Sign in

EUVD Bot

@euvd-bot.bsky.social
176 followers 1 following 65K posts

🛡️ Unofficial bot posting new entries from the EU Vulnerability Database (EUVD). 🔔 Stay updated on the latest security vulnerabilities. 🤖 Automated • Not affiliated with ENISA or the EU Maintainer: bsky.app/profile/moltenbit.bsky.soc…

PostsRepliesMedia
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2024-23772 📊 7.8/10 📝 An issue in FinalWire AIRDA Extreme, AIDA64 Engineer, AIDA64 Business, AIDA64 Network Audit through 7.00.6742 allows a local attacker to escalate privileges via the... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94359 📊 n/a 📝 An issue in iTerm2 macOS before 3.6.12 allows a local attacker to obtain sensitive information. 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94358 📊 n/a 📝 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to corrupt heap memory in the SUID-root n... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94357 📊 n/a 📝 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_decompress() in compress.c that allows an attacker to corrupt one byte of heap memory in the SUID-roo... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94356 📊 n/a 📝 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in cat() in ntfscat.c that allows an attacker to corrupt heap memory in the ntfscat binary by crafting a mali... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94355 📊 n/a 📝 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94354 📊 n/a 📝 In NTFS-3G before 2026.7.7, a heap buffer overflow exists in ntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to corrupt heap memory in the SUID-roo... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-93792 📊 7.1/10 🏢 TP-Link Systems Inc. 📝 TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthentica... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94353 📊 n/a 📝 In NTFS-3G before 2026.7.7, a out-of-bounds read exists in ntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to read possibly confidential informati... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94326 📊 n/a 🏢 SonicWall 📝 A Zip Slip vulnerability in the in the SMA1000 Appliance Management Console (AMC) interface allows an attacker to extract files outside the intended destin... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94327 📊 n/a 🏢 SonicWall 📝 Post-authentication Stored Cross-Site Scripting (XSS) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94328 📊 7.1/10 🏢 wger-project 📝 wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94329 📊 8.6/10 🏢 Telegram 📝 Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: reco... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94330 📊 9.2/10 🏢 ggml-org 📝 llama.cpp before b11393 contains a use-after-free and double free vulnerability in common_chat_peg_mapper::map that allows unauthenticated remote attacke... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94331 📊 5.4/10 🏢 wger-project 📝 wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `dj... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 19m
🚨 EUVD-2026-94332 📊 9.2/10 🏢 SunGrow 📝 Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local b... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 20m
🚨 EUVD-2026-94333 📊 7.1/10 🏢 wger-project 📝 wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any accou... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 20m
🚨 EUVD-2026-94334 📊 4.8/10 🏢 wger-project 📝 wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger`... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 20m
🚨 EUVD-2026-94335 📊 6.5/10 🏢 wger-project 📝 wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries int... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94309 📊 7.1/10 🏢 obot-platform 📝 Obot 0.12.0 before 0.26.2 contains an insufficiently protected credentials vulnerability that allows authenticated users to read static secrets set ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94310 📊 5.3/10 🏢 obot-platform 📝 Obot 0.26.0 before 0.26.2 contains an authorization bypass vulnerability that allows authenticated users matching any vMCP profile to reach prompts ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94311 📊 2.3/10 🏢 obot-platform 📝 Obot 0.25.0 before 0.25.6 and 0.26.0 before 0.26.1 contains a race condition in auth provider group refreshes that can restore group memberships jus... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94312 📊 5.9/10 📝 Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report whe... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94313 📊 6.2/10 📝 A flaw was found in m17n-lib. By providing crafted input containing an invalid UTF-8 character sequence, an attacker can cause the text parsing function to enter an... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94314 📊 5.3/10 🏢 MISP 📝 MISP contains a defect in its event save workflow that prevents the correlation engine from recalculating correlations when an event's distribution level or ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94315 📊 2.9/10 📝 A flaw was found in m17n-lib. A partial failure during library initialization can leave an internal driver pointer uninitialized. Under specific error conditions, s... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94316 📊 7.6/10 🏢 ExpressGateway 📝 Express Gateway through 1.16.11 contains an authentication bypass vulnerability in the OAuth 2.0 refresh_token grant that fails to validate the tok... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94317 📊 7.4/10 🏢 ExpressGateway 📝 Express Gateway through 1.16.11 contains a hardcoded cryptographic key vulnerability that allows attackers with datastore access to decrypt stored ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94318 📊 7.1/10 🏢 MISP 📝 On MISP instances configured to require TOTP enrolment (Security.otp_required), the enforcement of the mandatory two-factor authentication setup applied only... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94319 📊 7.7/10 🏢 Anthropic 📝 Claude Code validated that a target file path resided within the project working directory at permission-check time, but re-resolved the path at write t... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94320 📊 5.5/10 🏢 visidata 📝 A path traversal vulnerability exists in the EmailSheet extract_parts functionality of VisiData (version(s): dev (commit 38b21f78)). A specially crafted ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94321 📊 6.5/10 🏢 visidata 📝 A path traversal vulnerability exists in the unzip_http RemoteZipFile extract functionality of VisiData (version(s): dev (commit 38b21f78)). A specially ... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94322 📊 n/a 🏢 Linux 📝 In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: preserve mremap address delta when skipping page tables move_hugetlb_page_tab... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94323 📊 n/a 🏢 Linux 📝 In the Linux kernel, the following vulnerability has been resolved: tcp: fix use-after-free of retransmit_skb_hint in tcp_send_synack() When tcp_send_synack(... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94324 📊 n/a 🏢 SonicWall 📝 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this pa... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 1h
🚨 EUVD-2026-94325 📊 n/a 🏢 SonicWall 📝 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-93781 📊 5.4/10 📝 A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Sp... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-93922 📊 4.3/10 🏢 Gitea 📝 With `[migrations] ALLOWED_DOMAINS` set to a matching entry such as `*` or a hostname wildcard, Gitea's migration URL validation could permit reserved and l... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-93908 📊 7.7/10 🏢 Gitea 📝 When `[migrations] ALLOWED_DOMAINS` was configured, a hostname matching the allow list was accepted without checking its resolved address against the local-... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94302 📊 7.6/10 🏢 10web 📝 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Slider by 10Web slider-wd allows Blind SQL Injec... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94303 📊 7.6/10 🏢 AF themes 📝 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AF themes WP Post Author wp-post-author allows Bli... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94304 📊 7.7/10 🏢 rundeck 📝 Rundeck before 6.2.0 contains an OS command injection vulnerability that allows authenticated users with job run permission to execute commands on Windows... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94305 📊 8.5/10 🏢 wummel 📝 patool before 4.0.6 contains an OS command injection vulnerability on Windows because shell_quote_nt fails to escape cmd.exe metacharacters or embedded dou... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94306 📊 7.7/10 🏢 gitahead 📝 GitAhead through 2.7.1 contains an OS command injection vulnerability in src/git/Filter.cpp that allows malicious repositories to execute commands by sub... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94307 📊 8.7/10 🏢 gitahead 📝 GitAhead through 2.7.1 on macOS contains a command injection vulnerability that allows attackers to execute shell commands by crafting repository filenam... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 2h
🚨 EUVD-2026-94308 📊 7.1/10 🏢 miniupnp project 📝 MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local netwo... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 4h
🚨 EUVD-2026-94247 📊 6.5/10 🏢 bdthemes 📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-ele... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 4h
🚨 EUVD-2026-94248 📊 6.5/10 🏢 David Lingren 📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in David Lingren Media LIbrary Assistant media-li... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 4h
🚨 EUVD-2026-94249 📊 6.5/10 🏢 bdthemes 📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Element Pack Elementor Addons bdthemes-ele... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000
EUVD Bot @euvd-bot.bsky.social · 4h
🚨 EUVD-2026-94250 📊 6.5/10 🏢 WP Media 📝 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Media Rocket Lazy Load rocket-lazy-load allows S... 🔗 euvd.enisa.europa.eu/vulnerability/… #cybersecurity #infosec #cve #euvd
000