24h | 7d | 30d

Overview

  • IBM
  • Guardium Data Protection

18 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.63%

KEV

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of input during web page generation.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-84108: IBM Guardium Data Protection 12.2 RCE via improper input neutralization. CVSS 8.1, unpatched. Patch now. valtersit.com/cve/CVE-2026-841 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • OISF
  • suricata

18 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.63%

KEV

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing all prior contents to be processed again, producing quadratic CPU complexity, degraded packet processing, loss of monitoring visibility, or denial of service. This issue is fixed in version 8.0.6.

Statistics

  • 1 Post

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CVE-2026-71418: Suricata DoS, CVSS 7.5. DNS-over-HTTP/2 buffer flaw causes quadratic CPU use, degrading packet processing. Unpatched as of now - update immediately. valtersit.com/cve/CVE-2026-714 #CVE #Suricata #infosec

  • 0
  • 0
  • 0
  • 18h ago

Overview

  • OISF
  • suricata

18 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
LOW (3.7)
EPSS
0.38%

KEV

Description

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-63450 Suricata FTP parser: pre-negotiation RETR/STOR kills parsing for the TCP flow, letting later commands evade parser-dependent rules and logging. CVSS 3.7, unpatched. Update to 8.0.6 now. valtersit.com/cve/CVE-2026-634 #CVE #infosec #Suricata

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.61%

KEV

Description

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
vCenter pre-auth RCE: CVE-2026-59309/59310 - patch-diffing to RCE
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • IBM
  • Guardium Data Protection

18 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.31%

KEV

Description

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-84081: IBM Guardium 12.2 improper cert validation lets remote attackers bypass security. CVSS 8.1, unpatched. Audit your configs now. valtersit.com/cve/CVE-2026-840 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Cotonti
  • Cotonti

18 Sep 2026
Published
24 Sep 2026
Updated

CVSS v4.0
MEDIUM (5.1)
EPSS
0.27%

KEV

Description

Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-93871 Cotonti through 1.0.0 open redirect lets authenticated page editors store redirects to malicious hosts for phishing. CVSS 5.4, no patch yet. Restrict page permissions now. valtersit.com/cve/CVE-2026-938 #CVE #infosec #cybersecurity

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • FluidSynth
  • fluidsynth

18 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
MEDIUM (6.2)
EPSS
0.18%

KEV

Description

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction wrap to UINT_MAX, and the parser then attempts billions of SFMod allocations. This exhausts process memory and causes denial of service. No workaround is available. This issue is fixed in version 2.5.6.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-61720 FluidSynth SF2 parser DoS: zero-sized DMOD chunk wraps count to UINT_MAX, triggering billions of allocations and memory exhaustion. CVSS 6.2. Patched in 2.5.6, no workaround. Update now. valtersit.com/cve/CVE-2026-617 #CVE #infosec #FluidSynth

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • NetworkManager-l2tp

14 Sep 2026
Published
14 Sep 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.13%

KEV

Description

A flaw was found in NetworkManager-l2tp. The plugin writes attacker-controlled VPN connection properties (vpn.data and vpn.secrets values) unescaped into a generated ipsec.conf file that pluto loads as root. A local unprivileged user can create and activate their own L2TP VPN profile containing a newline-injected leftupdown directive; pluto executes that command as root when the IKE security association is established, resulting in local privilege escalation. This is the same bug class as CVE-2018-10900 (NetworkManager-vpnc).

Statistics

  • 1 Post

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2026-19624 NetworkManager-l2tp local privilege escalation: newline injection into ipsec.conf lets a local user run commands as root via pluto. CVSS 7.8. Patched. Update now. valtersit.com/cve/CVE-2026-196 #CVE #infosec #Linux

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • IBM
  • CICS TX Advanced

18 Sep 2026
Published
19 Sep 2026
Updated

CVSS v3.1
MEDIUM (4.8)
EPSS
0.18%

KEV

Description

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-11722: IBM WebSphere HTTP request smuggling, CVSS 4.8, patch status unknown. Update immediately. valtersit.com/cve/CVE-2026-117 #CVE #infosec #IBM

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Pending

16 Sep 2019
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
10.58%

KEV

Description

The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

Statistics

  • 1 Post

Last activity: 20 hours ago
Showing 11 to 20 of 35 CVEs