24h | 7d | 30d

Overview

  • Advantech
  • IoTSuite and IoT Edge Products

12 Jan 2026
Published
12 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

KEV

Description

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture

🔴 CVE-2025-52694 - Critical (10)

Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Hewlett Packard Enterprise (HPE)
  • HPE OneView

16 Dec 2025
Published
08 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
81.31%

Description

A remote code execution issue exists in HPE OneView.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture
📌 CISA Adds Actively Exploited HPE OneView RCE Flaw (CVE-2025-37164) to KEV Catalog https://www.cyberhub.blog/article/17912-cisa-adds-actively-exploited-hpe-oneview-rce-flaw-cve-2025-37164-to-kev-catalog
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Apache Software Foundation
  • Apache Struts
  • com.opensymphony:xwork

11 Jan 2026
Published
11 Jan 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

Statistics

  • 1 Post

Last activity: 14 hours ago

Bluesky

Profile picture
SIOSセキュリティブログを更新しました。 Apache StrutsのXXE脆弱性(CVE-2025-68493) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #apache #struts security.sios.jp/vulnerabilit...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • AWS
  • Kiro IDE

09 Jan 2026
Published
09 Jan 2026
Updated

CVSS v4.0
HIGH (8.4)
EPSS
0.03%

KEV

Description

Processing specially crafted workspace folder names could allow for arbitrary command injection in the Kiro GitLab Merge-Request helper in Kiro IDE before version 0.6.18 when opening maliciously crafted workspaces. To mitigate, users should update to the latest version.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture
📢 CVE-2026-0830 : injection de commandes dans Kiro IDE (corrigé en 0.6.18) 📝 Selon un bulletin de sécurité AWS (Bulletin ID: 2026-001-AWS) publié le 9 janvier 20… https://cyberveille.ch/posts/2026-01-10-cve-2026-0830-injection-de-commandes-dans-kiro-ide-corrige-en-0-6-18/ #CVE_2026_0830 #Cyberveille
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • frappe
  • lms

12 Dec 2025
Published
18 Dec 2025
Updated

CVSS v4.0
MEDIUM (5.1)
EPSS
0.03%

KEV

Description

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Versions prior to 2.42.0 allow authenticated users to add malicious HTML and JavaScript through description fields in the Job, Course and Batch forms. This issue is fixed in version 2.42.0.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture
The CVE-2025-67730 Deep Dive: How Open-Source Initiatives Are Your Ultimate Cybersecurity Training Ground + Video Introduction: The intersection of open-source contribution and cybersecurity is where theoretical knowledge meets practical, hands-on warfare. As highlighted by security intern Dharan…
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • n8n-io
  • n8n

07 Jan 2026
Published
08 Jan 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.02%

KEV

Description

n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture
📢 CVE-2026-21858 : RCE non authentifiée critique dans n8n (maj 1.121.0 requise) 📝 Source : Cyera Research Labs (blog de recherche, 7 janvier 2026). https://cyberveille.ch/posts/2026-01-10-cve-2026-21858-rce-non-authentifiee-critique-dans-n8n-maj-1-121-0-requise/ #CVE_2026_21858 #Cyberveille
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • MongoDB Inc.
  • MongoDB Server

19 Dec 2025
Published
31 Dec 2025
Updated

CVSS v4.0
HIGH (8.7)
EPSS
69.62%

Description

Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2 versions prior to 8.2.3, MongoDB Server v6.0 versions prior to 6.0.27, MongoDB Server v5.0 versions prior to 5.0.32, MongoDB Server v4.4 versions prior to 4.4.30, MongoDB Server v4.2 versions greater than or equal to 4.2.0, MongoDB Server v4.0 versions greater than or equal to 4.0.0, and MongoDB Server v3.6 versions greater than or equal to 3.6.0.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture
The latest update for #Coralogix includes "A Milestone for Government #AI: Coralogix Begins FedRAMP Journey" and "MongoBleed (CVE-2025-14847): Critical Unauthenticated #MongoDB Memory Disclosure". #cybersecurity #monitoring #logging #devops https://opsmtrs.com/3JXoJPm
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Merit LILIN
  • P2

12 Jan 2026
Published
12 Jan 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
Pending

KEV

Description

Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture

🟠 CVE-2026-0855 - High (8.8)

Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

🔗 thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Veeam
  • Backup and Recovery

08 Jan 2026
Published
09 Jan 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
0.22%

KEV

Description

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture
Instagram fixed an issue allowing external parties to request password reset emails; Malwarebytes reported a 17.5M data claim; Veeam patched four high‑severity vulnerabilities including CVE-2025-59470.
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • aio-libs
  • aiohttp

05 Jan 2026
Published
06 Jan 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.05%

KEV

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture
URGENT: #openSUSE Tumbleweed advisory patches 8 CVEs in python311-aiohttp (CVE-2025-69223 to 69230). Read more: 👉 tinyurl.com/4usce7hw #Security
  • 0
  • 0
  • 0
  • 21h ago
Showing 11 to 20 of 25 CVEs