🚨 EUVD-2026-31332

πŸ“Š Score: 7.5/10 (CVSS v3.1)
πŸ“¦ Product: Authen::TOTP
🏒 Vendor: TCHATZI
πŸ“… Updated: 2026-05-21

πŸ“ Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand.

Secrets were generated using Perl's built-in rand function, which is predictable and unsuitable for security usage.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31332

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2026-31333

πŸ“Š Score: 4.3/10 (CVSS v3.1)
πŸ“¦ Product: GSheet For Woo Importer
🏒 Vendor: mrdollar4444
πŸ“… Updated: 2026-05-21

πŸ“ The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the process_ajax_restore_action() function in all versions up to, and including, 2.3.1. This makes it possib...

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31333

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2026-31331

πŸ“Š Score: 8.6/10 (CVSS v3.1)
πŸ“¦ Product: iina
🏒 Vendor: iina
πŸ“… Updated: 2026-05-21

πŸ“ IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a c...

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-31331

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🟠 CVE-2026-45206 - High (7.8)

An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-45207 but exists in a different process protection communication mechanism.

Pl...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-45206/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

🟠 CVE-2026-45208 - High (7.8)

A time-of-check time-of-use vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-45208/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

πŸ”΄ CVE-2026-48207 - Critical (9.8)

Deserialization of untrusted data in Apache Fory PyFory. PyFory's ReduceSerializer could bypass documented DeserializationPolicy validation hooks during reduce-state restoration and global-name resolution. An application is vulnerable if it deseri...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-48207/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

Cool, there's now a code execution exploit on nginx. Now this might sound harmless since you need some ridiculous settings like disabling certain memory protection features but this can still be used to cause a denial of service by crashing nginc workers and what if someone combines it with another exploit in for example the memory protection thingy and then combine it with copyfail. I fucking hate the mordern world, in sometime the entire Internet is just ai finding exploits and other ai fixing it. Fuck all of this man

#nginx #ai #vulnerability

🚨 CRITICAL: Open ISES Tickets <3.44.2 has hardcoded MySQL creds in loader.php (CVE-2026-48241), exposing DBs to attack if reachable. Restrict file & DB access, rotate creds now. No official fix yet. https://radar.offseq.com/threat/cve-2026-48241-use-of-hard-coded-credentials-in-op-e794805b #OffSeq #Vulnerability #MySQL #AppSec

πŸ“° Warning: Microsoft Defender Flaws Actively Exploited to Gain SYSTEM Privileges

⚠️ ACTIVE EXPLOITATION ALERT: Flaws in Microsoft Defender (CVE-2026-41091, CVE-2026-45498) are being used by attackers to gain SYSTEM privileges and disable AV. Patch the Malware Protection Engine immediately! #CyberSecurity #Vulnerability #PatchNow

🌐 cyber[.]netsecops[.]io

πŸ”— https://cyber.netsecops.io/articles/microsoft-defender-vulnerabilities-actively-exploited-for-privilege-escalati…

🟠 CVE-2026-48235 - High (8.2)

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude, and timestamp values parsed from external GPS tracking service XML/JSON responses (InstaMapper and G...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-48235/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack