CVE ID :CVE-2026-85082 Published : Sept. 24, 2026, 11:48 p.m. | 19 minutes ago Description :Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely…
CVE-2026-87722 – Regular Expression Denial of Service (ReDoS) in Search Query Predicates and REST Filter Endpoints in Gerrit Code Review
CVE ID :CVE-2026-87722 Published : Sept. 24, 2026, 10:17 p.m. | 1 hour, 50 minutes ago Description :Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and…
CVE-2026-87721 – Denial of Service via Exponential Backtracking in ANTLR Search Query Parser in Gerrit Code Review
CVE ID :CVE-2026-87721 Published : Sept. 24, 2026, 10:17 p.m. | 1 hour, 50 minutes ago Description :Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in…
CVE-2026-95699 – MrSteam iSteamX Improper Isolation or Compartmentalization
CVE ID :CVE-2026-95699 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 49 minutes ago Description :Prior to 9/18/2026, the iSteamX mobile application’s AWS policy could grant authenticated users access to wildcard MQTT…
CVE-2026-81630 – Botslab G980H Dashcams Insufficient Verification of Data Authenticity
CVE ID :CVE-2026-81630 Published : Sept. 24, 2026, 9:18 p.m. | 2 hours, 49 minutes ago Description :The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update…
CVE-2026-97055 – SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret
CVE ID :CVE-2026-97055 Published : Sept. 24, 2026, 1:53 a.m. | 9 minutes ago Description :SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated…
CVE-2026-18467 – Paytium: Mollie payment forms & donations <= 5.0.3 – Unauthenticated Privilege Escalation via 'pt_form_field[pt-user-role]' Parameter
CVE ID :CVE-2026-18467 Published : Sept. 24, 2026, 1:27 a.m. | 34 minutes ago Description :The Paytium: Mollie payment forms & donations plugin for WordPress is vulnerable to Privilege Escalation in all versions…
CVE-2026-82370 – Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service
CVE ID :CVE-2026-82370 Published : Sept. 23, 2026, 11:38 p.m. | 23 minutes ago Description :Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attackers to execute arbitrary administrative…
CVE-2026-70125 – Microsoft Outlook Remote Code Execution Vulnerability
CVE ID :CVE-2026-70125 Published : Sept. 23, 2026, 11:18 p.m. | 44 minutes ago Description :Microsoft Outlook Remote Code Execution Vulnerability Severity: 8.8 | HIGH Visit the link for more details, such as…
CVE-2026-89078 – Double Free in GitLab
CVE ID :CVE-2026-89078 Published : Sept. 23, 2026, 11:05 p.m. | 56 minutes ago Description :GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3,…