Aggregator
Please support the site operations by clicking ads.
[Virtual Event] Building a Secure AI Strategy for the Enterprise
3 weeks 5 days hence
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
6 hours 25 minutes ago
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
Nate Nelson
CVE-2026-79396 | XiongMai IP Camera up to 220608.1837 bin/config.xml hard-coded credentials
6 hours 43 minutes ago
A vulnerability was found in XiongMai IP Camera up to 220608.1837. It has been rated as very critical. This impacts an unknown function of the file bin/config.xml. The manipulation leads to hard-coded credentials.
This vulnerability is documented as CVE-2026-79396. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-54072 | Authorizerdev Authorizer up to 2.2.0 Authorize Endpoint redirect_uri
6 hours 43 minutes ago
A vulnerability was found in Authorizerdev Authorizer up to 2.2.0. It has been declared as problematic. This affects an unknown function of the component Authorize Endpoint. Executing a manipulation of the argument redirect_uri can lead to open redirect.
This vulnerability is registered as CVE-2026-54072. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-79362 | WoltLab Suite Core up to 6.2.5 Cache injection
6 hours 44 minutes ago
A vulnerability was found in WoltLab Suite Core up to 6.2.5. It has been classified as critical. The impacted element is an unknown function of the component Cache. Performing a manipulation results in injection.
This vulnerability is cataloged as CVE-2026-79362. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
Florida confirms DMV database breached via stolen police account
6 hours 46 minutes ago
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
Lawrence Abrams
CVE-2026-62138 | Visual Composer Plugin up to 45.16.1 on WordPress cross site scripting
6 hours 55 minutes ago
A vulnerability was found in Visual Composer Plugin up to 45.16.1 on WordPress and classified as problematic. The affected element is an unknown function. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-62138. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-62139 | Google Site Kit Plugin up to 1.186.0 on WordPress cross-site request forgery
6 hours 56 minutes ago
A vulnerability has been found in Google Site Kit Plugin up to 1.186.0 on WordPress and classified as problematic. Impacted is an unknown function. This manipulation causes cross-site request forgery.
This vulnerability is tracked as CVE-2026-62139. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-62140 | ExpressTech Systems Quiz and Survey Master Plugin up to 11.2.5 on WordPress authorization
6 hours 57 minutes ago
A vulnerability, which was classified as problematic, was found in ExpressTech Systems Quiz and Survey Master Plugin up to 11.2.5 on WordPress. This issue affects some unknown processing. The manipulation results in authorization bypass.
This vulnerability is identified as CVE-2026-62140. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-62088 | 10up ElasticPress Plugin up to 5.3.4 on WordPress information disclosure
6 hours 57 minutes ago
A vulnerability, which was classified as problematic, has been found in 10up ElasticPress Plugin up to 5.3.4 on WordPress. This vulnerability affects unknown code. The manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-62088. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-71646 | Robotics-STAR-Lab RACER Fast Exploration FSM fast_exploration_fsm.cpp optTimerCallback denial of service (abcdef1234567890)
6 hours 58 minutes ago
A vulnerability classified as problematic was found in Robotics-STAR-Lab RACER. This affects the function FastExplorationFSM::optTimerCallback of the file swarm_exploration/exploration_manager/src/fast_exploration_fsm.cpp of the component Fast Exploration FSM. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2026-71646. The attack may be launched remotely. There is no exploit available.
A patch should be applied to remediate this issue.
vuldb.com
CVE-2026-79395 | XiongMai IP Camera up to 0608.1837 WS-Security Verification Routine improper authentication
6 hours 58 minutes ago
A vulnerability classified as very critical has been found in XiongMai IP Camera up to 0608.1837. Affected by this issue is some unknown functionality of the component WS-Security Verification Routine. Performing a manipulation results in improper authentication.
This vulnerability was named CVE-2026-79395. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-79394 | XiongMai Sofia IPC daemon up to 0608.1837 RTSP Server access control
6 hours 59 minutes ago
A vulnerability described as problematic has been identified in XiongMai Sofia IPC daemon up to 0608.1837. Affected by this vulnerability is an unknown functionality of the component RTSP Server. Such manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2026-79394. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-79393 | XiongMai IP Camera up to 0608.1837 Sofia IPC daemon WS-Addressing Action transformation function wsa5:Action buffer overflow
6 hours 59 minutes ago
A vulnerability marked as very critical has been reported in XiongMai IP Camera up to 0608.1837. Affected is the function WS-Addressing Action transformation function of the component Sofia IPC daemon. This manipulation of the argument wsa5:Action causes buffer overflow.
This vulnerability is handled as CVE-2026-79393. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-81910 | Concrete CMS up to 9.5.2 Theme Customizer special elements in template engine
7 hours ago
A vulnerability labeled as problematic has been found in Concrete CMS up to 9.5.2. This impacts an unknown function of the component Theme Customizer. The manipulation results in improper neutralization of special elements used in a template engine.
This vulnerability is known as CVE-2026-81910. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
7 hours 3 minutes ago
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
Arielle Waldman
CVE-2026-62133 | Rometheme RTMKit Plugin up to 2.1.5 on WordPress cross-site request forgery
7 hours 6 minutes ago
A vulnerability identified as problematic has been detected in Rometheme RTMKit Plugin up to 2.1.5 on WordPress. This affects an unknown function. The manipulation leads to cross-site request forgery.
This vulnerability is traded as CVE-2026-62133. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-62111 | Simple Payment Plugin up to 2.5.4 on WordPress cross site scripting
7 hours 6 minutes ago
A vulnerability categorized as problematic has been discovered in Simple Payment Plugin up to 2.5.4 on WordPress. The impacted element is an unknown function. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2026-62111. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-62110 | Boldmes Bold Page Builder Plugin up to 5.9.9 on WordPress cross site scripting
7 hours 7 minutes ago
A vulnerability was found in Boldmes Bold Page Builder Plugin up to 5.9.9 on WordPress. It has been rated as problematic. The affected element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-62110. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com