Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Vulnerability Disclosure

20 articles

Zero Day Initiative Vulnerability Disclosure Apr 15

ZDI-26-267: Malwarebytes Anti-Malware Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Malwarebytes Anti-Malware. An attacker must first obtain the ab...

T1548 T1068

Zero Day Initiative →

Zero Day Initiative Vulnerability Disclosure Docker Apr 15

ZDI-26-261: (0Day) Docker Desktop credentialHelper Directory Traversal Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to es...

T1548

Zero Day Initiative →

Zero Day Initiative Vulnerability Disclosure Docker Apr 15

ZDI-26-260: (0Day) Docker Desktop System Editor Uncontrolled Search Path Element Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop. An attacker must first obtain the ability to es...

T1548

Zero Day Initiative →

Zero Day Initiative Vulnerability Disclosure Microsoft Docker Apr 15

ZDI-26-259: (0Day) Docker Desktop cli-plugins Incorrect Permission Assignment Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop for Windows. An attacker must first obtain the a...

T1548 T1068

Zero Day Initiative →

Zero Day Initiative Vulnerability Disclosure Microsoft Docker Apr 15

ZDI-26-258: (0Day) Docker Desktop extension-manager Exposed Dangerous Function Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Docker Desktop for Windows. An attacker must first obtain the a...

T1548 T1068

Zero Day Initiative →

Wordfence Blog Vulnerability Disclosure Intel WordPress Apr 13

Attackers Actively Exploiting Critical Vulnerability in Kali Forms Plugin

On March 2nd, 2026, we received a submission through our Bug Bounty Program for a Remote Code Execution vulnerability in Kali Forms, a WordPress plugin with ...

T1190

Wordfence Blog →

Wordfence Blog Vulnerability Disclosure WordPress Apr 10

The Increasing Role of AI in Vulnerability Research

At Wordfence, we run a bug bounty program that pays out mid-six figures per year to researchers in bug bounties for WordPress related vulnerabilities. Fundin...

Wordfence Blog →

Exploit Database Vulnerability Disclosure Apr 10

[local] NetBT e-Fatura - Privilege Escalation

NetBT e-Fatura - Privilege Escalation

T1548

Exploit Database →

Wordfence Blog Vulnerability Disclosure Intel WordPress Apr 9

Wordfence Intelligence Weekly WordPress Vulnerability Report (March 30, 2026 to April 5, 2026)

Last week, there were disclosed in that have been added to the Wordfence Intelligence Vulnerability Database, and there were that contributed to WordPress Se...

Wordfence Blog →

SentinelOne Blog Vulnerability Disclosure Apr 9

Edge Decay: How a Failing Perimeter Is Fueling Modern Intrusions

Edge devices are prime targets — learn how attackers exploit the perimeter to gain access, persist, and pivot to identity.

SentinelOne Blog →

Exploit Database Vulnerability Disclosure Apr 9

[webapps] React Server 19.2.0 - Remote Code Execution

React Server 19.2.

T1190

Exploit Database →

Exploit Database Vulnerability Disclosure Apr 9

[webapps] Jumbo Website Manager - Remote Code Execution

Jumbo Website Manager - Remote Code Execution

T1190

Exploit Database →

Exploit Database Vulnerability Disclosure Apr 9

[local] ZSH 5.9 - RCE

ZSH 5.

Exploit Database →

Unit 42 Vulnerability Disclosure Amazon Apr 8

Cracks in the Bedrock: Agent God Mode

Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks.

T1548 T1041

Unit 42 →

Infosecurity Magazine Vulnerability Disclosure WordPress Apr 8

Critical Vulnerability in Ninja Forms Exposes WordPress Sites

Ninja Forms File Upload RCE via unauthenticated arbitrary file upload; update to 3.3.

Infosecurity Magazine →

Infosecurity Magazine Vulnerability Disclosure Apache Apr 8

Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years

Anthropic’s Claude AI has helped researchers find a vulnerability in Apache ActiveMQ Classic

Infosecurity Magazine →

Exploit Database Vulnerability Disclosure Apr 8

[webapps] FortiWeb 8.0.2 - Remote Code Execution

FortiWeb 8.0.

T1190

Exploit Database →

Exploit Database Vulnerability Disclosure Apr 8

[webapps] xibocms 3.3.4 - RCE

xibocms 3.3.

Exploit Database →

Infosecurity Magazine Vulnerability Disclosure Apr 7

GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise

GPUBreach uses GPU Rowhammer on GDDR6 to flip bits, corrupt page tables and escalate to system root

T1548

Infosecurity Magazine →

Infosecurity Magazine Vulnerability Disclosure Amazon Apr 7

GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration

GrafanaGhost chains AI prompt injection and URL flaws to exfiltrate sensitive Grafana data

T1041

Infosecurity Magazine →

«Previous page 1 ... 14 15 16 17 18 ... 20 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA