Security Intelligence
Feed

Real-time CVE tracking, exploit analysis, and vulnerability intelligence curated for security professionals.

339 New today
65,684 Total advisories
Live Monitoring

Daily Security Trends (Last 14 Days)

60
Jun 13
68
Jun 14
443
Jun 15
630
Jun 16
464
Jun 17
3
Jun 18
352
Jun 19
56
Jun 20
104
Jun 21
317
Jun 22
294
Jun 23
355
Jun 24
376
Jun 25
21
Jun 26
Critical
High
Medium
Low

Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-48933

CVE-2026-48933_CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability af...

nodejs node 22.22.3 CVE
MEDIUM 5.6 CVE-2026-48930

CVE-2026-48930_CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resol...

nodejs node 22.22.3 CVE
MEDIUM 4.2 CVE-2026-48928

CVE-2026-48928_CVE-2026-48928

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all suppor...

nodejs node 22.22.3 CVE
MEDIUM 5.3 CVE-2026-48619

CVE-2026-48619_CVE-2026-48619

A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the cli...

nodejs node 22.22.3 CVE
HIGH 7.7 CVE-2026-48618

CVE-2026-48618_CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due t...

nodejs node 22.22.3 CVE
MEDIUM 5.9 CVE-2026-48615

CVE-2026-48615_CVE-2026-48615

A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are em...

nodejs node 22.22.3 CVE
MEDIUM 4.8 CVE-2026-8661

Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown to PDF Plugin_CVE-2026-8661

Server-Side Cross-Site Scripting and Server-Side Request Forgery vulnerability in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plug...

Rapid7 InsightConnect Markdown Plugin CVE
MEDIUM 6.5 CVE-2026-13226

Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter_CVE-2026-13226

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter i...

trainingbusinesspros Groundhogg — CRM, Newsletters, and Marketing Automation CVE
HIGH 8.8 921E88F8-3925-

Exploit for CVE-2026-43503_921E88F8-3925-519D-9067-4928D48E9B4D

CVE-2026-43503 — DirtyClone Linux local privilege escalation. A cloned skbuff loses the SKBFLSHAREDFRAG flag, so ESP in-place decryption writes int...

N/A N/A GITHUBEXPLOIT