π¨ CVE-2026-92839
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the userβs session.
π@cveNotify
Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the userβs session.
π@cveNotify
Canva
Canva Trust & Security Portal | Powered by SafeBase
See how Canva manages their security program with SafeBase.
π¨ CVE-2025-59607
Memory Corruption when copying large input data exceeds normal allocation limits.
π@cveNotify
Memory Corruption when copying large input data exceeds normal allocation limits.
π@cveNotify
π¨ CVE-2026-24073
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
π@cveNotify
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
π@cveNotify
π¨ CVE-2026-24074
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
π@cveNotify
Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.
π@cveNotify
π¨ CVE-2026-24075
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
π@cveNotify
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
π@cveNotify
π¨ CVE-2026-24081
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
π@cveNotify
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
π@cveNotify
π¨ CVE-2026-25275
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
π@cveNotify
Transient DOS when processing authentication frames with invalid FILS information element header lengths.
π@cveNotify
π¨ CVE-2026-25278
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
π@cveNotify
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
π@cveNotify
π¨ CVE-2026-25280
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
π@cveNotify
Memory corruption when processing escape handling flow with insufficient user buffer sizes.
π@cveNotify
π¨ CVE-2026-25281
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
π@cveNotify
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
π@cveNotify
π¨ CVE-2026-25282
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
π@cveNotify
Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.
π@cveNotify
π¨ CVE-2026-25283
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
π@cveNotify
Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.
π@cveNotify
π¨ CVE-2026-25284
Information Disclosure when a pointer is reused after being deallocated.
π@cveNotify
Information Disclosure when a pointer is reused after being deallocated.
π@cveNotify
π¨ CVE-2026-25290
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
π@cveNotify
Memory Corruption when validating large data buffers from external sources using addition to check buffer length.
π@cveNotify
π¨ CVE-2026-50604
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
π@cveNotify
A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially allowing access to functionality that should be restricted.
π@cveNotify
Acer Community
Security Advisory: Unauthenticated Access Vulnerability in NitroSense and PredatorSense Software (CVE-2026-50604) - Acer Community
Vulnerability Description A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Underβ¦
π¨ CVE-2026-87796
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
π@cveNotify
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
π@cveNotify
π¨ CVE-2026-87935
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.
π@cveNotify
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. On Apache servers where AllowOverride is enabled, an .htaccess file placed in the upload directory may block direct HTTP retrieval of uploaded files, limiting exploitability to stacks that do not honor .htaccess directives such as nginx, LiteSpeed, and Apache with AllowOverride None.
π@cveNotify
π¨ CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
π@cveNotify
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
π@cveNotify
π¨ CVE-2026-56092
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.
π@cveNotify
The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions on cached pages.
π@cveNotify
Typo3
TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr) - TYPO3 News
It has been discovered that the extension "Apache Solr for TYPO3 - Enterprise Search" (solr) is vulnerable to Broken Access Control, Insecure Deserialization and Information Disclosure.