π¨ CVE-2026-15623
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter.
This vulnerability was patched in version 6.3.85, and no customer action is needed.
π@cveNotify
A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to execute blind SQL queries using a crafted request parameter.
This vulnerability was patched in version 6.3.85, and no customer action is needed.
π@cveNotify
Google Cloud Documentation
Google Security Operations SOAR release notes | Google Cloud Documentation
π¨ CVE-2026-19995
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
π@cveNotify
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
π@cveNotify
GitHub
PHP_Web_POCs/Bagisto/39_english_vulnerability_report.md at main Β· Mitchell45/PHP_Web_POCs
Contribute to Mitchell45/PHP_Web_POCs development by creating an account on GitHub.
π¨ CVE-2026-19997
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
π@cveNotify
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
π@cveNotify
GitHub
PHP_Web_POCs/Bagisto/11_18_english_vulnerability_report.md at main Β· Mitchell45/PHP_Web_POCs
Contribute to Mitchell45/PHP_Web_POCs development by creating an account on GitHub.
π¨ CVE-2026-22072
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
π@cveNotify
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
π@cveNotify
π¨ CVE-2026-20000
A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the argument delid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
π@cveNotify
A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptionrecord.php. The manipulation of the argument delid results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
π@cveNotify
GitHub
itsourcecode Hospital Management System V1.0 SQL Injection Vulnerability Β· Issue #3 Β· Kristin5634487/cve
itsourcecode Hospital Management System V1.0 SQL Injection Vulnerability NAME OF AFFECTED PRODUCT(S) Hospital Management System Vendor Homepage https://itsourcecode.com/free-projects/php-project/ho...
π¨ CVE-2026-49307
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
π@cveNotify
Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
π@cveNotify
π¨ CVE-2026-74800
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
π@cveNotify
SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-site scripting attacks. Authenticated attackers can upload HTML files as assets and execute scripts with full kernel API access when the workspace owner opens the asset link.
π@cveNotify
GitHub
Stored XSS via arbitrary-file assets served same-origin without Content-Disposition or X-Content-Type-Options, escalating to fullβ¦
### Summary
SiYuan lets users attach/embed arbitrary files as "assets" (there is no
file-extension allowlist or denylist on upload). Assets are served back at
`GET /assets/*path`. For ...
SiYuan lets users attach/embed arbitrary files as "assets" (there is no
file-extension allowlist or denylist on upload). Assets are served back at
`GET /assets/*path`. For ...
π¨ CVE-2026-74801
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
π@cveNotify
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
π@cveNotify
GitHub
Unescaped workspace path concatenated into a UAC-elevated command line allows local privilege escalation via the bundled elevator.exeβ¦
### Summary
On Windows, SiYuan can prompt to add a Windows Defender exclusion for the
install and workspace directories. To do this with the required
administrator rights, it launches a bundled ...
On Windows, SiYuan can prompt to add a Windows Defender exclusion for the
install and workspace directories. To do this with the required
administrator rights, it launches a bundled ...
π¨ CVE-2026-74869
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display names, avatars, and status changes for members they should not have access to.
π@cveNotify
stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message with an arbitrary server ID, receiving live UserUpdate events including display names, avatars, and status changes for members they should not have access to.
π@cveNotify
GitHub
Missing authorization on Bonfire `Subscribe` β crossβserver member enumeration & profile/status surveillance (banβevasion)
### Summary
Bonfire decides what events to send a client purely from which pub/sub topic the socket is subscribed to β it never re-checks permissions on the event itself. The problem is the `Sub...
Bonfire decides what events to send a client purely from which pub/sub topic the socket is subscribed to β it never re-checks permissions on the event itself. The problem is the `Sub...
π¨ CVE-2026-74870
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal scrollback, session recordings, or CI logs. Impact is limited because the pepper is derived from a random per-invocation test salt and is salt-bound, so the leaked value cannot be used to decrypt real files. A related plugin issue logged raw prf_data outside the secret-redaction path. Fixed in 1.4.8 (and 1.5.0) by removing the hex dumps and routing plugin debug output through the redaction layer.
π@cveNotify
openssl_encrypt (pip) versions <= 1.4.7 contain an information exposure vulnerability where the 'hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to stdout/stderr (crypt_cli.py, handle_hsm_command). The printed value can persist in terminal scrollback, session recordings, or CI logs. Impact is limited because the pepper is derived from a random per-invocation test salt and is salt-bound, so the leaked value cannot be used to decrypt real files. A related plugin issue logged raw prf_data outside the secret-redaction path. Fixed in 1.4.8 (and 1.5.0) by removing the hex dumps and routing plugin debug output through the redaction layer.
π@cveNotify
GitHub
hsm fido2-test/onlykey-test print the derived hardware pepper in cleartext
The 'openssl-encrypt hsm fido2-test' and 'hsm onlykey-test' diagnostic commands unconditionally print the full derived hardware pepper as hex to the terminal (openssl_encrypt/module...
π¨ CVE-2026-74875
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
π@cveNotify
openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks and process malicious data.
π@cveNotify
GitHub
Schema validation silently skipped when jsonschema library is not installed
## Severity: HIGH
### Summary
In `openssl_encrypt/modules/json_validator.py` at **lines 234-238**, when the `jsonschema` library is not installed, all schema validation is silently skipped wi...
### Summary
In `openssl_encrypt/modules/json_validator.py` at **lines 234-238**, when the `jsonschema` library is not installed, all schema validation is silently skipped wi...
π¨ CVE-2026-74876
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
π@cveNotify
openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using attacker-controlled public keys, leaking secrets.
π@cveNotify
GitHub
Unverified key bundle from_dict() + to_identity() path allows encryption to attacker keys
## Severity: HIGH
### Summary
The `PublicKeyBundle.from_dict()` method in `openssl_encrypt/modules/key_bundle.py` at **lines 329-361** creates bundles from untrusted data without verifying th...
### Summary
The `PublicKeyBundle.from_dict()` method in `openssl_encrypt/modules/key_bundle.py` at **lines 329-361** creates bundles from untrusted data without verifying th...
π¨ CVE-2026-74879
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
π@cveNotify
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to unauthenticated callers. Attackers can trigger database errors to extract sensitive information including hostnames, IP addresses, connection parameters, and potentially credentials from exception messages.
π@cveNotify
GitHub
Readiness endpoint leaks database error details to unauthenticated callers
## Severity: HIGH
### Summary
The `/ready` endpoint in `openssl_encrypt_server/server.py` at **lines 159-175** catches database errors and returns the full exception string in the response.
...
### Summary
The `/ready` endpoint in `openssl_encrypt_server/server.py` at **lines 159-175** catches database errors and returns the full exception string in the response.
...
π¨ CVE-2026-74884
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.
π@cveNotify
openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitized before constructing the plugin config directory path. Attackers can declare a malicious plugin_id containing path traversal sequences like '../' to access arbitrary directories outside the intended plugin directory.
π@cveNotify
GitHub
Path traversal via unsanitized plugin_id in sandbox _is_safe_path
## Severity: HIGH
### Summary
The `_is_safe_path` method in `openssl_encrypt/modules/plugin_system/plugin_sandbox.py` at **lines 617-633** constructs a plugin config directory path using the unsa...
### Summary
The `_is_safe_path` method in `openssl_encrypt/modules/plugin_system/plugin_sandbox.py` at **lines 617-633** constructs a plugin config directory path using the unsa...
π¨ CVE-2026-74886
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
π@cveNotify
openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import unblocked dangerous modules like sys, shutil, multiprocessing, importlib, and pickle for arbitrary code execution.
π@cveNotify
GitHub
Plugin import guard blocked modules not synchronized with AST analyzer
## Severity: HIGH
### Summary
The `PluginImportGuard` in `openssl_encrypt/modules/plugin_system/plugin_sandbox.py` at **lines 69-94** blocks a different set of modules than the AST analyzer's...
### Summary
The `PluginImportGuard` in `openssl_encrypt/modules/plugin_system/plugin_sandbox.py` at **lines 69-94** blocks a different set of modules than the AST analyzer's...
π¨ CVE-2026-74889
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
π@cveNotify
openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.
π@cveNotify
GitHub
HKDF key normalization uses no salt with static info parameter
## Severity: HIGH
### Summary
The `normalize_to_key_length_secure` function in `openssl_encrypt/modules/crypt_core.py` at **lines 2082-2088** and the parallel KDF equivalent `_normalize_bytes` in...
### Summary
The `normalize_to_key_length_secure` function in `openssl_encrypt/modules/crypt_core.py` at **lines 2082-2088** and the parallel KDF equivalent `_normalize_bytes` in...
π¨ CVE-2026-74891
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
π@cveNotify
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.
π@cveNotify
GitHub
Hardcoded database credentials in standalone servers
## Severity: CRITICAL
### Summary
Both standalone servers ship with hardcoded database credentials as default connection strings.
### Affected Code
```python
# server/key-server/app/config.py:3...
### Summary
Both standalone servers ship with hardcoded database credentials as default connection strings.
### Affected Code
```python
# server/key-server/app/config.py:3...
π¨ CVE-2026-74894
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.
π@cveNotify
openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user by providing any Bearer token in the Authorization header.
π@cveNotify
GitHub
Standalone key server accepts ANY Bearer token as valid authentication
## Severity: CRITICAL
### Summary
The standalone key server's `verify_api_token()` function in `server/key-server/app/api/v1/keys.py` at **lines 48-87** only checks that a non-empty token str...
### Summary
The standalone key server's `verify_api_token()` function in `server/key-server/app/api/v1/keys.py` at **lines 48-87** only checks that a non-empty token str...
π¨ CVE-2026-74901
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
π@cveNotify
openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping attacks without detection.
π@cveNotify
GitHub
PQC fallback to unauthenticated AES-CTR when GCM fails
## Severity: CRITICAL
### Summary
In `openssl_encrypt/modules/pqc.py` at **lines 1400-1444**, when AES-GCM decryption fails (authentication error), the code falls back to **unauthenticated AES-CT...
### Summary
In `openssl_encrypt/modules/pqc.py` at **lines 1400-1444**, when AES-GCM decryption fails (authentication error), the code falls back to **unauthenticated AES-CT...
π¨ CVE-2026-74998
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
π@cveNotify
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
π@cveNotify
GitHub
Add basic validation for content proxied by the css proxy Β· roundcube/roundcubemail@62d33c8
The Roundcube Webmail suite. Contribute to roundcube/roundcubemail development by creating an account on GitHub.
π¨ CVE-2026-16137
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
π@cveNotify
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
π@cveNotify
Sharefile
ShareFile Storage Zones Controller (SZC) Service Disruption Guidance, Login Issues, and Access Information
This article addresses common questions related to the ShareFile Storage Zones Controller (SZC) service disruption notification, including whether the email communication is legitimate, why ShareFile access may be unavailable, login and authentication issuesβ¦