CVE-2020-26526: Schwachstellen-Eintrag (NVD)
An issue was discovered in Damstra Smart Asset 2020.7. It is possible to enumerate valid usernames on the login page. The application sends a different server response when the username is invalid than when the username is valid ("Unable to find an APIDomain" versus "Wrong email or password").
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-15 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Ga
CVE-2026-75501 | Calix EXOS up to 6.6.47 UPnP WANIPConnection service missing authentication (EUVD-2026-63988)
A vulnerability, which was classified as critical, has been found in Calix EXOS up to 6.6.47. Affected is an unknown function of the component UPnP WANIPConnection service. This manipulation causes missing authentication. The identification
CVE-2026-76692 | HPE EdgeConnect SD-WAN Gateways up to 9.4.8.2/9.5.8.1/9.6.3.1/9.7.0.0 missing initialization (EUVD-2026-79218)
A vulnerability was found in HPE EdgeConnect SD-WAN Gateways up to 9.4.8.2/9.5.8.1/9.6.3.1/9.7.0.0. It has been classified as critical. The affected element is an unknown function. Performing a manipulation results in missing initialization
CVE-2026-55225 | Strimzi Kafka Operator up to 1.0.0 Cluster Operator watchedNamespace privileges management (EUVD-2026-78883)
A vulnerability described as critical has been identified in Strimzi Kafka Operator up to 1.0.0. The impacted element is an unknown function of the component Cluster Operator. Such manipulation of the argument watchedNamespace leads to impr
CVE-2026-12354 | IBM MQ up to 10.0.0.0 Resource Adapter deserialization (EUVD-2026-78878)
A vulnerability classified as critical has been found in IBM MQ up to 10.0.0.0. The impacted element is an unknown function of the component Resource Adapter. This manipulation causes deserialization. The identification of this vulnerabilit
CVE-2026-88922 | HashiCorp go-getter Archive Decompression privileges management (EUVD-2026-79245)
A vulnerability, which was classified as problematic, was found in HashiCorp go-getter. This issue affects some unknown processing of the component Archive Decompression Handler. Such manipulation leads to improper privilege management. Thi
CVE-2026-44300 | OpenCost up to 1.120.x pkg/costmodel/router.go AddServiceKey input validation (EUVD-2026-78874)
A vulnerability, which was classified as critical, was found in OpenCost up to 1.120.x. Affected by this vulnerability is the function AddServiceKey of the file pkg/costmodel/router.go. The manipulation results in improper input validation.
CVE-2026-12728 | IBM MQ up to 10.0.0.0 deserialization (EUVD-2026-78871)
A vulnerability categorized as very critical has been discovered in IBM MQ up to 10.0.0.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to deserialization. This vulnerability is documented as CVE-2026-
CVE-2026-12752 | IBM Business Automation Workflow xml external entity reference (EUVD-2026-78865)
A vulnerability marked as critical has been reported in IBM Business Automation Workflow. The affected element is an unknown function. This manipulation causes xml external entity reference. This vulnerability appears as CVE-2026-12752. The
CVE-2026-53710 | IBM MCP Context Forge up to 1.0.1 python_sandbox_server server_fastmcp.py execute_code os command injection (EUVD-2026-78933)
A vulnerability classified as critical was found in IBM MCP Context Forge up to 1.0.1. Impacted is the function execute_code of the file mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py of the component p
CVE-2026-58200 | Jhb-software Payload Plugins up to 0.3.x Cloudinary Signature getGenerateSignature.ts cloudinary.utils.api_sign_request paramsToSign improper authorization (EUVD-2026-78825)
A vulnerability identified as problematic has been detected in Jhb-software Payload Plugins up to 0.3.x. Affected by this vulnerability is the function cloudinary.utils.api_sign_request of the file cloudinary/src/getGenerateSignature.ts of
CVE-2026-55690 | StarCitizenWiki EmbedVideo Extension up to 4.0.x EmbedServiceFactory EmbedServiceFactory.php newFromName cross site scripting (EUVD-2026-78831)
A vulnerability described as problematic has been identified in StarCitizenWiki EmbedVideo Extension up to 4.0.x. Affected by this vulnerability is the function EmbedServiceFactory::newFromName of the file includes/EmbedService/EmbedService
CVE-2026-76706 | HPE EdgeConnect SD-WAN Gateways up to 9.4.10/9.5.8/9.6.3/9.7.0 API Endpoint information disclosure (EUVD-2026-79232)
A vulnerability classified as problematic has been found in HPE EdgeConnect SD-WAN Gateways up to 9.4.10/9.5.8/9.6.3/9.7.0. This vulnerability affects unknown code of the component API Endpoint. The manipulation leads to information disclos
CVE-2026-58744 | Google Android input validation (EUVD-2026-79015)
