Currently trending CVE - Hype Score: 5 - Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Currently trending CVE - Hype Score: 21 - A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server restart can reset internal timing mechanisms. This allows a remote attacker, who has previously captured a user's refresh token, to replay that token even ...
Currently trending CVE - Hype Score: 21 - A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can lead to the creation of admin-capable ...
The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims' historical messages. [...]
A vulnerability classified as problematic was found in PowerSchool Employee Access Center 23.10. Affected by this vulnerability is the function eval. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-12425. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, has been found in OpenStack Nova up to 31.3.0/32.2.0/33.0.1. Affected by this issue is some unknown functionality of the component Server Create API. This manipulation causes incorrect resource transfer.
The identification of this vulnerability is CVE-2026-46448. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in langchain-ai langchain-sdk up to 1.2.0. It has been classified as critical. This impacts an unknown function. The manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-48776. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in HCL iControl 4.2.0. It has been classified as problematic. The affected element is an unknown function. This manipulation causes session expiration.
This vulnerability is handled as CVE-2025-62340. The attack can be initiated remotely. There is not any exploit available.
A vulnerability, which was classified as critical, has been found in Microsoft Copilot. Affected by this vulnerability is an unknown functionality. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-42895. The attack can only be initiated within the local network. No exploit exists.
A vulnerability has been found in radvd-project radvdump up to 2.20 and classified as critical. Impacted is the function print_ff of the component Route Information Option Parser. This manipulation causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-48715. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, has been found in PTC Windchill PDMLink and FlexPLM up to 13.1.3.0. This affects an unknown part. This manipulation causes improper input validation.
This vulnerability is handled as CVE-2026-12569. The attack can be initiated remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.
A vulnerability has been found in libssh2 up to 1.11.1 and classified as problematic. Affected by this issue is the function _libssh2_get_string of the file src/packet.c of the component SSH_MSG_EXT_INFO Handler. This manipulation causes infinite loop.
The identification of this vulnerability is CVE-2026-55199. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability was found in libssh2 up to 1.11.1 and classified as critical. This affects the function ssh2_transport_read of the component SSH Handler. Such manipulation leads to integer overflow to buffer overflow.
This vulnerability is referenced as CVE-2026-55200. It is possible to launch the attack remotely. No exploit is available.
It is best practice to apply a patch to resolve this issue.
A vulnerability, which was classified as problematic, has been found in HCL ZIE 16.0. This affects an unknown part of the component File Upload Handler. Performing a manipulation results in information exposure through error message.
This vulnerability is reported as CVE-2025-59872. The attack is possible to be carried out remotely. No exploit exists.