Overview
- leepeuker
- movary
Description
Statistics
- 1 Post
Fediverse
๐ด CVE-2026-23840 - Critical (9.3)
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryDeleted=`...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23840/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- dokaninc
- Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ Build Your Own Amazon, eBay, Etsy
Description
Statistics
- 1 Post
Fediverse
๐ CVE-2025-14977 - High (8.1)
The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution โ Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.2.4 via the `/wp-json/dokan/v1/sett...
๐ https://www.thehackerwire.com/vulnerability/CVE-2025-14977/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- leepeuker
- movary
Description
Statistics
- 1 Post
Fediverse
๐ด CVE-2026-23841 - Critical (9.3)
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryCreated=`...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23841/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Quenary
- tugtainer
Description
Statistics
- 1 Post
Fediverse
๐ CVE-2026-23846 - High (8.1)
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password authentication mechanism transmits passwords via URL query parameters instead of the HTTP request body. This causes passwords to ...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23846/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- opf
- openproject
Description
Statistics
- 1 Post
Fediverse
๐ CVE-2026-23625 - High (8.7)
OpenProject is an open-source, web-based project management software. Versions 16.3.0 through 16.6.4 are affected by a stored cross-site scripting vulnerability in the Roadmap view. OpenProjectโs roadmap view renders the โRelated work packages...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23625/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- gunthercox
- ChatterBot
Description
Statistics
- 1 Post
Fediverse
๐ CVE-2026-23842 - High (7.5)
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool management. Concurrent ...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- jaraco
- jaraco.context
Description
Statistics
- 1 Post
Fediverse
๐ CVE-2026-23949 - High (8.6)
jaraco.context, an open-source software package that provides some useful decorators and context managers, has a Zip Slip path traversal vulnerability in the `jaraco.context.tarball()` function starting in version 5.2.0 and prior to version 6.1.0....
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- fastify
- middie
Description
Statistics
- 1 Post
Fediverse
๐ CVE-2026-22031 - High (8.4)
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded ...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-22031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- franklioxygen
- MyTube
Description
Statistics
- 1 Post
Fediverse
๐ด CVE-2026-23837 - Critical (9.8)
MyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions allows unauthenticated users to bypass the mandatory authentication check in the roleBasedAuthMidd...
๐ https://www.thehackerwire.com/vulnerability/CVE-2026-23837/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Fediverse
GNU C Library fixes a security Issue present since 1996 (getnetbyaddr and getnetbyaddr_r functions can leak the stack contents to the DNS resolver) CVE-2026-0915 #Infosec https://sourceware.org/git/?p=glibc.git;a=commit;h=e56ff82d5034ec66c6a78f517af6faa427f65b0b