🛰️ Tehdit Radarı — Güncel Güvenlik Açıkları & Saldırı Tipleri

CISA KEV (aktif exploit edilen açıklar) ve NVD'den otomatik toplanan güncel güvenlik açıkları (CVE) ve saldırı tipleri — önem derecesi, kategori ve aktif sömürü durumuyla. Yeni açıkları e-posta ile takip edin.

📬 Yeni açıkları e-postayla al → giriş yap🛡️ Farkındalık Eğitimi
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94425
A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege management. Attacking locally is a requirement. The vendor was contacted early about this disclosure but did not respond in any way.
Moore Threads MTT S80 sürücü paketi 340.150'deki mtdispkm64.sys kütüphanesinin sub_140006F0C fonksiyonunda, IOCTL işleyicisindeki hatalı yetki yönetimi nedeniyle yerel bir saldırganın ayrıcalıklarını yükseltmesine olanak…
📅 2026-09-21NVD →
Yüksek 7.5Diğer / Sınıflandırılmamış
CVE-2026-94627
vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhaustion by submitting completion requests with multiple prompts, causing orphaned KV cache blocks to accumulate until process restart and eventually preventing legitima
vLLM Mooncake connector 0.29.0 ve öncesinde, prefill/decode ayrıştırılmış dağıtımlarda aynı transfer ID'sini paylaşan eşzamanlı alt istekler GPU KV cache blok sahipliğini doğru yönetemediğinden, saldırganlar çoklu prompt…
📅 2026-09-21NVD →
Yüksek 7.5Diğer / Sınıflandırılmamış
CVE-2026-94626
vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode disaggregated deployments to exhaust memory and trigger kernel OOM-kill of the decode worker process.
vLLM 0.29.0 ve öncesi sürümlerde, OpenAI uyumlu tamamlama uç noktalarında kv_transfer_params içindeki tp_size parametresi doğrulanmadığı için saldırganlar sınırsız bellek tahsisine yol açabilir. Prefill/decode ayrıştırıl…
📅 2026-09-21NVD →
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-94624
vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port values in kv_transfer_params to create unreachable peer sessions that retain ZeroMQ sockets until the context quota is exhausted, causing an uncaught ZMQError that
vLLM 0.29.0 ve öncesinde, P2P KV offloading yapılandırmasında saldırganların kv_transfer_params içinde rastgele uzak host ve port değerleri sağlayarak erişilemeyen eş oturumları oluşturması ve ZeroMQ soketlerinin bağlam …
📅 2026-09-21NVD →
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-94623
vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can trigger an assertion failure in NixlBaseConnectorWorker._apply_prefix_caching by submitting completion requests with multiple prompts of va
vLLM 0.29.0 ve öncesi sürümlerde, NIXL bağlayıcısının önek önbellekleme mekanizması, prefill/decode ayrıştırılmış dağıtımlarda çoklu istem içeren tamamlama isteklerindeki blok sayılarını doğru şekilde doğrulamadığı için …
📅 2026-09-21NVD →
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-94622
vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entries to trigger an uncaught KeyError in EngineCore scheduling, causing the decode engine to terminate and making all routed requests fail until manual restart.
vLLM 0.29.0 ve öncesi sürümlerde, prefill/decode ayrıştırılmış dağıtımlarda NIXL bağlayıcısının metadata işlemesinde bir hizmet dışı bırakma (DoS) açığı bulunur. Saldırganlar eksik kv_transfer_params girdileri içeren ist…
📅 2026-09-21NVD →
Yüksek 7.7Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94540
DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's local service without any pairing confirmation or user interaction. Attackers can exploit the unauthenticated local service through same-device loopback to perform
DesktopSMS 1.11.0'daki kimlik doğrulaması olmayan yerel servis, aynı cihazdaki saldırganların eşleştirme onayı veya kullanıcı etkileşimi olmadan SMS göndermesine, SMS içeriğine erişmesine ve sahte bir eşleşmiş kimlik kal…
📅 2026-09-21NVD →
Yüksek 7.1Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94535
lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNotice endpoint with arbitrary notice IDs to permanently remove notifications belonging to other users without recipient validation.
