π¨ CVE-2026-67567
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.
π@cveNotify
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the tenant to deploy arbitrary resources across the entire cluster, leading to a significant security compromise.
π@cveNotify
π¨ CVE-2026-73137
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-controlled Helm repository. This can lead to the exfiltration of credentials from arbitrary namespace Secrets, resulting in information disclosure.
π@cveNotify
A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function in the HelmRelease controller to fetch sensitive credentials from any namespace, which are then sent to an attacker-controlled Helm repository. This can lead to the exfiltration of credentials from arbitrary namespace Secrets, resulting in information disclosure.
π@cveNotify
π¨ CVE-2026-78416
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.
π@cveNotify
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.
π@cveNotify
GitHub
GitHub - craftcms/cms: Build bespoke content experiences with Craft.
Build bespoke content experiences with Craft. Contribute to craftcms/cms development by creating an account on GitHub.
π¨ CVE-2026-16809
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message.
This issue affects LimeSurvey: 7.0.5.
π@cveNotify
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the survey quota creation workflow. An authenticated low-privileged user who can create and manage their own survey can store malicious JavaScript in a quota message.
This issue affects LimeSurvey: 7.0.5.
π@cveNotify
Fluidattacks
LimeSurvey Community Edition 7.0.5 - Stored XSS in quota message rendering | Fluid Attacks
AppSec solution that integrates AI, automated tools, and pentesters to help you prevent, detect, manage, and fix vulnerabilities continuously across your SDLC.
π¨ CVE-2026-21809
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
π@cveNotify
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Quantum Risk Analyzer - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Quantum Risk Analyzer. These issues
π¨ CVE-2026-21810
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
π@cveNotify
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
π@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Quantum Risk Analyzer - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Quantum Risk Analyzer. These issues
π¨ CVE-2026-43621
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.
π@cveNotify
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.
π@cveNotify
GitHub
Implements SMF\Profile::loadMember() Β· SimpleMachines/SMF@6f0dc61
Signed-off-by: Jon Stovell <jonstovell@gmail.com>
π¨ CVE-2026-45694
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate encoding. The parameters are placed into the page title with only strip_tags applied, and the title is then written into an inline document.title assignment through string interpolation, so a single quote terminates the JavaScript string and the remaining input runs as script. An attacker who lures an authenticated user into following a crafted link can execute script in that user's session, enabling actions such as theft of session data. This issue is fixed in version 26.5.0.
π@cveNotify
LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnerable to reflected cross-site scripting through the user-supplied instance and vmid GET parameters, which are reflected into the page title without adequate encoding. The parameters are placed into the page title with only strip_tags applied, and the title is then written into an inline document.title assignment through string interpolation, so a single quote terminates the JavaScript string and the remaining input runs as script. An attacker who lures an authenticated user into following a crafted link can execute script in that user's session, enabling actions such as theft of session data. This issue is fixed in version 26.5.0.
π@cveNotify
GitHub
Fix legacy page title xss (#19659) Β· librenms/librenms@0be1bfd
Community-based GPL-licensed network monitoring system - Fix legacy page title xss (#19659) Β· librenms/librenms@0be1bfd
π¨ CVE-2026-55182
LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped before being passed to an exec call. An authenticated administrator can craft a transport entry whose Recipient contains shell metacharacters and whose path points to the bundled composer_wrapper.php script, which itself passes attacker-controlled input to further unsafe exec calls. By chaining these calls, the administrator can execute arbitrary operating-system commands on the LibreNMS host. This issue is fixed in version 26.5.0.
π@cveNotify
LibreNMS is a network monitoring system. In versions from 21.6.0 up to 26.5.0, the Signal alert transport is vulnerable to command injection because the signal-cli path and the Recipient field of an alert transport entry are insufficiently escaped before being passed to an exec call. An authenticated administrator can craft a transport entry whose Recipient contains shell metacharacters and whose path points to the bundled composer_wrapper.php script, which itself passes attacker-controlled input to further unsafe exec calls. By chaining these calls, the administrator can execute arbitrary operating-system commands on the LibreNMS host. This issue is fixed in version 26.5.0.
π@cveNotify
GitHub
Composer wrapper escape args (#19663) Β· librenms/librenms@868e3b9
Community-based GPL-licensed network monitoring system - Composer wrapper escape args (#19663) Β· librenms/librenms@868e3b9
π¨ CVE-2026-58070
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
π@cveNotify
A vulnerability that records guest OS processing credentials in cleartext in a support log on the guest, allowing a user with read access to that log to recover privileged account credentials.
