🚨 CVE-2026-101066
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/dbgate_archive_link_path_traversal.md at main · 0xGenesi/CVE
Contribute to 0xGenesi/CVE development by creating an account on GitHub.
🚨 CVE-2026-101067
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/dbgate_save_uploaded_file_path_traversal.md at main · 0xGenesi/CVE
Contribute to 0xGenesi/CVE development by creating an account on GitHub.
🚨 CVE-2026-101068
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/dbgate_config_zip_arbitrary_write.md at main · 0xGenesi/CVE
Contribute to 0xGenesi/CVE development by creating an account on GitHub.
🚨 CVE-2026-101069
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A weakness has been identified in dbgate up to 7.3.1. Affected is the function exportModelSql of the file packages/api/src/controllers/databaseConnections.js of the component Export Handler. Executing a manipulation of the argument outputFile can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/dbgate_export_model_sql_arbitrary_write.md at main · 0xGenesi/CVE
Contribute to 0xGenesi/CVE development by creating an account on GitHub.
🚨 CVE-2026-101292
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
🎖@cveNotify
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
🎖@cveNotify
🚨 CVE-2026-12265
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
🎖@cveNotify
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
🎖@cveNotify
ManageEngine
Security Updates - CVE Database | ManageEngine DDI Central
List of security vulnerabilities fixed in DDI Central This page lists security vulnerability fixes made in various releases of DDI Central and vulnerability details. Go to ManageEngine's Security Response Center to report vulnerabilities on ManageEngine products.…
🚨 CVE-2026-18825
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
🎖@cveNotify
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
🎖@cveNotify
🚨 CVE-2026-52748
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
cert.pl
Vulnerabilities in Kaon AR2140 routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-52748 and CVE-2026-52749) found in Kaon AR2140 routers.
🚨 CVE-2026-52749
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
cert.pl
Vulnerabilities in Kaon AR2140 routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-52748 and CVE-2026-52749) found in Kaon AR2140 routers.
🚨 CVE-2026-59563
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
🎖@cveNotify
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
🎖@cveNotify
GitHub
fix: bind resource IDs to HMAC confirmation tokens (CWE-345) by willguibr · Pull Request #41 · zscaler/zscaler-mcp-server
31 delete operations across ZPA, ZIA, and ZTW passed empty params to check_confirmation(), producing fungible tokens replayable across different resources. All calls now include the specific resour...
🚨 CVE-2026-82323
Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers.
This issue affects Enocta Platform: through 2026-09-28.
🎖@cveNotify
Authorization bypass through User-Controlled key vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows Exploitation of Trusted Identifiers.
This issue affects Enocta Platform: through 2026-09-28.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-82326
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes.
This issue affects Enocta Platform: through 2026-09-28.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes.
This issue affects Enocta Platform: through 2026-09-28.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-82928
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82929
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82932
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82933
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82935
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.
Vulnerable components were updated or hardened, if update was not possible in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.
Vulnerable components were updated or hardened, if update was not possible in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82936
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-86330
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
🎖@cveNotify
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
🎖@cveNotify
Redhat
CVE-2026-86330 - Red Hat Customer Portal
CVE Details App
🚨 CVE-2026-16481
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox.
The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport automatically attaches an Authorization: Bearer header to every outbound request regardless of the destination host. An attacker can supply an arbitrary external URL to the pageURL parameter (either directly via the tool execution payload or implicitly via data-driven pagination tracking loops), leading Toolbox into sending its OAuth/service-account access token to an attacker-controlled listener. Depending on the configuration, this leaks either the end-user's token or the broader service-account access token (ADC), potentially exposing Protected Health Information (PHI) and secondary Google Cloud Platform services.
🎖@cveNotify
A Server-Side Request Forgery (SSRF) and credential exfiltration vulnerability exists in the cloud-healthcare-fhir-fetch-page tool of googleapis/mcp-toolbox.
The tool takes an unvalidated pageURL parameter from the client and issues an HTTP GET request to it using an authenticated client. The underlying transport automatically attaches an Authorization: Bearer header to every outbound request regardless of the destination host. An attacker can supply an arbitrary external URL to the pageURL parameter (either directly via the tool execution payload or implicitly via data-driven pagination tracking loops), leading Toolbox into sending its OAuth/service-account access token to an attacker-controlled listener. Depending on the configuration, this leaks either the end-user's token or the broader service-account access token (ADC), potentially exposing Protected Health Information (PHI) and secondary Google Cloud Platform services.
🎖@cveNotify
GitHub
fix(source/cloudhealthcare): validate pageURL parameter to prevent SSRF by duwenxin99 · Pull Request #3453 · googleapis/mcp-toolbox
This PR resolves a Server-Side Request Forgery (SSRF) vulnerability in the Cloud Healthcare FHIR Fetch Page tool by introducing strict validation for the pageURL parameter.
Reported by: HE WEI(ギカク)
Reported by: HE WEI(ギカク)
🚨 CVE-2026-69480
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
🎖@cveNotify
Heap-based buffer overflow in Windows Partition Management Driver allows an authorized attacker to elevate privileges locally.
🎖@cveNotify