Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

CVE

20 articles

CISA Advisories CVE May 26

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-48172 LiteSpeed...

T1548 1 IOC

CISA Advisories →

The Hacker News CVE Microsoft May 26

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without r...

T1190 1 IOC

The Hacker News →

Help Net Security CVE Microsoft May 26

High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)

Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity...

T1190 1 IOC

Help Net Security →

GBHackers CVE May 26

Memcached SASL Flaw Exposes Usernames to Enumeration Attacks

A newly identified vulnerability in Memcached has raised concerns among security professionals after researchers confirmed a timing side-channel flaw that al...

1 IOC

GBHackers →

GBHackers CVE May 26

Ghost CMS Vulnerability Exploited to Infect 700 Sites With ClickFix Malware

Hackers are actively exploiting a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) to compromise websites and distribute ClickFix malware t...

1 IOC

GBHackers →

GBHackers CVE Apache May 26

Apache CXF Flaw Exposes Systems to LDAP Injection Attacks

Apache CXF users are facing a significant security risk following the disclosure of a new vulnerability that exposes systems to LDAP injection attacks, poten...

1 IOC

GBHackers →

GBHackers CVE May 26

ConnectWise Automate Flaw Allows Hackers to Evade Security Controls

ConnectWise has released a security update to address a high-severity vulnerability in its ConnectWise Automate remote monitoring and management (RMM) platfo...

1 IOC

GBHackers →

GBHackers CVE Google Intel May 26

Hackers Abuse KnowledgeDeliver LMS Flaw to Install BLUEBEAM Web Shell

Hackers are actively exploiting a critical vulnerability in the KnowledgeDeliver Learning Management System (LMS) to deploy the BLUEBEAM web shell, according...

T1190 2 IOCs

GBHackers →

Security Affairs CVE May 25

Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites

Attackers are exploiting the patched Ghost CMS flaw CVE-2026-26980, compromising over 700 unpatched sites, including universities. Threat actors are actively...

1 IOC

Security Affairs →

The Hacker News CVE Oracle May 25

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attack...

1 IOC

The Hacker News →

GBHackers CVE Drupal May 25

CISA Warns Drupal Core SQL Injection Vulnerability Is Being Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical SQL injection vulnerability in Drupal Core, tra...

1 IOC

GBHackers →

GBHackers CVE F5 May 25

Nginx-poolslip Flaw Exposes Servers to DoS and Code Execution Attacks

NGINX users are facing a critical security issue after F5 disclosed a new vulnerability, tracked as CVE-2026-9256, affecting the widely used ngx_http_rewrite...

T1190 1 IOC

GBHackers →

BleepingComputer CVE Oracle May 24

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers C...

1 IOC

BleepingComputer →

Security Affairs CVE Drupal May 24

Security Affairs newsletter Round 578 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

1 IOC

Security Affairs →

Security Affairs CVE Microsoft Drupal May 24

U.S. CISA adds a flaw in Drupal Core to its Known Exploited Vulnerabilities catalog

The U.S.

1 IOC

Security Affairs →

Security Affairs CVE Drupal May 23

CVE-2026-9082: Drupal’s Highly Critical SQL Injection Flaw Is Already Under Active Attack

Attackers began exploiting Drupal SQL injection flaw CVE-2026-9082 within 48 hours of patch release. Drupal issued a highly critical security patch on May 20...

1 IOC

Security Affairs →

The Hacker News CVE May 23

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE...

1 IOC

The Hacker News →

The Hacker News CVE Drupal May 23

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S.

1 IOC

The Hacker News →

SC Media CVE May 22

Ubiquiti patches three critical vulnerabilities in UniFi OS

The vulnerabilities, identified as CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, allow for unauthorized system changes, path traversal for accessing un...

T1059 3 IOCs

SC Media →

SC Media CVE Amazon Trend Micro May 22

CISA adds Trend Micro Apex One and Langflow flaws to exploited vulnerabilities catalog

The vulnerabilities added are CVE-2025-34291, an origin validation error in Langflow with a CVSS score of 9.4, and CVE-2026-34926, a directory traversal flaw...

2 IOCs

SC Media →

«Previous page 1 ... 7 8 9 10 11 ... 29 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA