ZCyberNews
中文

Articles

460 articles

Custom css-js-php WordPress Plugin SQLi Leads to RCE (CVE-2026-6433)CRITICAL
Vulnerabilities

Custom css-js-php WordPress Plugin SQLi Leads to RCE (CVE-2026-6433)

CVE-2026-6433: Unauthenticated SQL injection in Custom css-js-php plugin ≤2.0.7 lets attackers execute arbitrary PHP via eval(). No patch available.

CVE-2026-6433
3 min read
CVE-2025-61314: Reflected XSS in Mecury Managed Print ServicesHIGH
Vulnerabilities

CVE-2025-61314: Reflected XSS in Mecury Managed Print Services

CVE-2025-61314: Reflected XSS in GmbH Mecury Managed Print Services docuForm v11.11c allows attackers to execute arbitrary JS via crafted payload in dfm-menu_orderopt.php.

CVE-2025-61314
3 min read
CVE-2025-65417: docuFORM MPS Client Reflected XSS in Login PageHIGH
Vulnerabilities

CVE-2025-65417: docuFORM MPS Client Reflected XSS in Login Page

CVE-2025-65417: A reflected XSS flaw in docuFORM Managed Print Service Client 11.11c lets unauthenticated attackers execute arbitrary scripts via the login page.

CVE-2025-65417
3 min read
CVE-2026-5084: WebDyne Session IDs Generated with Weak MD5/rand()HIGH
Vulnerabilities

CVE-2026-5084: WebDyne Session IDs Generated with Weak MD5/rand()

CVE-2026-5084: WebDyne::Session through 2.075 for Perl generates session IDs from an MD5 hash seeded with rand(), enabling session prediction and hijacking.

CVE-2026-5084
3 min read
CVE-2026-7813: pgAdmin 4 Server Mode Flaw Lets Users Access PrivateCRITICAL
Vulnerabilities

CVE-2026-7813: pgAdmin 4 Server Mode Flaw Lets Users Access Private

CVE-2026-7813 (CVSS 9.9) in pgAdmin 4 server mode lets authenticated users access private servers, groups, and debugger data from other users by guessing object IDs.

CVE-2026-7813
3 min read
D-Link DNS-320 OS Command Injection Flaw CVE-2026-8273 Lets RemoteMEDIUM
Vulnerabilities

D-Link DNS-320 OS Command Injection Flaw CVE-2026-8273 Lets Remote

CVE-2026-8273 (CVSS 5.8) in D-Link DNS-320 2.06B01 allows remote OS command injection via multiple CGI endpoints in system_mgr.cgi. No patch available.

CVE-2026-8273
3 min read
Dell ECS Hard-Coded Credentials Flaw CVE-2026-40636 Hits 9.8 CVSSCRITICAL
Vulnerabilities

Dell ECS Hard-Coded Credentials Flaw CVE-2026-40636 Hits 9.8 CVSS

CVE-2026-40636 (CVSS 9.8) in Dell ECS and ObjectScale uses hard-coded credentials, letting local attackers gain filesystem access.

CVE-2026-40636CVE-2026-35157
3 min read
Devs Palace ERP Online XSS Flaws Allow Remote Script InjectionMEDIUM
Vulnerabilities

Devs Palace ERP Online XSS Flaws Allow Remote Script Injection

Two stored XSS vulnerabilities in Devs Palace ERP Online up to 4.0.0 let remote attackers inject scripts via /inventory/addnewcustomer and /inventory/sales_save.

CVE-2026-8255CVE-2026-8254
3 min read
Dirty Frag Linux Flaws Let Unprivileged Users Gain Root, EscapeHIGH
Vulnerabilities

Dirty Frag Linux Flaws Let Unprivileged Users Gain Root, Escape

CVE-2026-43284 and CVE-2026-43500 in the Linux kernel's networking code allow unprivileged users to gain root and escape containers. Exploit published after embargo broke.

CVE-2026-43284CVE-2026-43500
4 min read
Docling JATS XML Backend XXE Flaw CVE-2026-31247 Enables DoSHIGH
Vulnerabilities

Docling JATS XML Backend XXE Flaw CVE-2026-31247 Enables DoS

CVE-2026-31247: Docling's JATS XML backend through 2.61.0 uses etree.parse() without disabling entity expansion, allowing XML bomb attacks that consume excessive resources and...

CVE-2026-31247
3 min read
FCC Delays Ban on Security Updates for Foreign-Made Routers to 2029MEDIUM
Industry News

FCC Delays Ban on Security Updates for Foreign-Made Routers to 2029

The FCC extended the deadline for banning software updates on foreign-made routers from March 2027 to January 2029, citing public interest concerns and industry pushback.

3 min read
GPT-Pilot Command Injection Flaw CVE-2026-31246 Lets Users ExecuteCRITICAL
Vulnerabilities

GPT-Pilot Command Injection Flaw CVE-2026-31246 Lets Users Execute

CVE-2026-31246 (CVSS 9.8) in GPT-Pilot's Executor.run() passes unvalidated user input to asyncio.createsubprocessshell(), enabling arbitrary command injection during project...

CVE-2026-31246
4 min read
← PrevPage 11 of 39Next →