CVE Notify
19.6K subscribers
4 photos
339K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2026-92839
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

πŸŽ–@cveNotify
🚨 CVE-2025-59607
Memory Corruption when copying large input data exceeds normal allocation limits.

πŸŽ–@cveNotify
🚨 CVE-2026-24073
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.

πŸŽ–@cveNotify
🚨 CVE-2026-24074
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

πŸŽ–@cveNotify
🚨 CVE-2026-24075
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

πŸŽ–@cveNotify
🚨 CVE-2026-24081
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.

πŸŽ–@cveNotify
🚨 CVE-2026-25261
Memory corruption while processing rear sensor IOCTL calls.

πŸŽ–@cveNotify
🚨 CVE-2026-25275
Transient DOS when processing authentication frames with invalid FILS information element header lengths.

πŸŽ–@cveNotify
🚨 CVE-2026-25278
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

πŸŽ–@cveNotify
🚨 CVE-2026-25280
Memory corruption when processing escape handling flow with insufficient user buffer sizes.

πŸŽ–@cveNotify
🚨 CVE-2026-25281
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

πŸŽ–@cveNotify
🚨 CVE-2026-25282
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

πŸŽ–@cveNotify
🚨 CVE-2026-25283
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

πŸŽ–@cveNotify
🚨 CVE-2026-25284
Information Disclosure when a pointer is reused after being deallocated.

πŸŽ–@cveNotify
🚨 CVE-2026-25290
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

πŸŽ–@cveNotify
🚨 CVE-2026-25294
Transient DOS while parsing frame during channel usage.

πŸŽ–@cveNotify
🚨 CVE-2026-50604
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.

πŸŽ–@cveNotify
🚨 CVE-2026-87796
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

πŸŽ–@cveNotify
🚨 CVE-2026-87935
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.

πŸŽ–@cveNotify
🚨 CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

πŸŽ–@cveNotify
🚨 CVE-2026-56092
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.

πŸŽ–@cveNotify