🛰️ Tehdit Radarı — Güncel Güvenlik Açıkları & Saldırı Tipleri

CISA KEV (aktif exploit edilen açıklar) ve NVD'den otomatik toplanan güncel güvenlik açıkları (CVE) ve saldırı tipleri — önem derecesi, kategori ve aktif sömürü durumuyla. Yeni açıkları e-posta ile takip edin.

📬 Yeni açıkları e-postayla al → giriş yap🛡️ Farkındalık Eğitimi
Yüksek 7.3Uzaktan Kod Çalıştırma (RCE)
CVE-2026-19231
A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
SourceCodester Simple Doctors Appointment System 1.0'un /admin/ajax.php?action=delete_appointment dosyasındaki ID parametresi, uzaktan SQL enjeksiyonuna açık bir güvenlik açığı içeriyor ve kamuya açıklanmış istismar kodu…
📅 2026-08-07NVD →
Yüksek 7.3Kimlik Doğrulama / Yetki Atlatma
CVE-2026-11430
Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-circuits and skips token validation, so an unauthenticated remote attacker who can reach POST /scheduler/webhook can trigger the operator's already-configured scheduled jobs by sending a single request.
Grav CMS'in scheduler-webhook eklentisinde, webhook özelliği etkinleştirilmiş ancak webhookToken tanımlanmamışsa token doğrulaması atlanır ve kimliği doğrulanmamış uzak bir saldırgan, tek bir istekle önceden yapılandırıl…
📅 2026-08-07NVD →
Yüksek 8Güvensiz Seri Hale Getirme
CVE-2026-68772
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands wh
ZenML 0.94.6'daki CloudpickleMaterializer bileşeni, paylaşılan bir artifact deposuna yazma erişimi olan saldırganların, kötü niyetli bir pickle dosyası yerleştirerek herhangi bir kullanıcı veya pipeline bu artifact'ı kul…
📅 2026-08-07NVD →
Yüksek 7.5Bellek Bozulması (Taşma/UAF)
CVE-2026-20348
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file th
ClamAV'nin XAR dosya formatı ayrıştırıcısındaki sınır kontrolü eksikliği, uzak bir saldırganın özel hazırlanmış bir dosya göndererek bellek bozulmasına yol açmasına ve tarama işleminin sonlanmasıyla hizmet reddi (DoS) du…
📅 2026-08-07NVD →
Yüksek 7.5Bellek Bozulması (Taşma/UAF)
CVE-2026-20347
A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could ex
ClamAV'nin Mach-O dosya ayrıştırıcısındaki sınır kontrolü eksikliği, uzak bir saldırganın özel hazırlanmış bir dosya göndererek bellek bozulmasına ve hizmet reddine (DoS) yol açmasına olanak tanır.
📅 2026-08-07NVD →
Yüksek 7.5Bellek Bozulması (Taşma/UAF)
CVE-2026-20346
A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit
ClamAV'nin PDF dosya ayrıştırıcısındaki bir bellek bozulması güvenlik açığı, kimliği doğrulanmamış uzak bir saldırganın özel hazırlanmış bir PDF dosyası göndererek tarama işlemini sonlandırmasına ve hizmet dışı bırakma (…
📅 2026-08-07NVD →
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-20345
A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerab
ClamAV'nin GPT dosya formatı ayrıştırıcısındaki bir bellek bozulması, uzak ve kimliği doğrulanmamış bir saldırganın özel hazırlanmış bir GPT dosyası göndererek tarama işlemini sonlandırmasına ve hizmet dışı bırakma (DoS)…
📅 2026-08-07NVD →
Yüksek 7.5Bellek Bozulması (Taşma/UAF)
CVE-2026-20339
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit thi
ClamAV'nin PESpin dosya formatı ayrıştırıcısındaki sınır kontrolü eksikliği, tamsayı taşmasına ve bellek bozulmasına yol açarak, uzak bir saldırganın özel hazırlanmış bir dosya göndererek hizmet reddi (DoS) durumuna nede…
📅 2026-08-07NVD →
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-20338
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to
ClamAV'nin zip arşiv ayrıştırıcısındaki hatalı bellek yönetimi, kimliği doğrulanmamış uzak bir saldırganın özel hazırlanmış bir zip dosyası göndererek tarama işleminin çift serbest bırakma (double-free) nedeniyle sonlanm…
📅 2026-08-07NVD →
Yüksek 7.5Bellek Bozulması (Taşma/UAF)
CVE-2026-20337
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A succe
ClamAV'nin zip arşiv ayrıştırıcısındaki bir güvenlik açığı, kimliği doğrulanmamış uzak bir saldırganın, özel hazırlanmış bir zip dosyası göndererek sınır dışı yazma hatasına yol açmasına ve tarama işleminin sonlanmasına …
📅 2026-08-07NVD →
Yüksek 7.3Uzaktan Kod Çalıştırma (RCE)
CVE-2026-19211
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
SourceCodester Photo Share Website 1.0'un /social/ajax.php?action=signup dosyasındaki email parametresi, uzaktan SQL enjeksiyonuna açık bir güvenlik açığı içeriyor ve istismar kodu kamuya yayınlanmış durumda.
📅 2026-08-07NVD →
Kritik 9.8Uzaktan Kod Çalıştırma (RCE)
CVE-2022-4995
Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.jsp with arbitrary secId and plandetailid field values. Successful exploitation results in remote code execution under the
Weaver (Fanwei) E-cology 9.0'un 10.52 öncesi sürümlerinde, kimliği doğrulanmamış bir saldırganın belirli bir POST isteğiyle keyfi dosya (JSP webshell dahil) yüklemesine ve böylece uzaktan kod çalıştırmasına olanak tanıya…
📅 2026-08-07NVD →
Yüksek 7.5Enjeksiyon (SQL/Komut)
CVE-2026-15816
A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option, an attacker on the adjacent network who controls a rogue DHCP server can inject a command-substitution sequence that executes as root the next time
dracut'taki die() hata işleme fonksiyonu, mesajı initramfs acil durum kancası dizinindeki bir kabuk betiğine uygun kabuk tırnaklama yapmadan yazar; DHCP ROOT_PATH seçeneğinden türetilen veri içerdiğinde, ağdaki kötü niye…
📅 2026-08-07NVD →
Yüksek 7.3Uzaktan Kod Çalıştırma (RCE)
CVE-2026-19196
A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
SourceCodester Photo Share Website 1.0'un /social/ajax.php?action=login dosyasındaki email parametresi, uzaktan SQL enjeksiyonuna açıktır ve istismar kodu kamuya yayınlanmıştır.
📅 2026-08-07NVD →
Yüksek 7.8Diğer / Sınıflandırılmamış
CVE-2026-19195
A vulnerability has been found in V-Secure Jingyun Antivirus 2.4.2.39. The affected element is an unknown function in the library ZyArk.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond
V-Secure Jingyun Antivirus 2.4.2.39 sürümündeki ZyArk.sys çekirdek sürücüsünde, yerel olarak gerçekleştirilebilen ve uygunsuz erişim kontrollerine yol açan bir güvenlik açığı bulunmaktadır; istismar kodu kamuya ifşa edil…
📅 2026-08-07NVD →
Yüksek 7.8Diğer / Sınıflandırılmamış
CVE-2026-19193
A flaw has been found in Jiangmin Antivirus 21. Impacted is the function MessageNotifyCallback in the library kvcore.sys of the component Minifilter Port. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Jiangmin Antivirus 21'in kvcore.sys sürücüsündeki MessageNotifyCallback işlevinde, yerel olarak istismar edilebilen ve uygunsuz erişim kontrollerine yol açan bir güvenlik açığı bulunmaktadır; istismar kodu yayınlanmış ol…
📅 2026-08-07NVD →
Yüksek 7.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-19192
A vulnerability was detected in DeepCool DisplayService 1.2.12. This issue affects some unknown processing of the file C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit is now public and may be used.
DeepCool DisplayService 1.2.12 sürümünde, yerel erişimle C:\DeepCool\resources\service\x64\DeepCoolDisplayService.exe dosyasına yapılan manipülasyon, hatalı erişim kontrollerine yol açıyor ve kamuya açıklanmış bu istisma…
📅 2026-08-07NVD →
Yüksek 7.8Diğer / Sınıflandırılmamış
CVE-2026-19191
A security vulnerability has been detected in StableBit DrivePool 2.3.13.1687. This vulnerability affects unknown code of the file C:\Program Files\StableBit\DrivePool\DrivePool.Service.exe of the component DrivePoolService. Such manipulation leads to permission issues. The attack must be carried out locally. The exploit has been disclosed publicly and may be used.
StableBit DrivePool 2.3.13.1687 sürümündeki DrivePool.Service.exe dosyasında, yerel olarak istismar edilebilen ve yetki sorunlarına yol açan bir güvenlik açığı bulunmaktadır; bu açık kamuya ifşa edilmiştir ve saldırganla…
📅 2026-08-07NVD →
Kritik 9.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-14365
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to change the password of arbitrary user accounts, including administrators, which can b
WordPress için TrueBooker eklentisinin 1.2.3 ve önceki tüm sürümlerinde, kullanıcı yetkilendirmesinin düzgün doğrulanmaması nedeniyle kimlik doğrulaması yapılmamış saldırganlar, yöneticiler dahil herhangi bir kullanıcını…
📅 2026-08-07NVD →
Kritik 9.8Diğer / Sınıflandırılmamış
CVE-2026-14364
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before resetting their password. This makes it possible for unauthenticated attackers to reset the password of arbitrary user accounts,
TrueBooker WordPress eklentisinin 1.2.3 ve önceki sürümlerinde, şifre sıfırlama işlemi kullanıcı kimliğini doğrulamadığı için kimliği doğrulanmamış saldırganlar, yöneticiler dahil herhangi bir hesabın şifresini sıfırlayı…
📅 2026-08-07NVD →
Yüksek 7.8Diğer / Sınıflandırılmamış
CVE-2026-19190
A weakness has been identified in StableBit Scanner 2.6.13.4088. This affects an unknown part of the file C:\Program Files (x86)\StableBit\Scanner\Service\Scanner.Service.exe of the component ScannerService. This manipulation causes permission issues. The attack is restricted to local execution. The exploit has been made available to the public and could be used for attacks.
StableBit Scanner 2.6.13.4088 sürümündeki Scanner.Service.exe dosyasında, yerel olarak çalıştırılabilen ve izin yönetimi sorunlarına yol açan bir güvenlik açığı bulunmaktadır; bu açık için genel bir istismar kodu yayınla…
📅 2026-08-07NVD →
Yüksek 7.8Diğer / Sınıflandırılmamış
CVE-2026-19189
A security flaw has been discovered in Power Sofware PowerISO 9.3.0.0. Affected by this issue is some unknown functionality in the library C:\Windows\System32\drivers\scdemu.sys of the component Kernel Driver. The manipulation results in improper privilege management. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The vendor
PowerISO 9.3.0.0'un çekirdek sürücüsü scdemu.sys içindeki bilinmeyen bir işlev, yerel erişimle ayrıcalık yönetimini bozarak saldırgana yetki yükseltme imkânı tanıyor ve bu güvenlik açığı için genel bir istismar kodu yayı…
📅 2026-08-07NVD →
Kritik 9.6SSRF — Sunucu Taraflı İstek
CVE-2026-70332
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Microsoft Office SharePoint'daki sunucu taraflı istek sahteciliği (SSRF) açığı, yetkisiz bir saldırganın ağ üzerinde kimlik sahtekarlığı yapmasına olanak tanır.
📅 2026-08-07NVD →
Kritik 9.1Diğer / Sınıflandırılmamış
CVE-2026-68823
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Azure Confidential Ledger'daki tehlikeli bir metodun veya fonksiyonun açıkta olması, yetkili bir saldırganın ağ üzerinden kod çalıştırmasına olanak tanır.
📅 2026-08-07NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-65668
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network.
Microsoft Purview eDiscovery'daki hatalı erişim kontrolü, yetkili bir saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 10Kimlik Doğrulama / Yetki Atlatma
CVE-2026-65667
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Microsoft Teams'teki yetkilendirme eksikliği, ağ üzerinden yetkisiz bir saldırganın ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 10Kimlik Doğrulama / Yetki Atlatma
CVE-2026-63508
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Microsoft Planetary Computer Pro'da kritik bir işlev için kimlik doğrulama eksikliği, ağ üzerinden yetkisiz bir saldırganın ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Yüksek 7.5Kriptografik Zayıflık
CVE-2026-62918
Improper verification of cryptographic signature in Microsoft Teams allows an unauthorized attacker to perform spoofing over a network.
Microsoft Teams'teki kriptografik imza doğrulama hatası, ağ üzerinden yetkisiz bir saldırganın kimlik sahtekarlığı yapmasına olanak tanır.
📅 2026-08-07NVD →
Kritik 9.6Kimlik Doğrulama / Yetki Atlatma
CVE-2026-62896
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Microsoft Teams’teki hatalı kimlik doğrulama, yetkili bir saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 9.8Kriptografik Zayıflık
CVE-2026-62873
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Microsoft 365 Yönetim Merkezi'ndeki kriptografik imza doğrulamasının hatalı olması, yetkisiz bir saldırganın ağ üzerinden ayrıcalık yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Yüksek 8.7Diğer / Sınıflandırılmamış
CVE-2026-62836
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
Azure SQL Managed Instance'daki iletişim kanalının hedeflenen uç noktalarla sınırlandırılmaması, yetkisiz bir saldırganın ağ üzerinden ayrıcalık yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 9.9Kimlik Doğrulama / Yetki Atlatma
CVE-2026-62830
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Azure SRE Agent'teki yetkilendirme eksikliği, kimliği doğrulanmış bir saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 9.3Diğer / Sınıflandırılmamış
CVE-2026-59118
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network.
Microsoft Power Apps'teki hatalı yetkilendirme kontrolü, ağ üzerinden yetkisiz bir saldırganın ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 9.9Diğer / Sınıflandırılmamış
CVE-2026-59115
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Microsoft Entra Sağlama Hizmeti'ndeki (SyncFabric) bir yol geçişi (path traversal) güvenlik açığı, yetkili bir saldırganın ağ üzerinden ayrıcalık yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 10Kimlik Doğrulama / Yetki Atlatma
CVE-2026-56162
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Azure SQL Database'teki hatalı kimlik doğrulama mekanizması, ağ üzerinden yetkisiz bir saldırganın ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 9.6Diğer / Sınıflandırılmamış
CVE-2026-56161
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Azure Logic Apps'teki hatalı erişim kontrolü, yetkili bir saldırganın ağ üzerinden bilgi ifşa etmesine olanak tanır.
📅 2026-08-07NVD →
Kritik 9.9Güvensiz Seri Hale Getirme
CVE-2026-50515
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Azure Service Bus'taki güvenilir olmayan verilerin seri durumdan çıkarılması, yetkili bir saldırganın ağ üzerinden kod çalıştırmasına olanak tanır.
📅 2026-08-07NVD →
Kritik 9.9Diğer / Sınıflandırılmamış
CVE-2026-50481
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Azure Active Directory'de varsayılan olarak değiştirilemez kabul edilen verilerin (MAID) değiştirilebilmesi, yetkili bir saldırganın ağ üzerinden ayrıcalık yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Yüksek 8.8Yol Geçişi / Dosya Erişimi
CVE-2026-49163
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
Application Insights Profiler'daki yol geçişi (path traversal) güvenlik açığı, yetkili bir saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanır.
