<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Google Container-Optimized OS (COS) (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/cos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cos-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Google Container-Optimized OS (COS) (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-41118 – Pyroscope is an open-source continuous profiling database. The database supports...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41118</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41118</strong></p>
  <p>Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).  If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API.  To exploit this vulnerability, an attacker needs direct access to the Pyroscope API. W…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5756 – Unauthenticated Configuration File Modification Vulnerability in DRC Central Off...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5756</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5756</strong></p>
  <p>Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5150 – A security vulnerability has been detected in code-projects Accounting System 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5150</guid>
    <pubDate>Mon, 30 Mar 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5150</strong></p>
  <p>A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewin_costumer.php of the component Parameter Handler. Such manipulation of the argument cos_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5034 – A flaw has been found in code-projects Accounting System 1.0. Affected by this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5034</guid>
    <pubDate>Sun, 29 Mar 2026 06:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5034</strong></p>
  <p>A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5033 – A vulnerability was detected in code-projects Accounting System 1.0. Affected by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5033</guid>
    <pubDate>Sun, 29 Mar 2026 06:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5033</strong></p>
  <p>A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30382 – An Improper Handling of Exceptional Conditions vulnerability in the routing prot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30382</guid>
    <pubDate>Fri, 12 Apr 2024 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30382</strong></p>
  <p>An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS).  This issue can only be triggered when the system is configured for CoS-based forwa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22391 – A vulnerability in class-of-service (CoS) queue management in Juniper Networks J...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22391</guid>
    <pubDate>Fri, 13 Jan 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22391</strong></p>
  <p>A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Specific packets are being incorrectly routed to a queue used for other high-priority traffic such as BGP, PIM, ICMP, ICMPV6 ND and ISAKMP. Due to this misclassification of traffic, receipt of a hig…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17352 – In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17352</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17352</strong></p>
  <p>In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-1654 – A vulnerability in the development shell (devshell) authentication for Cisco Air...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1654</guid>
    <pubDate>Wed, 17 Apr 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-1654</strong></p>
  <p>A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication, which allows for root access to the underlying Linux OS. The attacker would need valid device credentials. The vulnerability exists becau…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1654">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
