CVE-2026-90804: Schwachstellen-Eintrag (NVD)
A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-15 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-77866 | Slab safeurl server-side request forgery (EUVD-2026-78678)
A vulnerability, which was classified as critical, was found in Slab safeurl. Affected by this issue is some unknown functionality. Executing a manipulation can lead to server-side request forgery. This vulnerability is registered as CVE-20
CVE-2026-65831 | ArcadeData ArcadeDB/ArcadeDB Server up to 26.7.0 Polyglot Query Engine /api/v1/command PolyglotQueryEngine.command Language improper authorization (EUVD-2026-78662)
A vulnerability identified as problematic has been detected in ArcadeData ArcadeDB and ArcadeDB Server up to 26.7.0. Affected by this issue is the function PolyglotQueryEngine.command of the file /api/v1/command of the component Polyglot Qu
CVE-2026-90786 | Dvidelabs flatcc up to 0.6.3 Duplicate Symbol src/compiler/semantics.c align_order_members assertion (Issue 387 / EUVD-2026-77478)
A vulnerability was found in Dvidelabs flatcc up to 0.6.3. It has been rated as problematic. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol Handler. This manipulation cau
CVE-2026-91934 | FlowiseAI Flowise up to 3.1.3 SQL Database Chain Node path traversal (EUVD-2026-78792)
A vulnerability described as critical has been identified in FlowiseAI Flowise up to 3.1.3. Impacted is an unknown function of the component SQL Database Chain Node. Executing a manipulation can lead to path traversal. This vulnerability is
CVE-2026-91929 | FlowiseAI Flowise up to 3.1.3 Enterprise Endpoints improper authorization (EUVD-2026-78787)
A vulnerability, which was classified as problematic, has been found in FlowiseAI Flowise up to 3.1.3. The impacted element is an unknown function of the component Enterprise Endpoints. The manipulation leads to improper authorization. This
CVE-2026-90805 | subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578 doctorlogin.php doc_mail/doc_pswd sql injection (EUVD-2026-77681)
A vulnerability categorized as critical has been discovered in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation o
CVE-2026-57583 | OpenZeppelin Contracts Wizard prior 0.10.11/3.0.1/0.6.2/0.3.1 Comment Generation setInfo securityContact/license code injection (CNNVD-2026-96801169)
A vulnerability categorized as problematic has been discovered in OpenZeppelin Contracts Wizard. This affects the function setInfo of the component Comment Generation. Executing a manipulation of the argument securityContact/license can lea
CVE-2026-7208 | Yealink SIP-T33G prior 124.87.0.0 File Deletion Endpoint race condition (CNNVD-2026-97242179)
A vulnerability classified as critical has been found in Yealink SIP-T33G. This vulnerability affects unknown code of the component File Deletion Endpoint. This manipulation causes race condition. The identification of this vulnerability is
CVE-2026-18151 | IBM i 7.3/7.4/7.5/7.6 WebSocket Handshake race condition (CNNVD-2026-97778860)
A vulnerability, which was classified as problematic, was found in IBM i 7.3/7.4/7.5/7.6. Affected by this vulnerability is an unknown functionality of the component WebSocket Handshake. Executing a manipulation can lead to race condition.
CVE-2026-82783 | Contec Programmable Remote I/O Coupler Unit CPSN-PCB271-S1-041 missing encryption (CNNVD-2026-98851012)
A vulnerability, which was classified as problematic, has been found in Contec Remote IO Coupler Unit CPSN-MCB271-*, O Coupler Unit CPSN-EOB471EI- and Programmable Remote IO Coupler Unit CPSN-PCB271-S1-041. This impacts an unknown function.
CVE-2026-82431 | Apache Storm Nimbus authorization (CNNVD-2026-98874501)
A vulnerability, which was classified as critical, has been found in Apache Storm. This affects an unknown function of the component Nimbus. Performing a manipulation results in authorization bypass. This vulnerability is reported as CVE-20
USN-8770-1: SimpleSAMLphp vulnerabilities
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privileges. This issue only affected Ubuntu 1
Cisco email security boxes can be rooted by... an email
Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gatew
Cisco warns customers of actively exploited zero-day in email gateways
Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday. The vulnerability — CVE-2026-76461 — was exploited before Cisco disclosed
CVE-2026-73180 | Apache Tomcat up to 11.0.24 Session Expiration session expiration (EUVD-2026-66192 / Nessus ID 345835)
A vulnerability described as critical has been identified in Apache Tomcat up to 7.0.109/8.5.100/9.0.120/10.1.57/11.0.24. This affects an unknown part of the component Session Expiration. Executing a manipulation can lead to session expirat
CVE-2026-12548 | Red Hat libsoup HTTP Headers Parsing soup_headers_parse length out-of-bounds (Nessus ID 345832)
A vulnerability identified as critical has been detected in Red Hat libsoup. Affected by this issue is the function soup_headers_parse of the component HTTP Headers Parsing. This manipulation of the argument length causes out-of-bounds read
CVE-2026-68763 | Apache Tomcat up to 11.0.24/10.1.57/9.0.120/8.5.100 HTTP/2 Backlog Tracking allocation of resources (EUVD-2026-66190 / Nessus ID 345835)
A vulnerability marked as problematic has been reported in Apache Tomcat up to 11.0.24/10.1.57/9.0.120/8.5.100. Affected by this issue is some unknown functionality of the component HTTP2 Backlog Tracking. Performing a manipulation results
CVE-2026-68525 | Apache Tomcat up to 11.0.24 Form Authentication improper authorization (EUVD-2026-66132 / Nessus ID 345835)
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.120/10.1.57/11.0.24. It has been declared as critical. This issue affects some unknown processing of the component Form Authentication. Such manipulation leads to improper
CVE-2026-84445 | gRPC-Go prior 1.82.2/1.83.2 xDS Routing Interceptor out-of-bounds (Nessus ID 345841)
A vulnerability classified as problematic was found in gRPC-Go. This issue affects some unknown processing of the component xDS Routing Interceptor. Executing a manipulation can lead to out-of-bounds read. This vulnerability appears as CVE-
CVE-2026-66422 | Apache Tomcat up to 11.0.24 Request.isUserInRole improper authorization (EUVD-2026-66131 / Nessus ID 345835)
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.120/10.1.57/11.0.24. It has been classified as critical. This vulnerability affects the function Request.isUserInRole. This manipulation causes improper authorization. Thi
CVE-2022-44017 | Simmeth Lieferantenmanager up to 5.5 /LMS/LM/#main user session (EUVD-2022-46980)
A vulnerability described as critical has been identified in Simmeth Lieferantenmanager up to 5.5. Impacted is an unknown function of the file /LMS/LM/#main. Executing a manipulation can lead to manage user sessions. This vulnerability is r
CVE-2022-44011 | ClickHouse heap-based overflow (EUVD-2022-46974)
A vulnerability categorized as critical has been discovered in ClickHouse. This affects an unknown part. The manipulation results in heap-based buffer overflow. This vulnerability is reported as CVE-2022-44011. The attacker must have access
CVE-2022-44010 | ClickHouse HTTP Endpoint heap-based overflow (EUVD-2022-46973)
A vulnerability classified as critical has been found in ClickHouse. The impacted element is an unknown function of the component HTTP Endpoint. The manipulation leads to heap-based buffer overflow. This vulnerability is uniquely identified
CVE-2022-44009 | StackStorm 3.7.0 Key-Value RBAC information disclosure (EUVD-2022-46972)
A vulnerability classified as problematic was found in StackStorm 3.7.0. The affected element is an unknown function of the component Key-Value RBAC Handler. Executing a manipulation can lead to information disclosure. This vulnerability ap
CVE-2022-44008 | BACKCLICK Professional 5.9.63 Back-End Tomcat Server information disclosure (SYSS-2022-037 / EUVD-2022-46971)
A vulnerability, which was classified as problematic, has been found in BACKCLICK Professional 5.9.63. This affects an unknown function of the component Back-End Tomcat Server. Performing a manipulation results in information disclosure. Th
CVE-2025-9236 | Portabilis i-Educar up to 2.10 Tipos de usuàrio Page educar_tipo_usuario_lst.php nm_tipo/descrição sql injection (EUVD-2025-25381)
A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument
CVE-2024-44957 | Linux Kernel up to 6.6.45/6.10.4 privcmd irqfd_wakeup deadlock (c2775ae4d922/49f2a5da6785/1c682593096a / Nessus ID 212724)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.6.45/6.10.4. The affected element is the function irqfd_wakeup of the component privcmd. Such manipulation leads to deadlock. This vulnerability is traded as CVE-202
CVE-2024-44959 | Linux Kernel up to 6.6.45/6.10.4 tracefs i_lru initialization (726f4c241e17/061da60716ce/0b6743bd60a5 / Nessus ID 212724)
A vulnerability identified as problematic has been detected in Linux Kernel up to 6.6.45/6.10.4. This affects the function i_lru of the component tracefs. Performing a manipulation results in improper initialization. This vulnerability is r
CVE-2024-44954 | Linux Kernel up to 6.10.4 line6 race condition (Nessus ID 208245 / WID-SEC-2024-2057)
A vulnerability classified as problematic has been found in Linux Kernel up to 6.10.4. Affected by this issue is some unknown functionality of the component line6. This manipulation causes race condition. This vulnerability is handled as CV
CVE-2024-44956 | Linux Kernel up to 6.10.4 preempt_fence_work_func deadlock (458bb83119df/3cd1585e5790 / Nessus ID 212724)
A vulnerability was found in Linux Kernel up to 6.10.4 and classified as critical. This vulnerability affects the function preempt_fence_work_func. Executing a manipulation can lead to deadlock. This vulnerability is tracked as CVE-2024-449
CVE-2024-44955 | Linux Kernel up to 6.10.4 AMD Display is_dsc_need_re_compute null pointer dereference (39b217193729/fcf6a49d7992 / Nessus ID 234782)
This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all. Weiterlesen
CVE-2024-44953 | Linux Kernel up to 6.10.4 scsi kworker/0 ufshcd_rpm_get_sync deadlock (f13f1858a28c/3911af778f20 / Nessus ID 212724)
A vulnerability described as critical has been identified in Linux Kernel up to 6.10.4. Affected by this vulnerability is the function ufshcd_rpm_get_sync of the file kworker/0 of the component scsi. The manipulation results in deadlock. Th
<b>Windows</b>-Update-Panne: Microsoft reagiert mit Notfall-Patch - it-daily.net
Windows Server 2025: KB5129235. Bei den Server-Versionen korrigieren die Patches konkret jene Fehler, die durch die Updates KB5122871 (Windows Server ... Weiterlesen
USN-8764-1: SRT vulnerabilities
It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an encrypted connection and inject arbitrary content or interrupt a media stream. (CVE-2026-55
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für <b>Windows</b> - Golem.de
Unter Windows 10 und Windows Server wurde CVE-2026-62721 zum September-Patchday bereits geschlossen. Microsoft hatte es aber nach eigenen Angaben ... Weiterlesen
USN-8763-1: kitty vulnerabilities
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands. (CVE-2026-42850) It was discovered tha
Wärtsilä FOS-Onboard
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to deliver an unauthorized update, execute code, or extract credentials to allow the attacker to impersonate a privileged client. The following versi
Siemens Reyrolle 7SR5
View CSAF Summary Siemens Reyrolle 7SR5 Before V2.70 is affected by multiple vulnerabilities. Siemens has released a new version for Reyrolle 7SR5 and recommends to update to the latest version. The following versions of Siemens Reyrolle 7S
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b
CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca
CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb
CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a
CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution
CVE-2026-82600 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be in
CVE-2026-81315 | Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins: nil, origin_allowed?/3 accepts an origin when uri.host == conn.host and the forwarded scheme is https. Both values are attacker-controlled: conn.host comes from the Host header and the
Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Ser
CVE-2026-77956 | Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as
Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2.
CVE-2026-82599 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path tr
CVE-2026-82598 | A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate th
CVE-2026-82597 | A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remo
CVE-2026-82596 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a manipulation can lead to memory corruption. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has no
A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a man
CVE-2026-82595 | A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results
CVE-2026-82594 | A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an i
A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remot
CVE-2026-82593 | A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based b
CVE-2026-82592 | A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-ba
CVE-2026-82591 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewI