Currently trending CVE - Hype Score: 20 - A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.
Currently trending CVE - Hype Score: 4 - LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without ...
Currently trending CVE - Hype Score: 5 - MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system does not enforce meaningful rate-limiting, account lockout, or source-based restrictions, allowing repeated authentication ...
Currently trending CVE - Hype Score: 7 - In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or ...
Currently trending CVE - Hype Score: 3 - VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 ...
Currently trending CVE - Hype Score: 19 - A logic issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5. An app may be able to enumerate a user's installed apps.
A vulnerability was found in Open Library Foundation VuFind 4.1/11.0.3 and classified as critical. Impacted is the function VuFind\Controller\AbstractBase::validateAccessPermission. Executing a manipulation can lead to improper access controls.
This vulnerability is handled as CVE-2026-52466. The attack can be executed remotely. There is not any exploit available.
A vulnerability has been found in Systerel S2OPC 1.7.3 and classified as problematic. This issue affects some unknown processing of the component Queue. Performing a manipulation results in denial of service.
This vulnerability is known as CVE-2026-67872. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability, which was classified as critical, was found in open62541 1.5.5. This vulnerability affects unknown code of the file src/server/ua_services_nodemanagement.c of the component AddReferences. Such manipulation leads to improper input validation.
This vulnerability is traded as CVE-2026-67870. The attack may be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in mz-automation lib60870 2.4.0. This affects the function FileSegment_encode of the component FileSegment. This manipulation causes buffer overflow.
This vulnerability appears as CVE-2026-67873. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as problematic was found in Systerel S2OPC 1.7.3. Affected by this issue is some unknown functionality of the file address_space_bs.c. The manipulation results in buffer overflow.
This vulnerability is reported as CVE-2026-67871. The attack can be launched remotely. No exploit exists.
A vulnerability classified as problematic has been found in open62541 up to 1.5.4. Affected by this vulnerability is an unknown functionality. The manipulation leads to buffer overflow.
This vulnerability is documented as CVE-2026-67869. The attack can be initiated remotely. There is not any exploit available.
A vulnerability described as problematic has been identified in HDF Group HDF5 up to 2.3.0. Affected is the function H5Z__filter_fletcher32 of the file H5Zfletcher32.c. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is registered as CVE-2026-19028. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as very critical has been reported in Agentfront FrontMCP up to 1.5.6. This impacts the function getTool of the component Codecall Execute. Performing a manipulation results in sandbox issue.
This vulnerability is cataloged as CVE-2026-67531. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in HDF Group HDF5 up to 2.3.0. This affects the function H5Z__nbit_decompress_one_byte/H5Z__nbit_decompress_one_nooptype/H5Z__nbit_decompress_one_atomic of the file H5Znbit.c of the component N-Bit Filter. Such manipulation leads to out-of-bounds read.
This vulnerability is listed as CVE-2026-19027. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Linux Kernel up to 6.1.87/6.6.28/6.8.7/6.9-rc5 and classified as problematic. Affected by this issue is the function smb2_allocate_rsp_buf of the component ksmbd. The manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2024-26980. Access to the local network is required for this attack. No exploit is available.
It is suggested to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.1.87/6.6.28/6.8.7/6.9-rc4. It has been rated as critical. This issue affects the function xbc_exit of the component bootconfig. Performing a manipulation results in use after free.
This vulnerability was named CVE-2024-26983. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Linux Kernel up to 5.15.156/6.1.87/6.6.28/6.8.7/6.9-rc4. The affected element is the function eth_stop of the component f_ncm. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2024-26996. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability described as problematic has been identified in Linux Kernel up to 6.6.28/6.8.7/6.9-rc4 on TDP. This impacts the function kvm_mmu_page_ad_need_write_protect of the component KVM. Such manipulation leads to privilege escalation.
This vulnerability is listed as CVE-2024-26990. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability classified as critical was found in Linux Kernel up to 5.15.156/6.1.87/6.6.28/6.8.7/6.9-rc4. Affected by this vulnerability is an unknown functionality of the component speakup. Executing a manipulation can lead to buffer overflow.
This vulnerability is registered as CVE-2024-26994. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is advised.