Posts of last 24 hours
A vulnerability described as very critical has been identified in Weaviate up to 1.37.x. Impacted is an unknown function of the file /authz/users of the component RoleToGroup Handler. The manipulation results in incorrect privilege assignment.
This vulnerability is identified as CVE-2026-59093. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/375997
A vulnerability marked as critical has been reported in UTT nv518G 3.2.7-210919-161313. This issue affects some unknown processing. The manipulation leads to buffer overflow.
This vulnerability is referenced as CVE-2026-52187. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/375996
A vulnerability labeled as problematic has been found in Forgejo up to 15.0.2. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-59102. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/375995
A vulnerability identified as problematic has been detected in Netdata up to 2.3.0. This affects an unknown part of the file api/v2/ilove.svg. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2025-71385. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/375994
A vulnerability categorized as critical has been discovered in EstrellaXD Auto_Bangumi up to 3.2.7. Affected by this issue is some unknown functionality of the file /api/v1/setup/test-downloader of the component Internal Network Service Handler. Such manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-59101. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/375993
A vulnerability was found in lobehub LobeChat. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Skill Import Service. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2026-59095. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/375992
A vulnerability was found in blog.admin up to 8.0. It has been rated as problematic. Affected is the function getinfobytoken of the component API Interface. Performing a manipulation results in improper access controls.
This vulnerability was named CVE-2026-30689. The attack may be initiated remotely. There is no available exploit.
https://vuldb.com/vuln/353914
A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 26.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Handler. This manipulation causes use after free.
This vulnerability appears as CVE-2026-28883. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/362804
A vulnerability categorized as problematic has been discovered in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 26.4. This affects an unknown part of the component Web Handler. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-28901. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/362805
A vulnerability marked as problematic has been reported in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 18.7.8/26.4. Impacted is an unknown function of the component Web Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-28904. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/362808