24h | 7d | 30d

Overview

  • mlflow
  • mlflow

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.35%

KEV

Description

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

Statistics

  • 1 Post

Last activity: 3 hours ago

Fediverse

Profile picture fallback

A public PoC for CVE-2026-64849, an unauthenticated MLflow SSRF (CVSS 9.3), is now live. watchTowr reports exploitation attempts. Patch to 3.15.0.

securityonline.info/mlflow-ssr

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.74%

KEV

Description

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
【対策】BroadcomはVMSA-2026-0006.1で修正版を公開しています。 CVE-2026-59310:vCenter Syslog ServerのDirectory Traversal → 任意コード実行 CVE-2026-59309:VMware Directory Serviceの認証回避 いずれもCritical / CVSS 9.8で、Broadcomは「回避策なし」としています。 主な修正版: ・vCenter 9.1.x → 9.1.0.0300 ・vCenter 9.0.x → 9.0.2.0100 ・vCenter 8.0 → 8.0 U3k / 8.0 U2f
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • xz
  • xz

29 Mar 2024
Published
04 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
85.97%

KEV

Description

Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Eclecticiq~ Attackers exploit developer dependency culture via account takeovers, malicious packages, and self-propagating worms to compromise software supply chains. - IOCs: CVE-2024-3094, CVE-2025-30066, Shai-Hulud - ...
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • tj-actions
  • changed-files

15 Mar 2025
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
69.56%

Description

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Eclecticiq~ Attackers exploit developer dependency culture via account takeovers, malicious packages, and self-propagating worms to compromise software supply chains. - IOCs: CVE-2024-3094, CVE-2025-30066, Shai-Hulud - ...
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Pending

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS
Pending
EPSS
0.20%

KEV

Description

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: radar.offseq.com/threat/sql-in

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • itwanger
  • paicoding

27 Feb 2026
Published
27 Feb 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
0.31%

KEV

Description

A vulnerability was identified in itwanger paicoding 1.0.0/1.0.1/1.0.2/1.0.3. The impacted element is the function Save of the file paicoding-web/src/main/java/com/github/paicoding/forum/web/common/image/rest/ImageRestController.java of the component Image Save Endpoint. Such manipulation of the argument img leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

SQL Injection flaw (CVE-2026-67854) in Qcms v6.0.6 rated CRITICAL: remote code execution risk. No official patch. Restrict access & monitor for injection attempts. Details: radar.offseq.com/threat/sql-in

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Checkpoint~ Multiple vendors patch actively exploited critical flaws, while Lazarus and China-linked APTs target defense and government sectors. - IOCs: CVE-2026-68820, CVE-2026-65400, CVE-2026-71362 - #Ransomware #ThreatIntel #ZeroDay
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
30 Jun 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
15.65%

KEV

Description

Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Canadian Cyber Centre digest: 7 advisories for IBM, Tenable, Dell, MS Edge, Citrix, Apple, SAP with multiple exploited CVEs. - IOCs: CVE-2026-8451, CVE-2026-8452, CVE-2026-65400 - #PatchNow #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 23h ago
Showing 51 to 58 of 58 CVEs