Search
Search HackerFeeds
Across ransomware, CVEs, defacements, breaches, and countries — last 90 days
Search
Across ransomware, CVEs, defacements, breaches, and countries — last 90 days
32 of 1,407 results
CVE
(10)CVE-2026-103237
MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edi
matched in description · 2026-09-30
CVE-2026-6172
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'caption' parameter of the plugin's bt_bb_image shortcode in all
matched in description · 2026-09-30
CVE-2026-102911
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP too
matched in description · 2026-09-30
CVE-2026-76731
An authentication bypass vulnerability in the captive portal of HPE Networking Instant On could allow an unauthenticated remote attacker to circumvent existing
matched in description · 2026-09-29
CVE-2026-53989
Dockhand before 1.0.36 contains an open redirect vulnerability in the OIDC initiation endpoint that allows unauthenticated remote attackers to redirect authenti
matched in description · 2026-09-29
CVE-2026-102878
mcp-chrome-bridge through 1.0.31 contains an origin validation error in the native-server HTTP API that allows attackers to bypass CORS restrictions. Attackers
matched in description · 2026-09-29
CVE-2026-95317
Incorrect authorization in MediaCapture in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain cross-origin d
matched in description · 2026-09-29
CVE-2026-102710
Attacker model / Preconditions: a loaded `TXM_MODULE_USER_MODE | TXM_MODULE_MEMORY_PROTECTION` module issuing kernel dispatch calls, on a build with `TX_ENABLE_
matched in description · 2026-09-29
CVE-2026-102601
Flysystem is an open source file storage library for PHP. Prior to 3.35.3, the default WhitespacePathNormalizer in src/WhitespacePathNormalizer.php used by File
matched in description · 2026-09-29
CVE-2026-7395
Asset Suite allows unauthenticated users to access HTTPPublishAdapterTestServlet that can be used for configuration file upload, leading to information disclosu
matched in description · 2026-09-29
Ransomware
(10)Breach
(2)Apteki Mareshki
thegentlemen • BG
matched in victim · 2026-09-14