Posts of last 24 hours
A vulnerability labeled as problematic has been found in Forgejo up to 15.0.2. This vulnerability affects unknown code. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-59102. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/375995
A vulnerability identified as problematic has been detected in Netdata up to 2.3.0. This affects an unknown part of the file api/v2/ilove.svg. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2025-71385. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/375994
A vulnerability categorized as critical has been discovered in EstrellaXD Auto_Bangumi up to 3.2.7. Affected by this issue is some unknown functionality of the file /api/v1/setup/test-downloader of the component Internal Network Service Handler. Such manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-59101. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/375993
A vulnerability was found in lobehub LobeChat. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Skill Import Service. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2026-59095. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/375992
A vulnerability was found in blog.admin up to 8.0. It has been rated as problematic. Affected is the function getinfobytoken of the component API Interface. Performing a manipulation results in improper access controls.
This vulnerability was named CVE-2026-30689. The attack may be initiated remotely. There is no available exploit.
https://vuldb.com/vuln/353914
A vulnerability was found in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 26.4. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Handler. This manipulation causes use after free.
This vulnerability appears as CVE-2026-28883. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
https://vuldb.com/vuln/362804
A vulnerability categorized as problematic has been discovered in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 26.4. This affects an unknown part of the component Web Handler. Such manipulation leads to denial of service.
This vulnerability is traded as CVE-2026-28901. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/362805
A vulnerability marked as problematic has been reported in Apple iOS, iPadOS, macOS, tvOS, visionOS and watchOS up to 18.7.8/26.4. Impacted is an unknown function of the component Web Handler. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-28904. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/362808
A vulnerability described as problematic has been identified in Apple iOS, iPadOS, macOS, tvOS and visionOS up to 26.4. The affected element is an unknown function of the component Web Handler. The manipulation results in denial of service.
This vulnerability was named CVE-2026-28905. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/362809
A vulnerability was found in Apple macOS up to 26.4. It has been declared as critical. This vulnerability affects unknown code of the component Web Handler. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-28946. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/362817