lamp-cloud 5.10.0 ve öncesi sürümlerde, deleteMyNotice uç noktasındaki yetkilendirme atlama açığı nedeniyle kimliği doğrulanmış kullanıcılar, DELETE /anyone/extendNotice/deleteMyNotice isteğine rastgele bildirim kimlikle…
📅 2026-09-21NVD →
Yüksek 7.1Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94534
lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodies to rewrite profile fields including nickname, ID card, sex, nation, education, work description, and avatar attachments of other users.
lamp-cloud 5.10.0 ve öncesi sürümlerde, PUT /anyone/baseInfo ve PUT /anyone/avatar uç noktalarında kullanıcı kimliği doğrulanmadığı için kimliği doğrulanmış saldırganlar, istek gövdesine başka kullanıcıların ID'lerini ek…
📅 2026-09-21NVD →
Yüksek 8.8Bellek Bozulması (Taşma/UAF)
CVE-2026-94424
A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
Moore Threads MTT S80 sürücü paketinin 340.150 ve öncesi sürümlerinde, mtdispkm64.sys kütüphanesindeki sub_140001000 fonksiyonunda IOCTL işleyicisi üzerinden yerel bir saldırganın tetikleyebileceği heap tabanlı bir belle…
📅 2026-09-21NVD →
Yüksek 8.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94501
jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authenticated users to create, modify, or delete authorization-relation rows without privilege checks. Attackers can manipulate user-role mappings and access controls to escalate privileges, strip access from other accounts, or modify role-function relationships for any user in the tena
jshERP 3.6 ve öncesi sürümlerde, userBusiness CRUD uç noktalarında yetkilendirme atlama açığı bulunur; kimliği doğrulanmış bir kullanıcı, yetki kontrolü olmadan yetki ilişkisi kayıtlarını oluşturabilir, değiştirebilir ve…
📅 2026-09-21NVD →
Yüksek 8.3Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94497
jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object identifiers without authorization checks.
jshERP 3.6 ve öncesi sürümlerinde, kimliğe göre bilgi alma, güncelleme ve silme uç noktalarında nesne sahipliği doğrulanmadığı için kimliği doğrulanmış kullanıcılar, doğrudan nesne kimlikleri göndererek başka kullanıcıla…
📅 2026-09-21NVD →
Yüksek 8.3Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94496
jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to escalate privileges, change data visibility to all data, and access all business records in the tenant.
jshERP 3.6 ve öncesi sürümlerde, rol yönetimi uç noktalarında çağıranın yetkileri doğrulanmadığından, kimliği doğrulanmış herhangi bir kullanıcı /role/update ve /role/delete uç noktalarını kullanarak istediği rolün veri …
📅 2026-09-21NVD →
Yüksek 7.1Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94495
jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering company identity, stock rules, approval behavior, and printing configuration through the systemConfig endpoint.
jshERP 3.6 ve öncesinde SystemConfigService.updateSystemConfig fonksiyonunda yetki doğrulaması yapılmadığından, kimliği doğrulanmış kullanıcılar systemConfig uç noktası üzerinden şirket kimliği, stok kuralları, onay davr…
📅 2026-09-21NVD →
Yüksek 8.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94412
jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to reset that account's password to a known default value, enabling unauthorized access to other user accounts including administrators.
jshERP 3.6 ve öncesinde, POST /user/resetPwd uç noktasındaki yetkilendirme atlama açığı sayesinde kimliği doğrulanmış bir kullanıcı, hedef kullanıcı kimliğini belirterek başka bir kullanıcının parolasını bilinen varsayıl…
📅 2026-09-21NVD →
Yüksek 8.8Kimlik Doğrulama / Yetki Atlatma
CVE-2026-94411
jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own user ID, and a role ID list to escalate from low-privilege tenant user to tenant administrator.
