Offensive Sequence
- CVE-2026-93436: Missing Release of Memory after Effective Lifetime in vllm-project vllm [12m]
- CVE-2026-93435: Uncontrolled Recursion in NodeRedis redis-parser [12m]
- CVE-2026-86688: CWE-384 Session Fixation in team-alembic ash_authentication [42m]
- CVE-2026-76949: CWE-290 Authentication Bypass by Spoofing in team-alembic ash_authentication [42m]
- CVE-2026-54734: CWE-918: Server-Side Request Forgery (SSRF) in prebid prebid-server-java [42m]
- CVE-2026-54648: CWE-862: Missing Authorization in cubecart v6 [42m]
- CVE-2026-54643: CWE-862: Missing Authorization in cubecart v6 [42m]
- CVE-2026-54642: CWE-352: Cross-Site Request Forgery (CSRF) in cubecart v6 [42m]
- CVE-2026-54520: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vmDeshpande ai-agent-automation [42m]
- CVE-2026-54519: CWE-862: Missing Authorization in vmDeshpande ai-agent-automation [42m]
- New RatHat Android malware uses AI to automate device control [43m]
- AI agents trust MCP tool descriptions the way browsers trust TLS certs. Attackers are starting to exploit that. [43m]
- CVE-2026-92970: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in hubzero hubzero-cms [47m]
- CVE-2026-92963: CWE-227 in patriksimek vm2 [47m]
- CVE-2026-92961: Allocation of Resources Without Limits or Throttling in patriksimek vm2 [47m]
- CVE-2026-92959: Protection Mechanism Failure in patriksimek vm2 [47m]
- CVE-2026-92958: Improper Privilege Management in patriksimek vm2 [47m]
- CVE-2026-92954: Uncaught Exception in patriksimek vm2 [47m]
- CVE-2026-92953: Improper Control of Dynamically-Managed Code Resources in patriksimek vm2 [47m]
- CVE-2026-92949: Modification of Assumed-Immutable Data (MAID) in patriksimek vm2 [47m]
- CVE-2026-92948: Protection Mechanism Failure in patriksimek vm2 [47m]
- CVE-2026-92944: Protection Mechanism Failure in patriksimek vm2 [47m]
- CVE-2026-92942: Uncontrolled Resource Consumption in patriksimek vm2 [47m]
- CVE-2026-92938: Protection Mechanism Failure in patriksimek vm2 [47m]
- CVE-2026-92937: Improper Control of Generation of Code ('Code Injection') in patriksimek vm2 [47m]
VulDB
- CVE-2026-54646 | CubeCart up to 6.7.4 Maintenance maintenance.index.inc.php tablename sql injection [37m]
- CVE-2026-54645 | CubeCart up to 6.7.4 Product Editing products.index.inc.php RAW cross site scripting [37m]
- CVE-2026-54647 | CubeCart up to 6.7.4 Settings settings.index.inc.php download_expire sql injection [38m]
- CVE-2026-54644 | CubeCart up to 6.7.4 GUI Message classes/gui.class.php _errorMessage cross site scripting [38m]
- CVE-2026-93203 | Linux Kernel up to 7.2.5 batman-adv batadv_bla_add_claim race condition [43m]
- CVE-2026-93118 | Linux Kernel up to 7.2.5 aspeed_udc ast_udc_probe null pointer dereference [43m]
- CVE-2026-93201 | Linux Kernel up to 7.2.5 dm-pcache cache_pos_decode out-of-bounds [44m]
- CVE-2026-93204 | Linux Kernel up to 7.2.5 batman-adv batadv_dat_entry_add race condition [44m]
- CVE-2026-93200 | Linux Kernel up to 6.18.51/7.2.5 i3c i3c_master_set_info use after free [44m]
- CVE-2026-93198 | Linux Kernel up to 6.18.51/7.2.5 dm-pcache cache_writeback_fn infinite loop [45m]
- CVE-2026-93199 | Linux Kernel up to 6.18.51/7.2.5 i3c i3c_master_search_i3c_dev_duplicate input validation [45m]
- CVE-2026-93193 | Linux Kernel up to 6.18.51/7.2.5 analogix_dp analogix_dp.c rockchip_dp_drm_encoder_enable denial of service [45m]
- CVE-2026-93192 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 V3D drm/v3d v3d_fence_create active_job/queue_lock use after free [46m]
- CVE-2026-93191 | Linux Kernel up to 7.2.5 Smack ipc/msg.c smack_msg_queue_msgrcv Target improper authorization [46m]
- CVE-2026-93188 | Linux Kernel up to 7.2.5 HID roccat out-of-bounds [46m]
- CVE-2026-93187 | Linux Kernel up to 7.2.5 ipc4-topology ipc4-topology.c input validation [47m]
- CVE-2026-93186 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 CXL Mailbox cxl_mbox_cmd_ctor allocation of resources [47m]
- CVE-2026-93185 | Linux Kernel up to 7.2.5 ASoC rt700_sdw_remove race condition [47m]
- CVE-2026-93184 | Linux Kernel up to 6.12.109/6.18.51/7.2.5 fsl_audmix fsl_audmix_runtime_resume resource consumption [48m]
- CVE-2026-93183 | Linux Kernel up to 7.2.5 lima drivers/gpu/drm/drm_mm.c lima_vm_create allocation of resources [48m]
- CVE-2026-53534 | JabRef up to 6.0-alpha.5 HTTP Server /better-bibtex/cayw CAYWQueryParams.getCommand command os command injection [49m]
- CVE-2026-54634 | Hamlib up to 4.7.1 Send Raw Command tests/rigctl_parse.c rigctl_send_raw/rig_send_raw out-of-bounds write [50m]
- CVE-2026-93181 | Linux Kernel up to 7.2.5 Uncore uncore.c uncore_event_cpu_online race condition [54m]
- CVE-2026-93179 | Linux Kernel up to 7.2.5 Powerplay out-of-bounds [54m]
- CVE-2026-93178 | Linux Kernel up to 7.2.5 powerplay drm/amdgpu/pm/powerplay vddInd/vddcInd memory corruption [55m]
Zero Day Initiative
- ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability [18h]
- ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability [1d]
- ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability [1d]
- ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability [1d]
- ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability [1d]
- ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [1d]
- ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [1d]
- ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability [1d]
- ZDI-26-712: NoMachine nxhtd Server-Side Request Forgery Information Disclosure Vulnerability [1d]
- ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability [1d]
- ZDI-26-710: NoMachine mDNS Heap-based Buffer Overflow Remote Code Execution Vulnerability [1d]
- ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability [1d]