Posts of last 24 hours
A vulnerability categorized as problematic has been discovered in FreeScout up to 1.8.223. This impacts an unknown function of the component file upload endpoint. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-53596. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/380753
Ivanti CSO Daniel Spicer says frontier models have shown surprising effectiveness in early stages; but cost and human-in-the-loop viability remain open questions.
https://www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation
A vulnerability was found in Best Practical RT up to 5.0.9/6.0.2. It has been rated as problematic. This affects an unknown function of the component URL Handler. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-44230. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/380752
A vulnerability was found in Best Practical RT up to 5.0.9/6.0.2. It has been declared as problematic. The impacted element is an unknown function of the component Upload. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-44229. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/380751
Currently trending CVE - Hype Score: 5 - Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
https://cvemon.intruder.io/cves/CVE-2026-32201
Currently trending CVE - Hype Score: 11 - Integer underflow (wrap or wraparound) in Windows NT OS Kernel allows an authorized attacker to elevate privileges locally.
https://cvemon.intruder.io/cves/CVE-2026-42980
Currently trending CVE - Hype Score: 15 - A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a ...
https://cvemon.intruder.io/cves/CVE-2026-42533
Currently trending CVE - Hype Score: 17 - In the Linux kernel, the following vulnerability has been resolved:
rtmutex: Use waiter::task instead of current in remove_waiter()
remove_waiter() is used by the slowlock paths, but it is also used for
proxy-lock rollback in rt_mutex_start_proxy_lock() when invoked ...
https://cvemon.intruder.io/cves/CVE-2026-43499
Currently trending CVE - Hype Score: 35 - WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
https://cvemon.intruder.io/cves/CVE-2026-60137