Posts of last few hours
A vulnerability, which was classified as critical, was found in fastify busboy up to 3.2.0. Affected by this vulnerability is an unknown functionality of the component Header Parser. Executing a manipulation can lead to improperly controlled modification of object prototype attributes.
This vulnerability is handled as CVE-2026-19481. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/389357
Фермент Пакман открыл опасную сторону пластисферы.
https://www.securitylab.ru/news/576898.php
A vulnerability classified as very critical has been found in Microsoft Windows up to Server 2025. This vulnerability affects unknown code of the component Deployment Services. Performing a manipulation results in use after free.
This vulnerability is identified as CVE-2026-62893. The attack can be initiated remotely. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/388612
A vulnerability categorized as problematic has been discovered in Quanovate Tech Mira and Mira Android App 1.7.1.47. This impacts an unknown function. Such manipulation leads to missing encryption of sensitive data.
This vulnerability is referenced as CVE-2026-66875. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/388761
A vulnerability identified as critical has been detected in Quanovate Tech Mira and Mira Android App. Affected is an unknown function of the component BLE. Performing a manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-66098. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/388762
A vulnerability classified as critical has been found in Microsoft Visual Studio Code CoPilot Chat Extension up to 1.132.0. This vulnerability affects unknown code of the component CoPilot Chat. This manipulation causes improper authorization.
This vulnerability is registered as CVE-2026-65675. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/388766
A vulnerability classified as very critical has been found in Microsoft Windows up to Server 2025. This issue affects some unknown processing of the component DNS. Performing a manipulation results in use after free.
This vulnerability is identified as CVE-2026-65789. The attack can be initiated remotely. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/388822
A vulnerability was found in Microsoft GitHub Copilot and Visual Studio Code up to 1.132.0. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in os command injection.
This vulnerability is reported as CVE-2026-70335. The attack requires a local approach. No exploit exists.
Upgrading the affected component is advised.
https://vuldb.com/vuln/388858
A vulnerability labeled as critical has been found in Microsoft Visual Studio Code up to 1.132.0. Affected is an unknown function. The manipulation results in improper authorization.
This vulnerability is known as CVE-2026-69306. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/388861
CVE-2026-69320 | Microsoft Visual Studio Code up to 1.132.0 os command injection (WID-SEC-2026-2761)
A vulnerability marked as critical has been reported in Microsoft Visual Studio Code up to 1.132.0. Affected by this vulnerability is an unknown functionality. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-69320. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/388862
A vulnerability described as critical has been identified in Microsoft Visual Studio Code up to 1.132.0. Affected by this issue is some unknown functionality. Such manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-70336. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/388863
A vulnerability has been found in Microsoft Visual Studio Code up to 1.132.0 and classified as problematic. The affected element is an unknown function. This manipulation causes improper authorization.
This vulnerability is tracked as CVE-2026-69278. The attack is restricted to local execution. No exploit exists.
The affected component should be upgraded.
https://vuldb.com/vuln/388868
A vulnerability categorized as problematic has been discovered in Total Upkeep Plugin up to 1.17.2 on WordPress. Affected by this issue is some unknown functionality. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-16253. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/388929
A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been rated as problematic. The affected element is an unknown function of the component Logging. The manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-71474. The attack must be carried out locally. There is no available exploit.
https://vuldb.com/vuln/388494
A vulnerability was found in Red Hat Advanced Cluster Management for Kubernetes. It has been classified as problematic. This issue affects some unknown processing of the component Insights API URL Path. Performing a manipulation of the argument ClusterID results in open redirect.
This vulnerability is identified as CVE-2026-71475. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/388492
Currently trending CVE - Hype Score: 8 - Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.
These vulnerabilities are due to ...
https://cvemon.intruder.io/cves/CVE-2026-20355
Currently trending CVE - Hype Score: 35 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
https://cvemon.intruder.io/cves/CVE-2026-20279
Currently trending CVE - Hype Score: 35 - As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered ...
https://cvemon.intruder.io/cves/CVE-2026-20274
Currently trending CVE - Hype Score: 9 - Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
https://cvemon.intruder.io/cves/CVE-2026-12555
Currently trending CVE - Hype Score: 9 - Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.
https://cvemon.intruder.io/cves/CVE-2026-12556
Latest Blog Posts
- 1 week 6 days ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago