| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-52101 | Cri | 0.52 | 9.1 | 0.01 | Jul 14, 2026 | An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go | ||
| CVE-2026-48327 | Cri | 0.59 | 9.0 | 0.00 | Jul 14, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | ||
| CVE-2026-48325 | Cri | 0.60 | 9.3 | 0.01 | Jul 14, 2026 | ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | ||
| CVE-2026-48324 | Cri | 0.59 | 9.1 | 0.01 | Jul 14, 2026 | ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to… | ||
| CVE-2026-48322 | Cri | 0.64 | 9.9 | 0.01 | Jul 14, 2026 | ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.… | ||
| CVE-2026-48321 | Cri | 0.60 | 9.3 | 0.00 | Jul 14, 2026 | ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by… | ||
| CVE-2026-48319 | Cri | 0.62 | 9.1 | 0.01 | Jul 14, 2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to… | ||
| CVE-2026-48318 | Cri | 0.64 | 9.9 | 0.01 | Jul 14, 2026 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended… | ||
| CVE-2026-48284 | Cri | 0.63 | 9.6 | 0.00 | Jul 14, 2026 | ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require… | ||
| CVE-2026-15773 | Cri | 0.00 | 9.6 | 0.00 | Jul 14, 2026 | Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | ||
| CVE-2026-53633 | Cri | 0.57 | 9.8 | 0.01 | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed… | ||
| CVE-2026-48359 | Cri | 0.62 | 9.6 | 0.01 | Jul 14, 2026 | Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive… | ||
| CVE-2026-48358 | Cri | 0.59 | 9.1 | 0.01 | Jul 14, 2026 | Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of… | ||
| CVE-2026-48356 | Cri | 0.61 | 9.3 | 0.01 | Jul 14, 2026 | Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of… | ||
| CVE-2026-48259 | Cri | 0.62 | 9.6 | 0.01 | Jul 14, 2026 | Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests,… | ||
| CVE-2026-47429 | Cri | 0.57 | 9.8 | 0.01 | Jul 14, 2026 | Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun… | ||
| CVE-2026-47428 | Cri | 0.55 | 9.6 | 0.01 | Jul 14, 2026 | Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary… | ||
| CVE-2026-15409 | Cri | 0.24 | 10.0 | 0.07 | KEV | Jul 14, 2026 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | |
| CVE-2026-13001 | Cri | 0.57 | 9.8 | 0.04 | Jul 14, 2026 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload… | ||
| CVE-2026-47767 | Cri | 0.57 | 9.8 | 0.01 | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a… | ||
| CVE-2026-45069 | Cri | 0.52 | 9.1 | 0.00 | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list… | ||
| CVE-2026-45063 | Cri | 0.52 | 9.1 | 0.00 | Jul 14, 2026 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress=… | ||
| CVE-2026-57092 | Cri | 0.00 | 9.9 | 0.01 | Jul 14, 2026 | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-56190 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-56188 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-56159 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-55944 | Cri | 0.00 | 9.8 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-55040 | Cri | 0.71 | 9.1 | 0.70 | KEV | Jul 14, 2026 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | |
| CVE-2026-55010 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-50518 | Cri | 0.01 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-50447 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-50380 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-15747 | Cri | 0.52 | 9.1 | 0.00 | Jul 14, 2026 | Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a… | ||
| CVE-2026-59891 | Cri | 0.55 | 9.6 | 0.00 | Jul 14, 2026 | sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because… | ||
| CVE-2026-58644 | Cri | 0.12 | 9.8 | 0.16 | KEV | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-55008 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-54990 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-54118 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-54117 | Cri | 0.64 | 9.8 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-54058 | Cri | 0.52 | 9.1 | 0.01 | Jul 14, 2026 | Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as… | ||
| CVE-2026-50522 | Cri | 0.18 | 9.8 | 0.03 | KEV | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | |
| CVE-2026-49798 | Cri | 0.00 | 9.3 | 0.00 | Jul 14, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-49172 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-48561 | Cri | 0.00 | 9.6 | 0.01 | Jul 14, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42990 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-15701 | Cri | 0.00 | 9.8 | 0.01 | Jul 14, 2026 | A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible… | ||
| CVE-2026-45262 | cri | 0.59 | — | — | Jul 14, 2026 | ## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A scoped `ApiKey` with `fullaccess=0` and an `ApiAccess` row granting `allowget=1` on the `clientes` resource only (no other rights, no UI session, no admin) issued one `GET… | ||
| CVE-2026-60082 | Cri | 0.52 | 9.1 | 0.01 | Jul 14, 2026 | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller… | ||
