search
EUVD
Trends
- 1Cross-site scripting flaw found in Greek Open eClass platformโผ๐จ EUVD-2024-55777 ๐ Score: 5.4/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ Cross Site Scripting vulne
A cross-site scripting vulnerability, tracked as EUVD-2024-55777, has been disclosed in the Greek Universities Network (GUnet) Open eClass Platform version 3.15. The flaw, rated 5.4 out of 10 on the CVSS v3.1 scale, could let a remote attacker execute arbitrary code through user name fields. The advisory was published on 29 September and updated the following day.
- 2TOTOLINK N150RT router firmware hit by buffer overflow flawโผ๐จ EUVD-2026-89331 ๐ Score: n/a ๐ Updated: 2026-09-29 ๐ A stack-based buffer overflow vulnerability exists in the web man
A new vulnerability entry, EUVD-2026-89331, documents a stack-based buffer overflow in the web management interface of TOTOLINK N150RT (NTR150) routers running firmware V3.4.0-B20201030. The flaw is reachable through the /boafrm/formFilter route, which handles access-control and URL filter functions. No severity score has been assigned yet. Security teams are being urged to check whether their devices run the affected firmware.
- 3Kilo Code vulnerability lets local attackers run codeโผ๐จ EUVD-2026-89423 ๐ Score: 8.4/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ An issue in Kilo Code befo
A high-severity flaw tracked as EUVD-2026-89423 affects Kilo Code versions before v7.4.1, scoring 8.4 out of 10 under CVSS v3.1. The issue, published on 29 September 2026 and updated a day later, allows a local attacker to execute arbitrary code through the permission or allow-everything endpoint. Users are urged to update to v7.4.1 or later.
- 4Medium-Severity Flaw Reported in FluentForm WordPress Pluginโผ๐จ EUVD-2026-90761 ๐ Score: 5.3/10 (CVSS v3.1) ๐ฆ Product: FluentForm ๐ข Vendor: WP ManageNinja LLC ๐ Updated: 2026-10-01 ๐
A vulnerability tracked as EUVD-2026-90761 has been published affecting FluentForm, the WordPress form plugin by WP ManageNinja LLC. The issue is classified as an Incorrect Behavior Order flaw with a CVSS v3.1 score of 5.3 out of 10, and can reportedly allow removal of important client functionality. Details were updated on 1 October 2026. Administrators running FluentForm are likely to check whether their installed version is affected and apply any available patch.
- 5High-severity XML flaw flagged in Apache Camel Quarkusโผ๐จ EUVD-2026-90762 ๐ Score: 8.6/10 (CVSS v3.1) ๐ฆ Product: Apache Camel Quarkus, Apache Camel Quarkus ๐ข Vendor: Apache Sof
A vulnerability tracked as EUVD-2026-90762 has been recorded for Apache Camel Quarkus, the Apache Software Foundation's Quarkus extensions for Camel. The flaw, rated 8.6 out of 10 under CVSS v3.1, involves improper restriction of XML external entity references in the XSLT support extension (camel-quarkus-support-xalan). Such issues can allow attackers to read files or make requests from affected systems. The record was updated on 1 October 2026, and security teams are being urged to check whether their deployments use the affected extension.
- 6ArgusMonitor Driver Vulnerability Flagged With Medium Severityโผ๐จ EUVD-2026-89424 ๐ Score: 5.3/10 (CVSS v3.1) ๐ Published: 2026-09-29 | Updated: 2026-09-30 ๐ Improper Access Control in
A newly tracked vulnerability, EUVD-2026-89424, describes improper access control in the ArgusMonitor.sys driver used by Argotronic eGbR's hardware monitoring tool ArgusMonitor, affecting version 7.4.02 and earlier. With a CVSS v3.1 score of 5.3, the flaw reportedly allows local, low-privileged users to bypass device handle access restrictions. Published on 29 September and updated the next day, it is drawing attention from security watchers tracking Windows driver weaknesses.
