24h | 7d | 30d

Overview

  • Mozilla
  • Firefox

09 Dec 2025
Published
11 Dec 2025
Updated

CVSS
Pending
EPSS
0.06%

KEV

Description

Use-after-free in the WebRTC: Signaling component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
🚨 Attention #openSUSE Tumbleweed Users & System Admins! 🚨 A new security update is live, patching vulnerability CVE-2025-14321 in the cockpit-machines package. Read more: 👉 tinyurl.com/325jehsn #Security
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
Exposed: How UDP Sockets Let Hackers Ghost Past GitHub’s Harden-Runner Undetected + Video Introduction: A critical security vulnerability, designated CVE-2026-25598, was recently disclosed in the popular `harden-runner` GitHub Action. This flaw allowed malicious code within a workflow to establish…
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Pending

04 Feb 2024
Published
03 Nov 2025
Updated

CVSS
Pending
EPSS
0.12%

KEV

Description

An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
Just published: A technical deep-dive into the critical libxml2 vulnerability (CVE-2024-25062) impacting #OpenSUSE and the broader Linux ecosystem. Read more: 👉 tinyurl.com/bdh26pfx #Security
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • djangorestframework

26 Jun 2024
Published
31 Dec 2024
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
16.27%

KEV

Description

Versions of the package djangorestframework before 3.15.2 are vulnerable to Cross-site Scripting (XSS) via the break_long_headers template filter due to improper input sanitization before splitting and joining with <br> tags.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
🚨 Urgent: CVE-2024-21520 patched for Django REST Framework on #openSUSE. Medium severity XSS vulnerability (CVSS 6.1) requires immediate patching. Read more: 👉 tinyurl.com/mppzum6v #Security
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • ISC
  • BIND 9

21 Jan 2026
Published
21 Jan 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.04%

KEV

Description

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Bluesky

Profile picture fallback
URGENT: #Fedora 42 BIND DNS security flaw (CVE-2025-13878) patched. DoS via corrupt BRID/HHIT records Read more: 👉 tinyurl.com/yhtadmte #Security
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
🚨 CRITICAL: #Fedora 42 bind-dyndb-ldap vulnerability (CVE-2025-13878) allows DNS privilege escalation via LDAP. If you're running BIND with directory service integration: Read more: 👉 tinyurl.com/2ewfr5pu #Security
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • SolarWinds
  • Web Help Desk

28 Jan 2026
Published
04 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
22.94%

Description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Exposed and Unpatched: How 170+ SolarWinds Help Desk Systems Invite Catastrophic RCE Attacks + Video Introduction: A critical remote code execution vulnerability in SolarWinds Web Help Desk, tracked as CVE-2025-40551, is actively being exploited, threatening unpatched IT service management systems…
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

15 Jan 2026
Published
30 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.6)
EPSS
0.06%

KEV

Description

A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode.

Statistics

  • 1 Post

Last activity: 12 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal (Severity: HIGH)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0227
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Pending

16 Mar 2023
Published
02 Aug 2024
Updated

CVSS
Pending
EPSS
0.11%

KEV

Description

Sudo before 1.9.13 does not escape control characters in log messages.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
🚨 #Debian 11 Admins: Patch Sudo NOW. CVE-2023-28486 in sudo is a sneaky "log obfuscation" vulnerability. Attackers can hide malicious commands in your logs, breaking audit trails & compliance. Read more: 👉 tinyurl.com/2h5ne8w5 #Security
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Google Cloud
  • Gemini Enterprise (formerly Agentspace)

06 Feb 2026
Published
06 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.1)
EPSS
0.04%

KEV

Description

The Agentspace service was affected by a vulnerability that exposed sensitive information due to the use of predictable Google Cloud Storage bucket names. These names were utilized for error logs and temporary staging during data imports from GCS and Cloud SQL. This predictability allowed an attacker to engage in "bucket squatting" by establishing these buckets before a victim's initial use. All versions after December 12th, 2025 have been updated to protect from this vulnerability. No user action is required for this.

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CRITICAL: CVE-2026-1727 in Google Cloud Gemini Enterprise exposes sensitive info via predictable GCS bucket names (bucket squatting risk). All versions prior to Dec 12, 2025 are vulnerable — ensure you're patched! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • VMware
  • VCF operations

29 Sep 2025
Published
04 Nov 2025
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.96%

Description

VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
Critical security advisory for #Fedora administrators: CVE-2025-41244 represents a local privilege escalation vulnerability in open-vm-tools with CISA Major Incident designation. Read more: 👉 tinyurl.com/bjtnhc9f #Security
  • 0
  • 0
  • 0
  • 3h ago
Showing 11 to 20 of 32 CVEs