π¨ CVE-2026-73007
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-73015
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-77489
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
Null pointer dereference in Windows Biometric Service allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-77906
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
π@cveNotify
Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-78455
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
π@cveNotify
Out-of-bounds read in Xbox allows an unauthorized attacker to disclose information with a physical attack.
π@cveNotify
π¨ CVE-2026-80075
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
π@cveNotify
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
π@cveNotify
π¨ CVE-2026-84000
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
π@cveNotify
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-84869
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
π@cveNotify
A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
π@cveNotify
GitHub
Disclosures/CVE-2026-84869 at main Β· ConnectWise-Advisories/Disclosures
Disclosures. Contribute to ConnectWise-Advisories/Disclosures development by creating an account on GitHub.
π¨ CVE-2026-88890
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
π@cveNotify
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analytics data and profile PII via blind boolean oracle techniques.
π@cveNotify
GitHub
OpenPanel β ClickHouse SQL injection via unvalidated profile.* filter column identifier
## Summary
OpenPanel's analytics query layer builds ClickHouse `WHERE` clauses from user-supplied event filters. Filters that reference a group column, a session column, or a bare event column...
OpenPanel's analytics query layer builds ClickHouse `WHERE` clauses from user-supplied event filters. Filters that reference a group column, a session column, or a bare event column...
π¨ CVE-2026-88895
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
π@cveNotify
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.
π@cveNotify
GitHub
CyberPanel API authentication bypasses two-factor authentication
CyberPanel 3.0.4 and earlier accepted password-derived API tokens and account passwords on the standard API, cloud API router, and cloud session handoff without enforcing the account's configur...
π¨ CVE-2026-88938
knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.
π@cveNotify
knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve full file contents from outside the intended project directory.
π@cveNotify
GitHub
knowns/internal/mcp/handlers/code.go at v0.33.0 Β· knowns-dev/knowns
The memory layer for AI-native development - giving AI persistent understanding of your software projects. - knowns-dev/knowns
π¨ CVE-2026-78124
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
π@cveNotify
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
π@cveNotify
GitHub
Release strongSwan 6.1.0 Β· strongswan/strongswan
Vulnerabilities
CVE-2026-78123 - Fixed a vulnerability in the openssl plugin related to the processing of PKCS#7 containers that can result in a crash. Affects 5.0.2 and newer.
CVE-2026-78124 - Fi...
CVE-2026-78123 - Fixed a vulnerability in the openssl plugin related to the processing of PKCS#7 containers that can result in a crash. Affects 5.0.2 and newer.
CVE-2026-78124 - Fi...
π¨ CVE-2026-78131
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
π@cveNotify
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
π@cveNotify
GitHub
Release strongSwan 6.1.0 Β· strongswan/strongswan
Vulnerabilities
CVE-2026-78123 - Fixed a vulnerability in the openssl plugin related to the processing of PKCS#7 containers that can result in a crash. Affects 5.0.2 and newer.
CVE-2026-78124 - Fi...
CVE-2026-78123 - Fixed a vulnerability in the openssl plugin related to the processing of PKCS#7 containers that can result in a crash. Affects 5.0.2 and newer.
CVE-2026-78124 - Fi...
π¨ CVE-2026-89151
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
π@cveNotify
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
π@cveNotify
Codeberg.org
forgejo
Beyond coding. We forge.
π¨ CVE-2026-89060
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed clusterβs ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
π@cveNotify
A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed clusterβs ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
π@cveNotify
Redhat
CVE-2026-89060 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-89241
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that execute in the victim's browser within the site origin.
π@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute and inject event handlers that execute in the victim's browser within the site origin.
π@cveNotify
GitHub
Reflected XSS: `plugin/Live/confirmLivePassword.php` copies `$_SERVER['REQUEST_URI']` into a form `action` without encoding
## Summary
`plugin/Live/confirmLivePassword.php` writes `$_SERVER['REQUEST_URI']` into a double-quoted form `action`. Apache leaves a literal `"` in the request-target, so a query par...
`plugin/Live/confirmLivePassword.php` writes `$_SERVER['REQUEST_URI']` into a double-quoted form `action`. Apache leaves a literal `"` in the request-target, so a query par...
π¨ CVE-2026-89256
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the payload in the AVideo origin.
π@cveNotify
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every visitor of that video executes the payload in the AVideo origin.
π@cveNotify
GitHub
Stored XSS: Bookmark chapter names are concatenated into public watch-page HTML
## Summary
`plugin/Bookmark/page/bookmarkSave.json.php:21` calls `BookmarkTable::setName($_REQUEST['name'])`. `setName()` (`plugin/Bookmark/Objects/BookmarkTable.php:35-37`) assigns the st...
`plugin/Bookmark/page/bookmarkSave.json.php:21` calls `BookmarkTable::setName($_REQUEST['name'])`. `setName()` (`plugin/Bookmark/Objects/BookmarkTable.php:35-37`) assigns the st...
π¨ CVE-2026-85083
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
π@cveNotify
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise.
π@cveNotify
π¨ CVE-2026-3869
CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.
π@cveNotify
CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.
π@cveNotify
π¨ CVE-2026-81861
CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.
π@cveNotify
CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.
π@cveNotify
π¨ CVE-2026-89012
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
π@cveNotify
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can exploit the case-insensitive database column resolution against the case-sensitive denylist check in the core library to use prefix-matching predicates as a boolean oracle and extract full password hashes for any user account, including administrators.
π@cveNotify
GitHub
Fix control of operand name must be non case sensitive. Β· Dolibarr/dolibarr@7a04d9c
Dolibarr ERP CRM is a modern software package to manage your company or foundation's activity (contacts, suppliers, invoices, orders, stocks, agenda, accounting, ...). it's an open source Web application (written in PHP) designed for businesses of any sizesβ¦