24h | 7d | 30d

Overview

  • VMware
  • Spring Security

19 Mar 2026
Published
02 Apr 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP Headers: : from 5.7.0 through 5.7.21, from 5.8.0 through 5.8.23, from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.8, from 7.0.0 through 7.0.3.

Statistics

  • 1 Post

Last activity: 5 hours ago

Bluesky

Profile picture fallback
Spring Security CVE-2026-22732 Detection / Remediation Tool https://packetstorm.news/files/230354
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Azure Kubernetes Service

09 Jun 2026
Published
25 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.34%

KEV

Description

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
How it works: 1. A Word doc with a hidden prompt injection gets uploaded to Copilot 2. Launder intent (using a gzip payload) to bypass safety filters 3. Escalate to root inside the sandbox 4. Execute a full container-to-host escape (CVE-2026-32193)
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Linux
  • Linux

15 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.66%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: xfrm: nat_keepalive: avoid double free on send error nat_keepalive_send() frees the keepalive skb whenever the IPv4 or IPv6 send helper reports an error. That cleanup is only correct before the skb is handed to the output path. Once ip_build_and_send_pkt() or ip6_xmit() takes ownership, the networking stack may already have consumed the skb before returning an error, so freeing it again is unsafe. Handle the pre-handoff failure cases inside nat_keepalive_send_ipv4() and nat_keepalive_send_ipv6(), where the caller still owns the skb, and keep nat_keepalive_send() responsible only for family dispatch and the unsupported-family cleanup path.

Statistics

  • 2 Posts
  • 11 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

We've released an updated kernel (6.12.0-211.50.1.el10_2.0.1 - available in our security repo) that fixes two LPE CVEs, CVE-2026-72137 and CVE-2026-53361.

(You can enable the security repo with `sudo dnf --enablerepo=security update`)

Once again, thanks to CIQ engineers who provided the fix!

  • 3
  • 8
  • 1
  • 9h ago

Overview

  • Linux
  • Linux

04 Jul 2026
Published
19 Aug 2026
Updated

CVSS v3.1
HIGH (7.1)
EPSS
0.19%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc() unix_schedule_gc() `- if (!gc_in_progress) `- if (!gc_in_progress) |- gc_in_progress = true | `- queue_work() | unix_gc() <----------------/ | | |- gc_in_progress = true ... `- queue_work() | | `- gc_in_progress = false | | unix_gc() <---------------------------------------------' | ... /* gc_in_progress == false */ | `- gc_in_progress = false unix_peek_fpl() relies on gc_in_progress not to confuse GC by MSG_PEEK. Let's set gc_in_progress to true in unix_gc().

Statistics

  • 2 Posts
  • 11 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

We've released an updated kernel (6.12.0-211.50.1.el10_2.0.1 - available in our security repo) that fixes two LPE CVEs, CVE-2026-72137 and CVE-2026-53361.

(You can enable the security repo with `sudo dnf --enablerepo=security update`)

Once again, thanks to CIQ engineers who provided the fix!

  • 3
  • 8
  • 1
  • 9h ago

Overview

  • arraytics
  • Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)

14 Apr 2026
Published
14 Apr 2026
Updated

CVSS v3.1
MEDIUM (4.3)
EPSS
0.18%

KEV

Description

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order data including customer PII (name, email, phone) by iterating order IDs.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
🚨 #Alerta: Explotación activa de vulnerabilidades críticas en #MicrosoftDefender | CVE-2026-4109 | CVE-2026-45498 | www.newstecnicas.com/2026/06/aler...
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Microsoft
  • Microsoft Defender Antimalware Platform

20 May 2026
Published
10 Aug 2026
Updated

CVSS v3.1
MEDIUM (4.0)
EPSS
63.08%

Description

Microsoft Defender Denial of Service Vulnerability

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
🚨 #Alerta: Explotación activa de vulnerabilidades críticas en #MicrosoftDefender | CVE-2026-4109 | CVE-2026-45498 | www.newstecnicas.com/2026/06/aler...
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • HP Inc
  • HP Easy Start for macOS

24 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
0.23%

KEV

Description

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556)
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • HP Inc
  • HP Easy Start for macOS

24 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
0.15%

KEV

Description

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556)
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • HP Inc
  • HP Easy Start for macOS

24 Aug 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.21%

KEV

Description

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556)
  • 0
  • 0
  • 0
  • 3h ago
Showing 31 to 39 of 39 CVEs