π¨ CVE-2026-71227
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
π@cveNotify
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
π@cveNotify
π¨ CVE-2026-82762
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
π@cveNotify
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
π@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
π¨ CVE-2026-82763
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
π@cveNotify
Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.
π@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
π¨ CVE-2026-82764
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
π@cveNotify
Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.
π@cveNotify
jvn.jp
JVNVU#90314828: Multiple vulnerabilities in Contec PC-HELPER series
Japan Vulnerability Notes
π¨ CVE-2026-82765
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
π@cveNotify
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
π@cveNotify
jvn.jp
JVNVU#99009004: Multiple vulnerabilities in Contec FLEXLAN series
Japan Vulnerability Notes
π¨ CVE-2026-68570
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.
This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
π@cveNotify
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information.
This issue affects Apache Doris: from 2.0.0 through 2.1.*, from 3.0.0 through 3.0.*, from 4.0.0 before 4.0.8, and from 4.1.0 before 4.1.4.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
π@cveNotify
π¨ CVE-2026-72524
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to.
This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
π@cveNotify
Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to.
This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 through 4.0.7, and from 4.1.0 through 4.1.3.
Users are recommended to upgrade to a fixed release (4.0.8 or 4.1.4), which fixes the issue.
π@cveNotify
π¨ CVE-2026-90701
A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet.
π@cveNotify
GitHub
GitHub - subhajitkhan/online-clinic-management-system: Aim of this project is to develop a dynamic web based application usingβ¦
Aim of this project is to develop a dynamic web based application using PHP, HTML, CSS,Bootstrap, JavaScript,Jquery, and MySQL to provide appointment to the patients according to doctorsβ availabil...
π¨ CVE-2026-90702
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
π@cveNotify
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
π@cveNotify
Gist
D-Link DWR-M921 V1.1.52 - Command Injection in /boafrm/formDiskFormat
D-Link DWR-M921 V1.1.52 - Command Injection in /boafrm/formDiskFormat - DWR-M921_Vuln1.md
π¨ CVE-2026-90703
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
π@cveNotify
Gist
D-Link DWR-M921 V1.1.52 - Command Injection in /boafrm/formDiskCreateShare
D-Link DWR-M921 V1.1.52 - Command Injection in /boafrm/formDiskCreateShare - DWR-M921_Vuln4.md
π¨ CVE-2026-90704
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
π@cveNotify
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
π@cveNotify
Gist
D-Link DWR-M921 V1.1.52 - Command Injection in /boafrm/formDiskPartition
D-Link DWR-M921 V1.1.52 - Command Injection in /boafrm/formDiskPartition - DWR-M921_Vuln5.md
π¨ CVE-2026-90893
MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which disabled all CSRF validation (both token and field-hash checks) for those endpoints. Because these endpoints accept POST requests and modify per-user application state (theme selection, default homepage URL, and event index column visibility), an attacker who can induce a logged-in MISP user to load a malicious page (e.g., via a crafted link, embedded image, or auto-submitting form) can forge requests that alter the victim's settings without their knowledge or consent. The most impactful action is setHomePage, which allows an attacker to redirect the victim's default landing page to an arbitrary attacker-controlled URL, potentially facilitating phishing or further social engineering. The setTheme action can alter the user's visual theme, and eventIndexColumnToggle can change which columns are displayed in the event index view. No authentication bypass is involved; the victim must already be authenticated to MISP. The vulnerability was reported by the Scottish Government National Cyber Team.
Version affected: β€2.5.45
π@cveNotify
MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which disabled all CSRF validation (both token and field-hash checks) for those endpoints. Because these endpoints accept POST requests and modify per-user application state (theme selection, default homepage URL, and event index column visibility), an attacker who can induce a logged-in MISP user to load a malicious page (e.g., via a crafted link, embedded image, or auto-submitting form) can forge requests that alter the victim's settings without their knowledge or consent. The most impactful action is setHomePage, which allows an attacker to redirect the victim's default landing page to an arbitrary attacker-controlled URL, potentially facilitating phishing or further social engineering. The setTheme action can alter the user's visual theme, and eventIndexColumnToggle can change which columns are displayed in the event index view. No authentication bypass is involved; the victim must already be authenticated to MISP. The vulnerability was reported by the Scottish Government National Cyber Team.
Version affected: β€2.5.45
π@cveNotify
GitHub
fix: [security] Put the user-settings endpoints back under CSRF valid⦠· MISP/MISP@979337b
β¦ation
- setTheme, setHomePage and eventIndexColumnToggle were unlocked from CSRF validation
- as reported by Scottish Government - National Cyber Team
Co-Authored-By: Claude Opus 5 (1M context)...
- setTheme, setHomePage and eventIndexColumnToggle were unlocked from CSRF validation
- as reported by Scottish Government - National Cyber Team
Co-Authored-By: Claude Opus 5 (1M context)...
π¨ CVE-2026-90894
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group.
After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.
π@cveNotify
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group.
After login, PrlSrv_InstallAppliance lets you pick the appliance folder (sVmParentPath). The daemon unpacks with one string, tar -xf "%1" -C "%2", then Qt QProcess::splitCommand chops that string into words. A quote in the folder name closes early. The leftover text becomes extra tar flags. macOS tar --use-compress-program= runs the named program as root.
π@cveNotify
Parallels Desktop for Mac 27.0.2Β (58673) update addresses the overall stability and security issues.
