24h | 7d | 30d

Overview

  • Python Software Foundation
  • CPython

13 Apr 2026
Published
29 Apr 2026
Updated

CVSS v4.0
HIGH (7.0)
EPSS
0.02%

KEV

Description

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-4786 impacts python in 6 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/526 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Palo Alto Networks
  • WildFire WF-500 and WF-500-B

13 May 2026
Published
13 May 2026
Updated

CVSS v4.0
MEDIUM (5.0)
EPSS
0.05%

KEV

Description

An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode. The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing. Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0259 WildFire WF-500 and WF-500-B: Arbitrary File Read and Delete Vulnerability in WildFire Appliance (WF-500, WF-500-B) (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0259
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Exim
  • Exim

12 May 2026
Published
14 May 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.06%

KEV

Description

Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
🚨 Exim v4.99.3 is out, patching a critical use-after-free vulnerability. CVE-2026-45185 allows unauthenticated #RCE, affecting versions prior to v4.99.3. Exim often sits under mail-handling stacks and appliances, extending the blast radius past direct deployments. Upgrade to v4.99.3.
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Go standard library
  • net/mail
  • net/mail

07 May 2026
Published
08 May 2026
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
🔍 Lambda Watchdog detected that CVE-2026-42499 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/503 #AWS #Lambda #Security #CVE #DevOps #SecOps
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

01 May 2026
Published
07 May 2026
Updated

CVSS
Pending
EPSS
0.24%

KEV

Description

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted CANswitch frames.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
【脆弱性情報】 CVE-2026-42469 Open Vehicle Monitoring System 3 (OVMS3) 3.3.005の脆弱性について Open Vehicle Monitoring System 3 (OVMS3) 3.3.005におけるバッファオーバーフローの脆弱性です。
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
13 May 2026
Updated

CVSS v4.0
MEDIUM (4.8)
EPSS
0.05%

KEV

Description

A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition. Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
Paloaltoの脆弱性情報 「CVE-2026-0258 PAN-OS: Server-Side Request Forgery (SSRF) in IKEv2 Certificate URL Fetching (Severity: MEDIUM)」が公開されました。 → https://security.paloaltonetworks.com/CVE-2026-0258
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • AMD
  • AMD Instinct™ MI210

15 May 2026
Published
15 May 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.20%

KEV

Description

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CVE-2026-0481 in AMD Instinct™ MI210 (ROCm). Unrestricted IP binding allows remote attackers to modify GPU configs — could cause availability loss. Awaiting mitigation. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Pending

01 May 2026
Published
07 May 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.22%

KEV

Description

Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
【脆弱性情報】 CVE-2026-37541 Open Vehicle Monitoring System 3 (OVMS3) 3.3.005の脆弱性について Open Vehicle Monitoring System 3 (OVMS3) 3.3.005におけるバッファオーバーフローの脆弱性です。
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Yannick Lefebvre
  • Link Library
  • link-library

24 Dec 2025
Published
28 Apr 2026
Updated

CVSS v3.1
MEDIUM (4.9)
EPSS
0.05%

KEV

Description

Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
CVE-2025–68600: The Ronin’s Path Breaking WordPress Security with My First Validated Discovery https://medium.com/@krissaphat.j/cve-2025-68600-the-ronins-path-breaking-wordpress-security-with-my-first-validated-discovery-b26cfbaab12d?source=rss------bug_bounty-5
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Google
  • Chrome

14 May 2026
Published
15 May 2026
Updated

CVSS
Pending
EPSS
0.07%

KEV

Description

Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL vuln: CVE-2026-8511 in Google Chrome (pre-148.0.7778.168) — use-after-free in UI may enable remote sandbox escape via crafted HTML. Patch status unclear. Update ASAP once confirmed! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago
Showing 51 to 60 of 68 CVEs