Aggregator
疑似俄罗斯APT28组织重启高端定制,“复活”高端攻击武器工具链展开攻击活动
1 month 3 weeks ago
常见AI助手的安全漏洞
1 month 3 weeks ago
CVE-2026-30927 | admidio up to 5.0.5 User Management events_function.php possibleToParticipate user_uuid authorization
1 month 3 weeks ago
A vulnerability labeled as problematic has been found in admidio up to 5.0.5. Affected is the function possibleToParticipate of the file modules/events/events_function.php of the component User Management Handler. Such manipulation of the argument user_uuid leads to authorization bypass.
This vulnerability is listed as CVE-2026-30927. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-30885 | WWBN AVideo up to 24.x playlistsFromUser.json.php missing authentication
1 month 3 weeks ago
A vulnerability marked as critical has been reported in WWBN AVideo up to 24.x. Affected by this vulnerability is an unknown functionality of the file /objects/playlistsFromUser.json.php. Performing a manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-30885. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-30921 | oneuptime up to 10.0.19 this.constructor.constructor routine
1 month 3 weeks ago
A vulnerability marked as very critical has been reported in oneuptime up to 10.0.19. This vulnerability affects the function this.constructor.constructor. The manipulation leads to exposed dangerous routine.
This vulnerability is listed as CVE-2026-30921. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-30925 | parse-community parse-server up to 8.6.10/9.0.0 9.5.0-alpha.13 regex redos
1 month 3 weeks ago
A vulnerability has been found in parse-community parse-server up to 8.6.10/9.0.0 9.5.0-alpha.13 and classified as problematic. This impacts an unknown function. The manipulation of the argument regex leads to inefficient regular expression complexity.
This vulnerability is traded as CVE-2026-30925. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-30913 | flarum nicknames up to 1.8.2 Nicknames Extension cross site scripting
1 month 3 weeks ago
A vulnerability was found in flarum nicknames up to 1.8.2. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Nicknames Extension. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-30913. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-30918 | facileManager up to 6.0.3 log_search_query cross site scripting
1 month 3 weeks ago
A vulnerability marked as problematic has been reported in facileManager up to 6.0.3. The affected element is the function log_search_query. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2026-30918. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-30919 | facileManager up to 6.0.3 fmDNS cross site scripting
1 month 3 weeks ago
A vulnerability described as problematic has been identified in facileManager up to 6.0.3. The impacted element is an unknown function of the component fmDNS Module. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-30919. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-30920 | oneuptime up to 10.0.18 GitHub Endpoint installation_id data authenticity
1 month 3 weeks ago
A vulnerability classified as critical has been found in oneuptime up to 10.0.18. This affects an unknown function of the component GitHub Endpoint. Performing a manipulation of the argument installation_id results in insufficient verification of data authenticity.
This vulnerability is cataloged as CVE-2026-30920. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-30917 | weirdgloop mediawiki-extensions-Bucket up to 2.1.0 cross site scripting
1 month 3 weeks ago
A vulnerability, which was classified as problematic, has been found in weirdgloop mediawiki-extensions-Bucket up to 2.1.0. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-30917. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-30926 | SiYuan up to 3.5.9 API Endpoint appendHeadingChildren access control
1 month 3 weeks ago
A vulnerability was found in SiYuan up to 3.5.9. It has been rated as critical. This impacts an unknown function of the file /api/block/appendHeadingChildren of the component API Endpoint. The manipulation leads to improper access controls.
This vulnerability is listed as CVE-2026-30926. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-30935 | ImageMagick up to 7.1.2-15 out-of-bounds (EUVD-2026-10400)
1 month 3 weeks ago
A vulnerability labeled as critical has been found in ImageMagick up to 7.1.2-15. Affected by this issue is some unknown functionality. Such manipulation leads to out-of-bounds read.
This vulnerability is documented as CVE-2026-30935. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-30936 | ImageMagick up to 6.9.13-40/7.1.2-15 WaveletDenoiseImage heap-based overflow (EUVD-2026-10401)
1 month 3 weeks ago
A vulnerability marked as critical has been reported in ImageMagick up to 6.9.13-40/7.1.2-15. This affects the function WaveletDenoiseImage. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is reported as CVE-2026-30936. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-30929 | ImageMagick up to 6.9.13-40/7.1.2-15 Image Parser stack-based overflow (EUVD-2026-10395)
1 month 3 weeks ago
A vulnerability described as critical has been identified in ImageMagick up to 6.9.13-40/7.1.2-15. This vulnerability affects unknown code of the component Image Parser. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability appears as CVE-2026-30929. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-30931 | ImageMagick up to 7.1.2-15 UHDR Encoder heap-based overflow (EUVD-2026-10397)
1 month 3 weeks ago
A vulnerability, which was classified as critical, was found in ImageMagick up to 7.1.2-15. The impacted element is an unknown function of the component UHDR Encoder. Such manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2026-30931. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-28689 | ImageMagick up to 6.9.13-40/7.1.2-15 Image Parser link following (EUVD-2026-10381)
1 month 3 weeks ago
A vulnerability identified as critical has been detected in ImageMagick up to 6.9.13-40/7.1.2-15. This vulnerability affects unknown code of the component Image Parser. Performing a manipulation results in link following.
This vulnerability is cataloged as CVE-2026-28689. The attack must be initiated from a local position. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-28691 | ImageMagick Prior to up to 6.9.13-40/7.1.2-15 JBIG Decoder return value (EUVD-2026-10386)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, has been found in ImageMagick Prior to up to 6.9.13-40/7.1.2-15. Affected by this issue is some unknown functionality of the component JBIG Decoder. The manipulation leads to unchecked return value.
This vulnerability is traded as CVE-2026-28691. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-28693 | ImageMagick up to 6.9.13-40/7.1.2-15 DIB Coder out-of-bounds write (EUVD-2026-10389)
1 month 3 weeks ago
A vulnerability, which was classified as critical, was found in ImageMagick up to 6.9.13-40/7.1.2-15. This affects an unknown part of the component DIB Coder. The manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2026-28693. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com