Posts of last 24 hours
A vulnerability was found in mtrudel bandit 1.11.0/1.11.1/1.12.1 and classified as critical. This vulnerability affects the function Bandit.HTTP2.Stream.read_headers of the component HTTP2 Header Processing. Executing a manipulation can lead to crlf injection.
This vulnerability is registered as CVE-2026-75484. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/393881
A vulnerability has been found in mtrudel bandit up to 1.12.4 and classified as problematic. This affects an unknown part of the component HTTP2 Connection. Performing a manipulation results in allocation of resources.
This vulnerability is cataloged as CVE-2026-74836. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/393880
A vulnerability, which was classified as critical, was found in libvips up to 8.18.2. Affected by this issue is the function vips_image_sanity of the file libvips/iofuncs/image.c. Such manipulation leads to integer overflow.
This vulnerability is listed as CVE-2026-69242. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/393879
A vulnerability, which was classified as problematic, has been found in libvips up to 8.18.2. Affected by this vulnerability is an unknown functionality of the file libvips/foreign/magick6load.c of the component ImageMagick. This manipulation causes heap-based buffer overflow.
This vulnerability is tracked as CVE-2026-70651. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/393878
A vulnerability classified as problematic was found in axllent Mailpit up to 1.30.3. Affected is the function readLine of the file internal/smtpd/smtpd.go of the component smtpd. The manipulation results in allocation of resources.
This vulnerability is identified as CVE-2026-67445. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/393877
A vulnerability classified as problematic has been found in Centuran Consulting OTRS up to 6.0.41. This impacts an unknown function of the component PGP encryption module. The manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-53804. Remote exploitation of the attack is possible. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/393876
A vulnerability described as problematic has been identified in Tor Project Tor. This affects the function buf_add_compress of the component Decompression. Executing a manipulation can lead to infinite loop.
The identification of this vulnerability is CVE-2026-77640. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/393875
Currently trending CVE - Hype Score: 6 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered ...
https://cvemon.intruder.io/cves/CVE-2026-20317
Currently trending CVE - Hype Score: 8 - In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which ...
https://cvemon.intruder.io/cves/CVE-2026-76404
Currently trending CVE - Hype Score: 6 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered ...
https://cvemon.intruder.io/cves/CVE-2026-20315