24h | 7d | 30d

Overview

  • Linux
  • Linux

25 Jul 2026
Published
19 Aug 2026
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Support for hardening against JIT spraying The BPF JIT allocator packs many small programs into larger executable allocations and reuses space within those allocations as programs are loaded and freed. When fresh code is written into space that a previous program occupied, an indirect jump into the new program can reuse a branch prediction left behind by the old one. Flush the indirect branch predictors before reusing JIT memory so that indirect jumps into a newly written program don't reuse predictions from an old program that occupied the same space. Introduce bpf_arch_pred_flush_enabled static key and bpf_arch_pred_flush static call for flushing the branch predictors on JIT memory reuse. Architectures that need a flush, can update it to a predictor flush function. By default, its a NOP and does not emit any CALL. Allocations larger than a pack are not covered by this flush. That is safe because cBPF programs (the unprivileged attack surface) are bounded well below a pack size. Issue a warning if this assumption is ever violated while the flush is active.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
📢 [VULN] 5 minutes pour voler le hash du mot de passe root avec BTR, une variante de Spectre v2 - CVE-2026-64507 CVE-2026-64508. La nouvelle attaque BTR est capable de dérober le hash du mot de passe root sur une machine Linux équipée d'un processeur Intel récent, en 3 à 5 minut… #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Viidure
  • Dashcam Android Application

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
0.34%

KEV

Description

The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, including the ability to read, modify, or delete operational files such as firmware and application binaries.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CISA warns the Viidure dashcam app leaks hardcoded cloud credentials (CVE-2026-96587) and public storage (CVE-2026-94204). The vendor has not responded.

securityonline.info/viidure-da

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Python Software Foundation
  • CPython

30 Sep 2026
Published
01 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.51%

KEV

Description

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certificate per server name) and nothing else keeps the original ssl.SSLContext alive. Typical cases are servers that create an SSLContext per connection or replace it while connections are open; servers that wrap their listening socket with it are not affected. Mitigation: keep a reference to every SSLContext that sets sni_callback for the lifetime of the server. TLS clients are not affected.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CPython developers fixed critical Python SSL vulnerabilities. Update now to resolve these Python SSL vulnerabilities and protect secure network sockets.

securityonline.info/python-ssl

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • checkpoint
  • Quantum Security Gateway

09 Sep 2026
Published
23 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
7.55%

Description

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

From Check Point Research: Exploitation of CVE-2026-85102 and CVE-2026-93616

Check Point has observed active exploitation of two critical pre-authentication vulnerabilities with CVSS scores of 9.8 - CVE-2026-85102 and CVE-2026-93616. The flaws affect Security Gateway and Security Management products and can enable remote code execution. Fixes for both vulnerabilities are available.

blog.checkpoint.com/security/s

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Viidure
  • Dashcam Android Application

29 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.27%

KEV

Description

The central cloud storage backend for the entire dashcam platform is misconfigured with public-read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CISA warns the Viidure dashcam app leaks hardcoded cloud credentials (CVE-2026-96587) and public storage (CVE-2026-94204). The vendor has not responded.

securityonline.info/viidure-da

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Python Software Foundation
  • CPython

30 Sep 2026
Published
01 Oct 2026
Updated

CVSS v4.0
HIGH (7.6)
EPSS
0.47%

KEV

Description

ssl.SSLContext.wrap_bio() didn't require the server_hostname argument to not be None if ssl.SSLContext.check_hostname was set. Due to a missing parameter check in SSLObject, if the server_hostname argument isn't supplied then hostname verification would be silently skipped. This defect could lead to programs where certificate hostname verification *appeared* to be succeeding with SSLContext.check_hostname = True and no ValueError being raised due to misconfiguration. If the program passes a server_hostname value that isn't an empty string or None to any of these APIs then certificate hostname verification proceeds as expected and the program is not affected by this vulnerability. Mitigating this vulnerability doesn't require updating Python or applying the patch. To mitigate, pass a valid non-None and non-empty server_hostname value to SSLContext.wrap_bio(), asyncio.create_connection(), or asyncio.loop.start_tls() and certificate hostname verification will proceed as expected. Upgrading to the latest version of Python or applying the patch only changes the behavior from silently skipping hostname verification to raising a ValueError, similar to SSLContext.wrap_socket(), when server_hostname isn't supplied.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CPython developers fixed critical Python SSL vulnerabilities. Update now to resolve these Python SSL vulnerabilities and protect secure network sockets.

securityonline.info/python-ssl

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Kiteworks
  • Core

30 Sep 2026
Published
01 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.53%

KEV

Description

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset link and then authenticate as that user, including where the account holds administrative privileges.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Kiteworks vulnerabilities fixed in 9.5.1 include CVE-2026-102115, a 9.8 password reset flaw that enables admin account takeover. Patch now.

securityonline.info/kiteworks-

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Apache Software Foundation
  • Apache MINA SSHD
  • org.apache.sshd:sshd-ldap

30 Sep 2026
Published
30 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.55%

KEV

Description

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure an LdapPasswordAuthenticator to be used for password authentication. Normal password authentication via the built-in mechanisms in sshd-core is _not_ affected by this vulnerability, which concerns only LdapPasswordAuthenticator. Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Eight Apache MINA SSHD vulnerabilities allow authentication bypass. Fix critical Apache MINA SSHD vulnerabilities by upgrading your Java apps now.

securityonline.info/apache-min

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Apache Software Foundation
  • Apache MINA SSHD
  • org.apache.sshd:sshd-ldap

30 Sep 2026
Published
30 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.55%

KEV

Description

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and server-side SSH. The optional sshd-ldap component provides support for integrating password and publickey authentication on the server side with an LDAP server. sshd-ldap is an optional component. SSH servers implemented with Apache MINA SSHD are affected only if they use sshd-ldap and do configure it to be used for password of public key authentication. Other Apache MINA SSHD servers are not affected. Lack of escaping LDAP filter metacharacters enabled successful authentication with username "*" and password "*". Users are recommended to upgrade affected applications to version 2.20.0 or 3.0.0-M6, which fix this issue by properly escaping filter parameters according to RFC 4515.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Eight Apache MINA SSHD vulnerabilities allow authentication bypass. Fix critical Apache MINA SSHD vulnerabilities by upgrading your Java apps now.

securityonline.info/apache-min

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • CODESYS
  • CODESYS Development System

01 Dec 2025
Published
01 Dec 2025
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.16%

KEV

Description

An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.

Statistics

  • 1 Post

Last activity: 9 hours ago

Fediverse

Profile picture fallback

🔒 New CSAF advisory published

VDE-2025-081
WAGO: Multiple PLCs and Communication Components are Affected by multiple Vulnerabilities leading to RCE
CVE-2025-41700, CVE-2025-41738, CVE-2025-41739

Multiple WAGO devices are affected by CODESYS Control vulnerabilities. The affected WAGO firmware versions are <4.10.0 (FW32) and <4.10.0 (70).

HTML: certvde.com/en/advisories/vde-
CSAF JSON: wago.csaf-tp.certvde.com/.well

  • 0
  • 0
  • 0
  • 9h ago
Showing 71 to 80 of 87 CVEs