ZeroHour

Vulnerabilities

378 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-52023
+1 in the same advisory: …52022
Unauthenticated DoS in Kamailio ims_registrar_pcscf module (≤ 6.1.1)

Kamailio 6.1.1 and earlier contain a remotely exploitable denial-of-service flaw (CWE-400) in the ims_registrar_pcscf module, the component that implements the IMS P-CSCF registrar role. The bug is triggered by network input reaching the pcscf_save_pending/save_pending path and by security-agreement parsing in sec_agree.c:parse_sec_agree(), allowing an unauthenticated remote attacker to exhaust resources or crash the SIP proxy. Successful exploitation yields high availability impact (CVSS 3.1 7.5, AV:N/AC:L/PR:N/UI:N) with no confidentiality or integrity loss, meaning IMS/VoLTE registration service behind the affected P-CSCF can be disrupted. Only deployments running Kamailio as a P-CSCF with the ims_registrar_pcscf and security-agreement (sec_agree) functionality enabled are affected; Kamailio installations that do not load these IMS modules are not exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known, and EPSS estimates the 30-day exploitation probability at roughly 0.3%.

Do: Upgrade to a Kamailio release newer than 6.1.1 that includes the fix, prioritizing any system that loads the ims_registrar_pcscf or sec_agree modules. As interim mitigation, disable ims_registrar_pcscf if the P-CSCF role is not required, restrict access to the P-CSCF SIP ports to trusted IMS signaling peers, and monitor for worker crashes or unexpected restarts.

7.5<1% PoC
  • Kamailio (open-source project) Kamailio (ims_registrar_pcscf module / P-CSCF role, sec_agree.c) 6.1.1 and earlier
moderatelikely on the order of thousands of P-CSCF instances worldwide (estimate; no public install counts)
CVE-2026-53727
css_parser is a Ruby CSS parser.

css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.

NVD description · AI analysis pending
8.9<1% PoC
  • premailer css parser
CVE-2026-56292
Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was disc

Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1 - A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

NVD description · AI analysis pending
9.21% PoC
  • acymailing acymailing
CVE-2026-44400
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass a

MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing AuthenticationToken cookies generated for low-privileged users. Attackers can obtain a token from the WebMail login endpoint using the PersistentLogin parameter and replay it against the WebAdmin portal to perform highly privileged administrative actions.

NVD description · AI analysis pending
8.7<1%
  • mailenable mailenable
CVE-2026-39863
+1 in the same advisory: …39864
Kamailio is an open source implementation of a SIP Signaling Server.

Kamailio is an open source implementation of a SIP Signaling Server. Prior to 6.1.1, 6.0.6, and 5.8.8, an out-of-bounds access in the core of Kamailio (formerly OpenSER and SER) allows remote attackers to cause a denial of service (process crash) via a specially crafted data packet sent over TCP. The issue impacts Kamailio instances having TCP or TLS listeners. This vulnerability is fixed in 5.1.1, 6.0.6, and 5.8.8.

NVD description · AI analysis pending
7.5
group max
<1%
  • kamailio kamailio
CVE-2026-35389
+2 in the same advisory: …35391 …35390
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server.

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, S/MIME signature verification did not validate the certificate trust chain (checkChain: false). Any email signed with a self-signed or untrusted certificate was displayed as having a valid signature. This vulnerability is fixed in 1.4.11.

NVD description · AI analysis pending
8.7
group max
<1%
  • bulwarkmail webmail
CVE-2026-34834
+1 in the same advisory: …34833
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server.

Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to version 1.4.10, the verifyIdentity() function contained logic that returned true if no session cookies were present. This allowed unauthenticated attackers to bypass security checks and access/modify user settings via the /api/settings endpoint by providing arbitrary headers. This issue has been patched in version 1.4.10.

NVD description · AI analysis pending
8.7<1%
  • bulwarkmail webmail
CVE-2026-29139
SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.

SEPPmail Secure Email Gateway before version 15.0.3 allows account takeover by abusing GINA account initialization to reset a victim account password.

NVD description · AI analysis pending
7.8
group max
<1%
  • seppmail secure email gateway
CVE-2026-30562
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0.

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

NVD description · AI analysis pending
9.3
group max
<1% PoC
  • ahsanriaz26gmailcom sales and inventory system
CVE-2026-30567
+4 in the same advisory: …30571 …30570 …30569 …30568
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "limit" parame

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0 in the view_product.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

NVD description · AI analysis pending
6.1
group max
<1% PoC
  • ahsanriaz26gmailcom inventory system
CVE-2026-4826
A vulnerability was determined in SourceCodester Sales and Inventory System 1.0.

A vulnerability was determined in SourceCodester Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /update_stock.php of the component HTTP GET Parameter Handler. This manipulation of the argument sid causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

NVD description · AI analysis pending
2.1<1% PoC
  • ahsanriaz26gmailcom sales and inventory system
CVE-2026-4825
+2 in the same advisory: …4781 …4780
A vulnerability was found in SourceCodester Sales and Inventory System 1.0.

A vulnerability was found in SourceCodester Sales and Inventory System 1.0. This affects an unknown part of the file /update_sales.php of the component HTTP GET Parameter Handler. The manipulation of the argument sid results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

NVD description · AI analysis pending
2.1<1% PoC
  • ahsanriaz26gmailcom sales and inventory system
CVE-2026-4779
+2 in the same advisory: …4778 …4777
A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0.

A security vulnerability has been detected in SourceCodester Sales and Inventory System 1.0. This issue affects some unknown processing of the file update_customer_details.php of the component HTTP GET Parameter Handler. Such manipulation of the argument sid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

NVD description · AI analysis pending
2.1<1% PoC
  • ahsanriaz26gmailcom sales and inventory system
CVE-2026-32852
MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbit

MailEnable versions prior to 10.55 contain a reflected cross-site scripting vulnerability in the webmail interface that allows remote attackers to execute arbitrary JavaScript in a victim's browser by crafting a malicious URL. Attackers can inject malicious code through the StartDate parameter in the FreeBusy.aspx form, which is not properly sanitized before being embedded into dynamically generated JavaScript.

NVD description · AI analysis pending
5.1<1% PoC
  • mailenable mailenable