📅 2026-08-07NVD →
Yüksek🔥 AKTİF EXPLOITEnjeksiyon (SQL/Komut)
CVE-2026-8037
Progress LoadMaster Command Injection Vulnerability
Progress LoadMaster'da, kimliği doğrulanmamış bir saldırganın, birden fazla komut uç noktasındaki temizlenmemiş girdiyi istismar ederek cihaz üzerinde rastgele komut çalıştırmasına olanak tanıyan bir komut enjeksiyonu gü…
🏷 Progress · LoadMaster📅 2026-08-07NVD →
Yüksek 7.8Bellek Bozulması (Taşma/UAF)
CVE-2026-8325
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute ar…
📅 2026-08-06NVD →
Yüksek 7.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-7867
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation th
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This al…
📅 2026-08-06NVD →
Yüksek 7.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-7406
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the c…
📅 2026-08-06NVD →
Yüksek 7Uzaktan Kod Çalıştırma (RCE)
CVE-2026-70640
llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and free_1context() lack synchronization, allowing Thread A to operate on freed memory while Thread B concurrently frees the llama_context. Attackers can exploit this by performing heap spray with attacker-controlled data containing a fake vtable to hijac
llama.cpp'nin b1886 ile b7445 sürümlerinde, Android JNI sarmalayıcısındaki bir yarış koşulu, kullanıcı tarafından kontrol edilen verilerle sahte bir vtable işaretçisi yerleştirilerek uzaktan kod çalıştırmaya yol açabilen…
📅 2026-08-06NVD →
Yüksek 7.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-70638
llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multiplies sizeof(llama_seq_id) by an attacker-controlled n_seq_max parameter without overflow validation, causing heap buffer allocation to wrap and allocate insufficient memory. Attackers can exploit this by providing a crafted n_seq_max value through a
llama.cpp'nin b1886 ile b7445 sürümlerinde, LLaMA-Android JNI sarmalayıcısındaki new_1batch() işlevi, saldırganın kontrol ettiği n_seq_max parametresini doğrulamadan çarparak tamsayı taşmasına ve yetersiz bellek ayrımına…
📅 2026-08-06NVD →
Yüksek 7.5Kimlik Doğrulama / Yetki Atlatma
CVE-2026-70636
Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh endpoint by exploiting prefix-based whitelist matching in the authentication middleware defined in packages/server/src/utils/constants.ts. Attackers can send a POST request to the oauth2-credential refresh route with a trailing credential identifier to
Flowise 3.1.4 ve öncesinde, kimlik doğrulama ara katmanındaki önek tabanlı beyaz liste eşleştirme açığı sayesinde kimliği doğrulanmamış saldırganlar, OAuth2 kimlik bilgisi yenileme uç noktasına sonda bir kimlik bilgisi t…
📅 2026-08-06NVD →
Yüksek 7.1Bellek Bozulması (Taşma/UAF)
CVE-2026-70635
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with
TimescaleDB 2.29.1 ve öncesinde, kimliği doğrulanmış saldırganların özel hazırlanmış bir Simple8b değeri göndererek imzasız int16 Arrow dizin türünde saklanan ve doğrulama kontrollerini atlatan bir sınır dışı okuma hatas…
📅 2026-08-06NVD →
Yüksek 8.1Bellek Bozulması (Taşma/UAF)
CVE-2026-70634
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML
TimescaleDB 2.29.1 ve öncesinde, Dictionary sıkıştırma algoritmasının ters yönlü satır yineleyicisinde doğrulanmamış bir indeks nedeniyle sınır dışı bellek okuma açığı bulunur; DML erişimi olan bir saldırgan, özel hazırl…
📅 2026-08-06NVD →
Yüksek 7.8Bellek Bozulması (Taşma/UAF)
CVE-2026-70632
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing
FFmpeg 4.4 ile 9.0 arasındaki sürümlerde, GoPro CineForm HD (CFHD) kod çözücüsündeki bir bellek taşması hatası, özel hazırlanmış bir AVI dosyasıyla uzaktan kod yürütülmesine olanak tanır; cfhd_decode() fonksiyonu çıktı g…
📅 2026-08-06NVD →
Yüksek 7.8Bellek Bozulması (Taşma/UAF)
CVE-2026-70628
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-c
FFmpeg'in 0.5 ile 9.0 arasındaki sürümlerinde, DVB altyazı ayrıştırıcısındaki imzalı tamsayı taşması, özel hazırlanmış bir WTV dosyasıyla sınır kontrolünü atlatarak heap belleğinde taşmaya ve olası kod yürütmeye yol açab…
📅 2026-08-06NVD →

Kaynaklar: CISA Known Exploited Vulnerabilities (KEV) Catalog · NIST National Vulnerability Database (NVD). Veriler otomatik ve periyodik olarak toplanır; resmi kaynak her zaman önceliklidir.