Aggregator
JVN: TP-Link製ルーターArcher BE450およびBE7200におけるOSコマンドインジェクションの脆弱性
2 weeks 6 days ago
TP-Linkが提供するArcher BE450およびBE7200には、OSコマンドインジェクションの脆弱性が存在します。
CVE-2026-1260 | Google Sentencepiece up to 0.2.1pre2 src/normalizer.cc DecodePrecompiledCharsMap memory corruption (Nessus ID 318116)
2 weeks 6 days ago
A vulnerability labeled as critical has been found in Google Sentencepiece. Affected is the function Normalizer::DecodePrecompiledCharsMap of the file src/normalizer.cc. Executing a manipulation can lead to memory corruption.
This vulnerability is tracked as CVE-2026-1260. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-45077 | Symfony deserialization (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability has been found in Symfony and classified as critical. This issue affects some unknown processing. The manipulation leads to deserialization.
This vulnerability is uniquely identified as CVE-2026-45077. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-45754 | Symfony Mailjet Mailer Webhook Parser injection (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability has been found in Symfony Mailjet Mailer and classified as critical. The impacted element is an unknown function of the component Webhook Parser. This manipulation causes injection.
This vulnerability is handled as CVE-2026-45754. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45133 | Symfony recursion (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability was found in Symfony and classified as problematic. This affects an unknown function. Such manipulation leads to uncontrolled recursion.
This vulnerability is uniquely identified as CVE-2026-45133. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-45304 | Symfony YAML Parser allocation of resources (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability was found in Symfony. It has been classified as problematic. This impacts an unknown function of the component YAML Parser. Performing a manipulation results in allocation of resources.
This vulnerability was named CVE-2026-45304. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-45305 | Symfony YAML Parser Parser::cleanup redos (frc-8383-795 / Nessus ID 318121)
2 weeks 6 days ago
A vulnerability was found in Symfony. It has been declared as problematic. Affected is the function Parser::cleanup of the component YAML Parser. Executing a manipulation can lead to inefficient regular expression complexity.
The identification of this vulnerability is CVE-2026-45305. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-45072 | Symfony WebProfiler fileExcerpt cross site scripting (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability was found in Symfony. It has been declared as problematic. The impacted element is the function CodeExtension::fileExcerpt of the component WebProfiler. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-45072. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-45073 | Symfony PdoAdapter::doClear prefix sql injection (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability, which was classified as critical, has been found in Symfony. Impacted is the function PdoAdapter::doClear. The manipulation of the argument prefix leads to sql injection.
This vulnerability is traded as CVE-2026-45073. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-45071 | Symfony addXmlContent xml external entity reference (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability classified as problematic was found in Symfony. This issue affects the function DomCrawler::addXmlContent. Executing a manipulation can lead to xml external entity reference.
This vulnerability appears as CVE-2026-45071. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
【课程】战略情报撰写-结构化分析方法(含视频)
2 weeks 6 days ago
这一期重点介绍各种结构化情报分析方法。配套有8个短视频。
CVE-2026-45065 | Symfony UrlGenerator injection (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability classified as critical has been found in Symfony. This vulnerability affects the function UrlGenerator. Performing a manipulation results in injection.
This vulnerability is reported as CVE-2026-45065. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-46483 | vim up to 9.2.0478 Archive File runtime/autoload/tar.vim Vimuntar os command injection (GHSA-2fpv-9ff7-xg5w / Nessus ID 318124)
2 weeks 6 days ago
A vulnerability classified as critical was found in vim up to 9.2.0478. Impacted is the function Vimuntar of the file runtime/autoload/tar.vim of the component Archive File Handler. The manipulation results in os command injection.
This vulnerability is reported as CVE-2026-46483. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-43961 | vim up to 9.2.479 NetrwMarkFile code injection (Nessus ID 318124)
2 weeks 6 days ago
A vulnerability has been found in vim up to 9.2.479 and classified as critical. The affected element is the function NetrwMarkFile. Performing a manipulation results in code injection.
This vulnerability is identified as CVE-2026-43961. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45063 | Symfony incorrect regex (Nessus ID 318121)
2 weeks 6 days ago
A vulnerability described as problematic has been identified in Symfony. This affects an unknown part. Such manipulation leads to incorrect regular expression.
This vulnerability is documented as CVE-2026-45063. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-10194 | OFFIS DCMTK 3.7.0 dcmqrscp dcmqrdbi.cc deleteOldestImages heap-based overflow (EUVD-2026-33516 / Nessus ID 318122)
2 weeks 6 days ago
A vulnerability, which was classified as critical, was found in OFFIS DCMTK 3.7.0. This affects the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages of the file dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. Executing a manipulation can lead to heap-based buffer overflow.
The identification of this vulnerability is CVE-2026-10194. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-10276 | hekmon8 Jenkins-server-mcp 0.1.0 get_build_status/get_build_log/trigger_build src/index.ts jobPath server-side request forgery (EUVD-2026-33712)
2 weeks 6 days ago
A vulnerability described as critical has been identified in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of the file src/index.ts of the component get_build_status/get_build_log/trigger_build. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-10276. The attack may be performed from remote. In addition, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
CVE-2026-10295 | SourceCodester Customer Review App 1.0 review_app.py add_review/save_review/get_all_reviews name/comment denial of service (EUVD-2026-33835)
2 weeks 6 days ago
A vulnerability has been found in SourceCodester Customer Review App 1.0 and classified as problematic. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service.
This vulnerability is reported as CVE-2026-10295. The attack requires a local approach. Moreover, an exploit is present.
vuldb.com
CVE-2026-10296 | itsourcecode Fees Management System 1.0 /ajax.php Username sql injection (EUVD-2026-33841)
2 weeks 6 days ago
A vulnerability was found in itsourcecode Fees Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection.
This vulnerability appears as CVE-2026-10296. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com