24h | 7d | 30d

Overview

  • Go standard library
  • crypto/tls
  • crypto/tls

29 Oct 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture
Just published a deep-dive analysis on the recent #Fedora 42 security advisory. It's not just one CVEβ€”it's a coordinated patch for six vulnerabilities in the Go-based Cloud SQL Proxy, headlined by CVE-2025-58189. Read more:πŸ‘‰ tinyurl.com/trwu97dt #Security
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

22 Dec 2025
Published
22 Dec 2025
Updated

CVSS
Pending
EPSS
8.84%

KEV

Description

A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the /h/rest endpoint to influence internal request dispatching, allowing inclusion of arbitrary files from the WebRoot directory.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture

CVE-2025-68645 - A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration

github.com/MaxMnMl/zimbramail-

  • 0
  • 0
  • 1
  • Last hour

Overview

  • kromitgmbh
  • titra

31 Dec 2025
Published
31 Dec 2025
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.20%

KEV

Description

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitization, it leads to a Remote Code Execution. Version 0.99.49 fixes the issue.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture

πŸ”΄ CVE-2025-69288 - Critical (9.1)

Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitizati...

πŸ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Go standard library
  • os/exec
  • os/exec

18 Sep 2025
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

If the PATH environment variable contains paths which are executables (rather than just directories), passing certain strings to LookPath ("", ".", and ".."), can result in the binaries listed in the PATH being unexpectedly returned.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture
Just published: An in-depth analysis of the critical #Fedora Delve debugger vulnerability (FEDORA-2025-3591ae9dd3 / CVE-2025-47906). Read more: πŸ‘‰ tinyurl.com/mvsr65na #Security
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Meta
  • react-server-dom-webpack

03 Dec 2025
Published
11 Dec 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
47.37%

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture
A nine-month campaign used React2Shell (CVE-2025-55182) and other N-day flaws to enroll IoT devices and web apps into the RondoDox botnet, deploying miners and Mirai variants.
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Bluesky

Profile picture
URGENT: #OpenSUSE users must patch #go-sendxmpp for CVE-2025-47911 & CVE-2025-58190. High-severity memory flaws = severe DoS risk. Read more: πŸ‘‰ tinyurl.com/2ttpnad4
  • 0
  • 1
  • 0
  • 21h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Bluesky

Profile picture
URGENT: #OpenSUSE users must patch #go-sendxmpp for CVE-2025-47911 & CVE-2025-58190. High-severity memory flaws = severe DoS risk. Read more: πŸ‘‰ tinyurl.com/2ttpnad4
  • 0
  • 1
  • 0
  • 21h ago

Overview

  • Go standard library
  • net/http
  • net/http

22 Sep 2025
Published
24 Sep 2025
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

When using http.CrossOriginProtection, the AddInsecureBypassPattern method can unexpectedly bypass more requests than intended. CrossOriginProtection then skips validation, but forwards the original request path, which may be served by a different handler without the intended security protections.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture
🚨 #Fedora 42 security alert: golang-github-projectdiscovery-mapcidr update patches 9 CVEs (CVE-2025-58058, CVE-2025-47910, etc.). Memory leaks, HTTP bypasses, and DoS flaws fixed. Critical for pentesters & cloud sec. Read more: πŸ‘‰ tinyurl.com/bdtxdu2n #Security
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • ulikunitz
  • xz

28 Aug 2025
Published
29 Aug 2025
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.08%

KEV

Description

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture
🚨 #Fedora 42 security alert: golang-github-projectdiscovery-mapcidr update patches 9 CVEs (CVE-2025-58058, CVE-2025-47910, etc.). Memory leaks, HTTP bypasses, and DoS flaws fixed. Critical for pentesters & cloud sec. Read more: πŸ‘‰ tinyurl.com/bdtxdu2n #Security
  • 0
  • 0
  • 0
  • 22h ago
Showing 11 to 19 of 19 CVEs