Aggregator
【春锋行动】陌陌 SRC 联合狩猎,积分翻倍 + 新人专享 + 老带新福利+专项福利等你来!
2 months 3 weeks ago
春日猎洞狂欢!陌陌 SRC 多重活动叠加,奖励直接拉满
CVE-2026-1579 | PX4 Autopilot 1.16.0 SITL MAVLink Interface missing authentication
2 months 3 weeks ago
A vulnerability labeled as critical has been found in PX4 Autopilot 1.16.0 SITL. The impacted element is an unknown function of the component MAVLink Interface. The manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-1579. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-3470 | SonicWall Email Security improper authentication (SNWLID-2026-0002)
2 months 3 weeks ago
A vulnerability identified as critical has been detected in SonicWall Email Security. The affected element is an unknown function. The manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-3470. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-3469 | SonicWall Email Security denial of service (SNWLID-2026-0002)
2 months 3 weeks ago
A vulnerability categorized as problematic has been discovered in SonicWall Email Security. Impacted is an unknown function. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-3469. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-34372 | Sulu up to 2.6.21/3.0.4 Admin API authentication bypass (GHSA-6h7h-m7p5-hjqp)
2 months 3 weeks ago
A vulnerability was found in Sulu up to 2.6.21/3.0.4. It has been rated as critical. This issue affects some unknown processing of the component Admin API. Performing a manipulation results in authentication bypass using alternate channel.
This vulnerability is identified as CVE-2026-34372. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-34206 | libops captcha-protect up to 1.12.1 Destination cross site scripting (GHSA-ph62-4j5g-2q4r)
2 months 3 weeks ago
A vulnerability was found in libops captcha-protect up to 1.12.1. It has been declared as problematic. This vulnerability affects unknown code of the component Destination Handler. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-34206. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-30290 | InTouch Contacts & Caller ID App 6.38.1 privilege escalation (ID 19)
2 months 3 weeks ago
A vulnerability was found in InTouch Contacts & Caller ID App 6.38.1. It has been classified as critical. This affects an unknown part. This manipulation causes privilege escalation.
The identification of this vulnerability is CVE-2026-30290. The attack needs to be done within the local network. There is no exploit available.
vuldb.com
CVE-2026-4800 | Lodash up to 4.17.x Parameter Function options.imports code injection (GHSA-35jh-r3h4-6jhm)
2 months 3 weeks ago
A vulnerability was found in Lodash up to 4.17.x and classified as critical. Affected by this issue is the function Function of the component Parameter Handler. The manipulation of the argument options.imports results in code injection.
This vulnerability was named CVE-2026-4800. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-34204 | MinIO up to RELEASE.2025-10-15T17-29-55Z extractMetadataFromMime improper authentication (GHSA-3rh2-v3gr-35p9)
2 months 3 weeks ago
A vulnerability has been found in MinIO and classified as critical. Affected by this vulnerability is the function extractMetadataFromMime. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-34204. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-34784 | parse-community parse-server up to 8.6.70/9.7.0 HTTP Range Request improper authorization (GHSA-hpm8-9qx6-jvwv)
2 months 3 weeks ago
A vulnerability, which was classified as critical, was found in parse-community parse-server up to 8.6.70/9.7.0. Affected is an unknown function of the component HTTP Range Request Handler. Executing a manipulation can lead to improper authorization.
This vulnerability is handled as CVE-2026-34784. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-34215 | parse-community parse-server up to 8.6.62/9.7.0-alpha.6 Verify Password Endpoint information disclosure (GHSA-wp76-gg32-8258)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, has been found in parse-community parse-server up to 8.6.62/9.7.0-alpha.6. This impacts an unknown function of the component Verify Password Endpoint. Performing a manipulation results in information disclosure.
This vulnerability is known as CVE-2026-34215. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-34203 | Nautobot up to 2.4.29/3.0.9 REST API nautobot_config.py weak password (GHSA-xmpv-j7p2-j873)
2 months 3 weeks ago
A vulnerability classified as critical was found in Nautobot up to 2.4.29/3.0.9. This affects an unknown function of the file nautobot_config.py of the component REST API. Such manipulation leads to weak password requirements.
This vulnerability is traded as CVE-2026-34203. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-62184 | Pegasystems Pega Infinity up to 25.0.x User Interface cross site scripting
2 months 3 weeks ago
A vulnerability classified as problematic has been found in Pegasystems Pega Infinity up to 25.0.x. The impacted element is an unknown function of the component User Interface. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-62184. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-3356 | Anritsu Remote Spectrum Monitor MS27100A missing authentication (icsa-26-090-01)
2 months 3 weeks ago
A vulnerability described as critical has been identified in Anritsu Remote Spectrum Monitor MS27100A, Remote Spectrum Monitor MS27101A, Remote Spectrum Monitor MS27102A and Remote Spectrum Monitor MS27103A. The affected element is an unknown function. The manipulation results in missing authentication.
This vulnerability is reported as CVE-2026-3356. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-30285 | Zora Post, Trade, Earn Crypto 2.60.0 File Import privilege escalation (ID 15)
2 months 3 weeks ago
A vulnerability marked as critical has been reported in Zora Post, Trade, Earn Crypto 2.60.0. Impacted is an unknown function of the component File Import. The manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2026-30285. The attack requires being on the local network. There is not any exploit available.
vuldb.com
CVE-2026-2950 | Lodash up to 4.17.x _.unset/_.omit prototype pollution (GHSA-xxjr-mmjv-4gpg)
2 months 3 weeks ago
A vulnerability labeled as critical has been found in Lodash up to 4.17.x. This issue affects the function _.unset/_.omit. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is registered as CVE-2026-2950. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-30286 | Funambol Zefiro Cloud 32.0.2026011614 privilege escalation (ID 14)
2 months 3 weeks ago
A vulnerability identified as critical has been detected in Funambol Zefiro Cloud 32.0.2026011614. This vulnerability affects unknown code. Performing a manipulation results in privilege escalation.
This vulnerability is cataloged as CVE-2026-30286. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-30280 | Rareprob Video Player Play All Videos 1.0.135 privilege escalation (ID 29)
2 months 3 weeks ago
A vulnerability categorized as critical has been discovered in Rareprob Video Player Play All Videos 1.0.135. This affects an unknown part. Such manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2026-30280. The attack must be carried out from within the local network. There is no available exploit.
vuldb.com
JVN: CISA ICS Advisory / ICS Medical Advisory(2026年03月31日)
2 months 3 weeks ago
2026年03月31日(現地時間)、米国CISAがCISA ICS Advisory / ICS Medical Advisoryを公表しました。