Overview
- Cisco
- Cisco Catalyst SD-WAN Manager
25 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.15%
KEV
Description
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role.
The vulnerability is due to improper authentication for requests that are sent to the API. An attacker could exploit this vulnerability by sending a crafted request to the API of an affected system. A successful exploit could allow the attacker to execute commands with the privileges of the netadmin role.
Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.
Statistics
- 1 Post
Last activity: 22 hours ago
Overview
Description
Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
- go-vikunja
- vikunja
25 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
CRITICAL (9.1)
EPSS
0.01%
KEV
Description
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to set weak passwords (e.g., 1234, password) without enforcing minimum strength requirements. Additionally, active sessions remain valid after a user changes their password. An attacker who compromises an account (via brute-force or credential stuffing) can maintain persistent access even after the victim resets their password. Version 2.0.0 contains a fix.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
- kiteworks
- security-advisories
27 Feb 2026
Published
03 Mar 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
0.03%
KEV
Description
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface. Version 9.2.0 contains a patch for the issue.
Statistics
- 1 Post
Last activity: 23 hours ago
Overview
- IceWhaleTech
- ZimaOS
02 Mar 2026
Published
03 Mar 2026
Updated
CVSS v3.1
HIGH (7.1)
EPSS
0.04%
KEV
Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.0 and prior, due to insufficient validation or restriction of target URLs, an authenticated local user can craft requests that target internal IP addresses (e.g., 127.0.0.1, localhost, or private network ranges). This allows the attacker to interact with internal HTTP/HTTPS services that are not intended to be exposed externally or to local users. No known patch is publicly available.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Wireshark Foundation
- Wireshark
25 Feb 2026
Published
25 Feb 2026
Updated
CVSS v3.1
MEDIUM (4.7)
EPSS
0.02%
KEV
Description
USB HID protocol dissector memory exhaustion in Wireshark 4.6.0 to 4.6.3 and 4.4.0 to 4.4.13 allows denial of service
Statistics
- 2 Posts
Last activity: 7 hours ago
Bluesky
Critical patch for #openSUSE Leap 15.6: Wireshark update (SUSE-SU-2026:0810-1) addresses CVE-2026-3201. This fixes a memory exhaustion vulnerability in the USB HID dissector. Read more: 👉 tinyurl.com/4dndufnv #Security
Overview
- golang.org/x/crypto
- golang.org/x/crypto/ssh
- golang.org/x/crypto/ssh
19 Nov 2025
Published
20 Nov 2025
Updated
CVSS
Pending
EPSS
0.08%
KEV
Description
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Statistics
- 1 Post
Last activity: 2 hours ago
Overview
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Statistics
- 1 Post
Last activity: 16 hours ago
Overview
- astroidframe.work
- Astroid Template Framework
05 Mar 2026
Published
05 Mar 2026
Updated
CVSS v4.0
CRITICAL (10.0)
EPSS
0.21%
KEV
Description
A improperly secured file management feature allows uploads of dangerous data types for unauthenticated users, leading to remote code execution.
Statistics
- 1 Post
Last activity: 10 hours ago
Fediverse
🚨 CVE-2026-21628: CRITICAL RCE in Astroid Template Framework (2.0.0 – 3.3.10) for Joomla. Unauthenticated file uploads allow remote code execution. No patch yet — restrict uploads and monitor systems! https://radar.offseq.com/threat/cve-2026-21628-cwe-434-unrestricted-upload-of-file-fb005d26 #OffSeq #Joomla #CVE202621628 #RCE
Overview
- IceWhaleTech
- ZimaOS
02 Mar 2026
Published
03 Mar 2026
Updated
CVSS v3.1
HIGH (8.6)
EPSS
0.06%
KEV
Description
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.5.2-beta3, the application enforces restrictions in the frontend/UI to prevent users from creating files or folders in internal OS paths. However, when interacting directly with the API, the restrictions are bypass-able. By sending a crafted request targeting paths like /etc, /usr, or other sensitive system directories, the API successfully creates files or directories in locations where normal users should have no write access. This indicates that the API does not properly validate the target path, allowing unauthorized operations on critical system directories. No known patch is publicly available.
Statistics
- 1 Post
Last activity: 4 hours ago