π CVE-2026-34885 - High
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Media LIbrary Assistant allows SQL Injection.This issue affects Media LIbra...
https://t.co/CMrtRYQftO
π CVE-2026-3524 - High
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, downl...
https://t.co/YPEgYqdAFp
π CVE-2026-5629 - High
A vulnerability was detected in Belkin F9K1015 1.00.10. The affected element is the function formSetFirewall of the file /goform/formSetFirewall. The manipulation of the argument webpage resul...
https://t.co/Qw89A5mTOR
π CVE-2026-5628 - High
A security vulnerability has been detected in Belkin F9K1015 1.00.10. Impacted is the function formSetSystemSettings of the file /goform/formSetSystemSettings of the component Setting Handler....
https://t.co/L7UB8tQUzP
π CVE-2026-5614 - High
A security flaw has been discovered in Belkin F9K1015 1.00.10. Impacted is the function formSetPassword of the file /goform/formSetPassword. The manipulation of the argument webpage results in...
https://t.co/UoqyOhZj2N
π CVE-2026-5613 - High
A vulnerability was identified in Belkin F9K1015 1.00.10. This issue affects the function formReboot of the file /goform/formReboot. The manipulation of the argument webpage leads to stack-bas...
https://t.co/X7D0ETD3hi
π CVE-2026-5612 - High
A vulnerability was determined in Belkin F9K1015 1.00.10. This vulnerability affects the function formWlEncrypt of the file /goform/formWlEncrypt. Executing a manipulation of the argument webp...
https://t.co/JRnoknhx8g
π CVE-2026-5611 - High
A vulnerability was found in Belkin F9K1015 1.00.10. This affects the function formCrossBandSwitch of the file /goform/formCrossBandSwitch. Performing a manipulation of the argument webpage re...
https://t.co/ld4qcfGx2C
π CVE-2026-5610 - High
A vulnerability has been found in Belkin F9K1015 1.00.10. Affected by this issue is the function formWISP5G of the file /goform/formWISP5G. Such manipulation of the argument webpage leads to s...
https://t.co/tCUfSmUI29
π CVE-2026-5608 - High
A vulnerability was detected in Belkin F9K1122 1.00.33. Affected is the function formWlanSetup of the file /goform/formWlanSetup. The manipulation of the argument webpage results in stack-base...
https://t.co/N4pRl03Ja2
π CVE-2026-4272 - High
Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse.This issue affects Handheld Scanners: from C1 Base(Ingenic x1000) before G...
https://t.co/8TiO3tsmSA
π CVE-2026-5566 - High
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument Nat...
https://t.co/32L2qBTMLL
π CVE-2026-5544 - High
A security flaw has been discovered in UTT HiPER 1250GW up to 3.2.7-210907-180535. The impacted element is an unknown function of the file /goform/formRemoteControl. The manipulation of the ar...
https://t.co/f4YlFDhzIh
π CVE-2026-4636 - High
A flaw was found in Keycloak. An authenticated user with the uma_protection role can bypass User-Managed Access (UMA) policy validation. This allows the attacker to include resource identifier...
https://t.co/RUQAFd1Jtd
π CVE-2026-28805 - High
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, multiple AJAX select handlers in OpenSTAManager are vulnerable to Time-Ba...
https://t.co/De2HBOkWcP
π΄ CVE-2026-2701 - Critical
Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution.
https://t.co/GZMCbB6XFw
π΄ CVE-2026-2699 - Critical
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and poten...
https://t.co/bKECTs82vM
π CVE-2026-35168 - High
OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.10.2, the Aggiornamenti (Updates) module in OpenSTAManager contains a database ...
https://t.co/rnLfkIAL3i
π CVE-2026-34728 - High
phpMyFAQ is an open source FAQ web application. Prior to version 4.1.1, the MediaBrowserController::index() method handles file deletion for the media browser. When the fileRemove action is t...
https://t.co/2ClEbgpWbU
π CVE-2026-34791 - High
Endian Firewall version 3.3.25 and prior allow authenticated users to execute arbitrary OS commands via the DATE parameter to /cgi-bin/logs_proxy.cgi. The DATE parameter value is used to cons...
https://t.co/5AwQ6138DY