- CVE-2026-77929 HIGH CVSS 8.7 -
NVD: ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. NVD: The FileUpload::manageFile() function in fileupload.class.php fails to update the file extension after MIME validation, allowing an attacker-controlled .php extension to persist on disk and execute as PHP via PHP-FPM when the uploaded file is retrieved. OSV: ClipBucket < 5.5.3-#182 Remote Code Execution via Photo Upload Endpoint
An attacker may be able to run code or commands on affected systems; CVSS 8.7 (HIGH); EPSS percentile 59; sources: NVD, OSV.
- CVE-2026-93558 HIGH CVSS 7.5 -
NVD: A flaw was found in Netty's WebSocketServerExtensionHandler. NVD: A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. NVD: This leads to an unbounded growth of a per-connection queue, consuming excessive memory.
The affected service may become unavailable or unreliable; CVSS 7.5 (HIGH); EPSS percentile 54; sources: NVD.
- CVE-2026-93564 HIGH CVSS 7.5 -
NVD: A flaw was found in Netty. NVD: A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. NVD: This can lead to memory exhaustion, resulting in a Denial of Service (DoS) for the affected system.
The affected service may become unavailable or unreliable; CVSS 7.5 (HIGH); EPSS percentile 54; sources: NVD.
- CVE-2026-93568 HIGH CVSS 7.5 -
NVD: A flaw was found in Netty. NVD: A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. NVD: Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNECT requests, leading to a loss of critical protocol and path information.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 54; sources: NVD.
- CVE-2026-93567 HIGH CVSS 7.5 -
NVD: A flaw was found in Netty's HTTP/2 codec. NVD: When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. NVD: A remote attacker can exploit this by supplying a different Host header, leading to a malformed HTTP/2 CONNECT request.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 53; sources: NVD.
- CVE-2026-93565 HIGH CVSS 7.5 -
NVD: A flaw was found in Netty RtspDecoder. NVD: The RtspMethods.valueOf() function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. NVD: A remote attacker can exploit this by sending a specially crafted RTSP request, leading to method-token smuggling.
This high severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 7.5 (HIGH); EPSS percentile 48; sources: NVD.
- CVE-2026-77927 HIGH CVSS 7.1 -
NVD: ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() sanitization function... NVD: Attackers can pass unsanitized array elements through the bulk deletion handler in manage_photos.php to photo_exists() in photos.class.php, where non-numeric values are interpolated directly into a SQL query, enabling time-based blind SQL injection to... OSV: ClipBucket < 5.5.3-#182 Blind SQL Injection via Photo Deletion Endpoint
An attacker may be able to read or change database-backed application data; CVSS 7.1 (HIGH); EPSS percentile 34; sources: NVD, OSV.
- CVE-2026-77928 HIGH CVSS 7.1 -
NVD: ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitization function in... NVD: Attackers can pass unsanitized array elements through the deletion handler in private_message.php into cb_pm::delete_msg(), which interpolates the unescaped message ID directly into a SQL query string, enabling time-based blind SQL injection to retrieve all... OSV: ClipBucket < 5.5.3-#182 Blind SQL Injection via Private Message Deletion Endpoint
An attacker may be able to read or change database-backed application data; CVSS 7.1 (HIGH); EPSS percentile 34; sources: NVD, OSV.
- CVE-2026-93566 MEDIUM CVSS 6.5 -
NVD: A flaw was found in Netty. NVD: A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. NVD: This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests.
A remote attacker may be able to access information that should not be exposed; CVSS 6.5 (MEDIUM); EPSS percentile 48; sources: NVD.
- CVE-2026-10832 MEDIUM CVSS 5.9 -
NVD: A flaw was found in the DERDecoder class within wildfly-elytron-asn1. NVD: The decoder attempts to allocate excessive memory based on an inflated length value without proper validation, leading to Java Virtual Machine (JVM) memory exhaustion. NVD: This results in a remote Denial of Service (DoS) for services that process untrusted DER/ASN.1 input, including SASL (Simple Authentication and Security Layer) authentication mechanisms and X.500 certificate principal parsing paths.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.9 (MEDIUM); EPSS percentile 33; sources: NVD.
