CVE-2026-80104 — Critical vulnerability brief
CVSS 9.3DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in…
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user…
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability…
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062)…
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository…
CVE-2024-28224 is a vulnerability in Ollama that allows DNS rebinding attacks to access the Ollama API without authentication. The issue was fixed…
Marimo, the developer of the open-source Marimo notebook software, has patched a high-severity code injection vulnerability tracked as CVE-2026-75149. The flaw, discovered…
CVE-2026-75149 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
CVE-2026-67618 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…