2159 items
Unread (2149) All Dismissed
HIGH
CVE-2018-25407 (CVSS 8.2) — eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated atta...
NVD CVE-2018-25407 6d ago
HIGH
CVE-2018-25406 (CVSS 8.2) — eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated atta...
NVD CVE-2018-25406 6d ago
HIGH
CVE-2018-25405 (CVSS 8.2) — eNdonesia Portal 8.7 contains multiple SQL injection vulnerabilities that allow unauthenticated atta...
NVD CVE-2018-25405 6d ago
INFO
Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say
SecurityWeek breachesransomwaresupply-chain 6d ago
INFO
Exploit Code Published for Critical Flowise RCE Vulnerability
SecurityWeek breachesransomwaresupply-chain 6d ago
HIGH
CVE-2026-10120 (CVSS 8.8) — A vulnerability was detected in TRENDnet TEW-432BRP 3.10B20. The affected element is the function fo...
NVD CVE-2026-10120 6d ago
HIGH
CVE-2026-10119 (CVSS 8.8) — A security vulnerability has been detected in TRENDnet TEW-432BRP 3.10B20. Impacted is the function ...
NVD CVE-2026-10119 6d ago
INFO
New CIFSwitch Linux flaw gives root on multiple distributions
BleepingComputer breachesransomwaresupply-chain 6d ago
HIGH
CVE-2026-9757 (CVSS 7.5) — The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' ...
NVD CVE-2026-9757 6d ago
HIGH
CVE-2026-7465 (CVSS 8.8) — The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerab...
NVD CVE-2026-7465 6d ago
HIGH
CVE-2026-7459 (CVSS 7.5) — The Simple History – Track, Log, and Audit WordPress Changes plugin for WordPress is vulnerable to a...
NVD CVE-2026-7459 6d ago
HIGH
CVE-2026-10111 (CVSS 7.3) — A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function o...
NVD CVE-2026-10111 7d ago
HIGH
CVE-2026-10110 (CVSS 7.3) — A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an...
NVD CVE-2026-10110 7d ago
CRITICAL
CVE-2026-0257: Palo Alto Networks PAN-OS Authentication Bypass Vulnerability (Palo Alto Networks PAN-OS)
CISA KEV CVE-2026-0257actively-exploited +5 8d ago
CRITICAL
CVE-2026-0257 (CVSS 9.1) — Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks ...
NVD 23d ago
INFO
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation
The Hacker News 7d ago
INFO
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
BleepingComputer 6d ago
INFO
Recent Palo Alto Networks Vulnerability Exploited for Weeks
SecurityWeek 4d ago
INFO
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
rss:unit42 19h ago
INFO
Friday Squid Blogging: Another Squid
rss:schneier analysispolicy 7d ago
INFO
Name That Toon: Mark of (Cybersecurity) Progress
rss:darkreading breachesmalwarethreat-actors 7d ago
HIGH
CVE-2026-48557 (CVSS 8.8) — Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in Fil...
NVD CVE-2026-48557 7d ago
HIGH
CVE-2026-48555 (CVSS 7.4) — Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerabi...
NVD CVE-2026-48555 7d ago
HIGH
CVE-2026-46527 (CVSS 7.5) — cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, W...
NVD CVE-2026-46527 7d ago
CRITICAL
CVE-2026-45700 (CVSS 9.8) — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar b...
NVD CVE-2026-45700 7d ago
MEDIUM
CVE-2026-45352 (CVSS 5.3) — cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, n...
NVD CVE-2026-45352 7d ago
MEDIUM
CVE-2026-45149 (CVSS 6.5) — The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From ...
NVD CVE-2026-45149 7d ago
HIGH
CVE-2026-44422 (CVSS 7.5) — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR N...
NVD CVE-2026-44422 7d ago
MEDIUM
CVE-2026-49382 (CVSS 4.5) — In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the C...
NVD CVE-2026-49382 7d ago
HIGH
CVE-2026-49373 (CVSS 7.1) — In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection setti...
NVD CVE-2026-49373 7d ago
HIGH
CVE-2026-49371 (CVSS 7.1) — In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
NVD CVE-2026-49371 7d ago
INFO
CVE-2026-49370 (CVSS 3.4) — In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
NVD CVE-2026-49370 7d ago
HIGH
CVE-2026-49367 (CVSS 8) — In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
NVD CVE-2026-49367 7d ago
INFO
ChatGPT share links abused to host fake outage pages to deliver malware
BleepingComputer breachesransomwaresupply-chain 7d ago
HIGH
CVE-2026-10108 (CVSS 7.5) — xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_pa...
NVD CVE-2026-10108 7d ago
HIGH
CVE-2026-10105 (CVSS 8.3) — agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that all...
NVD CVE-2026-10105 7d ago
HIGH
MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems
The Hacker News supply-chainbreachesmalware +19 19d ago
INFO
'Dirty Frag' Exploit Poised to Blow Up on Enterprise Linux Distros
rss:darkreading 25d ago
INFO
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
rss:darkreading 24d ago
INFO
Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
The Hacker News 23d ago
INFO
[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud
The Hacker News 23d ago
INFO
Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence
The Hacker News 21d ago
INFO
Can Laws Stop Deepfakes? South Korea Aims to Find Out
rss:darkreading 19d ago
INFO
Processes and Culture Top Reasons Behind Data Breaches
rss:darkreading 16d ago
INFO
When Identity is the Attack Path
The Hacker News 15d ago
INFO
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV
The Hacker News 15d ago
INFO
Meta settles school district lawsuit claiming addictive design harmed students' mental health
The Record 14d ago
INFO
Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software
The Hacker News 13d ago
INFO
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
The Hacker News 11d ago
INFO
CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
The Hacker News 11d ago
INFO
RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries
SecurityWeek 9d ago
INFO
California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach
SecurityWeek 7d ago
INFO
California AG sues 23andMe over 2023 breach exposing health data
BleepingComputer 7d ago
INFO
Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs
SecurityWeek 2d ago
INFO
Chrome 149 Patches 429 Vulnerabilities
SecurityWeek 22h ago
INFO
EU unveils tech sovereignty package to cut reliance on US, Chinese suppliers
The Record 20h ago
INFO
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
The Hacker News supply-chainbreachesmalware 7d ago
INFO
In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks
SecurityWeek breachesransomwaresupply-chain 7d ago
HIGH
CVE-2026-48501 (CVSS 7.4) — GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly incl...
NVD CVE-2026-48501 7d ago
HIGH
CVE-2026-35674 (CVSS 8.8) — OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that ...
NVD CVE-2026-35674 7d ago
HIGH
CVE-2026-35630 (CVSS 8) — OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval bu...
NVD CVE-2026-35630 7d ago
HIGH
CVE-2026-32905 (CVSS 8.3) — OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair p...
NVD CVE-2026-32905 7d ago
HIGH
CVE-2026-10069 (CVSS 7.5) — A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of...
NVD CVE-2026-10069 7d ago
HIGH
CVE-2026-10067 (CVSS 8.8) — A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file mu...
NVD CVE-2026-10067 7d ago
HIGH
CVE-2026-10066 (CVSS 8.8) — A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the funct...
NVD CVE-2026-10066 7d ago
MEDIUM
CVE-2026-10064 (CVSS 6.3) — A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSe...
NVD CVE-2026-10064 7d ago
HIGH
CVE-2018-25404 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25404 7d ago
HIGH
CVE-2018-25403 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25403 7d ago
HIGH
CVE-2018-25402 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25402 7d ago
HIGH
CVE-2018-25401 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25401 7d ago
HIGH
CVE-2018-25400 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25400 7d ago
HIGH
CVE-2018-25399 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25399 7d ago
HIGH
CVE-2018-25398 (CVSS 8.2) — The Open ISES Project 3.30A contains an SQL injection vulnerability that allows unauthenticated atta...
NVD CVE-2018-25398 7d ago
HIGH
CVE-2018-25396 (CVSS 7.5) — Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthentic...
NVD CVE-2018-25396 7d ago
TL;DR
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. Due: 2026-06-01. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CVE-2026-0257actively-exploited
Read full story ↗