CISA KEV (aktif exploit edilen açıklar) ve NVD'den otomatik toplanan güncel güvenlik açıkları (CVE) ve saldırı tipleri — önem derecesi, kategori ve aktif sömürü durumuyla. Yeni açıkları e-posta ile takip edin.
Yüksek 7.3Enjeksiyon (SQL/Komut)
CVE-2026-19905
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but
Jinher OA 1.0'un /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx dosyasındaki httpOID parametresi, uzaktan SQL enjeksiyonuna açık bir güvenlik açığı içeriyor ve istismar kodu kamuya yayınlandığı için saldırı ris…
Kritik 9.1Yol Geçişi / Dosya Erişimi
CVE-2026-18855
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E
WordPress Link Library eklentisinin 7.9.4 ve önceki sürümlerinde, dosya yolu doğrulamasındaki eksiklik nedeniyle kimliği doğrulanmamış saldırganlar sunucudaki rastgele dosyaları silebilir; bu da wp-config.php gibi kritik…
Yüksek 8.1Diğer / Sınıflandırılmamış
CVE-2026-19901
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The
LB-LINK X-PRO 1.0.22-20231206 cihazında, /etc/config/easycwmp dosyasındaki bilinmeyen bir işlevde sabit kodlanmış kimlik bilgileri bulunuyor ve bu, uzaktan saldırıya olanak tanıyor; ancak saldırı karmaşık ve zor olduğund…
Kritik 9.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-19598
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met
WordPress için Pods – Custom Content Types and Fields eklentisinin 3.3.9 ve öncesi sürümlerinde, AJAX yönlendiricisindeki yetki kontrol mekanizmalarının hatalı işlenmesi nedeniyle kimliği doğrulanmamış saldırganlar yönet…
Yüksek 8.1Diğer / Sınıflandırılmamış
CVE-2026-19900
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was c
LB-LINK X-PRO 1.0.22-20231206 cihazında, /etc/shadow dosyasındaki bilinmeyen bir işlevde sabit kodlanmış kimlik bilgileri bulunuyor; bu, uzaktan ve yüksek karmaşıklıkta bir saldırıyla istismar edilebilir ve genel olarak …
Yüksek 7.3Uzaktan Kod Çalıştırma (RCE)
CVE-2026-19899
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
SourceCodester Class and Exam Timetabling System 1.0'un /edit_teacher.php dosyasındaki ID parametresi, uzaktan SQL enjeksiyonuna açık olup, bu güvenlik açığı kamuya ifşa edilmiştir ve istismar edilebilir durumdadır.
Yüksek 8.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-18438
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This is due to a filename validation/destination mismatch in fetch_remote_file, where file type validation is performed against the attacker-controlled Content
WordPress için Templately eklentisinin 3.7.1 ve önceki sürümlerinde, fetch_remote_file fonksiyonundaki dosya adı doğrulama hatası nedeniyle, katkıda bulunan (contributor) seviyesindeki kimliği doğrulanmış saldırganlar su…
Kritik 9.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-16142
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebooker_wp_user_id value, which is passed directly to wp_update_user() without verifying authentication or ownership. This makes it possible for unauthentic
TrueBooker WordPress eklentisinin 1.2.6 ve önceki sürümlerinde, kimlik doğrulaması yapılmayan kullanıcıların herhangi bir kullanıcının e-posta adresini değiştirmesine olanak tanıyan bir hesap ele geçirme açığı bulunmakta…
Yüksek 7.5Yetki Yükseltme
CVE-2026-15142
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This makes it possible for authenticated attackers, with Subscriber-level access and above
WordPress için Real Estate Manager Pro eklentisinin 12.8.6 ve önceki sürümlerinde, allow_attachment_actions() fonksiyonundaki hatalı yetki kontrolü nedeniyle, abone seviyesindeki kimliği doğrulanmış saldırganlar, hedef k…
Kritik 9.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-15826
