Threat Intelligence Feed

Aggregating 2299 articles from trusted cybersecurity sources

LATEST CVEs
HIGH · CVE-2026-14522 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to e HIGH · CVE-2026-14519 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to r HIGH · CVE-2026-12947 IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive infor HIGH · CVE-2026-11980 IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up. HIGH · CVE-2026-11897 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sen CRIT · CVE-2026-11707 IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site sc MED · CVE-2026-11383 IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri MED · CVE-2025-36431 IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera MED · CVE-2025-36298 IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 HIGH · CVE-2026-67351 Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and sessio HIGH · CVE-2026-60075 Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi HIGH · CVE-2026-60074 Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric ran HIGH · CVE-2026-5219 Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows C MED · CVE-2026-58218 A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY HIGH · CVE-2026-57859 e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows a HIGH · CVE-2026-56428 The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly CVE-2026-41709 VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform HIGH · CVE-2026-12722 Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel a CRIT · CVE-2026-59310 VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access CRIT · CVE-2026-59309 VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with n HIGH · CVE-2026-54368 CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows HIGH · CVE-2026-54367 CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w HIGH · CVE-2026-54366 CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack HIGH · CVE-2026-54365 CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthe MED · CVE-2026-54364 CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj CRIT · CVE-2026-54363 CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to fo CRIT · CVE-2026-47876 VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with HIGH · CVE-2026-41703 VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment pr CVE-2026-7260 Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP MED · CVE-2026-5582 The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24 MED · CVE-2026-18382 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able HIGH · CVE-2026-18381 A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r HIGH · CVE-2026-18378 A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able t CVE-2026-17544 Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions CVE-2026-17543 Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions f HIGH · CVE-2026-15397 The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and HIGH · CVE-2026-22622 Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could al HIGH · CVE-2026-22621 Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al HIGH · CVE-2026-22620 Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau MED · CVE-2026-18369 A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns
1215 general 472 advisories 302 research 245 vendor 65 enterprise

Trending Vendors

Latest News

Data Breaches

No articles found.