Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-11 | 2026-09-24 |
|---|---|---|
| ≥90 % | 0 | 484 |
| ≥50 % | 0 | 1436 |
| ≥10 % | 0 | 16 |
| <10 % | 300 | 30 |
CVE-2026-71959 | Bitwarden Server up to 2026.7.1 Audit Log privileges management (WID-SEC-2026-2737)
A vulnerability labeled as problematic has been found in Bitwarden Server up to 2026.7.1. Affected by this issue is some unknown functionality of the component Audit Log. Executing a manipulation can lead to improper privilege management. T
CVE-2026-69102 | dromara MaxKey up to 4.1.11 Authentication application-maxkey.properties improper authorization
A vulnerability, which was classified as critical, has been found in dromara MaxKey up to 4.1.11. Affected by this issue is some unknown functionality of the file application-maxkey.properties of the component Authentication. Performing a m
CVE-2026-65660 | Microsoft SharePoint Enterprise/SharePoint Server code injection
A vulnerability was found in Microsoft SharePoint Enterprise and SharePoint Server. It has been classified as critical. This affects an unknown part. This manipulation causes code injection. This vulnerability is tracked as CVE-2026-65660.
CVE-2026-6811 | MongoDB PHP Driver 1.21.5/2.1.8 recursion
A vulnerability categorized as problematic has been discovered in MongoDB PHP Driver 1.21.5/2.1.8. The impacted element is an unknown function. The manipulation results in uncontrolled recursion. This vulnerability was named CVE-2026-6811.
CVE-2026-24181 | NVIDIA DALI array index
A vulnerability identified as critical has been detected in NVIDIA DALI. This vulnerability affects unknown code. The manipulation leads to improper validation of array index. This vulnerability is documented as CVE-2026-24181. The attack n
CVE-2026-24180 | NVIDIA DALI heap-based overflow
A vulnerability categorized as critical has been discovered in NVIDIA DALI. This affects an unknown part. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is registered as CVE-2026-24180. The attack needs
CVE-2026-97152 | Nanomsg up to 1.2.2 WebSocket Transport snprintf buffer overflow (Nessus ID 349708)
A vulnerability described as critical has been identified in Nanomsg up to 1.2.2. This affects the function snprintf of the component WebSocket Transport. Such manipulation leads to buffer overflow. This vulnerability is traded as CVE-2026-
CVE-2026-67218 | RabbitMQ up to 4.0.21/4.1.10/4.2.5 HTTP API rabbit_stream_reader.erl accept_content privileges management (Nessus ID 349709)
A vulnerability, which was classified as problematic, has been found in RabbitMQ up to 4.0.21/4.1.10/4.2.5. This affects the function accept_content of the file rabbit_stream_reader.erl of the component HTTP API. The manipulation leads to i
CVE-2026-66072 | RabbitMQ up to 4.3.0 Stream Plugin get_chunk_selector/1 input validation (Nessus ID 349710)
A vulnerability, which was classified as problematic, has been found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5/4.3.0. Affected is the function get_chunk_selector/1 of the component Stream Plugin. Performing a manipulation results in imp
CVE-2026-67231 | RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5 trust-store plugin extract_issuer_id certificate validation (Nessus ID 349713)
A vulnerability was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5. It has been classified as problematic. The affected element is the function extract_issuer_id of the component trust-store plugin. Performing a manipulation results in
CVE-2026-66080 | RabbitMQ up to 4.1.10/4.2.5 Stream Management validate_partitions allocation of resources (Nessus ID 349714)
A vulnerability, which was classified as problematic, was found in RabbitMQ up to 4.1.10/4.2.5. Affected by this vulnerability is the function validate_partitions of the component Stream Management. Executing a manipulation can lead to allo
CVE-2026-67229 | RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5 Data Coercion rabbit_data_coercion:atomize_keys resource consumption (Nessus ID 349716)
A vulnerability was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5. It has been declared as problematic. This issue affects the function rabbit_data_coercion:atomize_keys of the component Data Coercion. Such manipulation leads to resou
CVE-2026-83452 | Oracle Document Management and Collaboration up to 12.2.15 Internal Operations privileges management (Nessus ID 349717)
A vulnerability, which was classified as critical, has been found in Oracle Document Management and Collaboration up to 12.2.15. This affects an unknown part of the component Internal Operations. Performing a manipulation results in imprope
CVE-2026-83462 | Oracle Mobile Application Server up to 12.2.15 MWA Terminal Server privileges management (Nessus ID 349717)
A vulnerability was found in Oracle Mobile Application Server up to 12.2.15. It has been classified as critical. This issue affects some unknown processing of the component MWA Terminal Server. This manipulation causes improper privilege ma
CVE-2026-83327 | Oracle Applications Framework up to 12.2.15 Personalization privileges management (Nessus ID 349717)
A vulnerability has been found in Oracle Applications Framework up to 12.2.15 and classified as critical. Affected is an unknown function of the component Personalization. The manipulation leads to improper privilege management. This vulner
CVE-2026-19915 | HP Support Assistant up to 9.53.2.0 access control (Nessus ID 349720)
A vulnerability was found in HP Support Assistant 8.1.52.1/8.7.50.3/9.44.18.0/9.47.41.0/9.53.2.0. It has been declared as problematic. The impacted element is an unknown function. Such manipulation leads to improper access controls. This vu
USN-8820-1: curl vulnerabilities
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for LDAP authentication in certain circumstances. A machine-in-the-middle attacker could possibly use this issue to bypass peer validation. This issue only affected Ubuntu
CVE-2023-2426 | vim up to 9.0.1498 out-of-range pointer offset (EUVD-2023-33915)
A vulnerability identified as problematic has been detected in vim up to 9.0.1498. The affected element is an unknown function. This manipulation causes use of out-of-range pointer offset. This vulnerability is handled as CVE-2023-2426. It
CVE-2023-0433 | Apple macOS up to 13.2.1 Vim heap-based overflow (HT213670 / EUVD-2023-12490)
A vulnerability labeled as problematic has been found in Apple macOS up to 13.2.1. Affected by this vulnerability is an unknown functionality of the component Vim. Such manipulation leads to heap-based buffer overflow. This vulnerability is
CVE-2023-0288 | Apple macOS up to 13.2.1 Vim heap-based overflow (HT213670 / EUVD-2023-12366)
A vulnerability identified as problematic has been detected in Apple macOS up to 13.2.1. Affected is an unknown function of the component Vim. This manipulation causes heap-based buffer overflow. This vulnerability appears as CVE-2023-0288.
CVE-2023-0433 | vim up to 9.0.1189 heap-based overflow (EUVD-2023-12490)
A vulnerability was found in vim. It has been rated as critical. This issue affects some unknown processing. Performing a manipulation results in heap-based buffer overflow. This vulnerability is known as CVE-2023-0433. Remote exploitation
CVE-2022-3296 | vim up to 9.0.0552 stack-based overflow (EUVD-2022-42688 / Nessus ID 211239)
A vulnerability was found in vim and classified as critical. This vulnerability affects unknown code. Executing a manipulation can lead to stack-based buffer overflow. This vulnerability is tracked as CVE-2022-3296. The attack can be launch
CVE-2026-82371 | Brocade SANnav up to 3.0.0 Discovery Service missing encryption (EUVD-2026-86349)
A vulnerability was found in Brocade SANnav up to 3.0.0 and classified as problematic. This vulnerability affects unknown code of the component Discovery Service. Such manipulation leads to missing encryption of sensitive data. This vulnera
CVE-2026-75743 | Adobe Experience Manager Forms JEE 6.5 cross-site request forgery (EUVD-2026-84793)
A vulnerability was found in Adobe Experience Manager Forms JEE 6.5. It has been classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in cross-site request forgery. This vulnerab
CVE-2022-44731 | Siemens SIMATIC WinCC OA up to 3.14/3.15/3.16/3.17 Web Interface argument injection (ssa-547714 / EUVD-2022-47663)
A vulnerability was found in Siemens SIMATIC WinCC OA up to 3.14/3.15/3.16/3.17. It has been rated as critical. Affected is an unknown function of the component Web Interface Handler. This manipulation causes argument injection. This vulner
CVE-2022-44726 | TouchDown Timesheet Tracking Component 4.1.4 on Jira Calendar View cross site scripting (SYSS-2022-050 / EUVD-2022-47660)
A vulnerability was found in TouchDown Timesheet Tracking Component 4.1.4 on Jira. It has been rated as problematic. This impacts an unknown function of the component Calendar View. Performing a manipulation results in cross site scripting.
CVE-2022-44725 | OPC Foundation Local Discovery Server up to 1.04.403.478 Configuration File race condition (EUVD-2022-47659)
A vulnerability was found in OPC Foundation Local Discovery Server up to 1.04.403.478. It has been rated as critical. Affected by this issue is some unknown functionality of the component Configuration File Handler. Performing a manipulatio
CVE-2022-44724 | Stiltsoft Handy Macros for Confluence Server and Data Center Handy Tip Macro cross site scripting (EUVD-2022-47658)
A vulnerability marked as problematic has been reported in Stiltsoft Handy Macros for Confluence Server and Data Center up to 3.5.4. This affects an unknown part of the component Handy Tip Macro. The manipulation leads to cross site scripti
F5 Fixes BIG-IP APM Zero-Day Enabling Unauthenticated RCE
BIG-IP Access Policy Manager (APM) vulnerabilities have been patched by F5 as a result of zero-day attacks utilizing this vulnerability, which allows unauthenticated attackers to execute code on the system. As a result of this flaw, CVE-202
CVE-2026-81473 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
CVE-2026-97322 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the component File Upload. Performing a manipulation results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this dis
A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the comp
CVE-2026-57440 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not the default), the urls for videos are passed into an iframe src attribute without sanitization. When given a malformed url or id, the src attribute can be escaped via double quotes, allowing for html/javascript injection. V
The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (not
CVE-2026-86857 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that the user otherwise would not be entitled to access, potentially enabling further unintended access. ServiceNow deployed an update to hosted instances, and ServiceNow provided the update to our partners and self-hosted
ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform that
CVE-2026-52853 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external email address with the OWNER role because the role ceiling does not prevent ADMIN users from granting privileges above their own. When the invitation is accepted, the new account receives OWNER-level permissions, allowing the ADMIN to create a backdoor OWNER account or promote a col
Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external email address with the OWNER role because the role ceiling d
CVE-2026-61823 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits the `srcdoc` attribute on iframe elements. Although markup inside `srcdoc` is HTML-encoded during sanitization, browsers decode attribute entities before interpreting the iframe document, allowing an authenticated user with
code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permits t
CVE-2026-48072 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confinement to the intended image directory. An unauthenticated attacker can traverse outside the avatar or logo directory and read local storage objects whose final basename satisfies the route's UUID check. This issue is fixed in ver
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confinement
CVE-2026-97321 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service/goview/GoViewDataServiceImpl.java of the component GoView Data Endpoint. Such manipulation of the argument sql leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public a
A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/service
CVE-2026-52850 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId and transclusionId pair because the lookup does not enforce private space membership before resolving the source page. The API can return confidential sync-block content and source page metadata even though the normal page APIs
Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId and
Dji_ble_vuln
DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306 Weiterlesen
CVE-2026-13249 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authentication. An attacker could potentially exploit this vulnerability, leading to the execution of malicious files and commands. Honeywell also recommends updating to the most recent firmware version, Honeywell PD45 Industri
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authen
CVE-2026-48070 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This issue is fixed in version 0.80.1.
