π¨ CVE-2026-83970
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83971
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83972
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83974
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83975
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83976
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83977
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83978
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83979
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83980
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83981
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83982
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83985
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-83987
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-79721
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
π@cveNotify
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
π@cveNotify
π¨ CVE-2026-85384
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
π@cveNotify
A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file. An authenticated attacker on the local network can upload a crafted configuration file to trigger the overflow, leading to remote code execution.
Successful exploitation may allow unauthorized access to sensitive information, modification of device configuration and network behavior, or disruption of device availability.
π@cveNotify
Tp-Link
TP-Link End of Life Products
This end-of-life page will be the new home of TP-Linkβs end-of-life product list. Please see the End-of-Life Policy for more details. Please contact us to further assist with replacement parts for products and services.
π¨ CVE-2026-19872
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message.
The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error.
A field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected.
A request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.
π@cveNotify
HTML::FormHandler versions before 0.410000 for Perl allow cross-site scripting via a submitted value rendered unescaped in an error message.
The wrappers and renderers that emit a form's errors interpolate the error string straight into HTML with no escaping. Two of the library's own messages, no_match and not_allowed, splice the submitted value into that string, and a failing type constraint puts the rejected value into the message it builds, which _apply_actions hands to add_error.
A field declared with a check regexp, a check list or a type constraint reaches those messages, with no custom validator and no non-default configuration. Errors rendered through an application's own escaping template layer rather than the library's rendering roles are not affected.
A request over the network that submits markup to such a field gets it back live inside the error span, running script in the victim's origin. Re-rendering a rejected value later gives the stored variant.
π@cveNotify
π¨ CVE-2026-84197
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.
π@cveNotify
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the underlying ws WebSocket. Certificate chain and hostname validation are therefore disabled for every wss:// connection, and no builder option, constructor argument or environment variable lets an application turn validation back on. An attacker in a position to intercept the connection can present an arbitrary certificate, complete the TLS handshake, read the credentials that the configured authentication provider sends in the Authorization header of the WebSocket upgrade request, and read, alter or inject Ditto Protocol messages for the lifetime of the connection. The Java client, the browser/DOM JavaScript client and the HTTP transport of the Node.js client are not affected.
π@cveNotify
GitLab
[Eclipse Ditto] TLS certificate validation disabled for all Node.js WebSocket connections (#660) Β· Issues Β· Eclipse Projects Securityβ¦
AI-Generated Vulnerability Report This report was produced using AI-assisted security analysis and has not been manually verified. It may contain false positives, inaccurate severity...
π¨ CVE-2026-84869
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
π@cveNotify
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
π@cveNotify
GitHub
Disclosures/CVE-2026-84869 at main Β· ConnectWise-Advisories/Disclosures
Disclosures. Contribute to ConnectWise-Advisories/Disclosures development by creating an account on GitHub.
π¨ CVE-2026-84942
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
π@cveNotify
Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega visualization. The checkForFunctionProperty validation routine failed to recurse into arrays of objects, allowing a function property nested inside an array to bypass validation.
π@cveNotify
π¨ CVE-2026-85484
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping.
The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also renders each radio button's own label unescaped.
Any application whose option list is built from data rather than literals, using options_from, an options_fieldname method, or the DBIC model, allows attacker-influenced text in a label that can override the options or embed JavaScript in rendered pages.
π@cveNotify
HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping.
The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other three into element content. RadioGroup also renders each radio button's own label unescaped.
Any application whose option list is built from data rather than literals, using options_from, an options_fieldname method, or the DBIC model, allows attacker-influenced text in a label that can override the options or embed JavaScript in rendered pages.
π@cveNotify