THREAT OPS › Threat News
Threat Intelligence News
12244 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- [NVD] CVE-2026-21349 (HIGH 7.8) — Lightroom Desktop versions 15.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21348 (MEDIUM 5.5) — Substance3D - Modeler versions 1.22.5 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user intnvd · 2026-02-10
- [NVD] CVE-2026-21355 (MEDIUM 5.5) — DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction invd · 2026-02-10
- [NVD] CVE-2026-21354 (MEDIUM 5.5) — DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation of this isnvd · 2026-02-10
- [NVD] CVE-2026-21353 (HIGH 7.8) — DNG SDK versions 1.7.1 2410 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious finvd · 2026-02-10
- [NVD] CVE-2026-21352 (HIGH 7.8) — DNG SDK versions 1.7.1 2410 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21347 (HIGH 7.8) — Bridge versions 15.1.3, 16.0.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a maliciousnvd · 2026-02-10
- [NVD] CVE-2026-21346 (HIGH 7.8) — Bridge versions 15.1.3, 16.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21345 (HIGH 7.8) — Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the contexnvd · 2026-02-10
- [NVD] CVE-2026-21344 (HIGH 7.8) — Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the contexnvd · 2026-02-10
- [NVD] CVE-2026-21343 (HIGH 7.8) — Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the contexnvd · 2026-02-10
- [NVD] CVE-2026-21342 (HIGH 7.8) — Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21341 (HIGH 7.8) — Substance3D - Stager versions 3.1.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- The February 2026 Security Update Reviewzdi_blog · 2026-02-10
- [NVD] CVE-2026-21358 (MEDIUM 5.5) — InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation ofnvd · 2026-02-10
- [NVD] CVE-2026-21357 (HIGH 7.8) — InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicinvd · 2026-02-10
- [NVD] CVE-2026-21351 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21350 (MEDIUM 5.5) — After Effects versions 25.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue reqnvd · 2026-02-10
- [NVD] CVE-2026-21340 (MEDIUM 5.5) — Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user innvd · 2026-02-10
- [NVD] CVE-2026-21339 (MEDIUM 5.5) — Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user innvd · 2026-02-10
- [NVD] CVE-2026-21338 (MEDIUM 5.5) — Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of thinvd · 2026-02-10
- [NVD] CVE-2026-21337 (MEDIUM 5.5) — Substance3D - Designer versions 15.1.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user intenvd · 2026-02-10
- [NVD] CVE-2026-21336 (MEDIUM 5.5) — Substance3D - Designer versions 15.1.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of thinvd · 2026-02-10
- [NVD] CVE-2026-21335 (HIGH 7.8) — Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious finvd · 2026-02-10
- [NVD] CVE-2026-21334 (HIGH 7.8) — Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious finvd · 2026-02-10
- [NVD] CVE-2026-21332 (MEDIUM 5.5) — InDesign Desktop versions 21.1, 20.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user innvd · 2026-02-10
- [NVD] CVE-2026-21330 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a nvd · 2026-02-10
- [NVD] CVE-2026-21329 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21328 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21327 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21326 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21325 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of thenvd · 2026-02-10
- [NVD] CVE-2026-21324 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of thenvd · 2026-02-10
- [NVD] CVE-2026-21323 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21322 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of thenvd · 2026-02-10
- [NVD] CVE-2026-21321 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious finvd · 2026-02-10
- [NVD] CVE-2026-21320 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21319 (MEDIUM 5.5) — After Effects versions 25.6 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in nvd · 2026-02-10
- [NVD] CVE-2026-21318 (HIGH 7.8) — After Effects versions 25.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-21317 (MEDIUM 5.5) — Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in thanvd · 2026-02-10
- [NVD] CVE-2026-21316 (MEDIUM 5.5) — Audition versions 25.3 and earlier are affected by an Access of Memory Location After End of Buffer vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to cause the application to crash or become unresponsive. Exploitation nvd · 2026-02-10
- [NVD] CVE-2026-21315 (MEDIUM 5.5) — Audition versions 25.3 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to access sensitive information stored in memory. Exploitation of this issue requires user interaction in that nvd · 2026-02-10
- [NVD] CVE-2026-21314 (MEDIUM 5.5) — Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in thanvd · 2026-02-10
- [NVD] CVE-2026-21313 (MEDIUM 5.5) — Audition versions 25.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in thanvd · 2026-02-10
- [NVD] CVE-2026-21312 (HIGH 7.8) — Audition versions 25.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.nvd · 2026-02-10
- [NVD] CVE-2026-0651 (HIGH 7.8) — A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalinvd · 2026-02-10
- SolarWinds Web Help Desk Exploitation - February 2026elastic_security · 2026-02-10
- [NVD] CVE-2026-25639 (HIGH 7.5) — Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providinvd · 2026-02-09
- [NVD] CVE-2025-14831 (MEDIUM 5.3) — A flaw was found in GnuTLS. This vulnerability allows a denial of service (DoS) by excessive CPU (Central Processing Unit) and memory consumption via specially crafted malicious certificates containing a large number of name constraints and subject alternative names (SANs).nvd · 2026-02-09
- [NVD] CVE-2026-23903 (MEDIUM 5.3) — Authentication Bypass by Alternate Name vulnerability in Apache Shiro. This issue affects Apache Shiro: before 2.0.7. Users are recommended to upgrade to version 2.0.7, which fixes the issue. The issue only effects static files. If static files are served from a case-insensitinvd · 2026-02-09
- [NVD] CVE-2026-1615 (CRITICAL 9.8) — Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not designed to handle untrusted data safely. Anvd · 2026-02-09
- [NVD] CVE-2025-15267 (MEDIUM 6.4) — The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's bt_bb_accordion_item shortcode in all versions up to, and including, 5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes invd · 2026-02-07
- [NVD] CVE-2026-1337 (MEDIUM 5.4) — Insufficient escaping of unicode characters in query log in Neo4j Enterprise and Community editions prior to 2026.01 can lead to XSS if the user opens the logs in a tool that treats them as HTML. There is no security impact on Neo4j products, but this advisory is released as a prnvd · 2026-02-06
- [NVD] CVE-2026-2015 (MEDIUM 6.3) — A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can bnvd · 2026-02-06
- DYNOWIPER: Destructive Malware Targeting Poland's Energy Sectorelastic_security · 2026-02-06
- [NVD] CVE-2020-37121 (MEDIUM 5.5) — CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious text file with 1982 bytes of buffer and shellcode to trigger rnvd · 2026-02-05
- CVE-2025-6978: Arbitrary Code Execution in the Arista NG Firewallzdi_blog · 2026-02-05
- OpenAI Explains URL-Based Data Exfiltration Mitigations in New Paperembracethered · 2026-02-05
- Automating GOAD and Live Malware Labselastic_security · 2026-02-05
- From Automation to Infection (Part II): Reverse Shells, Semantic Worms, and Cognitive Rootkits in OpenClaw Skillsvirustotal_blog · 2026-02-04
- The Engineer's Guide to Elastic Detections as Codeelastic_security · 2026-02-04
- [NVD] CVE-2025-62673 (HIGH 8.0) — Heap-based Buffer Overflow vulnerability in Archer AX53 v1.0 and AX12 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field. This issue anvd · 2026-02-03
- [NVD] CVE-2025-69848 (MEDIUM 5.4) — NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scripting (XSS) vulnerability exists in versions 2.11.0 through 3.7.x in the ProtectedError handling logic, where object names are included in HTML error messages nvd · 2026-02-03
- [NVD] CVE-2026-24737 (HIGH 8.1) — jsPDF is a library to generate PDFs in JavaScript. Prior to 4.1.0, user control of properties and methods of the Acroform module allows users to inject arbitrary PDF objects, such as JavaScript actions. If given the possibility to pass unsanitized input to one of the following menvd · 2026-02-02
- From Automation to Infection: How OpenClaw AI Agent Skills Are Being Weaponizedvirustotal_blog · 2026-02-02
- [NVD] CVE-2026-22223 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2 and BE3600 v1 (vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in sevenvd · 2026-02-02
- [NVD] CVE-2026-22221 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and BE3600 v1 allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resulting in severnvd · 2026-02-02
- [NVD] CVE-2026-0631 (HIGH 8.0) — An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) and OpenVPN of AXE75 v1 allows an adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of the device, resunvd · 2026-02-02
- [NVD] CVE-2026-1757 (MEDIUM 6.2) — A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command executionvd · 2026-02-02
- Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)watchtowr · 2026-01-30
- [NVD] CVE-2024-4027 (HIGH 7.5) — A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-senvd · 2026-01-30
- VulHunt in Practice: Detecting a Remote Code Execution Vulnerability in rsyncbinarly · 2026-01-30
- 2026-001: Critical vulnerabilities in Ivanti EPMMcert_eu · 2026-01-30
- [NVD] CVE-2025-1395 (HIGH 8.2) — Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026. NOTE: The vendor was contacted and it was learned tnvd · 2026-01-30
- Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529project_zero · 2026-01-30
- [NVD] CVE-2025-61731 (HIGH 7.8) — Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of the file content. The "#cgo pkg-config:" directive in a Go source file provides command-line arguments to provide to the Go pkg-config command. An attacker cannvd · 2026-01-28
- [NVD] CVE-2025-61726 (HIGH 7.5) — The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a lanvd · 2026-01-28
- [NVD] CVE-2026-24842 (HIGH 8.2) — node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bnvd · 2026-01-28
- New Android Theft Protection Feature Updates: Smarter, Strongergoogle_security · 2026-01-27
- [NVD] CVE-2025-15467 (HIGH 8.8) — Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. Whennvd · 2026-01-27
- [NVD] CVE-2026-24486 (HIGH 8.6) — Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on thnvd · 2026-01-27
- [NVD] CVE-2025-9820 (MEDIUM 4.0) — A flaw was found in the GnuTLS library, specifically in the gnutls_pkcs11_token_init() function that handles PKCS#11 token initialization. When a token label longer than expected is processed, the function writes past the end of a fixed-size stack buffer. This programming error cnvd · 2026-01-26
- Have you patched? Are you sure? The story of the sticky Supermicro BMC bugsbinarly · 2026-01-26
- Bypassing Windows Administrator Protectionproject_zero · 2026-01-26
- [NVD] CVE-2025-14843 (MEDIUM 5.3) — The Wizit Gateway for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Arbitrary Order Cancellation in all versions up to, and including, 1.3.1. This is due to a lack of authentication and authorization checks in the 'handle_checkout_redirecturl_response' functionvd · 2026-01-24
- [Breach] Edmunds — 177,860 accounts exposedhibp_breaches · 2026-01-24
- [NVD] CVE-2026-24423 (CRITICAL 9.8) — SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be nvd · 2026-01-23
- [NVD] CVE-2026-0994 (HIGH 7.5) — A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing recursion depth accounting inside the internal Any-handling lnvd · 2026-01-23
- [NVD] CVE-2026-0603 (HIGH 8.3) — A flaw was found in Hibernate. A remote attacker with low privileges could exploit a second-order SQL injection vulnerability by providing specially crafted, unsanitized non-alphanumeric characters in the ID column when the InlineIdsOrClauseBuilder is used. This could lead to sennvd · 2026-01-23
- [NVD] CVE-2026-0767 — Rejected reason: Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue. https://docs.openwebuinvd · 2026-01-23
- [NVD] CVE-2026-0766 — Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.openvd · 2026-01-23
- [NVD] CVE-2026-0765 — Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue. https://docs.opnvd · 2026-01-23
- Pwn2Own Automotive 2026 - Day Three Results and the Master of Pwnzdi_blog · 2026-01-23
- [NVD] CVE-2026-23760 (CRITICAL 9.8) — SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administranvd · 2026-01-22
- [NVD] CVE-2026-24332 (MEDIUM 4.3) — Discord through 2026-01-16 allows gathering information about whether a user's client state is Invisible (and not actually offline) because the response to a WebSocket API request includes the user in the presences array (with "status": "offline"), whereas offline users are omittnvd · 2026-01-22
- [NVD] CVE-2026-24049 (HIGH 7.1) — wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filnvd · 2026-01-22
- [NVD] CVE-2025-13465 (MEDIUM 5.3) — Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype pollution in the _.unset and _.omit functions. An attacker can pass crafted paths which cause Lodash to delete methods from global prototypes. The issue permits deletion of properties but does not allow overwritinnvd · 2026-01-21
- [NVD] CVE-2025-13878 (HIGH 7.5) — Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.nvd · 2026-01-21
- [NVD] CVE-2026-21962 (CRITICAL 10.0) — Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1nvd · 2026-01-20
- [NVD] CVE-2025-56005 (CRITICAL 9.8) — An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the `picklefile` parameter in the `yacc()` function. This parameter accepts a `.pkl` file that is deserialized with `pickle.load()` without validation. Because `picnvd · 2026-01-20