🚨 CVE-2026-67925
Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload
🎖@cveNotify
Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload
🎖@cveNotify
GitHub
High Risk Stored XSS Vulnerability in JeecgBoot 3.9.2 · Issue #9773 · jeecgboot/JeecgBoot
版本号: JeecgBoot 3.9.2(26.x/ 4.6 系列) 分支: 问题描述: JeecgBoot 存在未授权文件上传引发的存储型 XSS 漏洞。匿名可直接调用免登上传接口/airag/chat/upload,后端文件校验允许 SVG、HTML 等支持 JS 脚本的文件格式,上传文件持久存储至服务器磁盘,框架静态资源路由将上传目录对外开放,任意用户均可直接访问上传文件。 攻击者上传...
🚨 CVE-2026-67926
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
🎖@cveNotify
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
🎖@cveNotify
GitHub
Unauthenticated SSRF Triggered by files Parameter in JeecgBoot AI Chat Module · Issue #9774 · jeecgboot/JeecgBoot
版本号: JeecgBoot v3.9.2 问题描述: JeecgBoot /airag/chat/send 接口存在 SSRF 漏洞,接口未对传入的files参数做内网 IP、本地地址访问限制,攻击者可构造恶意 URL 传入 files 数组,服务端会主动发起网络请求。利用该漏洞可扫描内网资产、访问内网服务、读取本地文件,无身份校验即可触发,危害内网安全。 The /airag/chat/...
🚨 CVE-2026-67965
An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function
🎖@cveNotify
An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function
🎖@cveNotify
GitHub
GitHub - H0111mes/Tenda-W20E-Vulnerability-Disclosure
Contribute to H0111mes/Tenda-W20E-Vulnerability-Disclosure development by creating an account on GitHub.
🚨 CVE-2026-42163
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.
🎖@cveNotify
Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.
🎖@cveNotify
mahara.org
Security announcements - Security maintenance releases Mahara 25.04.7 and Mahara 26.04.1 - Mahara ePortfolio System
Mahara is an open source ePortfolio and social networking web application.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
🚨 CVE-2026-51977
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
🎖@cveNotify
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component
🎖@cveNotify
GitHub
CVE/CVE-2026-51977/README.md at main · EmbdCDACHyd/CVE
Research repository focused on security vulnerabilities (CVEs) in IoT devices, firmware, communication protocols, and embedded systems. - EmbdCDACHyd/CVE
🚨 CVE-2026-67854
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
🎖@cveNotify
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
🎖@cveNotify
JiuZero's Blog
QCMS tableField_Action Backend SQL Injection Vulnerability White-box Audit Report
This content is encrypted, please enter the password to view.
🚨 CVE-2026-67960
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
🎖@cveNotify
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
🎖@cveNotify
🚨 CVE-2026-42162
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.
🎖@cveNotify
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.
🎖@cveNotify
mahara.org
Home - Mahara ePortfolio System
Mahara is an open source ePortfolio and social networking web application.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
🚨 CVE-2026-42164
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
🎖@cveNotify
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
🎖@cveNotify
mahara.org
Home - Mahara ePortfolio System
Mahara is an open source ePortfolio and social networking web application.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
It provides people with tools to create and maintain a digital portfolio of their learning and social networking features to allow them to interact with each other.
🚨 CVE-2026-52606
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php.
🎖@cveNotify
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the loadTemplate parameter in conjunction with the execute_mode=PREPARE parameter of run.php.
🎖@cveNotify
GitHub
vulnerability-research/CVE-2026-52606 at main · kilotel/vulnerability-research
This repository contains information on the CVEs I found. - kilotel/vulnerability-research
🚨 CVE-2026-52607
A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint.
🎖@cveNotify
A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php endpoint.
🎖@cveNotify
GitHub
vulnerability-research/CVE-2026-52607 at main · kilotel/vulnerability-research
This repository contains information on the CVEs I found. - kilotel/vulnerability-research
🚨 CVE-2026-52608
An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.
🎖@cveNotify
An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.
🎖@cveNotify
GitHub
vulnerability-research/CVE-2026-52608 at main · kilotel/vulnerability-research
This repository contains information on the CVEs I found. - kilotel/vulnerability-research
🚨 CVE-2026-52609
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php.
🎖@cveNotify
A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA parameter of run.php.
🎖@cveNotify
GitHub
vulnerability-research/CVE-2026-52609 at main · kilotel/vulnerability-research
This repository contains information on the CVEs I found. - kilotel/vulnerability-research
🚨 CVE-2026-52610
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint.
🎖@cveNotify
An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction with "execute_mode=PREPARE" parameter in the "run.php" endpoint.
🎖@cveNotify
GitHub
vulnerability-research/CVE-2026-52610 at main · kilotel/vulnerability-research
This repository contains information on the CVEs I found. - kilotel/vulnerability-research
🚨 CVE-2026-67920
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components
🎖@cveNotify
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components
🎖@cveNotify
Gist
CVE-2026-67920.md
GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2026-67921
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.
🎖@cveNotify
Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.
🎖@cveNotify
Gist
CVE-2026-67921.md
GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2026-52480
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service
🎖@cveNotify
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service
🎖@cveNotify
GitHub
GitHub - AshtonKopelevich/SJ-GPS-PRO-F11-Vulnerability
Contribute to AshtonKopelevich/SJ-GPS-PRO-F11-Vulnerability development by creating an account on GitHub.
🚨 CVE-2026-71675
An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c
🎖@cveNotify
An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c
🎖@cveNotify
Gist
Memory Leakage in Open5GS AMF
Memory Leakage in Open5GS AMF. GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2026-71676
Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when the message type byte of a NAS PDU is mutated
🎖@cveNotify
Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when the message type byte of a NAS PDU is mutated
🎖@cveNotify
Gist
Open5GS_2.md
GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2026-71960
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface.
🎖@cveNotify
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image. Attackers can use the extracted secret to craft arbitrary JWT tokens and authenticate to the MQTT broker without legitimate credentials, gaining unauthorized access to the device's mesh networking interface.
🎖@cveNotify
Cudy
Downloads for WR3000 2.0
Cudy offers wide range of networking provides, including 5G 4G CPE Routers, Wi-Fi Router, Whole-Home Mesh System, Access Points, Industrial Routers
🚨 CVE-2026-77069
n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration requests use n8n's SSRF-protected HTTP client, the token exchange uses a separate client with no SSRF guard. A user with credential-creation permissions can set the access-token URL to an internal address and complete the OAuth2 flow, causing n8n to send a fixed-shape token-exchange POST to that target and reflect its response body back to the attacker (limited to what the target returns to this specific request).
🎖@cveNotify
n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-access-token exchange. While OAuth2 discovery and dynamic-client-registration requests use n8n's SSRF-protected HTTP client, the token exchange uses a separate client with no SSRF guard. A user with credential-creation permissions can set the access-token URL to an internal address and complete the OAuth2 flow, causing n8n to send a fixed-shape token-exchange POST to that target and reflect its response body back to the attacker (limited to what the target returns to this specific request).
🎖@cveNotify
GitHub
SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response Body
## Impact
n8n's OAuth2 credential flow routed discovery and dynamic-client-registration requests through its SSRF-protected HTTP client, but the authorization-code-to-access-token exchange use...
n8n's OAuth2 credential flow routed discovery and dynamic-client-registration requests through its SSRF-protected HTTP client, but the authorization-code-to-access-token exchange use...