🚨 CVE-2026-87752
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes.
This issue affects Agentis: from 4.44 before 4.6.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes.
This issue affects Agentis: from 4.44 before 4.6.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-91043
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service.
Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC 9113 section 6.5.2 defines the limit on the decoded header list. An HPACK indexed field costs one byte on the wire and decodes to a dynamic table entry of up to 4 KB, and join_cookie_headers/1 in lib/mint/http2.ex copies every cookie value of a response into one new binary. A header block under the default 256 KB wire limit therefore makes the client allocate about 1 GB for a single response, and several such responses in one delivery exhaust the memory of the process that owns the connection or of the whole VM.
This issue affects mint: from 1.1.0 before 1.11.0.
🎖@cveNotify
Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to exhaust memory on the client host and cause a denial of service.
Mint.HTTP2 enforces the client's max_header_list_size setting only on the compressed size of an inbound header block, while RFC 9113 section 6.5.2 defines the limit on the decoded header list. An HPACK indexed field costs one byte on the wire and decodes to a dynamic table entry of up to 4 KB, and join_cookie_headers/1 in lib/mint/http2.ex copies every cookie value of a response into one new binary. A header block under the default 256 KB wire limit therefore makes the client allocate about 1 GB for a single response, and several such responses in one delivery exhaust the memory of the process that owns the connection or of the whole VM.
This issue affects mint: from 1.1.0 before 1.11.0.
🎖@cveNotify
🚨 CVE-2026-101055
A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A security flaw has been discovered in Thinkware U3000 up to 1.02.04. Affected by this vulnerability is the function GET_STATUS of the component TCP Service. The manipulation of the argument wifi_info results in information disclosure. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
disclosure-thinkware-u3000/findings/03-wifi-credential-disclosure.md at main · turretsec/disclosure-thinkware-u3000
Contribute to turretsec/disclosure-thinkware-u3000 development by creating an account on GitHub.
🚨 CVE-2026-101068
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function zipJsonLinesData of the file packages/api/src/utility/zipJsonLinesData.js of the component Create Connection Endpoint. Performing a manipulation of the argument filePath results in path traversal. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. PR #1530 / commit 5f99b4d82 (7.2.5) hardened other export endpoints with checkSecureExportFilePath but omitted this endpoint. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/dbgate_config_zip_arbitrary_write.md at main · 0xGenesi/CVE
Contribute to 0xGenesi/CVE development by creating an account on GitHub.
🚨 CVE-2026-101292
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
🎖@cveNotify
Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFederationPolicy(). The method calls Class.forName(clazz).getConstructor().newInstance() where clazz is read directly from the CORE protocol wire buffer without type validation. An authenticated federation peer can send a FEDERATION_DOWNSTREAM_CONNECT packet with a crafted class name, causing the broker to load and instantiate arbitrary classes visible to the Artemis module classloader. Static initializers (<clinit>) and no-argument constructors (<init>()) execute as side effects before the type cast, enabling denial of service via system-property poisoning, out-of-memory conditions via classloading, or broker state manipulation.
🎖@cveNotify
🚨 CVE-2026-12265
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
🎖@cveNotify
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
🎖@cveNotify
ManageEngine
Security Updates - CVE Database | ManageEngine DDI Central
List of security vulnerabilities fixed in DDI Central This page lists security vulnerability fixes made in various releases of DDI Central and vulnerability details. Go to ManageEngine's Security Response Center to report vulnerabilities on ManageEngine products.…
🚨 CVE-2026-18825
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
🎖@cveNotify
An Origin Validation Error in the middleware of the connect-xcors npm package allows an attacker to bypass origin verification and perform a cross domain authenticated request.
🎖@cveNotify
🚨 CVE-2026-52748
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
The Kaon AR2140X router contains a vulnerability where the backup functionality is accessible without authentication. This allows an unauthenticated remote attacker to trigger a configuration backup and retrieve it in a form encrypted by a device-specific key. Triggering this function renders the router inoperable for a substantial period of time.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
cert.pl
Vulnerabilities in Kaon AR2140 routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-52748 and CVE-2026-52749) found in Kaon AR2140 routers.
