🚨 CVE-2026-84185
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
🎖@cveNotify
A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to correctly identify the specific key ID (kid) and may instead accept a signature made by any valid key in the set. This can allow an attacker with a valid key to bypass authorization checks in applications that rely on the key ID to identify specific tenants or users.
🎖@cveNotify
Redhat
CVE-2026-84185 - Red Hat Customer Portal
CVE Details App
🚨 CVE-2026-64195
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
measX - Measurement System Experts
Out-of-Bounds Write Vulnerabilities in DASYLab
measX ist seit über 40 Jahren Spezialist für Mess-, Prüf- und Auswerteaufgaben und bietet individuelle Systeme, Software und Dienstleistungen für Forschung, Entwicklung, Qualitätssicherung und Produktion – für nachhaltige Wettbewerbsvorteile.
🚨 CVE-2026-64196
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
measX - Measurement System Experts
Out-of-Bounds Write Vulnerabilities in DASYLab
measX ist seit über 40 Jahren Spezialist für Mess-, Prüf- und Auswerteaufgaben und bietet individuelle Systeme, Software und Dienstleistungen für Forschung, Entwicklung, Qualitätssicherung und Produktion – für nachhaltige Wettbewerbsvorteile.
🚨 CVE-2026-64197
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
measX - Measurement System Experts
Out-of-Bounds Write Vulnerabilities in DASYLab
measX ist seit über 40 Jahren Spezialist für Mess-, Prüf- und Auswerteaufgaben und bietet individuelle Systeme, Software und Dienstleistungen für Forschung, Entwicklung, Qualitätssicherung und Produktion – für nachhaltige Wettbewerbsvorteile.
🚨 CVE-2026-64198
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
measX - Measurement System Experts
Out-of-Bounds Read Vulnerabilities in DASYLab
measX ist seit über 40 Jahren Spezialist für Mess-, Prüf- und Auswerteaufgaben und bietet individuelle Systeme, Software und Dienstleistungen für Forschung, Entwicklung, Qualitätssicherung und Produktion – für nachhaltige Wettbewerbsvorteile.
🚨 CVE-2026-64199
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
measX - Measurement System Experts
Out-of-Bounds Read Vulnerabilities in DASYLab
measX ist seit über 40 Jahren Spezialist für Mess-, Prüf- und Auswerteaufgaben und bietet individuelle Systeme, Software und Dienstleistungen für Forschung, Entwicklung, Qualitätssicherung und Produktion – für nachhaltige Wettbewerbsvorteile.
🚨 CVE-2026-64200
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
🎖@cveNotify
measX - Measurement System Experts
Out-of-Bounds Read Vulnerabilities in DASYLab
measX ist seit über 40 Jahren Spezialist für Mess-, Prüf- und Auswerteaufgaben und bietet individuelle Systeme, Software und Dienstleistungen für Forschung, Entwicklung, Qualitätssicherung und Produktion – für nachhaltige Wettbewerbsvorteile.
🚨 CVE-2026-18167
A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.
Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.
🎖@cveNotify
A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.
Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device.
🎖@cveNotify
🚨 CVE-2026-18330
A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality.
🎖@cveNotify
A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality.
🎖@cveNotify
🚨 CVE-2026-49509
Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers.
This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.
🎖@cveNotify
Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers.
This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.
🎖@cveNotify
GitHub
stb_image: don't deal with fractional ratios by mmaciola · Pull Request #604 · Samsung/rlottie
Apply fix from stb 2.27
🚨 CVE-2026-85146
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
🎖@cveNotify
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.
🎖@cveNotify
🚨 CVE-2026-85147
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
🎖@cveNotify
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.
🎖@cveNotify
🚨 CVE-2026-85148
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
🎖@cveNotify
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
🎖@cveNotify
🚨 CVE-2026-85149
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
🎖@cveNotify
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials of the SmartIT Agent application from the source code, thereby browsing the file system of the user's host.
🎖@cveNotify
🚨 CVE-2025-15691
The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled.
This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
🎖@cveNotify
The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user accounts even when registration is disabled.
This is an incomplete fix for CVE-2025-12353: the check added in 3.6.3 covers only one of the three registration paths.
🎖@cveNotify
WPScan
WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms
See details on WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms CVE 2025-15691. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-16281
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
🎖@cveNotify
The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments from, and attach files to, any listing owned by another user.
🎖@cveNotify
WPScan
Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR
See details on Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image Tampering via IDOR CVE 2026-16281. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-17517
The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled posts, when a view has been configured to include them.
🎖@cveNotify
The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled posts, when a view has been configured to include them.
🎖@cveNotify
WPScan
Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status Filter
See details on Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Status Filter CVE 2026-17517. View the latest Plugin Vulnerabilities on WPScan.
🚨 CVE-2026-62928
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🎖@cveNotify
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-66840
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
🎖@cveNotify
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-69657
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。
🚨 CVE-2026-70403
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.
🎖@cveNotify
JOYSOUND.Biz | 業務用カラオケ機器(導入・レンタル)
通信アダプタ CPTrans-ME-X | 業務用カラオケ機器(導入・レンタル)| JOYSOUND.Biz
JOYSOUND 通信アダプタの製品ページです。カラオケ導入ご検討の方は是非ご覧下さい。