Logo
  • NEWS
  • NVD
  • EXPLOITS
  • SECURITY
    • NCSC
    • SECURELIST
    • US-CERT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

  • CVE-2026-64651 – The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed …

    The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay …

    20 July 2026
    NVD
  • CVE-2026-64650 – The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, …

    The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. …

    20 July 2026
    NVD
  • CVE-2026-58624 – Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java …

    Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side …

    20 July 2026
    NVD
  • CVE-2026-56624 – Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a …

    Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side …

    20 July 2026
    NVD
  • CVE-2026-56623 – Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a …

    Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side …

    20 July 2026
    NVD
  • CVE-2026-56452 – Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java …

    Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side …

    20 July 2026
    NVD
  • CVE-2026-55219 – Paymenter is a free and open-source webshop solution for management of hosting services. …

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment …

    20 July 2026
    NVD
  • CVE-2026-53596 – FreeScout is a free help desk and shared inbox built with PHP’s Laravel framework. Prior …

    FreeScout is a free help desk and shared inbox built with PHP’s Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk …

    20 July 2026
    NVD
  • CVE-2026-53595 – FreeScout is a free help desk and shared inbox built with PHP’s Laravel framework. Prior …

    FreeScout is a free help desk and shared inbox built with PHP’s Laravel framework. Prior to version 1.8.224, the public endpoint `POST …

    20 July 2026
    NVD
  • CVE-2026-53594 – FreeScout is a free help desk and shared inbox built with PHP’s Laravel framework. …

    FreeScout is a free help desk and shared inbox built with PHP’s Laravel framework. FreeScout’s `Manage -> Logs -> App Logs` feature uses …

    20 July 2026
    NVD
  • CVE-2026-47198 – Paymenter is a free and open-source webshop solution for management of hosting services. …

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component …

    20 July 2026
    NVD
  • CVE-2026-47130 – NextCRM is open-source customer relationship management (CRM) software. Versions prior to …

    NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization …

    20 July 2026
    NVD
{"loadingDistance":1200,"stickyPosts":[],"nextPageLink":"https://itts.at/page/2","queryId":0}

●●●

CookieFree

NVD

  • CVE-2026-44359 – Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, …20 July 2026
  • CVE-2026-64651 – The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed …20 July 2026
  • CVE-2026-45138 – CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version …20 July 2026
  • CVE-2026-42566 – Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a …20 July 2026
  • CVE-2026-10081 – The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or …20 July 2026

EXPLOITS

  • Krayin CRM v2.2.x – Authenticated Remote Code Execution8 July 2026
  • Langflow 1.9.0 – RCE8 July 2026
  • Atarim WordPress Plugin 4.2.2 – Sensitive Information Exposure8 July 2026
  • Joomla Page Builder CK 3.5.10 – Arbitrary File Upload8 July 2026
  • MCPJam Inspector – Remote Code Execution7 July 2026

SECURELIST

  • HelloNet campaign — new malicious modules launched through the ViPNet update system16 July 2026
  • GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration16 July 2026
  • OkoBot: new sophisticated malware framework targets cryptocurrency users15 July 2026
  • Threat landscape for industrial automation systems. Q1 20267 July 2026
  • When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft we6 July 2026


Copyright © 2026 ITTS | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.