- 7New security vulnerability disclosed in Red Hat Enterprise Linux productsโผ๐จ EUVD-2023-24169 ๐ Score: 7.0/10 (CVSS v3.1) ๐ฆ Product: Red Hat Enterprise Linux 8.6 Extended Update Support, Red Hat V
A vulnerability tracked as EUVD-2023-24169 has been published affecting several Red Hat products, including Red Hat Enterprise Linux 8.6 and 8.8 Extended Update Support and Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. The flaw carries a CVSS v3.1 severity score of 7.0 out of 10, placing it in the high-severity range. Administrators running the affected versions are being advised to review the advisory and apply patches.
- 8Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโผ๐จ EUVD-2026-70998 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.
- 9High-severity vulnerability disclosed in Capgo update serviceโผ๐จ EUVD-2026-87707 ๐ Score: 8.6/10 (CVSS v3.1) ๐ฆ Product: capgo.app ๐ข Vendor: Cap-go ๐ Published: 2026-09-26 | Updated: 2
A security advisory published as EUVD-2026-87707 describes a vulnerability in Capgo, the over-the-air update service for Capacitor apps, rated 8.6 out of 10 on the CVSS scale. Versions up to 12.261.0 reportedly contain an incomplete access-control fix for the public.sso_providers table, meaning earlier mitigation efforts did not fully close the flaw. The advisory was published on 26 September 2026 and updated on 30 September, prompting developers who rely on Capgo to check whether they need to update.
- 10Fastify vulnerability EUVD-2026-70989 scores 7.5โผ๐จ EUVD-2026-70989 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.
- 11CPython vulnerability EUVD-2026-89183 disclosed with moderate severityโผ๐จ EUVD-2026-89183 ๐ Score: 5.9/10 (CVSS v3.1) ๐ฆ Product: CPython ๐ข Vendor: Python Software Foundation ๐ Updated: 2026-09
A vulnerability tracked as EUVD-2026-89183 has been disclosed in CPython, the reference implementation of the Python language maintained by the Python Software Foundation. The flaw concerns cleanup of tempfile.TemporaryDirectory, where a race condition could let an attacker who can modify the directory tree during cleanup swap in a directory in place of the intended one. It is rated 5.9 out of 10 on the CVSS v3.1 scale, a moderate severity score.
- 12Fastify vulnerability allows authentication bypass via malformed URLsโผ๐จ EUVD-2026-70988 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A newly catalogued vulnerability, EUVD-2026-70988, affects the Fastify web framework, rated 7.5 out of 10 on the CVSS v3.1 scale. The flaw allows authentication bypass when malformed URLs reach encapsulated not-found handlers, meaning requests intended to be blocked could slip through route protections. Fastify is a widely used Node.js framework, so developers running exposed services are being urged to review the advisory and update to a patched version.
- 13Kiteworks Email Protection Gateway vulnerability logged with moderate severityโผ๐จ EUVD-2026-90275 ๐ Score: 6.5/10 (CVSS v3.1) ๐ฆ Product: Email Protection Gateway ๐ข Vendor: Kiteworks ๐ Updated: 2026-09
A new vulnerability, EUVD-2026-90275, has been recorded for Kiteworks' Email Protection Gateway, with a CVSS v3.1 score of 6.5 out of 10. The flaw concerns an authorization check in the large file exchange feature that failed to correctly verify whether the requesting user was entitled to access the resource. The entry was updated on 30 September 2026. Security teams monitoring Kiteworks deployments are expected to review the advisory and patch guidance.