jshERP 3.6'daki updateOneValueByKeyIdAndType uç noktası, kimliği doğrulanmış kullanıcıların kendilerine keyfi rol atamasına izin veren bir yetki yükseltme açığı içerir. Saldırganlar type=UserRole, kendi kullanıcı kimlikl…
📅 2026-09-21NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94403
A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did no
ColorFul iGameCenter 1.0.3.4 sürümündeki ene.sys sürücüsünde, IOCTL Handler bileşenindeki sub_140001AF0 fonksiyonunda güvenilmeyen bir işaretçinin referans alınmasına (untrusted pointer dereference) yol açan bir güvenlik…
📅 2026-09-21NVD →
Yüksek 7.5Hizmet Reddi (DoS)
CVE-2026-94449
A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the applica
Quarkus'un mikroservislerde retry ve circuit breaker gibi stratejiler için kullandığı SmallRye Fault Tolerance kütüphanesinde, ApplyGuard veya ApplyFaultTolerance anotasyonları kullanıldığında iç izleme nesnelerinin her …
📅 2026-09-21NVD →
Yüksek 8.1Uzaktan Kod Çalıştırma (RCE)
CVE-2026-94184
A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixed stack buffer while building the NTLM authenticate response. This may lead to remote code execution depending on stack-frame layout, or to authentication failure
NTLM desteğiyle derlenen fetchmail'de, kötü niyetli bir posta sunucusunun gönderdiği özel hazırlanmış Type 2 challenge yanıtı, NTLM kimlik doğrulama yanıtı oluşturulurken sabit boyutlu yığın tamponunun taşmasına neden ol…
📅 2026-09-21NVD →
Yüksek 8.1Kimlik Doğrulama / Yetki Atlatma
CVE-2026-80110
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended
pki-core'da, v2 REST ACL filtresi çakışan literal ve joker karakterli ACL anahtarları için özgüllük yerine sözlüksel dize karşılaştırması kullanıyor; bu nedenle joker karakterle eşlenen bir izin, daha özel bir literal iz…
📅 2026-09-21NVD →
Yüksek 7.4Uzaktan Kod Çalıştırma (RCE)
CVE-2026-75939
A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating network traffic to the signature endpoint, could exploit this to craft a PGP message with a valid R
OpenShift oc-mirror aracı, PGP imza doğrulamasını imzalı gövdenin tamamı işlenmeden önce hata kontrolü yaparak gerçekleştirdiğinden, saldırganlar geçerli bir Red Hat sürüm anahtarı kimliği içeren ancak sahte imzalı bir P…
📅 2026-09-21NVD →
Yüksek 7.2Yetki Yükseltme
CVE-2025-71421
UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit their own account identifier with a role parameter set to ROLE_ADMIN to gain full administrative control over agents, tickets, and mail configuration.
UVdesk core-framework 1.1.7 öncesinde, editAgent uç noktasındaki hatalı yetki yönetimi nedeniyle ajan yönetimi yetkisine sahip bir ajan, kendi hesap kimliğini ROLE_ADMIN rolüyle göndererek kendini yöneticiye yükseltebili…
📅 2026-09-21NVD →
Yüksek 7.1Uzaktan Kod Çalıştırma (RCE)
CVE-2026-94368
A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to improper validation, the service fails to reject requests containing unsigned x-amz- headers, instead simply dropping them from the signature calculation. This allows
NooBaa Multicloud Object Gateway'in çekirdek bileşeni noobaa-core'da, S3 SigV4 ön imzalı URL'lerinin doğrulanması sırasında bir hata bulunmuştur; servis, imzalanmamış x-amz- başlıklarını reddetmek yerine imza hesabından …
📅 2026-09-21NVD →
Yüksek 8.8Yetki Yükseltme
CVE-2026-92574
A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the checkpoint instead of enforcing the destination configuration. This can allow execution with elevated privileges across
CRI-O'daki checkpoint geri yükleme özelliğindeki bir güvenlik açığı, kötü niyetli bir checkpoint imajından pod oluşturabilen bir kullanıcının hedef Kubernetes güvenlik bağlamını atlamasına olanak tanır; geri yüklenen sür…
📅 2026-09-21NVD →
Yüksek 8Yol Geçişi / Dosya Erişimi
CVE-2026-15801
