Pwn2Own Berlin 2026 ended with 47 zero-days and $1.29M in payouts, as DEVCORE dominated the competition across all categories. Pwn2Own Berlin 2026 ended after three intense days, with participants discovering 47 unique zero-days, and earning $1,298,250 in total payouts. Pwn2Own Berlin 2026 wrapped up at OffensiveCon on Saturday with a final day that sealed DEVCORE’s […]
A vulnerability marked as problematic has been reported in Kingsoft WPS Office Free up to 10.2.0.5978. Impacted is an unknown function of the file \.\pipe\WPSCloudSvr\WpsCloudSvr. Performing a manipulation as part of Named Pipe results in improper access controls.
This vulnerability is known as CVE-2018-6400. Attacking locally is a requirement. No exploit is available.
A vulnerability was found in MPD. It has been rated as problematic. Impacted is an unknown function of the component PipeWire Output Plugin. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2022-48363. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability described as problematic has been identified in encoded_id-rails up to 1.0.0.beta1. This affects an unknown part of the component HTTP Request Handler. The manipulation of the argument ID results in resource consumption.
This vulnerability is reported as CVE-2024-0241. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Node.js up to 18.20.1/20.12.1/21.7.2 on Windows. The affected element is the function CreateProcess. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2024-3566. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as problematic has been identified in Formidable up to 3.5.2. The impacted element is an unknown function. Executing a manipulation can lead to cryptographically weak prng.
This vulnerability is handled as CVE-2025-46653. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability identified as problematic has been detected in fastify middie up to 9.0.x. This affects an unknown part. Performing a manipulation results in improper handling of url encoding.
This vulnerability is known as CVE-2026-22031. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability identified as problematic has been detected in Salesforce Marketing Cloud Engagement. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in use of hard-coded cryptographic key
.
This vulnerability is identified as CVE-2026-22586. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability marked as critical has been reported in Orderable Plugin up to 1.20.0 on WordPress. The impacted element is the function install_plugin of the component Plugin Installation Handler. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2026-0974. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability described as critical has been identified in Orderable Plugin up to 1.20.0 on WordPress. This affects the function install_plugin of the component Plugin Installation Handler. The manipulation results in missing authorization.
This vulnerability is identified as CVE-2026-0974. The attack can be executed remotely. There is not any exploit available.
A vulnerability described as critical has been identified in edu Business Solutions Print Shop Pro WebDesk 18.34. Affected is an unknown function. Executing a manipulation of the argument AccessID can lead to improper privilege management.
This vulnerability is registered as CVE-2026-26725. It is possible to launch the attack remotely. No exploit is available.
A vulnerability classified as problematic was found in sticky-notes Sticky Notes Widget 3.0.6. Affected by this vulnerability is an unknown functionality. Such manipulation leads to uncontrolled memory allocation.
This vulnerability is traded as CVE-2021-47973. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in Vxsearch VX Search 13.5.28 and classified as problematic. This issue affects some unknown processing of the component Search Enterprise Service. The manipulation results in unquoted search path.
This vulnerability was named CVE-2021-47974. The attack needs to be approached locally. In addition, an exploit is available.