- 14Kiteworks Core deserialization flaw logged as high-severity vulnerabilityโผ๐จ EUVD-2026-90276 ๐ Score: 8.1/10 (CVSS v3.1) ๐ฆ Product: core ๐ข Vendor: Kiteworks ๐ Updated: 2026-09-30 ๐ Kiteworks Core
Kiteworks Core versions before 9.5.0 are affected by a deserialization of untrusted data vulnerability, tracked as EUVD-2026-90276 with a CVSS v3.1 score of 8.1. Under certain conditions, the flaw could allow attackers to send crafted data that is deserialized unsafely, potentially leading to code execution. The advisory was updated on September 30, 2026, and users are advised to upgrade to version 9.5.0 or later.
- 15Apache APISIX vulnerability logs unmasked sensitive header valuesโ๐จ EUVD-2026-90763 ๐ Score: 5.7/10 (CVSS v3.1) ๐ฆ Product: Apache APISIX ๐ข Vendor: Apache Software Foundation ๐ Updated: 2
A medium-severity vulnerability, EUVD-2026-90763, has been catalogued in Apache APISIX, the open-source API gateway maintained by the Apache Software Foundation. Rated 5.7 out of 10 under CVSS v3.1, the flaw involves the insertion of sensitive information into log files, with unmasked header values potentially being written in cleartext.
- 16Google Chrome patches critical memory flawโผ๐จ EUVD-2026-89143 ๐ Score: 9.6/10 (CVSS v3.1) ๐ฆ Product: Chrome ๐ข Vendor: Google ๐ Published: 2026-09-29 | Updated: 2026
A critical vulnerability, EUVD-2026-89143, has been disclosed in Google Chrome with a CVSS score of 9.6. The flaw involves non-heap memory handling in the browser's Fonts component and could allow a remote attacker, working alongside social engineering, to potentially compromise systems. The fix is included in Chrome 154.0.8037.57, published 29 September 2026 and updated the following day. Security watchers are flagging the severity rating and urging users to update their browsers promptly.
- 17Two TLS handshake flaws disclosed in Eclipse NetX Duoโผ๐จ EUVD-2026-89195 ๐ Score: n/a ๐ฆ Product: NetX Duo ๐ข Vendor: Eclipse Foundation ๐ Updated: 2026-09-29 ๐ Two client-side
A new vulnerability entry, EUVD-2026-89195, was updated on 29 September 2026 affecting Eclipse Foundation's NetX Duo. Two client-side TLS/DTLS handshake parsers in NetX Secure read fields from a server-supplied message before checking that the message is long enough to contain them, a classic parsing flaw that could expose embedded devices to attacks. No severity score has been assigned yet.
- 18BurgerEditor vulnerability EUVD-2026-75231 disclosedโ๐จ EUVD-2026-75231 ๐ Score: 5.3/10 (CVSS v3.1) ๐ฆ Product: BurgerEditor ๐ข Vendor: D-ZERO CO.,LTD. ๐ Published: 2026-09-10
A medium-severity vulnerability, EUVD-2026-75231, has been published affecting BurgerEditor versions 3.0.0 through 3.4.0, a product from Japanese vendor D-ZERO CO.,LTD. The flaw is an authorization bypass through user-controlled keys, rated 5.3 out of 10 under CVSS v3.1. It was published on 10 September 2026 and updated on 1 October 2026. Users of affected versions are advised to check for vendor patches or mitigations.
- 19High-severity file upload flaw disclosed in BurgerEditorโ๐จ EUVD-2026-75229 ๐ Score: 8.5/10 (CVSS v3.1) ๐ฆ Product: BurgerEditor, BurgerEditor ๐ข Vendor: D-ZERO CO.,LTD. ๐ Publishe
A vulnerability tracked as EUVD-2026-75229 has been published for BurgerEditor, a product by Japanese vendor D-ZERO Co., Ltd. Versions 3.2.0 through 3.4.0 contain an unrestricted file upload flaw that allows files with dangerous types to be uploaded, a weakness that can enable remote code execution on affected servers. The issue carries a CVSS v3.1 score of 8.5, classified as high severity. It was published on 10 September 2026 and updated on 1 October 2026. Administrators running affected versions are advised to update promptly.
