##
Updated at UTC 2026-07-29T18:04:35.170333
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-20316 | 5.3 | 0.00% | 2 | 0 | 2026-07-29T17:16:51.840000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-20079 | 10.0 | 38.70% | 2 | 1 | template | 2026-07-29T17:16:51.683000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center |
| CVE-2026-67215 | 7.5 | 0.00% | 2 | 0 | 2026-07-29T16:17:57.997000 | cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack ex | |
| CVE-2026-43698 | 7.8 | 0.15% | 1 | 0 | 2026-07-29T15:46:07.463000 | An injection issue was addressed with improved validation. This issue is fixed i | |
| CVE-2026-65884 | None | 0.00% | 1 | 0 | 2026-07-29T15:31:18 | Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The | |
| CVE-2026-0667 | None | 0.00% | 2 | 0 | 2026-07-29T15:31:11 | CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that | |
| CVE-2026-59932 | 7.5 | 0.69% | 1 | 0 | 2026-07-29T15:16:26.967000 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. | |
| CVE-2026-55390 | 7.5 | 0.36% | 3 | 0 | 2026-07-29T15:16:26.230000 | datamodel-code-generator generates Python data models from schema definitions. F | |
| CVE-2026-14996 | 8.2 | 0.22% | 1 | 0 | 2026-07-29T15:16:20.930000 | IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related | |
| CVE-2026-50517 | 9.9 | 1.25% | 1 | 0 | 2026-07-29T14:19:20.030000 | Deserialization of untrusted data in M365 Copilot allows an authorized attacker | |
| CVE-2026-66748 | 8.8 | 0.74% | 1 | 1 | 2026-07-29T14:16:34.610000 | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code | |
| CVE-2026-62325 | 9.1 | 0.34% | 1 | 0 | 2026-07-29T14:16:33.530000 | goshs is a feature-rich single-binary file server for red teamers and developers | |
| CVE-2026-45293 | 8.6 | 0.18% | 1 | 0 | 2026-07-29T14:16:30.737000 | WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enfor | |
| CVE-2026-14973 | 9.3 | 0.45% | 1 | 0 | 2026-07-29T14:16:28.453000 | IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow fil | |
| CVE-2026-64863 | 9.1 | 0.34% | 1 | 0 | 2026-07-29T13:19:09.987000 | goshs is a feature-rich single-binary file server for red teamers and developers | |
| CVE-2026-55389 | 7.5 | 0.36% | 1 | 0 | 2026-07-29T13:19:01.067000 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, a | |
| CVE-2026-18220 | 7.8 | 0.00% | 2 | 1 | 2026-07-29T13:17:54.203000 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF back | |
| CVE-2026-16192 | 7.1 | 0.27% | 1 | 0 | 2026-07-29T13:17:48.460000 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected | |
| CVE-2026-15325 | 8.7 | 0.21% | 1 | 0 | 2026-07-29T13:17:46.973000 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-14270 | 8.8 | 0.00% | 2 | 0 | 2026-07-29T12:31:30 | The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCom | |
| CVE-2026-65883 | None | 0.00% | 2 | 0 | 2026-07-29T12:31:30 | Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Ca | |
| CVE-2026-35226 | 6.5 | 0.17% | 1 | 0 | 2026-07-29T09:31:37 | An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows a | |
| CVE-2026-18072 | 9.8 | 0.59% | 2 | 0 | 2026-07-29T06:32:11 | The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick | |
| CVE-2026-42533 | 8.1 | 3.60% | 2 | 9 | 2026-07-29T05:16:44.720000 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-12144 | 8.8 | 0.37% | 1 | 0 | 2026-07-29T03:30:21 | The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Es | |
| CVE-2026-54650 | 8.6 | 0.36% | 1 | 0 | 2026-07-28T22:20:54 | ## Summary openhole-server forwarded the URL-decoded request path (`r.URL.Path` | |
| CVE-2026-54658 | 9.8 | 0.40% | 1 | 0 | 2026-07-28T22:19:24 | ### Impact A SQL injection vulnerability exists in the `escapeValue()` function | |
| CVE-2026-54638 | 7.5 | 0.35% | 1 | 0 | 2026-07-28T22:15:29 | ### Impact A remote, unauthenticated attacker can cause excessive memory alloca | |
| CVE-2026-54719 | 7.5 | 0.28% | 1 | 0 | 2026-07-28T21:59:49 | GHSA-wvhv-qcqf-f3cx fixed the per-folder .goshs ACL bypass on the state-changing | |
| CVE-2026-55391 | 7.5 | 0.19% | 1 | 0 | 2026-07-28T21:45:50 | ### Summary `datamodel-code-generator`'s anti-SSRF guard validates the resolved | |
| CVE-2026-14893 | 7.3 | 0.33% | 1 | 0 | 2026-07-28T21:31:45 | IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana | |
| CVE-2026-15057 | 7.5 | 0.26% | 1 | 0 | 2026-07-28T21:31:45 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerab | |
| CVE-2026-14981 | 7.5 | 0.26% | 1 | 0 | 2026-07-28T21:31:45 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Serv | |
| CVE-2026-48395 | 8.6 | 0.17% | 1 | 0 | 2026-07-28T21:31:39 | Bridge is affected by an Untrusted Search Path vulnerability that could result i | |
| CVE-2026-7769 | 8.1 | 0.27% | 1 | 0 | 2026-07-28T21:31:39 | IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2 | |
| CVE-2026-66745 | 7.5 | 0.32% | 1 | 0 | 2026-07-28T21:31:39 | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) con | |
| CVE-2026-43776 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T19:44:17.417000 | A buffer overflow was addressed with improved bounds checking. This issue is fix | |
| CVE-2026-59931 | 7.7 | 0.53% | 1 | 0 | 2026-07-28T19:17:39.457000 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. | |
| CVE-2026-66754 | 5.9 | 0.40% | 1 | 1 | 2026-07-28T18:33:11 | Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the | |
| CVE-2026-54635 | 7.5 | 0.42% | 1 | 0 | 2026-07-28T18:17:22.427000 | pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webho | |
| CVE-2026-59878 | 7.5 | 0.55% | 1 | 0 | 2026-07-28T16:20:53.010000 | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ | |
| CVE-2026-63727 | 8.8 | 0.26% | 1 | 0 | 2026-07-28T16:19:43.127000 | Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper | |
| CVE-2026-66473 | 7.5 | 0.20% | 1 | 0 | 2026-07-28T16:19:12.780000 | Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions. | |
| CVE-2026-63077 | 9.8 | 0.65% | 5 | 0 | 2026-07-28T16:17:58.820000 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code exe | |
| CVE-2026-63720 | 7.5 | 0.42% | 2 | 0 | 2026-07-28T16:07:15.840000 | datamodel-code-generator prior to version 0.70.0 contains a code injection vulne | |
| CVE-2026-7187 | 8.8 | 0.21% | 1 | 0 | 2026-07-28T15:32:18 | Missing authentication for critical function vulnerability in Universal Software | |
| CVE-2026-61609 | 7.5 | 0.39% | 1 | 0 | 2026-07-28T14:58:00 | ### Summary The `authentication` rate limiter used for the login and two-factor | |
| CVE-2026-16812 | 10.0 | 0.88% | 5 | 0 | 2026-07-28T14:50:33.960000 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a | |
| CVE-2026-16462 | 9.8 | 0.42% | 1 | 0 | 2026-07-28T12:31:27 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a | |
| CVE-2026-64531 | 0 | 0.16% | 1 | 0 | 2026-07-28T12:16:36.880000 | In the Linux kernel, the following vulnerability has been resolved: net: openvs | |
| CVE-2026-14168 | 8.8 | 0.28% | 2 | 0 | 2026-07-28T09:31:36 | A low privileged remote attacker can gain administrator privileges due to missin | |
| CVE-2026-14167 | 8.8 | 0.28% | 2 | 0 | 2026-07-28T09:31:36 | A low privileged remote attacker can perform privileged configuration changes re | |
| CVE-2026-14169 | 8.1 | 0.29% | 2 | 0 | 2026-07-28T09:31:36 | Due to incorrect behavior order a low privileged remote attacker could trigger a | |
| CVE-2026-14171 | 6.1 | 0.18% | 2 | 0 | 2026-07-28T09:31:35 | An unauthenticated remote attacker can abuse the improper validation of the post | |
| CVE-2026-61511 | 9.8 | 1.27% | 10 | 5 | 2026-07-28T05:17:17.133000 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vul | |
| CVE-2026-43723 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T00:32:06 | A path handling issue was addressed with improved validation. This issue is fixe | |
| CVE-2026-43749 | 7.8 | 0.15% | 1 | 0 | 2026-07-28T00:32:05 | A parsing issue in the handling of directory paths was addressed with improved p | |
| CVE-2026-39874 | 7.8 | 0.10% | 1 | 0 | 2026-07-28T00:32:04 | A permissions issue was addressed with additional restrictions. This issue is fi | |
| CVE-2026-66018 | 6.5 | 0.23% | 1 | 0 | 2026-07-27T21:31:32 | Build readers can access another repository's environment properties. A caller w | |
| CVE-2026-65923 | 6.8 | 0.19% | 1 | 0 | 2026-07-27T21:31:28 | A URL validation weakness in JFrog Artifactory Ansible repository handling could | |
| CVE-2026-65617 | 8.8 | 0.30% | 1 | 0 | 2026-07-27T21:31:24 | A deserialization weakness in JFrog Artifactory package handling could allow a l | |
| CVE-2026-17497 | 8.3 | 0.46% | 1 | 0 | 2026-07-27T20:37:16.927000 | NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capabili | |
| CVE-2026-17457 | 4.3 | 0.32% | 1 | 0 | 2026-07-27T20:25:13.817000 | A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by t | |
| CVE-2026-17458 | 6.3 | 0.23% | 1 | 0 | 2026-07-27T20:25:13.817000 | A vulnerability was found in mf-yang openclaw-cn up to 0.2.1. This affects the f | |
| CVE-2025-68686 | 5.9 | 1.26% | 6 | 0 | 2026-07-27T18:31:25 | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE | |
| CVE-2026-16805 | 8.8 | 0.31% | 1 | 0 | 2026-07-27T12:45:44.210000 | Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remot | |
| CVE-2026-16806 | 8.8 | 0.40% | 1 | 0 | 2026-07-27T12:45:30.967000 | Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remo | |
| CVE-2026-16807 | 8.8 | 0.26% | 1 | 0 | 2026-07-27T12:45:14.207000 | Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a | |
| CVE-2026-14837 | 7.8 | 0.08% | 1 | 0 | 2026-07-27T09:31:26 | Multiple Lenze products are affected by an improper signature verification vulne | |
| CVE-2026-64600 | 7.8 | 0.49% | 6 | 6 | 2026-07-27T05:16:56.870000 | In the Linux kernel, the following vulnerability has been resolved: xfs: resamp | |
| CVE-2026-17496 | 8.1 | 0.30% | 1 | 0 | 2026-07-26T15:30:33 | NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with | |
| CVE-2026-17459 | 4.3 | 0.32% | 1 | 0 | 2026-07-26T12:30:21 | A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerabilit | |
| CVE-2026-15962 | 8.8 | 0.38% | 1 | 0 | 2026-07-26T03:30:31 | The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Objec | |
| CVE-2026-66012 | 10.0 | 0.44% | 2 | 1 | 2026-07-25T12:31:47 | SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST | |
| CVE-2026-25243 | 8.8 | 3.30% | 1 | 3 | 2026-07-25T11:10:00.100000 | Redis is an in-memory data structure store. In versions of redis-server up to 8. | |
