- Nvidia Is Buying AI Platform Hugging Face for $13 Billion
SecurityWeek · Fri, 04 Sep 2026 10:00:00 +0000
- Google Patches 6th Chrome Zero-Day of 2026
SecurityWeek · Fri, 04 Sep 2026 11:31:52 +0000
- VMware Workstation and Fusion Updates Patch Critical Vulnerability
SecurityWeek · Fri, 04 Sep 2026 11:42:55 +0000
- Catch Raises $5 Million for AI Executive Assistant With Guardrails
SecurityWeek · Fri, 04 Sep 2026 11:55:17 +0000
- 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
SecurityWeek · Fri, 04 Sep 2026 12:06:13 +0000
- Sangoma Switchvox Vulnerabilities Exploited in the Wild
SecurityWeek · Fri, 04 Sep 2026 13:23:12 +0000
- OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
SecurityWeek · Fri, 04 Sep 2026 16:07:22 +0000
- HPE Patches Critical RCE Vulnerabilities in AOS-CX
SecurityWeek · Fri, 04 Sep 2026 16:11:06 +0000
- In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
SecurityWeek · Fri, 04 Sep 2026 16:18:30 +0000
- Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
SecurityWeek · Sat, 05 Sep 2026 13:00:28 +0000
- CVE-2026-86272 — A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFHIGH
NVD · 2026-09-07T05:16:55.387
- CVE-2026-86271 — A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing MEDIUM
NVD · 2026-09-07T05:16:55.210
- CVE-2026-86270 — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation oMEDIUM
NVD · 2026-09-07T05:16:55.020
- CVE-2026-86315 — An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memorMEDIUM
NVD · 2026-09-07T04:17:55.650
- CVE-2026-86269 — A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argumenMEDIUM
NVD · 2026-09-07T04:17:55.467
- CVE-2026-86268 — A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email resultHIGH
NVD · 2026-09-07T04:17:55.277
- CVE-2026-86267 — A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_sMEDIUM
NVD · 2026-09-07T04:17:55.087
- CVE-2026-86265 — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such maMEDIUM
NVD · 2026-09-07T04:17:50.427
- CVE-2026-86314 — Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap reMEDIUM
NVD · 2026-09-07T03:17:19.530
- CVE-2026-86313 — Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.
This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.HIGH
NVD · 2026-09-07T03:17:19.407
- CVE-2026-86264 — A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderConMEDIUM
NVD · 2026-09-07T03:17:19.243
- CVE-2026-86263 — A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/srHIGH
NVD · 2026-09-07T03:17:19.070
- CVE-2026-86262 — A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo oHIGH
NVD · 2026-09-07T03:17:18.893
- CVE-2026-86261 — A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/HIGH
NVD · 2026-09-07T03:17:18.723
- CVE-2026-86260 — A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/sMEDIUM
NVD · 2026-09-07T03:17:17.647
- CVE-2026-86245 — A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. PerformiMEDIUM
NVD · 2026-09-07T02:17:21.427
- CVE-2026-86244 — A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the MEDIUM
NVD · 2026-09-07T02:17:21.247
- CVE-2026-86241 — A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie MEDIUM
NVD · 2026-09-07T02:17:21.067
- CVE-2026-86240 — A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. MEDIUM
NVD · 2026-09-07T02:17:20.890
- CVE-2026-86239 — A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of theMEDIUM
NVD · 2026-09-07T02:17:20.710
- CVE-2026-20518 — In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained th
NVD · 2026-09-07T02:17:20.583
- CVE-2026-20517 — In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the Syst
NVD · 2026-09-07T02:17:20.470
- CVE-2026-20516 — In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User int
NVD · 2026-09-07T02:17:20.360
- CVE-2026-20515 — In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed fo
NVD · 2026-09-07T02:17:20.257
- CVE-2026-20514 — In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtaine
NVD · 2026-09-07T02:17:20.150
- CVE-2026-20513 — In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained
NVD · 2026-09-07T02:17:20.040
- CVE-2026-20512 — In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtain
NVD · 2026-09-07T02:17:19.923
- CVE-2026-20511 — In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the Syste
NVD · 2026-09-07T02:17:19.810
- CVE-2026-20510 — In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the
NVD · 2026-09-07T02:17:19.697
- CVE-2026-20509 — In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the
NVD · 2026-09-07T02:17:19.587
- CVE-2026-20508 — In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the Syst
NVD · 2026-09-07T02:17:19.470
- CVE-2026-20507 — In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the Syst
NVD · 2026-09-07T02:17:19.360
- CVE-2026-20506 — In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the Syst
NVD · 2026-09-07T02:17:19.250
- CVE-2026-20504 — In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by t
NVD · 2026-09-07T02:17:19.143
- CVE-2026-20503 — In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by t
NVD · 2026-09-07T02:17:19.030
- CVE-2026-20502 — In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Use
NVD · 2026-09-07T02:17:18.917
- CVE-2026-20501 — In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. Use
NVD · 2026-09-07T02:17:18.800
- CVE-2026-20500 — In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is n
NVD · 2026-09-07T02:17:18.673
- CVE-2026-16876 — An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with We
NVD · 2026-09-07T02:17:17.630
- CVE-2026-86238 — A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. MEDIUM
NVD · 2026-09-07T01:16:56.223
- CVE-2026-86237 — A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py.MEDIUM
NVD · 2026-09-07T01:16:56.040
- CVE-2026-86236 — A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipuMEDIUM
NVD · 2026-09-07T01:16:55.863
- CVE-2026-86235 — A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of thMEDIUM
NVD · 2026-09-07T00:17:47.030
- CVE-2026-86234 — A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the arMEDIUM
NVD · 2026-09-07T00:17:46.867
- CVE-2026-86233 — A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=uMEDIUM
NVD · 2026-09-07T00:17:46.683
- CVE-2026-86304 — MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor.
parse_assert
NVD · 2026-09-06T23:17:39.483
- CVE-2026-86232 — A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=suppliMEDIUM
NVD · 2026-09-06T23:17:39.323
- CVE-2026-86231 — A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manLOW
NVD · 2026-09-06T23:17:39.157
- CVE-2026-86228 — A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-aiMEDIUM
NVD · 2026-09-06T23:17:38.990
- CVE-2026-86227 — A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didLOW
NVD · 2026-09-06T23:17:38.150
- CVE-2026-86226 — A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of LOW
NVD · 2026-09-06T22:17:20.673
- CVE-2026-86225 — A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_rooHIGH
NVD · 2026-09-06T22:17:20.507
- CVE-2026-86224 — A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a HIGH
NVD · 2026-09-06T21:17:22.567
- CVE-2026-86223 — A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manHIGH
NVD · 2026-09-06T20:17:28.280
- CVE-2026-86222 — A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipuHIGH
NVD · 2026-09-06T20:17:28.117
- CVE-2026-86221 — A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This maniHIGH
NVD · 2026-09-06T19:17:27.943
- CVE-2026-86220 — A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. TheHIGH
NVD · 2026-09-06T18:17:23.150
- CVE-2026-86219 — Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step.
server_start generates a fresh nonce a
NVD · 2026-09-06T18:17:23.027
- CVE-2026-82209 — When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches
NVD · 2026-09-06T18:17:22.847
- CVE-2026-82208 — With the wolfSSL backend, when CA caching is enabled and an
`CURLOPT_SSL_CTX_FUNCTION` callback replaces the trust store, libcurl can
silently reinstall the cached store after the
NVD · 2026-09-06T18:17:22.733
- CVE-2026-80255 — A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
space (ascii code 32) immediately before the `Secure` attribute causes curl to
store the cookie without i
NVD · 2026-09-06T18:17:22.623
- CVE-2026-80231 — A flaw in libcurl makes it wrongly reuse an existing HTTPS connection setup
for a given hostname even when using a different Native CA Store setting
(`CURLSSLOPT_NATIVE_CA`) than w
NVD · 2026-09-06T18:17:22.500
- CVE-2026-80230 — When `CURLOPT_PINNEDPUBLICKEY` is configured alongside options that disable
standard peer verification (`CURLOPT_SSL_VERIFYPEER = 0` and
`CURLOPT_SSL_VERIFYHOST = 0`), libcurl fail
NVD · 2026-09-06T18:17:22.327
- CVE-2026-80229 — When performing transfers via libcurl’s multi interface, pooled TLS
connections can outlive their originating easy handles. In OpenSSL 3 provider
configurations, libcurl attaches a
NVD · 2026-09-06T18:17:22.217
- CVE-2026-19931 — A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given
hostname using Negotiate authentication, when the initial request is done
using empty credentials. Thi
NVD · 2026-09-06T18:17:20.733
- CVE-2026-18924 — A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process
NVD · 2026-09-06T18:17:20.553
- CVE-2026-13608 — A flaw in the libcurl SASL negotiation for LDAP authentication allows an
