Posts of last few hours
Currently trending CVE - Hype Score: 9 - An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an ...
https://cvemon.intruder.io/cves/CVE-2026-82078
A vulnerability was found in vbpf Prevail up to 0.2.3 and classified as problematic. Affected is an unknown function of the component eBPF Verifier. Such manipulation leads to improper input validation.
This vulnerability is documented as CVE-2026-53706. The attack needs to be performed locally. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/398277
A vulnerability has been found in Pydantic Httpx2 up to 2.10.x and classified as problematic. This impacts the function Request._prepare of the file src/httpx2/httpx2/_models.py of the component Request Framing. This manipulation causes http request smuggling.
This vulnerability is registered as CVE-2026-84380. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/398276
A vulnerability, which was classified as problematic, was found in Pydantic HTTPX2 up to 2.10.x. This affects the function FileField.render_headers of the file src/httpx2/httpx2/_multipart.py of the component Multipart Parser. The manipulation results in injection.
This vulnerability is cataloged as CVE-2026-84379. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/398275
A vulnerability, which was classified as problematic, has been found in Pydantic Httpx2 up to 2.9.x. The impacted element is the function _SSELineDecoder.decode of the file src/httpx2/httpx2/_sse.py of the component Server-Sent Events Parser. The manipulation leads to information exposure through microarchitectural state after transient execution.
This vulnerability is listed as CVE-2026-84378. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/398274
These are the top threats you should know about this week.
https://www.f5.com/labs/articles/weekly-threat-bulletin-september-2nd-2026
A vulnerability classified as critical was found in libjxl up to 0.11.x. The affected element is an unknown function of the component Container Box Parser. Executing a manipulation can lead to integer underflow.
This vulnerability is tracked as CVE-2026-82522. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
https://vuldb.com/vuln/398273
A web-attack monitor. It sits next to nginx / Caddy / the app, tails access logs, and tells you whe
https://buaq.net/go-439658.html
A vulnerability classified as problematic has been found in malach-it boruta-server up to 0.9.x. Impacted is an unknown function. Performing a manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-55221. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/398272
A vulnerability described as problematic has been identified in Malach-IT Boruta Server up to 0.9.x. This issue affects the function BorutaIdentityWeb.UserSettingsController.update of the component UserSettingsController. Such manipulation of the argument User leads to resource consumption.
This vulnerability is referenced as CVE-2026-49249. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/398271
A vulnerability marked as problematic has been reported in BerriAI LiteLLM up to 1.88.5/1.96.1. This vulnerability affects unknown code of the file litellm/proxy/auth/auth_utils.py of the component Request Validation. This manipulation of the argument api_base/base_url/model_list/fallbacks/litellm_credential_name causes server-side request forgery.
The identification of this vulnerability is CVE-2026-84377. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/398270
A vulnerability labeled as problematic has been found in DSpace up to 8.3/9.2/10-rc1. This affects an unknown part of the component Velocity Templates. The manipulation results in code injection.
This vulnerability was named CVE-2026-49832. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/398269
A vulnerability identified as critical has been detected in BishopFox Joro up to 1.1.0. Affected by this issue is some unknown functionality of the component Default Proxy Mode. The manipulation leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-53649. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
https://vuldb.com/vuln/398268
A vulnerability marked as critical has been reported in Node.js up to 22.23.1/24.18.0/26.5.0. This issue affects the function trace_events.createTracing.enable of the component Permission Model. This manipulation causes permission issues.
The identification of this vulnerability is CVE-2026-56847. It is possible to initiate the attack remotely. There is no exploit available.
https://vuldb.com/vuln/384620
A vulnerability was found in Node.js and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTPS Agent. Such manipulation leads to improper certificate validation.
This vulnerability is documented as CVE-2026-56850. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/384627
A vulnerability was found in Node.js up to 22.23.1/24.18.0/26.5.0. It has been declared as critical. Impacted is the function nghttp2_session_mem_send of the component HTTP2. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2026-56848. The attack may be launched remotely. There is no exploit available.
https://vuldb.com/vuln/385875
A vulnerability was found in nodejs Node.js up to 22.23.1/24.18.0. It has been declared as problematic. This affects an unknown function of the component HTTP2. The manipulation results in uncontrolled memory allocation.
This vulnerability is cataloged as CVE-2026-56846. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/385735
A vulnerability described as critical has been identified in Go. This impacts an unknown function of the component x-mod-sumdb-tlog. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is handled as CVE-2026-56865. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/389927
A vulnerability categorized as problematic has been discovered in Node.js up to 22.22.3/24.16.0/26.3.0. This vulnerability affects unknown code. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-48934. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/374103
A vulnerability, which was classified as problematic, has been found in Go crypto tls up to 1.25.12/1.26.5. This impacts an unknown function of the component Client Handler. The manipulation leads to allocation of resources.
This vulnerability is referenced as CVE-2026-56862. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/389916
Latest Blog Posts
- 1 week 4 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 7 months ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago