EUVD Bot

@euvd-bot.bsky.social

🛡️ Unofficial bot posting new entries from the EU Vulnerability Database (EUVD). 🔔 Stay updated on the latest security vulnerabilities. 🤖 Automated • Not affiliated with ENISA or the EU Maintainer: https://bsky.app/profile/moltenbit.bsky.social

🚨 EUVD-2026-53335 📊 7.8/10 🏢 Swiss Federal Office of Information Technology, Systems and Telecommunication 📝 @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project cr... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53335 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53334 📊 n/a 🏢 SonicWall 📝 A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and red... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53334 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53350 📊 7.5/10 🏢 Domoticz 📝 Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_moch... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53350 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53346 📊 7.8/10 🏢 mackron 📝 dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk(),... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53346 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53347 📊 9.8/10 🏢 IoTSharp 📝 IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersContr... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53347 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53349 📊 8.2/10 🏢 Aircoookie 📝 WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike the /edit endpoint which expl... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53349 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53335 📊 7.8/10 🏢 Swiss Federal Office of Information Technology, Systems and Telecommunication 📝 @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project cr... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53335 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53334 📊 n/a 🏢 SonicWall 📝 A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and red... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53334 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53350 📊 7.5/10 🏢 Domoticz 📝 Domoticz's MochadTCP::MatchLine() handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_moch... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53350 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53346 📊 7.8/10 🏢 mackron 📝 dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk(),... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53346 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53347 📊 9.8/10 🏢 IoTSharp 📝 IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersContr... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53347 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53349 📊 8.2/10 🏢 Aircoookie 📝 WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike the /edit endpoint which expl... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53349 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53351 📊 7.8/10 🏢 syoyo 📝 tinyobjloader-c's tinyobj_parse_and_index_mtl_file() (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer `lineb... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53351 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53348 📊 9.1/10 🏢 cwalter-at 📝 The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool() (demo/LINUXTCP/port/porttcp.c). The check `if (usTCPFrameBytesL... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53348 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53345 📊 6.5/10 🏢 esphome 📝 ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_() (esphome/components/web_server/web_ser... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53345 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53344 📊 8.6/10 🏢 esphome 📝 ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in esphome/config_validation.py: `if parsed.scheme and parsed.n... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53344 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53353 📊 9.9/10 🏢 thiagoralves 📝 OpenPLC Runtime v3's compile_program() function (webserver/openplc.py) parses `(*FILE:path content*)` directives from uploaded Structured Text (.st) ... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53353 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53354 📊 7.2/10 🏢 node-red 📝 Node-RED's local-filesystem library storage module (getLibraryEntry() and saveLibraryEntry() in packages/node_modules/@node-red/runtime/lib/storage/local... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53354 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53366 📊 8.8/10 🏢 huggingface 📝 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py li... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53366 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53359 📊 8.5/10 🏢 openshwprojects 📝 OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup() wit... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53359 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53358 📊 6.5/10 🏢 openshwprojects 📝 OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the ... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53358 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53357 📊 8.5/10 🏢 usememos 📝 Memos' webhook dispatch function safeDialContext() (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost() and va... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53357 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53352 📊 9.8/10 🏢 rxi 📝 microtar's mtar_write_file_header() and mtar_write_dir_header() functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte `name` field of... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53352 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53360 📊 5.4/10 🏢 openshwprojects 📝 OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(req... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53360 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53355 📊 8.6/10 🏢 Stirling-Tools 📝 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService ... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53355 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53363 📊 9.8/10 🏢 iot-ecology 📝 rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary `script` f... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53363 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53364 📊 8.1/10 🏢 Koenkk 📝 Zigbee2MQTT's ExternalJSExtension.getFilePath() (lib/extension/externalJS.ts) joins a `name` parameter received via an MQTT message (topic zigbee2mqtt/brid... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53364 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53356 📊 8.5/10 🏢 usememos 📝 Memos' webhook URL validation, isReservedIP() (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53356 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53365 📊 8.5/10 🏢 go-shiori 📝 go-shiori's DownloadBookmark() (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext o... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53365 #cybersecurity #infosec #cve #euvd

🚨 EUVD-2026-53361 📊 7.1/10 🏢 absmach 📝 Magistrala (formerly Mainflux)'s message-readers API reads a `format` value from the HTTP query string (readers/api/http/transport.go) with no validation ... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53361 #cybersecurity #infosec #cve #euvd