24h | 7d | 30d

Overview

  • Cisco
  • Cisco Catalyst SD-WAN Manager

25 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.15%

KEV

Description

A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability. 

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-20129 - A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an a... https://www.cyberhub.blog/cves/CVE-2026-20129
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

03 Mar 2026
Published
03 Mar 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.47%

KEV

Description

Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
📌 CVE-2025-63911 - Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability. https://www.cyberhub.blog/cves/CVE-2025-63911
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • go-vikunja
  • vikunja

25 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.01%

KEV

Description

Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password. Version 2.0.0 contains a fix.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-27575 - Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234... https://www.cyberhub.blog/cves/CVE-2026-27575
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • kiteworks
  • security-advisories

27 Feb 2026
Published
03 Mar 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.03%

KEV

Description

Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface. Version 9.2.0 contains a patch for the issue.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-28272 - Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administ... https://www.cyberhub.blog/cves/CVE-2026-28272
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • IceWhaleTech
  • ZimaOS

02 Mar 2026
Published
03 Mar 2026
Updated

CVSS v3.1
HIGH (7.1)
EPSS
0.04%

KEV

Description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users. No known patch is publicly available.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
📌 CVE-2025-64427 - ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validat... https://www.cyberhub.blog/cves/CVE-2025-64427
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Wireshark Foundation
  • Wireshark

25 Feb 2026
Published
25 Feb 2026
Updated

CVSS v3.1
MEDIUM (4.7)
EPSS
0.02%

KEV

Description

USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service

Statistics

  • 2 Posts

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Critical patch for #openSUSE Leap 15.6: Wireshark update (SUSE-SU-2026:0810-1) addresses CVE-2026-3201. This fixes a memory exhaustion vulnerability in the USB HID dissector. Read more: 👉 tinyurl.com/4dndufnv #Security
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
New #USE patch advisory (SUSE-2026-0810-1) for Wireshark on #openSUSE Leap 15.6 addresses CVE-2026-3201. Read more: 👉 tinyurl.com/2u8upss3 #Security
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • golang.org/x/crypto
  • golang.org/x/crypto/ssh
  • golang.org/x/crypto/ssh

19 Nov 2025
Published
20 Nov 2025
Updated

CVSS
Pending
EPSS
0.08%

KEV

Description

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
New Docker vulnerability (CVE-2025-58181) patched in #SUSE Linux Micro 6.2. It's a moderate-severity memory exhaustion issue (CVSS 5.3). Unauthenticated remote attackers can potentially trigger it. Read more: 👉 tinyurl.com/25cyzha8 #Security
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • BeyondTrust
  • Remote Support(RS) & Privileged Remote Access(PRA)

06 Feb 2026
Published
26 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.9)
EPSS
64.61%

Description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ A critical pre-auth RCE (CVE-2026-1731) in BeyondTrust RS and PRA is being exploited in the wild. Patch immediately. - IOCs: CVE-2026-1731 - #BeyondTrust #CVE20261731 #ThreatIntel
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • astroidframe.work
  • Astroid Template Framework

05 Mar 2026
Published
05 Mar 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.21%

KEV

Description

A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

🚨 CVE-2026-21628: CRITICAL RCE in Astroid Template Framework (2.0.0 – 3.3.10) for Joomla. Unauthenticated file uploads allow remote code execution. No patch yet — restrict uploads and monitor systems! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • IceWhaleTech
  • ZimaOS

02 Mar 2026
Published
03 Mar 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
0.06%

KEV

Description

ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting directly with the API, the restrictions are bypass-able. By sending a crafted request targeting paths like /etc, /usr, or other sensitive system directories, the API successfully creates files or directories in locations where normal users should have no write access. This indicates that the API does not properly validate the target path, allowing unauthorized operations on critical system directories. No known patch is publicly available.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-28286 - ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restri... https://www.cyberhub.blog/cves/CVE-2026-28286
  • 0
  • 0
  • 0
  • 4h ago
Showing 41 to 50 of 84 CVEs