24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
📢 Vulnérabilité critique d'exécution de code à distance dans WordPress (CVE-2026-65640) Le CERT-FR a publié le 13 août 2026 l'avis CERTFR-2026-AVI-1018 signalant une vulnérabilité dans WordPress, basé sur le bulletin de sécurité… 🟡 vérification factuelle moyenne #WordPress #CERTFR #Cyberveille
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • siyuan-note
  • siyuan

16 Aug 2026
Published
16 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an unauthenticated remote attacker can perform unlimited automated guesses of the API token, particularly when a short or weak custom token has been configured, and upon success gains full RoleAdministrator access enabling arbitrary file operations and SQL queries.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • Last hour

Overview

  • ericcornelissen
  • shescape

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.21%

KEV

Description

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on Unix systems where the shell is explicitly configured to "sh" or true and /bin/sh points to BusyBox. Using the escape and escapeAll APIs with untrusted input in an assignment prefixed to a command, an attacker can inject a tilde payload to disclose the user's home directory location and, depending on usage, alter the location on which a command operates.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • KUNBUS
  • piControl

14 Aug 2026
Published
14 Aug 2026
Updated

CVSS v4.0
HIGH (7.3)
EPSS
Pending

KEV

Description

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer and corrupt adjacent kernel memory, resulting in kernel memory corruption and denial of service, by supplying crafted device configuration data and crafted input through the piControl character device.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-13196 - OOB write in KUNBUS piControl 2.6.2. Local auth attacker can corrupt kernel memory, cause DoS. No CVSS yet, unpatched. Update immediately. #CVE #KUNBUS #infosec

valtersit.com/cve/CVE-2026-131

  • 0
  • 0
  • 0
  • Last hour

Overview

  • siyuan-note
  • siyuan

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.28%

KEV

Description

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
Cl0p Ransomware Hits PTC Windchill: CVE-2026-12569 tech-insider.org/clop-ransomw...
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Apr 2026
Published
14 Aug 2026
Updated

CVSS v3.1
MEDIUM (5.7)
EPSS
0.27%

KEV

Description

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
📢 [VULN] Une faille Windows permet de désactiver l'antivirus avec un simple script CVE-2026-23670, Des chercheurs ont présenté une méthode capable de neutraliser l’antivirus et les protections noyau de Windows avec un seul script. #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 3h ago
Showing 21 to 27 of 27 CVEs