CVE-2023-49899
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communicati
CVSS
9.8
Crítico
EPSS
0.3%
p24
KEV
—
Exploit Today
7
0-100
Publicado: 16 jul 2026 · Última mod.: 18 jul 2026 · CWE-346
0.2%EPSS · 30 días0.3%
2026-08-142026-09-10
An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-50025——
———Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN provenance checks. The service stores a MyAnonamouse (MAM) session cookie in state and reuses the same cookie-bearing serialization for persisted state, public API responses, and WebSocket state updates. Any client that can reach the published Mousehole port can read cookie-bearing state, connect to WebSocket state updates, replace the stored cookie, or force MAM update side effects. The deployment examples publish port 5010 broadly with Docker's `5010:5010` syntax, which can make the issue reachable on mixed-trust LAN/VPN interfaces. Version 0.4.0 patches the issue.7hCVE-2026-788077.1 ALT—
———An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c7hCVE-2026-875634.3 MED5.9%
——2Origin validation error in Paint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)2dCVE-2026-696808.1 ALT27.6%
——8Origin validation error in Windows DNS allows an unauthorized attacker to perform spoofing over a network.2dCVE-2026-695595.8 MED24.8%
——7Origin validation error in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.3dCVE-2026-586496.5 MED19.4%
——6Origin validation error in .NET allows an unauthorized attacker to disclose information over a network.3d