24h | 7d | 30d

Overview

  • WatchGuard
  • Fireware OS

19 Dec 2025
Published
20 Dec 2025
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
31.40%

Description

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 when configured with a dynamic gateway peer.This vulnerability affects Fireware OS 11.10.2 up to and including 11.12.4_Update1, 12.0 up to and including 12.11.5 and 2025.1 up to and including 2025.1.3.

Statistics

  • 5 Posts
  • 6 Interactions

Last activity: 1 hour ago

Bluesky

Profile picture
Attention! We are scanning & reporting WatchGuard Firebox devices unpatched to CVE-2025-14733 (Out of Bounds Write Vulnerability, unauthenticated RCE, CVSS 9.8). Nearly 125 000 IPs found (2025-12-20): dashboard.shadowserver.org/statistics/c... WatchGuard Advisory: www.watchguard.com/wgrd-psirt/a...
  • 1
  • 3
  • 0
  • 1h ago
Profile picture
Most affected (most unpatched IPs): US (38.3K), Germany (14K), Italy (12.3K) CVE-2025-14733 World Map view: dashboard.shadowserver.org/statistics/c... CVE-2025-14733 Tracker: dashboard.shadowserver.org/statistics/c... #CyberCivilDefense
  • 0
  • 1
  • 0
  • 1h ago
Profile picture
We share daily IP data in our Vulnerable ISAKMP Report, tagged 'cve-2025-14733': www.shadowserver.org/what-we-do/n... CVE-2025-14733 is reported exploited in the wild & on US CISA KEV: www.cisa.gov/known-exploi... If you receive a report from us, check for signs of compromise as well
  • 0
  • 1
  • 0
  • 1h ago
Profile picture
📌 CISA Adds Critical WatchGuard Fireware OS Vulnerability (CVE-2025-14733) to KEV Catalog https://www.cyberhub.blog/article/17010-cisa-adds-critical-watchguard-fireware-os-vulnerability-cve-2025-14733-to-kev-catalog
  • 0
  • 0
  • 0
  • 15h ago
Profile picture
📌 Critical WatchGuard Fireware OS Vulnerability (CVE-2025-14733) Actively Exploited https://www.cyberhub.blog/article/17036-critical-watchguard-fireware-os-vulnerability-cve-2025-14733-actively-exploited
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Cisco
  • Cisco Secure Email

17 Dec 2025
Published
18 Dec 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
4.56%

Description

Cisco is aware of a potential vulnerability.  Cisco is currently investigating and will update these details as appropriate as more information becomes available.

Statistics

  • 2 Posts

Last activity: 8 hours ago

Bluesky

Profile picture
CVE-2025-20393: zero-day critico nei Cisco Secure Email Gateway 📌 Link all'articolo : www.redhotcyber.com/post/cve... #redhotcyber #news #cybersecurity #hacking #malware #ciscovulnerabile #sicurezzainformatica #vulnerabilita
  • 0
  • 0
  • 0
  • 11h ago
Profile picture
Actively Exploited Zero-Day (CVE-2025-20393) Targets Cisco Email Security Appliances #patchmanagement
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • uriparser project
  • uriparser

14 Dec 2025
Published
15 Dec 2025
Updated

CVSS v3.1
LOW (2.9)
EPSS
0.02%

KEV

Description

uriparser through 0.9.9 allows unbounded recursion and stack consumption, as demonstrated by ParseMustBeSegmentNzNc with large input containing many commas.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Bluesky

Profile picture
🚨 #Fedora 42 users: Patch CVE-2025-67899 NOW! Critical uriparser update fixes an unbounded recursion DoS vulnerability. Don't leave your systems exposed. Read more: 👉 tinyurl.com/3k6fkdkx #Security
  • 1
  • 0
  • 0
  • 9h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • util-linux

05 Dec 2025
Published
15 Dec 2025
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the `setpwnam()` function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Bluesky

Profile picture
CRITICAL: CVE-2025-14104 for #Fedora 42. Heap buffer overflow in util-linux's setpwnam(). Local privilege escalation risk. Read more: 👉 tinyurl.com/yk34b9n5 #Security
  • 1
  • 0
  • 0
  • 10h ago

Overview

  • Apple
  • iOS and iPadOS

17 Dec 2025
Published
19 Dec 2025
Updated

CVSS
Pending
EPSS
0.07%

KEV

Description

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, visionOS 26.2. Processing maliciously crafted web content may lead to an unexpected process crash.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture
New deep-dive analysis for the #Mageia community. The MGASA-2025-0331 advisory patches critical memory safety bugs in webkit2 (CVE-2025-43501, etc.). Read more: 👉 tinyurl.com/49w5m829 #Security
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Google
  • Chrome

16 Dec 2025
Published
18 Dec 2025
Updated

CVSS
Pending
EPSS
0.13%

KEV

Description

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture
#Debian Security Advisory DSA-6089-1: Patch Chromium NOW. Critical RCE vulnerabilities (CVE-2025-14765/14766) patched in versions 143.0.7499.169-1~deb12u1 (Bookworm) and ~deb13u1 (Trixie). Read more: 👉 tinyurl.com/2t43rzwe #Security
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture
oss-sec: [CVE-2025-14282] dropbear: privilege escalation via unix domain socket forwardings
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture
URGENT: #Mageia 9 security advisory MGASA-2025-0330 patches high-severity PHP flaws (CVE-2025-14177/78/80). Read more: 👉 tinyurl.com/yukwzjf8 #Security
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture
FreeBSD Network Alert: Malicious IPv6 Packets Can Trigger Remote Code Execution via resolvconf (CVE-2025-14558)
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Apache Software Foundation
  • Apache Commons Text

13 Oct 2022
Published
20 Nov 2024
Updated

CVSS
Pending
EPSS
97.16%

KEV

Description

Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture
📌 Critical RCE Vulnerability in Apache Commons Text (CVE-2022-42889) Affects Versions 1.5 to 1.9 https://www.cyberhub.blog/article/17018-critical-rce-vulnerability-in-apache-commons-text-cve-2022-42889-affects-versions-15-to-19
  • 0
  • 0
  • 0
  • 11h ago
Showing 1 to 10 of 12 CVEs