Logo
  • NEWS
  • NVD
  • EXPLOITS
  • SECURITY
    • NCSC
    • SECURELIST
    • US-CERT
  • ARCHIVE
  • ABOUT
    • Privacy Policy
    • Terms of Use
    • External Links
    • Sitemap

  • CVE-2026-78183 – DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in …

    DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of the string + 1, which …

    23 August 2026
    NVD
  • CVE-2026-78140 – A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function …

    A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file …

    23 August 2026
    NVD
  • CVE-2026-19565 – Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session …

    Apache::AppSamurai::Util versions through 1.01 for Perl generate predictable session authentication keys from the clock and process id in …

    23 August 2026
    NVD
  • CVE-2026-75922 – Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a …

    Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unencoded to the upstream …

    23 August 2026
    NVD
  • CVE-2026-9769 – justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading …

    justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() …

    23 August 2026
    NVD
  • CVE-2026-8630 – justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting ...

    justhtml before 1.12.0 (versions

    23 August 2026
    NVD
  • CVE-2026-8445 – justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant ...

    justhtml versions

    23 August 2026
    NVD
  • CVE-2026-7808 – justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow …

    justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to …

    23 August 2026
    NVD
  • CVE-2026-77088 – justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in …

    justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to …

    23 August 2026
    NVD
  • CVE-2026-74793 – justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default …

    justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in …

    23 August 2026
    NVD
  • CVE-2026-6827 – justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, …

    justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom …

    23 August 2026
    NVD
  • CVE-2026-5751 – justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site …

    justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom …

    23 August 2026
    NVD
{"loadingDistance":1200,"stickyPosts":[],"nextPageLink":"https://itts.at/page/2","queryId":0}

●●●

CookieFree

NVD

  • CVE-2026-0551 – The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object …23 August 2026
  • CVE-2026-16149 – The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all …23 August 2026
  • CVE-2026-78183 – DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in …23 August 2026
  • CVE-2026-78050 – A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the …23 August 2026
  • CVE-2026-18027 – The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels …23 August 2026

EXPLOITS

  • PCMan 2.0.7 – Buffer Overflow18 August 2026
  • flyto-core 2.26.7 – Arbitrary File Write18 August 2026
  • Nodemailer 9.0.0 – File Read/ SSRF18 August 2026
  • NanaZip 6.5 – DoS18 August 2026
  • Linuxfabrik monitoring_plugins_6.0.0 – SSRF18 August 2026

SECURELIST

  • The invisible passenger in your car21 August 2026
  • APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit14 August 2026
  • Armored Likho expands its cyber-espionage toolkit13 August 2026
  • Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver Pha11 August 2026
  • Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selectio11 August 2026


Copyright © 2026 ITTS | Cookie-Free | Privacy Policy | We are not responsible for the content of external sites.