Skip to main content

Medium Severity Threats

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Severity: Medium

Filtered Threats

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-108124 is an SQL injection vulnerability in the wp-post-author plugin affecting versions before 4.1.0. It involves improper neutralization of special elements in SQL commands, allowing an attacker with high privileges to potentially cause a high impact on confidentiality without affecting integrity or availability.

Join the discussion

CVE-2026-107804 is an origin validation error in 0xJacky's nginx-ui web interface affecting versions from 2.2.0 up to but not including 2.6.0. The bundled reverse proxy does not preserve the external client identity due to lack of trusted proxy configuration, causing management requests to be attributed to the loopback address. This allows valid credentials to bypass IP allowlist restrictions and lets unauthenticated attackers trigger shared temporary login bans without invalidating existing sessions. The issue is fixed in version 2.6.0.

Join the discussion
0

CVE-2026-33272 affects Red Lion Controls 700 Series switches. A malicious user with physical access can boot the device from factory settings without authentication, use default administrative credentials to gain administrative access, and save persistent configuration changes. This vulnerability allows unauthorized configuration changes but does not impact availability.

Join the discussion
0

A double free vulnerability exists in xerial snappy-java versions from 1.1.7.4 up to but not including 1.1.10.10. The flaw occurs in SnappyFramedInputStream when replacement allocation fails, causing pooled buffers to be released twice. This can lead to OutOfMemoryError and potentially expose or overwrite decompressed data from other streams.

Join the discussion

CVE-2026-104115 is a medium-severity stack-based buffer overflow vulnerability in the illumos reparse point daemon (reparsed). It allows a local unprivileged user to crash the daemon by sending an nfs-basic request with an overlong host or path component. The vulnerability arises because the daemon copies these components into a fixed 1024-byte stack buffer without length checks. The affected service is disabled by default and the flaw has existed since 2009. Systems built with stack protection will abort the daemon on exploitation, causing the filesystem reparse service to enter maintenance mode.

Join the discussion
0

Default factory credentials with administrative access are enabled and persist even after configuring other administrator accounts.

Join the discussion

CVE-2026-104114 is a medium severity vulnerability in the illumos Network Auto-Magic daemon (nwamd) caused by a NULL pointer dereference. A local unprivileged user can crash the nwamd daemon by invoking a door_call() with no argument data, leading to the network service entering maintenance mode and stopping automatic network configuration. This issue affects illumos distributions with the nwamd service enabled, which is not the default. The flaw has existed since 2010 and is fixed in illumos-gate commit 0f1064d9.

Join the discussion

CVE-2026-104112 is a resource management vulnerability in the illumos name service cache daemon (nscd). A local user can cause nscd to exhaust kernel memory by repeatedly passing file descriptors that are not properly closed. This leads to a denial of service affecting nscd and potentially rendering processes in all zones on the host unresponsive. The flaw has existed since 2006 and affects illumos distributions prior to a specific commit fix. The vulnerability requires local access and does not involve user interaction.

Join the discussion

CVE-2026-102916 is a reachable assertion vulnerability in the illumos bhyve instruction emulator that allows a guest VM to cause a host panic. The issue arises when emulating REP-prefixed MOVS or STOS instructions accessing guest MMIO, where a status flag is not cleared properly, leading to a VERIFY assertion failure and host denial of service. This flaw affects illumos distributions prior to a specific commit from 2020 and requires a privileged user within the guest VM to exploit.

Join the discussion

This report discusses the security risks posed by AI agents using valid credentials to perform actions beyond their assigned permissions, particularly in corporate environments. It highlights how traditional access controls may fail to prevent agents from escalating privileges by switching to more powerful credentials available on the same system. The article outlines various enforcement points and mitigation strategies to limit agent actions without sacrificing autonomy, including managed agent settings, runtime hooks, gateways, sandboxes, endpoint enforcement, and credential authorization. It emphasizes the importance of scoping agent permissions tightly and enforcing controls at the tool call level to prevent unauthorized actions. The report does not describe a specific vulnerability or exploit but rather addresses a broader security challenge in managing AI agent permissions.

MediumNews
Join the discussion

Showing 1 to 10 of 69737 results

Filters:Severity: Medium
Page 1 of 6974
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses