24h | 7d | 30d

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 37 Interactions

Last activity: 14 hours ago

Bluesky

Profile picture fallback
🎉 Go 1.26.1 and 1.25.8 are released! 🔏 Security: Includes security fixes for the standard library (CVE-2026-25679, CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-27142). 📢 Announcement: groups.google.com/g/golang-ann... 📦 Download: go.dev/dl/#go1.26.1 #golang
  • 7
  • 30
  • 0
  • 14h ago

Overview

  • Hikvision Cameras

06 May 2017
Published
06 Mar 2026
Updated

CVSS
Pending
EPSS
94.26%

Description

An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 160530, DS-2CD2xx0F-I Series V5.2.0 build 140721 to V5.4.0 Build 160401, DS-2CD2xx2FWD Series V5.3.1 build 150410 to V5.4.4 Build 161125, DS-2CD4x2xFWD Series V5.2.0 build 140721 to V5.4.0 Build 160414, DS-2CD4xx5 Series V5.2.0 build 140721 to V5.4.0 Build 160421, DS-2DFx Series V5.2.0 build 140805 to V5.4.5 Build 160928, and DS-2CD63xx Series V5.0.9 build 140305 to V5.3.5 Build 160106 devices. The improper authentication vulnerability occurs when an application does not adequately or correctly authenticate users. This may allow a malicious user to escalate his or her privileges on the system and gain access to sensitive information.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added five actively exploited vulnerabilities affecting Hikvision, Rockwell, and Apple products to its KEV catalog. - IOCs: CVE-2017-7921, CVE-2021-22681, CVE-2023-41974 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

03 Mar 2021
Published
06 Mar 2026
Updated

CVSS
Pending
EPSS
22.71%

Description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added five actively exploited vulnerabilities affecting Hikvision, Rockwell, and Apple products to its KEV catalog. - IOCs: CVE-2017-7921, CVE-2021-22681, CVE-2023-41974 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Apple
  • iOS and iPadOS

10 Jan 2024
Published
06 Mar 2026
Updated

CVSS
Pending
EPSS
0.71%

Description

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17. An app may be able to execute arbitrary code with kernel privileges.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Bluesky

Profile picture fallback
~Cisa~ CISA added five actively exploited vulnerabilities affecting Hikvision, Rockwell, and Apple products to its KEV catalog. - IOCs: CVE-2017-7921, CVE-2021-22681, CVE-2023-41974 - #CISA #KEV #ThreatIntel #Vulnerability
  • 0
  • 1
  • 0
  • 20h ago

Overview

  • PostgreSQL

12 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.08%

KEV

Description

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Bluesky

Profile picture fallback
Critical security advisory for the fediverse: RLSA-2026:3887 patches three RCE vulnerabilities (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006) in PostgreSQL 16 on #Rocky Linux 10. Read more: 👉 tinyurl.com/jaamsfek #Security
  • 0
  • 0
  • 1
  • 5h ago

Overview

  • PostgreSQL

12 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.07%

KEV

Description

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Bluesky

Profile picture fallback
Critical security advisory for the fediverse: RLSA-2026:3887 patches three RCE vulnerabilities (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006) in PostgreSQL 16 on #Rocky Linux 10. Read more: 👉 tinyurl.com/jaamsfek #Security
  • 0
  • 0
  • 1
  • 5h ago

Overview

  • AWS
  • AWS-LC

02 Mar 2026
Published
03 Mar 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.02%

KEV

Description

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

Statistics

  • 2 Posts

Last activity: 19 hours ago

Bluesky

Profile picture fallback
Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338) #patchmanagement
  • 0
  • 0
  • 1
  • 19h ago

Overview

  • Google
  • Chrome

04 Mar 2026
Published
05 Mar 2026
Updated

CVSS
Pending
EPSS
0.07%

KEV

Description

Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
Google、Chromeの致命的な脆弱性3件を含む脆弱性 10件を修正(CVE-2026-3536,CVE-2026-3537,CVE-2026-3538) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • PostgreSQL

12 Feb 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.12%

KEV

Description

Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

Statistics

  • 2 Posts

Last activity: 5 hours ago

Bluesky

Profile picture fallback
Critical security advisory for the fediverse: RLSA-2026:3887 patches three RCE vulnerabilities (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006) in PostgreSQL 16 on #Rocky Linux 10. Read more: 👉 tinyurl.com/jaamsfek #Security
  • 0
  • 0
  • 1
  • 5h ago

Overview

  • TP-Link Systems Inc.
  • Tapo C260 v1

10 Feb 2026
Published
11 Feb 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.16%

KEV

Description

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Getting a Shell on the Tapo C260 Webcam (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) spaceraccoon.dev/getting-shell

  • 0
  • 0
  • 0
  • 4h ago
Showing 71 to 80 of 105 CVEs