VulDB Updates Updates
- CVE-2025-68686 | Fortinet FortiOS up to 7.6.1 HTTP information disclosure (FG-IR-25-934)by vuldb.com on July 27, 2026 at 8:52 pm
A vulnerability was found in Fortinet FortiOS up to 6.4.16/7.0.19/7.2.13/7.4.6/7.6.1. It has been classified as problematic. Affected by this issue is some unknown functionality of the component HTTP Handler. The manipulation leads to information disclosure. This vulnerability is listed as CVE-2025-68686. The attack may be initiated remotely. In addition, an exploit is available. Upgrading the affected component is recommended.
- CVE-2026-16812 | Arista VeloCloud Orchestrator On-Prem prior 5.2.3.14/6.1.3.4/6.4.2.4/7.0.0.1 privileges managementby vuldb.com on July 27, 2026 at 8:52 pm
A vulnerability described as very critical has been identified in Arista VeloCloud Orchestrator On-Prem. This issue affects some unknown processing. Such manipulation leads to improper privilege management. This vulnerability is documented as CVE-2026-16812. The attack can be executed remotely. Additionally, an exploit exists. Upgrading the affected component is recommended.
- CVE-2026-59846 | Red Hat libssh ProxyCommand Username os command injection (Nessus ID 330077)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability marked as very critical has been reported in Red Hat libssh. This vulnerability affects unknown code of the component ProxyCommand. The manipulation of the argument Username leads to os command injection. This vulnerability is uniquely identified as CVE-2026-59846. The attack is possible to be carried out remotely. No exploit exists.
- CVE-2026-21579 | Atlassian Confluence Data Center up to 9.2.21/10.2.13 information disclosure (Nessus ID 330086)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability labeled as problematic has been found in Atlassian Confluence Data Center up to 9.2.21/10.2.13. The impacted element is an unknown function. Executing a manipulation can lead to information disclosure. This vulnerability is tracked as CVE-2026-21579. The attack can be launched remotely. No exploit exists. The affected component should be upgraded.
- CVE-2026-64642 | Vercel Next.js up to 16.2.10 App Router config.i18n locales improper authentication (Nessus ID 330087)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability categorized as critical has been discovered in Vercel Next.js up to 16.2.10. Affected by this issue is some unknown functionality of the file config.i18n of the component App Router. The manipulation of the argument locales results in improper authentication. This vulnerability was named CVE-2026-64642. The attack may be performed from remote. There is no available exploit. It is advisable to upgrade the affected component.
- CVE-2026-64641 | Vercel Next.js up to 15.5.20/16.2.10 resource consumption (Nessus ID 330089)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability was found in Vercel Next.js up to 15.5.20/16.2.10 and classified as problematic. This affects an unknown function. Such manipulation leads to resource consumption. This vulnerability is traded as CVE-2026-64641. The attack may be launched remotely. There is no exploit available. It is suggested to upgrade the affected component.
- CVE-2026-64645 | Vercel Next.js up to 15.5.20/16.0.0-16.2.10 rewrites/redirects server-side request forgery (Nessus ID 330090)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability was found in Vercel Next.js up to 15.5.20/16.0.0-16.2.10. It has been classified as critical. This impacts the function rewrites/redirects. Performing a manipulation results in server-side request forgery. This vulnerability is known as CVE-2026-64645. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component is recommended.
- CVE-2026-47838 | Vmware Spring Security up to 6.5.10 x.509 Certificate improper authentication (Nessus ID 330091)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability was found in Vmware Spring Security up to 5.7.24/5.8.26/6.3.17/6.4.17/6.5.10. It has been declared as critical. This vulnerability affects unknown code of the component x.509 Certificate Handler. Executing a manipulation can lead to improper authentication. The identification of this vulnerability is CVE-2026-47838. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2026-64534 | Linux Kernel up to 6.18.39 nvmet-tcp nvmet_tcp_try_recv_ddgst use after free (Nessus ID 330126)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability marked as very critical has been reported in Linux Kernel up to 6.18.39. This issue affects the function nvmet_tcp_try_recv_ddgst of the component nvmet-tcp. The manipulation leads to use after free. This vulnerability is uniquely identified as CVE-2026-64534. The attack is possible to be carried out remotely. No exploit exists. It is suggested to upgrade the affected component.
- CVE-2026-64535 | Linux Kernel up to 6.1.177/6.6.144/6.12.96/6.18.39 nvmet-tcp nvmet_tcp_try_recv_ddgst use after free (Nessus ID 330124)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability described as very critical has been identified in Linux Kernel up to 6.1.177/6.6.144/6.12.96/6.18.39. Impacted is the function nvmet_tcp_try_recv_ddgst of the component nvmet-tcp. The manipulation results in use after free. This vulnerability was named CVE-2026-64535. The attack may be performed from remote. There is no available exploit. Upgrading the affected component is recommended.
- CVE-2026-64536 | Linux Kernel up to 7.2-rc2 rtl8723bs is_ap_in_tkip element_id/length/data out-of-bounds (Nessus ID 330125)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability classified as very critical has been found in Linux Kernel up to 7.2-rc2. The affected element is the function is_ap_in_tkip of the component rtl8723bs. This manipulation of the argument element_id/length/data causes out-of-bounds read. The identification of this vulnerability is CVE-2026-64536. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to upgrade the affected component.
- CVE-2026-64533 | Linux Kernel up to 7.1.4 NTFS3 log_replay lcns_follow/page_lcns out-of-bounds (Nessus ID 330128)by vuldb.com on July 27, 2026 at 7:49 pm
A vulnerability labeled as critical has been found in Linux Kernel up to 7.1.4. This vulnerability affects the function log_replay of the component NTFS3. Executing a manipulation of the argument lcns_follow/page_lcns can lead to out-of-bounds read. This vulnerability is handled as CVE-2026-64533. The attack can be executed remotely. There is not any exploit available. The affected component should be upgraded.
- CVE-2026-17432 | NousResearch hermes-agent 2026.6.5 SimpleX Gateway Authorization adapter.py contactId access control (44729/44730 / EUVD-2026-49046)by vuldb.com on July 27, 2026 at 7:26 pm
A vulnerability labeled as critical has been found in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-agent/plugins/platforms/simplex/adapter.py of the component SimpleX Gateway Authorization. The manipulation of the argument contactId results in improper access controls. This vulnerability is cataloged as CVE-2026-17432. The attack may be launched remotely. Furthermore, there is an exploit available. Applying a patch is advised to resolve this issue.
- CVE-2026-17458 | mf-yang openclaw-cn up to 0.2.1 Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery (Issue 562 / EUVD-2026-49053)by vuldb.com on July 27, 2026 at 7:26 pm
A vulnerability classified as critical has been found in mf-yang openclaw-cn up to 0.2.1. This affects the function clickViaPlaywright of the file src/browser/routes/agent.act.ts of the component Browser Control HTTP API. Performing a manipulation results in server-side request forgery. This vulnerability is cataloged as CVE-2026-17458. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. The project was informed of the problem early through an issue report but has not responded yet.
- CVE-2026-17497 | codexu NoteGen up to 0.31.x Tauri shell plugin cross site scripting (EUVD-2026-49056 / CNNVD-2026-28936117)by vuldb.com on July 27, 2026 at 7:26 pm
A vulnerability was found in codexu NoteGen up to 0.31.x. It has been classified as problematic. This affects an unknown function of the component Tauri shell plugin. Performing a manipulation results in cross site scripting. This vulnerability is known as CVE-2026-17497. Remote exploitation of the attack is possible. No exploit is available. Upgrading the affected component is recommended.
- CVE-2026-17434 | nanocoai NanoClaw up to 2.0.64 add_mcp_server request.ts handleAddMcpServer improper authorization (Issue 2762 / EUVD-2026-49049)by vuldb.com on July 27, 2026 at 7:26 pm
A vulnerability was found in nanocoai NanoClaw up to 2.0.64. It has been declared as critical. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of the component add_mcp_server. Executing a manipulation can lead to improper authorization. The identification of this vulnerability is CVE-2026-17434. The attack may be launched remotely. Furthermore, there is an exploit available. A patch should be applied to remediate this issue.
- CVE-2026-57990 | Microsoft Edge information disclosure (EUVD-2026-49059 / CNNVD-2026-55243890)by vuldb.com on July 27, 2026 at 7:26 pm
A vulnerability was found in Microsoft Edge. It has been rated as problematic. Impacted is an unknown function. Performing a manipulation results in information disclosure. This vulnerability is known as CVE-2026-57990. Remote exploitation of the attack is possible. No exploit is available. To fix this issue, it is recommended to deploy a patch.
- CVE-2026-64224 | Linux Kernel up to 6.18.33/7.0.10 octeontx2-pf rvu_rep_rsrc_init double free (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability labeled as critical has been found in Linux Kernel up to 6.18.33/7.0.10. This impacts the function rvu_rep_rsrc_init of the component octeontx2-pf. Such manipulation leads to double free. This vulnerability is uniquely identified as CVE-2026-64224. Local access is required to approach this attack. No exploit exists. The affected component should be upgraded.
- CVE-2026-64225 | Linux Kernel up to 7.0.10 octeontx2-af out-of-bounds (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability has been found in Linux Kernel up to 7.0.10 and classified as very critical. Impacted is an unknown function of the component octeontx2-af. Performing a manipulation results in out-of-bounds read. This vulnerability is cataloged as CVE-2026-64225. It is possible to initiate the attack remotely. There is no exploit available. The affected component should be upgraded.
- CVE-2026-64223 | Linux Kernel up to 6.12.91/6.18.33/7.0.10 mac80211 out-of-bounds (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.91/6.18.33/7.0.10. This issue affects the function ieee80211_parse_neg_ttlm/ieee80211_tid_to_link_map_size_ok of the component mac80211. Such manipulation leads to out-of-bounds read. This vulnerability is listed as CVE-2026-64223. The attack may be performed from remote. There is no available exploit. You should upgrade the affected component.
