24h | 7d | 30d

Overview

  • SmarterTools
  • SmarterMail

29 Dec 2025
Published
09 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
10.87%

KEV

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Statistics

  • 3 Posts
  • 5 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture

watchTowr has published a technical analysis of a CVSS 10 pre-auth RCE vulnerability in SmartTool's SmarterMail business email platform.

The vulnerability (CVE-2025-52691) was silently patched in Oct and publicly disclosed only a few months later in Dec

labs.watchtowr.com/do-smart-pe

  • 3
  • 2
  • 1
  • 10h ago

Bluesky

Profile picture
๐Ÿ“Œ Critical Pre-Auth RCE Vulnerability in SmarterMail (CVE-2025-52691) Disclosed by watchTowr Labs https://www.cyberhub.blog/article/17899-critical-pre-auth-rce-vulnerability-in-smartermail-cve-2025-52691-disclosed-by-watchtowr-labs
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • parallax
  • jsPDF

05 Jan 2026
Published
06 Jan 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.08%

KEV

Description

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsanitized paths to the loadFile method, a user can retrieve file contents of arbitrary files in the local file system the node process is running in. The file contents are included verbatim in the generated PDFs. Other affected methods are `addImage`, `html`, and `addFont`. Only the node.js builds of the library are affected, namely the `dist/jspdf.node.js` and `dist/jspdf.node.min.js` files. The vulnerability has been fixed in jsPDF@4.0.0. This version restricts file system access per default. This semver-major update does not introduce other breaking changes. Some workarounds areavailable. With recent node versions, jsPDF recommends using the `--permission` flag in production. The feature was introduced experimentally in v20.0.0 and is stable since v22.13.0/v23.5.0/v24.0.0. For older node versions, sanitize user-provided paths before passing them to jsPDF.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 22 hours ago

Fediverse

Profile picture

โ—๏ธCVE-2025-68428: Critical Path Traversal in jsPDF

GitHub: github.com/12nio/CVE-2025-6842

CVSS: 9.2
CVE Published: January 5th, 2026
Exploit Published: January 8th, 2026

News source: bleepingcomputer.com/news/secu

  • 3
  • 1
  • 0
  • 22h ago

Overview

  • Airoha Technology Corp.
  • AB156x, AB157x, AB158x, AB159x series, AB1627

04 Aug 2025
Published
05 Aug 2025
Updated

CVSS
Pending
EPSS
0.04%

KEV

Description

In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 12 hours ago

Bluesky

Profile picture
Airoha Bluetooth RACE vulnerabilities (CVE-2025-20700/20701/20702) Blog post: insinuator.net/2025/12/blue... White paper: static.ernw.de/whitepaper/E... Credits Dennis Heinze, Frieder Steinmetz #infosec #bluetooth
  • 0
  • 2
  • 0
  • 12h ago

Overview

  • Meta
  • react-server-dom-webpack

03 Dec 2025
Published
11 Dec 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
53.46%

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 23 hours ago

Fediverse

Profile picture

โš ๏ธ If you are running Next.js, you need to see this.

The "React2Shell" vulnerability (CVE-2025-55182) is currently making waves, and for good reason. Unauthenticated RCE on default configurations is about as critical as it gets for modern web frameworks.

If you haven't audited your versions yet, do it now.

See the full technical breakdown: ๐Ÿ‘‰ cvedatabase.com/cve/CVE-2025-5

#AppSec #ReactJS #NextJS #CyberSecurity #RCE #DevOps

  • 0
  • 2
  • 0
  • 23h ago

Overview

  • Google
  • Chrome

06 Jan 2026
Published
08 Jan 2026
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Bluesky

Profile picture
๐Ÿšจ Attention #Fedora Users! A critical security update is available for your Chromium browser. Version 143.0.7499.192 patches a high-severity vulnerability (CVE-2026-0628) that could let malicious sites bypass security rules. Read more: ๐Ÿ‘‰ tinyurl.com/3xk6ta5d #Security
  • 0
  • 1
  • 0
  • 11h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture

I'm not exactly sure why I'm doing this on a Sunday, and the hard work was done by others, but there you go; proposed fix for CVE-2026-0716. gitlab.gnome.org/GNOME/libsoup

  • 0
  • 1
  • 0
  • 7h ago

Overview

  • Pending

14 Mar 2022
Published
07 Oct 2024
Updated

CVSS
Pending
EPSS
0.52%

KEV

Description

The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows efficient calculation of private RSA keys from the public key of a TLS certificate.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture

์š”์ฆ˜ ์Šค๋ ˆ๋“œ์— RSA-2048์„ ํ•ด๋…ํ–ˆ๋‹ค๋Š” ์–‘๋ฐ˜์ด ์žˆ์–ด์„œ ๊ธ€์„ ์ฒ˜์Œ๋ถ€ํ„ฐ ๋๊นŒ์ง€ ์ •๋…ํ–ˆ๋‹ค.

