Posts of last 24 hours
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
A vulnerability marked as problematic has been reported in ImageMagick. Affected by this issue is some unknown functionality of the component VIFF Encoder. Performing a manipulation results in memory leak.
This vulnerability is cataloged as CVE-2026-61870. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/377830
A vulnerability labeled as problematic has been found in parse-community parse-server up to 8.6.83/9.0.0-9.10.0-alpha.2. Affected by this vulnerability is an unknown functionality of the component FileUpload. Such manipulation of the argument content-type leads to cross site scripting.
This vulnerability is listed as CVE-2026-61448. The attack may be performed from remote. There is no available exploit.
https://vuldb.com/vuln/377829
A vulnerability identified as problematic has been detected in getgrav Grav Plugin up to 2.0.3. Affected is an unknown function of the file /grav/admin of the component Admin2. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-61454. The attack is possible to be carried out remotely. No exploit exists.
https://vuldb.com/vuln/377828
A vulnerability categorized as critical has been discovered in ImageMagick up to 7.1.2-25. This impacts an unknown function of the component APNG Encoder. The manipulation results in encoding error.
This vulnerability is identified as CVE-2026-61858. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/377827
A vulnerability was found in ImageMagick. It has been rated as critical. This affects an unknown function of the component XMP Handler. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-61857. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/377826
Currently trending CVE - Hype Score: 4 - scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
https://cvemon.intruder.io/cves/CVE-2026-59996
Currently trending CVE - Hype Score: 4 - sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
https://cvemon.intruder.io/cves/CVE-2026-59998
Currently trending CVE - Hype Score: 4 - In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
https://cvemon.intruder.io/cves/CVE-2026-59999
Currently trending CVE - Hype Score: 4 - A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
https://cvemon.intruder.io/cves/CVE-2026-44963