The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of…
active exploitationAjax.NETAjax.NET ProfessionalCISA
CERT/CC has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library, mwEmbed (also distributed as html5lib), that allow remote, unauthenticated attackers…
Kaltura is a video platform provider offering tools for video management, publishing, playback, and integration. The company distributes the mwEmbed player library…
mwEmbed is Kaltura's HTML5 video player library, also distributed as html5lib. It contains two unpatched vulnerabilities (CVE-2026-19912 and CVE-2026-19913) in the mwEmbedLoader.php…
html5lib is the distribution name for Kaltura's mwEmbed player library. Affected releases include v2.45, v2.103 and earlier, and other v2.x releases that…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution vulnerability in Gitea, tracked as CVE-2026-60004 (CVSS…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
A newly disclosed critical vulnerability in GitLab, tracked as CVE-2026-19478 (CVSS 9.4), is already being actively exploited in the wild, according to…
active exploitationcode injectionCVE-2026-19478Enterprise Security
A now-patched command injection vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 (CVSS 8.9), is under active exploitation in the wild, according…