PULSE
FEED
ransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technologyransomplay reclama a Bold Spring Nursery · US · Agriculture and Food Productionransomplay reclama a Silicon Valley Glass · US · Manufacturingransomemperador reclama a OMUR HIRDAVAT LTD · TR · Manufacturingransombooba project reclama a MorseLife Health System, Inc. · US · Healthcareransomstorm reclama a Nipigon District Memorial Hospital · CA · Healthcareransomqilin reclama a Unident Group · US · Otherransomqilin reclama a Chadwick Switchboards · AU · Manufacturingransomqilin reclama a Emser · ES · Manufacturingransomqilin reclama a Cotesma · CL · Manufacturingransomdirewolf reclama a Softruck · BR · Technologyransomqilin reclama a Mutsumi Group · JP · Manufacturingransompayoutsking reclama a M****C · US · Not Foundransomthegentlemen reclama a Center State Engineering · US · Manufacturingransomkrybit reclama a euroditel.com · FR · Technology
← Todos los CVEs
CVE Watch2 oct 2026

CVE-2026-104849

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options obje

CVSS

—

Sin CVSS

EPSS

0.4%

p31

KEV

—

Exploit Today

9

0-100

Publicado: 2 oct 2026 · Última mod.: 2 oct 2026 · CWE-94 · CWE-1321

EPSS · 30d
0.4%EPSS · 30 días0.4%
2026-10-032026-10-04
Descripción técnica

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1052264.7 MED
—
———A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.3h
CVE-2026-1052254.3 MED
—
———A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.3h
CVE-2026-1051883.5 BAJ
—
———A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used.3h
CVE-2026-1051733.5 BAJ
—
——0A flaw has been found in code-projects Human Resource Management 1.0. This affects an unknown part of the file /humanresourcemanagementsystem/src/store/EventStore.php of the component Event Creation. Executing a manipulation of the argument eventSubject can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used.7h
CVE-2026-10513510.0 CRÍ
54.1%
——16A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.1d
CVE-2026-1050993.5 BAJ
7.9%
——2A weakness has been identified in Omega Solution CoinEx Crypto 2025. Affected by this vulnerability is an unknown functionality of the file /user/ticket of the component Ticket Attachment Upload. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.1d