MikeTrendsTrends right now

search

EUVD

Trends

  1. 1
    Cross-site scripting flaw found in Greek Open eClass platformโ–ผ๐Ÿšจ EUVD-2024-55777 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ Cross Site Scripting vulneMmastodonTechnologyCybersecurity03 d ago

    A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.

  2. 2
    Medium-severity vulnerability flagged in Burst Statistics WordPress pluginโ–ผ๐Ÿšจ EUVD-2026-91950 ๐Ÿ“Š Score: 4.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Burst Statistics โ€“ Simple WordPress Analytics (Google AnalyticsMmastodonTechnologyCybersecurity01 d ago

    A new vulnerability listing, EUVD-2026-91950, has been published for the Burst Statistics WordPress analytics plugin by vendor burstbv, an alternative to Google Analytics. The flaw carries a CVSS v3.1 score of 4.3 out of 10, indicating moderate severity. Administrators running the plugin on WordPress sites are advised to check for updates and patch promptly.

  3. 3
    New Linux kernel configfs vulnerability disclosedโ–ผ๐Ÿšจ EUVD-2026-86803 ๐Ÿ“Š Score: n/a ๐Ÿ“ฆ Product: Linux, Linux, Linux (+7 more) ๐Ÿข Vendor: Linux ๐Ÿ“… Published: 2026-09-25 | UpdateMmastodonTechnologyCybersecurity01 d ago

    A vulnerability in the Linux kernel, tracked as EUVD-2026-86803, has been published after a fix was merged. The flaw sits in the configfs filesystem's rmdir handling, where the dentry was not unhashed before the item was dropped. It affects Linux across multiple product entries, with no severity score assigned yet. Security watchers are noting the advisory as part of routine kernel vulnerability tracking.

  4. 4
    WordPress app builder plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91951 ๐Ÿ“Š Score: 5.4/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPMobile.App โ€“ Android and iOS App Builder ๐Ÿข Vendor: amauric ๐Ÿ“…MmastodonTechnologyCybersecurity01 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-91951 with a CVSS score of 5.4, has been disclosed in the WPMobile.App โ€“ Android and iOS App Builder WordPress plugin by vendor amauric. The flaw is a stored cross-site scripting issue reachable via the REQUEST_URI parameter, meaning attackers could inject malicious scripts that persist and run in visitors' browsers. Administrators running the plugin are advised to check for an updated version.

  5. 5
    WPC Product Options plugin hit by stored XSS flawโ–ผ๐Ÿšจ EUVD-2026-91952 ๐Ÿ“Š Score: 7.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: WPC Product Options for WooCommerce ๐Ÿข Vendor: WPClever ๐Ÿ“… UpdateMmastodonTechnologyCybersecurity01 d ago

    A stored cross-site scripting vulnerability, tracked as EUVD-2026-91952 and rated 7.2 out of 10 on the CVSS v3.1 scale, has been disclosed in the WPC Product Options for WooCommerce WordPress plugin from vendor WPClever. The flaw involves injection through wpcpo-* array keys submitted via multipart requests, meaning attackers could persist malicious scripts on product pages and target site visitors or administrators. The advisory record was updated on 3 October 2026.

  6. 6
    OpenTelemetry JavaScript instrumentation libraries flagged in new vulnerability advisoryโ–ผ๐Ÿšจ EUVD-2026-91788 ๐Ÿ“Š Score: 5.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: instrumentation-cassandra-driver, instrumentation-pg, instrumenMmastodonTechnologyCybersecurity01 d ago

    A medium-severity vulnerability, EUVD-2026-91788, has been catalogued affecting several OpenTelemetry JavaScript Contrib instrumentation packages, including instrumentation-cassandra-driver, instrumentation-pg and instrumentation-tedious. The flaw carries a CVSS v3.1 score of 5.8 out of 10 and was updated on 2 October 2026. Security teams monitoring dependencies in Node.js applications are likely reviewing whether their projects use the affected OpenTelemetry packages.

