Aggregator
CISA warns of cyberattacks targeting fuel tank monitoring systems
3 weeks 3 days ago
CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors. [...]
Lawrence Abrams
CVE-2026-26378 | Koha up to 25.11 Invoice Feature cross site scripting
3 weeks 3 days ago
A vulnerability was found in Koha up to 25.11. It has been classified as problematic. Impacted is an unknown function of the component Invoice Feature. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2026-26378. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-8876 | Securly Chrome Extension up to 3.0.7 securly.min.js hard-coded key
3 weeks 3 days ago
A vulnerability was found in Securly Chrome Extension up to 3.0.7 and classified as problematic. This issue affects some unknown processing of the file securly.min.js. Executing a manipulation can lead to use of hard-coded cryptographic key
.
This vulnerability appears as CVE-2026-8876. The attacker needs to be present on the local network. There is no available exploit.
vuldb.com
CVE-2026-8889 | Securly Chrome Extension up to 3.0.7 weak hash
3 weeks 3 days ago
A vulnerability has been found in Securly Chrome Extension up to 3.0.7 and classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in use of weak hash.
This vulnerability is reported as CVE-2026-8889. The attacker must have access to the local network to execute the attack. No exploit exists.
vuldb.com
CVE-2026-36612 | Mercusys AC12G
3 weeks 3 days ago
A vulnerability, which was classified as problematic, was found in Mercusys AC12G. This affects an unknown part. Such manipulation leads to an unknown weakness.
This vulnerability is documented as CVE-2026-36612. The attack requires being on the local network. There is not any exploit available.
vuldb.com
CVE-2026-8879 | Securly Chrome Extension up to 3.0.7 content13.min.js chrome.scripting.registerContentScripts inclusion of functionality from untrusted control sphere
3 weeks 3 days ago
A vulnerability, which was classified as critical, has been found in Securly Chrome Extension up to 3.0.7. Affected by this issue is the function chrome.scripting.registerContentScripts of the file content13.min.js. This manipulation causes inclusion of functionality from untrusted control sphere.
This vulnerability is registered as CVE-2026-8879. The attack requires access to the local network. No exploit is available.
vuldb.com
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels
3 weeks 3 days ago
He told lawmakers that he wants approximately 600 more people than it has now, which would still be well below personnel numbers prior to Trump’s second term.
The post DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels appeared first on CyberScoop.
Tim Starks
CVE-2024-4604 | Magarsus Consultancy SSO 1.0 redirect
3 weeks 3 days ago
A vulnerability described as problematic has been identified in Magarsus Consultancy SSO 1.0. This affects an unknown function. Such manipulation leads to open redirect.
This vulnerability is referenced as CVE-2024-4604. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2024-4228 | Magarsus Consultancy SSO 1.0 sql injection
3 weeks 3 days ago
A vulnerability, which was classified as critical, has been found in Magarsus Consultancy SSO 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is listed as CVE-2024-4228. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-0947 | Talya Informatics Elektraweb up to 17.0.67 cookie validation
3 weeks 3 days ago
A vulnerability was found in Talya Informatics Elektraweb up to 17.0.67. It has been declared as critical. The affected element is an unknown function. The manipulation results in cookies without validation.
This vulnerability is cataloged as CVE-2024-0947. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-0949 | Talya Informatics Elektraweb up to 17.0.67 access control
3 weeks 3 days ago
A vulnerability categorized as critical has been discovered in Talya Informatics Elektraweb up to 17.0.67. This affects an unknown function. Such manipulation leads to improper access controls.
This vulnerability is documented as CVE-2024-0949. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-1107 | Talya Informatics Travel APPS prior 17.0.68 authorization
3 weeks 3 days ago
A vulnerability labeled as very critical has been found in Talya Informatics Travel APPS. Affected is an unknown function. Executing a manipulation can lead to authorization bypass.
This vulnerability appears as CVE-2024-1107. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2024-1153 | Talya Informatics Travel APPS prior 17.0.68 access control
3 weeks 3 days ago
A vulnerability marked as critical has been reported in Talya Informatics Travel APPS. Affected by this vulnerability is an unknown functionality. The manipulation leads to improper access controls.
This vulnerability is traded as CVE-2024-1153. It is possible to launch the attack on the physical device. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-4341 | ExtremePacs Extreme XDS up to 3927 privileges management
3 weeks 3 days ago
A vulnerability has been found in ExtremePacs Extreme XDS up to 3927 and classified as critical. Affected by this issue is some unknown functionality. This manipulation causes improper privilege management.
The identification of this vulnerability is CVE-2024-4341. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2024-5618 | PruvaSoft Informatics Apinizer Management Console prior 2024.05.1 permission assignment
3 weeks 3 days ago
A vulnerability, which was classified as very critical, was found in PruvaSoft Informatics Apinizer Management Console. This impacts an unknown function. The manipulation results in incorrect permission assignment.
This vulnerability is identified as CVE-2024-5618. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2024-5620 | PruvaSoft Informatics Apinizer Management Console prior 2024.05.1 authentication bypass
3 weeks 3 days ago
A vulnerability marked as critical has been reported in PruvaSoft Informatics Apinizer Management Console. The impacted element is an unknown function. Performing a manipulation results in authentication bypass using alternate channel.
This vulnerability is known as CVE-2024-5620. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2024-5619 | PruvaSoft Informatics Apinizer Management Console prior 2024.05.1 authorization
3 weeks 3 days ago
A vulnerability classified as critical has been found in PruvaSoft Informatics Apinizer Management Console. This impacts an unknown function. The manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2024-5619. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
Tropical Blend: Cyber & Politics Ramp Up Across Latin America
3 weeks 3 days ago
China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.
Robert Lemos
Broadcom VMware security advisory (AV26-548)
3 weeks 3 days ago
Canadian Centre for Cyber Security