๐จ CVE-2026-21078
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
๐@cveNotify
Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.
๐@cveNotify
๐จ CVE-2026-21079
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
๐@cveNotify
Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.
๐@cveNotify
๐จ CVE-2026-21080
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
๐จ CVE-2026-21081
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
๐@cveNotify
Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
๐@cveNotify
๐จ CVE-2026-21082
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-21083
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.
๐@cveNotify
๐จ CVE-2026-21084
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
๐@cveNotify
Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.
๐@cveNotify
๐จ CVE-2026-18503
Attacker-controlled CSV samples can trigger super-linear
regular-expression work during dialect sniffing and consume significant
CPU when applications pass unbounded input to csv.Sniffer.sniff().
๐@cveNotify
Attacker-controlled CSV samples can trigger super-linear
regular-expression work during dialect sniffing and consume significant
CPU when applications pass unbounded input to csv.Sniffer.sniff().
๐@cveNotify
GitHub
[3.12] gh-98820: Fix quadratic time in csv.Sniffer for quoted fields โฆ ยท python/cpython@063d455
โฆ(GH-154867) (#155166)
(cherry picked from commit b30c7fa9edd921a118f286e9f90f560777fa693b)
Co-authored-by: Miss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
(cherry picked from commit b30c7fa9edd921a118f286e9f90f560777fa693b)
Co-authored-by: Miss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
๐จ CVE-2026-12339
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
๐@cveNotify
A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to overwrite on the underlying system, affecting system integrity and availability.
๐@cveNotify
TP-Link
Download for Archer MR200 | TP-Link
TP Link - Download Center Detail
๐จ CVE-2025-30237
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks are not consistently enforced on certain endpoints. An attacker can send
specially crafted requests to bypass authentication and directly invoke
privileged functionality without valid credentials. This issue arises from
improper enforcement of access control mechanisms on sensitive operations.
Successful
exploitation may allow an unauthenticated attacker to execute privileged
operations and gain full control of the device.
๐@cveNotify
The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication
checks are not consistently enforced on certain endpoints. An attacker can send
specially crafted requests to bypass authentication and directly invoke
privileged functionality without valid credentials. This issue arises from
improper enforcement of access control mechanisms on sensitive operations.
Successful
exploitation may allow an unauthenticated attacker to execute privileged
operations and gain full control of the device.
๐@cveNotify
๐จ CVE-2025-30238
In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged users to execute higher-privileged
operations.
An attacker
may perform administrative actions such as creating privileged accounts or
modifying critical configuration settings.
๐@cveNotify
In affected TP-Link Aginet devices, insufficient
authorization validation allows authenticated low-privileged users to execute higher-privileged
operations.
An attacker
may perform administrative actions such as creating privileged accounts or
modifying critical configuration settings.
๐@cveNotify
๐จ CVE-2025-30239
In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.
Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.
๐@cveNotify
In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware to protect sensitive
configuration data may allow an attacker who has access to device storage to
recover the keys and decrypt stored data.
Successful
exploitation may allow access to decrypted sensitive configuration data,
including credentials and service-related information.
๐@cveNotify
๐จ CVE-2025-30240
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
devices. By placing a crafted symbolic link on supported storage media, an
attacker may cause the system to resolve the link.
Successful
exploitation may allow unauthorized read access to sensitive files within the
device filesystem.
๐@cveNotify
The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage
devices. By placing a crafted symbolic link on supported storage media, an
attacker may cause the system to resolve the link.
Successful
exploitation may allow unauthorized read access to sensitive files within the
device filesystem.
๐@cveNotify
๐จ CVE-2026-13716
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
๐@cveNotify
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
๐@cveNotify
GitLab
Path traversal in import/admin file upload (`fileName` header) allows arbitrary file write outside the upload sandbox (#727) ยทโฆ
Summary The chunked/non-chunked upload handler ApiFilesUploadHandler derives the destination file path by joining a fixed upload directory...
๐จ CVE-2026-19517
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
๐@cveNotify
Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
๐@cveNotify
GitHub
Safety limits to precomp, repeater, and polystar handling by mmaciola ยท Pull Request #596 ยท Samsung/rlottie
Introduce bounds to keep resource use predictable on deeply nested or oversized inputs:
Cap precomp nesting depth in repeater processing, render-tree build, and render walk
Cap total render-node c...
Cap precomp nesting depth in repeater processing, render-tree build, and render walk
Cap total render-node c...
๐จ CVE-2026-19518
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.
๐@cveNotify
Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.
๐@cveNotify
GitHub
Safety limits to precomp, repeater, and polystar handling by mmaciola ยท Pull Request #596 ยท Samsung/rlottie
Introduce bounds to keep resource use predictable on deeply nested or oversized inputs:
Cap precomp nesting depth in repeater processing, render-tree build, and render walk
Cap total render-node c...
Cap precomp nesting depth in repeater processing, render-tree build, and render walk
Cap total render-node c...
๐จ CVE-2026-62734
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-62748
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-19579
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
๐@cveNotify
Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side authorization check, so any authenticated, low-privileged user can supply a non-empty cancel_by_admin value to bypass the request-ownership check and cancel another user's pending checkout request. Because asset and user identifiers are sequential integers, an attacker can enumerate them to cancel every pending checkout request, disrupting the asset-request workflow. This is fixed in Snipe-IT 8.6.0.
๐@cveNotify
GitHub
Release v8.6.0 ยท grokability/snipe-it
CautionThis version of Snipe-IT REQUIRES PHP 8.2.0 or greater, 8.4+ recommended. PHP 8.2 is still in security release support until 31 Dec 2026, but let's not play that game
Wow wow wow. Wow....
Wow wow wow. Wow....
๐จ CVE-2026-19587
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
๐@cveNotify
Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.
๐@cveNotify
GitHub
Add shape-content budget to bound repeater cost by mmaciola ยท Pull Request #599 ยท Samsung/rlottie
Repeaters can multiply a shape by up to 10000 copies, and each shape can have up to 1024 points. Multiplying both together (or nesting repeaters inside each other) could still produce very large am...
๐จ CVE-2026-19588
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
๐@cveNotify
Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
๐@cveNotify
GitHub
Cap bitmap size to avoid large dimensions by mmaciola ยท Pull Request #600 ยท Samsung/rlottie
Compute stride and buffer size in 64-bit and reject requests bigger than 128 MB, falling back to an empty bitmap.