Posts of last 24 hours
A vulnerability has been found in libssh2 up to 1.11.1 and classified as problematic. This affects an unknown function of the component SSH Handler. This manipulation causes uninitialized resource.
This vulnerability appears as CVE-2026-58051. The attack may be initiated remotely. In addition, an exploit is available.
https://vuldb.com/vuln/374504
A vulnerability was found in MyBB up to 1.8.40 and classified as critical. This impacts the function verify_usergroup of the component User Module. Such manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2026-58054. The attack may be launched remotely. Furthermore, there is an exploit available.
https://vuldb.com/vuln/374505
A vulnerability categorized as problematic has been discovered in nghttp2 up to 1.69.0. This affects an unknown part of the component HTTP Request Handler. The manipulation results in http request smuggling.
This vulnerability was named CVE-2026-58055. The attack may be performed from remote. In addition, an exploit is available.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/374509
A vulnerability identified as critical has been detected in RustDesk. This vulnerability affects unknown code of the component Control Message Handler. This manipulation causes incorrect authorization.
The identification of this vulnerability is CVE-2026-58056. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/374510
A vulnerability labeled as problematic has been found in Flowise up to 3.1.2 on Windows. This issue affects some unknown processing of the component Environment Variable Handler. Such manipulation leads to improper handling of case sensitivity.
This vulnerability is referenced as CVE-2026-58057. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/374511
A vulnerability identified as critical has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection.
This vulnerability is identified as CVE-2026-13485. The attack can be initiated remotely. Additionally, an exploit exists.
https://vuldb.com/vuln/374482
A vulnerability labeled as critical has been found in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection.
This vulnerability is tracked as CVE-2026-13486. The attack can be launched remotely. Moreover, an exploit is present.
https://vuldb.com/vuln/374483
A vulnerability identified as critical has been detected in Feehi CMS up to 2.1.1. Affected by this issue is some unknown functionality of the file /api/users of the component API. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-13544. The attack can be initiated remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.
https://vuldb.com/vuln/374552
A vulnerability classified as critical has been found in zephyrproject zephyr up to 4.4.x. This issue affects the function uart_rx_enable of the file drivers/serial/uart_mchp_sercom_g1.c. Performing a manipulation results in out-of-bounds write.
This vulnerability is cataloged as CVE-2026-10644. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/374500
A vulnerability was found in Nmap up to 7.99. It has been classified as critical. Affected is an unknown function of the file libnetutil/netutil.cc. Performing a manipulation results in integer underflow.
This vulnerability is known as CVE-2026-58058. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/374506