24h | 7d | 30d

Overview

  • Devolutions
  • Server

03 Mar 2026
Published
04 Mar 2026
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

🚨 CVE-2026-3224: CRITICAL auth bypass in Devolutions Server <=2025.3.15.0 using Microsoft Entra ID. Attackers can forge JWTs for full access. No known exploits, but patch ASAP & tighten token validation. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Ivanti
  • Connect Secure

08 Jan 2025
Published
21 Oct 2025
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
94.18%

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Malware RESURGE colpisce Ivanti: come difendersi subito dalla zero-day 📌 Link all'articolo : www.redhotcyber.com/post/mal... #redhotcyber #news #cybersecurity #hacking #malware #ransomware #cisa #vulnerabilita #cve20250282 #rootkit
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • IceWarp
  • IceWarp

23 Dec 2025
Published
30 Dec 2025
Updated

CVSS v3.0
CRITICAL (9.8)
EPSS
1.29%

KEV

Description

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IceWarp. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the X-File-Operation header. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-27394.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Más de 1200 servidores IceWarp siguen siendo vulnerables a la falla RCE no autenticada (CVE-2025-14500). El fallo permite a atacantes tomar control total de servidores de correo. Si usas IceWarp, ¡actualiza a la versión 13.0.4 de inmediato! #ciberseguridad www.linkedin.com/pulse/m%C3%A...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Qualcomm, Inc.
  • Snapdragon

02 Mar 2026
Published
02 Mar 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.02%

KEV

Description

Memory Corruption when accessing buffers with invalid length during TA invocation.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
📌 CVE-2025-47373 - Memory Corruption when accessing buffers with invalid length during TA invocation. https://www.cyberhub.blog/cves/CVE-2025-47373
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Juniper Networks
  • Junos OS Evolved

25 Feb 2026
Published
04 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.28%

KEV

Description

An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework should only be reachable by other internal processes over the internal routing instance, but not over an externally exposed port. With the ability to access and manipulate the service to execute code as root a remote attacker can take complete control of the device. Please note that this service is enabled by default as no specific configuration is required. This issue affects Junos OS Evolved on PTX Series: * 25.4 versions before 25.4R1-S1-EVO, 25.4R2-EVO. This issue does not affect Junos OS Evolved versions before 25.4R1-EVO. This issue does not affect Junos OS.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
📌 Junos OS Evolved Vulnerability (CVE-2026-21902 RCE) Detailed by watchTowr Labs https://www.cyberhub.blog/article/20676-junos-os-evolved-vulnerability-cve-2026-21902-rce-detailed-by-watchtowr-labs
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • VMware
  • VMware Aria Operations
  • vmware-aria-operations

25 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
0.08%

KEV

Description

VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able to inject script to perform administrative actions in VMware Aria Operations.  To remediate CVE-2026-22720, apply the patches listed in the 'Fixed Version' column of the 'Response Matrix' of  VMSA-2026-0001 https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/36947https:// .

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-22720 - VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with privileges to create custom benchmarks may be able... https://www.cyberhub.blog/cves/CVE-2026-22720
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Qualcomm, Inc.
  • Snapdragon

02 Mar 2026
Published
03 Mar 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.04%

KEV

Description

Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
📌 CVE-2025-47383 - Weak configuration may lead to cryptographic issue when a VoWiFi call is triggered from UE. https://www.cyberhub.blog/cves/CVE-2025-47383
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • AMD
  • AMD EPYCâ„¢ 9004 Series Processors

06 Sep 2025
Published
03 Nov 2025
Updated

CVSS v3.1
LOW (3.2)
EPSS
0.02%

KEV

Description

Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
🚨 #Ubuntu 24.04 LTS (Azure) CRITICAL Kernel Update USN-8074-1 is LIVE. This patches a SEV-SNP data integrity flaw (CVE-2024-36331) where a hypervisor could overwrite "secure" guest memory. Plus 150+ other CVEs. Read more: 👉 tinyurl.com/42ukrdhj #Security
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Portwell
  • Portwell Engineering Toolkits

03 Mar 2026
Published
03 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.01%

KEV

Description

An Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Portwell Engineering Toolkits version 4.8.2 could allow a local authenticated attacker to read and write to arbitrary memory via the Portwell Engineering Toolkits driver. Successful exploitation of this vulnerability could result in escalation of privileges or cause a denial-of-service condition.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

🚨 CVE-2026-3437 (CRITICAL, CVSS 9.3): Portwell Engineering Toolkits 4.8.2 lets local users escalate privileges or trigger DoS via memory access in driver. No patch yet — restrict local access, audit users, monitor! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • SEPPmail
  • Secure Email Gateway

04 Mar 2026
Published
04 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.04%

KEV

Description

SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
🚨 CVE-2026-27441 – CRITICAL (9.5) OS Command Injection in SEPPmail Secure Email Gateway. A flaw in how PDF encryption passwords are handled allows attackers to execute OS commands. Full report: basefortify.eu/cve_reports/... #CVE #EmailSecurity #CommandInjection #CyberSecurity #InfoSec
  • 0
  • 0
  • 0
  • 10h ago
Showing 31 to 40 of 71 CVEs