Aggregator
注意喚起: 2026年6月マイクロソフトセキュリティ更新プログラムに関する注意喚起 (公開)
2 weeks ago
注意喚起: Adobe AcrobatおよびReaderの脆弱性(APSB26-63)に関する注意喚起 (公開)
2 weeks ago
CVE-2026-46542 | nimiq core-rs-albatross up to 1.3.x keys/src/multisig/mod.rs delinearize assertion (GHSA-h9cc-w26m-j342)
2 weeks ago
A vulnerability was found in nimiq core-rs-albatross up to 1.3.x. It has been classified as problematic. This affects the function Ed25519PublicKey::delinearize of the file keys/src/multisig/mod.rs. Performing a manipulation results in reachable assertion.
This vulnerability was named CVE-2026-46542. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-46411 | halfgaar FlashMQ up to 1.26.1 uncaught exception (GHSA-g35r-265r-rxrh)
2 weeks ago
A vulnerability was found in halfgaar FlashMQ up to 1.26.1 and classified as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to uncaught exception.
This vulnerability is uniquely identified as CVE-2026-46411. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-53675 | BuddyPress up to 14.4.0 Friends REST API get_items_permissions_check authorization
2 weeks ago
A vulnerability has been found in BuddyPress up to 14.4.0 and classified as problematic. Affected by this vulnerability is the function get_items_permissions_check of the component Friends REST API. This manipulation causes authorization bypass.
This vulnerability is handled as CVE-2026-53675. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-53674 | BuddyPress up to 14.4.0 Regular Expression data query logic injection
2 weeks ago
A vulnerability, which was classified as critical, was found in BuddyPress up to 14.4.0. Affected is an unknown function of the component Regular Expression Handler. The manipulation results in improper neutralization of special elements in data query logic.
This vulnerability is known as CVE-2026-53674. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-46545 | nimiq core-rs-albatross up to 1.4.x put_chunk uncaught exception (GHSA-mw3q-r9wh-h2ff)
2 weeks ago
A vulnerability, which was classified as problematic, has been found in nimiq core-rs-albatross up to 1.4.x. This impacts the function MerkleRadixTrie::put_chunk. The manipulation leads to uncaught exception.
This vulnerability is traded as CVE-2026-46545. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-46543 | nimiq core-rs-albatross up to 1.4.x macro_block_before assertion (GHSA-vghx-352f-93jm)
2 weeks ago
A vulnerability classified as problematic was found in nimiq core-rs-albatross up to 1.4.x. This affects the function Policy::macro_block_before. Executing a manipulation can lead to reachable assertion.
This vulnerability appears as CVE-2026-46543. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45782 | cloud-hypervisor Cloud Hypervisor up to 51.1 use after free (GHSA-f47p-p25q-83rh)
2 weeks ago
A vulnerability classified as critical has been found in cloud-hypervisor Cloud Hypervisor up to 51.1. The impacted element is an unknown function. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-45782. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-44716 | pipecat-ai pipecat up to 1.1.x HTTP Request run.py path path traversal (GHSA-3363-2ph6-35wh)
2 weeks ago
A vulnerability described as critical has been identified in pipecat-ai pipecat up to 1.1.x. The affected element is an unknown function of the file src/pipecat/runner/run.py of the component HTTP Request Handler. Such manipulation of the argument path leads to path traversal.
This vulnerability is documented as CVE-2026-44716. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-46540 | nimiq core-rs-albatross up to 1.3.x rebranch behavioral workflow (GHSA-m3pg-qc2q-mg8c)
2 weeks ago
A vulnerability marked as critical has been reported in nimiq core-rs-albatross up to 1.3.x. Impacted is the function LightBlockchain::rebranch. This manipulation causes enforcement of behavioral workflow.
This vulnerability is registered as CVE-2026-46540. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-46539 | nimiq core-rs-albatross up to 1.3.x data authenticity (GHSA-799f-29jm-gr6c)
2 weeks ago
A vulnerability labeled as problematic has been found in nimiq core-rs-albatross up to 1.3.x. This issue affects some unknown processing. The manipulation results in insufficient verification of data authenticity.
This vulnerability is cataloged as CVE-2026-46539. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-44505 | nimiq core-rs-albatross up to 1.3.x swarm.rs Network::dht_get exceptional condition (GHSA-g39c-jcgg-qwvr)
2 weeks ago
A vulnerability identified as problematic has been detected in nimiq core-rs-albatross up to 1.3.x. This vulnerability affects the function Network::dht_get of the file network-libp2p/src/swarm.rs. The manipulation leads to handling of exceptional conditions.
This vulnerability is listed as CVE-2026-44505. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-41837 | Vmware Spring Data REST up to 5.0.5 access control
2 weeks ago
A vulnerability categorized as critical has been discovered in Vmware Spring Data REST up to 3.7.19/4.3.16/4.4.14/4.5.11/5.0.5. This affects an unknown part. Executing a manipulation can lead to improper access controls.
This vulnerability is tracked as CVE-2026-41837. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-41730 | Vmware Spring Data REST up to 5.0.5 information exposure
2 weeks ago
A vulnerability was found in Vmware Spring Data REST up to 3.7.19/4.3.16/4.4.14/4.5.11/5.0.5. It has been rated as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in information exposure through error message.
This vulnerability is identified as CVE-2026-41730. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41729 | Vmware Spring Data REST up to 5.0.5 SpEL Expression expression language injection
2 weeks ago
A vulnerability was found in Vmware Spring Data REST up to 3.7.19/4.3.16/4.4.14/4.5.11/5.0.5. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component SpEL Expression Handler. Such manipulation leads to improper neutralization of special elements used in an expression language statement.
This vulnerability is referenced as CVE-2026-41729. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-41728 | Vmware Spring Data REST up to 5.0.5 access control
2 weeks ago
A vulnerability was found in Vmware Spring Data REST up to 3.7.19/4.3.16/4.4.14/4.5.11/5.0.5. It has been classified as critical. Affected is an unknown function. This manipulation causes improper access controls.
The identification of this vulnerability is CVE-2026-41728. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-46541 | nimiq core-rs-albatross up to 1.3.x handle_dht_get unusual condition (GHSA-ccqv-2c9q-mqw5)
2 weeks ago
A vulnerability was found in nimiq core-rs-albatross up to 1.3.x and classified as problematic. This impacts the function handle_dht_get. The manipulation results in improper check for unusual conditions.
This vulnerability was named CVE-2026-46541. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41732 | Vmware Spring for Apache Pulsar up to 1.1.17/1.2.17/2.0.5 JsonPulsarHeaderMapper deserialization
2 weeks ago
A vulnerability has been found in Vmware Spring for Apache Pulsar up to 1.1.17/1.2.17/2.0.5 and classified as problematic. This affects an unknown function of the component JsonPulsarHeaderMapper. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-41732. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com