Threat Intelligence Feed

Aggregating 5005 articles from trusted cybersecurity sources

LATEST CVEs
HIGH · CVE-2026-68861 Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS CVE-2026-68000 The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directl MED · CVE-2026-67275 Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerabi CVE-2026-66003 Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access CRIT · CVE-2026-60004 Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. CVE-2026-56547 The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler CVE-2026-54245 Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional a MED · CVE-2026-49809 Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used i MED · CVE-2026-47848 In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client MED · CVE-2026-47844 In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for CVE-2026-47843 In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrect MED · CVE-2026-47842 Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as th MED · CVE-2026-47834 Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted MED · CVE-2026-46371 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M MED · CVE-2026-46370 Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels HIGH · CVE-2026-46369 Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through HIGH · CVE-2026-26449 In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null poi CRIT · CVE-2026-26448 Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, HIGH · CVE-2026-26447 Stomper 5e2741e is vulnerable to Use-After-Free. When a single client repeatedly issues SUBSCRIBE commands for the same HIGH · CVE-2026-26446 Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was alread CVE-2026-26445 stomper 5e2741e is vulnerable to Denial of Service. A malicious client can send partial STOMP frames and keep the TCP co CVE-2025-70340 A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms CVE-2025-70293 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b CRIT · CVE-2025-70290 An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c MED · CVE-2026-79940 Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con MED · CVE-2026-75466 libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexe CRIT · CVE-2026-75325 DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param HIGH · CVE-2026-71171 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an CRIT · CVE-2026-70419 Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an MED · CVE-2026-63179 Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, au CRIT · CVE-2026-51106 An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.c MED · CVE-2026-48786 Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp MED · CVE-2026-41262 Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read HIGH · CVE-2026-36851 Path traversal vulnerability in UnPoller 2.33.0 password field allows arbitrary file read and network exfiltration. CVE-2026-19485 A Predictable Resource Name vulnerability in BigQuery Import Staging in Google Cloud Vertex AI Search for Commerce versi CRIT · CVE-2025-61165 An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac HIGH · CVE-2025-61164 Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. CRIT · CVE-2025-61163 Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This HIGH · CVE-2025-61162 Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req CVE-2026-76784 Multiple TP-Link Kasa smart home devices contain insufficient cryptographic protections in the local device communicatio
3224 general 705 advisories 495 research 411 vendor 170 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.