⤷ Title: DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 01:00:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA medical advisory #CVE_2026_50003 #DCMTK #DICOM #DICOM toolkit #medical imaging #OFFIS DCMTK #Path Traversal
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 04 Jul 2026 01:00:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA medical advisory #CVE_2026_50003 #DCMTK #DICOM #DICOM toolkit #medical imaging #OFFIS DCMTK #Path Traversal
Daily CyberSecurity
DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS
TL;DR CISA published an advisory for five DCMTK vulnerabilities on 30 June 2026. The DICOM toolkit powers medical imaging on many hospital systems. The worst flaw lets a malicious server write fil…
⤷ Title: Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 04:09:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #ColdFusion #CVE_2026_48282 #Path Traversal
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 04:09:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #ColdFusion #CVE_2026_48282 #Path Traversal
Daily CyberSecurity
Active ColdFusion Arbitrary Code Execution Flaw Scores CVSS 10
TL;DR CVE-2026-48282, a critical CVSS 10 ColdFusion arbitrary code execution vulnerability, is under active attack. Hackers are exploiting this path traversal flaw in the wild. Administrators must…
⤷ Title: Apache Lucene.NET Vulnerability Trio Fixed in Beta 18
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 14:33:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Lucene.NET #CVE_2026_47896 #CVE_2026_47897 #CVE_2026_47898 #Lucene.Net.Replicator #Path Traversal #xxe
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 14:33:43 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Lucene.NET #CVE_2026_47896 #CVE_2026_47897 #CVE_2026_47898 #Lucene.Net.Replicator #Path Traversal #xxe
Daily CyberSecurity
Apache Lucene.NET Vulnerability Trio Fixed in Beta 18
The Apache project patched three Apache Lucene.NET vulnerability issues in the 4.8.0-beta00018 release. Two of the flaws carry a high CVSS score of 8.9. Both live inside the Lucene.Net.Replicator …
⤷ Title: Apache IoTDB Fixes Path Traversal and Authentication Bypass Flaws (CVE-2026-24014)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 11 Jul 2026 01:37:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache IoTDB #Arbitrary File Write #Authentication Bypass #CVE_2026_24012 #CVE_2026_24013 #CVE_2026_24014 #IoT security #Path Traversal
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 11 Jul 2026 01:37:25 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache IoTDB #Arbitrary File Write #Authentication Bypass #CVE_2026_24012 #CVE_2026_24013 #CVE_2026_24014 #IoT security #Path Traversal
Daily CyberSecurity
Apache IoTDB Fixes Path Traversal and Authentication Bypass Flaws (CVE-2026-24014)
TL;DR Apache IoTDB has patched three flaws in its time-series database. The worst is a critical path traversal bug, CVE-2026-24014, scored 9.8. A second flaw allows an authentication bypass, and a…
⤷ Title: decompress npm Vulnerability CVE-2026-53486 (CVSS 9.1) Threatens 2.8 Million Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 13:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_53486 #decompress #Node.js Security #npm Security #Path Traversal #Supply Chain Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 13:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_53486 #decompress #Node.js Security #npm Security #Path Traversal #Supply Chain Security
Daily CyberSecurity
decompress npm Vulnerability CVE-2026-53486 (CVSS 9.1) Threatens 2.8 Million Weekly Downloads
TL;DR A high-severity decompress npm vulnerability lets crafted archives write files outside the extraction folder. Tracked as CVE-2026-53486, the flaw carries a CVSS score of 9.1. It sits in a li…
⤷ Title: CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
Daily CyberSecurity
CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
TL;DR PHP Composer, the main dependency manager for the language, patched three security flaws. The most serious, CVE-2026-59948, is an arbitrary file write rated CVSS 7.0. A malicious package can…
⤷ Title: Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 02:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #notepad++ #Path Traversal #Zip Slip
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 02:28:16 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #buffer overflow #notepad++ #Path Traversal #Zip Slip
Daily CyberSecurity
Notepad++ v8.9.7 Fixes 5 Vulnerabilities, All With Public Details and PoC Exploit Code
TL;DR Notepad++ v8.9.7 fixes five security flaws in the popular Windows editor. Technical details and proof-of-concept exploit code for all five Notepad++ vulnerabilities are public in the project…
⤷ Title: CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 12:25:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Apache OpenMeetings #Arbitrary File Read #Path Traversal
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 12:25:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Apache OpenMeetings #Arbitrary File Read #Path Traversal
Daily CyberSecurity
CVE-2026-49488: Arbitrary File Read Flaw in Apache OpenMeetings Exposes Server Credentials
TL;DR Apache has patched a critical OpenMeetings vulnerability tracked as CVE-2026-49488. The path traversal flaw grants arbitrary file read to any user with moderator rights in a room. Version 9.…
⤷ Title: Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 02:12:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #GHSA_p63j_vcc4_9vmv #javascript #npm #Path Traversal #Supply Chain Security #Vite #Vitest #Vitest Browser Mode
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 22 Jul 2026 02:12:08 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Read #GHSA_p63j_vcc4_9vmv #javascript #npm #Path Traversal #Supply Chain Security #Vite #Vitest #Vitest Browser Mode
Daily CyberSecurity
Vitest Flaw Rated CVSS 9.4 Hits an npm Package With 65 Million Weekly Downloads
TL;DR Vitest patched a critical vulnerability rated CVSS 9.4. Browser Mode commands could read, write, or delete files outside the project folder. They did so even when the allowWrite gate was set…
⤷ Title: ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 02:50:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADAudit Plus #Authentication Bypass #CVE_2026_6516 #ManageEngine #patch management #Path Traversal #unauthenticated RCE #Zoho
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 02:50:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #active directory #ADAudit Plus #Authentication Bypass #CVE_2026_6516 #ManageEngine #patch management #Path Traversal #unauthenticated RCE #Zoho
Daily CyberSecurity
ADAudit Plus Flaw CVE-2026-6516 Allows Unauthenticated Remote Code Execution at CVSS 10
TL;DR ManageEngine patched a critical ADAudit Plus vulnerability tracked as CVE-2026-6516. Two weaknesses in the product’s Agent APIs, an authentication bypass and a path traversal, chain in…