh PR rather than force...
π¨ CVE-2026-48033
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
π@cveNotify
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy packs can be bypassed by a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0.
π@cveNotify
GitHub
security: fix 4 HIGH + 15 MEDIUM Codex findings (8 root-cause clusters) β DCO-signed replacement for #177 by kerberosmansour Β·β¦
Replacement for #177 β identical changes, but every commit now carries a Signed-off-by (the cherry-picked worktree commits were missing DCO sign-off in #177). Opened as a fresh PR rather than force...
π¨ CVE-2026-48034
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.
π@cveNotify
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.
π@cveNotify
GitHub
fix(policies): bind H5 hardening checks to exempted bucket (replaces #174) by kerberosmansour Β· Pull Request #175 Β· kerberosmansour/hulumi
Replacement for #174 β same H5 policy fix, but with the DCO sign-off and Prettier formatting that #174 was missing. Opened as a fresh PR rather than force-pushing the bot branch's history (...
π¨ CVE-2026-48035
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal β while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
π@cveNotify
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal β while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
π@cveNotify
GitHub
security: fix 4 HIGH + 15 MEDIUM Codex findings (8 root-cause clusters) β DCO-signed replacement for #177 by kerberosmansour Β·β¦
Replacement for #177 β identical changes, but every commit now carries a Signed-off-by (the cherry-picked worktree commits were missing DCO sign-off in #177). Opened as a fresh PR rather than force...
π¨ CVE-2026-48036
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" β masking real attacks for up to six hours β or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
π@cveNotify
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers running drift detection in CI / cron could see transient adapter failures silently cached as "all clear" β masking real attacks for up to six hours β or see ordinary provider-version churn falsely promoted to incident severity. Either way, the verdict source was unreliable for downstream incident workflows that gate on it. This issue has been patched in version 1.4.0.
π@cveNotify
GitHub
security: fix 4 HIGH + 15 MEDIUM Codex findings (8 root-cause clusters) β DCO-signed replacement for #177 by kerberosmansour Β·β¦
Replacement for #177 β identical changes, but every commit now carries a Signed-off-by (the cherry-picked worktree commits were missing DCO sign-off in #177). Opened as a fresh PR rather than force...
π¨ CVE-2026-48037
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
π@cveNotify
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
π@cveNotify
GitHub
security: fix 4 HIGH + 15 MEDIUM Codex findings (8 root-cause clusters) β DCO-signed replacement for #177 by kerberosmansour Β·β¦
Replacement for #177 β identical changes, but every commit now carries a Signed-off-by (the cherry-picked worktree commits were missing DCO sign-off in #177). Opened as a fresh PR rather than force...
π¨ CVE-2026-54342
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh. This issue has been patched in version 2026-05-20.
π@cveNotify
In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA backend, the disabled TLS verification is the transport-level enabler for the VAU MITM described in GHSA-vvh7-x6c7-46gh. This issue has been patched in version 2026-05-20.
π@cveNotify
GitHub
Release 2026-05-20 Β· med-united/epa4all
Full Changelog: 2026-05-18...2026-05-20
π¨ CVE-2026-4267
The Query Monitor β The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β$_SERVER['REQUEST_URI']β parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
π@cveNotify
The Query Monitor β The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the β$_SERVER['REQUEST_URI']β parameter in all versions up to, and including, 3.20.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
π@cveNotify
π¨ CVE-2026-5198
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
π@cveNotify
π¨ CVE-2026-34532
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the validator store fails to mirror this traversal, causing all access control enforcement to be skipped. This allows unauthenticated callers to invoke Cloud Functions that are meant to be protected by validators such as requireUser, requireMaster, or custom validation logic. This issue has been patched in versions 8.6.67 and 9.7.0-alpha.11.
