24h | 7d | 30d

Overview

  • fast-uri
  • fast-uri

24 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.42%

KEV

Description

fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input depending only on whether a scheme is written out, and equal can return opposite verdicts for the same pair of hosts. An application that extracts a host with fast-uri to check it against a policy list and then resolves the same reference can make its decision on one host while the destination is another, enabling host confusion and policy bypass. The affected versions are 2.4.2 up to but not including 2.4.5, 3.1.3 up to but not including 3.1.6, and 4.0.1 up to but not including 4.1.3. The issue is fixed in 2.4.5, 3.1.6, and 4.1.3, which canonicalize the host consistently across the resolve path. Users should upgrade to a patched version.

Statistics

  • 2 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

🚨 High-severity security fix in fast-uri 2.4.5, 3.1.6, and 4.1.3 just released!

Patches CVE-2026-75931. Host confusion via skipped IDN canonicalization on scheme-relative references.

github.com/fastify/fast-uri/se

  • 0
  • 0
  • 1
  • 11h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

11 Aug 2026
Published
24 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
2.93%

KEV

Description

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

  • 4
  • 3
  • 0
  • 6h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
5.58%

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: vulncheck.com/blog/cve-2026-63

  • 4
  • 3
  • 0
  • 6h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • NetworkManager

26 Jan 2026
Published
30 Jun 2026
Updated

CVSS
Pending
EPSS
0.16%

KEV

Description

A flaw was found in NetworkManager. The NetworkManager package allows access to files that may belong to other users. NetworkManager allows non-root users to configure the system's network. The daemon runs with root privileges and can access files owned by users different from the one who added the connection.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

  • 1
  • 6
  • 0
  • 2h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • NetworkManager

24 Aug 2026
Published
24 Aug 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

Statistics

  • 1 Post
  • 7 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

i uSe lInUx bEcAuSe iT'S SeCuRe.

access.redhat.com/security/cve

NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA path at an attacker-controlled directory, bypassing server certificate validation and enabling credential theft via a rogue access point.

  • 1
  • 6
  • 0
  • 2h ago

Overview

  • IBM
  • Power Systems Firmware

19 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.21%

KEV

Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker with network access can send the FSP a malformed request, allowing arbitrary code execution, giving the attacker full control over the managed system, resulting in a confidentiality, integrity, and availability impact.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

securityonline.info/ibm-power-

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • IBM
  • Power Systems Firmware

19 Aug 2026
Published
22 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.23%

KEV

Description

IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the FSP management network protocol. An unauthenticated attacker on the management network can bypass authentication and perform any administrative operation on the managed system, including control of partition power state, configuration, and console access across all hosted partitions, resulting in a confidentiality, integrity, and availability impact to the managed system.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.

securityonline.info/ibm-power-

  • 0
  • 0
  • 0
  • 7h ago
Showing 41 to 47 of 47 CVEs