MikeTrendsTrends right now

search

EUVD

Trends

  1. 1
    Newly published flaw hits AVEZ Electronics learning platformโ–ผ๐Ÿšจ EUVD-2026-91567 ๐Ÿ“Š Score: 6.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Learning Management System (LMS) ๐Ÿข Vendor: AVEZ Electronics ComMmastodonTechnologyCybersecurity05 h ago

    A medium-severity missing authorization vulnerability, tracked as EUVD-2026-91567 and scored 6.5 out of 10 under CVSS v3.1, has been published for the Learning Management System from Turkish vendor AVEZ Electronics Communication Training and Consultancy Trade Inc. The advisory was updated on 2 October 2026. Missing authorization flaws can let users perform actions without proper permissions, so administrators of the LMS are being urged to review the advisory and apply any available fixes.

  2. 2
    High-severity infinite loop flaw reported in Apache Thrift Python bindingsโ–ผ๐Ÿšจ EUVD-2026-91568 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity05 h ago

    A vulnerability tracked as EUVD-2026-91568 has been disclosed in Apache Thrift, the Apache Software Foundation's cross-language RPC framework. The flaw, an infinite loop with an unreachable exit condition in the Python bindings, carries a CVSS v3.1 score of 8.2. Details on affected versions remain incomplete pending an update from the vendor.

  3. 3
    High-severity vulnerability disclosed in Apache Thrift Lua bindingsโ–ผ๐Ÿšจ EUVD-2026-91569 ๐Ÿ“Š Score: 8.2/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity05 h ago

    A high-severity vulnerability, EUVD-2026-91569, has been catalogued affecting the Lua bindings of Apache Thrift, the cross-language RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.2 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling combined with inefficient algorithmic complexity, which could allow denial-of-service conditions. The advisory was updated on 2 October 2026.

  4. 4
    Critical 10/10 vulnerability disclosed in Tenda routersโ—๐Ÿšจ EUVD-2026-91570 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: HG9, HG7, HG10 ๐Ÿข Vendor: Tenda ๐Ÿ“… Updated: 2026-10-02 ๐Ÿ“ A securMmastodonTechnologyCybersecurity05 h ago

    A maximum-severity security flaw, tracked as EUVD-2026-91570 with a CVSS score of 10.0, has been disclosed in Tenda HG7, HG9 and HG10 routers running the 300001138_en_xpon firmware. The vulnerability lies in the boaGetVar function in the /boaform/formLoopBack file. The advisory was updated on 2 October 2026, and security watchers are sharing the disclosure.

  5. 5
    New vulnerability disclosed in Dynamic Web Lab Team Manager pluginโ–ผ๐Ÿšจ EUVD-2025-30618 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Team Manager ๐Ÿข Vendor: Dynamic Web Lab ๐Ÿ“… Published: 2025-09-22MmastodonTechnologyCybersecurity09 h ago

    A medium-severity vulnerability, tracked as EUVD-2025-30618, was published on 22 September 2025 affecting the Team Manager plugin for WordPress by vendor Dynamic Web Lab. The flaw, scored 5.3 out of 10 under CVSS v3.1, is a missing authorization issue that could let attackers exploit incorrectly configured access controls. An update to the entry was recorded on 2 October 2026.

  6. 6
    High-severity SQL injection flaw reported in HAVELSAN Sef chatbotโ–ผ๐Ÿšจ EUVD-2026-91329 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity09 h ago

    A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.

  7. 7
    High-severity vulnerability disclosed in Apache Thrift Lua libraryโ—๐Ÿšจ EUVD-2026-91330 ๐Ÿ“Š Score: 8.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Apache Thrift ๐Ÿข Vendor: Apache Software Foundation ๐Ÿ“… Updated: 2MmastodonTechnologyCybersecurity09 h ago

    A vulnerability tracked as EUVD-2026-91330 has been catalogued affecting the Lua component of Apache Thrift, the open-source RPC framework maintained by the Apache Software Foundation. The flaw, scored 8.7 out of 10 under CVSS v3.1, involves allocation of resources without limits or throttling and improper handling of length parameter inconsistency, which could enable denial-of-service conditions.

  8. 8
    SSRF Vulnerability Disclosed in HAVELSAN Sef AI Chatbot Platformโ—๐Ÿšจ EUVD-2026-91323 ๐Ÿ“Š Score: 4.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Sef - AI Chatbot Platform ๐Ÿข Vendor: Havelsan Inc. ๐Ÿ“… Updated: 20MmastodonTechnologyCybersecurity09 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-91323 with a CVSS v3.1 score of 4.9, has been recorded for the Sef AI Chatbot Platform developed by Turkish defence technology company HAVELSAN Inc. The flaw is a server-side request forgery (SSRF) issue, which can allow an attacker to make the server send arbitrary requests. The advisory was updated on 2 October 2026; affected versions have not been fully detailed in the published record.

