CVE Notify
19.7K subscribers
4 photos
265K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-16999
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linking.

This issue affects UYAP Document Editor: from 4.5.17 before 5.4.17.

πŸŽ–@cveNotify
🚨 CVE-2026-66375
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-66381
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-66382
An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-67286
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

πŸŽ–@cveNotify
🚨 CVE-2026-15803
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an incomplete fix for CVE-2018-1000644: the earlier fix did not cover all parser entry points. The issue is resolved in RDF4J 5.3.2, which rejects or disables DOCTYPE declarations, external entities, and external DTD loading by default.

πŸŽ–@cveNotify
🚨 CVE-2026-65926
An anonymous caller when anonymous access is enabled, or a low-privilege authenticated user, may learn private Release Bundle names and versions when the bundle name is known.

πŸŽ–@cveNotify
🚨 CVE-2026-66384
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-68758
A low-privileged authenticated user may access restricted support information under specific conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-68759
A holder of a valid integration credential may impersonate other users under specific conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-69107
An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-48550
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An unauthenticated remote attacker can craft a malicious link that, when followed by an authenticated user, executes arbitrary JavaScript in the victim's browser.

πŸŽ–@cveNotify
🚨 CVE-2026-73237
XSS vulnerability in Markdown handling in Apache Allura.

This issue affects Apache Allura: from 1.10.0 before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

πŸŽ–@cveNotify
🚨 CVE-2026-73238
XSS vulnerability in code display in Apache Allura.

This issue affects Apache Allura: before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

πŸŽ–@cveNotify
🚨 CVE-2026-73239
Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.

This issue affects Apache Allura: before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

πŸŽ–@cveNotify
🚨 CVE-2026-73240
Specifically crafted inputs may lead to git argument injection in Apache Allura.

This issue affects Apache Allura: before 1.19.1.

Users are recommended to upgrade to version 1.19.1, which fixes the issue.

πŸŽ–@cveNotify
🚨 CVE-2026-16627
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a CI job modal.

πŸŽ–@cveNotify
🚨 CVE-2026-18673
When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to all interfaces - forwards almost the entire Envoy admin API to any caller that can reach the port, with no authentication.



An attacker with network access to a data plane's port 9902, for example another pod on the cluster network, can read Envoy and data plane configuration without credentials: config dumps, cluster and listener lists, stats, and the mesh trust bundle. Exposure is read-only - destructive Envoy admin actions are blocked and private keys are not exposed.

πŸŽ–@cveNotify