24h | 7d | 30d

Overview

  • pypa
  • wheel

22 Jan 2026
Published
27 Jan 2026
Updated

CVSS v3.1
HIGH (7.1)
EPSS
0.02%

KEV

Description

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
Just published a detailed analysis on the critical #openSUSE Leap 16.0 patch for CVE-2026-24049. This isn't just another bug fix. Read more: 👉 tinyurl.com/4b5ebsx6 #Security
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 15 Interactions

Last activity: 1 hour ago

Bluesky

Profile picture fallback
🎊 Go 1.25.7 and 1.24.13 are released! 🔏 Security: Includes a security fix for cmd/cgo (CVE-2025-61732) and an update for crypto/tls (CVE-2025-68121). 🔈 Announcement: https://groups.google.com/g/golang-announce/c/K09ubi9FQFk/m/oQiZUMk9AQAJ 📦 Download: https://go.dev/dl/#go1.25.7 #golang
  • 2
  • 13
  • 0
  • 1h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 15 Interactions

Last activity: 1 hour ago

Bluesky

Profile picture fallback
🎊 Go 1.25.7 and 1.24.13 are released! 🔏 Security: Includes a security fix for cmd/cgo (CVE-2025-61732) and an update for crypto/tls (CVE-2025-68121). 🔈 Announcement: https://groups.google.com/g/golang-announce/c/K09ubi9FQFk/m/oQiZUMk9AQAJ 📦 Download: https://go.dev/dl/#go1.25.7 #golang
  • 2
  • 13
  • 0
  • 1h ago

Overview

  • GitLab
  • GitLab

13 Dec 2021
Published
03 Feb 2026
Updated

CVSS v3.1
MEDIUM (6.8)
EPSS
80.80%

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. Unauthorized external users could perform Server Side Requests via the CI Lint API

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 21 hours ago

Fediverse

Profile picture fallback

‼️ CISA has added 4 vulnerabilities to the KEV Catalog

darkwebinformer.com/cisa-kev-c

CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

  • 1
  • 2
  • 0
  • 22h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities affecting Sangoma, GitLab, and SolarWinds to its KEV catalog. - IOCs: CVE-2025-40551, CVE-2021-39935, CVE-2025-64328 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • FreePBX
  • security-reporting

07 Nov 2025
Published
03 Feb 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
11.03%

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 21 hours ago

Fediverse

Profile picture fallback

‼️ CISA has added 4 vulnerabilities to the KEV Catalog

darkwebinformer.com/cisa-kev-c

CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

  • 1
  • 2
  • 0
  • 22h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added four actively exploited vulnerabilities affecting Sangoma, GitLab, and SolarWinds to its KEV catalog. - IOCs: CVE-2025-40551, CVE-2021-39935, CVE-2025-64328 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Pending

21 Nov 2019
Published
03 Feb 2026
Updated

CVSS
Pending
EPSS
31.70%

Description

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 22 hours ago

Fediverse

Profile picture fallback

‼️ CISA has added 4 vulnerabilities to the KEV Catalog

darkwebinformer.com/cisa-kev-c

CVE-2025-40551: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVE-2019-19006: Sangoma FreePBX Improper Authentication Vulnerability

CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability

CVE-2021-39935: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

  • 1
  • 2
  • 0
  • 22h ago
Showing 21 to 26 of 26 CVEs