Aggregator
Name That Toon Contest
3 weeks 6 days hence
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
2 weeks 5 days hence
[An RX Global Event] Infosecurity Europe
3 days 11 hours hence
Detect smarter. Detect faster.
2 hours 32 minutes ago
Red Canary, a Zscaler company
Name That Toon: Mark of (Cybersecurity) Progress
6 hours 3 minutes ago
As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades.
John Klossner
CVE-2026-42500 | x-image-bmp up to 0.40.x on Go BMP File array index
6 hours 26 minutes ago
A vulnerability classified as critical was found in x-image-bmp up to 0.40.x on Go. The impacted element is an unknown function of the component BMP File Handler. The manipulation results in improper validation of array index.
This vulnerability is cataloged as CVE-2026-42500. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-47266 | verbb formie up to 2.2.20/3.1.25 save-submission authorization
6 hours 30 minutes ago
A vulnerability classified as problematic has been found in verbb formie up to 2.2.20/3.1.25. The affected element is an unknown function of the file formie/submissions/save-submission. The manipulation leads to authorization bypass.
This vulnerability is listed as CVE-2026-47266. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-34127 | TP-Link TL-SG108PE v5 Configuration Parameter cross site scripting
6 hours 32 minutes ago
A vulnerability described as problematic has been identified in TP-Link TL-SG108PE v5. Impacted is an unknown function of the component Configuration Parameter Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-34127. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-45697 | verbb formie up to 2.2.19/3.1.23 code injection
6 hours 34 minutes ago
A vulnerability marked as critical has been reported in verbb formie up to 2.2.19/3.1.23. This issue affects some unknown processing. Performing a manipulation results in code injection.
This vulnerability is identified as CVE-2026-45697. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-45352 | yhirose cpp-httplib up to 0.43.3 httplib.h std::strtoul chunk-size denial of service
6 hours 34 minutes ago
A vulnerability labeled as problematic has been found in yhirose cpp-httplib up to 0.43.3. This vulnerability affects the function std::strtoul in the library httplib.h. Such manipulation of the argument chunk-size leads to denial of service.
This vulnerability is referenced as CVE-2026-45352. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-45613 | rizinorg rizin omf.c out-of-bounds
6 hours 34 minutes ago
A vulnerability identified as problematic has been detected in rizinorg rizin. This affects an unknown part of the file librz/bin/format/omf/omf.c. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-45613. The attack can only be executed locally. There is no exploit available.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2026-45324 | rizinorg rizin cmd_search.c byte_pattern_search double free
6 hours 34 minutes ago
A vulnerability categorized as problematic has been discovered in rizinorg rizin. Affected by this issue is the function byte_pattern_search of the file librz/core/cmd/cmd_search.c. The manipulation results in double free.
This vulnerability was named CVE-2026-45324. An attack on the physical device is feasible. There is no available exploit.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2026-48555 | spatie laravel-medialibrary up to 11.22.x HTTP Request InteractsWithMedia.php addMediaFromUrl server-side request forgery
6 hours 34 minutes ago
A vulnerability was found in spatie laravel-medialibrary up to 11.22.x. It has been rated as critical. Affected by this vulnerability is the function addMediaFromUrl of the file InteractsWithMedia.php of the component HTTP Request Handler. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-48555. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-4387 | StrongDM Desktop Application/Desktop Client up to 23.73.x cleartext storage
6 hours 35 minutes ago
A vulnerability was found in StrongDM Desktop Application and Desktop Client up to 23.73.x. It has been declared as problematic. Affected is an unknown function. Executing a manipulation can lead to cleartext storage of sensitive information.
This vulnerability is handled as CVE-2026-4387. It is possible to launch the attack on the local host. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-49384 | JetBrains PyCharm up to 2025.3.3 cross site scripting (EUVD-2026-33392)
6 hours 36 minutes ago
A vulnerability was found in JetBrains PyCharm up to 2025.3.3. It has been classified as problematic. This impacts an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is known as CVE-2026-49384. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-49383 | JetBrains IntelliJ IDEA up to 2026.0 UI Designer Form Parser xml external entity reference (EUVD-2026-33391)
6 hours 36 minutes ago
A vulnerability was found in JetBrains IntelliJ IDEA up to 2026.0 and classified as problematic. This affects an unknown function of the component UI Designer Form Parser. Such manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2026-49383. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-49381 | JetBrains TeamCity up to 2026.0 cross site scripting
6 hours 37 minutes ago
A vulnerability has been found in JetBrains TeamCity up to 2026.0 and classified as problematic. The impacted element is an unknown function. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2026-49381. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-49380 | JetBrains TeamCity up to 2026.0 redirect
6 hours 37 minutes ago
A vulnerability, which was classified as problematic, was found in JetBrains TeamCity up to 2026.0. The affected element is an unknown function. The manipulation results in open redirect.
This vulnerability is reported as CVE-2026-49380. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-49376 | JetBrains TeamCity up to 2026.0 authorization
6 hours 37 minutes ago
A vulnerability, which was classified as critical, has been found in JetBrains TeamCity up to 2026.0. Impacted is an unknown function. The manipulation leads to incorrect authorization.
This vulnerability is documented as CVE-2026-49376. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com