Threat Intelligence Feed

Aggregating 7582 articles from trusted cybersecurity sources

LATEST CVEs
MED · CVE-2026-92568 MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows MED · CVE-2026-92567 TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update HIGH · CVE-2026-92566 DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that a MED · CVE-2026-92565 Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns sched CRIT · CVE-2026-92395 @fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and i MED · CVE-2026-92383 A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControl CVE-2026-92381 A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/ HIGH · CVE-2026-92380 A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file core HIGH · CVE-2026-92366 A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search HIGH · CVE-2026-92087 @fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route MED · CVE-2026-89031 Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records o MED · CVE-2026-88976 Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0. HIGH · CVE-2026-88064 Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backst HIGH · CVE-2026-84997 react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, Re HIGH · CVE-2026-84860 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints b MED · CVE-2026-84859 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search e HIGH · CVE-2026-84858 ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Byp HIGH · CVE-2026-82964 Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low- CVE-2026-82410 Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middlew HIGH · CVE-2026-80274 If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a val HIGH · CVE-2026-79651 A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service respo CVE-2026-77412 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-ar CVE-2026-77411 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil CVE-2026-77410 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the messa CVE-2026-77409 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in conf CVE-2026-77408 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte le CVE-2026-77407 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as CVE-2026-77406 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount CVE-2026-77405 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values wit CVE-2026-77404 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CAC CVE-2026-77403 RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-ad MED · CVE-2026-77401 Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untruste MED · CVE-2026-77119 A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure deleg HIGH · CVE-2026-76825 RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted en HIGH · CVE-2026-76163 If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of MED · CVE-2026-75029 In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SO HIGH · CVE-2026-74909 Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security p HIGH · CVE-2026-63671 MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nu HIGH · CVE-2026-63128 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP s HIGH · CVE-2026-63127 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in cr
5086 general 974 advisories 720 research 534 vendor 268 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.