CVE-2026-64798
Published Jul 22, 2026Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
- evidence mentions
- 1
- Buzz score
- 11.9
Loading current evidence
Historical archive search
Search decades of CVEs by regex, severity, date, CWE, vendor/product tags, KEV, PoC, and other evidence.
Results
3,268 results · Sorted by Highest Buzz score first
Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could r…
Administrator URL purges did not consistently require a valid token and cache-management permission.
Custom purge and log paths could escape the site webroot directory.
Custom query URLs could access internal or reserved network services.
CDN credentials were exposed in administrator request URLs.
GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via th…
A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve com…
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injec…
The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injec…
MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.
Modals gallery paths could enumerate unintended directories.
ReReplacer XML include paths could read files outside the site directory.
Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing co…
Shortcut configuration accepted arbitrary inline JavaScript.
The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
The front-end Submissions view did not enforce access control. An unauthenticated visitor could therefore list a form's submissions.
Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCity: from…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This…
A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 could allow an…
Every filter state lives in the URL so you can bookmark, share, and crawl exact historical slices instead of a client-only search session.
Buzz order uses the latest all-time evidence snapshot, refreshed every two hours. Evidence-bearing CVEs rank first; records without a snapshot continue newest-first.