24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Announcing Incus 7.4

The Incus team is pleased to announce the release of Incus 7.4!

Another pretty busy month for us as we clear a lot of our Github backlog, fix quite a few longstanding bugs and land a good mix of new features too!

[🖼 stgraber.org/wp-content/upload…]

This fixes the following security issues:

  • CVE-2026-81500 (medium) – Client-side path traversal when exporting an image from a malicious server
  • CVE-2026-81501 (medium) – Private image import from another project by a restricted client

On the feature front, the highlights for this release are:

  • UEFI Secure Boot key management
  • Near-live migration of containers
  • One-time boot override for virtual machines
  • Sharing networks with restricted projects
  • DNS NOTIFY support for network zones
  • New table rendering in the CLI
  • librbd backend for Ceph RBD
  • Recovery of shared storage pools in clusters
  • Remote-specific client certificates
  • Raw API requests with custom headers and data files
  • NVRAM access from QEMU scriptlets
  • OVN multicast configuration
  • Control of IPv6 router advertisemens
  • Burst I/O limits for disk devices
  • Burst I/O limits for network devices
  • NIC queuing disciplines
  • Image property columns
  • Image locations in clusters
  • Instance start protection
  • Ceph Object endpoint certificate

The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:

https://www.youtube.com/watch?v=kL8t4qRKc1M

You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/

And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus

Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.

Enjoy!

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Pending

25 Nov 2018
Published
05 Aug 2024
Updated

CVSS
Pending
EPSS
95.23%

KEV

Description

University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
~Cisa~ Fuel-Boss flaws enable remote command/code execution; patch or remove unfixed systems from the internet. - IOCs: CVE-2019-11043, CVE-2018-19518 - #CVE-2018-19518 #CVE-2019-11043 #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • PHP
  • PHP

28 Oct 2019
Published
21 Oct 2025
Updated

CVSS v3.1
HIGH (8.7)
EPSS
99.78%

Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
~Cisa~ Fuel-Boss flaws enable remote command/code execution; patch or remove unfixed systems from the internet. - IOCs: CVE-2019-11043, CVE-2018-19518 - #CVE-2018-19518 #CVE-2019-11043 #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
~Checkpoint~ Attacks hit airports, healthcare and government while actively exploited flaws enable remote code execution. - IOCs: CVE-2026-82078, CVE-2026-18885, CVE-2026-75604 - #Ransomware #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • ServiceNow
  • ServiceNow AI Platform

27 Aug 2026
Published
29 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.25%

KEV

Description

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
ServiceNow、CVSS 10.0の脆弱性3件を修正-未認証RCE・権限昇格・SQLインジェクションに対応(CVE-2026-18885,CVE-2026-18886,CVE-2026-74820) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • Last hour

Overview

  • ServiceNow
  • ServiceNow AI Platform

27 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.25%

KEV

Description

ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
ServiceNow、CVSS 10.0の脆弱性3件を修正-未認証RCE・権限昇格・SQLインジェクションに対応(CVE-2026-18885,CVE-2026-18886,CVE-2026-74820) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性
  • 0
  • 0
  • 0
  • Last hour
Showing 21 to 26 of 26 CVEs