Aggregator
CVE-2026-30689 | blog.admin up to 8.0 API Interface getinfobytoken access control
1 week 5 days ago
A vulnerability was found in blog.admin up to 8.0. It has been rated as problematic. Affected is the function getinfobytoken of the component API Interface. Performing a manipulation results in improper access controls.
This vulnerability was named CVE-2026-30689. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-1496 | Black Duck Coverity prior 2025.12.1 API Endpoint /token authorization
1 week 5 days ago
A vulnerability was found in Black Duck Coverity up to 2024.12.1/2025.3.1/2025.6.3/2025.9.2/2025.12.0. It has been declared as critical. This impacts an unknown function of the file /token of the component API Endpoint. Such manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-1496. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-30304 | AI Code Terminal Command injection
1 week 5 days ago
A vulnerability was found in AI Code. It has been classified as critical. This affects an unknown function of the component Terminal Command Handler. This manipulation causes injection.
This vulnerability is handled as CVE-2026-30304. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-27877 | Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 Public Dashboard information disclosure
1 week 5 days ago
A vulnerability was found in Grafana up to 11.6.13/12.1.9/12.2.7/12.3.5/12.4.1 and classified as problematic. The impacted element is an unknown function of the component Public Dashboard Handler. The manipulation results in information disclosure.
This vulnerability is known as CVE-2026-27877. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-69986 | LSC Indoor Camera 7.6.32 ONVIF Service GetStreamUri stack-based overflow
1 week 5 days ago
A vulnerability has been found in LSC Indoor Camera 7.6.32 and classified as critical. The affected element is the function GetStreamUri of the component ONVIF Service. The manipulation leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2025-69986. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-30303 | MatterAI Axon Code Parser os command injection
1 week 5 days ago
A vulnerability, which was classified as critical, was found in MatterAI. Impacted is an unknown function of the component Axon Code Parser. Executing a manipulation can lead to os command injection.
This vulnerability appears as CVE-2026-30303. The attack may be performed from remote. There is no available exploit.
vuldb.com
Spotify 寻求安娜的档案赔偿 3 亿美元
1 week 5 days ago
Spotify 和唱片公司请求法庭对影子图书馆安娜的档案(Anna’s Archive)做出 3.22 亿美元的缺席判决。安娜的档案至今未回应针对它的诉讼。Spotify 等还寻求永久禁令,试图切断安娜的档案与域名和托管服务商之间的合作,将该网站从互联网上彻底清除。Spotify 和唱片公司去年底提起的诉讼已经导致安娜的档案失去了.org 等主域名和备用域名,但并没有让安娜的档案彻底消失,只是给它带来了些不便,迫使它不断更换域名和托管商。在最新递交到法庭的文件中,Spotify 和唱片公司要求安娜的档案向 Spotify 赔偿 3 亿美元,向索尼赔偿 750 万美元,向环球唱片(UMG)赔偿 750 万美元,向华纳赔偿 720 万美元。
WatchGuard security advisory (AV26-289)
1 week 5 days ago
Canadian Centre for Cyber Security
Submit #778514: Shenzhen Ruiming Technology Co., Ltd. Streamax Crocus O&M Platform 1.3.44 SQL Injection [Duplicate]
1 week 5 days ago
Submit #778514 / VDB-353143
Submit #778514: Shenzhen Ruiming Technology Co., Ltd. Streamax Crocus O&M Platform 1.3.44 SQL Injection [Duplicate]
1 week 5 days ago
Submit #778514 / VDB-353143
CVE-2026-5024 | D-Link DIR-513 1.10 /goform/formSetEmail curTime stack-based overflow
1 week 5 days ago
A vulnerability, which was classified as critical, has been found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formSetEmail. Performing a manipulation of the argument curTime results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is reported as CVE-2026-5024. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
Хочешь защититься от слежки? Следуй советам ФБР — и тебя будут следить еще сильнее
1 week 5 days ago
Почему использование VPN, которое советуют федеральные ведомства, может лишить защиты от слежки?
DragonForce
1 week 5 days ago
You must login to view this content
cohenido
CVE-2026-5023 | DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6 RepoMix Command src/tools/codebase.ts getCodebase/getRemoteCodebase/saveCodebase os command injection
1 week 5 days ago
A vulnerability classified as critical was found in DeDeveloper23 codebase-mcp up to 3ec749d237dd8eabbeef48657cf917275792fde6. This vulnerability affects the function getCodebase/getRemoteCodebase/saveCodebase of the file src/tools/codebase.ts of the component RepoMix Command Handler. Such manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-5023. The attack needs to be performed locally. Additionally, an exploit exists.
This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
Submit #778414: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Accepted]
1 week 5 days ago
Submit #778414 / VDB-353908
LtzHust2
Submit #778414: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Accepted]
1 week 5 days ago
Submit #778414 / VDB-353908
LtzHust2
Submit #778413: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Duplicate]
1 week 5 days ago
Submit #778413 / VDB-348871
LtzHust2
Submit #778413: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Duplicate]
1 week 5 days ago
Submit #778413 / VDB-348871
LtzHust2
Submit #778412: D-Link DIR-513 1.10 Stack-based Buffer Overflow [Duplicate]
1 week 5 days ago
Submit #778412 / VDB-350784
LtzHust2