A vulnerability described as very critical has been identified in Google Android. Affected by this issue is some unknown functionality. Such manipulation leads to improper input validation. This vulnerability is referenced as CVE-2026-58744
Critical Cisco Secure Email Gateway zero-day gives attackers root access
Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited
CVE-2026-58767 | Google Android arm-smmu-v3 arm-smmu-v3.c privileges management
A vulnerability classified as critical was found in Google Android. The affected element is an unknown function of the file arm-smmu-v3.c of the component arm-smmu-v3. The manipulation results in improper privilege management. This vulnerab
CVE-2026-58747 | Google Android arm-smmu-v3 arm-smmu-v3.c smmu_detach_dev privileges management
A vulnerability classified as critical was found in Google Android. This vulnerability affects the function smmu_detach_dev of the file arm-smmu-v3.c of the component arm-smmu-v3. Executing a manipulation can lead to improper privilege mana
CVE-2026-58728 | Google Android ARM64 MMU mmu.h ARM64_TLBI race condition
A vulnerability marked as very critical has been reported in Google Android. Affected by this vulnerability is the function ARM64_TLBI of the file mmu.h of the component ARM64 MMU. This manipulation causes race condition. The identification
CVE-2026-58695 | Google Android phy_power.c gmc_phy_lp3_exit_restore_registers memory corruption
A vulnerability was found in Google Android. It has been classified as critical. This affects the function gmc_phy_lp3_exit_restore_registers of the file phy_power.c. The manipulation leads to memory corruption. This vulnerability is traded
DFN-CERT-2026-4853 Xcode: Eine Schwachstelle ermöglicht das Ausspähen von Informationen
Gruppenleiter*in Managed Windows ServerBerlin, Home Office. SBK Siemens-Betriebskrankenkasse. IT-Anwendungsbetreuer DMS &amp; Archivsystem – d.3 ... Weiterlesen
Angreifer nehmen Sicherheitslücke im WooCommerce Wholesale Lead Capture-Plugin ins Visier
Im WordPress-Plugin WooCommerce Wholesale Lead Capture wurde eine Schwachstelle bekannt, über die sich ohne Anmeldung beliebige Dateien auf ... Weiterlesen
CVE-2024-45059 | portabilis i-educar up to 2.8 GET Parameter clsCampos.inc.php sql injection
A vulnerability was found in portabilis i-educar up to 2.8 and classified as critical. This affects an unknown function of the file ieducar/intranet/include/clsCampos.inc.php of the component GET Parameter Handler. The manipulation results
CVE-2022-44023 | PwnDoc up to 0.5.3 Authentication timing discrepancy (Issue 382 / EUVD-2022-46985)
A vulnerability marked as critical has been reported in PwnDoc up to 0.5.3. Affected by this vulnerability is an unknown functionality of the component Authentication Handler. The manipulation leads to observable timing discrepancy. This vu
CVE-2022-44022 | PwnDoc up to 0.5.3 Authentication timing discrepancy (Issue 381 / EUVD-2022-46984)
A vulnerability labeled as critical has been found in PwnDoc up to 0.5.3. Affected is an unknown function of the component Authentication Handler. Executing a manipulation can lead to observable timing discrepancy. This vulnerability is reg
CVE-2022-44019 | total.js Metacharacter /api/common/ping host os command injection (Issue 12 / 0e5ace7)
A vulnerability identified as critical has been detected in total.js. This impacts an unknown function of the file /api/common/ping of the component Metacharacter Handler. Performing a manipulation of the argument host results in os command
CVE-2022-44018 | Softing uaToolkit Embedded up to 1.40.0 PubSub Discovery Announcement Message null pointer dereference (EUVD-2022-46981)
A vulnerability was found in Softing uaToolkit Embedded up to 1.40.0. It has been classified as problematic. This impacts an unknown function of the component PubSub Discovery Announcement Message Handler. The manipulation leads to null poi
CVE-2024-44964 | Linux Kernel up to 6.10.4 idpf vport_open memory leak (6b289f8d9153/f01032a2ca09 / Nessus ID 213014)
A vulnerability was found in Linux Kernel up to 6.10.4 and classified as critical. The affected element is the function vport_open of the component idpf. The manipulation results in memory leak. This vulnerability is identified as CVE-2024-
CVE-2024-44963 | Linux Kernel up to 6.10.4 btrfs allocation of resources (98251cd60b4d/bb3868033a4c / Nessus ID 212724)
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.10.4. Affected by this vulnerability is an unknown functionality of the component btrfs. The manipulation leads to allocation of resources. This vulnerabili
CVE-2024-44962 | Linux Kernel up to 6.6.45/6.10.4 Bluetooth timer_shutdown_sync denial of service (4d9adcb94d55/28bbb5011a97/0d0df1e750ba / Nessus ID 212724)
A vulnerability has been found in Linux Kernel up to 6.6.45/6.10.4 and classified as problematic. Impacted is the function timer_shutdown_sync of the component Bluetooth. The manipulation leads to denial of service. This vulnerability is re
CVE-2024-44961 | Linux Kernel up to 6.6.45/6.10.4 AMD GPU buffer overflow (0da0b06165d8/c28d207edfc5/829798c789f5 / Nessus ID 212724)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.45/6.10.4. This vulnerability affects unknown code of the component AMD GPU. Performing a manipulation results in buffer overflow. This vulnerabilit
CVE-2024-44960 | Linux Kernel up to 6.10.4 gadget null pointer dereference (Nessus ID 208245 / WID-SEC-2024-2057)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.10.4. Affected is an unknown function of the component gadget. Executing a manipulation can lead to null pointer dereference. This vulnerability is register
CVE-2026-77822 | IBM ContextForge MCP Gateway up to 1.0.8 server-side request forgery
A vulnerability was found in IBM ContextForge MCP Gateway up to 1.0.8. It has been classified as critical. This affects an unknown function. The manipulation leads to server-side request forgery. This vulnerability is traded as CVE-2026-778
CVE-2026-84933 | undici prior 7.29.1/8.10.2 Cache Interceptor information disclosure (EUVD-2026-71518)
A vulnerability identified as problematic has been detected in undici. Affected is an unknown function of the component Cache Interceptor. This manipulation causes information disclosure. The identification of this vulnerability is CVE-2026
CVE-2019-7105 | Adobe XD up to 16.0 path traversal (APSB19-22)
A vulnerability, which was classified as critical, has been found in Adobe XD up to 16.0. This affects an unknown part. Performing a manipulation results in path traversal. This vulnerability was named CVE-2019-7105. The attack may be initi
CVE-2026-71362 | Adobe Commerce/Commerce B2B/Magento Open Source improper authorization
A vulnerability marked as critical has been reported in Adobe Commerce, Commerce B2B and Magento Open Source. This affects an unknown function. The manipulation leads to improper authorization. This vulnerability is referenced as CVE-2026-7
CVE-2025-15267 | Bold Page Builder Plugin up to 5.5.7 on WordPress bt_bb_accordion_item cross site scripting (EUVD-2025-206898)
A vulnerability categorized as problematic has been discovered in Bold Page Builder Plugin up to 5.5.7 on WordPress. The impacted element is the function bt_bb_accordion_item. Executing a manipulation can lead to cross site scripting. This
CVE-2019-7106 | Adobe XD up to 16.0 path traversal (APSB19-22)
A vulnerability, which was classified as critical, was found in Adobe XD up to 16.0. This vulnerability affects unknown code. Executing a manipulation can lead to path traversal. The identification of this vulnerability is CVE-2019-7106. Th
[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Privilegieneskalation und Denial of Service
Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel für eine Privilegieneskalation ausnutzen, sowie um einen Denial of Service Zustand oder andere, nicht spezifizierte Auswirkungen herbeizuführen. Weiterlesen
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b
CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca
CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb
CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a
CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution
CVE-2026-82600 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be in
CVE-2026-81315 | Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins: nil, origin_allowed?/3 accepts an origin when uri.host == conn.host and the forwarded scheme is https. Both values are attacker-controlled: conn.host comes from the Host header and the
Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Ser
CVE-2026-77956 | Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as
Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2.
CVE-2026-82599 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path tr
CVE-2026-82598 | A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate th
CVE-2026-82597 | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remo
CVE-2026-82596 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a manipulation can lead to memory corruption. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has no
A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a man
CVE-2026-82595 | A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results
CVE-2026-82594 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an i
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remot
CVE-2026-82593 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based b
CVE-2026-82592 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-ba
CVE-2026-82591 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewI