CVE Notify
19.6K subscribers
4 photos
315K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2026-21551
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21552
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21553
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21554
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-21555
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-70374
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateThumbnail in src/Server/Entity/Resource/Media.js builds a temporary file path as 'thumbnail' + Path.extname(filename) and passes it, unescaped, into a shell command executed via AppService.exec ('convert ' + tempFile + ...).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-70375
HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server/Entity/Deployer/GitDeployer.js executes AppService.exec, interpolating the configured branch value directly into a shell command with no escaping.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-54416
Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php','php3','php4','php5','php6','php7','phtml','.phtm','.pht','.ph3','.ph4','.ph5','.asp','.cgi','.phar'), checked against the last 4-5 characters of the filename.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-54418
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-55739
Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers method are similarly unscoped (self::find with no company filter).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-55747
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-70376
Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-70377
imagecli's pipeline operation (Scale::apply in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. Any application embedding imagecli as a library and accepting user-controlled pipeline strings is remotely crashable with a single request.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-70378
imagecli's pipeline operation (Carve::apply in src/image_ops.rs) only asserts , never validating that the ratio is positive. A negative ratio (e.g. -5) causes the computed target width to saturate to 0 via Rust's defined float-to-uint cast, which is then passed to imageproc::seam_carving::shrink_width โ€” a function that panics when given a width below 2, crashing the process.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-0516
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-15570
An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded browser to issue requests to unintended loopback/internal destinations, including 127.0.0.1 addresses. In demonstrated scenarios, requests initiated through the SmartCenter browserseturl mechanism could reach an internal service and receive a successful response, although the same destination was not reachable through normal browser navigation. The issue affects firmware version V2.78.0.0 and is fixed in firmware version V2.85.2.0.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-66151
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2026-72564
An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in any organization by reusing an access token issued for a different resource.

๐ŸŽ–@cveNotify