π¨ CVE-2026-69538
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
π@cveNotify
Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to execute code locally.
π@cveNotify
π¨ CVE-2026-69732
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
π@cveNotify
Heap-based buffer overflow in Windows Link Layer Topology Discovery Protocol allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-78510
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
To exploit the vulnerability, an attacker must first convince a user to open a specially crafted Office document.
The updates address the vulnerability by correcting how Office validates input before loading DLL files.
π@cveNotify
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files. An attacker who successfully exploited this vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
To exploit the vulnerability, an attacker must first convince a user to open a specially crafted Office document.
The updates address the vulnerability by correcting how Office validates input before loading DLL files.
π@cveNotify
π¨ CVE-2026-78512
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
π@cveNotify
Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
π@cveNotify
π¨ CVE-2026-57590
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task Group.
This issue affects Apache DolphinScheduler: before 3.4.3.
Users are recommended to upgrade to version 3.4.3, which fixes the issue.
π@cveNotify
π¨ CVE-2026-17511
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a limited snapshot of partition processor state. Successful exploitation results in a confidentiality impact to the managed system.
π@cveNotify
IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a limited snapshot of partition processor state. Successful exploitation results in a confidentiality impact to the managed system.
π@cveNotify
Ibm
Security Bulletin: This Power System update is being released to address CVE-2026-17511
Power Systems Firmware is affected by a vulnerability in the partition resource dump interface. An attacker with authenticated administrator-level access to the HMC or service processor can obtain a limited snapshot of partition processor state. Successfulβ¦
π¨ CVE-2026-6544
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
π@cveNotify
IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to unintentional inclusion of sensitive or unnecessary files and increased attack surface.
π@cveNotify
Ibm
Security Bulletin: Multiple Vulnerabilities in IBM Concert Software
Multiple vulnerabilities were addressed in IBM Concert Software version 3.0.1.1
π¨ CVE-2026-73064
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
π@cveNotify
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
π@cveNotify
GitHub
GitHub - Mbed-TLS/mbedtls: An open source, portable, easy to use, readable and flexible TLS library, and reference implementationβ¦
An open source, portable, easy to use, readable and flexible TLS library, and reference implementation of the PSA Cryptography API. Releases are on a varying cadence, typically around 3 - 6 months ...
π¨ CVE-2026-82094
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
π@cveNotify
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
π@cveNotify
Ibm
Security Bulletin: DataStage on Cloud Pak for Data has several vulnerabilities
Several vulnerabilities were found in DataStage on Cloud Pak for Data
π¨ CVE-2026-75907
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying.
π@cveNotify
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended to be secret or to authenticate the holder. Validating on the UID of the NTAG212 NFC chip alone is identification, not authentication, and the credential has no challenge-response capability that would resist copying.
π@cveNotify
kb.cert.org
CERT/CC Vulnerability Note VU#676317
Norwegian Cruise Line door access controller contains an improper authentication vulnerability
π¨ CVE-2026-79758
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections. Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.
π@cveNotify
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0 until 2.5.1, authenticated Termix users can access the server-stats API without per-host authorization. GET /status returns statuses for hosts the requester cannot access, GET /status/:id accepts an attacker-supplied numeric host identifier, and POST /clear-connections permits a regular user to clear the global SSH connection pool. The affected src/backend/ssh/server-stats.ts routes expose host online or offline state and lastChecked timestamps and can disrupt other users' active sessions or pooled connections. Unauthenticated requests remain blocked, but authentication alone does not preserve tenant isolation. This issue is fixed in version 2.5.1.
π@cveNotify
GitHub
release-2.5.1 (#1067) Β· Termix-SSH/Termix@ddbdd5c
* chore(deps): bump node from 24-slim to 26-slim in /docker in the docker-major-updates group (#1021)
* chore: fix release workflow to merge docs branch
* fix: svg donation generator push fail
*...
* chore: fix release workflow to merge docs branch
* fix: svg donation generator push fail
*...
π¨ CVE-2026-88357
nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and can cause process termination in UBSan-instrumented builds or on strict-alignment architectures, leading to denial of service.
π@cveNotify
nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted network input can cause byte-buffer addresses at odd offsets to be cast to uint16_t or wider integer pointers and directly dereferenced without alignment checks. This results in undefined behavior and can cause process termination in UBSan-instrumented builds or on strict-alignment architectures, leading to denial of service.
π@cveNotify
GitHub
UBSan "Type mismatch in operation" trap (SIGILL) on unaligned pointer-cast reads (DNS get16, ndpi_serializer) Β· Issue #3213 Β· ntop/nDPI
Describe the bug nDPI performs 16/32-bit field reads by casting a byte pointer directly and dereferencing it (*(u_int16_t*)&payload[*i] / ntohs(*((u_int16_t *)&buf[offset]))). When the byte...
π¨ CVE-2026-88368
NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer subsequently converts these values to int without range validation, resulting in undefined behavior and possible process termination, leading to denial of service.
π@cveNotify
NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() function. A specially crafted SVG document containing sufficiently large geometry coordinates can cause fixed-point-scaled edge coordinates to exceed the range representable by int. The rasterizer subsequently converts these values to int without range validation, resulting in undefined behavior and possible process termination, leading to denial of service.
π@cveNotify
GitHub
[Bug]rasterizer active-edge fixed-point coordinate overflow: (int) cast of NSVGFIX-scaled edge coordinates in nsvgaddActive (CWEβ¦
Summary When nsvgRasterize converts parsed geometry into the internal 10.6 fixed-point representation (NSVG__FIX = 1024), it casts the scaled coordinates directly to a 32-bit int. The two conversio...
