A vulnerability labeled as problematic has been found in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service.
This vulnerability is identified as CVE-2026-90713. The attack is only possible with local access. Additionally, an exploit exists.
The pull request to fix this issue awaits acceptance.
A vulnerability identified as problematic has been detected in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service.
This vulnerability is referenced as CVE-2026-90712. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]
A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to server-side request forgery.
The identification of this vulnerability is CVE-2026-90710. The attack may be launched remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.
Currently trending CVE - Hype Score: 2 - A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Currently trending CVE - Hype Score: 2 - Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Currently trending CVE - Hype Score: 1 - RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet ...
Currently trending CVE - Hype Score: 1 - A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 ...
Currently trending CVE - Hype Score: 1 - RouterOS contains an argument-handling flaw in the SSH login
path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to ...
A vulnerability was found in Apache Storm. It has been rated as very critical. This vulnerability affects unknown code of the component Nimbus. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-82427. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Apache Storm. It has been declared as very critical. This affects an unknown part of the component Worker Launcher. Such manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2026-82430. Local access is required to approach this attack. No exploit exists.
A vulnerability was found in Apache Storm. It has been classified as very critical. Affected by this issue is some unknown functionality of the component Worker Launcher. This manipulation causes improper privilege management.
This vulnerability is handled as CVE-2026-82429. It is possible to launch the attack on the local host. There is not any exploit available.