๊ทธ๋ฆฌ๊ณ  ์ฝ”๋“œ ์—†์ด ๊ฐœ๋…์ ์œผ๋กœ ๊ฐ€๋Šฅํ•œ์ง€ ๋”ฐ์ ธ๋ด„. ์ด ์‚ฌ๋žŒ์˜ ์ฃผ์žฅ์€ ๋„ˆ๋ฌด ์ค‘๊ตฌ๋‚œ๋ฐฉ์ด๋ผ ๊น”๋”ํ•˜๊ฒŒ ํ•œ์ค„๋กœ ์š”์•ฝํ•˜๋ฉด ์ด๋ ‡๋‹ค.

"d = | q - p | ์˜ d(๊ฑฐ๋ฆฌ)๊ฐ€ 0์— ์ˆ˜๋ ดํ• ์ˆ˜๋ก RSA๊ฐ€ ๊นจ์งˆ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์•„์ง„๋‹ค."

๊ทธ๋ฆฌ๊ณ  ์ด๊ฑด ์–ผ์ถ” ์‚ฌ์‹ค์€ ๋งž์Œ.

๊ฑฐ๋ฆฌ๊ฐ€ ๊ฐ€๊นŒ์›Œ์งˆ์ˆ˜๋ก Fermat's Factorization๋ฅผ ์ด์šฉํ•œ ๊ณต๊ฒฉ์ด ๊ฐ€๋Šฅํ•ด์ง€๊ณ , ์ด์™€ ๊ด€๋ จ๋œ ๊ณต์‹ ์ทจ์•ฝ์  CVE (์˜ˆ: CVE-2022-26320)๋„ ์กด์žฌํ•œ๋‹ค.

์ฐธ๊ณ ๋กœ ์–ด๋ ค์šด๊ฒŒ ์•„๋‹ˆ๋ผ ๊ณ ๋“ฑ๊ณผ์ • ๊ณฑ์…ˆ ๊ณต์‹ ์ค‘ ํ•˜๋‚˜๋‹ค.

RSA-2048์—์„œ๋Š” ์‚ฌ์‹ค์ƒ ๋ถˆ๊ฐ€๋Šฅํ•˜๊ณ , RSA-256 ์ˆ˜์ค€์—์„  ๊ฐ€๋Šฅํ•  ์ˆ˜ ์žˆ๋‹ค. (RSA-2048์€ ํŠน์ • ์กฐ๊ฑด ๋งŒ์กฑ์‹œ ๊ฐ€๋Šฅ)

RSA-2048์„ ํ’€์—ˆ๋‹ค๊ณ  ์ฃผ์žฅํ•˜์‹œ๋Š” ๋ถ„์ด ์˜ฌ๋ฆฐ ์ฝ”๋“œ๋ฅผ ๋ดค์„ ๋•Œ, ๊ทธ๋ƒฅ q๋ฅผ ์ €์žฅํ•ด๋†“๊ณ  n mod q ๋จน์—ฌ์„œ 0์ด ๋˜๋Š”์ง€ ํ™•์ธํ•˜๊ณ  p๋ฅผ ์œ ๋„ํ•˜๋Š” ๊ฒƒ์ž„.

๊ทธ๋ƒฅ ๋‹ต์ง€๊ฐ€์ง€๊ณ  ์žฅ๋‚œ์น˜๋Š”๊ฑฐ๋ผ ์ƒ๊ฐํ•˜๋ฉด ๋œ๋‹ค.

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • UTT
  • ่ฟ›ๅ– 520W

11 Jan 2026
Published
11 Jan 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.04%

KEV

Description

A security vulnerability has been detected in UTT ่ฟ›ๅ– 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture

๐ŸŸ  CVE-2026-0840 - High (8.8)

A security vulnerability has been detected in UTT ่ฟ›ๅ– 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argument timestart leads to buffer overflow. It i...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • UTT
  • ่ฟ›ๅ– 520W

11 Jan 2026
Published
11 Jan 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.04%

KEV

Description

A vulnerability was detected in UTT ่ฟ›ๅ– 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formPictureUrl. The manipulation of the argument importpictureurl results in buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture

๐ŸŸ  CVE-2026-0841 - High (8.8)

A vulnerability was detected in UTT ่ฟ›ๅ– 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formPictureUrl. The manipulation of the argument importpictureurl results in buffer overflow. It is possible to launch ...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • libsodium
  • libsodium

31 Dec 2025
Published
07 Jan 2026
Updated

CVSS v3.1
MEDIUM (4.5)
EPSS
0.02%

KEV

Description

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture
๐Ÿšจ CVE-2025-69277: Critical libsodium validation flaw impacts #Fedora42. Affects Ed25519 sig verification. Data integrity & disclosure risk. Read more: ๐Ÿ‘‰ tinyurl.com/3nypjx8s #Security
  • 0
  • 0
  • 0
  • 12h ago
Showing 1 to 10 of 22 CVEs