Skip to main content

Threats Tagged 'cve'

View all threats tagged with 'cve'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve

Threats Tagged 'cve'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-18179 is a medium severity vulnerability in IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10.0. It involves missing authorization controls that could allow a remote attacker to clear active chat sessions without proper permissions.

Join the discussion

CVE-2026-59167 is a critical stored cross-site scripting (XSS) vulnerability in JiHong88 suneditor, a lightweight JavaScript WYSIWYG editor. Versions prior to 2.47.11 have a sanitizer flaw in src/lib/core.js that fails to consistently reject namespaced or custom HTML elements, allowing event-handler attributes to persist on crafted elements. This enables attackers to execute arbitrary scripts in the browser context when users interact with malicious editor content. The issue is resolved in version 2.47.11.

Join the discussion

IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains a missing authorization vulnerability that could allow a remote attacker to perform unauthorized payment actions. This flaw affects versions from 4.0.6.0 through 4.0.10.0. The vulnerability has a high severity rating with a CVSS score of 7.1. No known exploits are reported in the wild, and no patch information is currently provided.

Join the discussion

CVE-2026-86678 is a high-severity authorization bypass vulnerability in ZohoCorp ManageEngine Applications Manager. Versions 182000 and below allow a low-privileged user to obtain an administrator's API key and perform administrator-level actions. This flaw is categorized under CWE-639, indicating improper authorization. The vulnerability has a CVSS 3.1 score of 8.8, reflecting high impact on confidentiality, integrity, and availability.

Join the discussion

CVE-2026-86677 is a high-severity SQL injection vulnerability in ZohoCorp ManageEngine Applications Manager versions prior to 182100. It allows a low-privileged user to execute unauthorized SQL commands, potentially leading to administrator access and remote code execution.

Join the discussion

ZohoCorp ManageEngine Applications Manager versions prior to 182300 contain a permissions validation vulnerability that allows low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. This issue is due to missing authentication for a critical function, classified as CWE-306. The vulnerability has a CVSS 3.1 score of 7.6, indicating high severity with low attack complexity and no user interaction required.

Join the discussion

ZohoCorp ManageEngine Applications Manager versions 182200 and below contain a hard-coded Google Cloud service-account private key in the installer. This vulnerability allows unauthenticated attackers to impersonate the service account and access or modify associated cloud resources. The issue is tracked as CVE-2026-86708 and has a critical severity with a CVSS score of 10. A patch is available to remediate this vulnerability.

Join the discussion

CVE-2026-95676 is a high-severity vulnerability in WatchGuard AuthPoint Authentication Gateway versions 4.2.2 up to but not including 7.5.1. It involves a missing or improper authentication check in the LDAP Sync first-factor authentication process, allowing a remote attacker to bypass single-factor password verification under non-default operating conditions. Multi-factor authentication remains effective, so additional factors still protect the system.

Join the discussion

ManageEngine OpManager MSP versions 12.8.709 and earlier contain a critical remote code execution vulnerability in the Notification Profile module. This vulnerability is due to improper neutralization of special elements used in OS commands (CWE-78), allowing an attacker with limited privileges to execute arbitrary commands remotely. The vulnerability has a high CVSS score of 9.9, indicating severe impact on confidentiality, integrity, and availability.

Join the discussion

ManageEngine OpManager versions 12.8.710 and earlier with the Application Manager Plugin enabled are affected by an authentication bypass vulnerability. This flaw allows unauthorized users with limited privileges to access critical functions without proper authentication. The vulnerability is identified as CWE-306 (Missing Authentication for Critical Function).

Join the discussion

Showing 1 to 10 of 98327 results

Filters:Tag: cve
Page 1 of 9833
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses