Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-04-20 09:01 Nästa om --:--
11 av 11 källor 10 per källa
Snabbfilter
Toppnyheter Säkerhet
Toppnyhet
SecurityWeek Vulnerabilities

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption. The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on SecurityWeek.

2026-04-18 12:30 1 d
Security feed-översikt Dolj widget
Poster
110
Källor
11
Senast uppdaterad
2026-04-20 09:01
NVD (National Vulnerability Database)10
SecurityWeek Vulnerabilities10
CERT-SE10
CISA KEV-katalog10
Microsoft MSRC10
Cisco PSIRT10
CVE-toppar
CVE-2026-341974
CVE-2024-37212
CVE-2009-02381
CVE-2012-18541
CVE-2017-201871
Senaste CVE
Fel per källa
NVD (National Vulnerability Database)NVD (National Vulnerability Database): 404, message='Not Found', url='https://nvd.nist.gov/feeds/xml/cve/misc/nvd-rss.xml'
Säkerhet 110 artiklar
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-6364 Out of bounds read in Skia

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-6363 Type Confusion in V8

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-6362 Use after free in Codecs

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-6359 Use after free in Video

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.16

Bland veckans läsning i veckobrevet finns råd för ökad säkerhet inom OT, som Nationellt cybersäkerhetscenter (NCSC) nyligen publicerat. Utöver det hittar du information om ett antal sårbarheter och rapporter att läsa.

CERT-SE ikon CERT-SE
1 fler källor
CERT-SE CERT-SE:s veckobrev v.15 2026-04-10 15:30
CERT-SE CERT-SE:s veckobrev v.14 2026-04-02 11:30
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Another DraftKings Hacker Sentenced to Prison

Kamerin Stokes sold stolen credentials through an online marketplace even after pleading guilty to his role in the DraftKings attack. The post Another DraftKings Hacker Sentenced to Prison appeared first on SecurityWeek.

Nyhetsbild
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Cursor AI Vulnerability Exposed Developer Devices

An indirect prompt injection could be chained with a sandbox bypass and Cursor’s remote tunnel feature for shell access to machines. The post Cursor AI Vulnerability Exposed Developer Devices appeared first on...

Nyhetsbild
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-34197 – Apache ActiveMQ

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Cisco PSIRT Cisco Identity Services Engine Remote Code Execution Vulnerabilities 2026-04-15 18:00
Fortinet PSIRT ikon
Fortinet PSIRT
Out-Of-Bounds Write in administrative interface

CVSSv3 Score: 6.7 An out-of-bounds write vulnerability [CWE-787] in FortiWeb CGI daemon may allow a remote privileged attacker to execute arbitrary code or command via crafted HTTP requests. Revised on 2026-04-15...

Nyhetsbild
1 fler källor
Fortinet PSIRT Clear-text credentials retrievable with IP modification for connectors 2026-04-14 09:00
Fortinet PSIRT ikon
Fortinet PSIRT
Heap-based buffer overflow in oftpd daemon

CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted...

Nyhetsbild
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2009-0238 – Microsoft Office

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-32201 – Microsoft SharePoint Server

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. | Åtgärd: Apply mitigations per vendor instructions, follow...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2025-60710 – Microsoft Windows

Microsoft Windows contains a link following vulnerability that allows for privilege escalation | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2023-21529 – Microsoft Exchange Server

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2023-36424 – Microsoft Windows

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation | Åtgärd: Apply mitigations per vendor instructions, follow...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2020-9715 – Adobe Acrobat

Adobe Acrobat contains a use-after-free vulnerability that allows for code execution | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-21643 – Fortinet FortiClient EMS

Fortinet FortiClient EMS contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | Åtgärd: Apply mitigations...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-34621 – Adobe Acrobat and Reader

Adobe Acrobat and Reader contain a prototype pollution vulnerability that allows for arbitrary code execution. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
Palo Alto Networks Advisories CVE-2026-0230 Cortex XDR Agent: Local Administrator can disable the agent on macOS (Severity: MEDIUM) 2026-03-11 17:00
1 fler källor
Palo Alto Networks Advisories PAN-SA-2026-0003 Chromium: Monthly Vulnerability Update (March 2026) (Severity: MEDIUM) 2026-03-11 17:00
CERT-SE ikon
CERT-SE
Kritisk sårbarhet i Fortinet FortiClient EMS

Fortinet har publicerat information om en kritisk sårbarhet i Fortinet FortiClient EMS. [1] Det finns observationer som tyder på att sårbarheten utnyttjas aktivt. Fortinet har publicerat en säkerhetsuppdatering och...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Skadliga versioner av Axios JavaScript-bibliotek

StepSecurity informerar om ett skadligt Axios JavaScript-bibliotek som funnits tillgängligt för nedladdning via NPM. [1] Enligt Socradar rör det sig om uppskattningsvis knappt tre timmar innan det togs bort. Vid...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Kritiska sårbarheter i F5 Networks-produkter

F5 Networks har publicerat en större mängd sårbarhetsuppdateringar gällande produkterna BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, och APM Clients [1]. Uppdateringarna är en åtgärd som svar på ett tidigare...

CERT-SE ikon CERT-SE
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2021-4430

A vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2018-25093

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2017-20187

** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2018-25092

A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2022-3172

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2022-43554

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2022-43555

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2022-44569

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2020-28407

In swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2017-7252

bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)