π¨ CVE-2026-75329
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
π@cveNotify
The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanism. Attackers can directly obtain the full configuration of any project (including database passwords, API keys, etc.) by sending a TCP request without any credential.
π@cveNotify
GitHub
CVE/super-diamond/NETTY-NOAUTH.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75331
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
π@cveNotify
tamguo 1.5.3 is vulnerable to Unrestricted File Upload Leading to Stored XSS. The /uploadFile and /imgUpload endpoints in FileUploadController.java and UEditorController.java have no file type validation. Attackers can upload arbitrary HTML/JavaScript files to the server.
π@cveNotify
GitHub
CVE/tamgou/xss.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75333
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
π@cveNotify
yx-image-recognition v1.0 is vulnerable to Path Traversal. Parameters such as dir, filePath are directly passed to new File() for file system operations without any path sanitization or whitelist validation.
π@cveNotify
GitHub
CVE/yx-image-recognition/PATH_TRAVERSAL_REPORT.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75330
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
π@cveNotify
The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being parameterized and bound.
π@cveNotify
GitHub
CVE/super-diamond/SQLI-HTTP.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75332
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
π@cveNotify
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
π@cveNotify
GitHub
CVE/Zyplayer-Doc/Zyplayer-Doc.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-75336
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
π@cveNotify
Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.
π@cveNotify
GitHub
CVE/funiture/SQL Injection.md at main Β· fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
π¨ CVE-2026-26452
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers.
π@cveNotify
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 lcontains a vulnerability in the option parsing logic that causes a segmentation fault when processing COAP messages containing invalid option numbers.
π@cveNotify
GitHub
GitHub - ipflavors/ccoap: A CoAP library in C
A CoAP library in C. Contribute to ipflavors/ccoap development by creating an account on GitHub.
π¨ CVE-2026-26453
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.
π@cveNotify
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a null pointer dereference vulnerability in the coap_server_handle_session() function when processing COAP messages containing URI_PATH options with NULL data pointers. When the server searches for a URI_PATH option matching the string "separate", it directly calls strncmp() on option_list[i].data without checking if the pointer is NULL. This causes a segmentation fault when the option's data field is NULL.
π@cveNotify
GitHub
GitHub - ipflavors/ccoap: A CoAP library in C
A CoAP library in C. Contribute to ipflavors/ccoap development by creating an account on GitHub.
π¨ CVE-2026-26459
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.
π@cveNotify
ccoap 77f55c4b466e99327c24ace8a2913d3ba7e2ccd5 contains a vulnerability in the option parsing logic that causes a segmentation fault when processing malformed COAP messages with insufficient option data.
π@cveNotify
GitHub
GitHub - ipflavors/ccoap: A CoAP library in C
A CoAP library in C. Contribute to ipflavors/ccoap development by creating an account on GitHub.
π¨ CVE-2026-26897
An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component
π@cveNotify
An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component
π@cveNotify
π¨ CVE-2026-26899
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
π@cveNotify
An issue was discovered in luci-app-https-dns-proxy on OpenWrt PR #15 (< 2026-01-17). The setInitAction function in /usr/libexec/rpcd/luci.https-dns-proxy allows authenticated users to execute arbitrary shell commands via shell metacharacters in the name parameter
π@cveNotify
GitHub
GitHub - iwallplace/CVE-2026-46368-OpenWrt-Exploit: Proof of Concept exploit for CVE-2026-46368 β authenticated root command injectionβ¦
Proof of Concept exploit for CVE-2026-46368 β authenticated root command injection in OpenWrt luci-app-https-dns-proxy (EDB-52521) - iwallplace/CVE-2026-46368-OpenWrt-Exploit
π¨ CVE-2026-30046
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
π@cveNotify
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
π@cveNotify
GitHub
[Bug]: UDM crashes due to reachable assertion when DELETE request omits pduSessionId path parameter Β· Issue #4264 Β· open5gs/open5gs
Open5GS Release, Revision, or Tag v2.7.6 Steps to reproduce curl --http2-prior-knowledge -X DELETE -v http://127.0.to.12:7777/nudm-uecm/v1/imsi-001010000000001/registrations/smf-registrations/ Logs...
