Posts of last 24 hours
A vulnerability was found in etruel WPeMatico Plugin up to 2.8.24 on WordPress and classified as critical. Affected is the function wpematico_import_settings of the component Import Settings. The manipulation results in improper authorization.
This vulnerability is reported as CVE-2026-19883. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/394273
做大做强中国网络安全产业!
https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247487131&idx=1&sn=6875fac780d00f5eb018908b8e1e4045
Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project
https://buaq.net/go-436901.html
A vulnerability classified as critical has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1. This impacts an unknown function of the component UDS Server Handler. The manipulation leads to permission issues.
This vulnerability is listed as CVE-2026-21711. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/354144
A vulnerability, which was classified as problematic, has been found in Node.js up to 20.20.1/22.22.1/24.14.0/25.8.1. Affected by this vulnerability is the function memcmp of the file crypto_hmac.cc of the component HMAC Verification. This manipulation causes incorrect comparison.
This vulnerability is registered as CVE-2026-21713. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/354146
A vulnerability, which was classified as critical, was found in TP-Link Tapo C520WS 2.6. Affected is an unknown function. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2026-34118. The attacker needs to be present on the local network. There is no available exploit.
https://vuldb.com/vuln/354959
A vulnerability has been found in Grafana Correlations up to 12.3.x and classified as problematic. The impacted element is an unknown function of the file /static/img/heros/hero-legal2.svg. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-21727. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/357816
A vulnerability marked as problematic has been reported in GnuTLS. Affected by this vulnerability is an unknown functionality of the component PKCS#7 Padding Check. The manipulation leads to observable timing discrepancy.
This vulnerability is listed as CVE-2026-5419. The attack may be initiated remotely. There is no available exploit.
https://vuldb.com/vuln/367764
A vulnerability categorized as problematic has been discovered in elixir-tesla tesla up to 1.18.2. This affects the function add_content_type_param. Executing a manipulation can lead to http response splitting.
This vulnerability appears as CVE-2026-48596. The attack requires local access. There is no available exploit.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/368069