24h | 7d | 30d

Overview

  • libsodium
  • libsodium

31 Dec 2025
Published
07 Jan 2026
Updated

CVSS v3.1
MEDIUM (4.5)
EPSS
0.01%

KEV

Description

libsodium before ad3004e, in atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
🚨 URGENT: #SUSE Linux Security Update 🚨 Critical flaws (CVE-2025-15444, CVE-2025-69277) in the libsodium crypto library have been patched for SUSE Linux Micro 6.1. Read more: 👉 tinyurl.com/2ruz8nx4 #Security
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • SolarWinds
  • Serv-U

24 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.03%

KEV

Description

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

All four security defects, tracked as CVE-2025-40538 to CVE-2025-40541, have a CVSS score of 9.1, could result in remote code execution, and impact Serv-U version 15.5. securityweek.com/solarwinds-pa

  • 0
  • 0
  • 1
  • 16h ago

Overview

  • BeyondTrust
  • Remote Support(RS) & Privileged Remote Access(PRA)

06 Feb 2026
Published
26 Feb 2026
Updated

CVSS v4.0
CRITICAL (9.9)
EPSS
61.83%

Description

BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Latest Metasploit update is out with unauthenticated RCE for Grandstream GXP1600 VoIP devices, enabling credential harvesting and SIP interception. Also included is critical support for BeyondTrust PRA/RS command injection (CVE-2026-1731), plus a serious Ollama RCE (CVE-2024-37032).

Check out the wrap up at rapid7.com/blog/post/pt-metasp

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • libexpat project
  • libexpat

30 Jan 2026
Published
03 Feb 2026
Updated

CVSS v3.1
MEDIUM (6.9)
EPSS
0.01%

KEV

Description

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
Urgent: #SUSE Linux Micro 6.1 patches Expat library with fixes for CVE-2026-24515 (NULL dereference) and CVE-2026-25210 (integer overflow). Read more: 👉 tinyurl.com/ya558teh #Security
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Pending

31 May 2024
Published
27 Mar 2025
Updated

CVSS
Pending
EPSS
93.76%

KEV

Description

Ollama before 0.1.34 does not validate the format of the digest (sha256 with 64 hex digits) when getting the model path, and thus mishandles the TestGetBlobsPath test cases such as fewer than 64 hex digits, more than 64 hex digits, or an initial ../ substring.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

Latest Metasploit update is out with unauthenticated RCE for Grandstream GXP1600 VoIP devices, enabling credential harvesting and SIP interception. Also included is critical support for BeyondTrust PRA/RS command injection (CVE-2026-1731), plus a serious Ollama RCE (CVE-2024-37032).

Check out the wrap up at rapid7.com/blog/post/pt-metasp

  • 0
  • 0
  • 0
  • 9h ago

Overview

  • IAMB
  • Crypt::Sodium::XS
  • Crypt-Sodium-XS

06 Jan 2026
Published
06 Jan 2026
Updated

CVSS
Pending
EPSS
0.06%

KEV

Description

Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1.0.20 or a version of libsodium released before December 30, 2025 contains a vulnerability documented as CVE-2025-69277  https://www.cve.org/CVERecord?id=CVE-2025-69277 . The libsodium vulnerability states: In atypical use cases involving certain custom cryptography or untrusted data to crypto_core_ed25519_is_valid_point, mishandles checks for whether an elliptic curve point is valid because it sometimes allows points that aren't in the main cryptographic group. 0.000042 includes a version of libsodium updated to 1.0.20-stable, released January 3, 2026, which includes a fix for the vulnerability.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
🚨 URGENT: #SUSE Linux Security Update 🚨 Critical flaws (CVE-2025-15444, CVE-2025-69277) in the libsodium crypto library have been patched for SUSE Linux Micro 6.1. Read more: 👉 tinyurl.com/2ruz8nx4 #Security
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • SolarWinds
  • Serv-U

24 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.02%

KEV

Description

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services frequently run under less-privileged service accounts by default.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Fediverse

Profile picture fallback

All four security defects, tracked as CVE-2025-40538 to CVE-2025-40541, have a CVSS score of 9.1, could result in remote code execution, and impact Serv-U version 15.5. securityweek.com/solarwinds-pa

  • 0
  • 0
  • 1
  • 16h ago

Overview

  • libexpat project
  • libexpat

23 Jan 2026
Published
23 Jan 2026
Updated

CVSS v3.1
LOW (2.9)
EPSS
0.00%

KEV

Description

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
Urgent: #SUSE Linux Micro 6.1 patches Expat library with fixes for CVE-2026-24515 (NULL dereference) and CVE-2026-25210 (integer overflow). Read more: 👉 tinyurl.com/ya558teh #Security
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • urllib3
  • urllib3

07 Jan 2026
Published
23 Jan 2026
Updated

CVSS v4.0
HIGH (8.9)
EPSS
0.03%

KEV

Description

urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression based on the HTTP `Content-Encoding` header (e.g., `gzip`, `deflate`, `br`, or `zstd`). When using the streaming API, the library decompresses only the necessary bytes, enabling partial content consumption. Starting in version 1.22 and prior to version 2.6.3, for HTTP redirect responses, the library would read the entire response body to drain the connection and decompress the content unnecessarily. This decompression occurred even before any read methods were called, and configured read limits did not restrict the amount of decompressed data. As a result, there was no safeguard against decompression bombs. A malicious server could exploit this to trigger excessive resource consumption on the client. Applications and libraries are affected when they stream content from untrusted sources by setting `preload_content=False` when they do not disable redirects. Users should upgrade to at least urllib3 v2.6.3, in which the library does not decode content of redirect responses when `preload_content=False`. If upgrading is not immediately possible, disable redirects by setting `redirect=False` for requests to untrusted source.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 15 hours ago

Bluesky

Profile picture fallback
Urgent: #openSUSE Leap 16.0 security update for python-urllib3 fixes 3 DoS flaws (CVE-2025-66471, CVE-2025-66418, CVE-2026-21441). Read more: 👉 tinyurl.com/2864pphy #Security #Linux
  • 0
  • 1
  • 0
  • 15h ago
Showing 71 to 79 of 79 CVEs