LIVE · cybersecurity feed
Latest
Archive
CVE Tracker
Report
Search
Ransomware
Vulnerability
Breach
Malware
Nation-state
Phishing
Zero-day
AI
Cloud
Live wire
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
OpenAI Announced $1B in Defensive Tools for Water Utilities
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
CVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
CVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Using a VM to Contain an AI Agent
CVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CX
Companies Have Six Months to Prepare for Automated Attacks
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
vendor
Haxx
19 CVEs published in the last four months. Exploited flaws first.
Critical
8
High
11
Medium
0
Exploited (KEV)
0
All recent CVEs
CVE
CVSS
Severity
Product
Summary
Published
CVE-2026-9079
9.8
critical
curl
libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving
65d ago
CVE-2026-8925
9.8
critical
curl
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clear
65d ago
CVE-2026-10536
9.8
critical
curl
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree v
65d ago
CVE-2026-11856
9.8
critical
curl
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and
65d ago
CVE-2026-8927
9.1
critical
curl
When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl
65d ago
CVE-2026-8924
9.1
critical
curl
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public
65d ago
CVE-2026-8926
9.1
critical
curl
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(w
65d ago
CVE-2026-11564
9.1
critical
curl
libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them ma
65d ago
CVE-2026-8286
8.1
high
curl
A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing li
65d ago
CVE-2026-5773
7.5
high
curl
libcurl might in some circumstances reuse the wrong connection for SMB(S) transfers.
115d ago
CVE-2026-6276
7.5
high
curl
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently d
115d ago
CVE-2026-11352
7.5
high
curl
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of servic
65d ago
CVE-2026-11586
7.5
high
curl
By default, curl automatically responds to WebSocket PING frames.
65d ago
CVE-2026-12064
7.5
high
curl
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs
65d ago
CVE-2026-8932
7.5
high
curl
libcurl would reuse a previously created connection even when some mTLS config related option had been changed that
65d ago
CVE-2026-9545
7.5
high
curl
In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second t
65d ago
CVE-2026-9546
7.5
high
curl
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared.
65d ago
CVE-2026-9547
7.4
high
curl
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNC
65d ago
CVE-2026-9080
7.3
high
curl
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vul
65d ago
Filter the full tracker by Haxx →