24h | 7d | 30d

Overview

  • SmarterTools
  • SmarterMail

29 Dec 2025
Published
27 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
77.81%

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: Last hour

Bluesky

Profile picture fallback
NEW OUTBREAK ALERT! An actively targeted vulnerability has been identified in SmarterTools SmarterMail, tracked as CVE-2025-52691. Learn more about this outbreak, including top targeted countries and industries; and recomended mitigation actions for affected users at: kootek.co.uk/outbreak-ale...
  • 0
  • 1
  • 0
  • Last hour

Overview

  • notepad-plus-plus
  • notepad-plus-plus

03 Feb 2026
Published
03 Feb 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
0.03%

KEV

Description

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges of the user.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
Supply Chain Attack: come è stato compromesso Notepad++ tramite il CVE-2025-15556 📌 Link all'articolo : www.redhotcyber.com/post/sup... #redhotcyber #news #sicurezzainformatica #cybersecurity #hacking #malware #supplychainattack #notepadplusplus
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Rapid7
  • Vulnerability Management

03 Feb 2026
Published
04 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
Pending

KEV

Description

Rapid7 InsightVM versions before 8.34.0 contain a signature verification issue on the Assertion Consumer Service (ACS) cloud endpoint that could allow an attacker to gain unauthorized access to InsightVM accounts setup via "Security Console" installations, resulting in full account takeover. The issue occurs due to the application processing these unsigned assertions and issuing session cookies that granted access to the targeted user accounts. This has been fixed in version 8.34.0 of InsightVM.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
🚨 Critical Rapid7 InsightVM vulnerability disclosed. CVE-2026-1568 allows attackers to bypass signature verification on the ACS endpoint, potentially enabling account takeover in affected setups. 🔗 basefortify.eu/cve_reports/... #cybersecurity #infosec #vulnerability #CVE #Rapid7 #InsightVM
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • risesoft-y9
  • Digital-Infrastructure

17 Jan 2026
Published
20 Jan 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.04%

KEV

Description

A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Our autonomous verification engine detected and validated a SQL Injection (CVE-2026-1050) in Digital-Infrastructure in versions <= 9.6.7.

Key Findings:
Vulnerability: SQL Injection (SQLi).
Endpoint: /server-platform/services/rest/auth/authenticate3
Root Cause: Lack of prepared statements in Y9PlatformUtil.
Impact: Attackers can manipulate database queries to access unauthorized tenant data or compromise the server.

The vulnerability was confirmed with Zero False Positives using an executable Proof of Concept (PoC). We recommend immediate remediation by implementing parameterized queries.

Vulnerability details: github.com/risesoft-y9/Digital

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • VibeThemes
  • WPLMS Learning Management System for WordPress, WordPress LMS

09 Nov 2024
Published
12 Nov 2024
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
49.00%

KEV

Description

The WPLMS Learning Management System for WordPress, WordPress LMS theme for WordPress is vulnerable to arbitrary file read and deletion due to insufficient file path validation and permissions checks in the readfile and unlink functions in all versions up to, and including, 4.962. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). The theme is vulnerable even when it is not activated.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
Security Analysts Warn of Shadow Directory Techniques Targeting WordPress #CVE202410470 #malwareinjection #SearchEngineCloaking
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Microsoft
  • Windows 10 Version 1809

11 Jul 2023
Published
21 Oct 2025
Updated

CVSS v3.1
HIGH (7.5)
EPSS
93.22%

Description

Windows Search Remote Code Execution Vulnerability

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
The Silent Heist: How Russian Hackers Weaponized Microsoft Office to Steal Ukraine War Secrets Without a Click + Video Introduction: A sophisticated Russian threat actor is exploiting a critical Microsoft Office vulnerability (CVE-2023-36884) to execute remote code execution (RCE) attacks. By…
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • GNU
  • Inetutils

21 Jan 2026
Published
29 Jan 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
29.55%

Description

telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
The Telnet Time Bomb: How a Single Command (CVE-2026-24061) Grants Root Access and How to Defuse It + Video Introduction: A recently disclosed critical vulnerability, CVE-2026-24061, has exposed the profound dangers of legacy protocols in modern networks. This flaw in GNU telnetd, a service that…
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • QOS.CH Sarl
  • Logback-core

22 Jan 2026
Published
22 Jan 2026
Updated

CVSS v4.0
LOW (1.8)
EPSS
0.01%

KEV

Description

ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
🚨 Attention System Admins & #DevOps Professionals! 🚨A new security update is critical for your #openSUSE Leap 15.6 servers. The logback library vulnerability (CVE-2026-1225) poses a moderate ACE (Arbitrary Code Execution) risk. Read more: 👉 tinyurl.com/yfwcbrsj #SUSE
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • pypa
  • wheel

22 Jan 2026
Published
27 Jan 2026
Updated

CVSS v3.1
HIGH (7.1)
EPSS
0.02%

KEV

Description

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

Statistics

  • 1 Post

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Just published a detailed analysis on the critical #openSUSE Leap 16.0 patch for CVE-2026-24049. This isn't just another bug fix. Read more: 👉 tinyurl.com/4b5ebsx6 #Security
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • GitLab
  • GitLab

13 Dec 2021
Published
03 Feb 2026
Updated

CVSS v3.1
MEDIUM (6.8)
EPSS
28.25%

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 17 hours ago

Fediverse

Profile picture fallback

‼️ CISA has added 4 vulnerabilities to the KEV Catalog

darkwebinformer.com/cisa-kev-c

CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

  • 1
  • 2
  • 0
  • 17h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities affecting Sangoma, GitLab, and SolarWinds to its KEV catalog. - IOCs: CVE-2025-40551, CVE-2021-39935, CVE-2025-64328 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 17h ago
Showing 11 to 20 of 26 CVEs