π@cveNotify
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.67 and 9.7.0-alpha.11, an attacker can bypass Cloud Function validator access controls by appending "prototype.constructor" to the function name in the URL. When a Cloud Function handler is declared using the function keyword and its validator is a plain object or arrow function, the trigger store traversal resolves the handler through its own prototype chain while the validator store fails to mirror this traversal, causing all access control enforcement to be skipped. This allows unauthenticated callers to invoke Cloud Functions that are meant to be protected by validators such as requireUser, requireMaster, or custom validation logic. This issue has been patched in versions 8.6.67 and 9.7.0-alpha.11.
π@cveNotify
GitHub
fix: Cloud function validator bypass via prototype chain traversal ([β¦ Β· parse-community/parse-server@4fc48cf
β¦GHSA-vpj2-qq7w-5qq6](https://github.com/parse-community/parse-server/security/advisories/GHSA-vpj2-qq7w-5qq6)) (#10343)
π¨ CVE-2026-4799
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
π@cveNotify
In Search Guard FLX up to version 4.0.1, it is possible to use specially crafted requests to redirect the user to an untrusted URL.
π@cveNotify
Search-Guard
Security for Elasticsearch | Search Guard FLX 4.1.0 | Search Guard
Changelog for Search Guard FLX 4.1.0
π¨ CVE-2026-22561
Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer.
π@cveNotify
Uncontrolled search path elements in Anthropic Claude for Windows installer (Claude Setup.exe) versions prior to 1.1.3363 allow local privilege escalation via DLL search-order hijacking. The installer loads DLLs (e.g., profapi.dll) from its own directory after UAC elevation, enabling arbitrary code execution if a malicious DLL is planted alongside the installer.
π@cveNotify
Anthropic
Anthropic Trust Center
Anthropic is an AI safety and research company with a mission of ensuring the world safely makes the transition through transformative AI. We believe deeply in transparency and the need for secure practices in this rapidly evolving industry.
π¨ CVE-2026-22569
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
π@cveNotify
An incorrect startup configuration of affected versions of Zscaler Client Connector on Windows may cause a limited amount of traffic from being inspected under rare circumstances.
π@cveNotify
π¨ CVE-2026-30276
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
π@cveNotify
An arbitrary file overwrite vulnerability in DeftPDF Document Translator v54.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
π@cveNotify
Deftpdf
DeftPDF | Free PDF Software to Edit, Convert, Sign & More.
An all-in-one free online PDF editor that does not require subscriptions or installations! DeftPDF is a free online tool that makes editing and converting easy in just a few clicks!
π¨ CVE-2026-30281
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
π@cveNotify
An arbitrary file overwrite vulnerability in MaruNuri LLC v2.0.23 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
π@cveNotify
GitHub
neo.maru APP Arbitrary File Overwrite Vulnerability Β· Issue #21 Β· Secsys-FDU/AF_CVEs
VendorοΌMaruNuri LLC (https://maru.xyz/) Affected productοΌneo.maru (https://play.google.com/store/apps/details?id=neo.maru) VersionοΌV2.0.23 Google Play linkοΌhttps://play.google.com/store/apps/detail...
π¨ CVE-2026-30284
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
π@cveNotify
An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure.
π@cveNotify
App Craze
App Craze β Discover & Enjoy Smart, Stylish Mobile Apps
Download App Craze and explore a world of innovative, easy-to-use mobile and web apps designed to simplify your digital life. Simple to use. Fun to explore.
π¨ CVE-2026-34218
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined file-access rules were not applied until the user interacted with policies through the GUI, triggering a policy mutation over XPC. This issue has been patched in version 4.2.14.
π@cveNotify
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 4.2.14, two related startup defects created a window during which only the single compile-time baseline rule was enforced by opfilter. All managed (MDM-delivered) and user-defined file-access rules were not applied until the user interacted with policies through the GUI, triggering a policy mutation over XPC. This issue has been patched in version 4.2.14.
