🚨 CVE-2026-83527
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
🎖@cveNotify
An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.
🎖@cveNotify
🚨 CVE-2026-84282
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.
🎖@cveNotify
A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses.
🎖@cveNotify
GitHub
onlyoffice-owncloud/controller/settingsapicontroller.php at master · ONLYOFFICE/onlyoffice-owncloud
The app which enables the users to edit office documents from ownCloud using ONLYOFFICE Document Server, allows multiple users to collaborate in real time and to save back those changes to ownCloud...
🚨 CVE-2026-86665
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
GitHub
GitHub - aircheng-org/iWebShop-5: iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它…
iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它可以承载大数据量且性能优良,代码支持二次开发是电商建站首选。 - aircheng-org/iWebShop-5
🚨 CVE-2026-16025
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
🎖@cveNotify
Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation.
This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-16769
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
🎖@cveNotify
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
🎖@cveNotify
🚨 CVE-2026-56101
OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed TKIP frames separated by more than 60 seconds. Attackers can exploit the reversed TKIP MIC failure countermeasure window check to deauthenticate all associated TKIP stations and block reassociation for up to 90 seconds, while within-window MIC failures that should engage countermeasures are silently discarded, leaving key-recovery attempts undetected.
🎖@cveNotify
OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed TKIP frames separated by more than 60 seconds. Attackers can exploit the reversed TKIP MIC failure countermeasure window check to deauthenticate all associated TKIP stations and block reassociation for up to 90 seconds, while within-window MIC failures that should engage countermeasures are silently discarded, leaving key-recovery attempts undetected.
🎖@cveNotify
GitHub
Fix an inversed if-condition in ieee80211_michael_mic_failure() · openbsd/src@1ee99df
Make the check for 60 seconds since the most recent previous MIC failure
work as intended. The code was enabling TKIP countermeasures if 60 seconds
have passed since the previous MIC failure. The i...
work as intended. The code was enabling TKIP countermeasures if 60 seconds
have passed since the previous MIC failure. The i...
🚨 CVE-2026-79572
An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload.
🎖@cveNotify
An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload.
🎖@cveNotify
GitHub
CVE/Distribution Management/XXE.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-79573
L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
🎖@cveNotify
L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
🎖@cveNotify
GitHub
CVE/L-ONE/JFinalOA SQL注入漏洞.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-79574
An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.
🎖@cveNotify
An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.
🎖@cveNotify
GitHub
CVE/mpush/rce.md at main · fangtang7/CVE
CVE. Contribute to fangtang7/CVE development by creating an account on GitHub.
🚨 CVE-2026-86600
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.
🎖@cveNotify
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.
🎖@cveNotify
🚨 CVE-2026-86666
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
🎖@cveNotify
GitHub
GitHub - aircheng-org/iWebShop-5: iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它…
iWebShop是一款基于PHP语言及MYSQL数据库开发的B2B2C多用户商城系统,支持自营和多商家入驻、集成微信商城、手机商城、移动端APP商城、三级分销、电商直播、微信小程序,它可以承载大数据量且性能优良,代码支持二次开发是电商建站首选。 - aircheng-org/iWebShop-5
🚨 CVE-2026-86718
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.
🎖@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or mark streams as finished when an admin visits the attacker-controlled site.
🎖@cveNotify
GitHub
GET-reachable CSRF on Live deleteHistory.json.php and finishAll.json.php wipes or finishes all live history
## Summary
`plugin/Live/view/deleteHistory.json.php` and `plugin/Live/view/finishAll.json.php` mutate global live state on GET. The only check is `User::isAdmin()`. There is no CSRF token and no P...
`plugin/Live/view/deleteHistory.json.php` and `plugin/Live/view/finishAll.json.php` mutate global live state on GET. The only check is `User::isAdmin()`. There is no CSRF token and no P...
🚨 CVE-2026-86719
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and invokes User::swapUser() without calling forbidIfNotPost() or forbidIfInvalidToken(), and the global autoCSRFGuard() check only runs for POST requests to *.json.php, so the action is reachable via GET. An attacker who causes an authenticated administrator's browser to issue a cross-origin GET (for example via an <img> tag or link) can replace that administrator's session with a non-admin user account, causing the administrator to lose administrative access until the swap is cancelled; swapping to another administrator account is rejected, so this is not privilege escalation. The JSON response also discloses the session_id. The CustomizeUser plugin is enabled by default, and no patch was available at the time of publication.
🎖@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and invokes User::swapUser() without calling forbidIfNotPost() or forbidIfInvalidToken(), and the global autoCSRFGuard() check only runs for POST requests to *.json.php, so the action is reachable via GET. An attacker who causes an authenticated administrator's browser to issue a cross-origin GET (for example via an <img> tag or link) can replace that administrator's session with a non-admin user account, causing the administrator to lose administrative access until the swap is cancelled; swapping to another administrator account is rejected, so this is not privilege escalation. The JSON response also discloses the session_id. The CustomizeUser plugin is enabled by default, and no patch was available at the time of publication.
🎖@cveNotify
GitHub
GET-reachable CSRF on CustomizeUser swapUser.json.php hijacks an admin session into a target account
## Summary
`plugin/CustomizeUser/swapUser.json.php` reads `$_REQUEST['users_id']` and calls `User::swapUser()` with no `forbidIfNotPost()` and no `forbidIfInvalidToken()`. A GET from anoth...
`plugin/CustomizeUser/swapUser.json.php` reads `$_REQUEST['users_id']` and calls `User::swapUser()` with no `forbidIfNotPost()` and no `forbidIfInvalidToken()`. A GET from anoth...
🚨 CVE-2026-86720
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, or Twitch streams using victim stream keys.
