Aggregator
CVE-2026-4342
1 month 2 weeks ago
ingress-nginx comment-based nginx configuration injection
Microsoft security advisory – January 2026 monthly rollup (AV26-024) – Update 2
1 month 2 weeks ago
Canadian Centre for Cyber Security
CVE-2026-3864 | Kubernetes CSI Driver subDir path traversal
1 month 2 weeks ago
A vulnerability was found in Kubernetes. It has been classified as critical. Affected is an unknown function of the component CSI Driver. The manipulation of the argument subDir leads to path traversal.
This vulnerability is listed as CVE-2026-3864. The attack must be carried out from within the local network. There is no available exploit.
vuldb.com
87 ML-моделей, 25 000 событий в секунду и детект Kerberoasting. Positive Technologies выпустила MaxPatrol SIEM 27.6
1 month 2 weeks ago
Представлена новая версия системы мониторинга событий ИБ.
Financial Brands Targeted in Global Mobile Banking Malware Surge
1 month 2 weeks ago
Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices
CVE-2025-71258 | BMC FootPrints up to 20.24.01.001 searchWeb API server-side request forgery
1 month 2 weeks ago
A vulnerability was found in BMC FootPrints up to 20.24.01.001 and classified as critical. This impacts an unknown function of the component searchWeb API. Executing a manipulation can lead to server-side request forgery.
This vulnerability is tracked as CVE-2025-71258. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2025-71259 | BMC FootPrints up to 20.24.01.001 Feed API server-side request forgery
1 month 2 weeks ago
A vulnerability has been found in BMC FootPrints up to 20.24.01.001 and classified as critical. This affects an unknown function of the component Feed API. Performing a manipulation results in server-side request forgery.
This vulnerability is identified as CVE-2025-71259. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-4426 | libarchive ISO File Parser pz_log2_bs incorrect bitwise shift of integer
1 month 2 weeks ago
A vulnerability, which was classified as problematic, was found in libarchive. The impacted element is an unknown function of the component ISO File Parser. Such manipulation of the argument pz_log2_bs leads to incorrect bitwise shift of integer.
This vulnerability is referenced as CVE-2026-4426. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2025-71257 | BMC FootPrints up to 20.24.01.001 REST API Endpoint missing authentication
1 month 2 weeks ago
A vulnerability, which was classified as critical, has been found in BMC FootPrints up to 20.24.01.001. The affected element is an unknown function of the component REST API Endpoint. This manipulation causes missing authentication.
The identification of this vulnerability is CVE-2025-71257. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-4424 | libarchive RAR out-of-bounds
1 month 2 weeks ago
A vulnerability classified as problematic was found in libarchive. Impacted is an unknown function of the component RAR Handler. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-4424. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2025-71260 | BMC FootPrints up to 20.24.01.001 ASP.NET Servlet VIEWSTATE deserialization
1 month 2 weeks ago
A vulnerability classified as critical has been found in BMC FootPrints up to 20.24.01.001. This issue affects some unknown processing of the component ASP.NET Servlet. The manipulation of the argument VIEWSTATE leads to deserialization.
This vulnerability is uniquely identified as CVE-2025-71260. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-30951 | Sequelize up to 6.37.7 _traverseJSON sql injection (GHSA-6457-6jrx-69cr / Nessus ID 301792)
1 month 2 weeks ago
A vulnerability has been found in Sequelize up to 6.37.7 and classified as critical. Affected by this vulnerability is the function _traverseJSON. This manipulation causes sql injection.
This vulnerability is registered as CVE-2026-30951. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-30952 | harttle liquidjs up to 10.24.x path traversal (GHSA-wmfp-5q7x-987x)
1 month 2 weeks ago
A vulnerability was found in harttle liquidjs up to 10.24.x and classified as critical. Affected by this issue is some unknown functionality. Such manipulation leads to path traversal.
This vulnerability is documented as CVE-2026-30952. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-31954 | Emlog up to 2.6.6 LoginAuth::checkToken cross-site request forgery
1 month 2 weeks ago
A vulnerability identified as problematic has been detected in Emlog up to 2.6.6. The impacted element is the function LoginAuth::checkToken. The manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-31954. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-32102 | OliveTin up to 3000.10.1 access control (GHSA-228v-wc5r-j8m7)
1 month 2 weeks ago
A vulnerability was found in OliveTin up to 3000.10.1. It has been classified as critical. Affected by this issue is some unknown functionality. This manipulation causes improper access controls.
This vulnerability appears as CVE-2026-32102. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-32101 | studiocms up to 0.3.0 PUT isAuthorized authorization (GHSA-mm78-fgq8-6pgr)
1 month 2 weeks ago
A vulnerability was found in studiocms up to 0.3.0. It has been declared as critical. Affected by this vulnerability is the function isAuthorized of the component PUT Handler. Such manipulation leads to incorrect authorization.
This vulnerability is documented as CVE-2026-32101. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-31815 | django-commons django-unicorn up to 0.66.x access control (GHSA-ffv6-jj46-x367)
1 month 2 weeks ago
A vulnerability was found in django-commons django-unicorn up to 0.66.x. It has been declared as critical. This vulnerability affects unknown code. Executing a manipulation can lead to improper access controls.
This vulnerability appears as CVE-2026-31815. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-31837 | Istio up to 1.27.7/1.28.4/1.29.0 information disclosure (GHSA-v75c-crr9-733c)
1 month 2 weeks ago
A vulnerability was found in Istio up to 1.27.7/1.28.4/1.29.0 and classified as problematic. This impacts an unknown function. The manipulation results in information disclosure.
This vulnerability is reported as CVE-2026-31837. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-31838 | Istio up to 1.27.7/1.28.4/1.29.0 authorization (GHSA-974c-2wxh-g4ww)
1 month 2 weeks ago
A vulnerability marked as problematic has been reported in Istio up to 1.27.7/1.28.4/1.29.0. This affects an unknown function. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-31838. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com