24h | 7d | 30d

Overview

  • cryptomator
  • cryptomator

20 Mar 2026
Published
27 Mar 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.02%

KEV

Description

Cryptomator encrypts data being stored on cloud infrastructure. Prior to version 1.19.1, the Hub-based unlock flow explicitly supports hub+http and consumes Hub endpoints from vault metadata without enforcing HTTPS. As a result, a vault configuration can drive OAuth and key-loading traffic over plaintext HTTP or other insecure endpoint combinations. An active network attacker can tamper with or observe this traffic. Even when the vault key is encrypted for the device, bearer tokens and endpoint-level trust decisions are still exposed to downgrade and interception. This issue has been patched in version 1.19.1.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Bluesky

Profile picture fallback
春休みなので脆弱性報告したらCVEついた話 (CVE-2026-32309) https://zenn.dev/ao9s/articles/cryptomator-hub-http-downgrade
  • 0
  • 1
  • 0
  • 4h ago

Overview

  • simple-git

25 Apr 2026
Published
25 Apr 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.08%

KEV

Description

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the equivalent --config form. If untrusted input can reach the options argument passed to simple-git, an attacker may still achieve remote code execution by enabling protocol.ext.allow=always and using an ext:: clone source.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 15 hours ago

Fediverse

Profile picture fallback

simple-git (the Node.js git wrapper sitting inside half of npm build pipelines) disclosed CVE-2026-6951 on April 25. Severity 9.8. It lets an attacker run any command on the build server. The new patch finishes a 2022 patch that blocked the "-c" flag and forgot "--config" was the same option. Snyk pulled telemetry: 73% of 9M weekly installs were on the broken patch at disclosure.

#OpenSource #CyberSecurity #SupplyChain

  • 0
  • 1
  • 0
  • 15h ago

Overview

  • Spring
  • Spring Boot

27 Apr 2026
Published
27 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
Spring Boot、重大な脆弱性(CVE-2026-40976)を修正-特定条件で全エンドポイントが未認証アクセス可能に rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Tenda
  • F456

27 Apr 2026
Published
27 Apr 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.05%

KEV

Description

A security vulnerability has been detected in Tenda F456 1.0.0.5. This impacts the function fromPPTPUserSetting of the file /goform/PPTPUserSetting of the component httpd. Such manipulation of the argument delno leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

⚠️ HIGH severity: Tenda F456 (v1.0.0.5) buffer overflow in httpd's fromPPTPUserSetting (CVE-2026-7080) enables remote code execution or DoS. No patch yet — restrict device exposure & monitor for updates. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Totolink
  • A8000RU

28 Apr 2026
Published
28 Apr 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

🚨 CRITICAL: Totolink A8000RU routers (7.1cu.643_b20200521) vulnerable to remote, unauthenticated OS command injection (CVE-2026-7204). No patch yet. Restrict access & monitor vendor channels. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 1
  • 2h ago

Overview

  • PowerDNS
  • Authoritative
  • pdns

22 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.01%

KEV

Description

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
PowerDNS Authoritative Serverの脆弱性情報が公開されました (CVE-2026-33257、他5件) https://jprs.jp/tech/security/2026-04-27-powerdns-auth.html
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • PowerDNS
  • Recursor
  • pdns-recursor

22 Apr 2026
Published
22 Apr 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.00%

KEV

Description

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-33256、他8件) https://jprs.jp/tech/security/2026-04-27-powerdns-recursor.html
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Apache Software Foundation
  • Apache Camel
  • org.apache.camel:camel-infinispan

27 Apr 2026
Published
28 Apr 2026
Updated

CVSS
Pending
EPSS
0.08%

KEV

Description

The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache used by a Camel application can inject a crafted serialized Java object that, when read during normal aggregation repository operations such as get or recover, results in arbitrary code execution in the context of the application. This issue affects Apache Camel: from 4.0.0 before 4.14.7, from 4.15.0 before 4.18.2, from 4.19.0 before 4.20.0. Users are recommended to upgrade to version 4.20.0, which fixes the issue. If users are on the 4.14.x LTS releases stream, then they are suggested to upgrade to 4.14.7. If users are on the 4.18.x releases stream, then they are suggested to upgrade to 4.18.2. The JIRA ticket: https://issues.apache.org/jira/browse/CAMEL-23322 refers to the various commits that resolved the issue, and have more details. This issue follows the same class of vulnerability previously addressed in CVE-2024-22369, CVE-2024-23114 and CVE-2026-25747.

Statistics

  • 1 Post

Last activity: 17 hours ago

Fediverse

Profile picture fallback

🔴 CRITICAL: CVE-2026-40858 in Apache Camel's camel-infinispan lets attackers with cache write access trigger arbitrary code execution. Patch to 4.20.0/4.14.7/4.18.2 ASAP! More info: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 17h ago

Overview

  • cloudways
  • Breeze Cache

23 Apr 2026
Published
23 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.06%

KEV

Description

The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote' function in all versions up to, and including, 2.4.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. The vulnerability can only be exploited if "Host Files Locally - Gravatars" is enabled, which is disabled by default.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) https://securityaffairs.com/191267/uncategorized/over-400000-sites-at-risk-as-hackers-exploit-breeze-cache-plugin-flaw-cve-2026-3844.html
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Pending

05 Jul 2024
Published
04 Nov 2025
Updated

CVSS
Pending
EPSS
0.18%

KEV

Description

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
This bash script fixes OpenStack Glance CVE-2024-32498. This book fixes ALL the CVEs you've never seen. tinyurl.com/5yxr9fn7 #ubuntu #Security
  • 0
  • 0
  • 0
  • 9h ago
Showing 11 to 20 of 132 CVEs