🚨 CVE-2026-18295
GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of MRF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29510.
🎖@cveNotify
GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of MRF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29510.
🎖@cveNotify
🚨 CVE-2026-18296
GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of MRF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29608.
🎖@cveNotify
GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of MRF files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-29608.
🎖@cveNotify
🚨 CVE-2026-54789
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.
🎖@cveNotify
mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Relying Party functionality. Prior to 2.4.19.4, an out-of-bounds read and a one-byte out-of-bounds write exist in the state-cookie parser of `mod_auth_openidc`. The issue is fixed in version 2.4.19.4 by stopping the scan at the string terminator so a value-less token is rejected. No in-product workarounds are available. As a stop-gap, an upstream reverse proxy or WAF that rejects or normalizes malformed `Cookie` headers (tokens lacking `=`) can reduce exposure, but upgrading is the recommended remediation.
🎖@cveNotify
GitHub
state: stop the state-cookie scan at the string terminator · OpenIDC/mod_auth_openidc@8017478
oidc_state_cookies_parse_token scanned a cookie token for the '=' that
separates the cookie name from its value, but the loop condition was
"cookie != NULL &&am...
separates the cookie name from its value, but the loop condition was
"cookie != NULL &&am...
🚨 CVE-2026-78676
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
🎖@cveNotify
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlines that become live git directives after any unrelated GitPython config write, enabling arbitrary code execution via hook invocation.
🎖@cveNotify
GitHub
Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser…
# [HIGH] Dormant multi-line git-config values are corrupted into live injected directives (e.g. `core.hooksPath`) on any unrelated `GitConfigParser` write, enabling RCE
- **CWE:** CWE-88 (Argume...
- **CWE:** CWE-88 (Argume...
🚨 CVE-2026-78677
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.
🎖@cveNotify
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.
🎖@cveNotify
GitHub
clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the…
# [HIGH] `Repo.clone_from()`/`Repo.clone()` omit `--separate-git-dir` from `unsafe_git_clone_options`, enabling arbitrary git-directory creation outside the clone destination
- **CWE:** CWE-73 (...
- **CWE:** CWE-73 (...
🚨 CVE-2026-12878
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
🎖@cveNotify
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
🎖@cveNotify
advisories.codefresh.io
Security Advisory 2026-01
2026-01 Authenticated user can utilize an API endpoint to elevate to Admin permissions
🚨 CVE-2026-37065
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
🎖@cveNotify
Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-37066
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
🎖@cveNotify
Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-37068
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
🎖@cveNotify
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-37069
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.
🎖@cveNotify
Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-37070
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.
🎖@cveNotify
Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-37071
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.
🎖@cveNotify
Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application configuration file and triggering a rebuild of configuration and resetting super administrator credentials to default values.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-37072
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
🎖@cveNotify
Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php.
🎖@cveNotify
Veno
Großhandel für Kurzwaren, Zubehör & modische Trends - VENO
Wir machen kreative Fachhändler besonders - mit exklusiven Marken, schneller Lieferung, Einrichtungen und persönlichem Service in allen Sortimenten.
🚨 CVE-2026-59285
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.
Spring for GraphQL 2.0.0 - 2.0.4
🎖@cveNotify
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries.
Spring for GraphQL 2.0.0 - 2.0.4
🎖@cveNotify
Spring for GraphQL Unsafe Deserialization in pagination support
Level up your Java code and explore what Spring can do for you.
🚨 CVE-2026-38345
A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
🎖@cveNotify
A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
🎖@cveNotify
FFmpeg Forgejo
[Bug Report] Division by Zero @ libswscale/utils.c:1412:60
# Summary of the bug
a division by zero vulnerability in libswscale's scaling context initialization at libswscale/utils.c:1412:60. When scaling yuv411p format to a very narrow width (8 pixels), the chroma destination width becomes 2 pixels, and the code…
a division by zero vulnerability in libswscale's scaling context initialization at libswscale/utils.c:1412:60. When scaling yuv411p format to a very narrow width (8 pixels), the chroma destination width becomes 2 pixels, and the code…
🚨 CVE-2026-51611
Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.
🎖@cveNotify
Incorrect access control in the startSlaveReboot function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to arbitrarily force a reboot via sending a crafted MQTT message.
🎖@cveNotify
GitHub
CVE-Vendor-Coordination/TOTOLINK/20260416_T6_vuln_report.pdf at main · ShengWu00/CVE-Vendor-Coordination
Contribute to ShengWu00/CVE-Vendor-Coordination development by creating an account on GitHub.
🚨 CVE-2026-82018
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.
🎖@cveNotify
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition. Attackers can exploit GRUB's fail-open signature verification behavior to drop into an interactive GRUB prompt, then boot the device's own kernel with additional command-line arguments to obtain a root shell with the disk unlocked while leaving TPM PCR values unaltered.
🎖@cveNotify
Amberwolf
Thin Client? Thin Crypto: An overview.
AmberWolf Security Research Blog
🚨 CVE-2026-82451
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
🎖@cveNotify
Formwork through 2.3.14 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the Statistics panel.
🎖@cveNotify
GitHub
GitHub - getformwork/formwork: 🏗 Formwork is a simple, fast and flexible flat-file CMS that allows you to create and manage websites…
🏗 Formwork is a simple, fast and flexible flat-file CMS that allows you to create and manage websites without the need for a database - getformwork/formwork
🚨 CVE-2026-82456
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
🎖@cveNotify
argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.
🎖@cveNotify
GitHub
GitHub - argoproj-labs/mcp-for-argocd: An implementation of Model Context Protocol (MCP) server for Argo CD.
An implementation of Model Context Protocol (MCP) server for Argo CD. - argoproj-labs/mcp-for-argocd
🚨 CVE-2026-82463
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.
🎖@cveNotify
pac4j-core before 6.5.6 contains an authentication bypass vulnerability in CheckProfileTypeAuthorizer that reverses the profile type validation logic. Attackers can authenticate through a weaker client and access resources requiring a stronger profile type by satisfying generic profile checks.
🎖@cveNotify
GitHub
GitHub - pac4j/pac4j: Security engine for Java (authentication, authorization, multi frameworks): OpenID Connect, SAML2, CAS, OAuth…
Security engine for Java (authentication, authorization, multi frameworks): OpenID Connect, SAML2, CAS, OAuth, LDAP, JWT... - pac4j/pac4j
🚨 CVE-2026-82468
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
🎖@cveNotify
Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.
🎖@cveNotify
GitHub
GitHub - jeremyevans/rodauth: Ruby's Most Advanced Authentication Framework
Ruby's Most Advanced Authentication Framework. Contribute to jeremyevans/rodauth development by creating an account on GitHub.