CVE Security News

Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.

A CVE (Common Vulnerabilities and Exposures) entry is the standardized identifier assigned to a publicly disclosed security flaw, letting researchers, vendors and defenders reference the same vulnerability unambiguously. New CVE IDs show up here as soon as they are assigned, usually the first public signal that a product needs patching. Coverage ranges from obscure library bugs to critical remote-code-execution flaws in widely deployed software.

Recent CVE items

CVE-2026-102335 Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives.…
@cveNotify · Sep 28, 2026
CVE-2026-102334 Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers…
@cveNotify · Sep 28, 2026
CVE-2026-102332 Dozzle versions before 11.1.2 fail to sanitize container display names when building ZIP archive entry names in the log download endpoint. Attackers who can label containers can use pa…
@cveNotify · Sep 28, 2026
CVE-2026-101262 A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0 . This vulnerability affects unknown code of the file /api/ZRQos/set_online_client. The manipulation of the argument ip lea…
@cveNotify · Sep 28, 2026
CVE-2026-101261 A flaw has been found in Ziroom ZHOME A0101 1.0.1.0 . This affects an unknown part of the file /api/ZRnetwork/firstSetup_wifi. Executing a manipulation of the argument login_pwd can le…
@cveNotify · Sep 28, 2026
CVE-2026-101260 A vulnerability was detected in Ziroom ZHOME A0101 1.0.1.0 . Affected by this issue is some unknown functionality of the file /api/ZRnetwork/firstLogin. Performing a manipulation of th…
@cveNotify · Sep 28, 2026
CVE-2026-97721 A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/m…
@cveNotify · Sep 28, 2026
CVE-2026-97818 phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. 🎖
@cveNotify · Sep 28, 2026
CVE-2026-58147 WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special…
@cveNotify · Sep 28, 2026
CVE-2026-58146 WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie…
@cveNotify · Sep 28, 2026
CVE-2026-40857 WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value par…
@cveNotify · Sep 28, 2026
CVE-2026-40856 WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows…
@cveNotify · Sep 28, 2026
CVE-2026-40855 WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting t…
@cveNotify · Sep 28, 2026
CVE-2026-40854 WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie…
@cveNotify · Sep 28, 2026
CVE-2026-92357 A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the…
@cveNotify · Sep 28, 2026
CVE-2026-92356 A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Execut…
@cveNotify · Sep 28, 2026
CVE-2026-90049 In the Linux kernel, the following vulnerability has been resolved: net: skbuff: don't skb_tx_error() the source skb in skb_zerocopy() skb_zerocopy() copies frags from into @to. On an s…
@cveNotify · Sep 28, 2026
CVE-2026-90048 In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix slab-out-of-bounds write in ni_create_attr_list() ni_create_attr_list() allocates a fixed buffer of al_…
@cveNotify · Sep 28, 2026
CVE-2026-90047 In the Linux kernel, the following vulnerability has been resolved: drm/xe: Don't hand out the flat CCS storage as usable VRAM get_flat_ccs_offset() reads the base of the flat CCS stora…
@cveNotify · Sep 28, 2026
CVE-2026-90046 In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: don't spin_trylock() in NMI on UP Patch series "mm/page_alloc: fixes for free_pages_nolock() on RT/UP"…
@cveNotify · Sep 28, 2026
CVE-2026-102297 ZoneMinder before 1.38.4 fails to apply per-monitor access restrictions in the FramesController index endpoint. Authenticated users with Events view permission can call the frames API…
@cveNotify · Sep 28, 2026
CVE-2026-102296 ZoneMinder before 1.38.4 contains static buffer overflow vulnerabilities in RemoteCameraHttp::GetResponse() that allow malicious HTTP cameras or intercepting attackers to overflow fixe…
@cveNotify · Sep 28, 2026
CVE-2026-102281 Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message with a deeply nested object in its pattern can terminate a Nest…
@cveNotify · Sep 28, 2026
CVE-2026-101205 A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PCX Decoder. This manipulation causes out-of-bounds read. The atta…
@cveNotify · Sep 28, 2026
CVE-2026-101204 A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe of the component TGA Image Handler. The manipulation results in…
@cveNotify · Sep 28, 2026
CVE-2026-101203 A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the component 1bpp RLE Decoder. The manipulation leads to out-of-boun…
@cveNotify · Sep 28, 2026
CVE-2026-101202 A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component TGA Image Handler. Executing a manipulation can lead to out-of-b…
@cveNotify · Sep 28, 2026
CVE-2026-101188 A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak p…
@cveNotify · Sep 28, 2026
CVE-2026-101093 Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft…
@cveNotify · Sep 28, 2026
CVE-2026-101091 SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read…
@cveNotify · Sep 28, 2026

Other topics

Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.