π¨ CVE-2026-93425
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.
π@cveNotify
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in packages/server/src/services/patch-repo.ts without safe argument quoting. An authenticated organization member with service:read permission can inject shell metacharacters into repoPath and execute arbitrary commands through child_process.exec as root in the Dokploy container. The supplied service identifier is used only to resolve the server and does not constrain repoPath. Because the standard deployment mounts /var/run/docker.sock, container-root command execution can be used to control Docker and compromise the host and its managed applications. This issue is fixed in version 0.29.13.
π@cveNotify
GitHub
fix(security): escape file paths and remote schedule command in shell⦠· Dokploy/dokploy@16b5b72
β¦ invocations
quote() the user-derived paths that reach the shell in file mounts
(mount.ts, docker getCreateFileCommand), patch repo read (repoPath/filePath),
certificate create/remove (certificat...
quote() the user-derived paths that reach the shell in file mounts
(mount.ts, docker getCreateFileCommand), patch repo read (repoPath/filePath),
certificate create/remove (certificat...
π¨ CVE-2026-93541
An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
π@cveNotify
An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a
π@cveNotify
GitLab
Fixes for AISLE reports (!23) Β· Merge requests Β· xorg / lib / libXi Β· GitLab
This fixes 7 issues reported downstream by AISLE Research in partnership with Red Hat: CVE-2026-93541: Out-of-bounds read in libXi's XQueryDeviceState(). CVE-2026-93542: Out-of-bounds read...
π¨ CVE-2026-96744
Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence the owner value an application uses when acquiring or restoring a lock may take over or prematurely expire a lock held by another process, which can lead to duplicated or conflicting operations.
π@cveNotify
Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than as a literal value. An authenticated user who can influence the owner value an application uses when acquiring or restoring a lock may take over or prematurely expire a lock held by another process, which can lead to duplicated or conflicting operations.
π@cveNotify
GitHub
PHPLARA-261 Wrap the cache lock owner in a literal expression by GromNaN Β· Pull Request #3579 Β· mongodb/laravel-mongodb
MongoLock::acquire() builds an aggregation-pipeline update where the lock owner string is embedded inside $eq and $cond expressions. When the owner string starts with a dollar sign, MongoDB reads i...
π¨ CVE-2026-96745
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application.
π@cveNotify
Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers a command monitoring subscriber and includes untrusted data in a database operation, an unauthenticated party who controls that data may cause an application class implementing the driver's persistable interface to be instantiated and its unserialization method invoked with the supplied data. The resulting impact depends on the classes available in the application.
π@cveNotify
GitHub
PHPC-2743: Fix `__pclass` inference in events by kevinAlbs Β· Pull Request #2115 Β· mongodb/mongo-php-driver
This PR is created due to https://github.com/mongodb/mongo-php-driver-ghsa-cmvj-vxvq-rh2c/pull/1 not easily applying to v2.5. Quoting Claude when trying to locally merge changes to v2.5:
v1.21 / ...
v1.21 / ...
π¨ CVE-2026-96746
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.
π@cveNotify
An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.
π@cveNotify
GitHub
Release mongo-c-driver 1.30.12 Β· mongodb/mongo-c-driver
Announcing 1.30.12 of libbson and libmongoc, the libraries constituting the MongoDB C Driver.
libbson
No changes since 1.30.11. Version incremented to match the libmongoc version.
libmongoc
Fixes
...
libbson
No changes since 1.30.11. Version incremented to match the libmongoc version.
libmongoc
Fixes
...
π¨ CVE-2026-96750
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.
π@cveNotify
MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Compass user connects to may, under specific conditions, have content evaluated as shell input within the Compass process, with that process's privileges. This requires the Compass user to open the shell for the affected database.
π@cveNotify
GitHub
Release 1.49.12 Β· mongodb-js/compass
Release v1.49.12
What's Changed
New Features
feat(compass-editor): add hover styling to autocomplete dropdown item COMPASS-8227
Bug Fixes
fix(import-export): better escape for csv values COM...
What's Changed
New Features
feat(compass-editor): add hover styling to autocomplete dropdown item COMPASS-8227
Bug Fixes
fix(import-export): better escape for csv values COM...
π¨ CVE-2026-97226
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument filePath/uri leads to path traversal. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
Vulnerability Database
CVE-2026-97226 in DbGate
A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This vulnerability is traded as CVE-2026-97226.
π¨ CVE-2026-47132
phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQβs chat user search allows any logged-in user to bypass the intended display-name search filter and enumerate active users. The endpoint escapes SQL string syntax but does not escape `%` and `_`, which remain active `LIKE` wildcards. Version 4.2.0-alpha patches the issue.
π@cveNotify
phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQβs chat user search allows any logged-in user to bypass the intended display-name search filter and enumerate active users. The endpoint escapes SQL string syntax but does not escape `%` and `_`, which remain active `LIKE` wildcards. Version 4.2.0-alpha patches the issue.
π@cveNotify
GitHub
fix: hardened query Β· thorsten/phpMyFAQ@bd4b08b
phpMyFAQ - Open Source FAQ web application for PHP 8.4+ and MySQL, PostgreSQL and other databases - fix: hardened query Β· thorsten/phpMyFAQ@bd4b08b