π@cveNotify
Veeam Software
KB4902: Vulnerability Resolved in Veeam Backup & Replication 13.1
π¨ CVE-2026-61617
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the write handle is opened, using a stale cached usage value and without knowing the size of the incoming data, and it then returns a raw, unaccounted file handle that is never re-checked as the transfer proceeds. A single upload can therefore be written without bound, far beyond the configured disk limit, until the node's disk is full, and because a server stopped for exceeding its limit is not treated as suspended, SFTP writes are still accepted even after the quota is already exceeded. This issue is fixed in version 1.13.3.
π@cveNotify
Wings is the server control plane for the Pterodactyl game-server management panel. In versions up to and including 1.13.2, the SFTP write path does not enforce a server's disk quota during a transfer, allowing a tenant with SFTP write access to a single server to exhaust the host node's physical disk and take down every server on it. Wings checks available space only once, as a boolean, when the write handle is opened, using a stale cached usage value and without knowing the size of the incoming data, and it then returns a raw, unaccounted file handle that is never re-checked as the transfer proceeds. A single upload can therefore be written without bound, far beyond the configured disk limit, until the node's disk is full, and because a server stopped for exceeding its limit is not treated as suspended, SFTP writes are still accepted even after the quota is already exceeded. This issue is fixed in version 1.13.3.
π@cveNotify
GitHub
Improve request handling Β· pterodactyl/wings@da1a216
The server control plane for Pterodactyl Panel. Written from the ground-up with security, speed, and stability in mind. - Improve request handling Β· pterodactyl/wings@da1a216
π¨ CVE-2026-63360
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding.
This issue affects LimeSurvey: 7.0.5.
π@cveNotify
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden input attribute without HTML attribute encoding.
This issue affects LimeSurvey: 7.0.5.
π@cveNotify
Fluidattacks
LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoint | Fluid Attacks
CVE-2026-63360: LimeSurvey Community Edition 7.0.5 contains an authenticated reflected Cross-Site Scripting vulnerability in the user activation confirmation endpoint. The action query parameter is copied into the response and inserted into a hidden inputβ¦
π¨ CVE-2026-64632
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
π@cveNotify
A vulnerability allowing a low-privileged user to capture the NTLM credentials of the Reporter service account.
π@cveNotify
Veeam Software
KB4892: Vulnerabilities Resolved in Veeam ONE 13.1
π¨ CVE-2026-65641
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
π@cveNotify
A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
π@cveNotify
Veeam Software
KB4905: Vulnerability Resolved in Veeam ONE 13.1 Patch 0
π¨ CVE-2026-65642
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
π@cveNotify
Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 through 18.0.80.3, allows remote authenticated users to read and modify other customers' databases.
π@cveNotify
Plesk
Vulnerability CVE-2026-65642 in Plesk's database management interface
SituationA security vulnerability CVE-2026-65642 was discovered in Plesk that could allow an authenticated user to gain unauthorized access to databases belonging to other users on the same server....
π¨ CVE-2026-65646
Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.
π@cveNotify
Improper neutralization of special elements in Plesk allows remote authenticated users to disclose arbitrary local files and escalate privileges.
π@cveNotify
Plesk
Vulnerability CVE-2026-65646 in Plesk's DNS zone management functionality
SituationA security vulnerability CVE-2026-65646 was discovered in Plesk's DNS zone management functionality that could allow a customer with a DNS-managed domain to read arbitrary files from the s...
π¨ CVE-2026-65647
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
π@cveNotify
Improper symlink resolution before file access in Plesk allows remote authenticated users to execute arbitrary code as root.
π@cveNotify
Plesk
Vulnerability CVE-2026-65647 in Plesk's Site Import and Migrator extensions
SituationA security vulnerability CVE-2026-65647 was discovered in Plesk's Site Import and Migrator extensions that could allow an unprivileged Plesk user to execute arbitrary code with root privil...
π¨ CVE-2026-65930
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
π@cveNotify
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.This issue affects LimeSurvey: 7.0.5.
π@cveNotify
Fluidattacks
LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields | Fluid Attacks
CVE-2026-65930: LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting vulnerability in the replacement-fields dialog used by the administrative question editor.
π¨ CVE-2026-75328
In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:
π@cveNotify
In DocSys-master V2.02.85, the downloadDocEx interface in src/com/DocSystem/controller/DocController.java has an arbitrary file read vulnerability:
π@cveNotify
GitHub
CVE/DocSys/DocSysδ»»ζζδ»Άθ―»ε.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75329
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
π@cveNotify
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
π@cveNotify
GitHub
CVE/super-diamond/NETTY-NOAUTH.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75333
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
π@cveNotify
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
π@cveNotify
GitHub
CVE/yx-image-recognition/PATH_TRAVERSAL_REPORT.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.