Aggregator
Mythos: Just One Piece of the Cybersecurity Puzzle
2 months 1 week ago
The post Mythos: Just One Piece of the Cybersecurity Puzzle appeared first on Security Boulevard.
Yoav Golan
CVE-2026-1491
2 months 1 week ago
Currently trending CVE - Hype Score: 2 - IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 IBM Security Verify could allow a remote attacker to ...
CVE-2026-0049
2 months 1 week ago
Currently trending CVE - Hype Score: 1 - In onHeaderDecoded of LocalImageResolver.java, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2025-48651
2 months 1 week ago
Currently trending CVE - Hype Score: 1 - In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for ...
Do Ceasefires Slow Cyberattacks? History Suggests Not
2 months 1 week ago
The cybersecurity community is waiting with bated breath to see if Iranian hackers will honor a ceasefire that doesn't actually name or directly involve them.
Nate Nelson
ИИ за минуты нашёл то, на что у учёных уходили месяцы: 3000 новых способов бактерий убивать вирусы
2 months 1 week ago
CRISPR был только началом… Встречайте DefensePredictor.
CVE-2026-40072 | Ethereum web3.py up to 7.14.x/8.0.0b1 Backend Service eth_call/call offchain_lookup_payload["urls"] server-side request forgery
2 months 1 week ago
A vulnerability categorized as critical has been discovered in Ethereum web3.py up to 7.14.x/8.0.0b1. This affects the function eth_call/call of the component Backend Service. Executing a manipulation of the argument offchain_lookup_payload["urls"] can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-40072. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-40070 | sgbett bsv-ruby-sdk/bsv-sdk/bsv-wallet prior 0.8.2 WalletClient signature verification
2 months 1 week ago
A vulnerability was found in sgbett bsv-ruby-sdk, bsv-sdk and bsv-wallet. It has been rated as critical. Affected by this issue is the function BSV::Wallet::WalletClient. Performing a manipulation results in improper verification of cryptographic signature.
This vulnerability was named CVE-2026-40070. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-40069 | sgbett bsv-ruby-sdk up to 0.8.1 Transaction BSV::Network txStatus unusual condition
2 months 1 week ago
A vulnerability was found in sgbett bsv-ruby-sdk up to 0.8.1. It has been declared as problematic. Affected by this vulnerability is the function BSV::Network of the component Transaction Handler. Such manipulation of the argument txStatus leads to improper check for unusual conditions.
This vulnerability is uniquely identified as CVE-2026-40069. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-40071 | pyLoad up to 0.5.0b3.dev96 WebUI JSON Endpoint /json/package_order authorization
2 months 1 week ago
A vulnerability was found in pyLoad up to 0.5.0b3.dev96. It has been classified as problematic. Affected is an unknown function of the file /json/package_order of the component WebUI JSON Endpoint. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-40071. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-70797 | LimeSurvey 6.15.20 Box[title]/box[url] cross site scripting
2 months 1 week ago
A vulnerability was found in LimeSurvey 6.15.20 and classified as problematic. This impacts an unknown function. The manipulation of the argument Box[title]/box[url] results in cross site scripting.
This vulnerability is known as CVE-2025-70797. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-30478 | GatewayGeo MapServer for Windows on Windows injection
2 months 1 week ago
A vulnerability has been found in GatewayGeo MapServer for Windows on Windows and classified as critical. This affects an unknown function. The manipulation leads to injection.
This vulnerability is traded as CVE-2026-30478. Access to the local network is required for this attack to succeed. There is no exploit available.
vuldb.com
CVE-2026-30479 | OSGeo MapServer up to 7.x injection
2 months 1 week ago
A vulnerability, which was classified as critical, was found in OSGeo MapServer up to 7.x. The impacted element is an unknown function. Executing a manipulation can lead to injection.
This vulnerability appears as CVE-2026-30479. The attacker needs to be present on the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-39943 | Directus up to 11.16.x information disclosure (GHSA-mvv8-v4jj-g47j)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Directus up to 11.16.x. The affected element is an unknown function. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-39943. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-39942 | Directus up to 11.16.x /files/ filename_disk access control (GHSA-393c-p46r-7c95)
2 months 1 week ago
A vulnerability classified as critical was found in Directus up to 11.16.x. Impacted is an unknown function of the file /files/. Such manipulation of the argument filename_disk leads to improper access controls.
This vulnerability is documented as CVE-2026-39942. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-39985 | aces Loris up to 27.0.2/28.0.0 redirect
2 months 1 week ago
A vulnerability classified as problematic has been found in aces Loris up to 27.0.2/28.0.0. This issue affects some unknown processing. This manipulation causes open redirect.
This vulnerability is registered as CVE-2026-39985. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-39983 | patrickjuchli basic-ftp up to 5.2.0 path crlf injection
2 months 1 week ago
A vulnerability described as problematic has been identified in patrickjuchli basic-ftp up to 5.2.0. This vulnerability affects the function cd/remove/rename/uploadFrom/downloadTo/list/removeDir. The manipulation of the argument path results in crlf injection.
This vulnerability is cataloged as CVE-2026-39983. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-39981 | Josh-XT AGiXT up to 1.9.1 safe_join path traversal
2 months 1 week ago
A vulnerability marked as critical has been reported in Josh-XT AGiXT up to 1.9.1. This affects the function safe_join. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-39981. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-39976 | laravel passport up to 13.7.0 retrieveById improper authentication (ID 1900)
2 months 1 week ago
A vulnerability labeled as critical has been found in laravel passport up to 13.7.0. Affected by this issue is the function retrieveById. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2026-39976. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com