Overview
Description
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.
Statistics
- 1 Post
Last activity: 20 hours ago
Overview
- steveukx
- simple-git
10 Mar 2026
Published
11 Mar 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%
KEV
Description
`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability.
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
Description
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Statistics
- 1 Post
Last activity: 20 hours ago
Overview
Description
Microsoft Exchange Server Remote Code Execution Vulnerability
Statistics
- 1 Post
Last activity: 20 hours ago
Overview
Description
The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).
Statistics
- 1 Post
Last activity: 21 hours ago
Overview
- Microsoft
- Windows 10 Version 1607
10 Mar 2026
Published
13 Mar 2026
Updated
CVSS v3.1
HIGH (7.0)
EPSS
0.03%
KEV
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Statistics
- 1 Post
Last activity: 20 hours ago