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check — when a registration is submitted with a 61–70 character username, WordPress core rejects it with a WP_Error
WordPress için User Profile Builder eklentisinin 3.16.4 ve önceki sürümlerinde, 61-70 karakterli bir kullanıcı adıyla kayıt yapıldığında, wppb_log_in_user() fonksiyonundaki tip karışıklığı nedeniyle kimlik doğrulama atla…
Yüksek 8.8Yetki Yükseltme
CVE-2026-14279
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is exposed to any authenticated user through wp_localize_script on the frontend) and that the caller has a positive user ID, then calls WP_User::add_role
WordPress Wholesale Market eklentisinin 2.2.2 ve önceki sürümlerinde, kimliği doğrulanmış bir kullanıcı, ön uçta açığa çıkan nonce'u kullanarak ve rol_required parametresini manipüle ederek, site yöneticisi ilgili seçene…
Yüksek 7.2XSS — Siteler Arası Betik
CVE-2026-16145
The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acces
WordPress için Invisible Anti-Spam & CAPTCHA eklentisinin 5.1 ve önceki sürümlerinde, 'action' parametresinin yetersiz temizlenmesi nedeniyle kimliği doğrulanmamış saldırganların saklanmış (stored) XSS saldırısı gerçekle…
Yüksek 7.2XSS — Siteler Arası Betik
CVE-2026-13360
The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in
WordPress için WPLP Cookie Consent eklentisinin 4.3.5 ve öncesi sürümlerinde, 'regionArray' parametresindeki yetersiz girdi temizliği ve çıktı kaçışı nedeniyle depolanmış XSS açığı bulunur; bu, kimliği doğrulanmamış sald…
Yüksek 8.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-15965
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload function where extension and MIME checks are applied to the uploaded chunk's filename but not to the final assembled filename de
WordPress için MaxUpload eklentisinin 1.4.0 ve önceki sürümlerinde, dosya adı doğrulama hatası nedeniyle kimliği doğrulanmamış saldırganların çalıştırılabilir dosyalar yükleyerek uzaktan kod çalıştırmasına olanak tanıyan…
Kritik 9.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-15341
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied `ussync-key`, `ussync-token`, and `ussync-ref` param
WordPress için User Session Synchronizer eklentisinin 1.4.0 ve önceki tüm sürümlerinde, kimlik doğrulama doğrulaması yapılmadan çalışan `synchronize_session()` fonksiyonu sayesinde, saldırganlar özel hazırlanmış istekler…
Yüksek 8.8Yetki Yükseltme
CVE-2026-15312
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and omitting any `promote_users` capability check before passing the sanitized value
Propovoice: All-in-One Client Management System eklentisinin 1.7.8 ve öncesi sürümlerinde, REST API’deki `create()` fonksiyonu kullanıcı tarafından sağlanan `role` parametresini izin verilen roller listesine karşı doğrul…
Kritik 9.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-15303
The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.27.0. This is due to the six_storage_create_wp_user() AJAX handler being registered on wp_ajax_nopriv_six_storage_create_wp_user without any nonce, capability, credential, or ownership verification, while calling wp_set_current_user() and wp_set_auth_cookie() for any WordPress user
6Storage Rentals WordPress eklentisinin 2.27.0 ve önceki sürümlerinde, kimlik doğrulaması yapılmamış saldırganların, e-posta adresini göndererek herhangi bir kullanıcının (yöneticiler dahil) oturumunu ele geçirmesine ola…
Yüksek 7.5Enjeksiyon (SQL/Komut)
CVE-2026-15162
The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push class — no capability or nonce — so it is reachable by unauthenticated users. The wordpress_object_type value is concatenated
Object Sync for Salesforce eklentisinin REST rotası, kimlik doğrulaması gerektirmeyen wordpress_object_type parametresini doğrudan SQL sorgusuna eklediğinden, kimliği doğrulanmamış saldırganların zaman tabanlı kör SQL en…
