Posts of last 24 hours
A vulnerability was found in Microsoft OneNote on Android. It has been classified as problematic. Impacted is an unknown function. Performing a manipulation results in improper authentication.
This vulnerability is known as CVE-2023-21721. Attacking locally is a requirement. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/220996
A vulnerability was found in Dropbox samly. It has been classified as critical. This affects the function Samly.SPHandler.validate_authresp of the file lib/samly/sp_handler.ex of the component SP Handler. The manipulation leads to insufficient verification of data authenticity.
This vulnerability is uniquely identified as CVE-2026-53425. The attack is possible to be carried out remotely. No exploit exists.
https://vuldb.com/vuln/393798
A vulnerability was found in django-cms django CMS up to 5.0.8 and classified as problematic. This affects the function render_object_structure of the component Placeholder Authorization. Such manipulation of the argument content_type_id/object_id leads to improper authorization.
This vulnerability is traded as CVE-2026-61663. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/393825
A vulnerability classified as problematic has been found in BigBlueButton up to 3.0.28. This issue affects some unknown processing of the file akka-bbb-apps/src/main/scala/org/bigbluebutton/core/apps/presentationpod/RemovePresentationPubMsgHdlr.scala of the component presentationpod. Performing a manipulation of the argument presentationId results in improper privilege management.
This vulnerability was named CVE-2026-55489. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/393904
A vulnerability labeled as problematic has been found in Cesanta Mongoose up to 7.21. This affects the function mg_ssi of the file src/ssi.c of the component Ssi. Executing a manipulation can lead to path traversal.
This vulnerability is tracked as CVE-2026-73255. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
https://vuldb.com/vuln/393803
Second French Baby Retailer Allegedly Breached the Same Morning, This Time With Building Entry Codes
A forum user posting as ChimeraZ is selling what they describe as the database of allobebe.fr, a French retailer of baby products and childcare equipment, covering 2,175,216 records across 1,136,058 people and spanning orders placed from 2006 through 2026.
https://darkwebinformer.com/second-french-baby-retailer-allegedly-breached-the-same-morning-this-time-with-building-entry-codes/
Nearly a Million French Customers of a Baby Goods Retailer Allegedly Exposed With Delivery Addresses
A forum user posting as ChimeraZ is selling what they describe as the database of madeinbebe.com, a French retailer of products for babies and children, comprising 1,359,546 invoice lines covering 960,106 people in 1.45GB of JSON.
https://darkwebinformer.com/nearly-a-million-french-customers-of-a-baby-goods-retailer-allegedly-exposed-with-delivery-addresses/
A vulnerability was found in Microsoft Office 2003/2007/2010. It has been rated as problematic. This impacts an unknown function in the library MSCOMCTL.OCX. This manipulation causes code injection.
This vulnerability is tracked as CVE-2012-0158. The attack is possible to be carried out remotely. Moreover, an exploit is present.
It is recommended to apply a patch to fix this issue.
https://vuldb.com/vuln/5048
A vulnerability categorized as problematic has been discovered in Microsoft SQL Server 2000/2005/2008. Affected is an unknown function in the library MSCOMCTL.OCX. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2012-0158. The attack may be performed from remote. In addition, an exploit is available.
Applying a patch is advised to resolve this issue.
https://vuldb.com/vuln/5049
A vulnerability identified as critical has been detected in SonicWALL SonicOS 6.0.5.3/6.5.1.12/6.5.4.7/6.5.4.v/7.0.0.0. Affected by this issue is some unknown functionality. This manipulation causes buffer overflow.
This vulnerability appears as CVE-2020-5135. The attack may be initiated remotely. In addition, an exploit is available.
https://vuldb.com/vuln/162494