Latest CVE

Latest Vulnerabilities

  • CVE-2026-108119 - Busybox: busybox: tar extraction-root escape via deferred symlink/hardlink creation bypasses cve-2026-26158 fix

    CVE ID :CVE-2026-108119
    Published : Oct. 9, 2026, 4:45 p.m. | 15 minutes ago
    Description :A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and hardlink entries with unsafe-looking targets does not validate that the resolved destination remains inside the extraction directory once the deferred link is created. An attacker can craft a tar archive using a symlink target of exactly '..' combined with a deferred hardlink to create a new file outside the extraction directory, or reuse an extraction directory across two archives to replace an existing file outside it. If the archive is extracted with elevated privileges, this flaw can lead to privilege escalation or arbitrary code execution.
    Severity: 6.3 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-108093 - Gimp: gimp: denial of service via null pointer dereference in xcf simulation parasite loading

    CVE ID :CVE-2026-108093
    Published : Oct. 9, 2026, 4:45 p.m. | 15 minutes ago
    Description :A flaw was found in GIMP. The XCF loader processes image-simulation-intent and image-simulation-bpc parasites without ensuring the parasite data is present before dereferencing it. Opening a specially crafted XCF file with a zero-size simulation parasite can cause a NULL pointer dereference and crash the GIMP application.
    Severity: 5.5 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-55797 - Argo CD repo-server command injection via crafted SSH repository SOCKS5 proxy URL

    CVE ID :CVE-2026-55797
    Published : Oct. 9, 2026, 4:43 p.m. | 17 minutes ago
    Description :Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository configured with a proxy URL. The proxy host and port are embedded in an SSH ProxyCommand that is executed through a shell without neutralizing shell metacharacters. A user who can create or update a repository or repository credential template can supply a crafted proxy host to execute commands in the repo-server and access its Git, Helm, and OCI credentials. This issue is fixed in versions 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2.
    Severity: 8.8 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-75597 - pyLoad: Unauthenticated access to /web/ bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo

    CVE ID :CVE-2026-75597
    Published : Oct. 9, 2026, 4:41 p.m. | 19 minutes ago
    Description :pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the `/web/` route in `src/pyload/webui/app/blueprints/app_blueprint.py` renders Jinja2 templates without any authentication requirement. Every equivalent direct route (`/logs`, `/settings`, `/queue`, `/dashboard`, etc.) is protected by `@login_required`, but the underlying templates for all of these pages are accessible unauthenticated via this endpoint. Combined with an exception attribute typo in `src/pyload/webui/app/handlers.py` (`exc.desc` instead of `exc.description`), internal Jinja2 variable names are leaked in HTTP 500 response bodies to unauthenticated callers. An attacker can also enumerate all valid template names by observing 200 vs 500 response differentiation. Version 0.5.0b3.dev101 contains a patch.
    Severity: 5.3 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-48484 - pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination

    CVE ID :CVE-2026-48484
    Published : Oct. 9, 2026, 4:26 p.m. | 34 minutes ago
    Description :pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, the API `rpc` function in `api_blueprint.py` handles `multipart/form-data` uploads by reading the whole content of the uploaded file into memory with `file.read()`. This occurs before the data is sent to the underlying function. Since there is no size limit set at this point, a large file upload can exhaust the server's available memory which led to process termination. Version 0.5.0b3.dev101 contains a patch.
    Severity: 6.5 | MEDIUM
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-90983 - OTP Code Exposure in Hayat Hospital's Hayat Mobile

    CVE ID :CVE-2026-90983
    Published : Oct. 9, 2026, 4:17 p.m. | 43 minutes ago
    Description :Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass. This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.
    Severity: 8.2 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-75349 - EIPStackGroup OpENer Out-of-Bounds Read Vulnerability

    CVE ID :CVE-2026-75349
    Published : Oct. 9, 2026, 4:17 p.m. | 43 minutes ago
    Description :EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.
    Severity: 7.5 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-75348 - EIPStackGroup OpENer Out-of-Bounds Read Vulnerability

    CVE ID :CVE-2026-75348
    Published : Oct. 9, 2026, 4:17 p.m. | 43 minutes ago
    Description :An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognized optional socket address information items of type 0x8000 or 0x8001 without first validating that the remaining CPF buffer contains the complete fixed sockaddr structure. This allows a remote attacker to cause a denial of service.
    Severity: 7.5 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-75346 - EIPStackGroup OpENer Out-of-Bounds Read Vulnerability

    CVE ID :CVE-2026-75346
    Published : Oct. 9, 2026, 4:17 p.m. | 43 minutes ago
    Description :An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service
    Severity: 0.0 | NA
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
  • CVE-2026-75345 - OpENer Out-of-Bounds Read Denial of Service

    CVE ID :CVE-2026-75345
    Published : Oct. 9, 2026, 4:17 p.m. | 43 minutes ago
    Description :OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
    Severity: 7.5 | HIGH
    Visit the link for more details, such as CVSS details, affected products, timeline, and more...
| Date published: Fri, 09 Oct 2026 16:45:59 +0000
Back to newsfeed list