π¨ CVE-2026-91119
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attributes without URL encoding. A quote-bearing display name could terminate the intended URL attribute and inject attacker-controlled elements into the trusted rendered markup. Although the visible mention text was escaped, the unencoded path component allowed stored HTML injection when another user viewed the affected topic action or activity log. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
π@cveNotify
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-action and nested-activity-log components interpolated the free-form action_code_who value into mention-link href attributes without URL encoding. A quote-bearing display name could terminate the intended URL attribute and inject attacker-controlled elements into the trusted rendered markup. Although the visible mention text was escaped, the unencoded path component allowed stored HTML injection when another user viewed the affected topic action or activity log. This issue is fixed in versions 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0.
π@cveNotify
GitHub
SECURITY: Encode action_code_who in mention URLs [backport 2026.6] Β· discourse/discourse@20dbf11
A platform for community discussion. Free, open, simple. - SECURITY: Encode action_code_who in mention URLs [backport 2026.6] Β· discourse/discourse@20dbf11
π¨ CVE-2026-100700
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.
π@cveNotify
nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits quadratic backtracking behavior. Attackers can supply crafted email header values with long whitespace-free runs to block the Node.js event loop for tens of seconds, causing service unavailability.
π@cveNotify
GitHub
Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
### Summary
When `addressparser` finds no address by its strict reading, it falls back to pulling one out of the free text with `/\s*\b[^@\s]+@[^\s]+\b\s*/`. That pattern backtracks quadratically:...
When `addressparser` finds no address by its strict reading, it falls back to pulling one out of the free text with `/\s*\b[^@\s]+@[^\s]+\b\s*/`. That pattern backtracks quadratically:...
π¨ CVE-2026-100745
A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard Handler. The manipulation of the argument interface1/interface2 leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
π@cveNotify
A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform/formWizSurvey of the component Wireless Wizard Handler. The manipulation of the argument interface1/interface2 leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
π@cveNotify
tzh00203 on Notion
Edimax BR-6428nC formWizSurvey Interface Stack Overflow | Notion
Vulnerability Title: Stack-Based Buffer Overflow in formWizSurvey via interface1 and interface2 Parameters on Edimax BR-6428nC
π¨ CVE-2026-100836
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.
π@cveNotify
Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSON function that fails to validate decoded ciphertext length before slicing. An authenticated workload with a valid mesh certificate can trigger a runtime panic by submitting a short base64-encoded ciphertext, causing log spam and request failures without crashing the process.
π@cveNotify
GitHub
Coordinator transit engine `ciphertextContainer.UnmarshalJSON` panics on attacker-controlled short ciphertexts
## Summary
`ciphertextContainer.UnmarshalJSON` decodes the third `:`-separated component of a `vault:vX:base64...` ciphertext and then unconditionally takes a 12-byte prefix slice for the AES-GCM ...
`ciphertextContainer.UnmarshalJSON` decodes the third `:`-separated component of a `vault:vX:base64...` ciphertext and then unconditionally takes a 12-byte prefix slice for the AES-GCM ...
π¨ CVE-2026-100868
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
π@cveNotify
Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in single-user mode. Unauthenticated attackers on adjacent networks can connect to the WebSocket port to impersonate the Penpot browser plugin, intercept task payloads, and return forged results to the MCP client.
π@cveNotify
GitHub
GitHub - penpot/penpot: Penpot: The open-source design platform for Product teams that need scalable collaboration.
Penpot: The open-source design platform for Product teams that need scalable collaboration. - penpot/penpot
π¨ CVE-2026-100872
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
π@cveNotify
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
π@cveNotify
GitHub
GitHub - Sylius/Sylius: Headless open-source eCommerce platform on top of PHP/Symfony/API Platform
Headless open-source eCommerce platform on top of PHP/Symfony/API Platform - Sylius/Sylius
π¨ CVE-2026-86838
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
π@cveNotify
The Bookly WordPress plugin before 28.3 does not validate client-supplied booking quantity values on the server before computing the appointment total, allowing unauthenticated users to reduce the total to zero and book paid services for free while bypassing the payment step.
π@cveNotify
WPScan
Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation
See details on Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation CVE 2026-86838. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-88828
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
π@cveNotify
The Blacklist Manager for WooCommerce WordPress plugin from 1.3.0 to 2.3.1 does not enforce its user blocking on every authentication path, allowing the holder of an account the site owner has blocked to keep authenticating with that account's privileges, without the block being enforced or recorded.