  9. 9
    Avada WordPress theme hit by reflected XSS vulnerabilityโ—๐Ÿšจ EUVD-2026-91174 ๐Ÿ“Š Score: 6.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Avada | Website Builder For WordPress & WooCommerce ๐Ÿข Vendor: TMmastodonTechnologyCybersecurity013 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-91174 with a CVSS score of 6.1, has been reported in Avada, the popular website builder theme for WordPress and WooCommerce from vendor ThemeFusion. The flaw is a reflected cross-site scripting issue, updated on 2026-10-02, allowing attackers to inject malicious scripts via crafted links. WordPress site owners using Avada are advised to update promptly.

  10. 10
    High-severity unquoted service path flaw reported in Remote Mouseโ—๐Ÿšจ EUVD-2026-3018 ๐Ÿ“Š Score: 8.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Remote Mouse ๐Ÿข Vendor: Remotemouse ๐Ÿ“… Published: 2026-01-15 | UpdMmastodonTechnologyCybersecurity023 h ago

    A vulnerability tracked as EUVD-2026-3018 has been published for Remote Mouse, the remote-control app by vendor Remotemouse. Version 4.002 contains an unquoted service path vulnerability, rated 8.5 out of 10 on the CVSS v3.1 scale, which can let a local attacker execute arbitrary code with elevated privileges. The entry was published on 15 January 2026 and updated on 1 October 2026. Users are advised to watch for a patched release from the vendor.

  11. 11
    Ultimate POS software flagged for stored cross-site scripting flawโ—๐Ÿšจ EUVD-2026-57170 ๐Ÿ“Š Score: 4.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: Ultimate POS (Stock Management & Point of Sale) ๐Ÿข Vendor: UltimMmastodonTechnologyCybersecurity020 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-57170, has been published for Ultimate POS, a stock management and point of sale application from vendor Ultimate Fosters. The flaw is a stored cross-site scripting issue, scored 4.8 out of 10 under CVSS v3.1. It was first published on 12 August 2026 and updated on 1 October 2026. Users of the software are advised to check for patches.

  12. 12
    encoded_id-rails vulnerability allows remote denial of service attacksโ—๐Ÿšจ EUVD-2023-2632 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“… Published: 2024-01-04 | Updated: 2026-10-01 ๐Ÿ“ encoded_id-rails versions bMmastodonTechnologyCybersecurity023 h ago

    A security advisory tracked as EUVD-2023-2632 warns that encoded_id-rails versions before 1.0.0.beta2 contain an uncontrolled resource consumption flaw. A remote, unauthenticated attacker could exploit it to trigger a denial of service. The vulnerability carries a CVSS v3.1 score of 7.5 and was published on 4 January 2024, with the advisory most recently updated on 1 October 2026.

  13. 13
    pfSense vulnerability allows privilege injection, patch releasedโ—๐Ÿšจ EUVD-2026-70495 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: pfSense Plus, pfSense CE ๐Ÿข Vendor: Netgate ๐Ÿ“… Published: 2026-09MmastodonTechnologyCybersecurity023 h ago

    A medium-severity vulnerability, tracked as EUVD-2026-70495 with a CVSS score of 5.1, affects Netgate's pfSense Plus before version 26.07 and pfSense CE before 2.9.0. The flaw lets authenticated users holding the Status: Monitoring privilege inject arbitrary content, potentially leading to further abuse. Netgate published the advisory on 3 September 2026 and updated it on 1 October; administrators are advised to upgrade.

  14. 14
    pfSense vulnerability EUVD-2026-70496 allows privilege injectionโ—๐Ÿšจ EUVD-2026-70496 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: pfSense Plus, pfSense CE ๐Ÿข Vendor: Netgate ๐Ÿ“… Published: 2026-09MmastodonTechnologyCybersecurity023 h ago

    A medium-severity vulnerability, EUVD-2026-70496, has been published for Netgate's pfSense firewall software. Versions of pfSense Plus before 26.07 and pfSense CE before 2.9.0 allow authenticated users holding the Firewall: Rules: Edit privilege to inject data, according to the advisory rated 5.1 out of 10 under CVSS v3.1. The issue was published on 3 September 2026 and updated on 1 October. Administrators running affected versions are advised to update.

  15. 15
    Medium-severity vulnerability disclosed in pfSense firewall softwareโ—๐Ÿšจ EUVD-2026-70498 ๐Ÿ“Š Score: 5.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: pfSense CE, pfSense Plus ๐Ÿข Vendor: Netgate ๐Ÿ“… Published: 2026-09MmastodonTechnologyCybersecurity023 h ago

    A vulnerability tracked as EUVD-2026-70498 affects Netgate's pfSense Plus before 26.07 and pfSense CE before 2.9.0, carrying a CVSS v3.1 score of 5.1 out of 10. It allows authenticated users holding the Firewall: Schedules: Edit privilege to inject malicious content. Netgate published the advisory on 3 September 2026 and updated it on 1 October, and administrators of pfSense firewalls are being urged to update their installations.