The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems against a five-year-old GitLab vulnerability that is actively being exploited in attacks. [...]
A vulnerability has been found in JS Help Desk Best Help Desk & Support Plugin up to 2.8.7 on WordPress and classified as problematic. The impacted element is an unknown function. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2024-51670. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in Synology Active Backup for Business. It has been classified as critical. This affects an unknown part. Performing a manipulation results in path traversal.
This vulnerability is identified as CVE-2024-47264. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in honojs hono up to 4.11.6 and classified as problematic. Affected by this issue is some unknown functionality of the component jsx. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-24771. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in MediaTek MT6890, MT7615, MT7915, MT7916, MT7981 and MT7986. This vulnerability affects unknown code of the component wlan. The manipulation results in heap-based buffer overflow.
This vulnerability was named CVE-2026-20408. The attack needs to be approached within the local network. There is no available exploit.
A patch should be applied to remediate this issue.
A vulnerability was found in MediaTek MT6897 and MT6989 and classified as critical. This impacts an unknown function of the component imgsys. The manipulation results in out-of-bounds write.
This vulnerability is cataloged as CVE-2026-20409. The attack must be initiated from a local position. There is no exploit available.
Applying a patch is advised to resolve this issue.
A vulnerability was found in MediaTek MT7902, MT7920, MT7921, MT7922, MT7925 and MT7927. It has been classified as critical. Affected is an unknown function of the component WLAN STA driver. This manipulation causes out-of-bounds write.
This vulnerability is registered as CVE-2026-20407. The attack needs to be launched locally. No exploit is available.
It is suggested to install a patch to address this issue.
A vulnerability was found in MediaTek MT6897, MT6989, MT8370, MT8390 and MT8395. It has been rated as critical. Affected by this issue is some unknown functionality of the component imgsys. Performing a manipulation results in out-of-bounds write.
This vulnerability is reported as CVE-2026-20410. The attack requires a local approach. No exploit exists.
To fix this issue, it is recommended to deploy a patch.
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.4.x. It has been rated as problematic. This issue affects some unknown processing of the component Merge Request Handler. The manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-1751. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. It has been rated as critical. Impacted is the function readData. Performing a manipulation of the argument length results in heap-based buffer overflow.
This vulnerability is known as CVE-2025-62602. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in Blesta up to 5.13.2. It has been classified as problematic. This impacts an unknown function. The manipulation leads to deserialization.
This vulnerability is documented as CVE-2026-25615. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Blesta up to 5.13.2 and classified as problematic. This affects an unknown function. Executing a manipulation can lead to deserialization.
This vulnerability is registered as CVE-2026-25614. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
French prosecutors raided X offices in Paris over illegal content; Elon Musk and CEO summoned for voluntary interviews in April. French prosecutors, with France’s National Gendarmerie and Europol support, raided the X offices in Paris in a criminal probe over complaints that the platform facilitated child sexual abuse material and other illegal content. The probe […]
Currently trending CVE - Hype Score: 6 - Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.
Currently trending CVE - Hype Score: 8 - A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to execute arbitrary code with kernel privileges.
Omdat de veiligheid van Nederland niet meer vanzelfsprekend is, heeft koningin Máxima besloten om reservist te worden. Zij is vandaag begonnen als soldaat bij de Koninklijke Landmacht.