24h | 7d | 30d

Overview

  • SAP_SE
  • SAP Commerce Cloud (Data Hub Adapter)

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.73%

KEV

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
securityaffairs.com/197244/sec
#cybersecurity #vulnerability #SAP

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

Συναγερμός για το SAP Commerce Cloud: μόλις τρεις ημέρες μετά τη διόρθωση, καταγράφηκαν προσπάθειες εκμετάλλευσης μιας αδυναμίας με τη μέγιστη βαθμολογία σοβαρότητας.

Το πιο ανησυχητικό; Δεν χρειάζεται λογαριασμός για να ξεκινήσει κάποιος.

Δεν έχει επιβεβαιωθεί επίθεση σε οργανισμό, αλλά οι διαχειριστές πρέπει να κινηθούν γρήγορα.

Δες τι πρέπει να κάνουν και ποιο προσωρινό μέτρ…

hacks.gr/sto-stochastro-chaker

#Cybersecurity #SAPCommerceCloud #CVE202658231 #RemoteCodeExecution #AuthenticationBypass

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch thehackernews.com/2026/08/sap-...
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
30 Jun 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.49%

KEV

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 2 Posts

Last activity: 17 hours ago

Bluesky

Profile picture fallback
> 注意喚起: NetScaler ADCおよびNetScaler Gatewayにおけるリモートコード実行につながる脆弱性(CVE-2026-8452)に関する注意喚起 (公開) https://www.jpcert.or.jp/at/2026/at260024.html
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) labs.watchtowr.com/youre-back-i...
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

11 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.86%

KEV

Description

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-62837 - Path traversal info disclosure in Microsoft Office SharePoint. CVSS 6.5. Patch under review. Monitor advisories and restrict access. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-628

  • 1
  • 2
  • 0
  • 19h ago

Overview

  • bestwebsoft
  • Profile Extra Fields by BestWebSoft
  • profile-extra-fields

13 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.21%

KEV

Description

Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2026-66456 - Stored XSS in BestWebSoft Profile Extra Fields ≤1.3.4. Subscriber-level attack. CVSS 6.5. Unpatched. Disable or restrict access now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-664

  • 0
  • 1
  • 0
  • 20h ago

Overview

  • KDE
  • Konsole

11 Jun 2025
Published
18 Jun 2025
Updated

CVSS v3.1
HIGH (8.2)
EPSS
0.58%

KEV

Description

KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. It supports loading URLs from the scheme handlers such as a ssh:// or telnet:// or rlogin:// URL. This can be executed regardless of whether the ssh, telnet, or rlogin binary is available. In this mode, there is a code path where if that binary is not available, Konsole falls back to using /bin/bash for the given arguments (i.e., the URL) provided. This allows an attacker to execute arbitrary code.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

‼️ CVE-2025-49091: Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.

GitHub PoC: github.com/thefreestyleresearc

  • 0
  • 1
  • 0
  • 13h ago

Overview

  • Gitea
  • Gitea Open Source Git Server

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.34%

KEV

Description

Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-58427 - Info disclosure via /members API leaks private org lists. Incomplete fix for PR #38145. CVSS 7.5. Update immediately. #CVE #infosec #privacy

valtersit.com/cve/CVE-2026-584

  • 0
  • 1
  • 0
  • 13h ago

Overview

  • Apple
  • macOS

06 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.50%

KEV

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

⚠️ Attackers are exploiting a macOS Screen Sharing flaw to install Monero miners.

CVE-2026-65400 is being abused on multiple Macs exposing port 5900 to the internet. Apple patched the flaw in emergency macOS updates.

What you need to know: thehackernews.com/2026/08/appl

  • 0
  • 1
  • 0
  • 19h ago

Overview

  • MongoDB
  • MongoDB Server

11 Aug 2026
Published
11 Aug 2026
Updated

CVSS v4.0
HIGH (7.1)
EPSS
0.21%

KEV

Description

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients without an appropriate authorization check on its embedded operations.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 17 hours ago

Fediverse

Profile picture fallback

CVE-2026-18704 - Privilege escalation in MongoDB. Authenticated read-only users can perform unauthorized writes via aggregation framework. CVSS 6.5. No patch available. Restrict access and monitor. #CVE #MongoDB #infosec

valtersit.com/cve/CVE-2026-187

  • 0
  • 1
  • 0
  • 17h ago

Overview

  • Go toolchain
  • cmd/go
  • cmd/go

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.25%

KEV

Description

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating GOPROXY and GOSUMDB to serve a client malicious module content that cannot be detected by evaluating the transparency log. In order to determine if you have been affected: rm -r go.sum go.work.sum vendor/ && go mod tidy

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-56864 - High severity Go module supply chain attack. Malicious GOSUMDB can serve unverified content bypassing transparency log. CVSS 7.5. Update Go toolchain and verify sums immediately. #CVE #GoLang #infosec

valtersit.com/cve/CVE-2026-568

  • 0
  • 1
  • 0
  • 14h ago

Overview

  • Microsoft
  • Microsoft 365 Apps for Enterprise

11 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.85%

KEV

Description

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-70328 - OOB read in Microsoft Excel. Info disclosure over network. CVSS 6.5. Patch under review - monitor updates closely. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-703

  • 0
  • 1
  • 0
  • 16h ago
Showing 1 to 10 of 31 CVEs