π@cveNotify
WPScan
Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML-RPC and Application Passwords
See details on Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML-RPC and Application Passwords CVE 2026-88828. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89300
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
π@cveNotify
The WP Verify API WordPress plugin through 1.0.0 does not have any authorisation check in one of its REST routes, allowing unauthenticated users to insert arbitrary data into its own database table, as well as to make the site send templated verification emails to arbitrary email addresses. The route is not rate limited either.
π@cveNotify
WPScan
WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients
See details on WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Recipients CVE 2026-89300. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89303
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
π@cveNotify
The Post Voting System WordPress plugin through 1.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing any authenticated user to perform SQL injection attacks.
π@cveNotify
WPScan
Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter
See details on Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter CVE 2026-89303. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-89411
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
π@cveNotify
The Paymattic WordPress plugin from 4.6.20 before 4.6.26 does not verify that a confirmed Stripe payment belongs to the order it is applied to, allowing unauthenticated users to mark an arbitrary pending order as paid by confirming a smaller payment of their own against it.
π@cveNotify
WPScan
Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent
See details on Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent CVE 2026-89411. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-92996
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
π@cveNotify
The Verge3D WordPress plugin from 4.1.0 through 4.13.0 does not verify with the payment provider that a payment was actually made, and does not check order ownership, allowing unauthenticated users to mark any order as paid.
π@cveNotify
WPScan
Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done
See details on Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done CVE 2026-92996. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-93000
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
The SPS-Suite WordPress plugin through 1.4.0 does not sanitise the search query before using it in a SQL query when its static-page search feature is enabled, allowing unauthenticated attackers to perform SQL injection attacks.
π@cveNotify
WPScan
SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search
See details on SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search CVE 2026-93000. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2026-12264
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
π@cveNotify
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
π@cveNotify
ManageEngine
Security Updates - CVE Database | ManageEngine DDI Central
List of security vulnerabilities fixed in DDI Central This page lists security vulnerability fixes made in various releases of DDI Central and vulnerability details. Go to ManageEngine's Security Response Center to report vulnerabilities on ManageEngine products.β¦
π¨ CVE-2026-101071
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was determined in Acrel Electric Unet Web Service up to 20260814. This vulnerability affects unknown code of the file /exchange/attachment/upload of the component Upload Endpoint. This manipulation of the argument File causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
CVE/Acrel_Unet_Web_Service_PoC.md at main Β· WAz1nR9/CVE
Contribute to WAz1nR9/CVE development by creating an account on GitHub.
π¨ CVE-2026-101074
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
HACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_boa_stack_overflow.md at main Β· senxitoyshuyi-ui/HACKALL
CVE about IOT. Contribute to senxitoyshuyi-ui/HACKALL development by creating an account on GitHub.
π¨ CVE-2026-101333
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
π@cveNotify
A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and access management. The issue occurs when the listener is configured to include the idp tag. An unauthenticated attacker can send requests to the identity broker login endpoint using arbitrary provider aliases, causing the system to create an unlimited number of metric time series. This can lead to excessive memory consumption and degrade the performance of both the server and its monitoring tools.
π@cveNotify
Redhat
CVE-2026-101333 - Red Hat Customer Portal
CVE Details App
π¨ CVE-2026-80359
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
π@cveNotify
Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface With Improper Access Control vulnerability in the SMCU on 17G BOSS-N1 controllers. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Unauthorized access.
π@cveNotify
π¨ CVE-2026-101076
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability was detected in Netcore NR289-GE 1.4.5102. This affects the function system of the file /set_ntp_server_ip.cgi of the component CGI Handler. The manipulation of the argument ntp_ip results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
HACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_set_ntp_server_ip_command_injection.md at main Β· senxitoyshuyiβ¦
CVE about IOT. Contribute to senxitoyshuyi-ui/HACKALL development by creating an account on GitHub.
π¨ CVE-2026-101077
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
HACKALL/netcore_NR289-GE_V1.4.5102,2018.06.1418_44 Router/Netcore_NR289-GE_unauth_file_write.md at main Β· senxitoyshuyi-ui/HACKALL
CVE about IOT. Contribute to senxitoyshuyi-ui/HACKALL development by creating an account on GitHub.
π¨ CVE-2026-101078
A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or compartmentalization. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. It is advisable to implement a patch to correct this issue. The vendor was contacted early about this disclosure but did not respond in any way.
π@cveNotify
GitHub
My_vulnerable/SECURITY-MOUNT-ESCAPE.en.md at main Β· Ruoyyy/My_vulnerable
Contribute to Ruoyyy/My_vulnerable development by creating an account on GitHub.