7 Aug 2026, 18:01 UTC16 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-19264
Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no authentication. Raw dot-segments are collapsed before routing, but URL-encoded separators survive route matchiβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC9 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-19207
A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation of the argument fullname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC8 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-18497
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The vulnerability resides in the glyph data parsing path. An attacker cβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-66914
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC2 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2022-4995
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote codβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-61477
An injection vulnerability was found in libvirtβs virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to injeβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-37171
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-19206
A security flaw has been discovered in MZ Automation libiec61850 up to 1.6.1. This affects the function SVReceiver_stopThreadless of the file src/sampled_values/sv_subscriber.c of the component ASDU Element Handler. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public aβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-16637
OPeNDAP Hyrax allows SSRF and credential disclosure via unvalidated HTTP redirects that bypass the AllowedHosts allowlist and leak Earthdata headers (User-Id, Echo-Token) to attacker-controlled endpoints.
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-15570
An improper restriction of URL schemes and destinations in the SmartCenter browserseturl command in the Telefunken TE24553B45V2DZ Smart TV running on the Vestel MB181 / Voltron181 / TiVo OS platform allows an attacker with access to the same local network to cause the embedded browser to issue requests to unintended loopback/internal destinations, including 127.0.0.1 addresseβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-66838
Improper Neutralization of Special Elements used in an SQL Command (βSQL Injectionβ) vulnerability in elixir-ecto postgrex allows SQL Injection via the :comment option of Postgrex.stream/4. An attacker who can influence that value can close the comment delimiter with */ and extend the streamed statement with their own clauses, which execute under the connectionβs role. Ecto eβ¦
Signed Feed Reader Bot
7 Aug 2026, 18:01 UTC1 viewsread 7 August 2026 CVE Alert & Security Feed
CVE-2026-66494
Joomla Extension - joomshaper.com - Unauthenticated stored XSS in Shapes API endpoint SP Page Builder < 6.7.0 - An unauthenticated attacker can store malicious JavaScript in a Joomla siteβs database via a single HTTP request. When an administrator opens the SP Page Builder editor, the JavaScript executes in their browser automatically..
Signed Feed Reader Bot
Showing the 12 most recent of 40 posts we hold for @golden_age_MD. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked β was rounded by Telegram before we ever saw it β t.me prints views in full below 1,000 and to three significant figures above, so β1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.