Yüksek 8.8Yetki Yükseltme
CVE-2026-15001
The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_configuration_data` and `save_bloyal_accesskeyverification_data` being registered without any capability or nonce checks, and the `bloyal_customer_auto_login` function unconditionally trusting the `Custo
WordPress bLoyal eklentisinin 3.1.611.78 ve önceki sürümlerinde, kimlik doğrulama ve nonce kontrolleri olmayan AJAX işlemleri sayesinde abone seviyesindeki kullanıcılar, eklentinin API URL’sini değiştirip saldırganın kon…
Kritik 9.1Yol Geçişi / Dosya Erişimi
CVE-2026-14484
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the righ
WordPress için RapiSafe – Secure Multi File Upload for Contact Form 7 eklentisinin 1.0.4 ve önceki sürümlerinde, dosya yolu doğrulaması yetersiz olduğundan, kimliği doğrulanmamış saldırganlar sunucudaki rastgele dosyalar…
Yüksek 7.2XSS — Siteler Arası Betik
CVE-2026-14433
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user access
WordPress için vcita Online Booking & Scheduling Calendar eklentisinin 4.6.0 ve önceki sürümlerinde, 'business_id' parametresindeki yetersiz girdi temizliği ve çıktı kaçışı nedeniyle, kimliği doğrulanmamış saldırganların…
Yüksek 8.1Kimlik Doğrulama / Yetki Atlatma
CVE-2026-73683
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php. Attackers who obtain a valid, unexpired id_token issued for the same Facebook App ID can submit the captured token to the backe
Laravel Socialite'ın Facebook sağlayıcısında, FacebookProvider.php dosyasındaki getUserByOIDCToken() fonksiyonunda nonce doğrulamasının eksik olması nedeniyle, kimliği doğrulanmamış saldırganlar ele geçirdikleri geçerli …
Yüksek 7.8Yetki Yükseltme
CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
Microsoft Defender'daki Microsoft Malware Protection Engine'de "ShieldBreak" olarak bilinen bir ayrıcalık yükseltme güvenlik açığı tespit edilmiştir ve Microsoft bu açığı gidermek için güncelleme üzerinde çalışmaktadır.
Yüksek 8.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-73682
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server host. Attackers can craft a malicious git_url value using git's --upload-pack= option to inject and execute arbitrary shell
Semaphore'un 2.18.20 öncesi sürümlerinde, depo git_url işleme sürecindeki bir argüman enjeksiyonu açığı, Manager veya Owner rolüne sahip kimliği doğrulanmış kullanıcıların, git'in --upload-pack= seçeneğiyle kötü niyetli …
Yüksek 7.8Enjeksiyon (SQL/Komut)
CVE-2026-50523
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
Microsoft PowerShell'deki komut enjeksiyonu zafiyeti, yetkili bir saldırganın özel karakterleri kötüye kullanarak sistemde yerel olarak kod çalıştırmasına olanak tanır.
Yüksek 8.8Enjeksiyon (SQL/Komut)
CVE-2026-73680
Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The unsanitized filename is interpolated into a shell command executed via Process::fromShellCommandline() before the slugify() sani
Cockpit CMS 2.14.0 ve öncesinde, yalnızca assets/upload iznine sahip kimliği doğrulanmış kullanıcılar, kabuk meta karakterleri içeren bir video dosyası adı yükleyerek FFmpeg entegrasyonundaki komut enjeksiyonu açığından …
Yüksek 7.5Yol Geçişi / Dosya Erişimi
CVE-2026-18554
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, kimliği doğrulanmış uzak bir saldırgan, kısıtlı dizinlere erişimi sınırlayan yol adı kısıtlamasındaki bir zayıflık nedeniyle hassas bilgileri ele geçirebilir.
Kritik 9.9Enjeksiyon (SQL/Komut)
CVE-2026-17186
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, komutlardaki özel karakterlerin düzgün şekilde filtrelenmemesi nedeniyle uzak bir saldırgan keyfi CL komutları çalıştırabilir.
Kritik 9.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-17184
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, dosya adı veya yolun harici kontrolü nedeniyle uzak bir saldırgan keyfi kod çalıştırabilir.
Kritik 9.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-17182
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, istek URI yol bölümlerinin hatalı doğrulanması nedeniyle uzak bir saldırgan kimlik doğrulamasını atlayarak hassas bilgileri okuyabilir veya değiştirebilir.
Kritik 9.3Yol Geçişi / Dosya Erişimi
CVE-2026-17181
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, yol geçişi (path traversal) zafiyeti nedeniyle uzaktaki bir saldırgan, sunucuda keyfi konumlara dosya yazabilir.
Yüksek 8.5Enjeksiyon (SQL/Komut)
CVE-2026-17179
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, kimliği doğrulanmış uzak bir saldırgan, komut enjeksiyonu açığı sayesinde hizmet reddi (denial of service) durumuna yol açabilir.
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-17177
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, kontrolsüz özyineleme nedeniyle uzak bir saldırgan hizmet reddi (denial of service) durumuna yol açabilir.
Yüksek 7.5Kimlik Doğrulama / Yetki Atlatma
CVE-2026-17175
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
IBM Db2 Mirror for i sürüm 7.4, 7.5 ve 7.6’da, kimlik doğrulama kontrollerinin yetersiz uygulanması nedeniyle uzaktan kimliği doğrulanmış bir saldırgan hassas bilgilere erişebilir.
Yüksek 8.2Yol Geçişi / Dosya Erişimi
CVE-2026-17081
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, yol adının kısıtlı bir dizine sınırlandırılmaması nedeniyle uzak bir saldırgan, sistemde rastgele dosyalar yazabilir.
Yüksek 7.5Yol Geçişi / Dosya Erişimi
CVE-2026-16915
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
IBM Db2 Mirror for i sürüm 7.4, 7.5 ve 7.6'daki hatalı girdi doğrulaması, kimliği doğrulanmış uzak bir saldırganın hassas bilgileri ele geçirmesine olanak tanır.
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-16879
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
IBM Db2 Mirror for i sürüm 7.4, 7.5 ve 7.6'da, kimliği doğrulanmış uzak bir saldırgan, kullanıcı tarafından sağlanan girdilerdeki hatalı yetkilendirme nedeniyle güvenlik kısıtlamalarını aşabilir.
Yüksek 8.3Bilgi İfşası
CVE-2026-16708
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
IBM Db2 Mirror for i'nin 7.4, 7.5 ve 7.6 sürümlerinde, sistem yapılandırmasının harici kontrolü nedeniyle uzak bir saldırgan hassas bilgileri ele geçirebilir.
Yüksek 7.2Uzaktan Kod Çalıştırma (RCE)
CVE-2026-73679
ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded content via undoHtmlSpecialChars() before passing it to eval() in the renderWithPhp() method, bypassing HTML Purifier saniti
ImpressCMS'in özel etiket modülünde, kimliği doğrulanmış yöneticilerin PHP tipinde kötü niyetli bir yük depolayarak, HTML Purifier filtrelemesini atlatan ve her sayfa yüklemesinde çalışan eval() çağrısı üzerinden rastgel…
Kritik 10Uzaktan Kod Çalıştırma (RCE)
CVE-2026-73678
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers
MindsDB Minds Platform 26.1.0 ve öncesi, kimlik doğrulaması gerektirmeyen POST /api/v1/responses/ uç noktasına özel hazırlanmış istemler gönderilerek, korumasız exec() çağrısı yapan Anton ajanının scratchpad aracı üzerin…
Yüksek 8.3Bellek Bozulması (Taşma/UAF)
CVE-2026-72970
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Microsoft Edge (Chromium tabanlı) tarayıcısındaki yığın tabanlı bellek taşması güvenlik açığı, ağ üzerinden yetkisiz bir saldırganın bu tarayıcıda kod çalıştırmasına olanak tanır.
