24h | 7d | 30d

Overview

  • Kubernetes
  • ingress-nginx

09 Mar 2026
Published
09 Mar 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
Pending

KEV

Description

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

[Security Advisory] CVE-2026-3288: ingress-nginx rewrite-target nginx configuration injection #devopsish groups.google.com/a/kubernetes

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Tenda
  • FH451

07 Mar 2026
Published
07 Mar 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.05%

KEV

Description

A vulnerability was determined in Tenda FH451 1.0.0.9. Affected is the function sub_3C434 of the file /goform/AdvSetWan. This manipulation of the argument wanmode/PPPOEPassword causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
๐Ÿ“Œ CVE-2026-3678 - A vulnerability was determined in Tenda FH451 1.0.0.9. Affected is the function sub_3C434 of the file /goform/AdvSetWan. This manipulation of the argu... https://www.cyberhub.blog/cves/CVE-2026-3678
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • SICK AG
  • SICK Lector85x

06 Mar 2026
Published
09 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.17%

KEV

Description

An attacker may perform unauthenticated read and write operations on sensitive filesystem areas via the AppEngine Fileaccess over HTTP due to improper access restrictions. A critical filesystem directory was unintentionally exposed through the HTTP-based file access feature, allowing access without authentication. This includes device parameter files, enabling an attacker to read and modify application settings, including customer-defined passwords. Additionally, exposure of the custom application directory may allow execution of arbitrary Lua code within the sandboxed AppEngine environment.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
CVE-2026-2331 - CVE-2026-2331 scq.ms/3PkZi2z
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Pending

18 Dec 2023
Published
14 May 2025
Updated

CVSS
Pending
EPSS
75.23%

KEV

Description

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
Paloaltoใฎ่„†ๅผฑๆ€งๆƒ…ๅ ฑ ใ€ŒCVE-2023-48795 Impact of Terrapin SSH Attack (Severity: MEDIUM)ใ€ใŒๅ…ฌ้–‹ใ•ใ‚Œใพใ—ใŸใ€‚ โ†’ https://security.paloaltonetworks.com/CVE-2023-48795
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Tenda
  • i3

09 Mar 2026
Published
09 Mar 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.09%

KEV

Description

A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of the file /goform/setAutoPing. Performing a manipulation of the argument ping1/ping2 results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture fallback
๐Ÿ“Œ CVE-2026-3801 - A vulnerability was found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formSetAutoPing of the file /goform/setAutoPing. P... https://www.cyberhub.blog/cves/CVE-2026-3801
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Tenda
  • F453

08 Mar 2026
Published
08 Mar 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.05%

KEV

Description

A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipulation of the argument GO results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
๐Ÿ“Œ CVE-2026-3769 - A vulnerability was detected in Tenda F453 1.0.0.3. Affected by this issue is the function WrlclientSet of the file /goform/WrlclientSet. The manipula... https://www.cyberhub.blog/cves/CVE-2026-3769
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • chamilo
  • chamilo-lms

06 Mar 2026
Published
09 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.04%

KEV

Description

Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious JavaScript into the course description field, an attacker with a low-privileged account (e.g., trainer) can execute arbitrary JavaScript code in the context of any other user viewing the course information page, including administrators. This allows an attacker to exfiltrate sensitive session cookies or tokens, resulting in account takeover (ATO) of higher-privileged users. This issue has been patched in version 1.11.34.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
๐Ÿ“Œ CVE-2025-59543 - Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerability. By injecting malicious ... https://www.cyberhub.blog/cves/CVE-2025-59543
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • SAP_SE
  • SAP NetWeaver Enterprise Portal Administration

10 Mar 2026
Published
10 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture fallback

๐Ÿšจ CRITICAL: CVE-2026-27685 in SAP NetWeaver EP-RUNTIME 7.50 (Admin) enables privileged users to upload malicious serialized data โ€” risking full system compromise. Restrict uploads, monitor privileged actions, patch ASAP! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Copeland
  • Copeland XWEB 300D PRO

27 Feb 2026
Published
02 Mar 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
0.31%

KEV

Description

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
๐Ÿ“Œ CVE-2026-25111 - An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code executi... https://www.cyberhub.blog/cves/CVE-2026-25111
  • 0
  • 0
  • 0
  • Last hour

Overview

  • chamilo
  • chamilo-lms

06 Mar 2026
Published
06 Mar 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.02%

KEV

Description

Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete projects inside a course without the victimโ€™s consent. The issue arises because sensitive actions such as project deletion do not implement anti-CSRF protections (tokens) and GET based requests. As a result, an authenticated user (Trainer) can be tricked into executing this unwanted action by simply visiting a malicious page. This issue has been patched in version 1.11.34.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
๐Ÿ“Œ CVE-2025-59541 - Chamilo is a learning management system. Prior to version 1.11.34, a Cross-Site Request Forgery (CSRF) vulnerability allows an attacker to delete proj... https://www.cyberhub.blog/cves/CVE-2025-59541
  • 0
  • 0
  • 0
  • 1h ago
Showing 31 to 40 of 87 CVEs