  7. 7
    Newly published flaw hits AVEZ Electronics learning platformโ–ผ๐Ÿšจ EUVD-2026-91567 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Learning Management System (LMS) ๐Ÿข Vendor: AVEZ Electronics ComMmastodonTechnologyCybersecurity02 d ago

    A medium-severity missing authorization vulnerability, tracked as EUVD-2026-91567 and scored 6.5 out of 10 under CVSS v3.1, has been published for the Learning Management System from Turkish vendor AVEZ Electronics Communication Training and Consultancy Trade Inc. The advisory was updated on 2 October 2026. Missing authorization flaws can let users perform actions without proper permissions, so administrators of the LMS are being urged to review the advisory and apply any available fixes.

  8. 8
    Low-severity directory traversal flaw patched in Trivy scannerโ–ผ๐Ÿšจ EUVD-2026-91789 ๐Ÿ“Š Score: 2.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: trivy ๐Ÿข Vendor: aquasec ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ Trivy before 0.MmastodonTechnologyCybersecurity01 d ago

    A new vulnerability listing, EUVD-2026-91789, describes a directory traversal issue in Aqua Security's Trivy vulnerability scanner. Versions before 0.71.0 allow path traversal in Terraform filesystem functions that access pathnames above the scan root, with risk arising in misconfiguration scanning. The flaw carries a CVSS v3.1 score of 2.5, indicating low severity, and the advisory was updated on 2 October 2026. Users are advised to upgrade to 0.71.0 or later.

  9. 9
    High-severity SQL injection flaw reported in UTMStackโ–ผ๐Ÿšจ EUVD-2026-91790 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: UTMStack ๐Ÿข Vendor: UTMStack ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ UTMStack beMmastodonTechnologyCybersecurity01 d ago

    A newly catalogued vulnerability, EUVD-2026-91790, affects UTMStack versions before 11.2.16. The flaw is a SQL injection in the UtmAssetGroupService.searchQueryBuilder() component, allowing authenticated attackers to inject arbitrary SQL commands. The issue carries a CVSS v3.1 severity score of 8.7 out of 10, placing it in the high-severity range. The advisory record was updated on 2 October 2026, and users are expected to patch to version 11.2.16 or later.

  10. 10
    High-severity infinite loop flaw reported in Apache Thrift Python bindingsโ–ผ๐Ÿšจ EUVD-2026-91568 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-91568 has been disclosed in Apache Thrift, the Apache Software Foundation's cross-language RPC framework. The flaw, an infinite loop with an unreachable exit condition in the Python bindings, carries a CVSS v3.1 score of 8.2. Details on affected versions remain incomplete pending an update from the vendor.

  11. 11
    Linux kernel configfs vulnerability patched in new advisoryโ—๐Ÿšจ EUVD-2026-86804 ๐Ÿ“Š Score: n/a ๐Ÿ“ฆ Product: Linux, Linux, Linux (+7 more) ๐Ÿข Vendor: Linux ๐Ÿ“… Published: 2026-09-25 | UpdateMmastodonTechnologyCybersecurity01 d ago

    A new vulnerability, tracked as EUVD-2026-86804, has been disclosed and resolved in the Linux kernel. The flaw involves the configfs subsystem, where the fix pins the symlink target's dirent instead of chasing its dentry pointer, closing a potential security issue. The advisory covers the Linux kernel across multiple affected versions and was published on September 25, 2026, with an update on October 3, 2026. No severity score has been assigned yet, and administrators are advised to apply kernel updates.

  12. 12
    TOTOLINK N150RT router firmware hit by buffer overflow flawโ–ผ๐Ÿšจ EUVD-2026-89331 ๐Ÿ“Š Score: n/a ๐Ÿ“… Updated: 2026-09-29 ๐Ÿ“ A stack-based buffer overflow vulnerability exists in the web manMmastodonTechnologyCybersecurity04 d ago

    A new vulnerability entry, EUVD-2026-89331, documents a stack-based buffer overflow in the web management interface of TOTOLINK N150RT (NTR150) routers running firmware V3.4.0-B20201030. The flaw is reachable through the /boafrm/formFilter route, which handles access-control and URL filter functions. No severity score has been assigned yet. Security teams are being urged to check whether their devices run the affected firmware.

