๐จ CVE-2026-50236
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
๐@cveNotify
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position.
๐@cveNotify
๐จ CVE-2026-13622
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
๐@cveNotify
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.
๐@cveNotify
๐จ CVE-2026-78376
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
๐@cveNotify
A flaw was found in WebKitGTK. Processing malicious web content can cause a use-after-free issue due to improper memory handling and result in memory corruption.
๐@cveNotify
๐จ CVE-2026-83596
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
๐@cveNotify
A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
๐@cveNotify
๐จ CVE-2026-81665
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
๐@cveNotify
A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to the cluster could cause a heap buffer overflow with attacker-controlled data. This can crash the Corosync daemon, causing a denial of service to the entire cluster, and may potentially allow further exploitation given sufficient heap-corruption control.
๐@cveNotify
๐จ CVE-2026-69598
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Incorrect calculation of buffer size in Windows iSCSI allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-69600
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69601
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
๐@cveNotify
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
๐@cveNotify
๐จ CVE-2026-69602
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges over a network.
๐@cveNotify
๐จ CVE-2026-69603
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
๐@cveNotify
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
๐@cveNotify
๐จ CVE-2026-69604
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Heap-based buffer overflow in Windows Audio Service allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2026-69606
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
๐@cveNotify
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
๐@cveNotify
๐จ CVE-2025-69904
Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.
๐@cveNotify
Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.
๐@cveNotify
GitHub
cves-collection/cve-2025-69904/README.md at main ยท pwnzillaa/cves-collection
Contribute to pwnzillaa/cves-collection development by creating an account on GitHub.
๐จ CVE-2026-79362
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
๐@cveNotify
Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core. Attacker-controlled data can terminate the nowdoc prematurely and inject arbitrary PHP Code.
๐@cveNotify
GitHub
Generate a unique boundary for cache files ยท WoltLab/WCF@c19789d
WoltLab Suite Core (previously WoltLab Community Framework) - Generate a unique boundary for cache files ยท WoltLab/WCF@c19789d
๐จ CVE-2026-90473
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
๐@cveNotify
msgpack-java through 0.9.12 contains an integer overflow vulnerability in MessageUnpacker.skipValue() when processing MAP32 containers with large element counts. Attackers can supply a MAP32 element count at or above 0x40000000 that wraps when doubled, causing the parser cursor to desynchronize and attacker-controlled data to be returned in place of later fields.
๐@cveNotify
GitHub
GitHub - msgpack/msgpack-java: MessagePack serializer implementation for Java / msgpack.org[Java]
MessagePack serializer implementation for Java / msgpack.org[Java] - msgpack/msgpack-java
๐จ CVE-2026-90536
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
๐@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and personalized ad creative URLs without authentication or permission checks.
๐@cveNotify
GitHub
Missing authorization: `APIName=adsInfo` on a password-protected video returns the owner `users_id` and per-user ad creatives
## Summary
`plugin/API/API.php` `get_api_adsInfo` does not call `User::canWatchVideo()`. When `videos_id` is present it sets `$users_id = Video::getOwner($parameters['videos_id'])` and ret...
`plugin/API/API.php` `get_api_adsInfo` does not call `User::canWatchVideo()`. When `videos_id` is present it sets `$users_id = Video::getOwner($parameters['videos_id'])` and ret...
๐จ CVE-2026-90546
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.
๐@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like counters and bypass access controls.
๐@cveNotify
GitHub
Missing authorization: `objects/like.json.php` records likes on password- and group-restricted videos without `canWatchVideo`
## Summary
`objects/like.json.php` constructs `new Like($_GET['like'], $_POST['videos_id'])` then returns `Video::getVideoLikes`. `Like::__construct` requires `User::isLogged()` on...
`objects/like.json.php` constructs `new Like($_GET['like'], $_POST['videos_id'])` then returns `Video::getVideoLikes`. `Like::__construct` requires `User::isLogged()` on...
๐จ CVE-2026-90551
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.
๐@cveNotify
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and video titles including password-protected content.
๐@cveNotify
GitHub
Missing authorization: `APIName=video_from_program` returns private playlist contents without `canManagePlaylist` or `forbidIfโฆ
## Summary
`plugin/API/API.php` `get_api_video_from_program` loads `PlayLists::getOnlyVideosAndAudioIDFromPlaylistLight($playlists_id)` and then `new PlayList($playlists_id)` with no playlist ACL....
`plugin/API/API.php` `get_api_video_from_program` loads `PlayLists::getOnlyVideosAndAudioIDFromPlaylistLight($playlists_id)` and then `new PlayList($playlists_id)` with no playlist ACL....
๐จ CVE-2026-90494
A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
Vulnerability Database
CVE-2026-90494 in node-restify
A flaw has been found in restify node-restify up to 12.0.0. This vulnerability is handled as CVE-2026-90494.
๐จ CVE-2026-90499
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
๐@cveNotify
GitHub
vhr-advisories/advisories/VHR-VULN-009-password-change-idor.md at main ยท ArrestX/vhr-advisories
vhr (ๅพฎไบบไบ) security advisories. Contribute to ArrestX/vhr-advisories development by creating an account on GitHub.
๐จ CVE-2026-90504
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
๐@cveNotify
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
๐@cveNotify
Gist
Advisory: CWE-306 Auth Bypass (CRITICAL) - vvbbnn00/WARP-Clash-API Finding 1
Advisory: CWE-306 Auth Bypass (CRITICAL) - vvbbnn00/WARP-Clash-API Finding 1 - warp_finding1.md