Aggregator
CVE-2023-33865 | RenderDoc up to 1.26 /tmp/RenderDoc symlink (ID 172804 / EUVD-2023-38015)
5 months 1 week ago
A vulnerability was found in RenderDoc up to 1.26 and classified as critical. This affects an unknown part of the file /tmp/RenderDoc. The manipulation results in symlink following.
This vulnerability is reported as CVE-2023-33865. The attack requires a local approach. Moreover, an exploit is present.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-33982 | Briar up to 1.5.2 Bramble Handshake Protocol inadequate encryption (EUVD-2023-38106)
5 months 1 week ago
A vulnerability labeled as problematic has been found in Briar up to 1.5.2. The affected element is an unknown function of the component Bramble Handshake Protocol Handler. Such manipulation leads to inadequate encryption strength.
This vulnerability is uniquely identified as CVE-2023-33982. The attack can only be initiated within the local network. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2023-33981 | Briar up to 1.4.21 Message access control (EUVD-2023-38105)
5 months 1 week ago
A vulnerability marked as critical has been reported in Briar up to 1.4.21. The impacted element is an unknown function of the component Message Handler. Performing a manipulation results in improper access controls.
This vulnerability was named CVE-2023-33981. The attack needs to be approached within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-33980 | Briar up to 1.4.21 Bramble Synchronisation Protocol denial of service (EUVD-2023-38104)
5 months 1 week ago
A vulnerability classified as problematic has been found in Briar up to 1.4.21. This impacts an unknown function of the component Bramble Synchronisation Protocol Handler. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2023-33980. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33864 | RenderDoc up to 1.26 integer underflow (ID 172804 / EUVD-2023-38014)
5 months 1 week ago
A vulnerability was found in RenderDoc up to 1.26. It has been classified as critical. This vulnerability affects unknown code. This manipulation causes integer underflow.
This vulnerability appears as CVE-2023-33864. The attack may be initiated remotely. In addition, an exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-21633 | Ubiquiti UniFi Protect Application up to 6.2.71 improper authorization (EUVD-2026-0828 / WID-SEC-2026-0014)
5 months 1 week ago
A vulnerability marked as critical has been reported in Ubiquiti UniFi Protect Application up to 6.2.71. This affects an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is reported as CVE-2026-21633. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-68668 | n8n-io n8n up to 1.x Environment Variable NODES_EXCLUDE protection mechanism (GHSA-62r4-hw23-cc8v / EUVD-2025-205454)
5 months 1 week ago
A vulnerability has been found in n8n-io n8n up to 1.x and classified as critical. Affected by this vulnerability is an unknown functionality of the component Environment Variable Handler. Performing a manipulation of the argument NODES_EXCLUDE results in protection mechanism failure.
This vulnerability is identified as CVE-2025-68668. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-32365 | Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0 File JBIG2Stream.cc JBIG2Bitmap::combine out-of-bounds (Issue 1577 / Nessus ID 234608)
5 months 1 week ago
A vulnerability described as problematic has been identified in Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0. This impacts the function JBIG2Bitmap::combine of the file JBIG2Stream.cc of the component File Handler. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is tracked as CVE-2025-32365. The attack is restricted to local execution. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-65018 | libpng up to 1.6.50 png_combine_row heap-based overflow (EUVD-2025-199236 / Nessus ID 276643)
5 months 1 week ago
A vulnerability marked as critical has been reported in libpng up to 1.6.50. This impacts the function png_combine_row. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2025-65018. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-32364 | Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0 PSStack::roll integer overflow (Issue 1574 / Nessus ID 234608)
5 months 1 week ago
A vulnerability marked as problematic has been reported in Freedesktop Poppler 0.75.0/0.89.0/20.12.1/22.07.0/22.08.0. This affects the function PSStack::roll. Performing a manipulation results in integer overflow.
This vulnerability is identified as CVE-2025-32364. The attack is only possible with local access. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-64720 | libpng up to 1.6.50 png_image_read_composite out-of-bounds (EUVD-2025-199237 / Nessus ID 276641)
5 months 1 week ago
A vulnerability labeled as problematic has been found in libpng up to 1.6.50. This affects the function png_image_read_composite. Such manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2025-64720. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server
5 months 1 week ago
A critical path traversal vulnerability in AdonisJS has been discovered that could allow remote attackers to write arbitrary files to server filesystems, potentially leading to complete system compromise. The vulnerability, tracked as CVE-2026-21440, affects the bodyparser module of the popular TypeScript-first web framework and carries a critical CVSS v4 severity rating. The security flaw resides in […]
The post Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server appeared first on Cyber Security News.
Abinaya
Unpatched Firmware Flaw Exposes TOTOLINK EX200 to Full Remote Device Takeover
5 months 1 week ago
The CERT Coordination Center (CERT/CC) has disclosed details of an unpatched security flaw impacting TOTOLINK EX200 wireless range extender that could allow a remote authenticated attacker to gain full control of the device.
The flaw, CVE-2025-65606 (CVSS score: N/A), has been characterized as a flaw in the firmware-upload error-handling logic, which could cause the device to inadvertently start
The Hacker News
UK government admits years of cyber policy have failed, announces reset
5 months 1 week ago
The current system of accountability has left much of the British government vulnerable to cyberattacks, according to a new Government Cyber Action Plan, with responsibilities for risk “unclear at all levels.”
CVE-2023-33863 | RenderDoc up to 1.26 integer overflow (ID 172804 / EUVD-2023-38013)
5 months 1 week ago
A vulnerability was found in RenderDoc up to 1.26. It has been declared as critical. This issue affects some unknown processing. Such manipulation leads to integer overflow.
This vulnerability is traded as CVE-2023-33863. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-33817 | HotelDruid Hotel Management Software 3.0.5 sql injection (EUVD-2023-37968)
5 months 1 week ago
A vulnerability was found in HotelDruid Hotel Management Software 3.0.5. It has been rated as critical. This affects an unknown part. The manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2023-33817. The attack can only be initiated within the local network. No exploit exists.
vuldb.com
CVE-2023-33829 | Cloudogu SCM Manager up to 1.60 Description cross site scripting (ID 172588 / EUVD-2023-37980)
5 months 1 week ago
A vulnerability was found in Cloudogu SCM Manager up to 1.60 and classified as problematic. Affected by this issue is some unknown functionality. Executing a manipulation of the argument Description can lead to cross site scripting.
This vulnerability is tracked as CVE-2023-33829. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2023-33802 | SumatraPDF Reader 3.4.6 Text File buffer overflow (EUVD-2023-37953)
5 months 1 week ago
A vulnerability identified as critical has been detected in SumatraPDF Reader 3.4.6. This affects an unknown part of the component Text File Handler. Performing a manipulation results in buffer overflow.
This vulnerability is known as CVE-2023-33802. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
High-Severity Flaw in Open WebUI Affects AI Connections
5 months 1 week ago
A high-severity security flaw in Open WebUI Direct Connections risks account takeover and server compromises