Aggregator
CVE-2026-33080 | filamentphp filament up to 4.8.4/5.3.4 cross site scripting
3 months ago
A vulnerability classified as problematic has been found in filamentphp filament up to 4.8.4/5.3.4. Affected is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-33080. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-2432 | creativemindssolutions CM Custom Reports Plugin up to 1.2.7 on WordPress Setting cross site scripting (EUVD-2026-13637)
3 months ago
A vulnerability described as problematic has been identified in creativemindssolutions CM Custom Reports Plugin up to 1.2.7 on WordPress. This impacts an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-2432. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-32701 | QwikDev qwik up to 1.19.1 FormData Parser type confusion
3 months ago
A vulnerability marked as problematic has been reported in QwikDev qwik up to 1.19.1. This affects an unknown function of the component FormData Parser. Performing a manipulation results in type confusion.
This vulnerability is identified as CVE-2026-32701. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-33075 | labring FastGPT up to 4.14.8.3 pull_request_target code download
3 months ago
A vulnerability labeled as problematic has been found in labring FastGPT up to 4.14.8.3. The impacted element is the function pull_request_target. Such manipulation leads to download of code without integrity check.
This vulnerability is referenced as CVE-2026-33075. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-27625 | Stirling-Tools Stirling-PDF up to 2.5.1 PDF File Parser pdf path traversal
3 months ago
A vulnerability identified as critical has been detected in Stirling-Tools Stirling-PDF up to 2.5.1. The affected element is an unknown function of the file /api/v1/convert/markdown/pdf of the component PDF File Parser. This manipulation causes path traversal.
The identification of this vulnerability is CVE-2026-27625. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-33070 | error311 FileRise up to 3.7.x deleteShareLink Endpoint missing authentication
3 months ago
A vulnerability categorized as critical has been discovered in error311 FileRise up to 3.7.x. Impacted is the function FileController::deleteShareLink of the component deleteShareLink Endpoint. The manipulation results in missing authentication.
This vulnerability was named CVE-2026-33070. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33072 | error311 FileRise up to 3.8.x Environment Variable default_please_change_this_key PERSISTENT_TOKENS_KEY hard-coded credentials
3 months ago
A vulnerability was found in error311 FileRise up to 3.8.x. It has been rated as critical. This issue affects the function default_please_change_this_key of the component Environment Variable Handler. The manipulation of the argument PERSISTENT_TOKENS_KEY leads to hard-coded credentials.
This vulnerability is uniquely identified as CVE-2026-33072. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-3550 | firetree RockPress Plugin up to 1.0.17 on WordPress AJAX profile.php current_user_can authorization (EUVD-2026-13655)
3 months ago
A vulnerability was found in firetree RockPress Plugin up to 1.0.17 on WordPress. It has been declared as problematic. This vulnerability affects the function current_user_can of the file profile.php of the component AJAX Handler. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-3550. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-2421 | ghera74 ilGhera Carta Docente for WooCommerce Plugin up to 1.5.0 on WordPress wccd-delete-certificate cert path traversal (EUVD-2026-13636)
3 months ago
A vulnerability was found in ghera74 ilGhera Carta Docente for WooCommerce Plugin up to 1.5.0 on WordPress. It has been classified as critical. This affects the function wccd-delete-certificate. Performing a manipulation of the argument cert results in path traversal.
This vulnerability is known as CVE-2026-2421. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-33071 | error311 FileRise up to 3.7.x WebDAV Upload Endpoint createFile unrestricted upload
3 months ago
A vulnerability was found in error311 FileRise up to 3.7.x and classified as critical. Affected by this issue is the function createFile of the component WebDAV Upload Endpoint. Such manipulation leads to unrestricted upload.
This vulnerability is traded as CVE-2026-33071. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
Securing E-commerce Transactions with Modern Authentication
3 months ago
Protect e-commerce transactions with OTP, passkeys, and fraud detection. Reduce shipping fraud and secure high-value purchases easily.
The post Securing E-commerce Transactions with Modern Authentication appeared first on Security Boulevard.
MojoAuth Blog - Passwordless Authentication & Identity Solutions
CVE-2026-33068 | Anthropic claude-code up to 2.1.52 claude/settings.json reliance on untrusted inputs in a security decision
3 months ago
A vulnerability has been found in Anthropic claude-code up to 2.1.52 and classified as critical. Affected by this vulnerability is an unknown functionality of the file claude/settings.json. This manipulation causes reliance on untrusted inputs in a security decision.
This vulnerability appears as CVE-2026-33068. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-33066 | SiYuan up to 3.6.0 lute.New cross site scripting
3 months ago
A vulnerability, which was classified as problematic, was found in SiYuan up to 3.6.0. Affected is the function lute.New. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-33066. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-33067 | SiYuan up to 3.6.0 Bazaar Page cross site scripting
3 months ago
A vulnerability, which was classified as problematic, has been found in SiYuan up to 3.6.0. This impacts an unknown function of the component Bazaar Page. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-33067. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33192 | Free5GC up to 1.4.1 PATCH Request information exposure
3 months ago
A vulnerability classified as problematic was found in Free5GC up to 1.4.1. This affects an unknown function of the component PATCH Request Handler. Executing a manipulation can lead to information exposure through error message.
This vulnerability is registered as CVE-2026-33192. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-33069 | pjsip pjproject up to 2.16 SIP Message pjsip_multipart_parse out-of-bounds (EUVD-2026-13632)
3 months ago
A vulnerability classified as problematic has been found in pjsip pjproject up to 2.16. The impacted element is the function pjsip_multipart_parse of the component SIP Message Handler. Performing a manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-33069. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Собственный бот Meta решил поработать модератором. Итог – угроза масштабной утечки
3 months ago
В корпорации поняли, что ИИ пока не стоит доверять сложные задачи.
人工智能重要漏洞通报(2026年第三期)
3 months ago
根据国家信息安全漏洞库(CNNVD)统计,近期(2026年3月4日至2026年3月19日)共采集重要人工智能漏洞155个
UniFi 曝高危安全漏洞 存在账号被劫持风险
3 months ago
HackerNews 编译,转载请注明出处: Ubiquiti修复了两个 UniFi 相关漏洞,其中一个高危漏洞可被攻击者用于接管用户账号。 Ubiquiti为其 UniFi 网络管理应用发布了两处漏洞补丁,其中包含一个最高危级别漏洞,攻击者可利用该漏洞实施账号劫持。该软件被广泛用于管理 UniFi 系列网络设备,如无线 AP、交换机及网关等。 UniFi 网络管理应用是Ubiquiti公司开发的管理软件,用于控制和监控旗下 UniFi 系列网络设备。 用户可通过统一控制台对无线 AP、交换机、网关等硬件进行配置、管理与性能优化。IT 管理员可通过本地或云端方式部署网络、监控性能、管理用户、配置安全策略及排查故障。 该厂商修复了编号为CVE-2026-22557的最高危漏洞(CVSS 评分 10.0),该漏洞影响 UniFi 网络应用10.1.85 及更早版本。 处于同一网络中的攻击者可利用 UniFi 中的路径遍历漏洞访问系统文件,进而有可能接管用户账号。 安全公告显示:“具备网络访问权限的恶意人员可利用 UniFi 网络应用中的路径遍历漏洞,访问底层系统文件,并可通过相关操作实现账号入侵。” 10.1.89 及更高版本已修复该漏洞。 Ubiquiti修复的第二个漏洞编号为CVE-2026-22558(CVSS 评分 7.7),同样存在于 UniFi 网络应用中,低权限攻击者可利用该漏洞进行权限提升。 该公司表示:“UniFi 网络应用中存在一处已认证 NoSQL 注入漏洞,获得网络授权访问权限的恶意人员可利用该漏洞提升自身权限。” 消息来源:securityaffairs.com; 本文由 HackerNews.cc 翻译整理,封面来源于网络; 转载请注明“转自 HackerNews.cc”并附上原文
hackernews