  13. 13
    Linux kernel fixes sunvdc driver vulnerabilityโ—๐Ÿšจ EUVD-2026-86806 ๐Ÿ“Š Score: n/a ๐Ÿ“ฆ Product: Linux, Linux, Linux (+25 more) ๐Ÿข Vendor: Linux ๐Ÿ“… Published: 2026-09-25 | UpdatMmastodonTechnologyCybersecurity01 d ago

    A new vulnerability entry, EUVD-2026-86806, was published on 25 September 2026 for the Linux kernel and later updated on 3 October. It concerns the sunvdc virtual disk driver, where LDC cookies were not unmapped when a descriptor send failed. The fix has been resolved in the kernel, and the advisory affects Linux alongside roughly two dozen other listed products.

  14. 14
    New vulnerability disclosed in Dynamic Web Lab Team Manager pluginโ–ผ๐Ÿšจ EUVD-2025-30618 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Team Manager ๐Ÿข Vendor: Dynamic Web Lab ๐Ÿ“… Published: 2025-09-22MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2025-30618, was published on 22 September 2025 affecting the Team Manager plugin for WordPress by vendor Dynamic Web Lab. The flaw, scored 5.3 out of 10 under CVSS v3.1, is a missing authorization issue that could let attackers exploit incorrectly configured access controls. An update to the entry was recorded on 2 October 2026.

  15. 15
    High-severity vulnerability disclosed in Apache Thrift Lua bindingsโ–ผ๐Ÿšจ EUVD-2026-91569 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity02 d ago

    A high-severity vulnerability, EUVD-2026-91569, has been catalogued affecting the Lua bindings of Apache Thrift, the cross-language RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.2 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling combined with inefficient algorithmic complexity, which could allow denial-of-service conditions. The advisory was updated on 2 October 2026.

  16. 16
    Linux kernel patch fixes TCP data corruption flawโ—๐Ÿšจ EUVD-2026-86808 ๐Ÿ“Š Score: n/a ๐Ÿ“ฆ Product: Linux, Linux, Linux (+15 more) ๐Ÿข Vendor: Linux ๐Ÿ“… Published: 2026-09-25 | UpdatMmastodonTechnologyCybersecurity01 d ago

    A vulnerability in the Linux kernel's Reliable Datagram Sockets networking subsystem has been resolved, with the fix addressing TCP stream corruption that could occur when large memory pages are in use. The advisory, published 25 September 2026 and updated 3 October, affects the Linux kernel and a range of related products, drawing attention from security teams tracking kernel updates.

  17. 17
    High-severity SQL injection flaw reported in HAVELSAN Sef chatbotโ–ผ๐Ÿšจ EUVD-2026-91329 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity02 d ago

    A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.

  18. 18
    Kilo Code vulnerability lets local attackers run codeโ–ผ๐Ÿšจ EUVD-2026-89423 ๐Ÿ“Š Score: 8.4/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ An issue in Kilo Code befoMmastodonTechnologyCybersecurity03 d ago

    A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.

  19. 19
    Critical vulnerability flagged in CISA's Malcolm network toolโ—๐Ÿšจ EUVD-2026-76738 ๐Ÿ“Š Score: 9.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Malcolm ๐Ÿข Vendor: CISA ๐Ÿ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity01 d ago

    A high-severity vulnerability, EUVD-2026-76738, has been published for Malcolm, the open-source network traffic analysis toolkit distributed by CISA. The flaw, scored 9.2 out of 10 on the CVSS v3.1 scale, stems from an example environment-configuration file for a bundled inventory-management component that ships with a fixed, publicly known administrative password. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  20. 20
    Malcolm vulnerability EUVD-2026-76736 rated medium severityโ—๐Ÿšจ EUVD-2026-76736 ๐Ÿ“Š Score: 6.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Malcolm ๐Ÿข Vendor: CISA ๐Ÿ“… Published: 2026-09-11 | Updated: 2026-MmastodonTechnologyCybersecurity01 d ago

    A vulnerability tracked as EUVD-2026-76736 has been published for Malcolm, with a CVSS v3.1 score of 6.3 out of 10. According to the advisory, a prior update that raised a bundled HTTP client library to a version fixing known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version. The advisory was published on 11 September 2026 and updated on 2 October 2026.