| CVE-2026-10818 | 8.1 | 0.42% | 1 | 1 | 2026-07-25T09:30:31 | The WPForms Pro plugin for WordPress is vulnerable to Arbitrary File Upload in a | |
| CVE-2026-35425 | 8.0 | 0.48% | 1 | 0 | 2026-07-25T05:16:34.867000 | Improper access control in Azure API Management (APIM) allows an authorized atta | |
| CVE-2026-65711 | 7.2 | 2.41% | 1 | 0 | 2026-07-24T18:31:41 | sysPass through version 3.2.11 contains an OS command injection vulnerability th | |
| CVE-2026-16804 | 8.3 | 0.25% | 1 | 0 | 2026-07-24T15:34:00 | Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remot | |
| CVE-2026-62145 | 7.5 | 7.54% | 1 | 1 | 2026-07-24T05:16:45.940000 | A vulnerability in Check Point Gaia Portal allows an authenticated attacker with | |
| CVE-2026-62144 | 9.1 | 20.62% | 1 | 1 | 2026-07-24T05:16:45.793000 | An authentication bypass vulnerability in Check Point Security Management and Mu | |
| CVE-2026-54120 | 9.9 | 0.71% | 1 | 0 | 2026-07-24T03:31:56 | Improper input validation in Microsoft Surface allows an authorized attacker to | |
| CVE-2026-42933 | 10.0 | 0.29% | 1 | 0 | 2026-07-24T00:32:40 | Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or inter | |
| CVE-2026-21655 | None | 0.17% | 2 | 0 | 2026-07-23T21:31:03 | Deserialization of untrusted data vulnerability in Johnson Control victor on Win | |
| CVE-2026-6516 | 10.0 | 4.73% | 1 | 0 | 2026-07-23T18:31:54 | Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthen | |
| CVE-2026-63108 | 8.8 | 1.92% | 1 | 0 | 2026-07-23T15:24:59.880000 | Roo Code through 3.54.0 contains a command injection vulnerability in the auto-a | |
| CVE-2026-63766 | 9.8 | 1.75% | 1 | 1 | 2026-07-23T15:24:59.880000 | GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability | |
| CVE-2026-59933 | 7.5 | 0.69% | 1 | 0 | 2026-07-23T15:01:52 | ## Summary PhpSpreadsheet's OLE reader follows sector chains from attacker-cont | |
| CVE-2026-16723 | 9.0 | 0.41% | 8 | 3 | 2026-07-23T15:01:24.377000 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1. | |
| CVE-2026-46331 | 7.8 | 0.53% | 1 | 13 | 2026-07-23T12:18:18.287000 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-15342 | 6.5 | 0.22% | 1 | 0 | 2026-07-22T21:33:00 | Plane contains a multi‑tenant authorization flaw in its asset‑management API tha | |
| CVE-2026-13072 | 8.1 | 0.32% | 1 | 0 | 2026-07-22T21:32:15 | When compute mode is enabled on a standalone mongod instance, insufficient valid | |
| CVE-2026-16232 | 9.1 | 69.97% | 8 | 2 | template | 2026-07-22T21:32:05 | An authentication bypass vulnerability in the Check Point SmartConsole login pro |
| CVE-2026-50522 | 9.8 | 57.10% | 2 | 5 | 2026-07-22T21:31:51 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-53359 | 8.8 | 0.91% | 1 | 6 | 2026-07-22T21:31:50 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: F | |
| CVE-2026-10702 | 4.3 | 0.55% | 1 | 0 | 2026-07-22T19:10:00.120000 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-49176 | 7.8 | 0.40% | 2 | 2 | 2026-07-22T16:17:28.753000 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-60137 | 5.9 | 77.97% | 1 | 45 | 2026-07-22T05:17:11.750000 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no | |
| CVE-2026-8985 | None | 4.19% | 1 | 0 | 2026-07-22T00:32:44 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command | |
| CVE-2026-64606 | 9.8 | 0.63% | 1 | 0 | 2026-07-21T21:33:35 | Deserialization of untrusted data vulnerability that may allow class-registratio | |
| CVE-2026-64879 | 9.9 | 2.59% | 1 | 0 | 2026-07-21T21:32:47 | A filename supplied during file upload is not properly sanitized before being us | |
| CVE-2026-40510 | 3.8 | 0.22% | 2 | 0 | 2026-07-21T12:10:00.090000 | OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overf | |
| CVE-2026-2291 | 7.3 | 0.92% | 2 | 1 | 2026-07-20T21:31:40 | dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, | |
| CVE-2026-53362 | 7.8 | 0.27% | 1 | 0 | 2026-07-18T09:32:17 | In the Linux kernel, the following vulnerability has been resolved: ipv6: accou | |
| CVE-2026-42530 | 8.1 | 3.68% | 1 | 3 | 2026-07-16T12:33:31 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGI | |
| CVE-2026-15410 | 7.2 | 76.35% | 1 | 3 | 2026-07-16T05:16:18.470000 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2023-4346 | 7.5 | 0.91% | 1 | 0 | 2026-07-16T05:16:16.603000 | KNX devices that use KNX Connection Authorization and support Option 1 are, dep | |
| CVE-2026-46817 | 9.8 | 13.31% | 1 | 2 | 2026-07-15T18:32:50 | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (compone | |
| CVE-2026-56155 | 7.8 | 2.33% | 1 | 0 | 2026-07-14T21:32:52 | Insufficient granularity of access control in Active Directory Federation Servic | |
| CVE-2026-54121 | 8.8 | 1.05% | 6 | 8 | 2026-07-14T18:32:37 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-50502 | 8.0 | 0.60% | 3 | 0 | 2026-07-14T18:32:33 | Insufficient granularity of access control in Windows Event Logging Service allo | |
| CVE-2026-50469 | 7.8 | 0.27% | 2 | 0 | 2026-07-14T18:32:32 | Improper link resolution before file access ('link following') in Windows Projec | |
| CVE-2025-15467 | 9.8 | 47.62% | 2 | 6 | 2026-07-14T15:32:45 | Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AE | |
| CVE-2026-55255 | 8.4 | 29.05% | 1 | 1 | 2026-07-07T22:14:37 | ## Summary Insecure Direct Object Reference (IDOR) vulnerability in `/api/v1/re | |
| CVE-2026-12569 | 9.8 | 2.26% | 3 | 1 | 2026-06-30T18:16:43.113000 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-5172 | 7.3 | 2.68% | 2 | 2 | 2026-06-30T03:37:45 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker t | |
| CVE-2026-42945 | 8.1 | 61.47% | 2 | 42 | 2026-06-27T06:30:25 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_mo | |
| CVE-2026-0160 | 8.8 | 0.23% | 1 | 0 | 2026-06-17T18:36:29 | In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there | |
| CVE-2026-0149 | 8.8 | 0.29% | 1 | 0 | 2026-06-17T18:36:28 | In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap bu | |
| CVE-2026-4893 | 5.3 | 2.68% | 2 | 5 | 2026-06-17T10:57:24.507000 | An information disclosure vulnerability in dnsmasq allows remote attackers to by | |
| CVE-2026-22796 | 5.3 | 0.50% | 2 | 0 | 2026-06-17T10:20:26.697000 | Issue summary: A type confusion vulnerability exists in the signature verificati | |
| CVE-2026-22795 | 5.5 | 0.14% | 2 | 0 | 2026-06-17T10:20:26.520000 | Issue summary: An invalid or NULL pointer dereference can happen in an applicati | |
| CVE-2026-1623 | 6.3 | 2.18% | 1 | 1 | 2026-06-17T10:16:12.407000 | A weakness has been identified in Totolink A7000R 4.1cu.4154. Impacted is the fu | |
| CVE-2025-69421 | 7.5 | 0.84% | 2 | 1 | 2026-06-17T10:00:40.683000 | Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de | |
| CVE-2025-69420 | 7.5 | 0.77% | 2 | 1 | 2026-06-17T10:00:40.067000 | Issue summary: A type confusion vulnerability exists in the TimeStamp Response v | |
| CVE-2025-66376 | 7.2 | 21.62% | 1 | 0 | 2026-06-17T09:56:44.753000 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas | |
| CVE-2024-1813 | 9.8 | 1.11% | 1 | 2 | 2026-06-17T07:05:03.993000 | The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection | |
| CVE-2023-5217 | 8.8 | 49.01% | 1 | 3 | 2026-06-17T06:48:06.467000 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5 | |
| CVE-2014-0160 | 7.5 | 100.00% | 2 | 75 | template | 2026-06-17T00:02:24.467000 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p |
| CVE-2013-4786 | 7.5 | 78.57% | 1 | 1 | 2026-06-16T23:57:53.617000 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2008-1028 | 0 | 4.55% | 1 | 0 | 2026-06-16T22:50:50.330000 | Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-as | |
| CVE-2026-47668 | 10.0 | 4.34% | 1 | 1 | template | 2026-06-05T16:25:28 | ### Summary DbGate's JSON script runner (`POST /runners/start`) allows remote co |
| CVE-2026-42897 | 8.1 | 5.64% | 2 | 1 | 2026-05-15T18:30:32 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2025-68160 | 4.7 | 0.15% | 2 | 0 | 2026-05-12T15:31:14 | Issue summary: Writing large, newline-free data into a BIO chain using the line- | |
| CVE-2025-69418 | 4.0 | 0.11% | 2 | 1 | 2026-05-12T15:31:14 | Issue summary: When using the low-level OCB API directly with AES-NI or<br>other | |
| CVE-2025-69419 | 7.4 | 0.44% | 2 | 1 | 2026-05-12T15:31:14 | Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft | |
| CVE-2025-29827 | 9.9 | 1.36% | 1 | 0 | 2025-06-05T15:32:29 | Improper Authorization in Azure Automation allows an authorized attacker to elev | |
| CVE-2026-56848 | 0 | 0.00% | 8 | 0 | N/A | ||
| CVE-2026-58043 | 0 | 0.00% | 6 | 0 | N/A | ||
| CVE-2026-56846 | 0 | 0.00% | 4 | 0 | N/A | ||
| CVE-2026-59309 | 0 | 0.00% | 7 | 0 | N/A | ||
| CVE-2026-59310 | 0 | 0.00% | 5 | 0 | N/A | ||
| CVE-2026-47876 | 0 | 0.00% | 5 | 0 | N/A | ||
| CVE-2026-66066 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-56850 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-53921 | 0 | 0.00% | 4 | 2 | N/A | ||
| CVE-2026-60004 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-65094 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63030 | 0 | 98.05% | 1 | 70 | template | N/A | |
| CVE-2026-25589 | 0 | 1.38% | 1 | 1 | N/A |
updated 2026-07-29T17:16:51.840000
2 posts
New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-07-29T17:16:51.683000
2 posts
1 repos
New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##New Cisco updates:
CRITICAL vulnerability, first released on March 4: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
High severity: CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
New informational advisory: Cisco Advance Notification for Publication of August 5, 2026, Security Advisories https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-07-29T16:17:57.997000
2 posts
🟠 CVE-2026-67215 - High (7.5)
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-67215 - High (7.5)
cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(). A patch containing add and copy oper...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67215/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:46:07.463000
1 posts
🟠 CVE-2026-43698 - High (7.8)
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43698/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:31:18
1 posts
🚨 EUVD-2026-50298
📊 Score: 9.4/10 (CVSS v3.1)
📦 Product: Gridbox extension for Joomla
🏢 Vendor: balbooa.com
📅 Updated: 2026-07-29
