All coverage
CVE-2026-56960 - android Certain parts of the program could be tricked into using memory that’s no longer valid, allowing an attacker to take control of the system from afar without needing any special access… Too many irrelevant or confusing CVEs? Use stackflag.com #android #google #CVE #infosec Certain parts of the program could be tricked into using memory that’s no longer valid, allowing an at
CVE-2026-43790 - macos Some older versions of macOS could be tricked by a remote attacker into crashing the computer or corrupting the core system memory. This can lead to loss of work or make the system… Too many irrelevant or confusing CVEs? Use stackflag.com #macos #apple #CVE #infosec Some older versions of macOS could be tricked by a remote attacker into crashing the computer or corrupting th
CVE-2026-70009 - azure arc Azure Arc does not properly restrict file paths, allowing a remote attacker to move outside intended directories and increase their access rights. This could let an unauthorized… Too many irrelevant or confusing CVEs? Use stackflag.com #azurearc #microsoft #CVE #infosec Azure Arc does not properly restrict file paths, allowing a remote attacker to move outside intended d
CVE-2026-69865 - azure container registry The Azure Container Registry service can be tricked into granting more access than intended. An attacker who can send specially crafted requests could increase their… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoft #CVE #infosec The Azure Container Registry service can be tricked into granting more access than intended.
CVE-2026-77903 - microsoft dataverse The Dataverse platform can be tricked into accepting a fake login, allowing an unauthorized person to act with the rights of a trusted user. This could let… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoftdataverse #microsoft #CVE #infosec The Dataverse platform can be tricked into accepting a fake login, allowing an unauthorized person to ac
CVE-2026-85885 - microsoft 365 copilot A flaw in Microsoft 365 Copilot lets someone with valid access run special commands that increase their permissions across the network. This could allow the attacker to view… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoft #CVE #infosec A flaw in Microsoft 365 Copilot lets someone with valid access run special commands that increase their
CVE-2026-87701 - azure cosmos db A flaw in Azure Cosmos DB’s handling of certain data can let a user who is already signed in increase their access rights across the network, potentially seeing or changing data… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoft #CVE #infosec A flaw in Azure Cosmos DB’s handling of certain data can let a user who is already signed in increase thei
CVE-2026-85889 - azure ai foundry Azure AI Foundry does not check who is using a key function, so someone on the network who should not have permission can raise their rights to act like an administrator. This… Too many irrelevant or confusing CVEs? Use stackflag.com #microsoft #CVE #infosec Azure AI Foundry does not check who is using a key function, so someone on the network who should not have
CVE-2026-13684 - diskstation manager (dsm) Versions of Synology DiskStation Manager before the latest updates may let a remote user trick the system into handling data incorrectly. This can lead… Too many irrelevant or confusing CVEs? Use stackflag.com #diskstationmanager #synology #CVE #infosec Versions of Synology DiskStation Manager before the latest updates may let a remote user trick the syst
CVE-2026-13639 - diskstation manager (dsm) Older versions of Synology DiskStation Manager may not generate enough random data during login, letting attackers guess authentication tokens. This can… Too many irrelevant or confusing CVEs? Use stackflag.com #diskstationmanager #synology #CVE #infosec Older versions of Synology DiskStation Manager may not generate enough random data during login, letti
CVE-2026-90999 - sentry seer Sentry Seer may let an outside person send false event data that is treated as code and run by its automation agent with high privileges. This could let a hacker perform… Too many irrelevant or confusing CVEs? Use stackflag.com #sentryseer #functional #CVE #infosec Sentry Seer may let an outside person send false event data that is treated as code and run by its automa
CVE-2026-90230 - linux The NVMe target code in the Linux kernel could read past the end of a data buffer when handling authentication data from a connected device. This can happen if a device sends… Too many irrelevant or confusing CVEs? Use stackflag.com #linux #canonical #Debian12 #CVE #infosec The Debian Linux kernel’s NVMe target component could read past the end of a memory buffer when handli
CVE-2026-58264 - fluidsynth Versions of FluidSynth from 1.1.2 up to 2.5.6 let a specially crafted pitch‑bend range command write data outside the program’s memory. This can make the program stop… Too many irrelevant or confusing CVEs? Use stackflag.com #fluidsynth #debian #Debian11 #CVE #infosec Versions of FluidSynth from 1.1.2 up to 2.5.6 let a specially crafted pitch‑bend range command write da