- CVE-2024-56344 MEDIUM CVSS 5.9 -
NVD: IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. NVD: An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
A remote attacker may be able to access information that should not be exposed; CVSS 5.9 (MEDIUM); EPSS percentile 5; sources: NVD.
- CVE-2026-93506 MEDIUM CVSS 5.3 -
NVD: A vulnerability was determined in SveltyCMS 0.0.6. NVD: This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. NVD: Executing a manipulation can lead to server-side request forgery.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 5.3 (MEDIUM); EPSS percentile 28; sources: NVD, OSV.
- CVE-2025-13882 MEDIUM CVSS 5.3 -
NVD: IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to cause a denial of...
The affected service may become unavailable or unreliable; CVSS 5.3 (MEDIUM); EPSS percentile 14; sources: NVD.
- CVE-2025-1350 MEDIUM CVSS 5.3 -
NVD: IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. NVD: This information could be used in further attacks against the system.
A remote attacker may be able to access information that should not be exposed; CVSS 5.3 (MEDIUM); EPSS percentile 14; sources: NVD.
- CVE-2026-93505 MEDIUM CVSS 5.1 -
NVD: A vulnerability was found in SveltyCMS 0.0.6. NVD: This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. NVD: Performing a manipulation results in cross site scripting.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for XSS risk; CVSS 5.1 (MEDIUM); EPSS percentile 26; sources: NVD, OSV.
- CVE-2026-16515 MEDIUM CVSS 4.7 -
NVD: net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). NVD: It did not check whether the triggering packet's source address identifies a single node (rule e.6) or whether the packet was sent to a multicast destination (rule e.3, whose only exceptions are Packet Too Big and Parameter Problem Code 2). NVD: Of the five call sites, only the port-unreachable path in subsys/net/ip/connection.c carried an equivalent guard of its own; the extension-header, unknown-next-header and fragmentation paths in subsys/net/ip/ipv6.c and subsys/net/ip/ipv6_fragment.c had none.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure · authenticated boundary; CVSS 4.7 (MEDIUM); EPSS percentile 9; sources: NVD, OSV.
- CVE-2026-25684 MEDIUM CVSS 4.4 -
NVD: A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.4 (MEDIUM); EPSS percentile 8; sources: NVD.
- CVE-2026-16514 MEDIUM CVSS 4.3 -
NVD: gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. NVD: The loop bound was taken solely from the attacker-controlled wire field announce->steps_removed (accepted up to 254), never from announce->tlv.len, which is the field that states how many identities the TLV actually carries. NVD: Because path_sequence is the flexible member of the wire TLV (struct gptp_path_trace_tlv) and GPTP_ANNOUNCE() yields a raw pointer into the received packet buffer, the memcmp() inside the loop can address memory well past the end of the received frame.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.3 (MEDIUM); EPSS percentile 13; sources: NVD, OSV.
- CVE-2026-85511 MEDIUM CVSS 4.2 -
NVD: A flaw was found in EAP's Elytron. NVD: An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.
This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 4.2 (MEDIUM); EPSS percentile 18; sources: NVD.
- CVE-2026-16512 LOW CVSS 3.1 -
NVD: The header accessor gptp_get_hdr() deliberately never fails for a short buffer — it returns pkt->frags->data and leaves validation to its callers — so a truncated frame produced a header pointer covering memory beyond the received data. NVD: The per-message-type checks that follow do not compensate: GPTP_VALID_LEN() reduces to len > 60 once the Ethernet header has been pulled, which is false for every fixed-size gPTP message, so GPTP_CHECK_LEN() never rejects a truncated SYNC, FOLLOWUP... NVD: The defect is reached by an unauthenticated peer on the same link sending an Ethernet frame with ethertype 0x88F7 to the PTP multicast address on an interface configured as a gPTP port, with CONFIG_NET_GPTP enabled.
This low severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for defensive exposure review; CVSS 3.1 (LOW); EPSS percentile 6; sources: NVD, OSV.