Stack Buffer Overflow in UTT HiPER 1200GW PPTP
CVE-2026-19341: A remotely exploitable stack-based buffer overflow in UTT HiPER 1200GW firmware via the EncryptionMode parameter, rated CVSS 8.8 High.
Free 30-min security demo — We'll scan your real code and show live findings, no commitment Book Now
In-depth technical analysis of recently disclosed vulnerabilities in open-source software. Every post includes the vulnerable code, the fix, real-world impact, and how SAST catches it.
CVE-2026-19341: A remotely exploitable stack-based buffer overflow in UTT HiPER 1200GW firmware via the EncryptionMode parameter, rated CVSS 8.8 High.
CVE-2026-67620: Flowise ≤3.1.4 SSRF flaw lets attackers bypass metadata endpoint deny-lists to steal OCI and Alibaba Cloud credentials.
CVE-2026-19211 exposes a critical SQL injection flaw in SourceCodester Photo Share Website 1.0's signup endpoint, enabling remote data exfiltration.
CVE-2026-19231 exposes a critical SQL injection flaw in SourceCodester Simple Doctors Appointment System 1.0, enabling remote database compromise via an unsanitized ID parameter.
CVE-2026-43629: A heap buffer overflow in llama.cpp's KV cache restore path enables heap corruption and potential code execution via malicious state files.
CVE-2026-53983: Unauthenticated blind SSRF in Ground Station <0.6.0 lets attackers reach internal services and cloud metadata endpoints with no credentials required.
CVE-2026-58080: Eclipse Milo's OpcUaServerConfig.copy() silently drops the RoleMapper, bypassing role-permission checks for anonymous OPC UA clients.
CVE-2026-70617: Missing authorization in Spacebar Server allows any authenticated user to join arbitrary group DMs, read history, and post messages.
CVE-2026-18895 is a remotely exploitable stack-based buffer overflow in UTT HiPER 1250GW routers that can lead to full device compromise.
CVE-2026-70619: Missing admin authorization in Odysseus lets any authenticated user hijack the embedding backend, exfiltrating all AI-processed data.
CVE-2026-18641 is a remotely exploitable OS command injection in Sangfor OMS up to 3.0.13, enabling full system compromise via the login endpoint.
CVE-2026-67598: Emlog Pro disables TLS certificate verification in ai.php, enabling MitM attackers to steal LLM API keys and inject malicious AI responses.
CVE-2026-67336: better-auth before 1.6.11 allows unsigned JWT tokens and plain PKCE in OIDC and MCP plugins, enabling token forgery and auth code interception.
CVE-2026-67356 is a critical privilege escalation in ArcadeDB where JavaScript triggers execute with unrestricted host access, enabling admin user creation.
CVE-2026-67325: GitPython's incomplete blocklist allows attackers to bypass unsafe-option guards via abbreviated git long-options, enabling arbitrary command execution.
CVE-2026-67343 exposes ArcadeDB's cluster token in plaintext via the server API, enabling privilege escalation to root and full administrative takeover.
CVE-2026-66416: Leantime 3.6.2 omits Laravel's VerifyCsrfToken middleware globally, enabling unauthenticated attackers to forge state-changing requests as any authenticated user.
CVE-2026-67351 is a high-severity authentication context confusion flaw in Serendipity CMS allowing privilege escalation from Editor to Administrator.
CVE-2026-67595: Obfuscated JavaScript embedded in VaahCMS OTP email templates enables keylogging, C2 communication, and DOM scraping in affected browsers.
CVE-2026-18107: A CRIU rseq race lets a container process hijack parasite injection to spoof credentials, gaining elevated capabilities on restore.
CVE-2026-57510 exposes a broken object-level authorization flaw in SuperPlane's gRPC handlers, enabling cross-tenant data access and workflow disruption.
CVE-2026-17523 is a Linux kernel flaw allowing unprivileged local users to execute arbitrary kernel code and gain root privileges — CVSS 7.8 HIGH.
CVE-2026-63720: datamodel-code-generator before 0.70.0 allows RCE via unsanitized customBasePath values injected into generated Python import statements.
CVE-2025-71408 is a high-severity eval injection in NLTK's collocations module allowing arbitrary Python code execution via CLI arguments.
CVE-2026-66033: A pre-authentication integer underflow in libssh2's AES-GCM cipher path lets a rogue SSH server crash any connecting client.
CVE-2026-65702: A path traversal flaw in Vanna's FileSystemConversationStore lets unauthenticated attackers write and read arbitrary files on the server.
CVE-2026-65917: CyberPanel's incremental-backup handlers let authenticated users hijack or delete any tenant's backups via sequential IDs.
CVE-2024-58353 exposes Cal.com ≤4.7.15 to stored XSS through unsanitized booking question labels rendered via dangerouslySetInnerHTML in public booking views.
CVE-2024-58355 is a stored XSS in Cal.com through 4.7.15 letting attackers inject JavaScript via booking-question labels.
CVE-2026-64624: FreeRDP's RDP file parser exposes the full CLI surface to untrusted input, enabling RCE, cert bypass, and filesystem exfiltration.
CVE-2026-65056: SSRF in mcp-webresearch 0.1.7 lets attackers access cloud metadata and internal services via prompt injection into the visit_page tool.
CVE-2026-63090 is a heap-based buffer overflow in ProFTPD's mod_sftp module enabling authenticated RCE — a critical risk for internet-facing FTP servers.
CVE-2026-63735: SurrealDB before 3.2.0 fails to validate namespace/database scope in custom API routes, enabling cross-tenant data access.
CVE-2024-58366 exposes a format string vulnerability in SurrealDB's rquickjs bindings, enabling memory reads or RCE for authenticated scripting users.
CVE-2026-11826 is a heap-based buffer overflow in OpenPLC v3's getData() enabling heap corruption and denial of service.
CVE-2023-54366: SurrealDB defaulted table permissions to FULL instead of NONE, exposing all tables to unrestricted read/write.
CVE-2024-58362 is a critical deserialization flaw in SurrealDB's RPC API allowing unauthenticated attackers to inject and execute arbitrary subqueries.
CVE-2026-62231: Grav API plugin ignores key scopes, letting a read-only API key perform full administrative operations. CVSS 8.1 HIGH.
CVE-2026-62234: Grav CMS webhook dispatch allows file://, dict://, and gopher:// protocols, enabling authenticated SSRF and local file read.
CVE-2026-62202 is a high-severity privilege escalation in OpenClaw's isolated cron jobs, allowing lower-trust callers to bypass denied execution controls.
CVE-2026-63085 is an authorization bypass in Axelor Open Platform 8.x letting authenticated users escalate to admin via nested saves.
CVE-2026-46640: A code injection flaw in Twig 3.15–3.25 allows attackers to inject raw PHP via dynamic macro attribute syntax, enabling RCE.
CVE-2026-57996: A missing authorization guard in phpMyFAQ's user/add API lets delegated admins create SuperAdmin accounts, enabling full instance takeover.
CVE-2026-15691: Stack-based buffer overflow in Tenda BE12 Pro 16.03.66.23 via fromSafeClientFilter allows unauthenticated RCE over the network.
CVE-2026-15694 exposes a remotely exploitable stack-based buffer overflow in Tenda BE12 Pro firmware, enabling unauthenticated RCE on affected routers.
CVE-2026-49970 is a path traversal flaw in Laravel-Mediable's sanitizePath() that lets attackers write files to arbitrary server locations, enabling RCE.
CVE-2026-61876: Stored XSS in OpenWrt LuCI via unsanitized DHCPv6 FQDN hostnames lets adjacent attackers hijack admin sessions.
CVE-2026-15483: A remotely exploitable stack buffer overflow in TRENDnet TEW-821DAP 1.12B01 allows attackers to achieve RCE via a crafted nslookup request.
CVE-2026-15484 is a remote stack buffer overflow in TRENDnet TEW-821DAP 1.12B01 firmware that allows unauthenticated RCE via the tools_nslookup endpoint.
CVE-2026-15480 is a remotely exploitable stack-based buffer overflow in TRENDnet TEW-635BRM routers, enabling unauthenticated RCE on EOL devices.
CVE-2026-15481 is a critical command injection flaw in TRENDnet TEW-635BRM firmware allowing unauthenticated RCE via the ipoa_ipaddr argument.
CVE-2025-30007: Authenticated OS command injection in HestiaCP's DNS record handling lets low-privilege users execute arbitrary commands as root.
CVE-2026-54329: A mass assignment flaw in Snipe-IT's Accessories API lets low-privileged users write records across company boundaries, scoring CVSS 8.5.
CVE-2026-58459: gpsd's gpsprof tool allows attackers who control GPS device subtype values to execute arbitrary shell commands via unsanitized gnuplot titles.
CVE-2026-59937: pypdf before 6.14.0 allows denial of service via crafted PDFs with malformed cross-reference streams causing unbounded recovery loops.
CVE-2026-59257 is a SQL injection flaw in n8n's legacy MySQL v1 node that allows attackers to execute arbitrary SQL via expression interpolation.
CVE-2026-60104: Bitwarden Server authorization bypass lets a low-privileged org member steal another user's vault key and take over their account.
CVE-2026-54765 is a filter-merging flaw in Traefik's Kubernetes Gateway API provider allowing cross-tenant header injection via shared backends.
CVE-2026-60102 allows authenticated attackers to execute arbitrary OS commands through malicious filenames in Horde VFS before 3.0.1.
CVE-2024-6387 (regreSSHion) is a signal handler race in OpenSSH sshd allowing unauthenticated root RCE on glibc Linux. Detection and patch guidance.
CVE-2024-21626 (Leaky Vessels) is a runc container escape via a leaked /proc/self/cwd file descriptor, letting attackers access the host filesystem.
CVE-2023-50585 is a stack overflow in Tenda A18 v15.13.07.09 formSetDeviceName, allowing unauthenticated remote code execution via the devName parameter.
CVE-2023-50643 lets attackers execute arbitrary code in Evernote for macOS 10.68.2 via an unsafe Electron RunAsNode configuration. CVSS 9.8 critical.
CVE-2023-49235 is an OS command injection in TRENDnet TV-IP1314PI cameras via unsafe popen() and weak debug filtering, enabling unauthenticated RCE.
CVE-2023-51126 is a command injection in FLIR AX8 thermal cameras up to firmware 1.46.16, enabling RCE via unsanitized input to the res.php endpoint.
CVE-2023-7220 is a critical stack buffer overflow in the Totolink NR1800X loginAuth function, enabling remote code execution without authentication.
CVE-2023-7221 is a critical buffer overflow in the Totolink T6 HTTP POST login handler, enabling unauthenticated remote code execution. CVSS 9.8.
CVE-2023-31446 is a command injection flaw in Cassia Gateway firmware; the unsanitized queueUrl parameter gives unauthenticated attackers root RCE.
CVE-2024-21646 is an integer overflow in the Azure uAMQP C library when parsing crafted binary type data, enabling RCE in dependent AMQP clients.
CVE-2023-49237 is an OS command injection in the TRENDnet TV-IP1314PI language pack handler; unfiltered URL parameters allow unauthenticated RCE.
CVE-2024-21650 is a critical RCE in XWiki Platform user registration; unsanitized first and last name fields let attackers execute arbitrary code.
CVE-2023-49236 exploits unvalidated sscanf input in TRENDnet TV-IP1314PI, enabling remote code execution through malicious RTSP scale parameters.
CVE-2024-0321 is a critical stack-based buffer overflow in GPAC prior to v2.3-DEV enabling remote code execution through malformed media files.
CVE-2024-22087 is a stack buffer overflow in Pico HTTP Server URI handling, allowing unauthenticated remote code execution via oversized request paths.
CVE-2024-22051 is an integer overflow in CommonMarker's GFM table parser causing heap corruption and potential RCE via oversized marker rows.
CVE-2023-51277 is a macOS entitlement flaw in Jupyter Notebook Viewer before 0.1.6 allowing unauthorized task access and privilege escalation.
CVE-2024-22086 is a stack buffer overflow in Cherry HTTP server URI parsing, enabling unauthenticated remote code execution via malformed requests.
CVE-2024-22088 is a use-after-free in Lotos WebServer buffer management; long URIs trigger mishandled realloc calls, enabling remote code execution.
CVE-2023-50921 is a pre-auth privilege escalation in GL.iNet routers via the add_user API endpoint, affecting 12 models on firmware 4.3.7 through 4.5.0.
CVE-2023-46308 is a prototype pollution flaw in Plotly.js before 2.25.2; plot API calls can manipulate __proto__ to enable arbitrary code execution.
CVE-2024-21623 exposes critical expression injection vulnerability in OTClient's SonarCloud workflow, enabling remote command execution and secret exfiltration.
No vulnerabilities match your filter.
Offensive360 SAST detects the vulnerability patterns documented here — plus thousands more — across 60+ programming languages. See what's hiding in your source code.