A vulnerability classified as problematic was found in Best Practical Request Tracker up to 4.4.8/5.0.8/6.0.1. This impacts an unknown function of the component TSV Export. Executing a manipulation can lead to csv injection.
The identification of this vulnerability is CVE-2025-61873. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in SchedMD Slurm up to 23.11.10/24.05.7/24.11.4. This affects an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2025-43904. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Apple iOS and iPadOS up to 18.0. The impacted element is an unknown function of the component Lock Screen. Such manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2024-54556. The attack can be executed directly on the physical device. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in EnterpriseDB Postgres Enterprise Manager up to 9.8.0. The affected element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2026-0949. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
The identity of the Black Basta ransomware gang leader has been confirmed by law enforcement in Ukraine and Germany, and the individual has been added to the wanted list of Europol and Interpol. [...]
A vulnerability labeled as critical has been found in VideoLAN VLC Media Player up to 3.0.21. Impacted is an unknown function of the file mmstu.c. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2025-51602. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in strongSwan up to 6.0.2. This issue affects some unknown processing of the component eap-mschapv2 Plugin. The manipulation leads to integer underflow.
This vulnerability is traded as CVE-2025-62291. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability was found in OpenAgentPlatform Dive up to 0.12.x. It has been rated as critical. This affects an unknown part of the component Deeplink Handler. Performing a manipulation results in code injection.
This vulnerability is reported as CVE-2026-23523. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in dask distributed. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Dask Dashboard. Such manipulation leads to basic cross site scripting.
This vulnerability is documented as CVE-2026-23528. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Google Android. It has been classified as critical. Affected by this vulnerability is the function cpm_fwtp_msg_handler in the library cpm/google/lib/tracepoint/cpm_fwtp_ipc.c. This manipulation causes improper input validation.
This vulnerability is registered as CVE-2025-48647. The attack needs to be launched locally. No exploit is available.
A vulnerability was found in Browser Company of New York Dia up to 1.8.x on macOS and classified as problematic. Affected is an unknown function of the component Trusted Domain Handler. The manipulation results in improper restriction of rendered ui layers.
This vulnerability is cataloged as CVE-2025-15032. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in Aiven-Open bigquery-connector-for-apache-kafka up to 2.10.x and classified as problematic. This impacts an unknown function. The manipulation leads to file inclusion.
This vulnerability is listed as CVE-2026-23529. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
The operator of a cybercrime forum account known as "r1z" could spend up to 10 years in prison after pleading guilty to selling malware built to break into corporate networks.
A vulnerability was found in Emlog 2.5.23. It has been classified as problematic. This affects an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-21432. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Emlog 2.5.23. It has been declared as problematic. This impacts an unknown function of the component Resource Media Library. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-21431. The attack can be executed remotely. There is not any exploit available.
The activist website called "ICE List" was offline after a massive DDoS attack. The crash followed a leak of 4,500 federal agent names linked to the Renee Nicole Good shooting.
The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that's designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives.
"The actor creates a malformed archive as an anti-analysis technique," Expel security researcher Aaron Walton said in a report shared with The Hacker News. "That is, many unarchiving tools