π@cveNotify
GitHub
Fix startup policy state mismatch β apply full merged rules after ES β¦ Β· craigjbass/clearancekit@56d617b
β¦client starts
applyPolicyToFilter(), applyAllowlistToFilter(), and applyJailRulesToFilter()
were called before adapter.start() created the ES client. Each guards on a
nil client and returned earl...
applyPolicyToFilter(), applyAllowlistToFilter(), and applyJailRulesToFilter()
were called before adapter.start() created the ES client. Each guards on a
nil client and returned earl...
π¨ CVE-2026-34219
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff value, the value is accepted and stored as an Instant near the representable upper bound. On a later heartbeat, the implementation performs unchecked Instant + Duration arithmetic (backoff_time + slack), which can overflow and panic with: overflow when adding duration to instant. This issue is reachable from any Gossipsub peer over normal TCP + Noise + mplex/yamux connectivity and requires no further authentication beyond becoming a protocol peer. This issue has been patched in version 0.49.4.
π@cveNotify
libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Rust libp2p Gossipsub implementation contains a remotely reachable panic in backoff expiry handling. After a peer sends a crafted PRUNE control message with an attacker-controlled, near-maximum backoff value, the value is accepted and stored as an Instant near the representable upper bound. On a later heartbeat, the implementation performs unchecked Instant + Duration arithmetic (backoff_time + slack), which can overflow and panic with: overflow when adding duration to instant. This issue is reachable from any Gossipsub peer over normal TCP + Noise + mplex/yamux connectivity and requires no further authentication beyond becoming a protocol peer. This issue has been patched in version 0.49.4.
π@cveNotify
GitHub
Gossipsub PRUNE Backoff Heartbeat Instant Overflow
## Description
### Summary
The Rust libp2p Gossipsub implementation contains a remotely reachable panic in `backoff` expiry handling.
After a peer sends a crafted `PRUNE` control message with ...
### Summary
The Rust libp2p Gossipsub implementation contains a remotely reachable panic in `backoff` expiry handling.
After a peer sends a crafted `PRUNE` control message with ...
π¨ CVE-2026-34220
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.
π@cveNotify
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.
π@cveNotify
GitHub
SQL injection via specially crafted object
## Summary
MikroORM versions <= 6.6.9 and <= 7.0.5 are vulnerable to SQL injection when specially crafted objects are interpreted as raw SQL query fragments.
## Impact
If user-contro...
MikroORM versions <= 6.6.9 and <= 7.0.5 are vulnerable to SQL injection when specially crafted objects are interpreted as raw SQL query fragments.
## Impact
If user-contro...
π¨ CVE-2026-34221
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM when merging object structures. The function did not prevent special keys such as __proto__, constructor, or prototype, allowing attacker-controlled input to modify the JavaScript object prototype when merged. This issue has been patched in versions 6.6.10 and 7.0.6.
π@cveNotify
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, a prototype pollution vulnerability exists in the Utils.merge helper used internally by MikroORM when merging object structures. The function did not prevent special keys such as __proto__, constructor, or prototype, allowing attacker-controlled input to modify the JavaScript object prototype when merged. This issue has been patched in versions 6.6.10 and 7.0.6.
π@cveNotify
GitHub
Prototype pollution in Utils.merge
A prototype pollution vulnerability exists in the `Utils.merge` helper used internally by MikroORM when merging object structures.
The function did not prevent special keys such as `__proto__`, ...
The function did not prevent special keys such as `__proto__`, ...
π¨ CVE-2026-34227
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser. This issue has been patched in version 1.7.4.
π@cveNotify
Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to version 1.7.4, a single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH keys, ntds.dit) or destroying the entire compromised infrastructure, entirely through the operator's own browser. This issue has been patched in version 1.7.4.
π@cveNotify
GitHub
One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
A single click on a malicious link gives an unauthenticated attacker immediate, silent control over every active C2 session or beacon, capable of exfiltrating all collected target data (e.g. SSH ke...