- 20Microsoft patches high-severity Visual Studio heap overflow flawโผ๐จ EUVD-2026-73170 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: .NET 10.0, Microsoft Visual Studio 2022 version 17.14, Microsof
Microsoft's Visual Studio 2022 version 17.14, .NET 10.0 and .NET Framework 4.8 are affected by a vulnerability tracked as EUVD-2026-73170, rated 8.8 out of 10 on the CVSS v3.1 scale. The flaw is a heap-based buffer overflow in Visual Studio, and the advisory was published on 8 September 2026 with an update issued on 29 September 2026. Security trackers are flagging the high severity rating, urging developers using affected Microsoft products to check whether they need to update.
- 21High-severity JetBrains YouTrack flaw enables account takeoverโ๐จ EUVD-2026-90021 ๐ Score: 8.9/10 (CVSS v3.1) ๐ฆ Product: YouTrack ๐ข Vendor: JetBrains ๐ Published: 2026-09-30 | Updated:
A newly published vulnerability, EUVD-2026-90021, affects JetBrains YouTrack before version 2026.2.19197 and carries a CVSS score of 8.9. Attackers could take over accounts by replaying a notification signature. JetBrains has issued a fix, and security teams are urged to update their YouTrack instances promptly to close the hole.
- 22IBM patches high-severity code execution flaw in DataStageโผ๐จ EUVD-2026-89197 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: DataStage on Cloud Pak for Data ๐ข Vendor: IBM ๐ Updated: 2026-0
A new vulnerability, tracked as EUVD-2026-89197, has been disclosed in IBM DataStage on Cloud Pak for Data 5.4.0.0. Rated 8.8 out of 10 on the CVSS v3.1 scale, the flaw could let a remote authenticated attacker execute arbitrary code because of improper path validation. Security teams monitoring IBM products are flagging the advisory as organisations assess whether their deployments are affected and await a fix.
- 23Medium-severity vulnerability found in Naichen ThinkCMFโผ๐จ EUVD-2026-89477 ๐ Score: 5.1/10 (CVSS v3.1) ๐ฆ Product: ThinkCMF, ThinkCMF, ThinkCMF (+5 more) ๐ข Vendor: Naichen ๐ Upda
A security vulnerability, tracked as EUVD-2026-89477, has been identified in Naichen's ThinkCMF content management framework in versions up to 8.0.7. The flaw carries a CVSS v3.1 score of 5.1 out of 10, marking it as moderate severity. The advisory was updated on 29 September 2026, and multiple ThinkCMF product entries are listed as affected. Details of the vulnerable function remain limited in the published notice.
- 24High-severity command injection flaw fixed in Renovateโผ๐จ EUVD-2024-55728 ๐ Score: 8.4/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A high-severity vulnerability, EUVD-2024-55728, was published for Renovate, the popular open-source dependency update tool maintained by renovatebot. Versions 37.158.0 before 37.199.0 contain a command injection flaw in the helmv3 manager's registryAliases handling, rated 8.4 out of 10 on the CVSS v3.1 scale. Users are being urged to update to a patched release, as the bug could allow attackers to execute arbitrary commands through manipulated registry alias values.
- 25High-severity vulnerability disclosed in MobilityDBโผ๐จ EUVD-2026-89198 ๐ Score: 7.1/10 (CVSS v3.1) ๐ฆ Product: MobilityDB, MobilityDB, MobilityDB ๐ข Vendor: MobilityDB ๐ Updat
A security advisory, EUVD-2026-89198, flags an out-of-bounds read vulnerability in MobilityDB version 1.3.0 and earlier, located in the MEOS binary and library WKB deserialization logic. The flaw carries a CVSS v3.1 score of 7.1, marking it as high severity. The advisory was updated on 2026-09-29, and users of the open-source moving-object database extension are being urged to check for patched releases.
- 26Medium-severity FTP flaw disclosed in Eclipse NetX Duoโผ๐จ EUVD-2026-89199 ๐ Score: 6.0/10 (CVSS v3.1) ๐ฆ Product: NetX Duo ๐ข Vendor: Eclipse Foundation ๐ Updated: 2026-09-29 ๐ F
A medium-severity vulnerability, EUVD-2026-89199, has been catalogued in Eclipse Foundation's NetX Duo embedded network stack. Rated 6.0 out of 10 under CVSS v3.1, the flaw lies in the FTP component, where passive data connections are not bound to the authenticated control peer, potentially allowing session mixing. The entry was updated on 29 September 2026 via the EU vulnerability database maintained by ENISA.
- 27FluentCart WordPress plugin patched over guest checkout flawโ๐จ EUVD-2026-89640 ๐ Score: n/a ๐ฆ Product: FluentCart A New Era of eCommerce ๐ข Vendor: Unknown ๐ Updated: 2026-09-30 ๐ Th
A vulnerability tracked as EUVD-2026-89640 affects the FluentCart eCommerce plugin for WordPress in versions before 1.6.5. The flaw allows a guest checkout to proceed without verifying that the buyer actually controls the email address entered, which could enable orders or account activity tied to addresses the buyer does not own. Users are advised to update to version 1.6.5 or later. No severity score has been assigned yet and the vendor is unlisted in the advisory.
- 28Zella Theme WordPress vulnerability allows unauthenticated font uploadโ๐จ EUVD-2026-89637 ๐ Score: n/a ๐ฆ Product: Zella Theme ๐ข Vendor: Unknown ๐ Updated: 2026-09-30 ๐ The Zella Theme WordPres
A newly logged vulnerability, EUVD-2026-89637, affects the Zella Theme for WordPress in versions before 2.6.3. The theme fails to perform capability or nonce checks on one of its font upload actions, which is available to unauthenticated users, potentially allowing attackers to upload files without an account. Site administrators running the theme are advised to update to version 2.6.3 or later.
- 29WordPress User Frontend Plugin Vulnerability Allows Unauthorized Account Creationโ๐จ EUVD-2026-89638 ๐ Score: n/a ๐ฆ Product: User Frontend ๐ข Vendor: Unknown ๐ Updated: 2026-09-30 ๐ The User Frontend Word
A newly catalogued vulnerability, EUVD-2026-89638, affects the User Frontend WordPress plugin in versions before 4.3.12. The flaw lets unauthenticated users create accounts without checking whether the site permits user registration. Site owners running the plugin are advised to update, though details such as an official severity score and vendor confirmation are not yet available.
- 30WordPress User Frontend plugin vulnerability allows role tamperingโ๐จ EUVD-2026-89639 ๐ Score: n/a ๐ฆ Product: User Frontend ๐ข Vendor: Unknown ๐ Updated: 2026-09-30 ๐ The User Frontend Word
A new vulnerability entry, EUVD-2026-89639, was published concerning the User Frontend WordPress plugin. Versions before 4.3.12 fail to prevent tampering with the role assigned by its registration form, potentially letting unauthenticated users register with elevated privileges. Administrators running the plugin are advised to update to 4.3.12 or later. No severity score has been assigned yet.
- 31Renovate tool patched over remote code execution flawโ๐จ EUVD-2026-62467 ๐ Score: 6.8/10 (CVSS v3.1) ๐ฆ Product: renovate ๐ข Vendor: renovatebot ๐ Published: 2026-08-19 | Update
A medium-severity vulnerability, tracked as EUVD-2026-62467 with a CVSS score of 6.8, was disclosed in Renovate, the dependency update tool maintained by renovatebot. Versions from 43.65.0 before 43.102.11 contain a remote code execution flaw affecting the bazel-module and bazelisk managers. The advisory was published on 19 August 2026 and updated on 29 September, and administrators are urged to upgrade to a fixed release.