24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
20 Jul 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
5.60%

Description

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Canadian Cyber Centre flags 5 advisories; Microsoft and WordPress CVEs actively exploited in the wild. - IOCs: CVE-2026-56164, CVE-2026-60137, CVE-2026-63030 - #PatchNow #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Apache Software Foundation
  • Apache Fineract

15 Jul 2026
Published
15 Jul 2026
Updated

CVSS
Pending
EPSS
0.70%

KEV

Description

A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versions up to and including 1.14.0. The orderBy and sortOrder request parameters are concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view clients to inject arbitrary SQL via a crafted orderBy value. This can be leveraged to perform blind boolean-based data extraction and, on MySQL/MariaDB, to disclose arbitrary files readable by the database process via the LOAD_FILE() function. Users are recommended to upgrade to a version containing the fix

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.

securityonline.info/apache-fin

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Apache Software Foundation
  • Apache Fineract

15 Jul 2026
Published
15 Jul 2026
Updated

CVSS
Pending
EPSS
0.79%

KEV

Description

A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and including 1.14.0. The orderBy request parameter is concatenated into a SQL query without sufficient validation, allowing an authenticated user with permission to view offices to inject arbitrary SQL via a crafted orderBy value. This is a bypass of the ColumnValidator fix introduced for CVE-2024-32838, which does not detect bare subqueries in the ORDER BY position. This can be leveraged to perform time-based blind SQL injection for data exfiltration. Because the injected query blocks the database connection for its full duration, concurrent exploitation can exhaust the application's database connection pool, resulting in denial of service for other users. Users are recommended to upgrade to a version containing the fix.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Three Apache Fineract SQL injection flaws (CVE-2026-57821, CVE-2026-56287, CVE-2026-35152) let authenticated users exfiltrate data. Upgrade to 1.15.0.

securityonline.info/apache-fin

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Linux
  • Linux

27 Feb 2025
Published
18 Jul 2026
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: block: fix queue freeze vs limits lock order in sysfs store methods queue_attr_store() always freezes a device queue before calling the attribute store operation. For attributes that control queue limits, the store operation will also lock the queue limits with a call to queue_limits_start_update(). However, some drivers (e.g. SCSI sd) may need to issue commands to a device to obtain limit values from the hardware with the queue limits locked. This creates a potential ABBA deadlock situation if a user attempts to modify a limit (thus freezing the device queue) while the device driver starts a revalidation of the device queue limits. Avoid such deadlock by not freezing the queue before calling the ->store_limit() method in struct queue_sysfs_entry and instead use the queue_limits_commit_update_frozen helper to freeze the queue after taking the limits lock. This also removes taking the sysfs lock for the store_limit method as it doesn't protect anything here, but creates even more nesting. Hopefully it will go away from the actual sysfs methods entirely soon. (commit log adapted from a similar patch from Damien Le Moal)

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
🚨 ALERTA DE SEGURANÇA! O #Debian lançou o DSA-6393-1 com correções para 4 vulnerabilidades CRÍTICAS no kernel Linux (CVE-2025-21807, CVE-2026-46093, CVE-2026-53027 e CVE-2026-53226). Saiba mais . -> tinyurl.com/56s6t5hj
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Linux
  • Linux

27 May 2026
Published
18 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.13%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: mm/vmalloc: take vmap_purge_lock in shrinker decay_va_pool_node() can be invoked concurrently from two paths: __purge_vmap_area_lazy() when pools are being purged, and the shrinker via vmap_node_shrink_scan(). However, decay_va_pool_node() is not safe to run concurrently, and the shrinker path currently lacks serialization, leading to races and possible leaks. Protect decay_va_pool_node() by taking vmap_purge_lock in the shrinker path to ensure serialization with purge users.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
🚨 ALERTA DE SEGURANÇA! O #Debian lançou o DSA-6393-1 com correções para 4 vulnerabilidades CRÍTICAS no kernel Linux (CVE-2025-21807, CVE-2026-46093, CVE-2026-53027 e CVE-2026-53226). Saiba mais . -> tinyurl.com/56s6t5hj
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Linux
  • Linux

24 Jun 2026
Published
18 Jul 2026
Updated

CVSS
Pending
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked() When a compressed or sparse attribute has its clusters frame-aligned, vcn is rounded down to the frame start using cmask, which can result in vcn != vcn0. In this case, vcn and vcn0 may reside in different attribute segments. The code already handles the case where vcn is in a different segment by loading its runs before allocation. However, it fails to load runs for vcn0 when vcn0 resides in a different segment than vcn. This causes run_lookup_entry() to return SPARSE_LCN for vcn0 since its segment was never loaded into the in-memory run list, triggering the WARN_ON(1). Fix this by adding a missing check for vcn0 after the existing vcn segment check. If vcn0 falls outside the current segment range [svcn, evcn1), find and load the attribute segment containing vcn0 before performing the run lookup. The following scenario triggers the bug: attr_data_get_block_locked() vcn = vcn0 & cmask <- vcn != vcn0 after frame alignment load runs for vcn segment <- vcn0 segment not loaded! attr_allocate_clusters() <- allocation succeeds run_lookup_entry(vcn0) <- vcn0 not in run -> SPARSE_LCN WARN_ON(1) <- bug fires here!

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
🚨 ALERTA DE SEGURANÇA! O #Debian lançou o DSA-6393-1 com correções para 4 vulnerabilidades CRÍTICAS no kernel Linux (CVE-2025-21807, CVE-2026-46093, CVE-2026-53027 e CVE-2026-53226). Saiba mais . -> tinyurl.com/56s6t5hj
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Linux
  • Linux

25 Jun 2026
Published
18 Jul 2026
Updated

CVSS
Pending
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: gpio: rockchip: fix generic IRQ chip leak on remove The driver allocates domain generic chips using irq_alloc_domain_generic_chips() during probe. However, on driver remove/teardown, the generic chips are not automatically freed when the IRQ domain is removed because the domain flags do not include IRQ_DOMAIN_FLAG_DESTROY_GC. This causes both the domain generic chips structure and the associated generic chips to be leaked. Additionally, the generic chips remain on the global gc_list and may later be visited by generic IRQ chip suspend, resume, or shutdown callbacks after the GPIO bank has been removed, potentially resulting in a use-after-free and kernel crash. Fix the resource leak by explicitly calling irq_domain_remove_generic_chips() before removing the IRQ domain in rockchip_gpio_remove().

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
🚨 ALERTA DE SEGURANÇA! O #Debian lançou o DSA-6393-1 com correções para 4 vulnerabilidades CRÍTICAS no kernel Linux (CVE-2025-21807, CVE-2026-46093, CVE-2026-53027 e CVE-2026-53226). Saiba mais . -> tinyurl.com/56s6t5hj
  • 0
  • 0
  • 0
  • Last hour
Showing 71 to 77 of 77 CVEs