๐จ CVE-2026-86098
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.
๐@cveNotify
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers, or DNS names that reach the vulnerable function, causing heap corruption.
๐@cveNotify
GitHub
GitHub - ntop/nDPI: Open Source Deep Packet Inspection Software Toolkit
Open Source Deep Packet Inspection Software Toolkit - ntop/nDPI
๐จ CVE-2026-86114
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
๐@cveNotify
Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide defaults. Attackers can inject malicious container configurations with privileged settings or host path mounts that execute with administrative privileges when deployed by administrators.
๐@cveNotify
GitHub
oss/arcane.md at main ยท geo-chen/oss
securing oss responsibly. Contribute to geo-chen/oss development by creating an account on GitHub.
๐จ CVE-2022-51013
PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions in the Durable class, causing server crashes.
๐@cveNotify
PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-range damage values in itemstack NBT to trigger unhandled exceptions in the Durable class, causing server crashes.
๐@cveNotify
GitHub
TypeConverter: account for possible out-of-range meta in items ยท pmmp/PocketMine-MP@c8e1cfc
Custom server software for Minecraft: Bedrock, built from scratch in PHP, C and C++ - TypeConverter: account for possible out-of-range meta in items ยท pmmp/PocketMine-MP@c8e1cfc
๐จ CVE-2022-51018
PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption and server crashes (exceeding the 1 MB chunk size limit when saving region-based worlds in PM3, or exceeding the 32 KiB TAG_String limit in PM4).
๐@cveNotify
PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create oversized NBT ('book bombs'), causing excess bandwidth consumption and server crashes (exceeding the 1 MB chunk size limit when saving region-based worlds in PM3, or exceeding the 32 KiB TAG_String limit in PM4).
๐@cveNotify
GitHub
Book page text, count, and author/title length is not limited
### Impact
Players can fill book pages with as many characters as they like; the server does not check this.
In addition, the maximum of 50 pages is also not enforced, meaning that players can cr...
Players can fill book pages with as many characters as they like; the server does not check this.
In addition, the maximum of 50 pages is also not enforced, meaning that players can cr...
๐จ CVE-2026-86538
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.
๐@cveNotify
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal sequences in the templateFile parameter to bypass path restrictions and read sensitive files like credentials and configuration through the JSON response.
๐@cveNotify
GitHub
knowns/internal/server/routes/templates.go at v0.29.1 ยท knowns-dev/knowns
The memory layer for AI-native development - giving AI persistent understanding of your software projects. - knowns-dev/knowns
๐จ CVE-2026-86543
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
๐@cveNotify
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish the API at a publicly accessible address.
๐@cveNotify
GitHub
knowns/internal/cli/browser.go at v0.29.1 ยท knowns-dev/knowns
The memory layer for AI-native development - giving AI persistent understanding of your software projects. - knowns-dev/knowns
๐จ CVE-2026-86714
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
๐@cveNotify
PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
๐@cveNotify
GitHub
GitHub - PX4/PX4-Autopilot: PX4 Autopilot Software
PX4 Autopilot Software. Contribute to PX4/PX4-Autopilot development by creating an account on GitHub.
๐จ CVE-2026-73313
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.
๐@cveNotify
XenForo before 2.3.13 contains a multi-factor authentication bypass vulnerability in the passkey TFA provider that allows an authenticated attacker to complete login as another user by submitting their own registered passkey credential during the WebAuthn assertion step. The passkey verification path performs a global credential lookup without validating that the matched credential belongs to the user whose login is pending, enabling an attacker who knows a target account's password to sign the challenge with their own passkey and bypass multi-factor authentication on both public forum and ACP login paths.
๐@cveNotify
bombobombone.github.io
CVE-2026-73313: Passkey accepted for the wrong account โ BomboBombone
A passkey owned by one XenForo user completed another user's pending two-step login.
๐จ CVE-2026-73318
XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.
๐@cveNotify
XenForo before 2.3.13 contains a missing authorization vulnerability in the force-agreement controller that allows any ACP administrator to access and submit force-agreement forms regardless of their assigned permissions. Attackers can bypass the option permission declared in the navigation configuration to update the global policy last-updated timestamp, forcing all users to re-agree to the privacy policy or terms of service.
๐@cveNotify
bombobombone.github.io
CVE-2026-73318: Missing permission checks on agreement resets โ BomboBombone
A restricted ACP administrator could force every user to accept the privacy policy and terms again.
๐จ CVE-2026-68832
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Integer overflow or wraparound in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-68834
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-68838
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-68841
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-68851
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
๐@cveNotify
Buffer over-read in Windows NTFS allows an authorized attacker to disclose information locally.
๐@cveNotify
๐จ CVE-2026-68875
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
๐@cveNotify
Buffer over-read in Windows NTFS allows an authorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-69265
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69312
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69332
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-69340
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-69379
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69425
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.
๐@cveNotify
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.
๐@cveNotify