Common Vulnerabilities and Exposures (CVE)

CVE-2026-101016

Sep 28, 2026 10:57:07 UTC

A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. This affects the function opendmarc_policy_parse_dmarc in the library libopendmarc/opendmarc_policy.c. The manipulation of the argument fo/rf/ri/pct/sp/adkim/as...

CVE-2026-101035

Sep 28, 2026 10:56:08 UTC

A flaw has been found in aligungr UERANSIM up to 3.3.0. This affects the function DecodePlainMmMessage in the library src/lib/nas/encode.cpp of the component nr-gnb. Executing a manipulation can lead to uncaught exception. The attack can be...

CVE-2026-101038

Sep 28, 2026 10:53:39 UTC

A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation of...

CVE-2026-81867

Sep 28, 2026 10:49:16 UTC

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with standard permissions to run arbitrary c...

CVE-2026-101037

Sep 28, 2026 10:00:07 UTC

A vulnerability was found in FAST FAC1200R 5.0_20201119_1.0.2. Affected is the function parse_advertisement_frame of the component devdiscover Service. The manipulation results in stack-based buffer overflow. The attack may be launched remo...

CVE-2025-40592

Sep 28, 2026 09:58:07 UTC

A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.24.24 for Windows), Mendix Studio Pro 10 (All versions < V10.24.24 for Mac), Mendix Studio Pro 11 (All versions < V11.13.0 for Windows), Mendix Studio Pro 11 (A...

CVE-2026-7171

Sep 28, 2026 09:50:18 UTC

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user_add&user_id=45&option=com_virtuemart'. ...

CVE-2026-7172

Sep 28, 2026 09:50:16 UTC

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com_virtuemart&page=admin.user_list'. Su...

CVE-2026-7170

Sep 28, 2026 09:49:41 UTC

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint  '/administrator/index.php?pshop_mode=admin&page=store.store_add&option=com_...

CVE-2026-18951

Sep 28, 2026 09:48:24 UTC

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` management permissions into the native Kubernetes `edit ClusterRole`. This allows any user with `ed...

CVE-2026-18950

Sep 28, 2026 09:48:14 UTC

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The system does not properly validate the `roleRef` field, allowing a user to specify an arbitrar...

CVE-2026-18948

Sep 28, 2026 09:48:13 UTC

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenti...

CVE-2026-11861

Sep 28, 2026 09:36:07 UTC

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authentication for FreeIPA services, including the portal, SMB server, and LDAP directory. This is ...

CVE-2026-79678

Sep 28, 2026 09:30:34 UTC

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IP...

CVE-2026-76578

Sep 28, 2026 09:30:23 UTC

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a rela...