24h | 7d | 30d

Overview

  • Tenda
  • A21

21 Feb 2026
Published
23 Feb 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.08%

KEV

Description

A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 12 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-2870 - A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. T... https://www.cyberhub.blog/cves/CVE-2026-2870
  • 0
  • 1
  • 0
  • 12h ago

Overview

  • Agenta-AI
  • agenta

26 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.05%

KEV

Description

Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage β€” it only impacts self-hosted or managed Agenta platform deployments. Version 0.86.8 contains a fix for the issue.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-27961 - Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API ser... https://www.cyberhub.blog/cves/CVE-2026-27961
  • 0
  • 1
  • 0
  • 5h ago

Overview

  • discourse
  • discourse

26 Feb 2026
Published
27 Feb 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.03%

KEV

Description

Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty string as the key. Since the request body is known to the sender, the attacker can produce a matching signature and send arbitrary webhook payloads. This allows unauthorized creation, modification, or deletion of Patreon pledge data and triggering patron-to-group synchronization. This vulnerability is patched in versions 2025.12.2, 2026.1.1, and 2026.2.0. The fix rejects webhook requests when the webhook secret is not configured, preventing signature forgery with an empty key. As a workaround, configure the `patreon_webhook_secret` site setting with a strong, non-empty secret value. When the secret is non-empty, an attacker cannot forge valid signatures without knowing the secret.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-26078 - Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting i... https://www.cyberhub.blog/cves/CVE-2026-26078
  • 0
  • 1
  • 0
  • 3h ago

Overview

  • BeyondTrust
  • Remote Support(RS) & Privileged Remote Access(PRA)

06 Feb 2026
Published
26 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.9)
EPSS
60.92%

Description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
Exploitation of vulnerability (CVE-2026-1731) activity targeting the wholesale and retail sectors, according to research from Palo Alto Networks and Unit 42. rhisac.org/threat-in... #cybersecurity #retailsecurity
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Chargemap
  • chargemap.com

26 Feb 2026
Published
02 Mar 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.06%

KEV

Description

The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or misrouting legitimate charger telemetry, or conduct brute-force attacks to gain unauthorized access.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-20792 - The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow... https://www.cyberhub.blog/cves/CVE-2026-20792
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • ImageMagick
  • ImageMagick

24 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.2)
EPSS
0.05%

KEV

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write. This can crash the process or potentially lead to an out of bounds heap write. Version 7.1.2-15 contains a patch.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-25794 - ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmet... https://www.cyberhub.blog/cves/CVE-2026-25794
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • OneUptime
  • oneuptime

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.24%

KEV

Description

OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell metacharacters into a monitor's destination field. Version 10.0.7 fixes the vulnerability.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-27728 - OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMon... https://www.cyberhub.blog/cves/CVE-2026-27728
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Changing
  • IDExpert Windows Logon Agent

02 Mar 2026
Published
02 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.10%

KEV

Description

IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
🚨 CVE-2026-2999 – CRITICAL (9.3) Remote Code Execution in IDExpert Windows Logon Agent. Unauthenticated attackers can force systems to download and execute arbitrary EXE files from a remote source. Full report: basefortify.eu/cve_reports/... #CVE #RCE #WindowsSecurity #CyberSecurity #InfoSec
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • UnitreeRobotics
  • Unitree Go2

26 Feb 2026
Published
27 Feb 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.03%

KEV

Description

Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publish a crafted message (api_id=1002) containing arbitrary Python, which the robot writes to disk under /unitree/etc/programming/ and binds to a physical controller keybinding. When the keybinding is pressed, the code executes as root and the binding persists across reboots.

Statistics

  • 2 Posts

Last activity: 3 hours ago

Bluesky

Profile picture fallback
From DDS Packets to Robot Shells: Two RCEs in Unitree Robots (CVE-2026-27509 & CVE-2026-27510)
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
πŸ“’ Robots Unitree Go2 : deux failles RCE (CVE-2026-27509, CVE-2026-27510) via DDS et base Android πŸ“ Selon un billet technique publiΓ© par Oli… https://cyberveille.ch/posts/2026-03-02-robots-unitree-go2-deux-failles-rce-cve-2026-27509-cve-2026-27510-via-dds-et-base-android/ #CVE_2026_27509 #Cyberveille
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • e-Excellence
  • U-Office Force

02 Mar 2026
Published
02 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.40%

KEV

Description

U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

🚨 CRITICAL: CVE-2026-3422 in e-Excellence U-Office Force enables unauthenticated remote code execution via insecure deserialization (CWE-502). No patch β€” restrict access, monitor traffic, use WAF/RASP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago
Showing 11 to 20 of 71 CVEs