🚨 CVE-2025-70082
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
🎖@cveNotify
The administrator password can be changed without knowledge of the current password. When chained with an authentication bypass vulnerability, this issue may allow unauthenticated attackers to modify the administrator password.
🎖@cveNotify
GitHub
CSAF/csaf_files/OT/white/2026/icsa-26-069-02.json at develop · cisagov/CSAF
CISA CSAF Security Advisories. Contribute to cisagov/CSAF development by creating an account on GitHub.
🚨 CVE-2026-19795
Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.
🎖@cveNotify
Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segmentation fault, causing the application to crash when deserializing untrusted input.
🎖@cveNotify
Ibm
Security Bulletin: Qiskit SDK is vulnerable when deserializing QPY Files and may overflow the available stack space.
A maliciously constructed QPY payload that contains specifically constructed ParameterExpression objects as part of the payload can trigger a segfault in the evaluation of those expressions during deserialization. The function qiskit.qpy.load() may recurse…
🚨 CVE-2022-26961
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
🎖@cveNotify
Italtel NetMatch-S 5.0.0-20200703 allows Multiple Stored XSS under NP_IBCF-NATUP-01/NMSCI-WebGui/backup_restore.jsp and NP_IBCF-MIBER-03/NMSCI-WebGui/storage.jsp via the name parameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
🎖@cveNotify
www.gruppotim.it
CVE-2022-26961 – Italtel NETMATCH-S CLOUD INSIDE VNF - NFV
🚨 CVE-2025-67066
SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path
🎖@cveNotify
SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path
🎖@cveNotify
GitHub
OASYS-SQL-injection/vulnerability/OASYS SQL Injection Vulnerability.md at main · lanpan001/OASYS-SQL-injection
OASYS SQL injection. Contribute to lanpan001/OASYS-SQL-injection development by creating an account on GitHub.
🚨 CVE-2026-50894
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
🎖@cveNotify
easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.
🎖@cveNotify
GitHub
EasyAdmin v2.0.2.2 - Unrestricted File Upload Leading to Arbitrary PHP Code Execution · Issue #1 · lilil3333/cve
Proof of Concept 1. Identify the Affected Asset Locate an EasyAdmin instance running the affected version. Example: https://129.226.119.47/aadmin The /admin interface can be used to identify the Ea...
🚨 CVE-2026-53769
Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.
🎖@cveNotify
Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload policy methods such as upload_{FIELD_ID}?. An authenticated Avo user who can reach the Avo attachment upload endpoint can replace or add attachment content, including binary content, filename, and content-type metadata, on a resolved record even when both update? and upload_<field>? policies deny the operation. This primarily affects multi-role Avo Pro/Advanced-style deployments where non-administrator or restricted operator users can reach Avo and per-record or per-field operations are expected to be enforced by policies. This issue has been patched in version 3.32.0.
🎖@cveNotify
GitHub
fix: attachment upload authorization in attachments controller (#4520) · avo-hq/avo@de12070
* Enhance attachment upload authorization in attachments controller
* run request specs
* run request specs
🚨 CVE-2026-75438
Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function
🎖@cveNotify
Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function
🎖@cveNotify
Gist
CVE-2026-75438
CVE-2026-75438. GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2026-75439
An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
🎖@cveNotify
An issue in Free5GC v.4.2.2 allows a remote attacker to cause a denial of service via the UPF component
🎖@cveNotify
Gist
CVE-2026-75439
CVE-2026-75439. GitHub Gist: instantly share code, notes, and snippets.
🚨 CVE-2026-77847
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
🎖@cveNotify
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.
🎖@cveNotify
🚨 CVE-2026-79423
An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.
🎖@cveNotify
An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.
🎖@cveNotify
GitHub
returnwrong-security-advisories/CVE-2026-79423.md at main · returnwrong/returnwrong-security-advisories
Public security advisories and CVE disclosures researched and reported by returnwrong. - returnwrong/returnwrong-security-advisories
🚨 CVE-2026-79426
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.
🎖@cveNotify
An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.
🎖@cveNotify
GitHub
GitHub - crmeb/CRMEB: 🔥CRMEB开源商城免费开源多语言商城系统,Tp6框架商城,系统可商用;包含小程序商城、H5商城、公众号商城、PC商城、App,支持分销、拼团、砍价、秒杀、优惠券、积分、会员等级、小程序直播、页面DIY,前后…
🔥CRMEB开源商城免费开源多语言商城系统,Tp6框架商城,系统可商用;包含小程序商城、H5商城、公众号商城、PC商城、App,支持分销、拼团、砍价、秒杀、优惠券、积分、会员等级、小程序直播、页面DIY,前后端分离,方便二开,更有详细使用文档、接口文档、数据字典、二开文档/视频教程,欢迎大家提出宝贵意见和建议 - crmeb/CRMEB
🚨 CVE-2026-82712
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
🎖@cveNotify
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.
🎖@cveNotify
🚨 CVE-2026-85701
A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.
🎖@cveNotify
A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. This vulnerability only affects products that are no longer supported by the maintainer.
🎖@cveNotify
Gist
Advisory: CWE-306 Auth Bypass (CRITICAL) - ramon-victor/freegpt-webui Finding 1
Advisory: CWE-306 Auth Bypass (CRITICAL) - ramon-victor/freegpt-webui Finding 1 - freegpt_finding1.md
🚨 CVE-2026-85702
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer.
🎖@cveNotify
A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads to missing authentication. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases. This vulnerability only affects products that are no longer supported by the maintainer.
🎖@cveNotify
Gist
Advisory: CWE-306 Unauth API (HIGH) - ramon-victor/freegpt-webui Finding 2
Advisory: CWE-306 Unauth API (HIGH) - ramon-victor/freegpt-webui Finding 2 - freegpt_finding2.md
🚨 CVE-2026-85704
A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This vulnerability only affects products that are no longer supported by the maintainer.
🎖@cveNotify
A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible to launch the attack remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit has been released to the public and may be used for attacks. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. This vulnerability only affects products that are no longer supported by the maintainer.
🎖@cveNotify
Gist
Advisory: CWE-362 Race Condition (HIGH) - ramon-victor/freegpt-webui Finding 4
Advisory: CWE-362 Race Condition (HIGH) - ramon-victor/freegpt-webui Finding 4 - freegpt_finding4.md
🚨 CVE-2026-85787
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.
To remediate this issue, users should upgrade to version 1.1.7 or above.
🎖@cveNotify
An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an authenticated user interacts with the MCP server.
To remediate this issue, users should upgrade to version 1.1.7 or above.
🎖@cveNotify
🚨 CVE-2026-55985
The web management interface in Tycon Systems TPDIN-Monitor-WEB2
stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
🎖@cveNotify
The web management interface in Tycon Systems TPDIN-Monitor-WEB2
stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these credentials, which may be used to compromise other systems on the local network.
🎖@cveNotify
GitHub
CSAF/csaf_files/OT/white/2026/icsa-26-202-01.json at develop · cisagov/CSAF
CISA CSAF Security Advisories. Contribute to cisagov/CSAF development by creating an account on GitHub.
🚨 CVE-2026-61884
The Tycon Systems TPDIN-Monitor-WEB2
ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
🎖@cveNotify
The Tycon Systems TPDIN-Monitor-WEB2
ships without HTTP credentials configured, intended for an installer to set them on first use. On firmware 2.4.4 and earlier, a unit left in this unconfigured state serves the web management interface without requiring any login. An attacker with network access to such a unit can reach full device controls, including power relay management, device reboot, remote access service configuration, and network settings, which could allow disruption of connected infrastructure or physical damage to equipment.
🎖@cveNotify
GitHub
CSAF/csaf_files/OT/white/2026/icsa-26-202-01.json at develop · cisagov/CSAF
CISA CSAF Security Advisories. Contribute to cisagov/CSAF development by creating an account on GitHub.
🚨 CVE-2026-69249
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.
🎖@cveNotify
python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In versions 42.0.0 through 48.0.0, when resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack. The core issue arises in the recursive nature of build_chain_inner, which does not de-duplicate against previously analyzed candidates. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability. This issue is fixed in 49.0.0.
🎖@cveNotify
GitHub
add initial X.509 path validation implementation (#8873) · pyca/cryptography@3763aa7
cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. - add initial X.509 path validation implementation (#8873) · pyca/cryptography@3763aa7
🚨 CVE-2026-78012
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
🎖@cveNotify
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
🎖@cveNotify
🚨 CVE-2026-46636
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.
🎖@cveNotify
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0.
🎖@cveNotify
GitHub
Release v3.27.0 · twigphp/Twig
Changelog (v3.26.0...v3.27.0)
security #558 Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders (@fabpot)
security #cve-2026-48805 Fix sandbox bypass in de...
security #558 Fix sandbox filter/tag/function allow-list bypass when sandbox state changes between renders (@fabpot)
security #cve-2026-48805 Fix sandbox bypass in de...