24h | 7d | 30d

Overview

  • eagerterrier
  • MimeTypes Link Icons

21 Mar 2026
Published
21 Mar 2026
Updated

CVSS v3.1
HIGH (8.3)
EPSS
Pending

KEV

Description

The MimeTypes Link Icons plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.2.20. This is due to the plugin making outbound HTTP requests to user-controlled URLs without proper validation when the "Show file size" option is enabled. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services via crafted links in post content.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

MimeTypes Link Icons plugin (≤3.2.20) hit by HIGH severity SSRF (CVE-2026-1313, CVSS 8.3). Contributor+ users can abuse "Show file size" to access internal resources. Disable the feature & check user roles. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Gainsight
  • Gainsight Assist

20 Mar 2026
Published
20 Mar 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
Pending

KEV

Description

An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callback URL.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 23 hours ago

Bluesky

Profile picture fallback
🚨 Rapid7 Labs recently identified a chain of security vulns in #Gainsight Assist, an email plugin for the popular Customer Success software. CVE-2026-31381 & CVE-2026-31382 are an info. disclosure flaw and a reflected XSS vulnerability, respectively: r-7.co/4uG8I93
  • 0
  • 1
  • 0
  • 23h ago

Overview

  • GNU
  • inetutils

27 Feb 2026
Published
07 Mar 2026
Updated

CVSS v3.1
HIGH (7.4)
EPSS
0.01%

KEV

Description

telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged local user to create a login.noauth file.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Bluesky

Profile picture fallback
inetutils: apply patches for CVE-2026-32746 and CVE-2026-28372 https://github.com/NixOS/nixpkgs/pull/500368 https://tracker.security.nixos.org/issues/NIXPKGS-2026-0492 https://tracker.security.nixos.org/issues/NIXPKGS-2026-0660 #security
  • 0
  • 1
  • 0
  • 3h ago

Overview

  • Gainsight
  • Gainsight Assist

20 Mar 2026
Published
20 Mar 2026
Updated

CVSS v3.1
MEDIUM (6.1)
EPSS
Pending

KEV

Description

The error_description parameter is vulnerable to Reflected XSS. An attacker can bypass the domain's WAF using a Safari-specific onpagereveal payload.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 23 hours ago

Bluesky

Profile picture fallback
🚨 Rapid7 Labs recently identified a chain of security vulns in #Gainsight Assist, an email plugin for the popular Customer Success software. CVE-2026-31381 & CVE-2026-31382 are an info. disclosure flaw and a reflected XSS vulnerability, respectively: r-7.co/4uG8I93
  • 0
  • 1
  • 0
  • 23h ago

Overview

  • Apple
  • Safari

29 Jul 2025
Published
20 Mar 2026
Updated

CVSS
Pending
EPSS
0.13%

Description

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, watchOS 11.6, visionOS 2.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6. Processing maliciously crafted web content may lead to memory corruption.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added five actively exploited vulnerabilities to the KEV catalog, affecting Apple, Craft CMS, and Laravel. - IOCs: CVE-2025-31277, CVE-2025-32432, CVE-2025-54068 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • livewire
  • livewire

17 Jul 2025
Published
21 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
15.97%

Description

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added five actively exploited vulnerabilities to the KEV catalog, affecting Apple, Craft CMS, and Laravel. - IOCs: CVE-2025-31277, CVE-2025-32432, CVE-2025-54068 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • craftcms
  • cms

25 Apr 2025
Published
21 Mar 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
79.02%

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added five actively exploited vulnerabilities to the KEV catalog, affecting Apple, Craft CMS, and Laravel. - IOCs: CVE-2025-31277, CVE-2025-32432, CVE-2025-54068 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Connect2id
  • Nimbus JOSE+JWT

11 Jul 2025
Published
23 Sep 2025
Updated

CVSS v3.1
MEDIUM (5.8)
EPSS
0.05%

KEV

Description

Connect2id Nimbus JOSE + JWT 10.0.x before 10.0.2 and 9.37.x before 9.37.4 allows a remote attacker to cause a denial of service via a deeply nested JSON object supplied in a JWT claim set, because of uncontrolled recursion. NOTE: this is independent of the Gson 2.11.0 issue because the Connect2id product could have checked the JSON object nesting depth, regardless of what limits (if any) were imposed by Gson.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
Dataproc Serverless update on March 18, 2026 https://docs.cloud.google.com/dataproc-serverless/docs/release-notes/#March_18_2026 #googlecloud Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Apache Software Foundation
  • Apache Avro Java SDK
  • org.apache.avro:avro

13 Feb 2026
Published
13 Feb 2026
Updated

CVSS
Pending
EPSS
0.06%

KEV

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are recommended to upgrade to version 1.12.1 or 1.11.5, which fix the issue.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
Dataproc Serverless update on March 18, 2026 https://docs.cloud.google.com/dataproc-serverless/docs/release-notes/#March_18_2026 #googlecloud Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • netty
  • netty

03 Sep 2025
Published
04 Sep 2025
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.06%

KEV

Description

Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In netty-codec-compression versions 4.1.124.Final and below, and netty-codec versions 4.2.4.Final and below, when supplied with specially crafted input, BrotliDecoder and certain other decompression decoders will allocate a large number of reachable byte buffers, which can lead to denial of service. BrotliDecoder.decompress has no limit in how often it calls pull, decompressing data 64K bytes at a time. The buffers are saved in the output list, and remain reachable until OOM is hit. This is fixed in versions 4.1.125.Final of netty-codec and 4.2.5.Final of netty-codec-compression.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
2.2.79-rocky9, 2.2.79-ubuntu22, 2.2.79-ubuntu22-arm 2.3.26-debian12, 2.3.26-ml-ubuntu22, 2.3.26-rocky9, 2.3.26-ubuntu22, 2.3.26-ubuntu22-arm Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042. Upgraded Dataproc Metastore Proxy to
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
Dataproc Serverless update on March 18, 2026 https://docs.cloud.google.com/dataproc-serverless/docs/release-notes/#March_18_2026 #googlecloud Fixed CVEs CVE-2025-58057, CVE-2025-53864, CVE-2025-68161, CVE-2025-48924, and CVE-2025-33042
  • 0
  • 0
  • 0
  • 2h ago
Showing 31 to 40 of 42 CVEs