Yüksek 8.8Bellek Bozulması (Taşma/UAF)
CVE-2026-19847
A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
TOTOLINK A800R yönlendiricisinin wps.so bileşenindeki setWiFiWpsConfig fonksiyonunda, pin parametresinin manipülasyonuyla uzaktan istismar edilebilen bir yığın tabanlı arabellek taşması güvenlik açığı bulunmaktadır ve bu…
Yüksek 8.8Bellek Bozulması (Taşma/UAF)
CVE-2026-19846
A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.
TOTOLINK A800R yönlendiricisinin firewall.so bileşenindeki setUrlFilterRules fonksiyonunda, url parametresinin işlenmesi sırasında yığın tabanlı arabellek taşması oluşuyor ve bu güvenlik açığı uzaktan istismar edilebiliy…
Yüksek 8.8Bellek Bozulması (Taşma/UAF)
CVE-2026-19845
A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
TOTOLINK A800R yönlendiricinin 4.1.2cu.5137_B20200730 sürümünde, /cgi-bin/cstecgi.cgi dosyasındaki setStaticDhcpConfig fonksiyonuna gönderilen "Comment" parametresinin işlenmesi sırasında yığın tabanlı arabellek taşması …
Yüksek 8.8Bellek Bozulması (Taşma/UAF)
CVE-2026-19844
A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.
TOTOLINK A800R yönlendiricinin ipv6.so bileşenindeki setRadvdCfg fonksiyonunda, radvdinterfacename parametresinin uzun bir değerle gönderilmesi yığın tabanlı arabellek taşmasına yol açıyor ve bu güvenlik açığı uzaktan is…
Yüksek 7.5Uzaktan Kod Çalıştırma (RCE)
CVE-2026-53970
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-co
ZeroBrew 0.3.1 ve öncesi sürümlerinde, Ruby uyumluluk katmanındaki bütünlük doğrulama eksikliği nedeniyle, ağ saldırganları formül kaynakları veya URL tabanlı yama adreslerindeki indirmeleri sahte içerikle değiştirerek, …
Yüksek 7.7Enjeksiyon (SQL/Komut)
CVE-2026-69101
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a m
Datavane TIS v5.0.0'daki XXE açığı, kimliği doğrulanmış saldırganların doEditWorkflow uç noktasına özel hazırlanmış bir XML yükü göndererek sunucu tarafı istek sahteciliği yapmasına ve yerel dosyaları (ör. yapılandırma v…
Yüksek 8.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-73673
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentica
Netis NC63 yönlendirici yazılımı V3.0.0.3327, kimlik doğrulama gerektirmeyen bir ürün yazılımı güncelleme açığı içerir; saldırganlar, geçerli bir oturum çerezi olmadan /cgi-bin/upload_fw.cgi adresine çok parçalı bir POST…
Yüksek 7.3Güvensiz Seri Hale Getirme
CVE-2026-19826
A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/HessianSerializer.java of the component xxl-rpc Listener. The manipulation results in deserialization. The attack may be performed from remote. The exploit is now public and may be used. The project closed the issue report as "not planned" without any fu
alldatacenter alldata 0.6.8 ve öncesindeki xxl-rpc Listener bileşeninde, Hessian2Input.readObject fonksiyonundaki güvenlik açığı, uzaktan deserialization saldırısına olanak tanır ve istismar kodu kamuya açık olduğundan k…
Yüksek 7.3Uzaktan Kod Çalıştırma (RCE)
CVE-2026-19825
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
SourceCodester Simple Client Management System 1.0'daki /classes/Master.php?f=save_service dosyasında, ID parametresine yapılan manipülasyon SQL enjeksiyonuna yol açıyor ve uzaktan istismar edilebiliyor; bu açık kamuya d…
Kaynaklar: CISA Known Exploited Vulnerabilities (KEV) Catalog · NIST National Vulnerability Database (NVD). Veriler otomatik ve periyodik olarak toplanır; resmi kaynak her zaman önceliklidir.