<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Google Container-Optimized OS (COS)</title>
  <link>https://cvedaily.com/pages/tags/cos.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cos.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Google Container-Optimized OS (COS)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-41118 – Pyroscope is an open-source continuous profiling database. The database supports...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41118</guid>
    <pubDate>Wed, 15 Apr 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-41118</strong></p>
  <p>Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).  If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API.  To exploit this vulnerability, an attacker needs direct access to the Pyroscope API. W…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5756 – Unauthenticated Configuration File Modification Vulnerability in DRC Central Off...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5756</guid>
    <pubDate>Tue, 14 Apr 2026 18:17:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5756</strong></p>
  <p>Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5150 – A security vulnerability has been detected in code-projects Accounting System 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5150</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5150</guid>
    <pubDate>Mon, 30 Mar 2026 20:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5150</strong></p>
  <p>A security vulnerability has been detected in code-projects Accounting System 1.0. This issue affects some unknown processing of the file /viewin_costumer.php of the component Parameter Handler. Such manipulation of the argument cos_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5150">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5034 – A flaw has been found in code-projects Accounting System 1.0. Affected by this i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5034</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5034</guid>
    <pubDate>Sun, 29 Mar 2026 06:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5034</strong></p>
  <p>A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler. This manipulation of the argument cos_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5034">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-5033 – A vulnerability was detected in code-projects Accounting System 1.0. Affected by...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5033</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5033</guid>
    <pubDate>Sun, 29 Mar 2026 06:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-5033</strong></p>
  <p>A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Parameter Handler. The manipulation of the argument cos_id results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5033">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-4836 – A vulnerability was detected in code-projects Accounting System 1.0. The affecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4836</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4836</guid>
    <pubDate>Thu, 26 Mar 2026 03:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-4836</strong></p>
  <p>A vulnerability was detected in code-projects Accounting System 1.0. The affected element is an unknown function of the file /my_account/delete.php. Performing a manipulation of the argument cos_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4836">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27087 – A vulnerability in the kernel of the Cray Operating System (COS) could allow an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27087</guid>
    <pubDate>Tue, 22 Apr 2025 22:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27087</strong></p>
  <p>A vulnerability in the kernel of the Cray Operating System (COS) could allow an attacker to perform a local Denial of Service (DoS) attack.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-29433 – Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-29433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-29433</guid>
    <pubDate>Mon, 09 Dec 2024 13:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-29433</strong></p>
  <p>Missing Authorization vulnerability in 腾讯云 tencentcloud-cos allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects tencentcloud-cos: from n/a through 1.0.7.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-29433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30382 – An Improper Handling of Exceptional Conditions vulnerability in the routing prot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30382</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30382</guid>
    <pubDate>Fri, 12 Apr 2024 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30382</strong></p>
  <p>An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS).  This issue can only be triggered when the system is configured for CoS-based forwa…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30382">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-21610 – An Improper Handling of Exceptional Conditions vulnerability in the Class of Ser...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-21610</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-21610</guid>
    <pubDate>Fri, 12 Apr 2024 15:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-21610</strong></p>
  <p>An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS).  In a scaled CoS scenario with 1000s of interfaces, when specific low privileged commands, received over NETCONF, SSH or telnet, are handled by cosd on behalf…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-21610">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-22391 – A vulnerability in class-of-service (CoS) queue management in Juniper Networks J...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-22391</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-22391</guid>
    <pubDate>Fri, 13 Jan 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-22391</strong></p>
  <p>A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Specific packets are being incorrectly routed to a queue used for other high-priority traffic such as BGP, PIM, ICMP, ICMPV6 ND and ISAKMP. Due to this misclassification of traffic, receipt of a hig…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-755</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-22391">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0659 – The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its se...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0659</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0659</guid>
    <pubDate>Mon, 14 Mar 2022 15:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0659</strong></p>
  <p>The Sync QCloud COS WordPress plugin before 2.0.1 does not escape some of its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0659">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-31369 – On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Li...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31369</guid>
    <pubDate>Tue, 19 Oct 2021 19:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-31369</strong></p>
  <p>On MX Series platforms with MS-MPC/MS-MIC, an Allocation of Resources Without Limits or Throttling vulnerability in Juniper Networks Junos OS allows an unauthenticated network attacker to cause a partial Denial of Service (DoS) with a high rate of specific traffic. If a Class of Service (CoS) rule is attached to the service-set and a high rate of specific traffic is processed by this service-set,…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-0239 – In Juniper Networks Junos OS Evolved, receipt of a stream of specific genuine La...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-0239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-0239</guid>
    <pubDate>Thu, 22 Apr 2021 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-0239</strong></p>
  <p>In Juniper Networks Junos OS Evolved, receipt of a stream of specific genuine Layer 2 frames may cause the Advanced Forwarding Toolkit (AFT) manager process (Evo-aftmand), responsible for handling Route, Class-of-Service (CoS), Firewall operations within the packet forwarding engine (PFE) to crash and restart, leading to a Denial of Service (DoS) condition. By continuously sending this specific s…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-754</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-0239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17352 – In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17352</guid>
    <pubDate>Tue, 08 Oct 2019 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17352</strong></p>
  <p>In JFinal cos before 2019-08-13, as used in JFinal 4.4, there is a vulnerability that can bypass the isSafeFile() function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-1654 – A vulnerability in the development shell (devshell) authentication for Cisco Air...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-1654</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-1654</guid>
    <pubDate>Wed, 17 Apr 2019 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-1654</strong></p>
  <p>A vulnerability in the development shell (devshell) authentication for Cisco Aironet Series Access Points (APs) running the Cisco AP-COS operating system could allow an authenticated, local attacker to access the development shell without proper authentication, which allows for root access to the underlying Linux OS. The attacker would need valid device credentials. The vulnerability exists becau…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-1654">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-8753 – The IKEv1 implementation in Clavister cOS Core before 11.00.11, 11.20.xx before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-8753</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-8753</guid>
    <pubDate>Wed, 15 Aug 2018 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-8753</strong></p>
  <p>The IKEv1 implementation in Clavister cOS Core before 11.00.11, 11.20.xx before 11.20.06, and 12.00.xx before 12.00.09 allows remote attackers to decrypt RSA-encrypted nonces by leveraging a Bleichenbacher attack.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-8753">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2009-3486 – Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Ju...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-3486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-3486</guid>
    <pubDate>Wed, 30 Sep 2009 15:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2009-3486</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authenticated users to inject arbitrary web script or HTML via the host parameter to (1) the pinghost program, reachable through the diagnose program; or (2) the traceroute program, reachable through the diagnose program; or (3) the probe-limit parameter to the configuration program;…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-3486">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
