Aggregator
CISA Flags Critical Flaw in Grassroots DICOM Imaging Library
1 week 2 days ago
Researcher: If Exploited, Bug Could Crash Hospital Medical Imaging Systems
The Cybersecurity Infrastructure and Security Agency is warning of a high severity in Grassroots DICOM, an open-source library commonly used for medical imaging products, that if exploited could allow an attacker to send a specially crafted file resulting in a denial-of-service situation.
The Cybersecurity Infrastructure and Security Agency is warning of a high severity in Grassroots DICOM, an open-source library commonly used for medical imaging products, that if exploited could allow an attacker to send a specially crafted file resulting in a denial-of-service situation.
Google's 2029 Quantum Deadline Is a Wake-Up Call
1 week 2 days ago
Google's Accelerated PQC Timeline Demands Enterprise Action Now
Google set a public deadline for migrating to post-quantum cryptography, setting a strong signal for IT and security leaders that they too should transition their encryption into more robust algorithms. Enterprises need a migration strategy now before the window closes.
Google set a public deadline for migrating to post-quantum cryptography, setting a strong signal for IT and security leaders that they too should transition their encryption into more robust algorithms. Enterprises need a migration strategy now before the window closes.
US Treasury Weighs Cyber Insurance Backstop
1 week 2 days ago
Federal Review Questions Whether Private Insurers Can Absorb Cyber Losses
A Department of the Treasury review of cyber risk under the Terrorism Risk Insurance Program comes amid concern that nation-state attacks and systemic cyber events may overwhelm private insurers, raising the prospect of a federal backstop to protect critical infrastructure and economic stability.
A Department of the Treasury review of cyber risk under the Terrorism Risk Insurance Program comes amid concern that nation-state attacks and systemic cyber events may overwhelm private insurers, raising the prospect of a federal backstop to protect critical infrastructure and economic stability.
Europe Girds for Looming IoT Security Regulations
1 week 2 days ago
European Commission Publishes Draft Guidance for Cyber Resilience Act
Key implementation deadlines loom for one of Europe's most consequential cybersecurity laws and draft guidance from the European Union may help manufacturers comply - up to a point.
Key implementation deadlines loom for one of Europe's most consequential cybersecurity laws and draft guidance from the European Union may help manufacturers comply - up to a point.
Breach of Confidence – 27 March 2026
1 week 2 days ago
I’ve been watching my phone battery go to 37% lately and it’s giving me anxiety even though I know I can make it through the day. This is why I don’t think I’ll ever be able to live with an electric car. The Scanner That Scanned Itself Trivy, the widely used security scanner that’s been … Continue reading Breach of Confidence – 27 March 2026 →
The post Breach of Confidence – 27 March 2026 appeared first on Security Boulevard.
j4vv4d
CVE-2026-33994 | locutusjs locutus up to 3.0.24 Query prototype pollution
1 week 2 days ago
A vulnerability was found in locutusjs locutus up to 3.0.24. It has been classified as problematic. This affects an unknown function of the component Query Handler. The manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is referenced as CVE-2026-33994. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-33994 | locutusjs locutus up to 3.0.24 Query prototype pollution
1 week 2 days ago
A vulnerability was found in locutusjs locutus up to 3.0.24. It has been classified as problematic. This affects an unknown function of the component Query Handler. The manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is referenced as CVE-2026-33994. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-33989 | mobile-next mobile-mcp up to 0.0.48 Fileystem Operation saveTo/output path traversal (GHSA-3p2m-h2v6-g9mx)
1 week 2 days ago
A vulnerability was found in mobile-next mobile-mcp up to 0.0.48 and classified as critical. The impacted element is the function mobile_save_screenshot/mobile_start_screen_recording of the component Fileystem Operation Handler. Executing a manipulation of the argument saveTo/output can lead to path traversal.
The identification of this vulnerability is CVE-2026-33989. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-33989 | mobile-next mobile-mcp up to 0.0.48 Fileystem Operation saveTo/output path traversal (GHSA-3p2m-h2v6-g9mx)
1 week 2 days ago
A vulnerability was found in mobile-next mobile-mcp up to 0.0.48 and classified as critical. The impacted element is the function mobile_save_screenshot/mobile_start_screen_recording of the component Fileystem Operation Handler. Executing a manipulation of the argument saveTo/output can lead to path traversal.
The identification of this vulnerability is CVE-2026-33989. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-33981 | dgtlmoon changedetection.io up to 0.54.6 Environment Variable SALTED_PASS/PLAYWRIGHT_DRIVER_URL/HTTP_PROXY information disclosure (GHSA-58r7-4wr5-hfx8)
1 week 2 days ago
A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.6 and classified as problematic. The affected element is an unknown function of the component Environment Variable Handler. Performing a manipulation of the argument SALTED_PASS/PLAYWRIGHT_DRIVER_URL/HTTP_PROXY results in information disclosure.
This vulnerability was named CVE-2026-33981. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-33981 | dgtlmoon changedetection.io up to 0.54.6 Environment Variable SALTED_PASS/PLAYWRIGHT_DRIVER_URL/HTTP_PROXY information disclosure (GHSA-58r7-4wr5-hfx8)
1 week 2 days ago
A vulnerability has been found in dgtlmoon changedetection.io up to 0.54.6 and classified as problematic. The affected element is an unknown function of the component Environment Variable Handler. Performing a manipulation of the argument SALTED_PASS/PLAYWRIGHT_DRIVER_URL/HTTP_PROXY results in information disclosure.
This vulnerability was named CVE-2026-33981. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-33996 | benmcollins libjwt up to 3.2.x JWK Parser null pointer dereference (EUVD-2026-16899 / Nessus ID 304156)
1 week 2 days ago
A vulnerability, which was classified as problematic, was found in benmcollins libjwt up to 3.2.x. Impacted is an unknown function of the component JWK Parser. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-33996. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-33996 | benmcollins libjwt up to 3.2.x JWK Parser null pointer dereference
1 week 2 days ago
A vulnerability, which was classified as problematic, was found in benmcollins libjwt up to 3.2.x. Impacted is an unknown function of the component JWK Parser. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-33996. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-33991 | LabRedesCefetRJ WeGIA up to 3.6.6 deletar_tag.php deletar_tag $_REQUEST sql injection (EUVD-2026-16884)
1 week 2 days ago
A vulnerability, which was classified as critical, has been found in LabRedesCefetRJ WeGIA up to 3.6.6. This issue affects the function deletar_tag of the file html/socio/sistema/deletar_tag.php. This manipulation of the argument $_REQUEST causes sql injection.
This vulnerability is handled as CVE-2026-33991. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33991 | LabRedesCefetRJ WeGIA up to 3.6.6 deletar_tag.php deletar_tag $_REQUEST sql injection (EUVD-2026-16884)
1 week 2 days ago
A vulnerability, which was classified as critical, has been found in LabRedesCefetRJ WeGIA up to 3.6.6. This issue affects the function deletar_tag of the file html/socio/sistema/deletar_tag.php. This manipulation of the argument $_REQUEST causes sql injection.
This vulnerability is handled as CVE-2026-33991. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-33936 | tlsfuzzer python-ecdsa up to 0.19.1 ECDSA.der.remove_octet_string denial of service (EUVD-2026-16856 / Nessus ID 304163)
1 week 2 days ago
A vulnerability classified as problematic was found in tlsfuzzer python-ecdsa up to 0.19.1. This vulnerability affects the function ECDSA.der.remove_octet_string. The manipulation results in denial of service.
This vulnerability is known as CVE-2026-33936. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-33936 | tlsfuzzer python-ecdsa up to 0.19.1 ECDSA.der.remove_octet_string denial of service (EUVD-2026-16856)
1 week 2 days ago
A vulnerability classified as problematic was found in tlsfuzzer python-ecdsa up to 0.19.1. This vulnerability affects the function ECDSA.der.remove_octet_string. The manipulation results in denial of service.
This vulnerability is known as CVE-2026-33936. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-4248 | ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress usermeta:password_reset_link improper authorization (EUVD-2026-16901)
1 week 2 days ago
A vulnerability classified as critical has been found in ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress. This affects an unknown part. The manipulation of the argument usermeta:password_reset_link leads to improper authorization.
This vulnerability is traded as CVE-2026-4248. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-4248 | ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress usermeta:password_reset_link improper authorization
1 week 2 days ago
A vulnerability classified as critical has been found in ultimatemember Ultimate Member Plugin up to 2.11.2 on WordPress. This affects an unknown part. The manipulation of the argument usermeta:password_reset_link leads to improper authorization.
This vulnerability is traded as CVE-2026-4248. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com