Aggregator
Please support the site operations by clicking ads.
CVE-2026-96258 | onSite internet GmbH Auktion NG Auktionssoftware up to 20260722 Public Password Reset Endpoint /forgotpasswd.html email cross site scripting
22 hours 48 minutes ago
A vulnerability was found in onSite internet GmbH Auktion NG Auktionssoftware up to 20260722. It has been classified as problematic. This affects an unknown part of the file /forgotpasswd.html of the component Public Password Reset Endpoint. The manipulation of the argument email leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-96258. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Microsoft Disrupts EvilTokens Device Code Phishing Service
22 hours 49 minutes ago
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Alexander Culafi
Submit #901875: onSite internet GmbH Auktion:NG Auktionssoftware Unknown Cross Site Scripting [Accepted]
22 hours 53 minutes ago
Submit #901875 / VDB-408708
david_12
CVE-2026-96257 | Fast FAC1203R Gigabit Edition 2.0.4 Device Discovery Service copy_msg_element stack-based overflow
22 hours 55 minutes ago
A vulnerability was found in Fast FAC1203R Gigabit Edition 2.0.4 and classified as very critical. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow.
This vulnerability is handled as CVE-2026-96257. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
22 hours 59 minutes ago
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
Submit #901889: Fast FAC1203R Gigabit Edition 20200116_2.0.4 Stack-based Buffer Overflow [Accepted]
23 hours ago
Submit #901889 / VDB-408707
xiaobor123
CVE-2026-88416 | Mcms up to 6.2.1 Model/Form Import sql injection
23 hours 1 minute ago
A vulnerability has been found in Mcms up to 6.2.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Model/Form Import. Performing a manipulation results in sql injection.
This vulnerability is known as CVE-2026-88416. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-88339 | GPAC gf_sg_vrml_field_clone null pointer dereference (2d7da22e)
23 hours 2 minutes ago
A vulnerability, which was classified as problematic, was found in GPAC. Affected is the function gf_sg_vrml_field_clone. Such manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2026-88339. The attack may be launched remotely. There is no exploit available.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2026-88624 | OpenCode 1.18.26 Worktree.remove path traversal
23 hours 2 minutes ago
A vulnerability, which was classified as problematic, has been found in OpenCode 1.18.26. This impacts the function Worktree.remove. This manipulation causes path traversal.
This vulnerability appears as CVE-2026-88624. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-88418 | CMSimple 5.24 CSRF Protection content/content.php evaluate_cmsimple_scripting cross-site request forgery
23 hours 3 minutes ago
A vulnerability classified as problematic was found in CMSimple 5.24. This affects the function evaluate_cmsimple_scripting of the file content/content.php of the component CSRF protection. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2026-88418. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-63104 | UseKaneo up to 2.12.1 Bulk Task Endpoint /api/task/bulk privileges management
23 hours 3 minutes ago
A vulnerability classified as problematic has been found in UseKaneo Kaneo up to 2.12.1. The impacted element is an unknown function of the file /api/task/bulk of the component Bulk Task Endpoint. The manipulation leads to improper privilege management.
This vulnerability is documented as CVE-2026-63104. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-88419 | WuzhiCMS 5.0.0 Thumbnail Upload index.php unrestricted upload
23 hours 4 minutes ago
A vulnerability described as critical has been identified in WuzhiCMS 5.0.0. The affected element is an unknown function of the file index.php of the component Thumbnail Upload. Executing a manipulation can lead to unrestricted upload.
This vulnerability is registered as CVE-2026-88419. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-75745 | Adobe Experience Manager Forms JEE improper authorization
23 hours 9 minutes ago
A vulnerability marked as critical has been reported in Adobe Experience Manager Forms JEE. Impacted is an unknown function. Performing a manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-75745. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-76716 | HPE Analytics and Location Engine up to 5.0.0.0 improper authorization
23 hours 10 minutes ago
A vulnerability labeled as very critical has been found in HPE Analytics and Location Engine up to 5.0.0.0. This issue affects some unknown processing. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-76716. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-76711 | HPE ALE up to 5.0.0.0 Analytics/Location Engine injection
23 hours 10 minutes ago
A vulnerability identified as problematic has been detected in HPE ALE up to 5.0.0.0. This vulnerability affects unknown code of the component Analytics/Location Engine. This manipulation causes injection.
This vulnerability is tracked as CVE-2026-76711. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-62985 | azu request-filtering-agent up to 3.2.0 createConnection improper synchronization
23 hours 10 minutes ago
A vulnerability categorized as problematic has been discovered in azu request-filtering-agent up to 3.2.0. This affects the function createConnection. The manipulation results in improper synchronization.
This vulnerability is identified as CVE-2026-62985. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
Check Point Fixes a New Actively Exploited Critical Security Flaw
23 hours 19 minutes ago
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to […]
Pierluigi Paganini
AI’s new role in exploiting vulnerabilities
23 hours 24 minutes ago
Red Canary, a Zscaler company
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
23 hours 37 minutes ago
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]
Lawrence Abrams