๐จ CVE-2026-78629
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
๐@cveNotify
The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an unverifiable authentication verdict being delivered to the relying application.
๐@cveNotify
๐จ CVE-2026-78630
The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution of arbitrary OS commands with root privileges.
๐@cveNotify
The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution of arbitrary OS commands with root privileges.
๐@cveNotify
๐จ CVE-2026-78631
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.
๐@cveNotify
The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local user with access to the log file.
๐@cveNotify
๐จ CVE-2026-85102
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
๐@cveNotify
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
๐@cveNotify
Checkpoint
sk1000117 - CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN
Applies to: Security Gateway, Spark Firewall (Centrally Managed), Spark Firewall (Locally Managed)
๐จ CVE-2026-89086
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
๐@cveNotify
In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
๐@cveNotify
GitHub
Validate that the signature is for the correct payload and header ยท ulrikstrid/ocaml-jose@cf17d99
Contribute to ulrikstrid/ocaml-jose development by creating an account on GitHub.
๐จ CVE-2022-26962
Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
๐@cveNotify
Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.
๐@cveNotify
www.gruppotim.it
CVE-2022-26962 โ Italtel NFV
๐จ CVE-2026-79591
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
๐@cveNotify
A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.
๐@cveNotify
GitHub
[Bug]heap-buffer-overflow / use-after-free in xls_getCSS() from an unchecked file-controlled font index (CWE-125) ยท Issue #161โฆ
Summary xls_getCSS() builds CSS by indexing the font table with the XF record's font field: pWB->fonts.font[xf->font-1]. The xf->font value comes straight from the BIFF XF record and i...
๐จ CVE-2026-79592
An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
๐@cveNotify
An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.
๐@cveNotify
GitHub
[Bug]out-of-bounds read / SEGV in xls_dumpSummary() from unchecked file-controlled OLE summary offsets (CWE-125) ยท Issue #162 ยทโฆ
Summary xls_dumpSummary() (reached via xls_summaryInfo()) parses the OLE SummaryInformation / DocumentSummaryInformation property sets, iterating property sections driven entirely by file-controlle...
๐จ CVE-2026-89094
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
๐@cveNotify
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
๐@cveNotify
Codeberg.org
forgejo
Beyond coding. We forge.
๐จ CVE-2025-57231
Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.
๐@cveNotify
Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.
๐@cveNotify
GitHub
docmost/apps/server/src/core/attachment/attachment.controller.ts at 0bd7ecb9b03a74e9a5e3f97b6457b82371c5ceb2 ยท docmost/docmost
Docmost is an open-source collaborative wiki and documentation software. It is an open-source alternative to Confluence and Notion. - docmost/docmost
๐จ CVE-2026-71640
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline
๐@cveNotify
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline
๐@cveNotify
Gist
Reference for CVE-2026-71640
Reference for CVE-2026-71640. GitHub Gist: instantly share code, notes, and snippets.
๐จ CVE-2026-71642
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()
๐@cveNotify
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()
๐@cveNotify
Gist
Reference for CVE-2026-71642
Reference for CVE-2026-71642. GitHub Gist: instantly share code, notes, and snippets.
๐จ CVE-2026-71643
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
๐@cveNotify
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component
๐@cveNotify
Gist
Reference for CVE-2026-71643
Reference for CVE-2026-71643. GitHub Gist: instantly share code, notes, and snippets.
๐จ CVE-2026-71645
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine
๐@cveNotify
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine
๐@cveNotify
Gist
Reference for CVE-2026-71645
Reference for CVE-2026-71645. GitHub Gist: instantly share code, notes, and snippets.
๐จ CVE-2026-71647
An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp
๐@cveNotify
An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp
๐@cveNotify
Gist
Reference for CVE-2026-71647
Reference for CVE-2026-71647. GitHub Gist: instantly share code, notes, and snippets.
๐จ CVE-2026-79590
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.
๐@cveNotify
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and application crash.
๐@cveNotify
GitHub
[Bug]mruby-compiler/Prism parser passes NULL to nonnull string functions (UBSan undefined behavior, CWE-476) ยท Issue #7032 ยท mruby/mruby
Summary The Prism Ruby parser embedded in mruby-compiler passes a NULL pointer to string functions declared nonnull: memcpy at mrbgems/mruby-compiler/lib/prism/src/prism.c:2852 (argument 1 is NULL)...
๐จ CVE-2026-89151
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
๐@cveNotify
Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
๐@cveNotify
Codeberg.org
forgejo
Beyond coding. We forge.
๐จ CVE-2026-89169
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
๐@cveNotify
live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.
๐@cveNotify
๐จ CVE-2026-71641
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic
๐@cveNotify
An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic
๐@cveNotify
Gist
Reference for CVE-2026-71641
Reference for CVE-2026-71641. GitHub Gist: instantly share code, notes, and snippets.
๐จ CVE-2026-71644
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
๐@cveNotify
An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the drone enters IDLE
๐@cveNotify
Gist
Reference for CVE-2026-71644
Reference for CVE-2026-71644. GitHub Gist: instantly share code, notes, and snippets.