| CVE-2026-55954 | Cri | 0.52 | — | 0.01 | Jul 14, 2026 | Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not… | ||
| CVE-2025-11698 | Cri | 0.60 | — | 0.00 | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault… |
- risk 0.52cvss 9.1epss 0.01
An issue in andreimarcu linux-server v.1.0 through v.2.3.8 allows a remote attacker to obtain sensitive information via the function uploadRemote function in upload.go
- risk 0.59cvss 9.0epss 0.00
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- risk 0.60cvss 9.3epss 0.01
ColdFusion is affected by a Missing Authentication for Critical Function vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
- risk 0.59cvss 9.1epss 0.01
ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…
- risk 0.64cvss 9.9epss 0.01
ColdFusion is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code.…
- risk 0.60cvss 9.3epss 0.00
ColdFusion is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain unauthorized read and write access. The vulnerable component is restricted to an administrative network zone by…
- risk 0.62cvss 9.1epss 0.01
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to…
- risk 0.64cvss 9.9epss 0.01
ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended…
- risk 0.63cvss 9.6epss 0.00
ColdFusion is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require…
- risk 0.00cvss 9.6epss 0.00
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.57cvss 9.8epss 0.01
Vitest is a testing framework powered by Vite. From 3.0.0 until 3.2.5, 4.1.8, and 5.0.0-beta.4, Vitest Browser Mode exposed a cdp() API that forwarded raw Chrome DevTools Protocol methods without being gated by allowWrite or allowExec, allowing a remote client with exposed…
- risk 0.62cvss 9.6epss 0.01
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to read sensitive…
- risk 0.59cvss 9.1epss 0.01
Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of…
- risk 0.61cvss 9.3epss 0.01
Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of…
- risk 0.62cvss 9.6epss 0.01
Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side requests,…
- risk 0.57cvss 9.8epss 0.01
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun…
- risk 0.55cvss 9.6epss 0.01
Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary…
- risk 0.24cvss 10.0epss 0.07
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
- risk 0.57cvss 9.8epss 0.04
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload…
- risk 0.57cvss 9.8epss 0.01
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a…
- risk 0.52cvss 9.1epss 0.00
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list…
- risk 0.52cvss 9.1epss 0.00
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress=…
- risk 0.00cvss 9.9epss 0.01
Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
- risk 0.00cvss 9.8epss 0.01
Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.01
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
- risk 0.71cvss 9.1epss 0.70
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
- risk 0.01cvss 9.8epss 0.01
Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.6epss 0.01
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
- risk 0.52cvss 9.1epss 0.00
Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a…
- risk 0.55cvss 9.6epss 0.00
sigstore-js provides JavaScript libraries for interacting with Sigstore services. Prior to 0.7.1, getRegistryCredentials() reads credentials from the Docker config file and selects an entry by checking whether any configured auth key contains the target registry string. Because…
- risk 0.12cvss 9.8epss 0.16
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.52cvss 9.1epss 0.01
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as…
- risk 0.18cvss 9.8epss 0.03
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.3epss 0.00
Use after free in Windows Kernel allows an unauthorized attacker to elevate privileges locally.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.6epss 0.01
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.01
Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.
- risk 0.00cvss 9.8epss 0.01
A weakness has been identified in Totolink NR1800X 9.1.0u.6279_B20210910. Affected by this issue is the function Form_Logout of the file /formLogout.htm of the component lighttpd. This manipulation of the argument Host causes stack-based buffer overflow. The attack is possible…
- risk 0.59cvss —epss —
## Summary > **Live PoC verified 2026-04-30** against a stock FacturaScripts master at `127.0.0.1:8081`. A scoped `ApiKey` with `fullaccess=0` and an `ApiAccess` row granting `allowget=1` on the `clientes` resource only (no other rights, no UI session, no admin) issued one `GET…
- risk 0.52cvss 9.1epss 0.01
DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller…
- risk 0.52cvss —epss 0.01
Authentication Bypass by Spoofing vulnerability in ueberauth ueberauth_apple allows account takeover via unvalidated ID token claims. The Ueberauth.Strategy.Apple.Token.payload/2 function verifies the JWT signature of the callback id_token against Apple's JWKS but does not…
- risk 0.60cvss —epss 0.00
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault…