社区情报
来自安全社区、研究机构和开源生态的情报。
-
CVE-2026-59845 | Red Hat Enterprise Linux libssh fork denial of service
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a>. This affects the function <code>fork</code> of the component <em>libssh</em>. The manipulation results in denial of service. This vulnerability is cataloged as <…
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a>. This affects the function <code>fork</code> of the component <em>libssh</em>. The manipulation results in denial of service. This vulnerability is cataloged as <A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux</a>. This affects the function <code>fork</code> of the component <em>libssh</em>. The manipulation results in denial of service. This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-59845">CVE-2026-59845</a>. The attack may be launched remotely. There is no exploit available.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:26:48 +0200" } -
CVE-2026-64628 | getgrav up to 6.2.1 shortcode-core attribute handlers cross site scripting
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/getgrav:grav">getgrav grav up to 6.2.1</a>. Affected by this issue is some unknown functionality of the component <em>shortcode-core attribute handlers</em>. The manipulation leads to cross site scripting. This v…
A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/getgrav:grav">getgrav grav up to 6.2.1</a>. Affected by this issue is some unknown functionality of the component <em>shortcode-core attribute handlers</em>. The manipulation leads to cross site scripting. This vA vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/getgrav:grav">getgrav grav up to 6.2.1</a>. Affected by this issue is some unknown functionality of the component <em>shortcode-core attribute handlers</em>. The manipulation leads to cross site scripting. This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2026-64628">CVE-2026-64628</a>. The attack may be initiated remotely. There is no available exploit.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:25:44 +0200" } -
CVE-2026-65007 | getgrav Api Plugin up to 1.0.7 API apiKeyGenerate/apiKeyRevoke improper authorization
A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/getgrav:api_plugin">getgrav Api Plugin up to 1.0.7</a>. Affected by this vulnerability is the function <code>apiKeyGenerate/apiKeyRevoke</code> of the component <em>API</em>. Executing a manipulation can lead to improper authoriza…
A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/getgrav:api_plugin">getgrav Api Plugin up to 1.0.7</a>. Affected by this vulnerability is the function <code>apiKeyGenerate/apiKeyRevoke</code> of the component <em>API</em>. Executing a manipulation can lead to improper authorizaA vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/getgrav:api_plugin">getgrav Api Plugin up to 1.0.7</a>. Affected by this vulnerability is the function <code>apiKeyGenerate/apiKeyRevoke</code> of the component <em>API</em>. Executing a manipulation can lead to improper authorization. This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-65007">CVE-2026-65007</a>. The attack can be launched remotely. No exploit exists.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:24:45 +0200" } -
CVE-2026-16461 | Red Hat Enterprise Linux/OpenShift Container Platform rpcinfo rpcbdump stack-based overflow
A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux and OpenShift Container Platform</a>. Affected is the function <code>rpcbdump</code> of the component <em>rpcinfo</em>. Performing a manipulation results in stack-based buffer o…
A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux and OpenShift Container Platform</a>. Affected is the function <code>rpcbdump</code> of the component <em>rpcinfo</em>. Performing a manipulation results in stack-based buffer oA vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/red_hat:enterprise_linux">Red Hat Enterprise Linux and OpenShift Container Platform</a>. Affected is the function <code>rpcbdump</code> of the component <em>rpcinfo</em>. Performing a manipulation results in stack-based buffer overflow. This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-16461">CVE-2026-16461</a>. The attack can be initiated remotely. There is not any exploit available.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:21:45 +0200" } -
CVE-2026-64627 | parse-community parse-server up to 9.10.0-alpha.3/8.6.84 GraphQL API information disclosure
A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/parse-community:parse-server">parse-community parse-server up to 9.10.0-alpha.3/8.6.84</a>. This impacts an unknown function of the component <em>GraphQL API</em>. Such manipulation leads to information disclosure. This …
A vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/parse-community:parse-server">parse-community parse-server up to 9.10.0-alpha.3/8.6.84</a>. This impacts an unknown function of the component <em>GraphQL API</em>. Such manipulation leads to information disclosure. ThisA vulnerability described as <a href="https://vuldb.com/kb/risk">problematic</a> has been identified in <a href="https://vuldb.com/product/parse-community:parse-server">parse-community parse-server up to 9.10.0-alpha.3/8.6.84</a>. This impacts an unknown function of the component <em>GraphQL API</em>. Such manipulation leads to information disclosure. This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-64627">CVE-2026-64627</a>. It is possible to launch the attack remotely. No exploit is available.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:20:45 +0200" } -
CVE-2026-65009 | OpenRemote up to 1.26.1 SyslogResource REST endpoint /syslog/event realm information disclosure
A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/openremote">OpenRemote up to 1.26.1</a>. This affects an unknown function of the file <em>/syslog/event</em> of the component <em>SyslogResource REST endpoint</em>. This manipulation of the argument <em>realm</em> causes infor…
A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/openremote">OpenRemote up to 1.26.1</a>. This affects an unknown function of the file <em>/syslog/event</em> of the component <em>SyslogResource REST endpoint</em>. This manipulation of the argument <em>realm</em> causes inforA vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/openremote">OpenRemote up to 1.26.1</a>. This affects an unknown function of the file <em>/syslog/event</em> of the component <em>SyslogResource REST endpoint</em>. This manipulation of the argument <em>realm</em> causes information disclosure. The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-65009">CVE-2026-65009</a>. It is possible to initiate the attack remotely. There is no exploit available.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:19:43 +0200" } -
CVE-2026-65008 | getgrav Grav up to 2.0.6 Blueprint Blueprint.php Blueprint::dynamicData code injection
A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/getgrav:grav">getgrav Grav up to 2.0.6</a>. The impacted element is the function <code>Blueprint::dynamicData</code> of the file <em>system/src/Grav/Common/Data/Blueprint.php</em> of the component <em>Blueprint</em>. The manipul…
A vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/getgrav:grav">getgrav Grav up to 2.0.6</a>. The impacted element is the function <code>Blueprint::dynamicData</code> of the file <em>system/src/Grav/Common/Data/Blueprint.php</em> of the component <em>Blueprint</em>. The manipulA vulnerability labeled as <a href="https://vuldb.com/kb/risk">problematic</a> has been found in <a href="https://vuldb.com/product/getgrav:grav">getgrav Grav up to 2.0.6</a>. The impacted element is the function <code>Blueprint::dynamicData</code> of the file <em>system/src/Grav/Common/Data/Blueprint.php</em> of the component <em>Blueprint</em>. The manipulation results in code injection. This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-65008">CVE-2026-65008</a>. The attack may be performed from remote. There is no available exploit.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 14:18:48 +0200" } -
CVE-2026-1617 | Turkmesh Communication Services Turkhotspot Loglama up to 5.1.2 sql injection
A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/turkmesh_communication_services:turkhotspot_loglama">Turkmesh Communication Services Turkhotspot Loglama up to 5.1.2</a>. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerabili…
A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/turkmesh_communication_services:turkhotspot_loglama">Turkmesh Communication Services Turkhotspot Loglama up to 5.1.2</a>. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerabiliA vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/turkmesh_communication_services:turkhotspot_loglama">Turkmesh Communication Services Turkhotspot Loglama up to 5.1.2</a>. The affected element is an unknown function. The manipulation leads to sql injection. This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-1617">CVE-2026-1617</a>. The attack is possible to be carried out remotely. No exploit exists.扩展字段
{ "raw_pub_date": "Tue, 21 Jul 2026 13:48:38 +0200" }