🚨 CVE-2026-8715
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
🎖@cveNotify
Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and transmit their contents to a tenant-controlled endpoint, potentially leading to privilege escalation within the cluster. This vulnerability (CVE-2026-8715) is fixed in Vault Secrets Operator 1.5.0.
🎖@cveNotify
HashiCorp Discuss
HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath
Bulletin ID: HCSEC-2026-28 Affected Products / Versions: Vault Secrets Operator 1.3.0 up to 1.4.1; fixed in Vault Secrets Operator 1.5.0. Publication Date: August 13, 2026 Summary Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary…
🚨 CVE-2026-72776
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.
🎖@cveNotify
AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard CORS. Attackers can send unauthenticated HTTP requests that cause the autonomous agent to generate and execute shell commands through BashInterpreter using subprocess.Popen with shell=True and safety=False, bypassing the incomplete command blocklist to achieve full host-level code execution.
🎖@cveNotify
GitHub
GitHub - Fosowl/agenticSeek: Fully Local Manus AI. No APIs, No $200 monthly bills. Enjoy an autonomous agent that thinks, browses…
Fully Local Manus AI. No APIs, No $200 monthly bills. Enjoy an autonomous agent that thinks, browses the web, and code for the sole cost of electricity. - Fosowl/agenticSeek
🚨 CVE-2026-73039
streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards by supplying arbitrary primary keys without ownership verification.
🎖@cveNotify
streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards by supplying arbitrary primary keys without ownership verification.
🎖@cveNotify
GitHub
GitHub - streamaserver/streama: Self hosted streaming media server. https://docs.streama-project.com/
Self hosted streaming media server. https://docs.streama-project.com/ - streamaserver/streama
🚨 CVE-2026-19823
A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos of the component QoS Rule Deletion. Performing a manipulation of the argument qosIndex results in stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
🎖@cveNotify
GitHub
mycve/Tenda_W20E/4.md at main · paueger/mycve
mycve. Contribute to paueger/mycve development by creating an account on GitHub.
🚨 CVE-2026-19824
A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
🎖@cveNotify
A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /goform/addIpMacBind. Executing a manipulation of the argument IPMacBindRule can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
🎖@cveNotify
GitHub
mycve/Tenda_W20E/5.md at main · paueger/mycve
mycve. Contribute to paueger/mycve development by creating an account on GitHub.
🚨 CVE-2026-19825
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
🎖@cveNotify
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
🎖@cveNotify
GitHub
SourceCodester Simple Client Management System in PHP with Source Code V1.0 Master.php save_service id SQL Injection · Issue #3…
VulDB Submission Title (Title) SourceCodester Simple Client Management System in PHP with Source Code V1.0 Master.php save_service id SQL Injection Affected Product and Version Product Name: Simple...
🚨 CVE-2026-19826
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.
🎖@cveNotify
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any further explanation.
🎖@cveNotify
GitHub
GitHub - alldatacenter/alldata: 🔥🔥 AllData可定义数据中台,以数据平台为底座,以数据中台为桥梁,以机器学习平台为工厂,以大模型应用为上游产品,提供全链路数字化解决方案。产品正式演示体验、社群咨询、商务采购:htt…
🔥🔥 AllData可定义数据中台,以数据平台为底座,以数据中台为桥梁,以机器学习平台为工厂,以大模型应用为上游产品,提供全链路数字化解决方案。产品正式演示体验、社群咨询、商务采购:https://docs.qq.com/doc/DVHlkSEtvVXVCdEFo - alldatacenter/alldata
🚨 CVE-2026-19870
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
🎖@cveNotify
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership
🎖@cveNotify
GitHub
Fix/payroll cross tenant isolation (#264) · Roskus/prospero-flow-crm@59644f9
* fix: scope payroll queries to caller's company and validate employee ownership
Thanks to CuriosidadesDeHacker for the responsible disclosure.
- PayrollIndexController: add company_id sc...
Thanks to CuriosidadesDeHacker for the responsible disclosure.
- PayrollIndexController: add company_id sc...
🚨 CVE-2026-73673
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.
🎖@cveNotify
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.
🎖@cveNotify
GitHub
GitHub - ozcanpng/CVE-2026-73673: Original research and non-destructive PoC for an unauthenticated firmware update vulnerability…
Original research and non-destructive PoC for an unauthenticated firmware update vulnerability with missing cryptographic firmware authentication in Netis NC63 - ozcanpng/CVE-2026-73673
🚨 CVE-2026-18084
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS).
This issue affects UEM: 12.23.0 QF8 or earlier.
🎖@cveNotify
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS).
This issue affects UEM: 12.23.0 QF8 or earlier.
🎖@cveNotify
Blackberry
BSRT-2026-001 Vulnerabilities in BlackBerry UEM Management Console Impact BlackBerry UEM
This advisory addresses 2 vulnerabilities in the BlackBerry UEM Management Console of BlackBerry UEM
🚨 CVE-2026-18085
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
🎖@cveNotify
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.
🎖@cveNotify
Blackberry
BSRT-2026-001 Vulnerabilities in BlackBerry UEM Management Console Impact BlackBerry UEM
This advisory addresses 2 vulnerabilities in the BlackBerry UEM Management Console of BlackBerry UEM
🚨 CVE-2026-62872
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
🎖@cveNotify
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.
🎖@cveNotify
🚨 CVE-2026-62886
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
🎖@cveNotify
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-62897
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-62899
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
🎖@cveNotify
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.
🎖@cveNotify
🚨 CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-62901
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.
🎖@cveNotify
🚨 CVE-2026-62902
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.
🎖@cveNotify
🚨 CVE-2026-62909
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
🚨 CVE-2026-64908
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.
🎖@cveNotify
🚨 CVE-2026-64915
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🎖@cveNotify
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
🎖@cveNotify