CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-19825
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.

🎖@cveNotify
🚨 CVE-2026-19870
Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership

🎖@cveNotify
🚨 CVE-2026-73673
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.

🎖@cveNotify
🚨 CVE-2026-18084
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS).

This issue affects UEM: 12.23.0 QF8 or earlier.

🎖@cveNotify
🚨 CVE-2026-18085
An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service.

🎖@cveNotify
🚨 CVE-2026-62872
Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network.

🎖@cveNotify
🚨 CVE-2026-62886
Integer overflow or wraparound in .NET allows an unauthorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-62897
Integer overflow or wraparound in .NET Framework allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-62899
Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.

🎖@cveNotify
🚨 CVE-2026-62900
Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62901
Unchecked input for loop condition in .NET allows an unauthorized attacker to deny service over a network.

🎖@cveNotify
🚨 CVE-2026-62902
Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

🎖@cveNotify
🚨 CVE-2026-62909
Uncaught exception in .NET allows an authorized attacker to elevate privileges locally.

🎖@cveNotify
🚨 CVE-2026-64908
Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-64915
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.

🎖@cveNotify
🚨 CVE-2026-64917
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-60121
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected commands to execute with root privileges via passwordless sudo.

🎖@cveNotify
🚨 CVE-2026-61498
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-supplied values directly to shell commands via passthru(), to execute arbitrary OS commands with root privileges due to the web server context having passwordless sudo access.

🎖@cveNotify
🚨 CVE-2026-63528
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

🎖@cveNotify
🚨 CVE-2026-64899
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.

🎖@cveNotify