🚨 CVE-2026-52749
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
The Kaon AR2140X router improperly issues session cookies in responses to unauthenticated HTTP requests. This vulnerability allows a remote attacker to obtain a valid session identifier without providing credentials, resulting in an authentication bypass. With this access, the attacker can perform unauthorized actions on upgrade-related functionalities. These actions can be abused to force the router to issue GET requests to arbitrarily chosen domains.
This issue was identified in firmware versions up to 4.2.17. Status of newer versions remains unknown.
🎖@cveNotify
cert.pl
Vulnerabilities in Kaon AR2140 routers
CERT Polska has received a report about 2 vulnerabilities (CVE-2026-52748 and CVE-2026-52749) found in Kaon AR2140 routers.
🚨 CVE-2026-59563
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
🎖@cveNotify
Zscaler MCP Server versions 0.7.0 and 0.7.1 has an issue where HMAC confirmation tokens were not bound to the target resource identifier, allowing an MCP client or agent to replay a token generated for one resource to affect another resource of the same type. This issue is fixed in version 0.7.2.
🎖@cveNotify
GitHub
fix: bind resource IDs to HMAC confirmation tokens (CWE-345) by willguibr · Pull Request #41 · zscaler/zscaler-mcp-server
31 delete operations across ZPA, ZIA, and ZTW passed empty params to check_confirmation(), producing fungible tokens replayable across different resources. All calls now include the specific resour...
🚨 CVE-2026-82326
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes.
This issue affects Enocta Platform: through 2026-09-28.
🎖@cveNotify
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Enocta Educational Technologies Inc. Enocta Platform allows XSS Targeting HTML Attributes.
This issue affects Enocta Platform: through 2026-09-28.
🎖@cveNotify
siberguvenlik.gov.tr
T.C. Siber Güvenlik Başkanlığı
Türkiye Cumhuriyeti Cumhurbaşkanlığı Siber Güvenlik Başkanlığı resmi web sitesi.
🚨 CVE-2026-82929
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82930
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82932
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82933
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82935
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.
Vulnerable components were updated or hardened, if update was not possible in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.
Vulnerable components were updated or hardened, if update was not possible in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-82936
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.
This issue was fixed in version 3.0.30
🎖@cveNotify
mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.
This issue was fixed in version 3.0.30
🎖@cveNotify
cert.pl
Podatności w urządzeniach F&F Filipowski mH-DEVELOPER
W urządzeniach F&F Filipowski mH-DEVELOPER wykryto 7 podatności różnego typu (od CVE-2026-82928 do CVE-2026-82930 oraz od CVE-2026-82932, CVE-2026-82933, CVE-2026-82935 i CVE-2026-82936)
🚨 CVE-2026-101070
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A security vulnerability has been detected in dbgate up to 7.3.1. Affected by this vulnerability is the function files of the file packages/api/src/controllers/runners.js of the component Files Endpoint. The manipulation of the argument runid leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/dbgate_runners_files_path_traversal.md at main · 0xGenesi/CVE
Contribute to 0xGenesi/CVE development by creating an account on GitHub.
🚨 CVE-2026-101071
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
CVE/Acrel_Unet_Web_Service_PoC.md at main · WAz1nR9/CVE
Contribute to WAz1nR9/CVE development by creating an account on GitHub.
🚨 CVE-2026-101072
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
🎖@cveNotify
GitHub
HACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_ap_ip_command_injection.md at main · senxitoyshuyi-ui/HACKALL
CVE about IOT. Contribute to senxitoyshuyi-ui/HACKALL development by creating an account on GitHub.
🚨 CVE-2026-15952
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).
This issue affects Protection and control IED manager (PCM600): through 2.14.
🎖@cveNotify
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600).
This issue affects Protection and control IED manager (PCM600): through 2.14.
🎖@cveNotify