Β
Β
KB Parallels: Parallels Desktop 27 updates summary
Parallels Desktop for Mac 27.0.2 (58673) update addresses the overall stability and security issues.
π¨ CVE-2026-90895
Affected versions of MISPβs interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies.
The patch shows that CLI access could differ from the web application in multiple security-sensitive areas:
β- feed listings did not enforce the same lookup_visible restrictions for non-host-organisation users;
β- feed detail access did not enforce the same host-organisation/site-admin authorization as FeedsController::view();
β- Feed.headers, which can contain HTTP authorization credentials, could be exposed instead of being hidden or masked;
β- server synchronization authkey values were not explicitly hidden from CLI detail output;
β- sharing-group detail access did not consistently use SharingGroup::checkIfAuthorised();
β- the use command could establish context for a record without first proving that the user was authorized to view that record
The commit additionally hardens pagination and terminal rendering, including neutralization of terminal control sequences found in database-backed values. Those are important hardening changes, but the main vulnerability is the CLI authorization/data-disclosure mismatch.
Version affected: β€2.5.45
π@cveNotify
Affected versions of MISPβs interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies.
The patch shows that CLI access could differ from the web application in multiple security-sensitive areas:
β- feed listings did not enforce the same lookup_visible restrictions for non-host-organisation users;
β- feed detail access did not enforce the same host-organisation/site-admin authorization as FeedsController::view();
β- Feed.headers, which can contain HTTP authorization credentials, could be exposed instead of being hidden or masked;
β- server synchronization authkey values were not explicitly hidden from CLI detail output;
β- sharing-group detail access did not consistently use SharingGroup::checkIfAuthorised();
β- the use command could establish context for a record without first proving that the user was authorized to view that record
The commit additionally hardens pagination and terminal rendering, including neutralization of terminal control sequences found in database-backed values. Those are important hardening changes, but the main vulnerability is the CLI authorization/data-disclosure mismatch.
Version affected: β€2.5.45
π@cveNotify
GitHub
fix: [cli] Route interactive CLI shell authorization through the mode⦠· MISP/MISP@cd9f548
β¦l accessors
- hand-rolled shell ACL replaced by the model accessors; credential columns, pagination and terminal control bytes handled as the web does
- as reported by Scottish Government - Nati...
- hand-rolled shell ACL replaced by the model accessors; credential columns, pagination and terminal control bytes handled as the web does
- as reported by Scottish Government - Nati...
π¨ CVE-2025-53341
Missing Authorization vulnerability in Pixel Makers Creative INC. App, SaaS & Software Startup Tech Theme - Stratus allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects App, SaaS & Software Startup Tech Theme - Stratus: from n/a before 4.2.11.
π@cveNotify
Missing Authorization vulnerability in Pixel Makers Creative INC. App, SaaS & Software Startup Tech Theme - Stratus allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects App, SaaS & Software Startup Tech Theme - Stratus: from n/a before 4.2.11.
π@cveNotify
Patchstack
Broken Access Control in WordPress App, SaaS & Software Startup Tech Theme - Stratus Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2025-69130
Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection.
This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5.
π@cveNotify
Deserialization of Untrusted Data vulnerability in Pixel Makers Creative INC. Entrepreneur - Booking for Small Businesses WordPress Theme allows Object Injection.
This issue affects Entrepreneur - Booking for Small Businesses WordPress Theme: from n/a before 3.1.5.
π@cveNotify
Patchstack
PHP Object Injection in WordPress Entrepreneur - Booking for Small Businesses WordPress Theme Theme
Patchstack is the leading open source vulnerability research organization. Find information and protection for all WordPress and Drupal security issues.
π¨ CVE-2026-14298
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713
π@cveNotify
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713
π@cveNotify
Mattermost
Security Updates | Mattermost Documentation
Live Mattermost security advisories. Filter by product, severity, issue ID, date, and affected version.
π¨ CVE-2026-56711
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
π@cveNotify
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
π@cveNotify
GitHub
GitHub - videolan/vlc: VLC media player - plays everything, runs anywhere. Code here: https://code.videolan.org/videolan/vlc
VLC media player - plays everything, runs anywhere. Code here: https://code.videolan.org/videolan/vlc - videolan/vlc
π¨ CVE-2026-73324
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.
π@cveNotify
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.
π@cveNotify
GitHub
GitHub - videolan/vlc: VLC media player - plays everything, runs anywhere. Code here: https://code.videolan.org/videolan/vlc
VLC media player - plays everything, runs anywhere. Code here: https://code.videolan.org/videolan/vlc - videolan/vlc
π¨ CVE-2026-85706
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
π@cveNotify
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
π@cveNotify
GitLab
Work items Β· GitLab.org / GitLab Β· GitLab
GitLab is the open-source DevSecOps platform that provides a complete software development lifecycle toolchain including source control, CI/CD, security scanning, and project management in a single application.
π¨ CVE-2026-90689
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
π@cveNotify
A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. The attack can be initiated remotely.
π@cveNotify
GitHub
router-vulnerability-research/advisories/Tenda/W20E/formDelWebAuthWhiteUser/README.md at main Β· Amalll-Sec/router-vulnerabilityβ¦
Security research and coordinated vulnerability disclosures for router firmware - Amalll-Sec/router-vulnerability-research