Posts of last 24 hours
A vulnerability was found in MyBB up to 1.8.40 and classified as critical. This impacts the function verify_usergroup of the component User Module. Such manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-58054. The attack may be launched remotely. Furthermore, there is an exploit available.
https://vuldb.com/vuln/374505
A vulnerability categorized as problematic has been discovered in nghttp2 up to 1.69.0. This affects an unknown part of the component HTTP Request Handler. The manipulation results in http request smuggling.
This vulnerability was named CVE-2026-58055. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/374509
A vulnerability identified as critical has been detected in RustDesk. This vulnerability affects unknown code of the component Control Message Handler. This manipulation causes incorrect authorization.
The identification of this vulnerability is CVE-2026-58056. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/374510
A vulnerability labeled as problematic has been found in Flowise up to 3.1.2 on Windows. This issue affects some unknown processing of the component Environment Variable Handler. Such manipulation leads to improper handling of case sensitivity.
This vulnerability is referenced as CVE-2026-58057. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/374511
A vulnerability identified as critical has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection.
This vulnerability is identified as CVE-2026-13485. The attack can be initiated remotely. Additionally, an exploit exists.
https://vuldb.com/vuln/374482
A vulnerability labeled as critical has been found in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection.
This vulnerability is tracked as CVE-2026-13486. The attack can be launched remotely. Moreover, an exploit is present.
https://vuldb.com/vuln/374483
A vulnerability identified as critical has been detected in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-13544. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
https://vuldb.com/vuln/374552
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077584&idx=3&sn=400d5763c8746914d79931cdb7e87349
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077584&idx=2&sn=24d77703c0c3db547cadcd8a4b91e0cb
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652077584&idx=1&sn=2e19796b96a8daf5fd98c9b38425cca3