Threat Intelligence Feed

Aggregating 4637 articles from trusted cybersecurity sources

LATEST CVEs
CVE-2026-78417 Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a HIGH · CVE-2026-75371 An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically- MED · CVE-2026-75370 An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC sof CVE-2026-71832 Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote MED · CVE-2026-71509 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t MED · CVE-2026-71508 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows MED · CVE-2026-71507 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w HIGH · CVE-2026-71506 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al HIGH · CVE-2026-71505 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou HIGH · CVE-2026-71504 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi MED · CVE-2026-71503 Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration templa HIGH · CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th CVE-2026-39975 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly HIGH · CVE-2026-30864 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scrip CVE-2026-13081 Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs fo CVE-2026-13047 Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs fo CVE-2025-26238 In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. CVE-2025-26237 D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b CVE-2026-9254 An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, B MED · CVE-2026-78475 A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin al HIGH · CVE-2026-76838 Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backen MED · CVE-2026-76837 Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/acco HIGH · CVE-2026-76836 AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu CRIT · CVE-2026-76835 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b HIGH · CVE-2026-76073 Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label HIGH · CVE-2026-76072 The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende CVE-2026-71982 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. HIGH · CVE-2026-71943 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili HIGH · CVE-2026-71942 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerab HIGH · CVE-2026-71941 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerabil HIGH · CVE-2026-71940 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. HIGH · CVE-2026-71939 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. T HIGH · CVE-2026-71938 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnera HIGH · CVE-2026-71937 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vu HIGH · CVE-2026-71936 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability HIGH · CVE-2026-71935 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnera HIGH · CVE-2026-71934 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability CRIT · CVE-2026-71933 Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul MED · CVE-2026-71932 Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulne HIGH · CVE-2026-71931 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab
3022 general 691 advisories 395 vendor 364 research 165 enterprise

Trending Vendors

Latest News

Siemens IAM Client

View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacke...

T1548

CISA Advisories → Details

Siemens Opcenter X

View CSAF Summary Opcenter X before V2604 contain an authentication bypass vulnerability that could allow an attacker to gain full unauthorized access to the...

T1556

CISA Advisories → Details

Data Breaches

No articles found.