Aggregator
Submit #759594 / VDB-347674
Submit #759589: Tenda F453 v1.0.0.3 Buffer Access Using Size of Source Buffer [Accepted]
4 months ago
Submit #759589 / VDB-347673
LtzHust
Submit #759587: Tenda F453 v1.0.0.3 Buffer Access Using Size of Source Buffer [Accepted]
4 months ago
Submit #759587 / VDB-347672
LtzHust
Submit #759546: itsourcecode News Portal Project V1.0 sql [Accepted]
4 months ago
Submit #759546 / VDB-347671
Chen Yang
Submit #758932: SourceCodester Website Link Extractor 1.0 (or Latest) Server-Side Request Forgery (SSRF) [Accepted]
4 months ago
Submit #758932 / VDB-347670
Hemant Raj Bhati
Wynn Resorts confirms employee data breach after extortion threat
4 months ago
Wynn Resorts has confirmed that a hacker stole employee data from its systems after the company was listed on the ShinyHunters extortion gang's data leak site. [...]
Lawrence Abrams
1Campaign platform helps malicious Google ads evade detection
4 months ago
A newly identified cybercrime service known as 1Campaign is enabling threat actors to run malicious Google Ads that remain online for extended periods while evading scrutiny from security researchers. [...]
Bill Toulas
Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker
4 months ago
Additionally, the U.S. Treasury sanctioned the Russian zero-day brokerage that Peter Williams sold the exploits to.
The post Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker appeared first on CyberScoop.
Greg Otto
CVE-2025-46320 | Claris FileMaker Server up to 21.1.6/22.0.3 cross site scripting
4 months ago
A vulnerability was found in Claris FileMaker Server up to 21.1.6/22.0.3. It has been declared as problematic. This affects an unknown part. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2025-46320. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-23858 | Dell Wyse Management Suite up to 5.4 cross site scripting (dsa-2026-103)
4 months ago
A vulnerability was found in Dell Wyse Management Suite up to 5.4. It has been classified as problematic. Affected by this issue is some unknown functionality. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-23858. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
US sanctions Russian exploit broker for buying cyber tools stolen from defense contractor
4 months ago
The Treasury Department sanctioned a Russian national and his company for allegedly acquiring eight proprietary cyber tools that were stolen from the defense contractor L3Harris and sold to "unauthorized" customers.
CVE-2026-27195 | bytecodealliance wasmtime up to 40.0.3/41.0.3 exceptional condition
4 months ago
A vulnerability was found in bytecodealliance wasmtime up to 40.0.3/41.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality. Such manipulation leads to handling of exceptional conditions.
This vulnerability is documented as CVE-2026-27195. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-25899 | gofiber up to 3.0.x fiber_flash memory allocation
4 months ago
A vulnerability has been found in gofiber fiber up to 3.0.x and classified as problematic. Affected is an unknown function. This manipulation of the argument fiber_flash causes uncontrolled memory allocation.
This vulnerability is registered as CVE-2026-25899. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-25891 | gofiber up to 3.0.x on Windows path traversal
4 months ago
A vulnerability, which was classified as critical, was found in gofiber fiber up to 3.0.x on Windows. This impacts an unknown function. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-25891. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-25882 | gofiber up to 2.52.11/3.0.x Registration array index (GHSA-mrq8-rjmw-wpq3)
4 months ago
A vulnerability, which was classified as problematic, has been found in gofiber fiber up to 2.52.11/3.0.x. This affects an unknown function of the component Registration Handler. The manipulation leads to improper validation of array index.
This vulnerability is listed as CVE-2026-25882. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-24443 | Netikus EventSentry up to 6.0.1.20 Web Reports Interface unverified password change
4 months ago
A vulnerability classified as critical was found in Netikus EventSentry up to 6.0.1.20. The impacted element is an unknown function of the component Web Reports Interface. Executing a manipulation can lead to unverified password change.
This vulnerability is tracked as CVE-2026-24443. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-23859 | Dell Wyse Management Suite up to 5.4 client-side enforcement of server-side security (dsa-2026-103)
4 months ago
A vulnerability classified as problematic has been found in Dell Wyse Management Suite up to 5.4. The affected element is an unknown function. Performing a manipulation results in client-side enforcement of server-side security.
This vulnerability is identified as CVE-2026-23859. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Attackers Now Need Just 29 Minutes to Own a Network
4 months ago
Credential misuse, AI tools, and security blind spots help attackers move through breached networks faster than ever, CrowdStrike finds.
Jai Vijayan
Operation Red Card 2.0: Cybercrime Disruption
4 months ago
Nisos
Operation Red Card 2.0: Cybercrime Disruption
On February 18, 2026, INTERPOL announced the results of Operation Red Card 2.0, a sweeping multinational law enforcement action targeting online scams across sixteen African countries...
The post Operation Red Card 2.0: Cybercrime Disruption appeared first on Nisos by Nisos
The post Operation Red Card 2.0: Cybercrime Disruption appeared first on Security Boulevard.
Nisos
Legit License Scanning and Policy Enforcement
4 months ago
Liav Caspi