Overview
- Python Software Foundation
- CPython
13 Apr 2026
Published
29 Apr 2026
Updated
CVSS v4.0
HIGH (7.0)
EPSS
0.02%
KEV
Description
Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Palo Alto Networks
- WildFire WF-500 and WF-500-B
13 May 2026
Published
13 May 2026
Updated
CVSS v4.0
MEDIUM (5.0)
EPSS
0.05%
KEV
Description
An arbitrary File Read and Delete Vulnerability in Palo Alto Networks WildFire® WF-500 and WF-500-B appliances enables users to read sensitive information and delete arbitrary files. This vulnerability affects WF-500 and WF-500-B appliances running in the default non-FIPS configuration mode.
The WildFire Appliance (WF-500, WF-500-B) software update is now available to customers that use the WildFire Appliance (WF-500, WF-500-B) for on-premise sandboxing.
Please note that customers using the WildFire Public cloud service are NOT impacted by this vulnerability.
Statistics
- 1 Post
Last activity: 17 hours ago
Overview
Description
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
- Go standard library
- net/mail
- net/mail
07 May 2026
Published
08 May 2026
Updated
CVSS
Pending
EPSS
0.02%
KEV
Description
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
Description
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_canswitch.cpp the parser does not properly validate a CANswitch DLC value, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted CANswitch frames.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Palo Alto Networks
- Cloud NGFW
13 May 2026
Published
13 May 2026
Updated
CVSS v4.0
MEDIUM (4.8)
EPSS
0.05%
KEV
Description
A server-side request forgery (SSRF) vulnerability in the IKEv2 implementation of Palo Alto Networks PAN-OS® software allows an unauthenticated attacker to cause the firewall to send network requests to unintended destinations or cause a denial of service (DoS) condition.
Panorama, Cloud NGFW and Prisma® Access are not impacted by these vulnerabilities.
Statistics
- 1 Post
Last activity: 17 hours ago
Overview
- AMD
- AMD Instinct™ MI210
15 May 2026
Published
15 May 2026
Updated
CVSS v4.0
CRITICAL (9.2)
EPSS
0.20%
KEV
Description
Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in loss of availability
Statistics
- 1 Post
Last activity: 11 hours ago
Fediverse
⚠️ CRITICAL: CVE-2026-0481 in AMD Instinct™ MI210 (ROCm). Unrestricted IP binding allows remote attackers to modify GPU configs — could cause availability loss. Awaiting mitigation. Details: https://radar.offseq.com/threat/cve-2026-0481-cwe-1327-binding-to-an-unrestricted--12062e2f #OffSeq #AMD #Vuln #ROCm #GPUsecurity
Overview
Description
Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length field in GVRET binary data is not properly validated, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted GVRET frames.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Yannick Lefebvre
- Link Library
- link-library
24 Dec 2025
Published
28 Apr 2026
Updated
CVSS v3.1
MEDIUM (4.9)
EPSS
0.05%
KEV
Description
Server-Side Request Forgery (SSRF) vulnerability in Yannick Lefebvre Link Library link-library allows Server Side Request Forgery.This issue affects Link Library: from n/a through <= 7.8.7.
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
Description
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Statistics
- 1 Post
Last activity: 13 hours ago
Fediverse
⚠️ CRITICAL vuln: CVE-2026-8511 in Google Chrome (pre-148.0.7778.168) — use-after-free in UI may enable remote sandbox escape via crafted HTML. Patch status unclear. Update ASAP once confirmed! https://radar.offseq.com/threat/cve-2026-8511-use-after-free-in-google-chrome-d050ec47 #OffSeq #Chrome #Infosec #Vuln