๐จ CVE-2024-58377
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not provide or expose the xmllint tool where the issue occurs.
๐@cveNotify
Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not provide or expose the xmllint tool where the issue occurs.
๐@cveNotify
GitHub
[CVE-2024-34459] Fix buffer overread with `xmllint --htmlout` ยท GNOME/libxml2@2876ac5
Add a missing bounds check.
๐จ CVE-2024-58378
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
๐@cveNotify
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies Nokogiri::XML::Reader. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing a crafted XML document can lead to an xmlValidatePopElement use-after-free. Nokogiri 1.15.6 and 1.16.2 resolve this by upgrading the packaged libxml2 to 2.11.7 and 2.12.5 respectively. JRuby and installations using system libxml2 are not affected.
๐@cveNotify
GitHub
[CVE-2024-25062] xmlreader: Don't expand XIncludes when backtracking ยท GNOME/libxml2@9272197
Fixes a use-after-free if XML Reader if used with DTD validation and
XInclude expansion.
Fixes #604.
XInclude expansion.
Fixes #604.
๐จ CVE-2026-79773
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.
๐@cveNotify
Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript assets. Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials.
๐@cveNotify
GitHub
Confine JavaScript importer paths to allowed roots (#237) ยท wintercms/storm@fd673f4
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
๐จ CVE-2026-78895
Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
๐@cveNotify
Information leak in Paint in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
๐@cveNotify
Chrome Releases
Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out ov...
๐จ CVE-2026-78903
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
๐@cveNotify
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
๐@cveNotify
Chrome Releases
Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out ov...
๐จ CVE-2026-78908
Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
๐@cveNotify
Information leak in Canvas in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
๐@cveNotify
Chrome Releases
Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out ov...
๐จ CVE-2026-78912
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
๐@cveNotify
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
๐@cveNotify
Chrome Releases
Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out ov...
๐จ CVE-2026-73335
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.
๐@cveNotify
Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.
๐@cveNotify
jvn.jp
JVN#67155805: Android App "Myna Point" vulnerable to improper access restriction
Japan Vulnerability Notes
๐จ CVE-2026-76148
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
๐@cveNotify
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
๐@cveNotify
GitHub
Release CorvusSKK 3.3.4 ยท nathancorvussolis/corvusskk
JVN#18496672 ใฎๅฏพๅฟ
ๆปๆใซใใฃใฆ่ๅผฑๆงใจใชใใใLuaใฎๆฉ่ฝใ็กๅนๅใใพใใใ
JVN#49765069 ใฎๅฏพๅฟ
็ฌฆๅทใใ32ใใใๆดๆฐใซใใtarใฎใใกใคใซใตใคใบใฎใชใผใใผใใญใผใไฟฎๆญฃใใพใใใ
ใใกใคใซ
ๅฏพๅฟOS
corvusskk-3.3.4.exe
Windows 10 (version 1607 build 14393 ไปฅ้) (x86/x64...
ๆปๆใซใใฃใฆ่ๅผฑๆงใจใชใใใLuaใฎๆฉ่ฝใ็กๅนๅใใพใใใ
JVN#49765069 ใฎๅฏพๅฟ
็ฌฆๅทใใ32ใใใๆดๆฐใซใใtarใฎใใกใคใซใตใคใบใฎใชใผใใผใใญใผใไฟฎๆญฃใใพใใใ
ใใกใคใซ
ๅฏพๅฟOS
corvusskk-3.3.4.exe
Windows 10 (version 1607 build 14393 ไปฅ้) (x86/x64...
๐จ CVE-2026-76149
CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
๐@cveNotify
CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.
๐@cveNotify
GitHub
Release CorvusSKK 3.3.4 ยท nathancorvussolis/corvusskk
JVN#18496672 ใฎๅฏพๅฟ
ๆปๆใซใใฃใฆ่ๅผฑๆงใจใชใใใLuaใฎๆฉ่ฝใ็กๅนๅใใพใใใ
JVN#49765069 ใฎๅฏพๅฟ
็ฌฆๅทใใ32ใใใๆดๆฐใซใใtarใฎใใกใคใซใตใคใบใฎใชใผใใผใใญใผใไฟฎๆญฃใใพใใใ
ใใกใคใซ
ๅฏพๅฟOS
corvusskk-3.3.4.exe
Windows 10 (version 1607 build 14393 ไปฅ้) (x86/x64...
ๆปๆใซใใฃใฆ่ๅผฑๆงใจใชใใใLuaใฎๆฉ่ฝใ็กๅนๅใใพใใใ
JVN#49765069 ใฎๅฏพๅฟ
็ฌฆๅทใใ32ใใใๆดๆฐใซใใtarใฎใใกใคใซใตใคใบใฎใชใผใใผใใญใผใไฟฎๆญฃใใพใใใ
ใใกใคใซ
ๅฏพๅฟOS
corvusskk-3.3.4.exe
Windows 10 (version 1607 build 14393 ไปฅ้) (x86/x64...
๐จ CVE-2026-80200
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.
๐@cveNotify
Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users to attacker-controlled URLs for credential theft or phishing attacks.
๐@cveNotify
GitHub
Open Redirect via Unvalidated RelayState in SAML ACS Handler
### Summary
The SAML authentication success handler in Kimai returns the `RelayState` POST parameter as a redirect destination without validating the host or scheme. After a user successfully au...
The SAML authentication success handler in Kimai returns the `RelayState` POST parameter as a redirect destination without validating the host or scheme. After a user successfully au...
๐จ CVE-2026-79654
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.
๐@cveNotify
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.
๐@cveNotify
Redhat
CVE-2026-79654 - Red Hat Customer Portal
CVE Details App
๐จ CVE-2026-81031
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the request that the token middleware populated, then issues its update against a filter built from the identifier in the URL path, and never compares the two. The route is mounted behind the administrator token check only, so any valid administrator session is sufficient, and the sole ownership-like guard in the handler rejects a single hardcoded demo address. A caller can therefore set an arbitrary password on any other administrator account and sign in as it. The read handler in the same controller directory accepts an identifier the same way, which supplies the identifiers needed to pick a target.
๐@cveNotify
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the request that the token middleware populated, then issues its update against a filter built from the identifier in the URL path, and never compares the two. The route is mounted behind the administrator token check only, so any valid administrator session is sufficient, and the sole ownership-like guard in the handler rejects a single hardcoded demo address. A caller can therefore set an arbitrary password on any other administrator account and sign in as it. The read handler in the same controller directory accepts an identifier the same way, which supplies the identifiers needed to pick a target.
๐@cveNotify
GitHub
GitHub - idurar/idurar-erp-crm: Free Open Source ERP CRM Software Accounting Invoicing | Node.Js React
Free Open Source ERP CRM Software Accounting Invoicing | Node.Js React - idurar/idurar-erp-crm
๐จ CVE-2026-21809
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
๐@cveNotify
HCL BigFix Quantum Risk Analyzer has a certain validation process that provides overly descriptive error messages when it encounters malformed input which can allow an attacker to conduct more efficient reconnaissance and fine-tune automated fuzzing tools to produce valid input.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Quantum Risk Analyzer - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Quantum Risk Analyzer. These issues
๐จ CVE-2026-21810
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
๐@cveNotify
HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity which could allow an attacker to obtain sensitive information or modify the binary.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Quantum Risk Analyzer - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Quantum Risk Analyzer. These issues
๐จ CVE-2026-21807
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
๐@cveNotify
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Quantum Risk Analyzer - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Quantum Risk Analyzer. These issues
๐จ CVE-2026-21808
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
๐@cveNotify
HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.
๐@cveNotify
Hcl-Software
Security Bulletin: Multiple vulnerabilities affect HCL BigFix Quantum Risk Analyzer - Customer Support
Multiple security vulnerabilities have been identified in HCL BigFix Quantum Risk Analyzer. These issues
๐จ CVE-2026-77034
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
๐@cveNotify
Joomla Extension - joomlaeventmanager.net - Unauthenticated article overwrite and force-publish in Joomla Event Manager < 5.0.1 - Any visitor holding their own session token can republish and overwrite an article associated with an event.
๐@cveNotify
www.joomlaeventmanager.net
JEM - Joomla Event Manager
JEM is an open source Event Management component for Joomla CMS with an active user and development community.
๐จ CVE-2026-77035
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
๐@cveNotify
Joomla Extension - joomlaeventmanager.net - Cross-user event and venue takeover through forged form fields in Joomla Event Manager < 5.0.1 - A registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user's record id together with their own id as created_by and take over that record.
๐@cveNotify
www.joomlaeventmanager.net
JEM - Joomla Event Manager
JEM is an open source Event Management component for Joomla CMS with an active user and development community.
๐จ CVE-2026-77989
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
๐@cveNotify
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla Events Manager < 5.0.1 - buildCurrentPdfLink copies the current request query string into the PDF button URL, and pdfbutton() echoes it unescaped, leading to an reflected XSS vector.
๐@cveNotify
www.joomlaeventmanager.net
JEM - Joomla Event Manager
JEM is an open source Event Management component for Joomla CMS with an active user and development community.
๐จ CVE-2026-77990
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
๐@cveNotify
Joomla Extension - joomlaeventmanager.net - Attendee lists readable by any logged-in user in Joomla Event Manager < 5.0.1 - A non-manager can therefore read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events.
๐@cveNotify
www.joomlaeventmanager.net
JEM - Joomla Event Manager
JEM is an open source Event Management component for Joomla CMS with an active user and development community.