24h | 7d | 30d

Overview

  • OpenClaw
  • OpenClaw

01 Feb 2026
Published
03 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.04%

KEV

Description

OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Bluesky

Profile picture fallback
⚠️ OpenClaw – CVE-2026-25253 : un lien malveillant suffit à exécuter du code à distance en 1-clic Tous les détails par ici 👇 - www.it-connect.fr/openclaw-cve... #OpenClaw #Moltbot #IA #infosec #cybersecurite
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
The latest update for #Foresiet includes "CVE-2026-25253: OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link" and "CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Zero-Day Analysis". #cybersecurity #infosec https://opsmtrs.com/3J3CMGz
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Fortinet
  • FortiProxy

27 Jan 2026
Published
29 Jan 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
3.71%

Description

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.12, FortiProxy 7.2.0 through 7.2.15, FortiProxy 7.0.0 through 7.0.22, FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.

Statistics

  • 2 Posts

Last activity: 13 hours ago

Bluesky

Profile picture fallback
The latest update for #Foresiet includes "CVE-2026-25253: OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link" and "CVE-2026-24858: Fortinet Multiple Products Authentication Bypass Zero-Day Analysis". #cybersecurity #infosec https://opsmtrs.com/3J3CMGz
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 42 Interactions

Last activity: 3 hours ago

Bluesky

Profile picture fallback
🎉 Go 1.26 Release Candidate 3 is released! 🔒 Security: Includes an update for crypto/tls (CVE-2025-68121). 🏖 Run it in dev! Run it in prod! File bugs! go.dev/issue/new 📢 Announcement: groups.google.com/g/golang-ann... ⬇️ Download: go.dev/dl/#go1.26rc3 #golang
  • 3
  • 11
  • 0
  • 3h ago
Profile picture fallback
🎊 Go 1.25.7 and 1.24.13 are released! 🔏 Security: Includes a security fix for cmd/cgo (CVE-2025-61732) and an update for crypto/tls (CVE-2025-68121). 🔈 Announcement: https://groups.google.com/g/golang-announce/c/K09ubi9FQFk/m/oQiZUMk9AQAJ 📦 Download: https://go.dev/dl/#go1.25.7 #golang
  • 6
  • 22
  • 0
  • 9h ago

Overview

  • Kubernetes
  • ingress-nginx

03 Feb 2026
Published
04 Feb 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.04%

KEV

Description

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

Statistics

  • 5 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-24514: ingress-nginx Admission Controller denial of service - github.com/kubernetes/kubernet

  • 0
  • 0
  • 2
  • 5h ago

Bluesky

Profile picture fallback
🔴 CVE-2026-1580 and CVE-2026-24512 allow for config #injection via the "nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively. 🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests.
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
⏳ With EOL in March, Ingress #NGINX has 4 newly disclosed vulnerabilities: #CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, and CVE-2026-24514. We recommend that you migrate to F5's NGINX Ingress: buff.ly/vqTJvPK If you can’t migrate yet, update to v1.14.3. More details on each CVE below.
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • SmarterTools
  • SmarterMail

29 Dec 2025
Published
27 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
79.96%

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 12 hours ago

Bluesky

Profile picture fallback
NEW OUTBREAK ALERT! An actively targeted vulnerability has been identified in SmarterTools SmarterMail, tracked as CVE-2025-52691. Learn more about this outbreak, including top targeted countries and industries; and recomended mitigation actions for affected users at: kootek.co.uk/outbreak-ale...
  • 0
  • 1
  • 0
  • 12h ago

Overview

  • Wikimedia Foundation
  • MediaWiki - CSS extension

07 Jan 2026
Published
07 Jan 2026
Updated

CVSS
Pending
EPSS
0.06%

KEV

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows Path Traversal.This issue affects MediaWiki - CSS extension: 1.44, 1.43, 1.39.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 8 hours ago

Bluesky

Profile picture fallback
🚨New Security Vulnerability Disclosure: Path Traversal in MediaWiki Extension 'CSS' (CVE-2026-0669)🚨 I identified a path traversal vulnerability in the CSS extension to MediaWiki, which has since been patched. ⚠️Cause and Impact: Lack of proper URL validation allowed attackers to carry out path...
  • 0
  • 1
  • 0
  • 8h ago

Overview

  • notepad-plus-plus
  • notepad-plus-plus

03 Feb 2026
Published
03 Feb 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
0.03%

KEV

Description

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Supply Chain Attack: come è stato compromesso Notepad++ tramite il CVE-2025-15556 📌 Link all'articolo : www.redhotcyber.com/post/sup... #redhotcyber #news #sicurezzainformatica #cybersecurity #hacking #malware #supplychainattack #notepadplusplus
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Rapid7
  • Vulnerability Management

03 Feb 2026
Published
04 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.02%

KEV

Description

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
🚨 Critical Rapid7 InsightVM vulnerability disclosed. CVE-2026-1568 allows attackers to bypass signature verification on the ACS endpoint, potentially enabling account takeover in affected setups. 🔗 basefortify.eu/cve_reports/... #cybersecurity #infosec #vulnerability #CVE #Rapid7 #InsightVM
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • bootc

27 Jan 2026
Published
03 Feb 2026
Updated

CVSS
Pending
EPSS
0.04%

KEV

Description

A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
CRITICAL: #OpenSUSE glib2 update patches privilege escalation & memory corruption vulns (CVE-2026-1484). A must-patch for all admins. Read more: 👉 tinyurl.com/3cpdfnvz #Security
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
New security advisory deep dive. CVE-2026-1484 in glib2 #SUSE is a textbook case of why vulnerability management must extend to foundational dependencies. Read more: 👉 tinyurl.com/mwv66yj8 #Security
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Windows 10 Version 1809

11 Jul 2023
Published
21 Oct 2025
Updated

CVSS v3.1
HIGH (7.5)
EPSS
93.22%

Description

Windows Search Remote Code Execution Vulnerability

Statistics

  • 1 Post

Last activity: 14 hours ago

Bluesky

Profile picture fallback
The Silent Heist: How Russian Hackers Weaponized Microsoft Office to Steal Ukraine War Secrets Without a Click + Video Introduction: A sophisticated Russian threat actor is exploiting a critical Microsoft Office vulnerability (CVE-2023-36884) to execute remote code execution (RCE) attacks. By…
  • 0
  • 0
  • 0
  • 14h ago
Showing 11 to 20 of 30 CVEs