🎖@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream to victim-configured restream destinations by supplying arbitrary live_restreams_id values, hijacking YouTube, Facebook, or Twitch streams using victim stream keys.
🎖@cveNotify
GitHub
Missing authorization: Live resendRestreamer.json.php uses another user's live_restreams_id / stream key
## Summary
`plugin/Live/view/Live_restreams/resendRestreamer.json.php` checks ownership of `live_transmitions_history_id` and does not check ownership of `live_restreams_id`. A user with `canStrea...
`plugin/Live/view/Live_restreams/resendRestreamer.json.php` checks ownership of `live_transmitions_history_id` and does not check ownership of `live_restreams_id`. A user with `canStrea...
🚨 CVE-2026-86721
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
🎖@cveNotify
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
🎖@cveNotify
GitHub
Authorization bypass: session cookie named `key` overrides `$_REQUEST['key']` in `saveLive.php`, setting all live stream keys to…
## Summary
`session_start_preload` in `objects/functionsPHP.php:592` sets a cookie named `key` with the literal value `value` for every session. PHP's `variables_order=EGPCS` makes `$_COOKIE` ...
`session_start_preload` in `objects/functionsPHP.php:592` sets a cookie named `key` with the literal value `value` for every session. PHP's `variables_order=EGPCS` makes `$_COOKIE` ...
🚨 CVE-2026-86722
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.
🎖@cveNotify
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because the confirmation code hash fails to generate from the stale cached empty result.
🎖@cveNotify
GitHub
Improper authentication: `sqlDAL::readSql` caches an empty result set that `writeSql` never invalidates, so LoginControl email…
## Summary
`sqlDAL::readSql` stores every result set it produces, including an empty one, in the request-scoped `$readSqlCached` keyed by the statement and its bound values (`objects/mysql_dal.php...
`sqlDAL::readSql` stores every result set it produces, including an empty one, in the request-scoped `$readSqlCached` keyed by the statement and its bound values (`objects/mysql_dal.php...
🚨 CVE-2026-86723
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
🎖@cveNotify
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
🎖@cveNotify
GitHub
Improper authentication: `LoginControl::verifyChallenge()` compares with `==`, so an omitted `response` against an unset session…
## Summary
`LoginControl::verifyChallenge($response)` tests `$response == $_SESSION['user']['challenge']['text']` (`plugin/LoginControl/LoginControl.php:534`). When the ses...
`LoginControl::verifyChallenge($response)` tests `$response == $_SESSION['user']['challenge']['text']` (`plugin/LoginControl/LoginControl.php:534`). When the ses...
🚨 CVE-2026-86724
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session cookies without token validation. Attackers can craft a malicious webpage that, when loaded by an administrator, submits a POST request to modify any user's wallet balance to any value.
🎖@cveNotify
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session cookies without token validation. Attackers can craft a malicious webpage that, when loaded by an administrator, submits a POST request to modify any user's wallet balance to any value.
🎖@cveNotify
GitHub
CSRF: `plugin/YPTWallet/view/saveBalance.php` sets any user's wallet balance with no authenticity check, and does not match the…
## Summary
`plugin/YPTWallet/view/saveBalance.php` writes an arbitrary wallet balance for an arbitrary `users_id` on the strength of the ambient session cookie. The only guard in the file is `User...
`plugin/YPTWallet/view/saveBalance.php` writes an arbitrary wallet balance for an arbitrary `users_id` on the strength of the ambient session cookie. The only guard in the file is `User...
🚨 CVE-2026-86725
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then delete the compromised record to destroy the victim's provider linkage.
🎖@cveNotify
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to overwrite another user's stored access_token and refresh_token, then delete the compromised record to destroy the victim's provider linkage.
🎖@cveNotify
GitHub
Missing authorization: SocialMediaPublisher `Publisher_user_preferences/add.json.php` loads any row by `id` and reassigns it to…
## Summary
`plugin/SocialMediaPublisher/View/Publisher_user_preferences/add.json.php` builds its row from an attacker-supplied primary key, `new Publisher_user_preferences(@$_POST['id'])`,...
`plugin/SocialMediaPublisher/View/Publisher_user_preferences/add.json.php` builds its row from an attacker-supplied primary key, `new Publisher_user_preferences(@$_POST['id'])`,...
🚨 CVE-2026-86726
AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.
🎖@cveNotify
AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership, exposing sensitive transmission credentials and streamer identity across all accounts to any user with streaming capability.
🎖@cveNotify
GitHub
Cross-user active-restream source stream-key and identity disclosure in restreamsActive.json.php
## Summary
`plugin/Live/view/restreamsActive.json.php` is gated on a capability (`canStream()||isAdmin()`), not ownership, and returns every active ffmpeg restream's source stream `key` plus st...
`plugin/Live/view/restreamsActive.json.php` is gated on a capability (`canStream()||isAdmin()`), not ownership, and returns every active ffmpeg restream's source stream `key` plus st...
🚨 CVE-2026-86727
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.
🎖@cveNotify
AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and group-restricted live streams by parsing the hidden_applications array in the JSON response to obtain sensitive streaming credentials.
🎖@cveNotify
GitHub
Unauthenticated private/unlisted live-stream key and m3u8 disclosure in plugin/Live/stats.json.php
## Summary
`plugin/Live/stats.json.php` is unauthenticated (gated only on the Live plugin being enabled) and echoes a stats structure whose `hidden_applications[]` bucket retains the raw stream `ke...
`plugin/Live/stats.json.php` is unauthenticated (gated only on the Live plugin being enabled) and echoes a stats structure whose `hidden_applications[]` bucket retains the raw stream `ke...