  21. 21
    High-severity unquoted service path flaw reported in Remote Mouseโ—๐Ÿšจ EUVD-2026-3018 ๐Ÿ“Š Score: 8.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Remote Mouse ๐Ÿข Vendor: Remotemouse ๐Ÿ“… Published: 2026-01-15 | UpdMmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-3018 has been published for Remote Mouse, the remote-control app by vendor Remotemouse. Version 4.002 contains an unquoted service path vulnerability, rated 8.5 out of 10 on the CVSS v3.1 scale, which can let a local attacker execute arbitrary code with elevated privileges. The entry was published on 15 January 2026 and updated on 1 October 2026. Users are advised to watch for a patched release from the vendor.

  22. 22
    Medium-Severity Flaw Reported in FluentForm WordPress Pluginโ–ผ๐Ÿšจ EUVD-2026-90761 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: FluentForm ๐Ÿข Vendor: WP ManageNinja LLC ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“MmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2026-90761 has been published affecting FluentForm, the WordPress form plugin by WP ManageNinja LLC. The issue is classified as an Incorrect Behavior Order flaw with a CVSS v3.1 score of 5.3 out of 10, and can reportedly allow removal of important client functionality. Details were updated on 1 October 2026. Administrators running FluentForm are likely to check whether their installed version is affected and apply any available patch.

  23. 23
    Critical 10/10 vulnerability disclosed in Tenda routersโ—๐Ÿšจ EUVD-2026-91570 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HG9, HG7, HG10 ๐Ÿข Vendor: Tenda ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ A securMmastodonTechnologyCybersecurity02 d ago

    A maximum-severity security flaw, tracked as EUVD-2026-91570 with a CVSS score of 10.0, has been disclosed in Tenda HG7, HG9 and HG10 routers running the 300001138_en_xpon firmware. The vulnerability lies in the boaGetVar function in the /boaform/formLoopBack file. The advisory was updated on 2 October 2026, and security watchers are sharing the disclosure.

  24. 24
    High-severity XML flaw flagged in Apache Camel Quarkusโ–ผ๐Ÿšจ EUVD-2026-90762 ๐Ÿ“Š Score: 8.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Camel Quarkus, Apache Camel Quarkus ๐Ÿข Vendor: Apache SofMmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2026-90762 has been recorded for Apache Camel Quarkus, the Apache Software Foundation's Quarkus extensions for Camel. The flaw, rated 8.6 out of 10 under CVSS v3.1, involves improper restriction of XML external entity references in the XSLT support extension (camel-quarkus-support-xalan). Such issues can allow attackers to read files or make requests from affected systems. The record was updated on 1 October 2026, and security teams are being urged to check whether their deployments use the affected extension.

  25. 25
    High-severity vulnerability disclosed in Apache Thrift Lua libraryโ—๐Ÿšจ EUVD-2026-91330 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity02 d ago

    A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.

  26. 26
    ArgusMonitor Driver Vulnerability Flagged With Medium Severityโ–ผ๐Ÿšจ EUVD-2026-89424 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“… Published: 2026-09-29 | Updated: 2026-09-30 ๐Ÿ“ Improper Access Control inMmastodonTechnologyCybersecurity03 d ago

    A newly tracked vulnerability, EUVD-2026-89424, describes improper access control in the ArgusMonitor.sys driver used by Argotronic eGbR's hardware monitoring tool ArgusMonitor, affecting version 7.4.02 and earlier. With a CVSS v3.1 score of 5.3, the flaw reportedly allows local, low-privileged users to bypass device handle access restrictions. Published on 29 September and updated the next day, it is drawing attention from security watchers tracking Windows driver weaknesses.

