24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
The #Debian LTS project has disclosed DLA-4487-1, addressing two critical vulnerabilities (CVE-2026-2049, CVE-2026-2050) in the GEGL image processing library. Read more: 👉 tinyurl.com/zbuh7nf7 #Security
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • nodeca
  • js-yaml

13 Nov 2025
Published
29 Jan 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.02%

KEV

Description

js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to modify the prototype of the result of a parsed yaml document via prototype pollution (`__proto__`). All users who parse untrusted yaml documents may be impacted. The problem is patched in js-yaml 4.1.1 and 3.14.2. Users can protect against this kind of attack on the server by using `node --disable-proto=delete` or `deno` (in Deno, pollution protection is on by default).

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
Critical patch for #openSUSE Leap 16.0: SLE-WU-2026-38129-5. It fixes prototype pollution in Cockpit (CVE-2025-13465) and js-yaml (CVE-2025-64718). Read more: 👉 tinyurl.com/47j9sufj #Security
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • bigbluebutton
  • bigbluebutton

21 Feb 2026
Published
21 Feb 2026
Updated

CVSS v3.1
LOW (2.0)
EPSS
0.02%

KEV

Description

BigBlueButton is an open-source virtual classroom. In versions 3.0.19 and below, when first joining a session with the microphone muted, the client sends audio to the server regardless of mute state. Media is discarded at the server side, so it isn't audible to any participants, but this may allow for malicious server operators to access audio data. The behavior is only incorrect between joining the meeting and the first time the user unmutes. This issue has been fixed in version 3.0.20.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

BigBlueButton on < 3.0.22 with two new CVEs today: CVE-2026-27466 & CVE-2026-27467

hecate.pw/vulnerabilities?sear

Feel free to use the AI slop analyses (Gemini for student with free API configured).. Hecate is a prototype app for my master thesis

#vulnerability #cve #security #InfoSec #bigbluebutton

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Ivanti
  • Endpoint Manager Mobile

29 Jan 2026
Published
30 Jan 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
38.65%

KEV

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Statistics

  • 1 Post

Last activity: 15 hours ago

Overview

  • bigbluebutton
  • bigbluebutton

21 Feb 2026
Published
21 Feb 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.07%

KEV

Description

BigBlueButton is an open-source virtual classroom. In versions 3.0.21 and below, the official documentation for "Server Customization" on Support for ClamAV as presentation file scanner contains instructions that leave a BBB server vulnerable for Denial of Service. The flawed command exposes both ports (3310 and 7357) to the internet. A remote attacker can use this to send complex or large documents to clamd and waste server resources, or shutdown the clamd process. The clamd documentation explicitly warns about exposing this port. Enabling ufw (ubuntu firewall) during install does not help, because Docker routes container traffic through the nat table, which is not managed or restricted by ufw. Rules installed by ufw in the filter table have no effect on docker traffic. In addition, the provided example also mounts /var/bigbluebutton with write permissions into the container, which should not be required. Future vulnerabilities in clamd may allow attackers to manipulate files in that folder. Users are unaffected unless they have opted in to follow the extra instructions from BigBlueButton's documentation. This issue has been fixed in version 3.0.22.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

BigBlueButton on < 3.0.22 with two new CVEs today: CVE-2026-27466 & CVE-2026-27467

hecate.pw/vulnerabilities?sear

Feel free to use the AI slop analyses (Gemini for student with free API configured).. Hecate is a prototype app for my master thesis

#vulnerability #cve #security #InfoSec #bigbluebutton

  • 0
  • 0
  • 0
  • 13h ago
Showing 41 to 45 of 45 CVEs