Aggregator
CVE-2026-41523 | vLLM up to 0.20.0 Activation code injection
1 week 6 days ago
A vulnerability was found in vLLM and classified as critical. The affected element is an unknown function of the component Activation. Executing a manipulation can lead to code injection.
This vulnerability is tracked as CVE-2026-41523. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-49050 | Apache DolphinScheduler up to 3.4.1 Access Token /access-tokens privilege escalation
1 week 6 days ago
A vulnerability has been found in Apache DolphinScheduler up to 3.4.1 and classified as critical. Impacted is an unknown function of the file /access-tokens of the component Access Token Handler. Performing a manipulation results in privilege escalation.
This vulnerability is identified as CVE-2026-49050. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-40722 | Yoast BV Yoast SEO Premium Plugin up to 26.6 on WordPress authorization
1 week 6 days ago
A vulnerability, which was classified as problematic, was found in Yoast BV Yoast SEO Premium Plugin up to 26.6 on WordPress. This issue affects some unknown processing. Such manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-40722. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-27869 | Teldat Regesta Smart HD-PLC up to 11.02.05.10.02 Web Interface allocation of resources
1 week 6 days ago
A vulnerability, which was classified as problematic, has been found in Teldat Regesta Smart HD-PLC up to 11.02.05.10.02. This vulnerability affects unknown code of the component Web Interface. This manipulation causes allocation of resources.
The identification of this vulnerability is CVE-2026-27869. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-27870 | Teldat Regesta Smart HD-PLC up to 11.02.05.10.02 Configuration File /upgrade/query.php Hostname cross site scripting
1 week 6 days ago
A vulnerability classified as problematic was found in Teldat Regesta Smart HD-PLC up to 11.02.05.10.02. This affects an unknown part of the file /upgrade/query.php of the component Configuration File Handler. The manipulation of the argument Hostname results in cross site scripting.
This vulnerability was named CVE-2026-27870. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-47340 | Apache DolphinScheduler up to 3.4.1 information disclosure
1 week 6 days ago
A vulnerability classified as problematic has been found in Apache DolphinScheduler up to 3.4.1. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-47340. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42357 | Apache DolphinScheduler up to 3.4.0 authorization
1 week 6 days ago
A vulnerability described as problematic has been identified in Apache DolphinScheduler up to 3.4.0. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to incorrect authorization.
This vulnerability is handled as CVE-2026-42357. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41280 | Apache DolphinScheduler up to 3.4.1 authorization
1 week 6 days ago
A vulnerability marked as problematic has been reported in Apache DolphinScheduler up to 3.4.1. Affected is an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability is known as CVE-2026-41280. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-32967 | Apache DolphinScheduler up to 3.4.1 Experimental Interface /v2 authorization
1 week 6 days ago
A vulnerability labeled as critical has been found in Apache DolphinScheduler up to 3.4.1. This impacts an unknown function of the file /v2 of the component Experimental Interface. Such manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-32967. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-32966 | Apache DolphinScheduler up to 3.4.1 DataSource API authorization
1 week 6 days ago
A vulnerability identified as critical has been detected in Apache DolphinScheduler up to 3.4.1. This affects an unknown function of the component DataSource API. This manipulation causes incorrect authorization.
This vulnerability appears as CVE-2026-32966. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
1-Click атака: кликнул, Copilot нашёл, Bing доставил. И всё это — через сайты самой Microsoft, которым все доверяли
1 week 6 days ago
Уязвимость SearchLeak в Microsoft Copilot позволяла похищать почту и коды подтверждения после перехода по ссылке.
CVE-2026-27868 | Teldat Regesta Smart HD-PLC up to 11.02.05.10.02 Registration /upgrade/query.php insertion of sensitive information into sent data
1 week 6 days ago
A vulnerability categorized as problematic has been discovered in Teldat Regesta Smart HD-PLC up to 11.02.05.10.02. The impacted element is an unknown function of the file /upgrade/query.php of the component Registration Handler. The manipulation results in insertion of sensitive information into sent data.
This vulnerability is reported as CVE-2026-27868. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-12115 | wpcalc Counter Box Plugin up to 2.0.13 on WordPress import deserialization
1 week 6 days ago
A vulnerability was found in wpcalc Counter Box Plugin up to 2.0.13 on WordPress. It has been rated as problematic. The affected element is the function Import. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2026-12115. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-12165 | contest-gallery Contest Gallery Plugin up to 30.0.2 on WordPress Database Table change-options-and-sizes.php current_user_can RegistryUserRole privileges management
1 week 6 days ago
A vulnerability was found in contest-gallery Contest Gallery Plugin up to 30.0.2 on WordPress. It has been declared as critical. Impacted is the function current_user_can of the file change-options-and-sizes.php of the component Database Table Handler. Executing a manipulation of the argument RegistryUserRole can lead to improper privilege management.
This vulnerability is registered as CVE-2026-12165. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
How to lead SecOps in a new era
1 week 6 days ago
Red Canary, a Zscaler company
CVE-2026-44824 | Microsoft Office up to 16.0.10417.20128 heap-based overflow (Nessus ID 321311)
1 week 6 days ago
A vulnerability has been found in Microsoft Office and classified as critical. This issue affects some unknown processing. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-44824. It is possible to initiate the attack remotely. There is no exploit available.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2026-44819 | Microsoft Office up to SharePoint Server Subscription Edition heap-based overflow (Nessus ID 321311)
1 week 6 days ago
A vulnerability described as critical has been identified in Microsoft Office. Affected is an unknown function. The manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-44819. The attack may be launched remotely. There is no exploit available.
It is best practice to apply a patch to resolve this issue.
vuldb.com
CVE-2026-46227 | Linux Kernel up to 7.1-rc3 sctp sctp_sendmsg_to_asoc use after free (EUVD-2026-32854 / Nessus ID 321327)
1 week 6 days ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.139/6.12.89/6.18.31/7.0.8/7.1-rc3. Affected is the function sctp_sendmsg_to_asoc of the component sctp. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-46227. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
What’s new in Android 17? Anti-theft tools, scam detection, and parental controls
1 week 6 days ago
The Android 17 rollout has started for supported Pixel devices, delivering new security and privacy capabilities before expanding to other devices later this year. Security and privacy updates Google has improved location privacy features so users can choose to share their approximate location with websites and grant apps temporary access to their precise location when services require exact coordinates. In previous Android versions, users had no OS-level way to grant an app access to only … More →
The post What’s new in Android 17? Anti-theft tools, scam detection, and parental controls appeared first on Help Net Security.
Anamarija Pogorelec