Aggregator
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month 1 week hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
3 days 16 hours hence
CVE-2026-96940
3 hours ago
Currently trending CVE - Hype Score: 10 - Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
CVE-2026-100520
3 hours ago
Currently trending CVE - Hype Score: 16 - Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to ...
CVE-2026-40281
3 hours ago
Currently trending CVE - Hype Score: 15 - Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line ...
CVE-2026-102489
3 hours ago
Currently trending CVE - Hype Score: 7 - Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
CVE-2026-102490
3 hours ago
Currently trending CVE - Hype Score: 6 - All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
CVE-2026-104286
3 hours ago
Currently trending CVE - Hype Score: 3 - An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write ...
CVE-2024-58388
3 hours ago
Currently trending CVE - Hype Score: 2 - Sharp (and Toshiba Tec rebranded) multifunction printers contain an unauthenticated local file inclusion vulnerability that allows remote attackers to read arbitrary files by manipulating the path parameter in the installed_emanual_down.html endpoint. Attackers can supply ...
CVE-2026-61500
3 hours ago
Currently trending CVE - Hype Score: 10 - Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, ...
CVE-2026-88772
3 hours ago
Currently trending CVE - Hype Score: 5 - Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or ...
CVE-2026-88771
3 hours ago
Currently trending CVE - Hype Score: 4 - Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway.
This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading ...
Взрыв. Ещё взрыв. Снова взрыв. Hubble ждёт, когда Вселенная покажет ту же сверхновую ещё раз
4 hours 2 minutes ago
Спустя 36 лет Hubble продолжает измерять Вселенную и помогает искать ответ на спор о постоянной Хаббла.
CVE-2026-105218 | go-pay gopay up to 1.5.118 os command injection
4 hours 32 minutes ago
A vulnerability described as critical has been identified in go-pay gopay up to 1.5.118. This vulnerability affects unknown code. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-105218. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-105216 | micro go-micro up to 5.x information disclosure
4 hours 32 minutes ago
A vulnerability marked as problematic has been reported in micro go-micro up to 5.x. This affects an unknown part. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2026-105216. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-105217 | Cockpit-HQ Cockpit up to 2.14.0 information disclosure
4 hours 33 minutes ago
A vulnerability labeled as problematic has been found in Cockpit-HQ Cockpit up to 2.14.0. Affected by this issue is some unknown functionality. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2026-105217. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-105251 | vgmstream up to r2117 VAG File src/coding/psx_decoder.c ps_find_padding out-of-bounds (Issue 2000)
4 hours 34 minutes ago
A vulnerability identified as critical has been detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-105251. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to install a patch to address this issue.
vuldb.com
CVE-2026-105250 | vgmstream up to r2117 Microsoft IMA Decoder src/coding/ima_decoder.c decode_ms_ima divide by zero (Issue 1999)
4 hours 34 minutes ago
A vulnerability categorized as problematic has been discovered in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero.
This vulnerability is documented as CVE-2026-105250. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-105249 | vgmstream up to r2117 TXTP File src/meta/txtp_process.c make_group_random use after free (Issue 1998)
4 hours 35 minutes ago
A vulnerability was found in vgmstream up to r2117. It has been rated as problematic. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-105249. The attack needs to be launched locally. No exploit is available.
It is recommended to apply a patch to fix this issue.
vuldb.com