Overview
- Ivanti
- Endpoint Manager Mobile
29 Jan 2026
Published
30 Jan 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
41.90%
KEV
Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Statistics
- 1 Post
Last activity: 6 hours ago
Bluesky
Overview
Description
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.
Statistics
- 1 Post
Last activity: 7 hours ago
Overview
Description
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Statistics
- 1 Post
Last activity: 5 hours ago
Bluesky
Overview
- VMware vCenter Server
18 Jun 2024
Published
02 Aug 2024
Updated
CVSS v3.1
HIGH (7.8)
EPSS
48.35%
KEV
Description
The vCenter Server contains multiple local privilege escalation vulnerabilities due to misconfiguration of sudo. An authenticated local user with non-administrative privileges may exploit these issues to elevate privileges to root on vCenter Server Appliance.
Statistics
- 1 Post
Last activity: 5 hours ago
Bluesky
Overview
- VMware vCenter Server
18 Jun 2024
Published
24 Jan 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
22.42%
KEV
Description
vCenter Server contains a heap-overflow vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger this vulnerability by sending a specially crafted network packet potentially leading to remote code execution.
Statistics
- 1 Post
Last activity: 5 hours ago
Bluesky
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- bootc
21 Jan 2026
Published
21 Jan 2026
Updated
CVSS
Pending
EPSS
0.06%
KEV
Description
A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer overflow. This can cause application crashes, leading to a Denial of Service (DoS).
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- bootc
27 Jan 2026
Published
03 Feb 2026
Updated
CVSS
Pending
EPSS
0.04%
KEV
Description
A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause applications utilizing GLib for string conversion to crash or become unstable.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- bootc
27 Jan 2026
Published
03 Feb 2026
Updated
CVSS
Pending
EPSS
0.04%
KEV
Description
A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large Base64 input using GLib may crash or behave unpredictably.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- bootc
27 Jan 2026
Published
03 Feb 2026
Updated
CVSS
Pending
EPSS
0.00%
KEV
Description
A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a local user to install or process a specially crafted treemagic file, which can lead to local denial of service or application instability.
Statistics
- 1 Post
Last activity: 4 hours ago