Skip to content

Commit 52d3aba

Browse files
Update Tue Jul 7 12:02:03 UTC 2026
1 parent ae6c38f commit 52d3aba

87 files changed

Lines changed: 1334 additions & 2 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

2018/CVE-2018-21035.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ In Qt through 5.14.1, the WebSocket implementation accepts up to 2GB for frames
1010
### POC
1111

1212
#### Reference
13-
No PoCs from references.
13+
- https://bugreports.qt.io/browse/QTBUG-70693
1414

1515
#### Github
1616
- https://github.com/PalindromeLabs/awesome-websocket-security

2020/CVE-2020-35852.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,7 @@ Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any
1010
### POC
1111

1212
#### Reference
13+
- https://getgist.com/chatbot-software/
1314
- https://github.com/riteshgohil/My_CVE/blob/main/CVE-2020-35852.md
1415

1516
#### Github

2023/CVE-2023-2626.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ There exists an authentication bypass vulnerability in OpenThread border router
1818
### POC
1919

2020
#### Reference
21-
No PoCs from references.
21+
- https://support.google.com/product-documentation/answer/13588832?hl=en&ref_topic=12974021&sjid=7833436865896465963-NA#zippy=%2Cnest-wifi
2222

2323
#### Github
2424
- https://github.com/Qorvo/QGateway

2025/CVE-2025-15582.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ A security flaw has been discovered in detronetdip E-commerce 1.0.0. The impacte
1111
### POC
1212

1313
#### Reference
14+
- https://github.com/Nixon-H/Ecommerce-IDOR-Product-Manipulation
1415
- https://github.com/detronetdip/E-commerce/issues/23
1516

1617
#### Github

2025/CVE-2025-15668.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
### [CVE-2025-15668](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15668)
2+
![](https://img.shields.io/static/v1?label=Product&message=GPAC&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=b40ce70f5%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=Heap-based%20Buffer%20Overflow&color=brightgreen)
5+
![](https://img.shields.io/static/v1?label=Vulnerability&message=Memory%20Corruption&color=brightgreen)
6+
7+
### Description
8+
9+
A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/isomedia/box_code_base.c of the component MP4Box. Such manipulation of the argument data leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The name of the patch is f29f955f2a3b5e8e507caad3e52319f961bf37bf. It is advisable to implement a patch to correct this issue.
10+
11+
### POC
12+
13+
#### Reference
14+
- https://github.com/gpac/gpac/issues/3398
15+
16+
#### Github
17+
No PoCs found on GitHub currently.
18+

2026/CVE-2026-10834.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2026-10834](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-10834)
2+
![](https://img.shields.io/static/v1?label=Product&message=WP%20Travel%20Engine&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-73%20External%20Control%20of%20File%20Name%20or%20Path&color=brightgreen)
5+
6+
### Description
7+
8+
The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile image path before moving the file, allowing authenticated users with subscriber-level access and above to relocate arbitrary files within the WordPress uploads directory into their own profile-image path. This removes the targeted media from its original location and can break content across the site.
9+
10+
### POC
11+
12+
#### Reference
13+
- https://wpscan.com/vulnerability/5b939f98-0fbd-4f89-9948-77dbcc67f9d3/
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

2026/CVE-2026-12277.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2026-12277](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12277)
2+
![](https://img.shields.io/static/v1?label=Product&message=Frontend%20File%20Manager%20Plugin&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-73%20External%20Control%20of%20File%20Name%20or%20Path&color=brightgreen)
5+
6+
### Description
7+
8+
The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the site into its setup routine, which can be leveraged toward a full site takeover.
9+
10+
### POC
11+
12+
#### Reference
13+
- https://wpscan.com/vulnerability/30f208f6-9d7b-4aaf-8689-496521d1a1dc/
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

2026/CVE-2026-12375.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2026-12375](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-12375)
2+
![](https://img.shields.io/static/v1?label=Product&message=uncanny-automator-pro&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=7.3.0.5%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-912%20Hidden%20Functionality&color=brightgreen)
5+
6+
### Description
7+
8+
The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plugin before 7.3.0.6 update/distribution infrastructure was compromised; the injected backdoor grants unauthenticated attackers an administrator session on affected sites and beacons the site's secret keys and administrator details to attacker-controlled servers.
9+
10+
### POC
11+
12+
#### Reference
13+
- https://wpscan.com/vulnerability/ddc83705-3df6-427c-957b-935135330f73/
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

2026/CVE-2026-13578.md

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
### [CVE-2026-13578](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-13578)
2+
![](https://img.shields.io/static/v1?label=Product&message=Hospital%20Management%20System&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=1.0%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=Injection&color=brightgreen)
5+
![](https://img.shields.io/static/v1?label=Vulnerability&message=SQL%20Injection&color=brightgreen)
6+
7+
### Description
8+
9+
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing a manipulation of the argument editid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
10+
11+
### POC
12+
13+
#### Reference
14+
- https://vuldb.com/vuln/374584/cti
15+
16+
#### Github
17+
No PoCs found on GitHub currently.
18+

2026/CVE-2026-14536.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
### [CVE-2026-14536](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-14536)
2+
![](https://img.shields.io/static/v1?label=Product&message=Server&color=blue)
3+
![](https://img.shields.io/static/v1?label=Version&message=2026.2.4%20&color=brightgreen)
4+
![](https://img.shields.io/static/v1?label=Vulnerability&message=cwe-693&color=brightgreen)
5+
6+
### Description
7+
8+
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value.
9+
10+
### POC
11+
12+
#### Reference
13+
- https://devolutions.net/security/advisories/DEVO-2026-0023/
14+
15+
#### Github
16+
No PoCs found on GitHub currently.
17+

0 commit comments

Comments
 (0)