A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is en
CRI-O'nun konteyner checkpoint ve restore özelliğinde, geri yükleme meta verilerinin yetersiz doğrulanması nedeniyle yeterli ayrıcalığa sahip bir kullanıcının ana makine dosya sisteminde istenmeyen işlemler yapmasına ola…
📅 2026-09-21NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94146
A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been made public and could be used. The vendor was contacted early about this disclosur
BioStar BIOS Update Utility 1.9.7.3 sürümündeki BSMEM64_W10.sys sürücüsünde, IOCTL Handler bileşenindeki sub_110BC fonksiyonunda PhysicalAddress/Size argümanlarının manipüle edilmesiyle write-what-where koşuluna yol açan…
📅 2026-09-21NVD →
Yüksek 7.3Enjeksiyon (SQL/Komut)
CVE-2026-94144
A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond i
Drogon framework'ün 1.9.13 ve öncesi sürümlerinde, ORM bileşenindeki Criteria.cc dosyasındaki makeCriteria fonksiyonunda, filter argümanının manipüle edilmesiyle uzaktan SQL enjeksiyonu gerçekleştirilebilir; exploit yayı…
📅 2026-09-21NVD →
Yüksek 7.3Enjeksiyon (SQL/Komut)
CVE-2026-94143
A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but
Drogon framework'ünün 1.9.13 ve öncesi sürümlerinde, ORM Mapper bileşenindeki Mapper.h kütüphanesinde bulunan Mapper::orderBy fonksiyonuna aktarılan "sort" parametresinin manipüle edilmesiyle uzaktan SQL enjeksiyonu gerç…
📅 2026-09-21NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94142
A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of the argument PhysicalAddress leads to write-what-where condition. The attack needs to be performed locally. The exploit has been disclosed publicly and may be use
BioStar Temperature Monitor Utility 1.2.1806.2200'deki BS_HWMIO64_W10.sys sürücüsünün IOCTL işleyicisinde, PhysicalAddress argümanının manipüle edilmesiyle yerel bir saldırganın "write-what-where" koşulunu tetikleyerek ç…
📅 2026-09-21NVD →
Yüksek 7.4Enjeksiyon (SQL/Komut)
CVE-2026-94139
A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation of the argument session_id causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be u
Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656 cihazında, /send_order.cgi?parameter=loginout dosyasındaki session_id parametresinin işlenmesi sırasında komut enjeksiyonu açığı bulunmaktadır. Uzakt…
📅 2026-09-21NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94129
A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results in write-what-where condition. The attack needs to be approached locally. The exploit is now public and may be used. The vendor was contacted early about this dis
BioStar VALKYRIE AURORA 2.10.2411.0800 sürümündeki BS_RVSIO64.sys sürücüsünde, IOCTL Handler bileşenindeki sub_1105C fonksiyonunda PhysicalAddress argümanının işlenmesiyle tetiklenen bir write-what-where zafiyeti bulunuy…
📅 2026-09-21NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94128
A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-what-where condition. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early abo
BioStar VIVID LED DJ 4.0.2411.1500 sürümündeki BS_LED64.sys sürücüsünün IOCTL işleyicisinde, sub_1105C fonksiyonunda AssociatedIrp argümanının manipüle edilmesiyle write-what-where koşuluna yol açan bir güvenlik açığı te…
📅 2026-09-21NVD →
Yüksek 7.3Enjeksiyon (SQL/Komut)
CVE-2026-94110
A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Router uses raw REQUEST_URI without URL decoding, so pay
QCMS 6.0.6 ve öncesi sürümlerde, Content Detail Page bileşenindeki Lib/Config/Controllers.php dosyasında bulunan self_Tmp fonksiyonunda, ID parametresinin manipüle edilmesiyle uzaktan SQL enjeksiyonu yapılabilmektedir; y…
📅 2026-09-21NVD →
Kritik 9.9Bellek Bozulması (Taşma/UAF)
CVE-2026-94101
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did
Netcore NBR200V2 1.3.241127.071246 sürümünde, /usr/bin/routerd dosyasındaki vlan_load_form_uci fonksiyonunda wan_num argümanının işlenmesiyle uzaktan tetiklenebilen bir buffer overflow zafiyeti tespit edilmiştir. Exploit…
📅 2026-09-21NVD →
Kritik 9.9Bellek Bozulması (Taşma/UAF)
CVE-2026-94100
A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.ports can lead to buffer overflow. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The v
Netcore NBR200V2 yönlendiricisinin /usr/bin/routerd dosyasındaki wan_config_set_vlan fonksiyonunda, vlan_wanX.ports argümanının manipüle edilmesiyle tetiklenen bir buffer overflow zafiyeti bulunmaktadır. Uzaktan sömürüle…
📅 2026-09-21NVD →
Kritik 9.9Enjeksiyon (SQL/Komut)
CVE-2026-94099
A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor was c
Netcore NBR200V2 1.3.241127.071246 sürümünde, Backup Restore bileşenindeki restore.cgi dosyasında QUERY_STRING parametresinin manipüle edilmesiyle uzaktan komut enjeksiyonu yapılabilmektedir. Exploit kamuya açıklanmış ol…
📅 2026-09-21NVD →
Kritik 9.1Enjeksiyon (SQL/Komut)
CVE-2026-94098
A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING leads to command injection. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this di
Netcore NBR200V2 yönlendiricisinin 1.3.241127.071246 sürümünde, /www/cgi-bin/upgrade dosyasındaki firmware yükseltme CGI uç noktasında QUERY_STRING parametresinin işlenmesiyle uzaktan komut enjeksiyonu yapılabilmektedir.…
📅 2026-09-21NVD →
Kritik 10Enjeksiyon (SQL/Komut)
CVE-2026-94097
A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about t
Netcore NBR200V2 1.3.241127.071246 sürümünde, /www/cgi-bin/network_tools dosyasındaki CGI tanılama uç noktasına gönderilen param/key/val argümanlarının işlenmesi sırasında komut enjeksiyonu açığı bulunmaktadır. Uzaktan s…
📅 2026-09-21NVD →
Kritik 9.9Enjeksiyon (SQL/Komut)
CVE-2026-94096
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 results in command injection. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this d
Netcore NBR200V2 yönlendiricisinin 1.3.241127.071246 sürümünde, /usr/bin/network_tools dosyasındaki LAN IP yapılandırma işleyicisinde "ipv4" argümanının düzgün doğrulanmaması, uzaktan komut enjeksiyonuna yol açmaktadır. …
📅 2026-09-21NVD →
Kritik 9.9Enjeksiyon (SQL/Komut)
CVE-2026-94095
A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argument url leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacte
Netcore NBR200V2 1.3.241127.071246 sürümünde, Traceroute tanılama özelliğindeki /usr/bin/network_tools dosyasında "url" argümanının işlenmesi sırasında uzaktan tetiklenebilen bir komut enjeksiyonu açığı bulunmaktadır. Aç…
📅 2026-09-21NVD →
Yüksek🔥 AKTİF EXPLOITEnjeksiyon (SQL/Komut)
CVE-2026-7273
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel GS1900 serisi anahtarların CGI programında, LAN üzerinden kimlik doğrulaması yapmamış bir saldırganın özel hazırlanmış bir HTTP isteğiyle yığın tabanlı tampon taşmasına yol açarak işletim sistemi komutları çalıştır…
🏷 Zyxel · GS1900 Series Switches📅 2026-09-21NVD →
Kritik 10Bellek Bozulması (Taşma/UAF)
CVE-2026-94089
A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead to stack-based buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
D-Link DIR-868L 2.01b05 yönlendiricisinde, kimlik doğrulama işleyicisindeki /webfa_authentication.cgi dosyasında strcpy fonksiyonuna yapılan id/password argümanı manipülasyonu, uzaktan sömürülebilen yığın tabanlı bir tam…
📅 2026-09-20NVD →
Yüksek 7.3Yol Geçişi / Dosya Erişimi
CVE-2026-94044
A vulnerability was identified in 03-lovepreetSingh MCP up to f95d035c5317fad81af9828286631053ccb23546. This issue affects the function create_file of the file app/api/mcp/route.ts. Such manipulation of the argument filePath/content leads to path traversal. The attack can be launched remotely. The exploit is publicly available and might be used. This product does not use versioning. This is why in
03-lovepreetSingh MCP projesinin f95d035c5317fad81af9828286631053ccb23546 sürümüne kadar olan kısımlarında, app/api/mcp/route.ts dosyasındaki create_file fonksiyonunda filePath ve content argümanlarının manipüle edilmesi…
📅 2026-09-20NVD →
Yüksek 7.3SSRF — Sunucu Taraflı İstek
CVE-2026-94039
A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of t
Vas3k TaxHacker 0.8.5 ve öncesi sürümlerde, Invoice PDF Renderer bileşenindeki /apps/invoices/actions.ts dosyasında yer alan generateInvoicePDF fonksiyonunda, businessLogo parametresinin manipüle edilmesiyle uzaktan sunu…
📅 2026-09-20NVD →
Yüksek 7.3SSRF — Sunucu Taraflı İstek
CVE-2026-94038
A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 8389032e5d52c28c4855c612
NonceGeek dim-sum-app'in Deno Backend bileşenindeki deno/main.tsx dosyasında textSearchV2Handler fonksiyonunda, supabase_url argümanının manipüle edilmesiyle uzaktan sunucu taraflı istek sahteciliği (SSRF) saldırısı yapı…
📅 2026-09-20NVD →
Yüksek 8.8Diğer / Sınıflandırılmamış
CVE-2026-94036
A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402. The impacted element is an unknown function of the file /ubus of the component routerd. The manipulation of the argument passwd_set results in improper access controls. The attack must originate from the local network. The exploit has been released to the public and may be used for attacks.
D-Link DIR-X1860 ve DIR-X1860Z yönlendiricilerde, routerd bileşeninin /ubus dosyasındaki passwd_set parametresinin işlenmesi sırasında erişim kontrolü zafiyeti bulunuyor; yerel ağdan yararlanılabilen bu açığın istismar k…
📅 2026-09-20NVD →
Yüksek 7.3Uzaktan Kod Çalıştırma (RCE)
CVE-2026-94015
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
SourceCodester Drug Recommendation System 1.0'da, /drug_recommender/Admin/edit_user.php dosyasındaki ID parametresine yapılan manipülasyonla uzaktan SQL enjeksiyonu gerçekleştirilebilir; açığın exploit kodu kamuya açıktı…
📅 2026-09-20NVD →
Yüksek 8.8Uzaktan Kod Çalıştırma (RCE)
CVE-2026-94109
openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runt
openEQUELLA'nın 2026.1.0 öncesi sürümlerinde, FreeMarker şablon derlemesindeki sandbox'sız TemplateClassResolver yapılandırması nedeniyle uzaktan kod çalıştırma açığı bulunur; kimliği doğrulanmış saldırganlar koleksiyon …
📅 2026-09-20NVD →
Yüksek 8.1Diğer / Sınıflandırılmamış
CVE-2026-94107
NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that generates recovery codes using substr(md5(mt_rand()), 0, 10). Attackers who know an administrator's email address can request a password reset and predict the token to gain administrative account access without rate limiting or expiration.
NivoCart 2.4.0 ve öncesinde, forgotten.php uç noktası parola sıfırlama kodlarını zayıf rastgelelik içeren mt_rand() fonksiyonuyla ürettiği için saldırganlar yönetici e-postasını bilerek token'ı tahmin edip yönetici hesab…
📅 2026-09-20NVD →
Yüksek 8.8Enjeksiyon (SQL/Komut)
CVE-2026-94106
getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames in command strings. Attackers can craft malicious filenames containing shell metacharacters to inject arbitrary commands executed with the privileges of the process embedding getID3.
getID3 1.9.26 öncesi sürümlerde, shell-out işleyicileri komut dizelerindeki dosya adlarını düzgün kaçışlamadığı için bir işletim sistemi komut enjeksiyonu açığı bulunur. Saldırganlar, shell meta karakterleri içeren kötü …
📅 2026-09-20NVD →

Kaynaklar: CISA Known Exploited Vulnerabilities (KEV) Catalog · NIST National Vulnerability Database (NVD). Veriler otomatik ve periyodik olarak toplanır; resmi kaynak her zaman önceliklidir.