24h | 7d | 30d

Overview

  • GIMP
  • GIMP

20 Feb 2026
Published
23 Feb 2026
Updated

CVSS v3.0
HIGH (7.8)
EPSS
0.06%

KEV

Description

GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PGM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-28158.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-2044 - GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code o... https://www.cyberhub.blog/cves/CVE-2026-2044
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Microsoft
  • Microsoft SQL Server 2022 (GDR)

13 Jan 2026
Published
22 Feb 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.06%

KEV

Description

Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
Amazon RDS Custom now supports the latest GDR updates for Microsoft SQL Server Amazon RDS Custom for SQL Server now supports the latest GDR updates for Microsoft SQL Server, including SQL Server 2022 Cumulative Update and KB5072936. These updates address CVE-2026-20803 vulnerabilities.
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • SPIP
  • referer_spam

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.10%

KEV

Description

The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE clauses without input validation or parameterization. The endpoints do not enforce authorization checks and do not use SPIP action protections such as securiser_action(), allowing remote attackers to execute arbitrary SQL queries.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

🚨 CVE-2026-27743: CRITICAL SQL injection in SPIP referer_spam <1.3.0 allows unauthenticated SQL execution via GET. No exploit seen yet — patch to 1.3.0+ ASAP! Monitor logs & restrict DB perms. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • UTT
  • HiPER 810G

23 Feb 2026
Published
23 Feb 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.08%

KEV

Description

A vulnerability has been found in UTT HiPER 810G up to 1.7.7-1711. Impacted is the function strcpy of the file /goform/setSysAdm. The manipulation of the argument passwd1 leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Statistics

  • 1 Post

Last activity: 14 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-2980 - A vulnerability has been found in UTT HiPER 810G up to 1.7.7-1711. Impacted is the function strcpy of the file /goform/setSysAdm. The manipulation of ... https://www.cyberhub.blog/cves/CVE-2026-2980
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Tattile s.r.l.
  • Smart+

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.04%

KEV

Description

Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default credentials and gain administrative access, enabling unauthorized access to device configuration and data.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CVE-2026-26341 in Tattile Smart+, Vega & Basic (fw ≤1.181.5) — default creds allow admin access if device is reachable. Change passwords, restrict interface access ASAP. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Microsoft Corporation
  • Equation Editor

10 Jan 2018
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
93.89%

Description

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
『XWormはモジュール式を採用しているため、50種類以上のプラグインが追加できる』:Excelの古い脆弱性、XWormマルウェア配布に悪用される(CVE-2018-0802) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/44084/
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 14 hours ago

Bluesky

Profile picture fallback
FreeBSD Kernel Under Fire: New Critical Stack Overflow CVE-2026-3038 Puts All Versions at Risk for Privilege Escalation + Video Introduction: The integrity of the FreeBSD kernel has been compromised by a newly discovered stack overflow vulnerability, designated CVE-2026-3038, which allows an…
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Beyond Limits Inc.
  • Altec DocLink

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.64%

KEV

Description

Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe object unmarshalling, allowing remote attackers to read arbitrary files from the underlying system by specifying local file paths. Additionally, attackers can coerce SMB authentication via UNC paths and write arbitrary files to server locations. Because writable paths may be web-accessible under IIS, this can result in unauthenticated remote code execution or denial of service through file overwrite.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

🚩 CRITICAL: CVE-2026-26222 in Altec DocLink 4.0.336.0 enables unauthenticated remote code execution & file access via unsafe .NET deserialization. No patch yet — immediately restrict/segment endpoints & monitor. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Dell
  • Wyse Management Suite

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
Pending

KEV

Description

Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
📌 CVE-2026-22765 - Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access cou... https://www.cyberhub.blog/cves/CVE-2026-22765
  • 0
  • 0
  • 0
  • Last hour

Overview

  • SonicWall
  • SonicOS

23 Aug 2024
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
3.54%

Description

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource access and in specific conditions, causing the firewall to crash. This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Sophos~ Identity-based attacks now account for 67% of root causes, as adversaries increasingly 'log in' rather than 'break in'. - IOCs: CVE-2024-40766, Akira, Qilin - #IdentitySecurity #Ransomware #ThreatIntel
  • 0
  • 0
  • 0
  • 23h ago
Showing 31 to 40 of 84 CVEs