24h | 7d | 30d

Overview

  • Meta
  • react-server-dom-webpack

03 Dec 2025
Published
11 Dec 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
60.90%

Description

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
📌 Critical Vulnerability React2Shell (CVE-2025-55182) Allows Unauthenticated Remote Code Execution https://www.cyberhub.blog/article/19399-critical-vulnerability-react2shell-cve-2025-55182-allows-unauthenticated-remote-code-execution
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • karutoil
  • catalyst

10 Feb 2026
Published
10 Feb 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
Pending

KEV

Description

Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating system as root via bash -c, with no sandboxing or containerization. Any user with template.create or template.update permission can define arbitrary shell commands that achieve full root-level remote code execution on every node machine in the cluster. This vulnerability is fixed in commit 11980aaf3f46315b02777f325ba02c56b110165d.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

🚨 karutoil catalyst (<11980aaf3f46315b02777f325ba02c56b110165d) faces CRITICAL OS command injection (CVE-2026-26009, CVSS 10.0). Users with template perms can execute root shell commands cluster-wide. Patch immediately! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Fortinet
  • FortiSandbox

10 Feb 2026
Published
11 Feb 2026
Updated

CVSS v3.1
HIGH (7.9)
EPSS
Pending

KEV

Description

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated attacker to execute commands via crafted requests.

Statistics

  • 1 Post

Last activity: 18 hours ago

Fediverse

Profile picture fallback

RE: infosec.exchange/@ozu/11604108

Another another vuln. CVE-2025-52436

  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Microsoft
  • Windows Server 2022

13 Jan 2026
Published
30 Jan 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.06%

KEV

Description

Improper handling of insufficient permissions or privileges in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
CVE-2026-20817: The Hidden Windows Error Reporting Flaw That Grants Attackers Admin Keys + Video Introduction: A critical local privilege escalation (LPE) vulnerability has been discovered in the Windows Error Reporting (WER) service, a core component for crash reporting and diagnostics.…
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • nko
  • Custom Block Builder – Lazy Blocks

11 Feb 2026
Published
11 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
Pending

KEV

Description

The Custom Block Builder – Lazy Blocks plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.0 via multiple functions in the 'LazyBlocks_Blocks' class. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ HIGH severity: CVE-2026-1560 in Lazy Blocks (WordPress, ≤4.2.0) lets Contributor+ users run arbitrary code via improper code generation (CWE-94). No public exploits yet — restrict roles and monitor activity! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • ImageMagick
  • ImageMagick

20 Jan 2026
Published
21 Jan 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.06%

KEV

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
Critical vulnerability disclosure: CVE-2026-23876 in ImageMagick. Impacts the entire #Ubuntu LTS lineage . Read more: 👉 tinyurl.com/bdkk6j42 #Security
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • @react-native-community/cli-server-api

03 Nov 2025
Published
06 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
6.95%

Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
Metro4Shell Exposed: How a Default React Native Server Can Hand Over Your Network to Hackers + Video Introduction: A critical command injection vulnerability, dubbed Metro4Shell and tracked as CVE-2025-11953, has been discovered in the React Native Community CLI's Metro development server. By…
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • jquery-validation

15 Apr 2025
Published
15 Apr 2025
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.25%

KEV

Description

Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This value will populate a message via $.validator.messages in a user localizable dictionary.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

@zachleat

Should be a lot more! They don't organise frontend and npm vuln that way. This doesn't even mention JavaScript:

cve.org/CVERecord?id=CVE-2025-

The search relies on descriptions for which standard terms are "an ongoing area of research" 🧐

cve.org/ResourcesSupport/FAQs#

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Microsoft
  • GitHub Copilot Plugin for JetBrains IDEs

10 Feb 2026
Published
11 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
Pending

KEV

Description

Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
🚨 CVE-2026-21516 (CVSS 8.8 HIGH) Command Injection in GitHub Copilot allows an unauthorized attacker to execute code over a network due to improper neutralization of special elements in commands. Full analysis: basefortify.eu/cve_reports/... #CVE #GitHubCopilot #Microsoft #CyberSecurity #AppSec
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • SAP_SE
  • SAP CRM and SAP S/4HANA (Scripting Editor)

10 Feb 2026
Published
11 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.04%

KEV

Description

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
SAP released 27 security notes including two critical vulnerabilities (CVE-2026-0488 and CVE-2026-0509) enabling database compromise and unauthorized background remote function calls.
  • 1
  • 0
  • 0
  • 20h ago
Showing 31 to 40 of 43 CVEs