CVE-2026-10747 - mq appliance The IBM MQ Appliance can be tricked by specially crafted network messages to overflow its memory before a user logs in. This could cause the system to stop working or allow an… Too many irrelevant or confusing CVEs? Use stackflag.com #mqappliance #ibm #CVE #infosec The IBM MQ Appliance can be tricked by specially crafted network messages to overflow its memory before
CVE-2026-77240 - wacrm The WACRM CRM template for WhatsApp (versions up to 0.7.0) allows a logged‑in user to change their own role and account identifier, which can let them act as an administrator or move… Too many irrelevant or confusing CVEs? Use stackflag.com #wacrm #arnasdon #CVE #infosec The WACRM CRM template for WhatsApp (versions up to 0.7.0) allows a logged‑in user to change their own ro
CVE-2026-92701 - cocos Versions of Cocos up to 0.8.2 can be tricked into accepting a proof of trust that does not match the current connection, letting an attacker link the session to the wrong user.… Too many irrelevant or confusing CVEs? Use stackflag.com #cocos #ultravioletrs #CVE #infosec Versions of Cocos up to 0.8.2 can be tricked into accepting a proof of trust that does not match the curre
CVE-2026-93762 - mongoid Mongoid, the Ruby library that connects applications to MongoDB, can be tricked into revealing private document information and deleting records when it processes a field name… Too many irrelevant or confusing CVEs? Use stackflag.com #mongoid #mongodb #CVE #infosec Mongoid, the Ruby library that connects applications to MongoDB, can be tricked into revealing private docume
CVE-2026-63647 - cordyscrm In versions before 1.7.2, CordysCRM exposed public endpoints that let anyone listen to or interfere with another user's real‑time notifications. An unauthenticated person could… Too many irrelevant or confusing CVEs? Use stackflag.com #cordyscrm #1paneldev #CVE #infosec In versions before 1.7.2, CordysCRM exposed public endpoints that let anyone listen to or interfere wi
CVE-2026-93868 - cotonti The password reset feature in Cotonti (up to version 1.0.0) creates codes that can be guessed because they are based on the server's current time. An attacker who knows the server's clock can… Too many irrelevant or confusing CVEs? Use stackflag.com #cotonti #CVE #infosec The password reset feature in Cotonti (up to version 1.0.0) creates codes that can be guessed because
CVE-2026-80441 - guardium data protection IBM Guardium Data Protection version 12.2 can be tricked into running harmful database commands that an attacker sends without logging in. This could let a remote attacker view,… Too many irrelevant or confusing CVEs? Use stackflag.com #ibm #CVE #infosec IBM Guardium Data Protection version 12.2 can be tricked into running harmful database commands that an
CVE-2026-82832 - guardium data protection IBM Guardium Data Protection version 12.2 can be tricked by a signed‑in user to run any program they choose because it does not properly clean data shown on web pages. This could… Too many irrelevant or confusing CVEs? Use stackflag.com #ibm #CVE #infosec IBM Guardium Data Protection version 12.2 can be tricked by a signed‑in user to run any program they c
CVE-2026-84031 - guardium data protection Version 12.2 of IBM Guardium Data Protection can be tricked by a remote user who has login credentials into executing their own programs on the server. This could expose or… Too many irrelevant or confusing CVEs? Use stackflag.com #ibm #CVE #infosec Version 12.2 of IBM Guardium Data Protection can be tricked by a remote user who has login credentials into
CVE-2026-84073 - guardium data protection IBM Guardium Data Protection version 12.2 can be tricked by a logged‑in user into running unintended database commands. This could let the attacker change, view, or delete data… Too many irrelevant or confusing CVEs? Use stackflag.com #ibm #CVE #infosec IBM Guardium Data Protection version 12.2 can be tricked by a logged‑in user into running unintended dat
CVE-2026-84078 - guardium data protection The Guardium Data Protection 12.2 product lets anyone reach a special web component that controls load‑balancing without needing to log in. This could let an outsider change how… Too many irrelevant or confusing CVEs? Use stackflag.com #ibm #CVE #infosec The Guardium Data Protection 12.2 product lets anyone reach a special web component that controls load‑
CVE-2026-93839 LightLLM versions up through 1.2.0 let anyone connect to its /pd_register WebSocket address and add their own nodes without proving who they are. Doing this can let an attacker see the questions users type,… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec LightLLM versions up through 1.2.0 let anyone connect to its /pd_register WebSocket address and add their
CVE-2026-92751 - cmak The CMAK tool (versions up to 3.0.0.6) does not block forged web requests, so a malicious site could trick a logged‑in administrator into performing actions like deleting topics or altering… Too many irrelevant or confusing CVEs? Use stackflag.com #cmak #yahoo #CVE #infosec The CMAK tool (versions up to 3.0.0.6) does not block forged web requests, so a malicious site could tr