freshcrate
Skin:/

freshcrate security

Latest high-impact CVEs, exploited vulnerability links, breach disclosures, and security news for agent operators.

Critical CVEs
0
High CVEs
0
CISA KEV
30
Breaches
20
News
30
Fetched: 5/24/2026, 8:00:31 AM • API: /api/security
Recent high CVEs
No recent CVEs cached yet.
Known exploited vulnerabilities
CVE-2026-9082unknownexploited2026-05-22

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

DrupalCore
CISA due: 2026-05-27Ransomware use: Unknown
CVE-2025-34291unknownexploited2026-05-21

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that pe

LangflowLangflow
CISA due: 2026-06-04Ransomware use: Unknown
CVE-2026-34926unknownexploited2026-05-21

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

Trend MicroApex One
CISA due: 2026-06-04Ransomware use: Unknown
CVE-2008-4250unknownexploited2026-05-20

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

MicrosoftWindows
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2009-1537unknownexploited2026-05-20

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

MicrosoftDirectX
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2009-3459unknownexploited2026-05-20

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.

AdobeAcrobat and Reader
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2010-0249unknownexploited2026-05-20

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

MicrosoftInternet Explorer
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2010-0806unknownexploited2026-05-20

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

MicrosoftInternet Explorer
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2026-41091unknownexploited2026-05-20

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

MicrosoftDefender
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2026-45498unknownexploited2026-05-20

Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

MicrosoftDefender
CISA due: 2026-06-03Ransomware use: Unknown
CVE-2026-42897unknownexploited2026-05-15

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context.

MicrosoftMicrosoft
CISA due: 2026-05-29Ransomware use: Unknown
CVE-2026-20182unknownexploited2026-05-14

Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.

CiscoCatalyst SD-WAN
CISA due: 2026-05-17Ransomware use: Unknown
CVE-2026-42208unknownexploited2026-05-08

BerriAI LiteLLM contains a SQL injection vulnerability that allows an attacker to read data from the proxy's database and potentially modify it, leading to unauthorized access to the proxy and the credentials it manages.

BerriAILiteLLM
CISA due: 2026-05-11Ransomware use: Unknown
CVE-2026-6973unknownexploited2026-05-07

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution.

IvantiEndpoint Manager Mobile (EPMM)
CISA due: 2026-05-10Ransomware use: Unknown
CVE-2026-0300unknownexploited2026-05-06

Palo Alto Networks PAN-OS contains an out-of-bounds write vulnerability in the User-ID Authentication Portal (aka Captive Portal) service that can allow an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets.

Palo Alto NetworksPAN-OS
CISA due: 2026-05-09Ransomware use: Unknown
CVE-2026-31431unknownexploited2026-05-01

Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation.

LinuxKernel
CISA due: 2026-05-15Ransomware use: Unknown
CVE-2026-41940unknownexploited2026-04-30

WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

WebProscPanel & WHM and WP2 (WordPress Squared)
CISA due: 2026-05-03Ransomware use: Known
CVE-2024-1708unknownexploited2026-04-28

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

ConnectWiseScreenConnect
CISA due: 2026-05-12Ransomware use: Known
CVE-2026-32202unknownexploited2026-04-28

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network.

MicrosoftWindows
CISA due: 2026-05-12Ransomware use: Unknown
CVE-2025-29635unknownexploited2026-04-24

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

D-LinkDIR-823X
CISA due: 2026-05-08Ransomware use: Unknown
CVE-2024-7399unknownexploited2026-04-24

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

SamsungMagicINFO 9 Server
CISA due: 2026-05-08Ransomware use: Unknown
CVE-2024-57728unknownexploited2026-04-24

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

SimpleHelp SimpleHelp
CISA due: 2026-05-08Ransomware use: Known
CVE-2024-57726unknownexploited2026-04-24

SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.

SimpleHelp SimpleHelp
CISA due: 2026-05-08Ransomware use: Known
CVE-2026-39987unknownexploited2026-04-23

Marimo contains an pre-authorization remote code execution vulnerability, allowing an unauthenticated attacked to shell access and execute arbitrary system commands.

MarimoMarimo
CISA due: 2026-05-07Ransomware use: Unknown
CVE-2026-33825unknownexploited2026-04-22

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.

MicrosoftDefender
CISA due: 2026-05-06Ransomware use: Unknown
CVE-2026-20122unknownexploited2026-04-20

Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.

CiscoCatalyst SD-WAN Manger
CISA due: 2026-04-23Ransomware use: Unknown
CVE-2026-20133unknownexploited2026-04-20

Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.

CiscoCatalyst SD-WAN Manager
CISA due: 2026-04-23Ransomware use: Unknown
CVE-2025-2749unknownexploited2026-04-20

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

KenticoKentico Xperience
CISA due: 2026-05-04Ransomware use: Unknown
CVE-2023-27351unknownexploited2026-04-20

PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.

PaperCutNG/MF
CISA due: 2026-05-04Ransomware use: Known
CVE-2025-48700unknownexploited2026-04-20

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information.

SynacorZimbra Collaboration Suite (ZCS)
CISA due: 2026-04-23Ransomware use: Unknown
Latest breach disclosures
7-Elevenverified2026-05-24
185K accounts7-eleven.com
Dates of birthEmail addressesNamesPhone numbersPhysical addresses
Dragonica Lunarisverified2026-05-21
126K accountsplaydragonica.eu
Dates of birthEmail addressesNamesPasswordsSpoken languagesUsernames
Windows93 / Myspace93verified2026-05-21
46K accountswindows93.net
Email addressesIP addressesPasswordsUsernames
CTTverified2026-05-19
468K accountsctt.pt
Email addressesNamesPhone numbers
Addiverified2026-05-18
34.5M accountsaddi.com
Age groupsCredit scoresDevice informationEmail addressesGovernment issued IDsIncome levelsIP addressesLatitude and longitude pairs
Abrigoverified2026-05-14
711K accountsabrigo.com
Email addressesEmployersJob titlesNamesPhone numbersPhysical addresses
Canada Lifeverified2026-05-13
238K accountscanadalife.com
Email addressesJob titlesNamesPhone numbersPhysical addressesSalutationsSupport tickets
Cushman & Wakefieldverified2026-05-12
310K accountscushmanwakefield.com
Email addressesJob titlesNamesPhone numbersPhysical addressesSalutations
Zaraverified2026-05-08
197K accountszara.com
Email addressesGeographic locationsPurchasesSupport tickets
Woflowverified2026-05-07
448K accountswoflow.com
Email addressesNamesPhone numbersPhysical addresses
LegionProxyverified2026-05-06
10K accountslegionproxy.io
Email addressesNamesPasswordsPurchases
Vimeoverified2026-05-05
119K accountsvimeo.com
Email addressesNames
Reborn Gamingverified2026-05-04
126 accountsreborngaming.net
Email addressesIP addresses
Marcus & Millichapverified2026-05-03
1.8M accountsmarcusmillichap.com
Email addressesEmployersJob titlesNamesPhone numbersPhysical addresses
ZenBusinessverified2026-05-02
5.1M accountszenbusiness.com
Email addressesNamesPhone numbers
Amanverified2026-05-01
216K accountsaman.com
Dates of birthEmail addressesGendersLanguage preferencesNamesNationalitiesPhone numbersPhysical addresses
Pitney Bowesverified2026-04-27
8.2M accountspitneybowes.com
Email addressesJob titlesNamesPhone numbersPhysical addresses
ADTverified2026-04-27
5.5M accountsadt.com
Dates of birthEmail addressesNamesPartial government issued IDsPhone numbersPhysical addresses
Udemyverified2026-04-26
1.4M accountsudemy.com
Email addressesEmployersJob titlesNamesPayment methodsPhone numbersPhysical addresses
Carnivalverified2026-04-24
7.5M accountscarnivalcorp.com
Dates of birthEmail addressesGendersGeographic locationsLoyalty program detailsNamesSalutations
Security news

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]

2026-05-23

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attack

2026-05-23

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in ques

2026-05-23

Fraud losses don't stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into risk and customer impact. [...]

2026-05-22
Sources