24h | 7d | 30d

Overview

  • Apache Software Foundation
  • Apache Log4j2

10 Dec 2021
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
94.36%

Description

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Sophos~ Iranian threat groups favor phishing, password spraying, RMM abuse, and exploiting public vulnerabilities for initial access. - IOCs: CVE-2021-44228, CVE-2021-34473, CVE-2018-13379 - #Iran #TTPs #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • steveukx
  • simple-git

10 Mar 2026
Published
11 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%

KEV

Description

`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through 3.32.2 that allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912) and achieve full remote code execution on the host machine. Version 3.23.0 contains an updated fix for the vulnerability.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
CVE-2026-28292: simple-git Remote Code Execution - A case-sensitivity bug in simple-git (12.4 million+ weekly npm downloads) allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912)
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Fortinet
  • Fortinet FortiOS, FortiProxy

04 Jun 2019
Published
21 Oct 2025
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
94.48%

Description

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Sophos~ Iranian threat groups favor phishing, password spraying, RMM abuse, and exploiting public vulnerabilities for initial access. - IOCs: CVE-2021-44228, CVE-2021-34473, CVE-2018-13379 - #Iran #TTPs #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2013 Cumulative Update 23

14 Jul 2021
Published
21 Oct 2025
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
94.26%

Description

Microsoft Exchange Server Remote Code Execution Vulnerability

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Sophos~ Iranian threat groups favor phishing, password spraying, RMM abuse, and exploiting public vulnerabilities for initial access. - IOCs: CVE-2021-44228, CVE-2021-34473, CVE-2018-13379 - #Iran #TTPs #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • simple-git

12 Dec 2022
Published
22 Apr 2025
Updated

CVSS v3.1
HIGH (8.1)
EPSS
43.30%

KEV

Description

The package simple-git before 3.15.0 are vulnerable to Remote Code Execution (RCE) when enabling the ext transport protocol, which makes it exploitable via clone() method. This vulnerability exists due to an incomplete fix of [CVE-2022-24066](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-2434306).

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
CVE-2026-28292: simple-git Remote Code Execution - A case-sensitivity bug in simple-git (12.4 million+ weekly npm downloads) allows an attacker to bypass two prior CVE fixes (CVE-2022-25860 and CVE-2022-25912)
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

10 Mar 2026
Published
13 Mar 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.03%

KEV

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Sophos~ Microsoft patched 84 CVEs, including 8 Critical flaws and 2 publicly disclosed issues. - IOCs: CVE-2026-21536, CVE-2026-21262, CVE-2026-23668 - #PatchTuesday #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 20h ago
Showing 41 to 46 of 46 CVEs