incomplete handshake sequence to be misinterpreted as a successful
cryptographic verification. An attacker
NVD · 2026-09-06T18:17:19.810
- CVE-2026-82751 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multi
NVD · 2026-09-06T17:17:56.070
- CVE-2026-82750 — Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per sponsored payment by a large multi
NVD · 2026-09-06T17:17:55.867
- CVE-2026-83534 — PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. TMEDIUM
NVD · 2026-09-06T16:16:50.753
- CVE-2026-19634 — PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a suMEDIUM
NVD · 2026-09-06T16:16:50.603
- CVE-2026-19633 — PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untHIGH
NVD · 2026-09-06T16:16:49.583
- CVE-2026-86283 — MISP's UiBeta theme collection view (app/View/Themed/UiBeta/Collections/view.ctp) performed a secondary query of member events by UUID without applying the caller's access control
NVD · 2026-09-06T15:17:24.813
- CVE-2026-86217 — A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component DatabaseMEDIUM
NVD · 2026-09-06T15:17:24.120
- CVE-2026-86216 — A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulationMEDIUM
NVD · 2026-09-06T14:17:25.760
- CVE-2026-86215 — A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. MEDIUM
NVD · 2026-09-06T14:17:24.773
- CVE-2026-86259 — OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. AttackersHIGH
NVD · 2026-09-06T13:17:10.963
- CVE-2026-86258 — nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can reMEDIUM
NVD · 2026-09-06T13:17:10.830
- CVE-2026-86214 — A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causeHIGH
NVD · 2026-09-06T13:17:10.667
- CVE-2026-86213 — A vulnerability was found in Mstfakts College-Management-System. This issue affects the function mysqli_query of the file Front-end/university.php of the component Search Handler. HIGH
NVD · 2026-09-06T13:17:10.487
- CVE-2026-86257 — wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can injecMEDIUM
NVD · 2026-09-06T12:17:16.700
- CVE-2026-86256 — wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode,MEDIUM
NVD · 2026-09-06T12:17:16.567
- CVE-2026-86255 — wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigMEDIUM
NVD · 2026-09-06T12:17:16.433
- CVE-2026-86254 — wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparisoMEDIUM
NVD · 2026-09-06T12:17:16.297
- CVE-2026-86253 — h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-encoded dMEDIUM
NVD · 2026-09-06T12:17:16.163
- CVE-2026-86252 — h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including unsanitMEDIUM
NVD · 2026-09-06T12:17:16.033
- CVE-2026-86251 — h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequences (eMEDIUM
NVD · 2026-09-06T12:17:15.900
- CVE-2026-86250 — h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attackers can sHIGH
NVD · 2026-09-06T12:17:15.767
- CVE-2026-86242 — Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled HIGH
NVD · 2026-09-06T12:17:15.583
- CVE-2026-86212 — A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. The attacMEDIUM
NVD · 2026-09-06T12:17:15.423
- CVE-2026-86205 — h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pathname. AMEDIUM
NVD · 2026-09-06T12:17:15.277
- CVE-2022-51009 — PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets withHIGH
NVD · 2026-09-06T12:17:15.073
- CVE-2022-51008 — PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flooMEDIUM
NVD · 2026-09-06T12:17:14.930
- CVE-2021-48007 — PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with iMEDIUM
NVD · 2026-09-06T12:17:14.783
- CVE-2021-48006 — PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but only removLOW
NVD · 2026-09-06T12:17:14.637
- CVE-2020-37277 — PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send speciallyMEDIUM
NVD · 2026-09-06T12:17:13.547
- CVE-2026-86211 — A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulation of thHIGH
NVD · 2026-09-06T11:18:06.427
- CVE-2026-86210 — A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_uHIGH
NVD · 2026-09-06T10:17:15.330
- CVE-2026-86209 — A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argumHIGH
NVD · 2026-09-06T10:17:15.163
- CVE-2026-86208 — A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of tHIGH
NVD · 2026-09-06T10:17:14.933
- CVE-2026-80439 — The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes those valuMEDIUM
NVD · 2026-09-06T10:17:14.810
- CVE-2026-80437 — The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it laterMEDIUM
NVD · 2026-09-06T10:17:14.693
- CVE-2026-19862 — The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to the headerMEDIUM
NVD · 2026-09-06T10:17:14.563
- CVE-2026-19859 — The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute arbitraryMEDIUM
NVD · 2026-09-06T10:17:13.577
- CVE-2026-86183 — A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.class.phMEDIUM
NVD · 2026-09-06T09:17:16.487
- CVE-2026-86182 — A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of tMEDIUM
NVD · 2026-09-06T09:17:16.310
- CVE-2026-86181 — A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the componentLOW
NVD · 2026-09-06T09:17:16.123
- CVE-2026-86180 — A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the componenHIGH
NVD · 2026-09-06T08:16:41.910
- CVE-2026-86179 — A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup HanMEDIUM
NVD · 2026-09-06T08:16:41.723
- CVE-2026-86172 — A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argument ID rMEDIUM
NVD · 2026-09-06T08:16:40.760
- CVE-2026-86171 — A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the argument IMEDIUM
NVD · 2026-09-06T07:16:43.633
- CVE-2026-85038 — The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected during reMEDIUM
NVD · 2026-09-06T07:16:43.530
- CVE-2026-84219 — The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScript in a cHIGH
NVD · 2026-09-06T07:16:43.427
- CVE-2026-84028 — The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the ContributoMEDIUM
NVD · 2026-09-06T07:16:43.320
- CVE-2026-75793 — The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to create an acMEDIUM
NVD · 2026-09-06T07:16:43.220
- CVE-2026-18480 — The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing users with HIGH
NVD · 2026-09-06T07:16:43.097
- CVE-2026-13159 — The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to MEDIUM
NVD · 2026-09-06T07:16:41.900
- CVE-2026-86170 — A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argument ID cMEDIUM
NVD · 2026-09-06T06:16:41.403
- Welcome to the new Project Zero Blog
Project Zero · 2025-12-16T02:00:00-08:00
- A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby
Project Zero · 2026-01-14T09:59:00-08:00
- A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave
Project Zero · 2026-01-14T10:00:00-08:00
- A 0-click exploit chain for the Pixel 9 Part 3: Where do we go from here?
Project Zero · 2026-01-14T10:01:00-08:00
- Bypassing Windows Administrator Protection
Project Zero · 2026-01-26T00:00:00-08:00
- Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529
Project Zero · 2026-01-30T00:00:00-08:00
- Bypassing Administrator Protection by Abusing UI Access
Project Zero · 2026-02-12T00:00:00-08:00
- A Deep Dive into the GetProcessHandleFromHwnd API
Project Zero · 2026-02-26T00:00:00-08:00
- On the Effectiveness of Mutational Grammar Fuzzing
Project Zero · 2026-03-05T00:00:00-08:00
- A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
Project Zero · 2026-05-13T00:00:00-07:00
- Felons, Fraudsters Flog Offensive Cybersecurity Startup
Krebs on Security · Wed, 08 Jul 2026 12:31:39 +0000
- Lessons Learned from CISA’s Recent GitHub Leak
Krebs on Security · Mon, 13 Jul 2026 15:03:28 +0000
- Microsoft Patches a Record 570 Security Flaws
Krebs on Security · Tue, 14 Jul 2026 19:22:42 +0000
- LG to Ban Residential Proxies from Smart TV Apps
Krebs on Security · Wed, 22 Jul 2026 01:10:38 +0000
- Read This Before You Buy That TV Streaming Stick
Krebs on Security · Thu, 30 Jul 2026 16:49:00 +0000
- Canadian Man Pleads Guilty in Snowflake Extortions
Krebs on Security · Thu, 06 Aug 2026 17:00:56 +0000
- Microsoft Plugs Nearly 400 Security Holes
Krebs on Security · Tue, 11 Aug 2026 21:28:35 +0000
- Who’s Tracking You? Use This New Service to Find Out
Krebs on Security · Fri, 14 Aug 2026 11:24:35 +0000
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Krebs on Security · Thu, 27 Aug 2026 11:04:15 +0000
- FBI Probes Service Selling 153M+ Drivers Licenses
Krebs on Security · Tue, 01 Sep 2026 22:40:28 +0000
- Microsoft: KB5120998 mouse reset bug affects only non-English PCs
BleepingComputer · Thu, 03 Sep 2026 11:22:33 -0400
- HPE patches critical ArubaOS-CX remote code execution flaw
BleepingComputer · Thu, 03 Sep 2026 14:28:12 -0400
- Coder's registry infrastructure compromised to push malicious modules
BleepingComputer · Thu, 03 Sep 2026 16:04:24 -0400
- French hospital fined €500,000 after breach exposes data of 727,000
BleepingComputer · Thu, 03 Sep 2026 18:01:37 -0400
- Google warns of new Chrome zero-day flaw exploited in attacks
BleepingComputer · Fri, 04 Sep 2026 07:48:17 -0400
- Exchange Online outage causes email delays, 'Server busy' errors
BleepingComputer · Fri, 04 Sep 2026 08:22:30 -0400
- New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
BleepingComputer · Fri, 04 Sep 2026 09:22:01 -0400
- 39 New Methods That Compromise Passkey Authentication
BleepingComputer · Fri, 04 Sep 2026 10:01:11 -0400
- Microsoft says some users can’t open the Teams desktop client
BleepingComputer · Fri, 04 Sep 2026 10:30:15 -0400
- Critical Citrix NetScaler auth bypass now leveraged in attacks
BleepingComputer · Fri, 04 Sep 2026 11:25:59 -0400
- IDScan sued over alleged data breach affecting 153 million drivers
BleepingComputer · Fri, 04 Sep 2026 12:56:45 -0400
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident
BleepingComputer · Sat, 05 Sep 2026 07:11:50 -0400
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
BleepingComputer · Sat, 05 Sep 2026 10:29:13 -0400
- Attackers conceal phishing lures using invisible Unicode characters
BleepingComputer · Sun, 06 Sep 2026 10:23:46 -0400
- ChatGPT Astra is now rolling out to $20 Plus subscription
BleepingComputer · Sun, 06 Sep 2026 21:15:43 -0400
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
The Hacker News · Tue, 01 Sep 2026 22:49:24 +0530
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
The Hacker News · Tue, 01 Sep 2026 23:23:11 +0530
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
The Hacker News · Wed, 02 Sep 2026 12:26:30 +0530
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
The Hacker News · Wed, 02 Sep 2026 12:38:50 +0530
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
The Hacker News · Wed, 02 Sep 2026 13:17:13 +0530
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The Hacker News · Wed, 02 Sep 2026 14:40:23 +0530
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
The Hacker News · Wed, 02 Sep 2026 14:48:02 +0530
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
The Hacker News · Wed, 02 Sep 2026 16:23:49 +0530
- How to Secure Enterprise AI: From Adoption to Incident Readiness
The Hacker News · Wed, 02 Sep 2026 17:00:00 +0530
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
The Hacker News · Wed, 02 Sep 2026 17:52:02 +0530
- BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News · Wed, 02 Sep 2026 18:42:45 +0530
- Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
The Hacker News · Wed, 02 Sep 2026 19:14:16 +0530
- Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
The Hacker News · Wed, 02 Sep 2026 19:36:59 +0530
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News · Wed, 02 Sep 2026 22:11:06 +0530
- Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
The Hacker News · Wed, 02 Sep 2026 23:57:49 +0530
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The Hacker News · Thu, 03 Sep 2026 10:49:04 +0530
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The Hacker News · Thu, 03 Sep 2026 11:56:59 +0530
- Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
The Hacker News · Thu, 03 Sep 2026 14:13:17 +0530
- Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
The Hacker News · Thu, 03 Sep 2026 16:06:39 +0530
- Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The Hacker News · Thu, 03 Sep 2026 16:13:01 +0530
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
The Hacker News · Thu, 03 Sep 2026 17:28:00 +0530
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
The Hacker News · Thu, 03 Sep 2026 20:09:05 +0530
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
The Hacker News · Thu, 03 Sep 2026 20:56:47 +0530
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
The Hacker News · Thu, 03 Sep 2026 21:22:07 +0530
- ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The Hacker News · Thu, 03 Sep 2026 23:32:47 +0530
- GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
The Hacker News · Fri, 04 Sep 2026 12:17:52 +0530
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
The Hacker News · Fri, 04 Sep 2026 12:48:47 +0530
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
The Hacker News · Fri, 04 Sep 2026 13:05:14 +0530
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
The Hacker News · Fri, 04 Sep 2026 14:18:45 +0530
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
The Hacker News · Fri, 04 Sep 2026 20:21:13 +0530
- PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
The Hacker News · Fri, 04 Sep 2026 20:50:19 +0530
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
The Hacker News · Fri, 04 Sep 2026 21:27:15 +0530
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
The Hacker News · Sat, 05 Sep 2026 13:01:53 +0530
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
The Hacker News · Sat, 05 Sep 2026 13:25:10 +0530
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
The Hacker News · Sat, 05 Sep 2026 19:47:02 +0530
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
The Hacker News · Sat, 05 Sep 2026 21:35:08 +0530
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
The Hacker News · Sat, 05 Sep 2026 22:22:33 +0530