Threat Intelligence Feed

Aggregating 4633 articles from trusted cybersecurity sources

LATEST CVEs
CVE-2026-78417 Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 a HIGH · CVE-2026-75371 An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically- MED · CVE-2026-75370 An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC sof CVE-2026-71832 Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote MED · CVE-2026-71509 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t MED · CVE-2026-71508 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows MED · CVE-2026-71507 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w HIGH · CVE-2026-71506 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that al HIGH · CVE-2026-71505 Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site accou HIGH · CVE-2026-71504 Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers wi MED · CVE-2026-71503 Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration templa HIGH · CVE-2026-40877 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in th CVE-2026-39975 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly HIGH · CVE-2026-30864 Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scrip CVE-2026-13081 Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs fo CVE-2026-13047 Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs fo CVE-2025-26238 In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code. CVE-2025-26237 D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can b CVE-2026-9254 An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, B MED · CVE-2026-78475 A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin al HIGH · CVE-2026-76838 Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backen MED · CVE-2026-76837 Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/acco HIGH · CVE-2026-76836 AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission gu CRIT · CVE-2026-76835 OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, b HIGH · CVE-2026-76073 Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label HIGH · CVE-2026-76072 The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattende CVE-2026-71982 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. HIGH · CVE-2026-71943 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili HIGH · CVE-2026-71942 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerab HIGH · CVE-2026-71941 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerabil HIGH · CVE-2026-71940 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. HIGH · CVE-2026-71939 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. T HIGH · CVE-2026-71938 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnera HIGH · CVE-2026-71937 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vu HIGH · CVE-2026-71936 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability HIGH · CVE-2026-71935 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnera HIGH · CVE-2026-71934 Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability CRIT · CVE-2026-71933 Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vul MED · CVE-2026-71932 Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulne HIGH · CVE-2026-71931 Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab
3018 general 691 advisories 395 vendor 364 research 165 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.