Latest Vulnerabilities
Latest Found
The latest vulnerability announcements
- CVE-2026-48840 - Exim Uninitialized Stack Memory Disclosure Vulnerability
- CVE-2026-9831 - ExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race Condition
- CVE-2026-4387 - Unencrypted storage of authentication state in StrongDM Desktop Application state.kv file
- CVE-2026-48810 - FreeScout: Thread Edit Authorization Bypass via Missing Mailbox Check
- CVE-2026-48811 - FreeScout: Thread Deletion Bypasses Mailbox Access Revocation
- CVE-2026-46527 - cpp-httplib: Malicious `X-Forwarded-For` Under Trusted-Proxy Configuration Triggers Empty `vector::front()`, Leading to Undefined Behavior and Server Crash
- CVE-2026-46599 - Excessive resource consumption in PackBits decompression in golang.org/x/image/tiff
- CVE-2026-47123 - FreeScout: Agent Impersonation via Missing HMAC Verification on Notification Reply Message-ID Path
- CVE-2026-47266 - Formie: Unauthenticated front-end submission editing can overwrite existing submissions
- CVE-2026-48555 - Spatie Laravel Media Library < 11.23.0 SSRF via addMediaFromUrl()
CISA Advisories
The latest advisories from CISA
- CISA Adds One Known Exploited Vulnerability to Catalog
- Supply Chain Compromises Impact Nx Console and GitHub Repositories
- CP Plus 8 Ch. Network Video Recorder
- Schnieider Electric EcoStruxure Machine Expert HVAC
- Fourth Frontier Frontier X Mobile Application, Frontier X2
- ABB Busch-Welcome 2 Wire Door Opener Actuator
- Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
- XCharge C6
- KMW CCTV Security Cameras
- MacGregor Voyage Data Recorder (VDR) G4e