Aggregator
CVE-2026-4342
1 month 1 week ago
ingress-nginx comment-based nginx configuration injection
Microsoft security advisory – January 2026 monthly rollup (AV26-024) – Update 2
1 month 1 week ago
Canadian Centre for Cyber Security
CVE-2026-3864 | Kubernetes CSI Driver subDir path traversal
1 month 1 week ago
A vulnerability was found in Kubernetes. It has been classified as critical. Affected is an unknown function of the component CSI Driver. The manipulation of the argument subDir leads to path traversal.
This vulnerability is listed as CVE-2026-3864. The attack must be carried out from within the local network. There is no available exploit.
vuldb.com
87 ML-моделей, 25 000 событий в секунду и детект Kerberoasting. Positive Technologies выпустила MaxPatrol SIEM 27.6
1 month 1 week ago
Представлена новая версия системы мониторинга событий ИБ.
Financial Brands Targeted in Global Mobile Banking Malware Surge
1 month 1 week ago
Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices
CVE-2025-71258 | BMC FootPrints up to 20.24.01.001 searchWeb API server-side request forgery
1 month 1 week ago
A vulnerability was found in BMC FootPrints up to 20.24.01.001 and classified as critical. This impacts an unknown function of the component searchWeb API. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2025-71258. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-71259 | BMC FootPrints up to 20.24.01.001 Feed API server-side request forgery
1 month 1 week ago
A vulnerability has been found in BMC FootPrints up to 20.24.01.001 and classified as critical. This affects an unknown function of the component Feed API. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2025-71259. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-4426 | libarchive ISO File Parser pz_log2_bs incorrect bitwise shift of integer
1 month 1 week ago
A vulnerability, which was classified as problematic, was found in libarchive. The impacted element is an unknown function of the component ISO File Parser. Such manipulation of the argument pz_log2_bs leads to incorrect bitwise shift of integer.
This vulnerability is referenced as CVE-2026-4426. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-71257 | BMC FootPrints up to 20.24.01.001 REST API Endpoint missing authentication
1 month 1 week ago
A vulnerability, which was classified as critical, has been found in BMC FootPrints up to 20.24.01.001. The affected element is an unknown function of the component REST API Endpoint. This manipulation causes missing authentication.
The identification of this vulnerability is CVE-2025-71257. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-4424 | libarchive RAR out-of-bounds
1 month 1 week ago
A vulnerability classified as problematic was found in libarchive. Impacted is an unknown function of the component RAR Handler. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-4424. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-71260 | BMC FootPrints up to 20.24.01.001 ASP.NET Servlet VIEWSTATE deserialization
1 month 1 week ago
A vulnerability classified as critical has been found in BMC FootPrints up to 20.24.01.001. This issue affects some unknown processing of the component ASP.NET Servlet. The manipulation of the argument VIEWSTATE leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-71260. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-30951 | Sequelize up to 6.37.7 _traverseJSON sql injection (GHSA-6457-6jrx-69cr / Nessus ID 301792)
1 month 1 week ago
A vulnerability has been found in Sequelize up to 6.37.7 and classified as critical. Affected by this vulnerability is the function _traverseJSON. This manipulation causes sql injection.
This vulnerability is registered as CVE-2026-30951. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-30952 | harttle liquidjs up to 10.24.x path traversal (GHSA-wmfp-5q7x-987x)
1 month 1 week ago
A vulnerability was found in harttle liquidjs up to 10.24.x and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-30952. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-31954 | Emlog up to 2.6.6 LoginAuth::checkToken cross-site request forgery
1 month 1 week ago
A vulnerability identified as problematic has been detected in Emlog up to 2.6.6. The impacted element is the function LoginAuth::checkToken. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-31954. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-32102 | OliveTin up to 3000.10.1 access control (GHSA-228v-wc5r-j8m7)
1 month 1 week ago
A vulnerability was found in OliveTin up to 3000.10.1. It has been classified as critical. Affected by this issue is some unknown functionality. This manipulation causes improper access controls.
This vulnerability appears as CVE-2026-32102. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-32101 | studiocms up to 0.3.0 PUT isAuthorized authorization (GHSA-mm78-fgq8-6pgr)
1 month 1 week ago
A vulnerability was found in studiocms up to 0.3.0. It has been declared as critical. Affected by this vulnerability is the function isAuthorized of the component PUT Handler. Such manipulation leads to incorrect authorization.
This vulnerability is documented as CVE-2026-32101. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-31815 | django-commons django-unicorn up to 0.66.x access control (GHSA-ffv6-jj46-x367)
1 month 1 week ago
A vulnerability was found in django-commons django-unicorn up to 0.66.x. It has been declared as critical. This vulnerability affects unknown code. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2026-31815. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-31837 | Istio up to 1.27.7/1.28.4/1.29.0 information disclosure (GHSA-v75c-crr9-733c)
1 month 1 week ago
A vulnerability was found in Istio up to 1.27.7/1.28.4/1.29.0 and classified as problematic. This impacts an unknown function. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-31837. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-31838 | Istio up to 1.27.7/1.28.4/1.29.0 authorization (GHSA-974c-2wxh-g4ww)
1 month 1 week ago
A vulnerability marked as problematic has been reported in Istio up to 1.27.7/1.28.4/1.29.0. This affects an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-31838. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com