24h | 7d | 30d

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: Last hour

Bluesky

Profile picture fallback
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
  • 1
  • 1
  • 0
  • Last hour

Overview

  • Microsoft
  • .NET 10.0

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
0.72%

KEV

Description

Inconsistent interpretation of http requests ('http request/response smuggling') in .NET allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Bluesky

Profile picture fallback
🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-62899 impacts Microsoft.NETCore.App.Runtime.linux-x64 in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/660 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 1
  • 0
  • 0
  • 9h ago

Overview

  • Red Hat
  • Red Hat Advanced Cluster Management for Kubernetes 2
  • rhacm2/multicloud-integrations-rhel9

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 18 hours ago

Fediverse

Profile picture fallback

CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 18h ago

Overview

  • WordPress
  • WordPress

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v4.0
HIGH (8.9)
EPSS
0.77%

KEV

Description

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7. Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

** XSS2Shell: WordPress XSS Vulnerability Can Lead to Remote Code Execution **

Security researchers at Pwn.ai disclosed CVE-2026-64638, a pre-authentication XSS vulnerability...
→ XSS is a well-known, well documented, old coding error: Teach your TPMs and developers!

hissenit.com/en/blog/it-securi

#ciso #ceo #awareness #training #nis2 #dora #iso27001

  • 1
  • 0
  • 0
  • 1h ago

Overview

  • OpenLDAP Foundation
  • OpenLDAP

07 Jan 2026
Published
25 May 2026
Updated

CVSS v4.0
MEDIUM (4.6)
EPSS
0.13%

KEV

Description

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

As an example of how ridiculous the CVE ecosystem has become... researchers claimed a CVE this year against an LMDB commandline tool (not a server) for a bug fixed in 0.9.15, which was released 2015-06-19 - eleven years ago.

openeuler.org/zh/security/cve/

  • 0
  • 7
  • 0
  • 9h ago

Overview

  • Puwell Technology Inc.
  • IP Camera

04 Aug 2026
Published
05 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.58%

KEV

Description

Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. Attackers can exploit the lack of authentication and input sanitization in the binary protocol service to pass arbitrary commands directly to the underlying operating system, achieving root-level code execution and complete device compromise.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

PoC exploit code is public for CVE-2026-61515, an unauthenticated command injection in Puwell IP Camera firmware. CVSS 9.3. Details inside.

securityonline.info/puwell-ip-

  • 0
  • 1
  • 0
  • 9h ago

Overview

  • Quanovate Tech Inc. (operating as Mira / Mira Care)
  • Mira Firmware

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.28%

KEV

Description

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record information and account settings.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Fediverse

Profile picture fallback

Mira Firmware v1.7.1.47 has a CRITICAL auth bug (CVE-2026-68067): login accepts any valid-format password, exposing hormone records. No patch yet; restrict access & monitor accounts. radar.offseq.com/threat/cve-20

  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.32%

KEV

Description

Heap-based buffer overflow in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-62747 - Heap buffer overflow in Windows Device Association Service. Local privilege escalation. CVSS 7.8. Patch reported—update immediately. #CVE #Microsoft #infosec

valtersit.com/cve/CVE-2026-627

  • 0
  • 1
  • 0
  • 4h ago

Overview

  • electerm
  • electerm

11 Aug 2026
Published
11 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.31%

KEV

Description

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP server to write attacker-controlled content outside the selected download directory because recursive transfers in src/client/components/file-transfer/transfer.jsx pass server-supplied file.name and folder.name values to resolve without sanitization. This issue is fixed in version 3.15.120.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-73225 - Path traversal in electerm FTP/SFTP client. Malicious server writes files outside download dir. CVSS 8.1. Update to 3.15.120 now. #CVE #infosec #electerm

valtersit.com/cve/CVE-2026-732

  • 0
  • 1
  • 0
  • 10h ago

Overview

  • owen2345
  • CamaleonCMS

11 Aug 2026
Published
11 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.36%

KEV

Description

CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting params[:id] to their own user ID to pass the self-authorization check while simultaneously setting params[:user_id] to a victim's ID, causing the controller to load and mutate the victim's account, including overwriting administrator passwords to achieve full site takeover.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-56721 - Privilege escalation in CamaleonCMS ≤2.9.2 via IDOR. Authenticated low-priv users can overwrite any credentials. CVSS 8.8. Unpatched - update immediately. #CVE #CamaleonCMS #infosec

valtersit.com/cve/CVE-2026-567

  • 0
  • 1
  • 0
  • 9h ago
Showing 11 to 20 of 88 CVEs