  27. 27
    New security vulnerability disclosed in Red Hat Enterprise Linux productsโ–ผ๐Ÿšจ EUVD-2023-24169 ๐Ÿ“Š Score: 7.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat VMmastodonTechnologyCybersecurity03 d ago

    A vulnerability tracked as EUVD-2023-24169 has been published affecting several Red Hat products, including Red Hat Enterprise Linux 8.6 and 8.8 Extended Update Support and Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. The flaw carries a CVSS v3.1 severity score of 7.0 out of 10, placing it in the high-severity range. Administrators running the affected versions are being advised to review the advisory and apply patches.

  28. 28
    SSRF Vulnerability Disclosed in HAVELSAN Sef AI Chatbot Platformโ—๐Ÿšจ EUVD-2026-91323 ๐Ÿ“Š Score: 4.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-91323 with a CVSS v3.1 score of 4.9, has been recorded for the Sef AI Chatbot Platform developed by Turkish defence technology company HAVELSAN Inc. The flaw is a server-side request forgery (SSRF) issue, which can allow an attacker to make the server send arbitrary requests. The advisory was updated on 2 October 2026; affected versions have not been fully detailed in the published record.

  29. 29
    Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโ–ผ๐Ÿšจ EUVD-2026-70998 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity03 d ago

    A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.

  30. 30
    Avada WordPress theme hit by reflected XSS vulnerabilityโ—๐Ÿšจ EUVD-2026-91174 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Avada | Website Builder For WordPress & WooCommerce ๐Ÿข Vendor: TMmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-91174 with a CVSS score of 6.1, has been reported in Avada, the popular website builder theme for WordPress and WooCommerce from vendor ThemeFusion. The flaw is a reflected cross-site scripting issue, updated on 2026-10-02, allowing attackers to inject malicious scripts via crafted links. WordPress site owners using Avada are advised to update promptly.

  31. 31
    High-severity vulnerability disclosed in Capgo update serviceโ–ผ๐Ÿšจ EUVD-2026-87707 ๐Ÿ“Š Score: 8.6/10 (CVSS v3.1) ๐Ÿ“ฆ Product: capgo.app ๐Ÿข Vendor: Cap-go ๐Ÿ“… Published: 2026-09-26 | Updated: 2MmastodonTechnologyCybersecurity03 d ago

    A security advisory published as EUVD-2026-87707 describes a vulnerability in Capgo, the over-the-air update service for Capacitor apps, rated 8.6 out of 10 on the CVSS scale. Versions up to 12.261.0 reportedly contain an incomplete access-control fix for the public.sso_providers table, meaning earlier mitigation efforts did not fully close the flaw. The advisory was published on 26 September 2026 and updated on 30 September, prompting developers who rely on Capgo to check whether they need to update.

  32. 32
    Fastify vulnerability EUVD-2026-70989 scores 7.5โ–ผ๐Ÿšจ EUVD-2026-70989 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity03 d ago

    A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.

  33. 33
    encoded_id-rails vulnerability allows remote denial of service attacksโ—๐Ÿšจ EUVD-2023-2632 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“… Published: 2024-01-04 | Updated: 2026-10-01 ๐Ÿ“ encoded_id-rails versions bMmastodonTechnologyCybersecurity02 d ago

    A security advisory tracked as EUVD-2023-2632 warns that encoded_id-rails versions before 1.0.0.beta2 contain an uncontrolled resource consumption flaw. A remote, unauthenticated attacker could exploit it to trigger a denial of service. The vulnerability carries a CVSS v3.1 score of 7.5 and was published on 4 January 2024, with the advisory most recently updated on 1 October 2026.

  34. 34
    pfSense vulnerability allows privilege injection, patch releasedโ—๐Ÿšจ EUVD-2026-70495 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: pfSense Plus, pfSense CE ๐Ÿข Vendor: Netgate ๐Ÿ“… Published: 2026-09MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-70495 with a CVSS score of 5.1, affects Netgate's pfSense Plus before version 26.07 and pfSense CE before 2.9.0. The flaw lets authenticated users holding the Status: Monitoring privilege inject arbitrary content, potentially leading to further abuse. Netgate published the advisory on 3 September 2026 and updated it on 1 October; administrators are advised to upgrade.

  35. 35
    Ultimate POS software flagged for stored cross-site scripting flawโ—๐Ÿšจ EUVD-2026-57170 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Ultimate POS (Stock Management & Point of Sale) ๐Ÿข Vendor: UltimMmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, tracked as EUVD-2026-57170, has been published for Ultimate POS, a stock management and point of sale application from vendor Ultimate Fosters. The flaw is a stored cross-site scripting issue, scored 4.8 out of 10 under CVSS v3.1. It was first published on 12 August 2026 and updated on 1 October 2026. Users of the software are advised to check for patches.

  36. 36
    CPython vulnerability EUVD-2026-89183 disclosed with moderate severityโ–ผ๐Ÿšจ EUVD-2026-89183 ๐Ÿ“Š Score: 5.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: CPython ๐Ÿข Vendor: Python Software Foundation ๐Ÿ“… Updated: 2026-09MmastodonTechnologyCybersecurity04 d ago

    A vulnerability tracked as EUVD-2026-89183 has been disclosed in CPython, the reference implementation of the Python language maintained by the Python Software Foundation. The flaw concerns cleanup of tempfile.TemporaryDirectory, where a race condition could let an attacker who can modify the directory tree during cleanup swap in a directory in place of the intended one. It is rated 5.9 out of 10 on the CVSS v3.1 scale, a moderate severity score.

  37. 37
    Fastify vulnerability allows authentication bypass via malformed URLsโ–ผ๐Ÿšจ EUVD-2026-70988 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity03 d ago

    A newly catalogued vulnerability, EUVD-2026-70988, affects the Fastify web framework, rated 7.5 out of 10 on the CVSS v3.1 scale. The flaw allows authentication bypass when malformed URLs reach encapsulated not-found handlers, meaning requests intended to be blocked could slip through route protections. Fastify is a widely used Node.js framework, so developers running exposed services are being urged to review the advisory and update to a patched version.

  38. 38
    Kiteworks Email Protection Gateway vulnerability logged with moderate severityโ–ผ๐Ÿšจ EUVD-2026-90275 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Email Protection Gateway ๐Ÿข Vendor: Kiteworks ๐Ÿ“… Updated: 2026-09MmastodonTechnologyCybersecurity03 d ago

    A new vulnerability, EUVD-2026-90275, has been recorded for Kiteworks' Email Protection Gateway, with a CVSS v3.1 score of 6.5 out of 10. The flaw concerns an authorization check in the large file exchange feature that failed to correctly verify whether the requesting user was entitled to access the resource. The entry was updated on 30 September 2026. Security teams monitoring Kiteworks deployments are expected to review the advisory and patch guidance.

  39. 39
    pfSense vulnerability EUVD-2026-70496 allows privilege injectionโ—๐Ÿšจ EUVD-2026-70496 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: pfSense Plus, pfSense CE ๐Ÿข Vendor: Netgate ๐Ÿ“… Published: 2026-09MmastodonTechnologyCybersecurity02 d ago

    A medium-severity vulnerability, EUVD-2026-70496, has been published for Netgate's pfSense firewall software. Versions of pfSense Plus before 26.07 and pfSense CE before 2.9.0 allow authenticated users holding the Firewall: Rules: Edit privilege to inject data, according to the advisory rated 5.1 out of 10 under CVSS v3.1. The issue was published on 3 September 2026 and updated on 1 October. Administrators running affected versions are advised to update.

  40. 40
    Low-severity vm2 sandbox flaw disclosed under EUVD-2026-81594โ—๐Ÿšจ EUVD-2026-81594 ๐Ÿ“Š Score: 2.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2: ExternalMmastodonTechnologyCybersecurity02 d ago

    A new vulnerability entry, EUVD-2026-81594, has been published for the vm2 JavaScript sandbox library maintained by patriksimek. The flaw carries a low CVSS v3.1 score of 2.3 out of 10 and stems from the external module allowlist using a raw prefix test, meaning a sibling package sharing a name prefix is incorrectly treated as allowlisted. The entry was updated on 1 October 2026.