- CVE-2026-64222 | Linux Kernel up to 7.0.10 octeontx2-pf otx2_pool_aq_init stack double free (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability was found in Linux Kernel up to 7.0.10 and classified as very critical. The affected element is the function otx2_pool_aq_init of the component octeontx2-pf. Executing a manipulation of the argument stack can lead to double free. This vulnerability is registered as CVE-2026-64222. The attack needs to be launched locally. No exploit is available. It is suggested to upgrade the affected component.
- CVE-2026-64220 | Linux Kernel up to 7.0.10 Device Property fwnode_init secondary stack-based overflow (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability classified as critical was found in Linux Kernel up to 7.0.10. This affects the function fwnode_init of the component Device Property. The manipulation of the argument secondary results in stack-based buffer overflow. This vulnerability is identified as CVE-2026-64220. The attack is only possible with local access. There is not any exploit available. Upgrading the affected component is advised.
- CVE-2026-64221 | Linux Kernel up to 7.0.10 ti-qspi use after free (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 7.0.10. This vulnerability affects unknown code of the component ti-qspi. This manipulation causes use after free. This vulnerability is tracked as CVE-2026-64221. The attack is possible to be carried out remotely. No exploit exists. It is advisable to upgrade the affected component.
- CVE-2026-64219 | Linux Kernel up to 7.0.10 Display Core drm/amd/display dc_process_dmub_aux_transfer_async length/link_index stack-based overflow (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability identified as very critical has been detected in Linux Kernel up to 7.0.10. This affects the function dc_process_dmub_aux_transfer_async of the file drm/amd/display of the component Display Core. This manipulation of the argument length/link_index causes stack-based buffer overflow. This vulnerability is handled as CVE-2026-64219. The attack can be initiated remotely. There is not any exploit available. You should upgrade the affected component.
- CVE-2026-64218 | Linux Kernel up to 7.0.10 batman-adv batadv_bla_purge_backbone_gw use after free (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability classified as very critical has been found in Linux Kernel up to 7.0.10. Affected by this issue is the function batadv_bla_purge_backbone_gw of the component batman-adv. The manipulation leads to use after free. This vulnerability is referenced as CVE-2026-64218. Remote exploitation of the attack is possible. No exploit is available. It is recommended to upgrade the affected component.
- CVE-2026-64217 | Linux Kernel up to 6.6.141/6.12.91/6.18.33/7.0.10 netfs netfs_extract_user_iter memory corruption (WID-SEC-2026-2527)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability described as very critical has been identified in Linux Kernel up to 6.6.141/6.12.91/6.18.33/7.0.10. Affected by this vulnerability is the function netfs_extract_user_iter of the component netfs. Executing a manipulation can lead to memory corruption. The identification of this vulnerability is CVE-2026-64217. The attack may be launched remotely. There is no exploit available. Upgrading the affected component is recommended.
- CVE-2026-61511 | vBulletin up to 5.7.5/6.2.1 Template Runtime runMaths pagenav[pagenumber] code injection (WID-SEC-2026-2528)by vuldb.com on July 27, 2026 at 7:17 pm
A vulnerability classified as critical has been found in vBulletin up to 5.7.5/6.2.1. Affected by this issue is the function vB5_Template_Runtime::runMaths of the component Template Runtime. The manipulation of the argument pagenav[pagenumber] leads to code injection. This vulnerability is uniquely identified as CVE-2026-61511. The attack is possible to be carried out remotely. No exploit exists. It is recommended to upgrade the affected component.
- CVE-2022-40874 | Tenda AX1803 up to 1.0.0.1 HTTP Request GetParentControlInfo heap-based overflow (EUVD-2022-44130)by vuldb.com on July 27, 2026 at 7:09 pm
A vulnerability was found in Tenda AX1803 up to 1.0.0.1. It has been declared as critical. This impacts the function GetParentControlInfo of the component HTTP Request Handler. Executing a manipulation can lead to heap-based buffer overflow. This vulnerability is handled as CVE-2022-40874. The attack can only be done within the local network. There is not any exploit available.
- CVE-2022-40842 | NdkAdvancedCustomizationFields 3.5.0 rotateimg.php server-side request forgery (EUVD-2022-44100)by vuldb.com on July 27, 2026 at 7:08 pm
A vulnerability marked as critical has been reported in NdkAdvancedCustomizationFields 3.5.0. The impacted element is an unknown function of the file rotateimg.php. Performing a manipulation results in server-side request forgery. This vulnerability is known as CVE-2022-40842. Access to the local network is required for this attack. Furthermore, an exploit is available.
- CVE-2022-40872 | SourceCodester Simple E-Learning System 1.0 /vcs/classRoom.php classCode sql injection (EUVD-2022-44128)by vuldb.com on July 27, 2026 at 7:08 pm
A vulnerability was found in SourceCodester Simple E-Learning System 1.0 and classified as critical. This affects an unknown part of the file /vcs/classRoom.php. Executing a manipulation of the argument classCode can lead to sql injection. This vulnerability is handled as CVE-2022-40872. The attack can be executed remotely. There is not any exploit available.