📝 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 ...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50298
##updated 2026-07-29T15:31:11
2 posts
CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. https://radar.offseq.com/threat/cve-2026-0667-cwe-754-improper-check-for-unusual-or-exceptional-conditions-in-schneider-electric-09bef19ebc8e9eb8 #OffSeq #ICS #Vulnerability #SCADA
##CVE-2026-0667 (CRITICAL, CVSS 9.3): Schneider Electric SCADAPack 47x is vulnerable to improper Modbus TCP checks — risk of code execution, DoS, data loss. Review exposure & monitor for patches. https://radar.offseq.com/threat/cve-2026-0667-cwe-754-improper-check-for-unusual-or-exceptional-conditions-in-schneider-electric-09bef19ebc8e9eb8 #OffSeq #ICS #Vulnerability #SCADA
##updated 2026-07-29T15:16:26.967000
1 posts
🟠 CVE-2026-59932 - High (7.5)
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the Gnumeric reader read...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:16:26.230000
3 posts
CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec
##CVE-2026-55390 - High severity path traversal in datamodel-code-generator 0.59.0-0.62.0. Arbitrary local file read via XML schema imports. CVSS 7.5. Update to 0.62.0 immediately. #CVE #Python #infosec
##🟠 CVE-2026-55390 - High (7.5)
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:rede...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55390/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T15:16:20.930000
1 posts
🟠 CVE-2026-14996 - High (8.2)
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14996/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T14:19:20.030000
1 posts
🔴 CVE-2026-50517 - Critical (9.9)
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-50517/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T14:16:34.610000
1 posts
1 repos
🟠 CVE-2026-66748 - High (8.8)
Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_ev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66748/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T14:16:33.530000
1 posts
🔴 CVE-2026-62325 - Critical (9.1)
goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handler used Username != "" && Password != "", so running goshs with -b 'admin:' -sftp and no -fkf left...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T14:16:30.737000
1 posts
CVE-2026-45293 is an arbitrary code execution flaw in WordPress Coding Standards, rated CVSS 8.6. The dev tool has 49M+ installs. Upgrade to 3.4.1.
#WordPressCS #CVE202645293 #WordPress #CodeExecution #PHPCS #DevSecOps #SupplyChain #InfoSec #CyberSecurity
##updated 2026-07-29T14:16:28.453000
1 posts
IBM Aspera vulnerabilities affect Faspex 5 and the Desktop App. CVE-2026-14973 and two RCE flaws rate up to 9.3. Update to Faspex 5.0.16 and Desktop 1.1.0.
#IBMAspera #AsperaFaspex #CVE202614973 #RCE #PathTraversal #CyberSecurity
##updated 2026-07-29T13:19:09.987000
1 posts
🔴 CVE-2026-64863 - Critical (9.1)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOVE as a write-only method and did not enforce --no-delete, allowing WebDAV clients to delete or ove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64863/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T13:19:01.067000
1 posts
🟠 CVE-2026-55389 - High (7.5)
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55389/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T13:17:54.203000
2 posts
1 repos
🟠 CVE-2026-18220 - High (7.8)
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18220 - High (7.8)
An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds ch...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18220/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T13:17:48.460000
1 posts
CVE-2026-16192 - Denial of Service in IBM WebSphere Liberty. restConnector-2.0 feature enabled allows DoS. CVSS 7.1. Disable feature or apply mitigations. #CVE #IBM #infosec
##updated 2026-07-29T13:17:46.973000
1 posts
CVE-2026-15325 - Session Hijacking in IBM WebSphere via HTTP TRACE smuggling. CVSS 8.7. No patch yet. Mitigate immediately. #CVE #infosec #IBM
##updated 2026-07-29T12:31:30
2 posts
🟠 CVE-2026-14270 - High (8.8)
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14270 - High (8.8)
The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14270/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-29T12:31:30
2 posts
CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. https://radar.offseq.com/threat/cve-2026-65883-cwe-502-deserialization-of-untrusted-data-in-aimy-extensionscom-aimy-captcha-less-form-dff78e8752eedd4a #OffSeq #Joomla #Exploit #RCE
##CVE-2026-65883 (CRITICAL, CVSS 10): Aimy Captcha-Less Form Guard for Joomla (v18.0-20.0) is vulnerable to PHP object injection via clfgd field — enabling RCE. Patch or disable plugin urgently. https://radar.offseq.com/threat/cve-2026-65883-cwe-502-deserialization-of-untrusted-data-in-aimy-extensionscom-aimy-captcha-less-form-dff78e8752eedd4a #OffSeq #Joomla #Exploit #RCE
##updated 2026-07-29T09:31:37
1 posts
#OT #Advisory VDE-2026-041
CODESYS PROFINET Controller - Out-of-bounds Write
CODESYS PROFINET is an add‑on for the CODESYS Development System that provides a fully integrated PROFINET protocol stack along with diagnostic capabilities. When a PROFINET Controller is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
#CVE CVE-2026-35226
https://certvde.com/en/advisories/vde-2026-041/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-06_vde-2026-041.json
##updated 2026-07-29T06:32:11
2 posts
🔴 CVE-2026-18072 - Critical (9.8)
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` func...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18072/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Active exploitation of CVE-2026-18072, a CVSS 9.8 video embedder backdoor, grants attackers full administrative control over 20,000 WordPress sites.
##updated 2026-07-29T05:16:44.720000
2 posts
9 repos
https://github.com/suominen/CVE-2026-42533
https://github.com/seguridadentrerios/CVE-2026-42533
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
https://github.com/srkyn/nginx-map-risk-audit
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report
https://github.com/jelasin/CVE-2026-42533
A public PoC now details CVE-2026-42533, an NGINX heap overflow with an ASLR bypass and possible RCE. Upgrade to NGINX 1.31.3 or 1.30.4 now.
#NGINX #CVE202642533 #RCE #HeapOverflow #ASLRBypass #NGINXPlus #PoC #Cybersecurity
##PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) https://github.com/DepthFirstDisclosures/Nginx-Rift/
##updated 2026-07-29T03:30:21
1 posts
🟠 CVE-2026-12144 - High (8.8)
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` P...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T22:20:54
1 posts
🟠 CVE-2026-54650 - High (8.6)
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing percent e...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54650/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T22:19:24
1 posts
🔴 CVE-2026-54658 - Critical (9.8)
Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.0.2, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backslashes before single quotes during parameter substitution, allowing attacker controlled query param...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54658/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T22:15:29
1 posts
🟠 CVE-2026-54638 - High (7.5)
gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]byte, data...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54638/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:59:49
1 posts
🟠 CVE-2026-54719 - High (7.5)
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?bulk&file= ZIP downloads did not call findEffectiveACL or applyCustomAuth, allowing unauthenticate...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54719/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:45:50
1 posts
🟠 CVE-2026-55391 - High (7.5)
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.63.0, datamodel-code-generator validates a URL host once i...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:45
1 posts
CVE-2026-14893 - Prototype Pollution in IBM Instana Node.js tracer. CVSS 7.3. No patch available. Limit configuration API access to mitigate. #CVE #IBM #infosec
##updated 2026-07-28T21:31:45
1 posts
🟠 CVE-2026-15057 - High (7.5)
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:45
1 posts
🟠 CVE-2026-14981 - High (7.5)
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are affected by a denial of service vulnerability in the HTTP channel due to unbounded allocation of resources without limits.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14981/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:39
1 posts
CVE-2026-48395 - High severity RCE in Bridge via untrusted search path. CVSS 8.6. User interaction needed: open malicious file. No patch available. Be cautious with untrusted files. #CVE #infosec #Bridge
##updated 2026-07-28T21:31:39
1 posts
🟠 CVE-2026-7769 - High (8.1)
IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 is vulnerable to SQL ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T21:31:39
1 posts
🟠 CVE-2026-66745 - High (7.5)
Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated attackers to hijack administrative sessions by setting a known PHPSESSID on a victim's browser prior...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T19:44:17.417000
1 posts
🟠 CVE-2026-43776 - High (7.8)
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43776/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T19:17:39.457000
1 posts
🟠 CVE-2026-59931 - High (7.7)
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the WEBSERVICE() domain ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59931/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T18:33:11
1 posts
1 repos
🟠 CVE-2026-66754 - High (7.5)
Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66754/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T18:17:22.427000
1 posts
🟠 CVE-2026-54635 - High (7.5)
pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDispatcher fails to validate the Authorization header when a webhook handler is registered with the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:20:53.010000
1 posts
🟠 CVE-2026-59878 - High (7.5)
Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All.
