CVE-2026-25267 — Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Veille cybersécurité : alertes, vulnérabilités, actualités et outils pour se protéger.
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
Missing Authorization vulnerability in Green Invoice Morning for WooCommerce wc-gateway-greeninvoice allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Morning for WooCommerce: fr…
Contributor Broken Access Control in WDS MCP Content Manager <= 3.10.4 versions.
Missing Authorization vulnerability in iatoai IATO MCP iato-mcp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IATO MCP: from n/a through 1.12.0.
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected is an unknown function. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote.…
Docker Buildx Bake does not request the expected fs.read approval for certain filesystem inputs. An untrusted Bake definition can expose a readable file through a pathless secret whose ID is interpreted as a client-side…
Langflow is a tool for building and deploying AI-powered agents and workflows. From 1.0.0 until 1.10.1, Langflow did not verify flow ownership in the deprecated POST /api/v1/build/{flow_id}/vertices and POST /api/v1/bui…
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the get-page RPC accepts a share-link permission object with blanket read access but does not verify that the caller-selected page-id belongs to…
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profi…
Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped sha…