Výsledky hledání

typ: zranitelnost× v celém archivu zrušit filtry

166 karet z 187 položek · strana 3 z 3 CZ · EN/orig

4

ZDI-26-614: (0Day) pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zneužíváno tg: zranitelnost

Zero Day Initiative ·

ZDI-26-615: (0Day) pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.

CVSS 7.8 pdfforge US

tg: zneužíváno tg: zranitelnost

Zero Day Initiative ·

1

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-76581, CVE-2026-18431, CVE-2026-19632, CVE-2026-19598, CVE-2026-82222, Summary: Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack,…

EPSS 0.03 CVSS 10.0 CVE-2026-18431 CVE-2026-19598 CVE-2026-19632 CVE-2026-76581 CVE-2026-82222 WPMU DEV Avada TranslatePress Pods FI

tg: zneužíváno tg: zranitelnost tp: malware

NCSC-FI ·

39

WebPros security advisory (AV26-861)

Serial Number: AV26-861Date: August 28, 2026 As of August 27, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.141 Prior to 11.134.0.53 Prior to 11.136.0.37 Prior to 11.138.0.2 Prior to WP2: 11.138.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking…

CVE-2026-65643 cPanel CA IT FI 3 zdrojů

tg: zranitelnost

Cyber Centre Kanada · CSIRT Itálie (ACN) · NCSC-FI

Grafana security advisory (AV26-860)

Serial Number: AV26-860Date: August 28, 2026 As of August 27, 2026, Grafana is affected by a vulnerability in the following product: Alloy Prior to or equal to 1.18.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Grafana: The open and composable observability platform | Grafana Labs CVE-2026-19516 CVE Record

EPSS 0.00 CVE-2026-19516 Grafana CA IT 2 zdrojů

tg: zranitelnost

Cyber Centre Kanada · CSIRT Itálie (ACN)

Redis security advisory (AV26-859)

Serial Number: AV26-859Date: August 28, 2026 As of August 27, 2026, Redis is affected by a vulnerability in the following product: Redis 8.0 All except 8.10.1 All except 8.2.9 All except 8.4.6 All except 8.6.6 All except 8.8.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Fix use-after-free in tlsProcessPendingData() pending-list iteration GitHub Releases

Redis CA

tg: zranitelnost

Cyber Centre Kanada ·

PaperCut security advisory (AV26-858)

Serial number: AV26-858Date: August 28, 2026 As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products: PaperCut MF Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 PaperCut NG Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 The Cyber Centre encourages users and administrators to review the provided web link and apply any…

PaperCut CA

tg: zranitelnost

Cyber Centre Kanada ·

ServiceNow security advisory (AV26-857)

Serial number: AV26-857Date: August 28, 2026 As of August 27, 2026, ServiceNow is affected by vulnerabilities in the following products: Xanadu Versions prior to Patch 11 Hot Fix 7a Yokohama Versions prior to Yokohama Patch 12 Hot Fix 3b Versions prior to Yokohama Patch 13 Hot Fix 4 Zurich Multiple versions Australia Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. August 2026 CVE…

ServiceNow CA

tg: zranitelnost

Cyber Centre Kanada ·

NCSC-2026-0334 [1.00] [M/H] Kwetsbaarheden verholpen in PaperCut MF en PaperCut NG van PaperCut

PaperCut heeft kwetsbaarheden verholpen in PaperCut MF en PaperCut NG. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheden mogelijk achtereenvolgens misbruiken om een PaperCut-omgeving over te nemen en hierop willekeurige code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de kwetsbare PaperCut-omgeving te sturen.

PaperCut NL

tg: zranitelnost

NCSC-NL ·

[Control Systems] National Instruments security advisory (AV26-856)

Serial Number: AV26-856Date: August 28, 2026 As of August 25, 2026, National Instruments is affected by vulnerabilities in the following product: LabVIEW Prior to 23.0.0 Prior to 23.3.10 Prior to 24.3.7 Prior to 25.3.5 Prior to 26.3.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Memory Corruption Vulnerabilities in NI LabVIEW - NI Integer Conversion Vulnerability Resulting in an Out of Bounds Read…

National Instruments výroba a průmysl energetika vodárenství telekomunikace CA

tg: zranitelnost tp: průmyslové systémy

Cyber Centre Kanada ·

Rilevate vulnerabilità in prodotti MongoDB

Rilevate molteplici vulnerabilità, tra cui 6 con gravità “alta”, in varie librerie client per MongoDB. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato la modifica non autorizzata di dati o codice e la compromissione della disponibilità del servizio sui sistemi interessati.

CVE-2026-75159 CVE-2026-81521 CVE-2026-81522 CVE-2026-81525 CVE-2026-81526 CVE-2026-81529 MongoDB IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

NCSC-2026-0333 [1.00] [M/H] Kwetsbaarheden verholpen in CodeMeter Runtime van Wibu-Systems

Wibu-Systems heeft meerdere kwetsbaarheden verholpen in CodeMeter Runtime. De kwetsbaarheden bevinden zich in verschillende onderdelen van CodeMeter Runtime, met name in versies voor 8.41a en 9.10. Een lokale aanvaller kan misbruik maken van onjuiste verificatie van NTFS reparse points bij het aanmaken van tijdelijke bestanden door cmu.exe, wat kan leiden tot het verwijderen van willekeurige systeembestanden met System-privileges en daarmee lokale privilege-escalatie. Daarnaast bevat de…

EPSS 0.00 CVE-2026-81573 Wibu-Systems NL

tg: zranitelnost

NCSC-NL ·

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the time of writing, the vulnerability has not been assigned a CVE identifier, and PaperCut has not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details…

KEV ✓ EPSS 1.00 CVE-2023-27350 PaperCut Software PaperCut školství výroba a průmysl US 2 zdrojů

tg: zneužíváno tg: zranitelnost tp: malware

Rapid7 · BleepingComputer

Sanata vulnerabilità in Grafana Alloy

Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” presente in Grafana Alloy, agente open source per la raccolta ed elaborazione di dati di osservabilità e monitoraggio. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a un utente malintenzionato di accedere ad informazioni sensibili sui sistemi interessati.

CVE-2026-75889 Grafana IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

Aggiornamenti di sicurezza sanano molteplici vulnerabilità in ServiceNow

Rilasciati aggiornamenti di sicurezza che sanano 4 vulnerabilità ,di cui una con gravità "alta" e 3 con gravità "critica", presenti nella piattaforma ServiceNow. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un attaccante non autenticato di eseguire codice arbitrario, manipolare dati delle istanze e ottenere privilegi elevati sui sistemi interessati.

CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-6876 CVE-2026-74820 ServiceNow IT FI 2 zdrojů

tg: zranitelnost

CSIRT Itálie (ACN) · NCSC-FI

Risolte vulnerabilità in prodotti WatchGuard

Aggiornamenti di sicurezza sanano numerose vulnerabilità, tra cui 5 con gravità "critica" e 12 con gravità “alta”, in prodotti WatchGuard. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione, eseguire codice arbitrario e/o compromettere la disponibilità del servizio sui sistemi interessati.

CVE-2026-13086 CVE-2026-13108 CVE-2026-19313 CVE-2026-19314 CVE-2026-19315 CVE-2026-19316 CVE-2026-19317 CVE-2026-19318 CVE-2026-78008 CVE-2026-78009 CVE-2026-78010 CVE-2026-78011 CVE-2026-78174 CVE-2026-78610 CVE-2026-78612 CVE-2026-78613 CVE-2026-78614 WatchGuard IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

1

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our…

EPSS 0.28 CVSS 9.5 CVE-2026-66066 Ruby on Rails US IT 2 zdrojů

tg: zranitelnost

Rapid7 · CSIRT Itálie (ACN)

1