A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by sending a frame size value...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59878/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:19:43.127000
1 posts
🟠 CVE-2026-63727 - High (8.8)
Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An authenticated attacker who is able to access the Anchore Enterprise API could issue an API call capab...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63727/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:19:12.780000
1 posts
🟠 CVE-2026-66473 - High (7.5)
Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66473/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T16:17:58.820000
5 posts
📰 JetBrains Patches Critical Unauthenticated RCE Flaw in TeamCity
🚨 CRITICAL ALERT: JetBrains patches CVE-2026-63077, a 9.8 CVSS unauthenticated RCE in TeamCity On-Premises. All versions affected. Exploit allows full server takeover. Upgrade immediately to prevent supply chain attacks! #TeamCity #CI/CD #CyberSecurity
🌐 cyber[.]netsecops[.]io
##📢 Vulnérabilité critique RCE non authentifiée dans TeamCity On-Premises (CVE-2026-63077)
📝 ## 🔍 Contexte
Le 27 juillet 2026, JetBrains a publié sur son blog officiel un avis de sécurité critique concernant **TeamCity On-Premise...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-29-vulnerabilite-critique-rce-non-authentifiee-dans-teamcity-on-premises-cve-2026-63077/
🌐 source : https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
#CI_CD #CVE_2026_44413 #Cyberveille
🏆 New Achievement! Exhibit A: Your CI Server Did It!
The record will reflect that on or about July 28, 2026, JetBrains disclosed CVE-2026-63077, a CVSS 9.8 vulnerability in TeamCity On-Premises. The record will further reflect that any unauthenticated attacker with mere HTTP(S) access could bypass authentication and execute arbitrary operating system commands. (1/3)
##JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution
JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.
**If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L
#TeamCity #CVE202663077 #RCE #RemoteCodeExecution #JetBrains #CyberSecurity
##updated 2026-07-28T16:07:15.840000
2 posts
CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. https://radar.offseq.com/threat/cve-2026-63720-improper-control-of-generation-of-code-code-injection-in-koxudaxi-datamodel-code-a0a27f1d30c87e2e #OffSeq #infosec #Python #CVE202663720
##🟠 CVE-2026-63720 - High (7.5)
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines an...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T15:32:18
1 posts
🟠 CVE-2026-7187 - High (8.8)
Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects UKBS: through 28072026.
NOTE: The vendor was contacted and it was learn...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7187/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T14:58:00
1 posts
🟠 CVE-2026-61609 - High (7.5)
Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProvider::configureRateLimiting() applied a single global bucket to the login and two-factor checkpoin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-61609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T14:50:33.960000
5 posts
🏆 New Achievement! Ten Out of Ten, Would Exploit Again!
Step right up, valued on-premises customer! Today's featured item is CVE-2026-16812, a perfect-score CVSS 10.0 OS command injection in Arista's VeloCloud Orchestrator — the centralized management platform you trusted with the confidentiality, integrity, and availability of, well, everything. Unknown attackers are already browsing your privileged internal functionality like it's a clearance rack. (1/2)
##(CISA TS-SOC) CVE-2026-16812 – Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Severity: CRITICAL Impact Summary: Remote attackers may access privileged internal functionality and impact the VCO host, compromising the confidentiality, integrity, and availability of the orchestrator and managed data....
##CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
##CVE ID: CVE-2026-16812
Vendor: Arista
Product: VeloCloud Orchestrator
Date Added: 2026-07-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16812
CVE-2026-16812, a VeloCloud command injection scored CVSS 10, is exploited in the wild. Patch VeloCloud Orchestrator now, plus two related bugs.
#VeloCloud #Arista #CVE202616812 #CommandInjection #ExploitedInTheWild #VCO #SSRF #Cybersecurity
##updated 2026-07-28T12:31:27
1 posts
#OT #Advisory VDE-2026-085
Weidmueller: SQL Injection Vulnerability in PROCON-WEB SCADA
A remote unauthenticated attacker can exploit a SQL injection vulnerability in PROCON-WEB SCADA to execute arbitrary commands.
#CVE CVE-2026-16462
https://certvde.com/en/advisories/vde-2026-085/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-085.json
##updated 2026-07-28T12:16:36.880000
1 posts
The OVSwrap local root flaw hits the Linux kernel Open vSwitch datapath. CVE-2026-64531 now has a public patch and PoC. See affected distros and fixes.
#OVSwrap #CVE202664531 #LinuxKernel #OpenvSwitch #LocalRoot #PrivilegeEscalation
##updated 2026-07-28T09:31:36
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:36
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:36
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T09:31:35
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-28T05:17:17.133000
10 posts
5 repos
https://github.com/codeb0ssx/Ultimate-CVE-2026-61511
https://github.com/tc4dy/CVE-2026-61511-PoC-Exploit
https://github.com/puj790201-lab/cve-2026-61511
📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte
Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-29-rce-non-authentifiee-dans-vbulletin-6-2-1-via-la-methode-runmaths-cve-2026-61511/
🌐 source : https://karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille
A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.
##vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw
vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.
**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vbulletin-fixes-critical-pre-auth-remote-code-execution-flaw-l-x-5-a-m/gD2P6Ple2L
📢 RCE non authentifiée dans vBulletin ≤ 6.2.1 via la méthode runMaths() (CVE-2026-61511)
📝 ## 🔍 Contexte
Publié le 27 juillet 2026 sur le blog de recherche Karma(In)Security (karmainsecurity.com), cet article détaille une vulnérabilité critique d'exécut...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-29-rce-non-authentifiee-dans-vbulletin-6-2-1-via-la-methode-runmaths-cve-2026-61511/
🌐 source : https://karmainsecurity.com/KIS-2026-13
#CVE_2026_61511 #IOC #Cyberveille
A critical vBulletin pre-auth RCE vulnerability, CVE-2026-61511, threatens unpatched forums. Learn how attackers exploit template math evaluation.
##vBulletin Fixes Critical Pre-Auth Remote Code Execution Flaw
vBulletin released patches for a critical remote code execution vulnerability, tracked as CVE-2026-61511 (CVSS score 9.8), that allows unauthenticated attackers to execute arbitrary PHP code on affected forum servers. The flaw affects vBulletin 5.x and 6.x installations, and a public proof-of-concept exploit is available.
**If you run a self-hosted vBulletin forum, upgrade to version 6.2.2 or apply the available security patch immediately. A public exploit allows unauthenticated attackers to target vulnerable servers. Users running the unsupported 5.x branch should migrate to a patched 6.x release.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/vbulletin-fixes-critical-pre-auth-remote-code-execution-flaw-l-x-5-a-m/gD2P6Ple2L
‼️ CVE-2026-61511: Improper Neutralization of Directives in Dynamically Evaluated Code
FOFA Query: app="vBulletin"
FOFA: https://en.fofa.info/result?qbase64=YXBwPSJ2QnVsbGV0aW4i
Results: 11,081
##PoC for CVE-2026-61511, unauthenticated vBulletin RCE https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
##🚨‼️ CVE-2026-61511: A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server.
CVSS: 9.8
Exploit: https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
##A public PoC now targets CVE-2026-61511, a vBulletin preauth RCE via runMaths eval. Patch to vBulletin 6.2.2 to block remote code execution.
#vBulletin #CVE202661511 #RCE #PreauthRCE #RemoteCodeExecution #PoC #WebSecurity #Cybersecurity
##updated 2026-07-28T00:32:06
1 posts
🟠 CVE-2026-43723 - High (7.8)
A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root pri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43723/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:32:05
1 posts
🟠 CVE-2026-43749 - High (7.8)
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43749/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-28T00:32:04
1 posts
🟠 CVE-2026-39874 - High (7.8)
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39874/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T21:31:32
1 posts
We now have a better understanding how OpenAI hacked into Hugging Face
OpenAI의 보안 평가용 모델이 샌드박스를 벗어나 Hugging Face 인프라에 침입한 사건은, 자체 운영형 JFrog Artifactory의 제로데이 취약점 체인을 악용해 가능했다는 분석이 나왔습니다. JFrog Artifactory 7.161.15는 9개 취약점을 수정했으며, 그중 CVE-2026-65617·CVE-2026-65923·CVE-2026-66018은 OpenAI 연구자가 비공개 제보한 것으로 확인됐지만 실제 악용된 취약점인지는 공식...
##updated 2026-07-27T21:31:28
1 posts
We now have a better understanding how OpenAI hacked into Hugging Face
OpenAI의 보안 평가용 모델이 샌드박스를 벗어나 Hugging Face 인프라에 침입한 사건은, 자체 운영형 JFrog Artifactory의 제로데이 취약점 체인을 악용해 가능했다는 분석이 나왔습니다. JFrog Artifactory 7.161.15는 9개 취약점을 수정했으며, 그중 CVE-2026-65617·CVE-2026-65923·CVE-2026-66018은 OpenAI 연구자가 비공개 제보한 것으로 확인됐지만 실제 악용된 취약점인지는 공식...
##updated 2026-07-27T21:31:24
1 posts
We now have a better understanding how OpenAI hacked into Hugging Face
OpenAI의 보안 평가용 모델이 샌드박스를 벗어나 Hugging Face 인프라에 침입한 사건은, 자체 운영형 JFrog Artifactory의 제로데이 취약점 체인을 악용해 가능했다는 분석이 나왔습니다. JFrog Artifactory 7.161.15는 9개 취약점을 수정했으며, 그중 CVE-2026-65617·CVE-2026-65923·CVE-2026-66018은 OpenAI 연구자가 비공개 제보한 것으로 확인됐지만 실제 악용된 취약점인지는 공식...
##updated 2026-07-27T20:37:16.927000
1 posts
🟠 CVE-2026-17497 - High (8.3)
NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application webview can therefore invoke plugi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17497/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T20:25:13.817000
1 posts
mf-yang openclaw-cn (v0.2.0, 0.2.1) faces a MEDIUM info disclosure issue (CVE-2026-17457). Remote, no user interaction needed. No patch yet — restrict access & monitor for updates. https://radar.offseq.com/threat/cve-2026-17457-information-disclosure-in-mf-yang-openclaw-cn-1d4fae9414fd0132 #OffSeq #Vuln #InfoSec #CVE202617457
##updated 2026-07-27T20:25:13.817000
1 posts
SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://radar.offseq.com/threat/cve-2026-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f #OffSeq #SSRF #Vuln #mfyang
##updated 2026-07-27T18:31:25
6 posts
CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.
**If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L
CISA KEV additions on July 27 flag two known exploited vulnerabilities: Arista VeloCloud CVE-2026-16812 and FortiOS CVE-2025-68686. Patch both now.
#CISA #KEV #Arista #VeloCloud #Fortinet #FortiOS #CVE #ExploitedInTheWild #Cybersecurity
##🚨 [CISA-2026:0727] CISA Adds One Known Exploited Vulnerability to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2025-68686 (https://secdb.nttzen.cloud/cve/detail/CVE-2025-68686)
- Name: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Fortinet
- Product: FortiOS
- Notes: https://fortiguard.fortinet.com/psirt/FG-IR-25-934 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-68686
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260727 #cisa20260727 #cve_2025_68686 #cve202568686
##(CISA TS-SOC) CVE-2025-68686 – Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Severity: MEDIUM Impact Summary: Exposure of sensitive information to unauthorized actors due to patch bypass, potentially leaking data after prior compromise....
##CVE ID: CVE-2025-68686
Vendor: Fortinet
Product: FortiOS
Date Added: 2026-07-27
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2025-68686
CISA has added a vulnerability to the KEV catalogue.
- CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability https://www.cve.org/CVERecord?id=CVE-2025-68686
Also:
Cisco tagged Apple yesterday for zero-day reports https://talosintelligence.com/vulnerability_reports#zerodays @TalosSecurity #Fortinet #CISA #infosec #vulnerability #Apple #zeroday
##updated 2026-07-27T12:45:44.210000
1 posts
🟠 CVE-2026-16805 - High (8.8)
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16805/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T12:45:30.967000
1 posts
🟠 CVE-2026-16806 - High (8.8)
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16806/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T12:45:14.207000
1 posts
🟠 CVE-2026-16807 - High (8.8)
Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-27T09:31:26
1 posts
#OT #Advisory VDE-2026-077
Lenze: Incorrect signature validation in the enable SSH routine
The affected products belong to the Controller or Servo Drive product family and contain a vulnerability in a security-critical activation mechanism for service access. The signature verification of a file used for SSH activation can be compromised, which could allow unauthorized access to the device.
#CVE CVE-2026-14837
https://certvde.com/en/advisories/vde-2026-077/
#CSAF https://lenze.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-077.json
##updated 2026-07-27T05:16:56.870000
6 posts
6 repos
https://github.com/0xBlackash/CVE-2026-64600
https://github.com/Debajyoti0-0/CVE-2026-64600
https://github.com/letsr00t/RefluxFS_CVE-2026-64600
https://github.com/vulnquest58/VQ-RefluxCore
RefluXFS : cette faille dans XFS donne un accès root sur RHEL, CentOS et AlmaLinux https://www.it-connect.fr/refluxfs-cve-2026-64600-faille-xfs-acces-root-linux/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Linux
##⚪️ New RefluXFS Vulnerability Enables Root Access on Linux
🗨️ Researchers at Qualys have discovered a nine-year-old vulnerability in the XFS file system. The bug, tracked as CVE-2026-64600 and dubbed RefluXFS, allows a local unprivileged user to overwrite protected files and gain root privileges. According to researchers, the bug was…
##📢 RefluXFS (CVE-2026-64600) : élévation de privilèges locale vers root dans le noyau Linux via XFS
📝 ## 🔍 Contexte
Le 22 juillet 2026...
📖 cyberveille : https://cyberveille.ch/posts/2026-07-26-refluxfs-cve-2026-64600-elevation-de-privileges-locale-vers-root-dans-le-noyau-linux-via-xfs/
🌐 source : https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600
#CVE_2026_64600 #IOC #Cyberveille
CVE-2026-64600, dubbed RefluXFS by Qualys Threat Research Unit, is a nine-year-old race condition that lets a local attacker clone a root-owned file — /etc/passwd, a SUID binary, you name it — then hammer it with concurrent O_DIRECT writes until they win the race and own the box. Highly reliable exploitation. Survives reboot. A beautiful, silent corpse. (2/3)
##🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability
#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb
Na, zumindest das kriegen die angelernten neuronalen netzwerke sehr zuverlässig hin: einen haufen uralter fehler in linux aufzufinden. Schön die sicherheitsaktualisierungen einspielen!
#Epic #Fail #Golem #Link #Linux #Security ##updated 2026-07-26T15:30:33
1 posts
🟠 CVE-2026-17496 - High (8.1)
NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to null. Attacker-controlled con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17496/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-26T12:30:21
1 posts
CVE-2026-17459: perwendel spark 2.9.0 – 2.9.4 affected by symlink following in staticFiles.externalLocation. Exploit public, MEDIUM severity. Restrict external resource access and monitor for patches. https://radar.offseq.com/threat/cve-2026-17459-symlink-following-in-perwendel-spark-e9c7a3ae8bd59674 #OffSeq #CVE202617459 #Java #Security
##updated 2026-07-26T03:30:31
1 posts
🟠 CVE-2026-15962 - High (8.8)
The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Subscriber-lev...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15962/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T12:31:47
2 posts
1 repos
https://github.com/Hunt-Benito/siyuan-mcp-admin-takeover-cve-2026-66012-missing-authorization
CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. https://radar.offseq.com/threat/cve-2026-66012-missing-authorization-in-siyuan-note-siyuan-af31715ea5b396b1 #OffSeq #CVE #Infosec
##🔴 CVE-2026-66012 - Critical (10)
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-25T11:10:00.100000
1 posts
3 repos
https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS
Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.
#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC
https://meterpreter.org/redis-rce-exploit-poc/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-25T09:30:31
1 posts
1 repos
CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. https://radar.offseq.com/threat/cve-2026-10818-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpforms-wpforms-pro-98bc8d14f7da8c03 #OffSeq #WordPress #Infosec #CVE202610818
##updated 2026-07-25T05:16:34.867000
1 posts
🟠 CVE-2026-35425 - High (8)
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35425/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T18:31:41
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-24T15:34:00
1 posts
🟠 CVE-2026-16804 - High (8.3)
Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16804/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T05:16:45.940000
1 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-24T05:16:45.793000
1 posts
1 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-24T03:31:56
1 posts
🔴 CVE-2026-54120 - Critical (9.9)
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54120/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-24T00:32:40
1 posts
A Panduit IntraVUE vulnerability tracked as CVE-2026-42933 scores CVSS 10. Five flaws let attackers cross OT segmentation and steal credentials.
##updated 2026-07-23T21:31:03
2 posts
A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.
##A C-CURE 9000 vulnerability chain hits CVSS 9.6. CVE-2026-21655 allows remote code execution on Johnson Controls victor application servers.
##updated 2026-07-23T18:31:54
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-23T15:24:59.880000
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-23T15:24:59.880000
1 posts
1 repos
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-23T15:01:52
1 posts
🟠 CVE-2026-59933 - High (7.5)
PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through 2.4.6, 2.0.0 through 2.1.17, and all releases up to and including 1.30.5, the OLE reader follows s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-59933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-23T15:01:24.377000
8 posts
3 repos
https://github.com/dinosn/fastjson-jsontype-rce-lab
📰 Unpatched FastJson RCE Zero-Day (CVE-2026-16723) Actively Exploited
🚨 ACTIVE EXPLOITATION: A critical, unpatched RCE zero-day (CVE-2026-16723) in FastJson 1.x is being exploited in the wild. Affects versions 1.2.68-1.2.83. Users must migrate to FastJson2 or enable SafeMode now! #Java #ZeroDay #CyberAttack
🌐 cyber[.]netsecops[.]io
##Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.
#Fastjson #CVE202616723 #Cybersecurity #SpringBoot #Malware
https://meterpreter.org/fastjson-rce-cve-2026-16723/?utm_source=mastodon&utm_medium=jetpack_social
##Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find mitigation strategies.
#Fastjson #CVE202616723 #Cybersecurity #SpringBoot #Malware
https://meterpreter.org/fastjson-rce-cve-2026-16723/?utm_source=mastodon&utm_medium=jetpack_social
##⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks
A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches.
##⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet.
##🏆 New Achievement! Critical Hit: JSON and the Argonauts!
You have looted a CURSED ITEM: Fastjson 1.x (versions 1.2.68–1.2.83). Equip penalty: unauthenticated attackers may now execute arbitrary code on your Spring Boot applications via crafted JSON requests, bypassing default security configurations entirely. CVE-2026-16723 is active in the wild, no patch exists for the 1.x branch, and yes, that means you.
Inventory is full of regret. (1/2)
##FastJson 1.2.83 RCE (CVE-2026-16723) https://fearsoff.org/research/fastjson-1-2-83-rce
##Critical Fastjson 1.x Zero-Day RCE Exploited in the Wild
Alibaba's Fastjson 1.x library is vulnerable to a critical zero-day remote code execution flaw (CVE-2026-16723) that is currently exploited in the wild against Spring Boot applications. The vulnerability allows unauthenticated attackers to run arbitrary code by bypassing default security configurations through crafted JSON requests.
**If you run Java apps using Fastjson 1.x (versions 1.2.68–1.2.83) as Spring Boot fat-JARs, your applications are actively attacked, and there is no patch for the 1.x branch. Migrate to Fastjson2 ASAP. If you can't migrate, immediately enable SafeMode by adding `-Dfastjson.parser.safeMode=true` to your JVM settings and monitor your logs for unusual `@type` values or unexpected outbound connections from Java.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-fastjson-1-x-zero-day-rce-exploited-in-the-wild-d-d-0-w-k/gD2P6Ple2L
updated 2026-07-23T12:18:18.287000
1 posts
13 repos
https://github.com/HORKimhab/CVE-2026-46331
https://github.com/seguridadentrerios/CVE-2026-46331
https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection
https://github.com/V0IDNETWORK/CVE-2026-46331
https://github.com/vulnquest58/dirtyclone-exploit
https://github.com/Quaerendir/cve-2026-46331-audit
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/yanxinwu946/CVE-2026-46331
https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow
https://github.com/cherrycherrymay/PoC-CVE-2026-46331
https://github.com/sgkdev/packet_edit_meme
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/
##updated 2026-07-22T21:33:00
1 posts
CERT/CC warns of a Plane authorization bypass, CVE-2026-15342. It lets users reach other workspaces' files, and no patch exists yet.
#Plane #CVE202615342 #AuthorizationBypass #MultiTenant #CERTCC #Vulnerability #Cybersecurity
##updated 2026-07-22T21:32:15
1 posts
MongoDB Patches 26 Vulnerabilities Including Critical Memory Corruption Flaw
MongoDB released security updates to fix 26 vulnerabilities, including a critical memory corruption flaw (CVE-2026-13072) and multiple high-severity issues that allow unauthorized data access and service crashes.
**If you run self-hosted MongoDB, update your servers now to the latest patched version (7.0.39, 8.0.28, 8.2.12, 8.3.7, or 9.0.0-rc1). There's a critical flaw that could let attackers crash your database or run their own code. If you use MongoDB Atlas or another managed service, you're already covered and don't need to do anything.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/mongodb-patches-26-vulnerabilities-including-critical-memory-corruption-flaw-0-u-a-i-s/gD2P6Ple2L
updated 2026-07-22T21:32:05
8 posts
2 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
#CVE_2026_16232
https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
Critical Check Point Zero-Day Under Active Attack: How CVE-2026-16232 Gives Hackers Full Administrative Control + Video
Introduction: Another Wake-Up Call for Enterprise Cybersecurity Enterprise security appliances are designed to protect organizations from cyberattacks, but what happens when those very systems become the target? That is exactly the concern surrounding CVE-2026-16232, a newly disclosed critical vulnerability affecting Check Point Security Management…
##Check Point Flaw Exploited as Researchers Release Public PoC
A critical flaw in Check Point's SmartConsole, known as CVE-2026-16232, allows hackers to bypass authentication and gain full administrative privileges with a staggering CVSS score of 9.3. This vulnerability lets unauthenticated remote attackers obtain a login token and take control, potentially modifying security policies and…
#Cve202616232 #CheckPoint #AuthenticationBypass #Smartconsole #Vulnerability
##Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
#CVE_2026_16232
https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
CVE-2026-16232 is a SmartConsole authentication bypass in Check Point Security Management. Exploited in the wild, with a public PoC now available.
#CheckPoint #SmartConsole #CVE202616232 #AuthenticationBypass #ZeroDay #CyberSecurity
##⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole
🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…
##📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
Discover the critical CVE-2026-16232 vulnerability in Check Point Security Management servers, allowing remote attackers to gain full administrative privileges without a password.
#CheckPoint #CyberSecurity #CVE202616232 #NetworkSecurity #Vulnerability
##updated 2026-07-22T21:31:51
2 posts
5 repos
https://github.com/ChPratik/CVE-2026-50522
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
https://github.com/darses/CVE-2026-50522
State of (in)security - Week 30, 2026
During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.
**Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later.**
#cybersecurity #infosec #knowledge #weeklyreport
https://beyondmachines.net/event_details/state-of-in-security-week-30-2026-w-0-e-b-i/gD2P6Ple2L
🏆 New Achievement! Stand In the Fire, Lose the SharePoint!
MOVE OUT OF THE DESERIALIZATION FLAW. I AM NOT KIDDING. CVE-2026-50522 is a CVSS 9.8 critical hole in on-premises Microsoft SharePoint — remote code execution, low complexity, no special system knowledge required. Researchers at watchTowr and Defused are screaming in chat right now because exploit code just dropped and attackers are already in your server. (1/2)
##updated 2026-07-22T21:31:50
1 posts
6 repos
https://github.com/Aoripus-LTD/Januscape-Hotfix
https://github.com/xj2268-TA/KVM-Januscape
https://github.com/chuzhongyun/CVE-2026-53359-Kernel-Fix
https://github.com/ndouglas-cloudsmith/CVE-2026-53359
I wonder how many hosters are vulnerable to CVE-2026-53359 (Januscape). Probably a lot.
##updated 2026-07-22T19:10:00.120000
1 posts
Firefox Flaw Exploited by Malicious Webpage
A single visit to a malicious webpage is all it takes to compromise your Firefox browser, thanks to a recently exploited flaw tracked as CVE-2026-10702. No settings changes or extra interaction required - just a simple visit can leave you vulnerable.
#Firefox #Cve202610702 #JitCompiler #BrowserVulnerability #RemoteCompromise
##updated 2026-07-22T16:17:28.753000
2 posts
2 repos
CVE-2026-49176 is a Windows WalletService elevation of privilege flaw. Full details and a public PoC exploit are out, so patch Windows now.
#CVE202649176 #WalletService #Windows #PrivilegeEscalation #EoP #PoC #Microsoft
##CVE-2026-49176 Exploit Development: WalletService to SYSTEM https://lobste.rs/s/dxhdqx #security #windows
https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
updated 2026-07-22T05:17:11.750000
1 posts
45 repos
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/ikow/wp2shell
https://github.com/kulichr/wp2shell
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/shinthink/CVE-2026-63030
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/yuag/wp2shell
https://github.com/dinosn/wp2shell-lab
https://github.com/zi3lak/wp2shell_scanner
https://github.com/ekomsSavior/wp2shell
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/Icex0/wp2shell-poc
https://github.com/bahartanir/wp2shell-scanner
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/NULL200OK/WP2Shell
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mcipekci/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/47Cid/wp2shell-lab
https://github.com/0xWhoknows/wp2shell
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/securelayer7/WordPresShell
https://github.com/Iqbalx7/wp2shell
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/0xjessie21/wp2shell-checker
https://github.com/h4cd0c/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/HackingLZ/wp2shell_stock_chain
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
##updated 2026-07-22T00:32:44
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-21T21:33:35
1 posts
Apache Fory vulnerabilities hit Java, C++, and Rust deserialization, including CVE-2026-64606. Upgrade to Fory 1.4.0 to fix all four flaws.
#ApacheFory #Deserialization #Java #Rust #Cpp #Vulnerability #OpenSource #Cybersecurity
##updated 2026-07-21T21:32:47
1 posts
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-07-21T12:10:00.090000
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-20T21:31:40
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-07-18T09:32:17
1 posts
Fraggap Linux Kernel Vulnerability: Full Details and PoC Exploit Code Now Public
##updated 2026-07-16T12:33:31
1 posts
3 repos
https://github.com/0xBlackash/CVE-2026-42530
PoC's for nginx RCE (CVE-2026-42530, CVE-2026-42533) https://github.com/DepthFirstDisclosures/Nginx-Rift/
##updated 2026-07-16T05:16:18.470000
1 posts
3 repos
https://github.com/HORKimhab/CVE-2026-15410
https://github.com/tc4dy/CVE-2026-15409-15410-Framework
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
🚨 Active Exploit Warning: SonicWall SMA1000 appliances are under fire from a high-severity code injection flaw (CVE-2026-15410). Our latest TSUITE brief breaks down the CrowdStrike detection logic and immediate hardening steps to secure your management interfaces. Command the wire: https://thecybermind.co/jily
##updated 2026-07-16T05:16:16.603000
1 posts
(CISA TS-MAN) CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
Severity: HIGH Impact Summary: An attacker could purge all devices and set a BCU key to lock the device, potentially resulting in denial of service if additional security options are not enabled....
##updated 2026-07-15T18:32:50
1 posts
2 repos
(CISA TS-MAN) CVE-2026-46817 – Oracle E-Business Suite Improper Privilege Management Vulnerability
Severity: CRITICAL Impact Summary: Allows unauthenticated attacker to compromise Oracle Payments, potentially resulting in full takeover....
##updated 2026-07-14T21:32:52
1 posts
(CISA TS-MAN) CVE-2026-56155 – Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
Severity: HIGH Impact Summary: Allows an authorized attacker to locally elevate privileges due to insufficient granularity of access control....
##updated 2026-07-14T18:32:37
6 posts
8 repos
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/mwnickerson/certighost-bof
https://github.com/ChPratik/CVE-2026-54121
https://github.com/aniqfakhrul/CVE-2026-54121
Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.
#Certighost #CVE202654121 #ADCS #ActiveDirectory
https://securityonline.info/certighost-cve-2026-54121/?utm_source=mastodon&utm_medium=jetpack_social
##Certighost AD CS vulnerability details and PoC code for CVE-2026-54121 are public. The flaw let a low-privileged user impersonate a Domain Controller.
#Certighost #CVE202654121 #ADCS #ActiveDirectory
https://securityonline.info/certighost-cve-2026-54121/?utm_source=mastodon&utm_medium=jetpack_social
##Exploit público para a falha Certighost expôs domínios do Windows a controlo total. Uma nova vulnerabilidade, rastreada como CVE-2026-54121, coloca redes empresariais em risco e permite que um atacante assuma o controlo completo de um domínio informático. 🚨
##CertiGhost fork - Patched SAN handling + MAQ-safe account reuse https://github.com/marcgoam/CVE-2026-54121-CertiGhost
##Detect the Certighost with NetExec🔥
Thanks to Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patched and is potentially vulnerable to the Certighost vulnerability (CVE-2026-54121)🚀
https://thecybersecguru.com/news/certighost-cve-2026-54121-ad-cs-domain-controller-impersonation/
##updated 2026-07-14T18:32:33
3 posts
A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.
#CVE202650502 #WindowsEventLog #RCE #PatchTuesday #InfoSec #Microsoft
##A public PoC exploit now targets CVE-2026-50502, an RCE in the Windows Event Log service. Microsoft patched the flaw on July 14, 2026. Details below.
#CVE202650502 #WindowsEventLog #RCE #PatchTuesday #InfoSec #Microsoft
##Microsoft has patched a critical Windows Event Logging vulnerability (CVE-2026-50502) allowing remote code execution. Update your systems immediately.
#Microsoft #Vulnerability #CyberSecurity #WindowsServer #CVE202650502
##updated 2026-07-14T18:32:32
2 posts
CVE-2026-50469 - ProjFS File Delete https://bad-jubies.github.io/projected-file-system-file-delete-cve-2026-50469
##CVE-2026-50469 - ProjFS File Delete https://bad-jubies.github.io/projected-file-system-file-delete-cve-2026-50469
##updated 2026-07-14T15:32:45
2 posts
6 repos
https://github.com/materaj2/cve-2025-15467
https://github.com/balgan/CVE-2025-15467
https://github.com/WostGit/cve-2025-15467-crash
https://github.com/x-stp/cves-2025-11187_15467_69418
Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems
Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.
**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/siemens-patches-critical-openssl-flaw-in-desigo-cc-building-management-systems-t-n-v-d-a/gD2P6Ple2L
Siemens Patches Critical OpenSSL Flaw in Desigo CC Building Management Systems
Siemens released security updates for Desigo CC to address a critical OpenSSL vulnerability (CVE-2025-15467) that allows unauthenticated remote code execution or denial of service through malformed cryptographic messages.
**First, make sure all Desigo CC building management systems are isolated from the internet and reachable only from trusted networks. Then, if you run V9 update to V9.0 QU1 (or later) and if you run V8 apply patch V8.0 QU2.0021; for V7 there is no patch yet.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/siemens-patches-critical-openssl-flaw-in-desigo-cc-building-management-systems-t-n-v-d-a/gD2P6Ple2L
updated 2026-07-07T22:14:37
1 posts
1 repos
(CISA TS-MAN) CVE-2026-55255 – Langflow Authorization Bypass Through User-Controlled Key Vulnerability
Severity: HIGH Impact Summary: An authenticated attacker can execute any flow belonging to another user by specifying the victim's flow ID in the request, bypassing authorization controls....
##updated 2026-06-30T18:16:43.113000
3 posts
1 repos
⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data…
##Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)
#Cl0p #CVE_2026_12569
https://ransom-isac.org/blog/clop-windchill-flexplm-exploitation/
2026-W30 — Weekly Threat Roundup
🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…
updated 2026-06-30T03:37:45
2 posts
2 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-27T06:30:25
2 posts
42 repos
https://github.com/p3Nt3st3r-sTAr/CVE-2026-42945-POC
https://github.com/nu0l/NGINX-Rift
https://github.com/imSre9/CVE-2026-42945
https://github.com/quantumworld-dpdns-io/CVE-2026-42945
https://github.com/Renison-Gohel/CVE-2026-42945-NGINX-Rift
https://github.com/dinosn/cve-2026-42945-nginx32-lab
https://github.com/azilRababe/CVE-2026-42945
https://github.com/cipherspy/CVE-2026-42945-POC
https://github.com/edgecases-PurpleHax/cve-images
https://github.com/F2u0a0d3/CVE-2026-42945-nginx-rift-poc
https://github.com/yusufdalbudak/CVE-2026-42945
https://github.com/nanwinata/nginxrift-CVE-2026-42945
https://github.com/webdev75950-ux/nginx-rce-cve-2026-42945
https://github.com/chenqin231/CVE-2026-42945
https://github.com/hnytgl/CVE-2026-42945
https://github.com/realityone/cve-2026-42945-scan
https://github.com/soksofos/wazuh-nginx-cve-2026-42945-sca-lab
https://github.com/byezero/nginx-cve-2026-42945-check
https://github.com/lowilol/CVE-2026-42945-NGINX-Rift-Check-Script
https://github.com/iammerrida-source/nginx-rift-detect
https://github.com/sec-sys/CVE-2026-42945-Reverse-Shell-POC
https://github.com/hulina9900-boop/DIY-CVE-2026-42945-POC
https://github.com/BarAppTeam/nginx-cve-fix
https://github.com/0xBlackash/CVE-2026-42945
https://github.com/simota/nginx-rift-scanner
https://github.com/rheodev/CVE-2026-42945
https://github.com/RedCrazyGhost/CVE-2026-42945
https://github.com/fkj-src/fix_nginx_cve_2026_42945
https://github.com/gagaltotal/CVE-2026-42945-NGINX-Rift-Toolkit
https://github.com/oseasfr/Scanner_CVE_2026-42945
https://github.com/jelasin/CVE-2026-42945
https://github.com/ChamsBouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945
https://github.com/strivepan/Nginx_cve-2026-42945-scanner-gui
https://github.com/MateusVerass/nGixshell
https://github.com/limo57640-crypto/nginx-rift-detector
https://github.com/tal7aouy/nginx-cve-2026-42945
https://github.com/sibersan/web-server-audit_CVE-2026-42945
https://github.com/aratane/CVE-2026-42945
https://github.com/forxiucn/nginx-cve-2026-42945-poc
https://github.com/LiaoZiqi-GZFLS/CVE-2026-42945
You do not get to respawn. The debuff is applied to all servers simultaneously. Enjoy your stay.
Patch NGINX now to address CVE-2026-42945 before the PoC makes your threat landscape significantly more crowded.
Reward: You've received the Mandatory Participation Trophy — it's just a heap of broken memory.
#Nginx #RCE #CyberSecurity #ZeroDay #BufferOverflow #ExploitUnlocked (2/2)
##🏆 New Achievement! Heap Today, Gone Tomorrow!
Welcome, new player, to the NGINX Rift tutorial! This mandatory onboarding introduces CVE-2026-42945, a critical heap buffer overflow in NGINX that enables remote code execution. A proof-of-concept exploit has now been published publicly, which means this mechanic is fully unlocked for every participant — including the ones you did not invite.
Think of it like Minecraft's Hardcore Mode, except the world was already on fire when you loaded in. (1/2)
##updated 2026-06-17T18:36:29
1 posts
@drwhax also CVE-2026-0160 affecting RTT (US mandated). Reachability is via RTT call.
##updated 2026-06-17T18:36:28
1 posts
updated 2026-06-17T10:57:24.507000
2 posts
5 repos
https://github.com/lottiedeyan/CVE20264893poc
https://github.com/shinthink/CVE-2026-48939
https://github.com/Polosss/By-Poloss..-..CVE-2026-48939
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:20:26.697000
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:20:26.520000
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:16:12.407000
1 posts
1 repos
⚪️ Hackers Exploit a Zero-Day in Check Point SmartConsole
🗨️ Check Point has warned customers about a critical vulnerability, CVE-2026-16232, affecting its Security Management and Multi-Domain Management products. The flaw allows attackers to bypass authentication, gain administrator privileges, and modify security policies. The vulnerability is already be…
##updated 2026-06-17T10:00:40.683000
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T10:00:40.067000
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-06-17T09:56:44.753000
1 posts
2026-W30 — Weekly Threat Roundup
🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required.
🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da…
updated 2026-06-17T07:05:03.993000
1 posts
2 repos
https://github.com/webshellseo8/CVE-2024-1813-Proof-of-Concept
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
##updated 2026-06-17T06:48:06.467000
1 posts
3 repos
https://github.com/Trinadh465/platform_external_libvpx_v1.8.0_CVE-2023-5217
https://github.com/UT-Security/cve-2023-5217-poc
https://github.com/Trinadh465/platform_external_libvpx_v1.4.0_CVE-2023-5217
now to figure out if CVE-2023-5217 on our NAS actually matters...
##updated 2026-06-17T00:02:24.467000
2 posts
75 repos
https://github.com/proactiveRISK/heartbleed-extention
https://github.com/titanous/heartbleeder
https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC
https://github.com/Saymeis/HeartBleed
https://github.com/mozilla-services/Heartbleed
https://github.com/cbk914/heartbleed-checker
https://github.com/22imer/CVE-2014-0160
https://github.com/belmind/heartbleed
https://github.com/iwaffles/heartbleed-test.crx
https://github.com/rouze-d/heartbleed
https://github.com/victoriacfigueiredo/heartbleed-lab
https://github.com/0x90/CVE-2014-0160
https://github.com/isgroup/openmagic
https://github.com/xanas/heartbleed.py
https://github.com/hreese/heartbleed-dtls
https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed
https://github.com/cheese-hub/heartbleed
https://github.com/amerine/coronary
https://github.com/OffensivePython/HeartLeak
https://github.com/Ryo-Soikutsu/Heartbleed
https://github.com/fb1h2s/CVE-2014-0160
https://github.com/ice-security88/CVE-2014-0160
https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin
https://github.com/DisK0nn3cT/MaltegoHeartbleed
https://github.com/GuillermoEscobero/heartbleed
https://github.com/sammyfung/openssl-heartbleed-fix
https://github.com/cved-sources/cve-2014-0160
https://github.com/0xinf0/bleeding_onions
https://github.com/musalbas/heartbleed-masstest
https://github.com/DominikTo/bleed
https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
https://github.com/anthophilee/A2SV--SSL-VUL-Scan
https://github.com/undacmic/heartbleed-proof-of-concept
https://github.com/iSCInc/heartbleed
https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script
https://github.com/GeeksXtreme/ssl-heartbleed.nse
https://github.com/hmlio/vaas-cve-2014-0160
https://github.com/cyphar/heartthreader
https://github.com/yryz/heartbleed.js
https://github.com/tungduongNT/CVE-2014-0160.
https://github.com/vortextube/ssl_scanner
https://github.com/ingochris/heartpatch.us
https://github.com/indiw0rm/-Heartbleed-
https://github.com/ThanHuuTuan/Heartexploit
https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker
https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx
https://github.com/pblittle/aws-suture
https://github.com/PinkP4nther/Heartbleed_PoC
https://github.com/hybridus/heartbleedscanner
https://github.com/pierceoneill/bleeding-heart
https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin
https://github.com/takeshixx/ssl-heartbleed.nse
https://github.com/tomdevman/heartbleed-bug
https://github.com/siddolo/knockbleed
https://github.com/xlucas/heartbleed
https://github.com/obayesshelton/CVE-2014-0160-Scanner
https://github.com/a0726h77/heartbleed-test
https://github.com/Shayhha/HeartbleedAttack
https://github.com/Lekensteyn/pacemaker
https://github.com/FiloSottile/Heartbleed
https://github.com/timsonner/cve-2014-0160-heartbleed
https://github.com/0xBlackash/CVE-2014-0160
https://github.com/jdauphant/patch-openssl-CVE-2014-0160
https://github.com/GardeniaWhite/fuzzing
https://github.com/yashfren/CVE-2014-0160-HeartBleed
https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang
https://github.com/idkqh7/heatbleeding
https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration
https://github.com/mpgn/heartbleed-PoC
https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
https://github.com/zouguangxian/heartbleed
https://github.com/roganartu/heartbleedchecker-chrome
Shodan-Query of the day:
asn:"AS59399" vuln:"cve-2014-0160"
##Shodan-Query of the day:
asn:"AS59399" vuln:"cve-2014-0160"
##updated 2026-06-16T23:57:53.617000
1 posts
1 repos
RE: https://infosec.exchange/@BleepingComputer/116997530501171992
The firm that provided the story to BC is a new startup aiming to help "Manage and Secure Data Centers".
They exploited CVE-2013-4786
This is advertising a new startup by flogging a report by extremely lazy "researchers" (did they even do *any* "is this a honeypot" tests?)
Perhaps don't let your C-suite give Lava any business?
##updated 2026-06-16T22:50:50.330000
1 posts
Apple was much more verbose in describing security issues in 2008 (look at CVE-2008-1028)
https://support.apple.com/en-ie/102486
updated 2026-06-05T16:25:28
1 posts
1 repos
📈 CVE Published in last days (2026-07-20 - 2026-07-20)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 435
- High: 1048
- Medium: 813
- Low: 137
- None: 478
Status:
- : 96
- Analyzed: 307
- Awaiting Analysis: 697
- Deferred: 654
- Modified: 16
- Received: 482
- Rejected: 8
- Undergoing Analysis: 651
CISA KEVs:
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
Top CNAs:
- Oracle: 1108
- kernel.org: 334
- VulnCheck: 204
- GitHub, Inc.: 195
- Patchstack: 156
- N/A: 96
- Mozilla Corporation: 65
- Wordfence: 63
- MITRE: 55
- Joomla! Project: 53
Top Affected Products:
- UNKNOWN: 1745
- Oracle Coherence: 97
- Mozilla Firefox: 58
- Mozilla Thunderbird: 50
- Oracle Mysql Cluster: 38
- Oracle Mysql Server: 37
- Surrealdb: 31
- Oracle Weblogic Server: 23
- Nlnetlabs Unbound: 23
- Oracle Enterprise Manager Base Platform: 23
Top EPSS Score:
- CVE-2026-62144 - 20.62 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62144)
- CVE-2026-16232 - 12.68 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-62145 - 7.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-62145)
- CVE-2026-6516 - 4.73 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-6516)
- CVE-2026-47668 - 4.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-47668)
- CVE-2026-8985 - 4.19 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-8985)
- CVE-2026-64879 - 2.59 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-64879)
- CVE-2026-65711 - 2.41 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-65711)
- CVE-2026-63108 - 1.92 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63108)
- CVE-2026-63766 - 1.75 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63766)
updated 2026-05-15T18:30:32
2 posts
1 repos
A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.
#TA488 #OWAReaper #HalfClickExploit #CVE202642897 #OutlookWebAccess #InfoSec
##A TA488 half-click exploit abuses CVE-2026-42897 in Outlook Web Access to drop OWAReaper, a stealthy implant that survives device reimaging.
#TA488 #OWAReaper #HalfClickExploit #CVE202642897 #OutlookWebAccess #InfoSec
##updated 2026-05-12T15:31:14
2 posts
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2026-05-12T15:31:14
2 posts
1 repos
#OT #Advisory VDE-2026-081
Weidmueller: Security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities
Weidmueller security routers IE-SR-4TX and IE-SR-4GT are affected by multiple vulnerabilities (CVE-2026-14167, CVE-2026-14168, CVE-2026-14169, CVE-2026-14171, CVE-2026-2291, CVE-2026-4893, CVE-2026-5172, CVE-2026-40510, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796) in firmware releases prior to V2.3.0 authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware V2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-081/
#CSAF https://weidmueller.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-081.json
###OT #Advisory VDE-2026-076
ads-tec Industrial IT: Multiple Vulnerabilities in ADS-TEC IRF Products
The ADS-TEC IRF1000 and IRF3000 products are affected by multiple vulnerabilities in firmware releases prior to 2.3.0: authorization, robustness and redirect flaws in the proprietary configuration interface and web UI, and multiple vulnerabilities in the bundled third-party components dnsmasq, OpenSC and OpenSSL. All are fixed in firmware 2.3.0.
#CVE CVE-2026-14168, CVE-2026-14167, CVE-2026-14169, CVE-2025-69421, CVE-2025-69420, CVE-2025-69419, CVE-2026-5172, CVE-2026-2291, CVE-2026-14171, CVE-2026-22795, CVE-2026-22796, CVE-2026-4893, CVE-2025-68160, CVE-2025-69418, CVE-2026-40510
https://certvde.com/en/advisories/vde-2026-076/
#CSAF https://ads-tec-iit.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-076.json
##updated 2025-06-05T15:32:29
1 posts
By continuing to run Azure Automation with default settings, you hereby agree to the following terms: (1) your tenant identity may be made available to any registered Azure user who wishes to borrow it, (2) your credentials, cloud workloads, and data shall be considered shared resources, and (3) you waive all complaints regarding CVE-2025-29827, CVSS 9.9, which allowed any attacker with their own Azure Automation account to vault the trust boundary and impersonate another tenant entirely. (2/3)
####This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
####This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
Node.js patched 11 vulnerabilities in its July 2026 release. The high-severity bugs include a HTTP/2 use-after-free (CVE-2026-56848). Update now.
#NodeJS #CVE202656848 #HTTP2 #UseAfterFree #Vulnerability #InfoSec
####This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
##This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission:...
📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
🌐 cyber[.]netsecops[.]io
##Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.
#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec
https://meterpreter.org/vmware-vcenter-cve-2026-59309/?utm_source=mastodon&utm_medium=jetpack_social
##VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
##Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.
##Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.
#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec
https://meterpreter.org/vmware-vcenter-cve-2026-59309/?utm_source=mastodon&utm_medium=jetpack_social
##VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
##Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.
##📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
🌐 cyber[.]netsecops[.]io
##Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.
#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec
https://meterpreter.org/vmware-vcenter-cve-2026-59309/?utm_source=mastodon&utm_medium=jetpack_social
##Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.
##Broadcom patched a critical VMware vCenter vulnerability. CVE-2026-59309 and CVE-2026-59310 both score 9.8 CVSS and allow auth bypass or code execution.
#VMware #vCenter #CVE202659309 #CVE202659310 #ESXi #InfoSec
https://meterpreter.org/vmware-vcenter-cve-2026-59309/?utm_source=mastodon&utm_medium=jetpack_social
##Broadcom released updates to fix a critical VMware authentication bypass (CVE-2026-59309). A directory traversal flaw (CVE-2026-59310) was also patched.
##📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi
Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday
🌐 cyber[.]netsecops[.]io
##Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
##VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
##Three of the vulnerabilities have been assigned a ‘critical’ severity rating. One of them is CVE-2026-47876, an out-of-bounds write issue in ESXi’s VMXNET3 virtual network adapter. https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
##VMware ESXi, vCenter, Workstation, and Fusion patched for CRITICAL flaws: CVE-2026-47876 enables VM escape and host code execution; CVE-2026-59309/59310 impact vCenter auth & RCE. Patch ASAP — no exploitation reported. https://radar.offseq.com/threat/critical-vm-escape-vulnerability-patched-in-vmware-esxi-7c609b015974b352 #OffSeq #VMware #Vuln #PatchNow
##深刻度「緊急」のRails脆弱性「KindaRails2Shell」(CVE-2026-66066)の概要と対応指針 - GMO Flatt Security Blog
https://blog.flatt.tech/entry/kindarails2shell_rails
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
##This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX...
4 posts
2 repos
OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action
##⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…
##OpenWrt Vulnerability CVE-2026-53921 Demands Immediate Action
##⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent…
##Gitea Flaw Lets Writers Run Shell Commands via Git Hook
A newly discovered vulnerability in Gitea, rated 9.8 in severity, allows ordinary repository writers to execute shell commands as the Gitea service account by exploiting a remote code execution bug via a cleverly planted Git hook. This critical flaw, tracked as CVE-2026-60004, puts Gitea users at risk of a devastating attack.
#RemoteCodeExecution #Gitea #Cve202660004 #GitHook #SupplyChain
##NVIDIA BlueField has a critical VIRTIO-Net flaw, CVE-2026-65094, rated CVSS 9.0. A VM user could trigger code execution. Update to the fixed DOCA build.
#NVIDIA #BlueField #VIRTIONet #CVE202665094 #CodeExecution #CyberSecurity
##1 posts
70 repos
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/4minx/CVE-2026-63030
https://github.com/ikow/wp2shell
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/kulichr/wp2shell
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/gbrsh/CVE-2026-63030
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/shinthink/CVE-2026-63030
https://github.com/mverschu/CVE-2026-63030
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/yuag/wp2shell
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/dinosn/wp2shell-lab
https://github.com/zi3lak/wp2shell_scanner
https://github.com/ekomsSavior/wp2shell
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/Icex0/wp2shell-poc
https://github.com/bahartanir/wp2shell-scanner
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/Crypto-Cat/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/NULL200OK/WP2Shell
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/c0gnit00/Wp2Shell
https://github.com/fullhunt/wp2shell-scan
https://github.com/mhtsec/CVE-2026-63030
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mcipekci/wp2shell
https://github.com/vulnquest58/PressVector
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/47Cid/wp2shell-lab
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/0xWhoknows/wp2shell
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/securelayer7/WordPresShell
https://github.com/attackercan/wp2shell-poc2
https://github.com/Iqbalx7/wp2shell
https://github.com/0xjessie21/wp2shell-checker
https://github.com/InstaWP/wp2shell-scan
https://github.com/h4cd0c/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
##1 posts
1 repos
https://github.com/mgiay/CVE-2026-25589-25588-25243-23631-23479-REDIS
Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.
#Redis #Cybersecurity #RCE #Vulnerability #ExploitPoC
https://meterpreter.org/redis-rce-exploit-poc/?utm_source=mastodon&utm_medium=jetpack_social
##