Threat Intelligence Feed

Aggregating 8031 articles from trusted cybersecurity sources

LATEST CVEs
CRIT · CVE-2026-92288 Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth CVE-2026-85417 Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be reco CVE-2026-53493 containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI CVE-2026-85082 Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely sep CVE-2026-84283 Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-stor CVE-2026-97387 Rejected reason: This CVE is a duplicate of another CVE. CRIT · CVE-2026-97230 IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated U MED · CVE-2026-97636 Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-co CVE-2026-87722 Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, CVE-2026-87721 Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerr CVE-2026-87720 Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction l HIGH · CVE-2026-85491 Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorizat MED · CVE-2026-97368 A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInf MED · CVE-2026-97366 A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function CRIT · CVE-2026-95699 Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT MED · CVE-2026-93353 copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users HIGH · CVE-2026-88388 Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace CVE-2026-88387 LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF ta MED · CVE-2026-88386 libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec MED · CVE-2026-87118 The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona MED · CVE-2026-84403 The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access MED · CVE-2026-82716 The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag MED · CVE-2026-82708 The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce MED · CVE-2026-82585 The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An at HIGH · CVE-2026-81630 The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update proce MED · CVE-2026-79959 The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. A MED · CVE-2026-75558 The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi cre CVE-2026-14443 Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extensio CVE-2026-14442 An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be writt CVE-2026-14441 A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when pro MED · CVE-2026-97365 A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file cr HIGH · CVE-2026-97326 A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this i MED · CVE-2026-97325 A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability HIGH · CVE-2026-97324 A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoO HIGH · CVE-2026-96883 pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 m HIGH · CVE-2026-93354 Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers t CRIT · CVE-2026-93291 Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which c MED · CVE-2026-93290 Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access i HIGH · CVE-2026-93289 The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute MED · CVE-2026-88956 The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the
5454 general 1015 advisories 729 research 551 vendor 282 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.