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory
CVE-2026-97320 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI Knowledge Module. This manipulation of the argument url causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure
A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI Knowledge Module. Thi
CVE-2026-62286 | Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returned by GET /api/events/stream. In a simple-auth deployment using per-user filters, any authenticated restricted account can receive resource telemetry and lifecycle events for containers outside its authorized label scope. The e
Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returned b
CVE-2026-85738 | TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An authenticated user who controls a DNS record can supply a URL whose AAAA result is a transition address embedding a private, loopback, or link-local IPv4 target, and isAlwaysBlocked and isPrivateNetwork classify the address as allowed. In a deploymen
TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An authenticated user who cont
CVE-2026-77293 | TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/services/collabService.ts resolves the target only by note and file identifiers without requiring the file to belong to that trip. A user with edit access to any trip can submit identifiers belonging to another user's trip and p
TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/servi
CVE-2026-77320 | TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables share_map. The client hides the map, but the public JSON response still includes the itinerary and place names, coordinates, addresses, descriptions, notes, and prices. Anyone holding the valid share token can therefore read location and
TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables share_map. The
CVE-2026-77321 | TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of the delegated scopes. A token granted only an unrelated capability, such as weather:read, can receive trip metadata, member email addresses from server/src/services/tripService.ts, itinerary days, and accommodations for every tr
TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of the d
CVE-2026-77294 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip instance is required to trigger the vulnerable AI-assisted import path. The value is consumed by the clients in server/src/nest/llm-parse/clients/openai-compatible.client.ts, server/src/nest/llm-parse/clients/anthropic.client.
TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip ins
CVE-2026-93405 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview document through innerHTML without sanitization. A remote sender can craft a supported attachment whose converted HTML executes script when a recipient opens quick preview. The preview renderer has no direct Node or Electron a
Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview doc
CVE-2026-61816 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled resource consumption / algorithmic complexity vulnerability (CWE-400) affects any application that parses untrusted email with this library. Three independent parsing paths are super-linear in cost, so a byte-size cap on t
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrolled
CVE-2026-61815 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header injection (CWE-93) affecting any application that uses this library to build or forward MIME messages with an attacker-influenced attachment filename. Attachment filenames are interpolated into the `Content-Type` and `Content-
zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header inj
CVE-2026-81508 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the received media buffer before validating that the packet layout contains the field. A paired BR/EDR audio source within radio range can send a malformed A2DP media packet to a build with BlueDroid Classic Bluetooth and A2DP sink support enabled, causing an out-of-bo
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the received media buffer before validating th
CVE-2026-71540 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the size declared in a 20-byte cluster protocol header before Fernet decryption validates the peer. An unauthenticated network peer can declare a payload of up to 256 MiB, stop sending after the header, and retain that allocation
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the si
CVE-2026-61741 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInstance` without any security configuration. With the JDK's default settings, the parser resolves DOCTYPE declarations, external general and parameter entities, and external DTDs.An application that uses these decoders to par
http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions 0.24.1 and 1.0.0-M39, these decoders used a `javax.xml.parsers.SAXParserFactory` obtained from `SAXParserFactory.newInst
CVE-2026-61811 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute without a depth limit while allocating two large local buffers in each stack frame. An enrolled agent can submit a Windows EventChannel event containing an element with enough attributes to exhaust the analysisd worker-threa
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.8.0 until 4.14.7, the _getattributes() function in src/os_xml/os_xml.c recursively processes every XML attribute w
CVE-2026-61604 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved address belonged to the transaction signer. Affected handlers included MsgMakeOutcomePayment, MsgBuy, MsgSell, MsgSwap, and MsgWithdrawShare, as well as the batch order processor. Because any account may list an arbitrary bl
The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds module moved funds from an address that was resolved from a DID verification method, without verifying that the resolved a
CVE-2026-61732 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Under the BYOK (Bring Your Own Key) deployment model, users configure their own LLM credentials to any OpenAI-compatible endpoint. Most open-source and self-deployed model providers (vLLM, SGLang, Ollama, LM Studio, text-gene
Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals. Un
CVE-2026-63645 | OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keyword filter. The filter does not recognize dsn or creds field names, so meta_postgres_dsn, meta_postgres_ro_dsn, meta_ddl_dsn, and usage_reporting_creds can be returned in plaintext to an unauthenticated network client. Postg
OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields keywo
CVE-2026-54461 | Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expression. An authenticated caller can supply a computationally expensive regular expression that degrades application performance or halts Node.js processes. This issue is fixed in version 5.48.2.
Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular expr
CVE-2026-61788 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set PostgreSQL `default_transaction_read_only=on` (and open SQLite in `readOnly` mode), but that code is gated on a config value that is never populated, so it never runs. The only thing left enforcing read-only is a classifier
DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to set