Aggregator
Secure Your Spot at RSAC 2026 Conference
3 weeks 5 days hence
[Virtual Event] Shields Up: Key Technologies Reshaping Cybersecurity Defenses
3 weeks 1 day hence
Weekly Threat Bulletin – February 25th, 2026
14 hours 7 minutes hence
These are the top threats you should know about this week.
CVE-2021-1730 | Microsoft Exchange Server 2016 CU18/2019 CU7
38 minutes 4 seconds ago
A vulnerability, which was classified as problematic, has been found in Microsoft Exchange Server 2016 CU18/2019 CU7. This affects an unknown function. Performing a manipulation results in an unknown weakness.
This vulnerability is known as CVE-2021-1730. Remote exploitation of the attack is possible. No exploit is available.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2021-26887 | Microsoft Windows up to Server 2019 privileges management
38 minutes 4 seconds ago
A vulnerability categorized as critical has been discovered in Microsoft Windows. This vulnerability affects unknown code. The manipulation results in improper privilege management.
This vulnerability is identified as CVE-2021-26887. The attack is only possible with local access. There is not any exploit available.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2020-7346 | McAfee Data Loss Prevention up to 11.5.3 on Windows privileges management (SB10344)
38 minutes 4 seconds ago
A vulnerability was found in McAfee Data Loss Prevention on Windows. It has been rated as critical. Impacted is an unknown function. The manipulation leads to improper privilege management.
This vulnerability is referenced as CVE-2020-7346. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2021-23892 | McAfee Endpoint Security on Linux Installation toctou (SB10355)
38 minutes 4 seconds ago
A vulnerability described as critical has been identified in McAfee Endpoint Security on Linux. Affected by this issue is some unknown functionality of the component Installation. Such manipulation leads to time-of-check time-of-use.
This vulnerability is documented as CVE-2021-23892. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2021-31838 | McAfee MVISION EDR up to 3.3.x command injection
38 minutes 4 seconds ago
A vulnerability identified as critical has been detected in McAfee MVISION EDR up to 3.3.x. This impacts an unknown function. The manipulation leads to command injection.
This vulnerability is referenced as CVE-2021-31838. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2021-36958 | Microsoft Windows Print Spooler Remote Code Execution
38 minutes 4 seconds ago
A vulnerability, which was classified as very critical, has been found in Microsoft Windows. This impacts an unknown function of the component Print Spooler. Performing a manipulation results in Remote Code Execution.
This vulnerability was named CVE-2021-36958. The attack may be initiated remotely. In addition, an exploit is available.
It is recommended to change the configuration settings.
vuldb.com
CVE-2020-8908 | Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59 File Processing information disclosure
38 minutes 4 seconds ago
A vulnerability marked as problematic has been reported in Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59. The impacted element is an unknown function of the component File Processing. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2020-8908. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2020-8908 | Oracle JD Edwards EnterpriseOne Orchestrator E1 IOT Orchestrator Security information disclosure
38 minutes 4 seconds ago
A vulnerability, which was classified as problematic, has been found in Oracle JD Edwards EnterpriseOne Orchestrator. This vulnerability affects unknown code of the component E1 IOT Orchestrator Security. Performing a manipulation results in information disclosure.
This vulnerability is reported as CVE-2020-8908. The attack requires a local approach. No exploit exists.
vuldb.com
CVE-2020-8908 | Oracle Communications BRM - Elastic Charging Engine up to 12.0.0.8.0 Charging Server information disclosure
38 minutes 4 seconds ago
A vulnerability labeled as problematic has been found in Oracle Communications BRM - Elastic Charging Engine up to 12.0.0.8.0. The impacted element is an unknown function of the component Charging Server. Executing a manipulation can lead to information disclosure.
This vulnerability appears as CVE-2020-8908. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2020-8908 | Oracle Data Integrator 12.2.1.4.0 information disclosure
38 minutes 4 seconds ago
A vulnerability was found in Oracle Data Integrator 12.2.1.4.0 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation results in information disclosure.
This vulnerability is known as CVE-2020-8908. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2020-8908 | Oracle WebLogic Server 14.1.1.0.0 Centralized Thirdparty Jars information disclosure
38 minutes 4 seconds ago
A vulnerability was found in Oracle WebLogic Server 14.1.1.0.0. It has been declared as problematic. This vulnerability affects unknown code of the component Centralized Thirdparty Jars. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2020-8908. Local access is required to approach this attack. No exploit exists.
vuldb.com
CVE-2021-34481 | Microsoft Windows Print Spooler Service privileges management
38 minutes 4 seconds ago
A vulnerability was found in Microsoft Windows. It has been declared as very critical. Affected by this vulnerability is an unknown functionality of the component Print Spooler Service. Such manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2021-34481. The attack can be launched remotely. No exploit exists.
Configuration settings should be changed.
vuldb.com
CVE-2021-24105 | Microsoft Package Manager Configurations Local Privilege Escalation (Nessus ID 236695)
38 minutes 4 seconds ago
A vulnerability identified as critical has been detected in Microsoft Package Manager Configurations. This affects an unknown part. Performing a manipulation results in Local Privilege Escalation.
This vulnerability is cataloged as CVE-2021-24105. The attack must be initiated from a local position. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2026-26331 | yt-dlp up to 2026.02.20 os command injection (GHSA-g3gw-q23r-pgqm / Nessus ID 299894)
46 minutes 20 seconds ago
A vulnerability was found in yt-dlp up to 2026.02.20 and classified as critical. This issue affects some unknown processing. Executing a manipulation can lead to os command injection.
This vulnerability appears as CVE-2026-26331. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-2757 | Mozilla Firefox up to 147 WebRTC Remote Code Execution (Nessus ID 299892)
46 minutes 20 seconds ago
A vulnerability labeled as critical has been found in Mozilla Firefox up to 147. Affected by this issue is some unknown functionality of the component WebRTC. Such manipulation leads to Remote Code Execution.
This vulnerability is documented as CVE-2026-2757. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-2769 | Mozilla Firefox up to 147 IndexedDB use after free (EUVD-2026-8469 / Nessus ID 299892)
46 minutes 20 seconds ago
A vulnerability identified as critical has been detected in Mozilla Firefox up to 147. This vulnerability affects unknown code of the component IndexedDB. Performing a manipulation results in use after free.
This vulnerability is cataloged as CVE-2026-2769. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com