Aggregator
CVE-2026-48241 | openises Tickets up to 3.44.1 loader.php hard-coded credentials
CVE-2026-48236 | openises Tickets up to 3.44.1 POST Parameter db_loader.php ticketsdb/ticketshost/ticketsuser/ticketspassword sql injection
CVE-2026-48235 | openises Tickets up to 3.44.1 Remote GPS Tracker Endpoint incs/remotes.inc.php sql injection
CVE-2026-48207 | Apache Fory 0.x unsafe deserialization (EUVD-2026-31292)
CVE-2026-48246 | openises Tickets up to 3.44.1 Google Maps Directions API Lookup ajax/reports.php certificate validation (EUVD-2026-31327)
CVE-2026-48245 | openises Tickets up to 3.44.1 Google Maps API tables.php hard-coded credentials
CVE-2026-48244 | openises Tickets up to 3.44.1 Google Maps API settings.inc.php hard-coded credentials (EUVD-2026-31323)
CVE-2026-3985 | constantcontact Creative Mail Plugin up to 1.6.9 on WordPress has_checkout_consent checkout_uuid sql injection (CNNVD-202605-4471)
CVE-2026-39309 | TriliumNext Trilium up to 0.102.1 clickjacking (GHSA-66pm-8hvq-2wwx / CNNVD-202605-4472)
Tech giants promise British regulator they will tweak platforms to protect kids online
SamaraCTF 2026
Date: May 15, 2026, 3 p.m. — 17 May 2026, 15:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://samara.volgactf.ru/
Rating weight: 25.00
Event organizers: SamaraCTF.ru
CVE-2026-27393 | Tobias CF7 WOW Styler Plugin up to 1.7.6 on WordPress authorization (EUVD-2026-31248)
CVE-2026-5118 | Divi Engine Divi Form Builder Plugin up to 5.1.2 on WordPress Setting default_user_role privileges management (EUVD-2026-31270)
CVE-2026-8596 | AWS Amazon SageMaker Python SDK up to 2.257.1/3.7.1 Serve cleartext storage (GHSA-7hh5-prp2-mfh5 / EUVD-2026-30420)
Fake Invitation Phishing Campaign Targets U.S. Organizations With Credential Theft
A large-scale phishing campaign is actively targeting U.S. organizations, using fake event invitations as bait to steal login credentials, intercept one-time passwords, or install remote access tools. The operation has been running since at least December 2025, with researchers tracking a growing pool of malicious domains built around the same repeatable framework. What makes this […]
The post Fake Invitation Phishing Campaign Targets U.S. Organizations With Credential Theft appeared first on Cyber Security News.
CVE-2026-20240 | Splunk Enterprise/Cloud Platform splunk_archiver App coldToFrozen.sh denial of service (SVD-2026-0504 / Nessus ID 315751)
CVE-2021-47952 | Jsonpickle python jsonpickle 2.0.0 eval code injection (Exploit 49585 / Nessus ID 315993)
Trump postpones executive order focused on AI security
Under a draft executive order, the NSA, Treasury Department and other federal agencies would get 90-days to test new models for cybersecurity and national security concerns.
The post Trump postpones executive order focused on AI security appeared first on CyberScoop.