π¨ CVE-2026-30047
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
π@cveNotify
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
π@cveNotify
GitHub
[Bug]: smf Crashed due to Assertion `psi != OGS_NAS_PDU_SESSION_IDENTITY_UNASSIGNED' failed. Β· Issue #4201 Β· open5gs/open5gs
Open5GS Release, Revision, or Tag v2.7.6 Steps to reproduce curl -X POST --http2-prior-knowledge http://127.0.0.4:7777/nsmf-pdusession/v1/sm-contexts -H "Content-Type: application/json" -...
π¨ CVE-2026-30050
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
π@cveNotify
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
π@cveNotify
GitHub
[Bugs] AMF Event Exposure ModifyAMFEventSubscriptionProcedure Panics on Negative Path Index Β· Issue #776 Β· free5gc/free5gc
Bug Description A vulnerability exists in the ModifyAMFEventSubscriptionProcedure function within the AMF Event Exposure service (processor/event_exposure.go). When processing a PATCH request to mo...
π¨ CVE-2026-30056
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.
π@cveNotify
A NULL pointer dereference in the AMF NGAP Dispatcher component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted NGAP messages during the initialization of a new RAN connection.
π@cveNotify
GitHub
[Bugs] Nil Pointer Dereference in AMF NGAP Dispatcher when receive unexpected message sequence Β· Issue #768 Β· free5gc/free5gc
Bug Description The issue occurs because the dispatcher does not enforce the mandatory NGAP message sequence during the initialization of a new RAN connection. Instead of requiring the first messag...
π¨ CVE-2026-30057
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.
π@cveNotify
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.
π@cveNotify
GitHub
[Bugs] AMF CreateUEContext Panic on multipart/related Content-Type due to improper deserialization Β· Issue #755 Β· free5gc/free5gc
Bug Description The AMFβs CreateUEContext handler (HTTPCreateUEContext in internal/sbi/api_communication.go) mishandles requests with Content-Type: multipart/related. When such a request is process...
π¨ CVE-2026-30062
An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.
π@cveNotify
An issue in the NGAP handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted NAS PDU.
π@cveNotify
GitHub
[Bugs] NGAP handler passes the received NAS PDU to the NAS decoding layer without sufficient validation Β· Issue #812 Β· free5gc/free5gc
Bug Description The AMF's NGAP handler passes the received NAS PDU to the NAS decoding layer without sufficient validation. A malformed NAS PDU (e.g., a single byte) causes the decoding functio...
π¨ CVE-2026-30073
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
π@cveNotify
An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
π@cveNotify
GitHub
[Bugs] NSSF Nil Pointer Panic in NssaiAvailabilitySubscriptionCreate Β· Issue #764 Β· free5gc/free5gc
Bug Description Creating an NSSAI availability subscription can crash the NSSF with just a single POST request. The request handler (NssaiAvailabilitySubscriptionCreate) dereferences and mutates a ...
π¨ CVE-2026-75357
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
π@cveNotify
An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.
π@cveNotify
GitHub
bilibili-desktop-ipc-origin-validation/advisory.md at main Β· LeoWSY-hashblue/bilibili-desktop-ipc-origin-validation
Sanitized advisory for Bilibili Desktop privileged IPC sender URL allowlist bypass (CWE-346) - LeoWSY-hashblue/bilibili-desktop-ipc-origin-validation
π¨ CVE-2026-30612
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
π@cveNotify
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
π@cveNotify
π¨ CVE-2026-36102
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
π@cveNotify
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
π@cveNotify
Gist
checkmateso-privilege-escalation.md
GitHub Gist: instantly share code, notes, and snippets.