Posts of last few hours
A vulnerability classified as problematic was found in Microsoft winml-cli up to 0.3.x. This impacts the function AutoConfig.from_pretrained of the file src/winml/modelkit/loader/_autoconfig.py of the component CLI API. The manipulation of the argument trust_remote_code results in permissive cross-domain policy with untrusted domains.
This vulnerability is identified as CVE-2026-84452. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/398287
A vulnerability classified as problematic has been found in Septeo IT Solutions UpSignOn up to 7.18.x. This affects an unknown function of the file UpSignOn.exe. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-75137. The attack can only be performed from a local environment. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/398286
A vulnerability described as problematic has been identified in Septeo IT Solutions UpSignOn up to 7.18.x. The impacted element is an unknown function. Executing a manipulation can lead to missing encryption of sensitive data.
The identification of this vulnerability is CVE-2026-75136. The attack can only be executed locally. There is no exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/398285
A vulnerability marked as problematic has been reported in Septeo IT Solutions UpSignOn up to 7.18.x. The affected element is an unknown function of the file UpSignOn.exe. Performing a manipulation results in information disclosure.
This vulnerability was named CVE-2026-75135. The attack needs to be approached locally. There is no available exploit.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/398284
A vulnerability labeled as problematic has been found in SEOWriting Plugin up to 1.12.5. Impacted is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-75134. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/398283
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/
A vulnerability identified as critical has been detected in Delinea Secret Server up to 11.7.61/11.8.1/11.9.47/12.0.22/12.1.2. This issue affects some unknown processing. This manipulation causes improper authentication.
This vulnerability is handled as CVE-2026-19117. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/398282
A vulnerability categorized as problematic has been discovered in pydantic httpx2 up to 2.11.x. This vulnerability affects the function iter_bytes/aiter_bytes of the file src/httpx2/httpx2/_decoders.py of the component Content Decoders. The manipulation results in allocation of resources.
This vulnerability is known as CVE-2026-84382. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/398281
A vulnerability was found in Pydantic HTTPX2 and httpcore2 up to 2.9.1. It has been rated as problematic. This affects the function Client.websocket/AsyncClient.websocket of the file src/httpcore2/httpcore2/_sync/socks_proxy.py of the component SOCKS Proxy. The manipulation leads to improper certificate validation.
This vulnerability is traded as CVE-2026-84381. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/398280
A vulnerability was found in vbpf Prevail up to 0.2.3. It has been declared as critical. Affected by this issue is the function do_mem_store of the file src/crab/ebpf_transformer.cpp of the component Abstract Transformer. Executing a manipulation can lead to memory corruption.
This vulnerability appears as CVE-2026-53671. The attack requires local access. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/398279
A vulnerability was found in vbpf Prevail up to 0.2.3. It has been classified as very critical. Affected by this vulnerability is the function EbpfTransformer::add of the component eBPF Verifier. Performing a manipulation results in memory corruption.
This vulnerability is reported as CVE-2026-53670. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/398278
Currently trending CVE - Hype Score: 1 - Heap-based buffer overflow in Windows HTTP.sys allows an authorized attacker to elevate privileges locally.
https://cvemon.intruder.io/cves/CVE-2026-62735
Currently trending CVE - Hype Score: 6 - Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
https://cvemon.intruder.io/cves/CVE-2026-84122
Currently trending CVE - Hype Score: 9 - Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
https://cvemon.intruder.io/cves/CVE-2026-62911
Currently trending CVE - Hype Score: 11 - Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated ...
https://cvemon.intruder.io/cves/CVE-2026-83549
Currently trending CVE - Hype Score: 12 - A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and ...
https://cvemon.intruder.io/cves/CVE-2026-83548
Currently trending CVE - Hype Score: 26 - This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information ...
https://cvemon.intruder.io/cves/CVE-2026-84148
Currently trending CVE - Hype Score: 26 - This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and ...
https://cvemon.intruder.io/cves/CVE-2026-84149
Currently trending CVE - Hype Score: 26 - This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the ...
https://cvemon.intruder.io/cves/CVE-2026-84147
Currently trending CVE - Hype Score: 14 - An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation ...
https://cvemon.intruder.io/cves/CVE-2026-81578
Latest Blog Posts
- 1 week 4 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 7 months ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago