24h | 7d | 30d

Overview

  • WebPros
  • cPanel

09 Sep 2026
Published
10 Sep 2026
Updated

CVSS v3.0
CRITICAL (9.9)
EPSS
0.96%

KEV

Description

A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Six advisories address vulnerabilities; CVE-2026-71362 is reportedly exploited in the wild. - IOCs: CVE-2026-71362, CVE-2026-67401, CVE-2026-65638 - #CVE202671362 #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • AVEVA
  • Pipeline Integrity Monitor

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.31%

KEV

Description

The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
~Cisa~ Four flaws enable data disclosure, hash cracking, unauthorized reads, or XSS; patch to 2025 SP1 P2. - IOCs: CVE-2026-81821, CVE-2026-81822, CVE-2026-81823 - #CVE #ICS #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • AVEVA
  • Pipeline Integrity Monitor

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v4.0
HIGH (8.3)
EPSS
0.11%

KEV

Description

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
~Cisa~ Four flaws enable data disclosure, hash cracking, unauthorized reads, or XSS; patch to 2025 SP1 P2. - IOCs: CVE-2026-81821, CVE-2026-81822, CVE-2026-81823 - #CVE #ICS #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
~Cisa~ Mirth Connect ≤4.7.1 flaws enable SQL injection, XXE, data exfiltration and denial of service; update to 4.7.2+. - IOCs: CVE-2026-82583, CVE-2026-78224, CVE-2026-82578 - #CVE-2026-78224 #CVE-2026-82583 #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
~Cisa~ Mirth Connect ≤4.7.1 flaws enable SQL injection, XXE, data exfiltration and denial of service; update to 4.7.2+. - IOCs: CVE-2026-82583, CVE-2026-78224, CVE-2026-82578 - #CVE-2026-78224 #CVE-2026-82583 #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
25.14%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Six advisories address vulnerabilities; CVE-2026-71362 is reportedly exploited in the wild. - IOCs: CVE-2026-71362, CVE-2026-67401, CVE-2026-65638 - #CVE202671362 #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • AVEVA
  • Pipeline Integrity Monitor

08 Sep 2026
Published
08 Sep 2026
Updated

CVSS v4.0
HIGH (8.3)
EPSS
0.14%

KEV

Description

The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
~Cisa~ Four flaws enable data disclosure, hash cracking, unauthorized reads, or XSS; patch to 2025 SP1 P2. - IOCs: CVE-2026-81821, CVE-2026-81822, CVE-2026-81823 - #CVE #ICS #ThreatIntel
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
~Cisa~ Mirth Connect ≤4.7.1 flaws enable SQL injection, XXE, data exfiltration and denial of service; update to 4.7.2+. - IOCs: CVE-2026-82583, CVE-2026-78224, CVE-2026-82578 - #CVE-2026-78224 #CVE-2026-82583 #ThreatIntel
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • grpc
  • grpc-go

20 Mar 2026
Published
10 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
1.56%

KEV

Description

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g., `Service/Method` instead of `/Service/Method`). While the server successfully routed these requests to the correct handler, authorization interceptors (including the official `grpc/authz` package) evaluated the raw, non-canonical path string. Consequently, "deny" rules defined using canonical paths (starting with `/`) failed to match the incoming request, allowing it to bypass the policy if a fallback "allow" rule was present. This affects gRPC-Go servers that use path-based authorization interceptors, such as the official RBAC implementation in `google.golang.org/grpc/authz` or custom interceptors relying on `info.FullMethod` or `grpc.Method(ctx)`; AND that have a security policy contains specific "deny" rules for canonical paths but allows other requests by default (a fallback "allow" rule). The vulnerability is exploitable by an attacker who can send raw HTTP/2 frames with malformed `:path` headers directly to the gRPC server. The fix in version 1.79.3 ensures that any request with a `:path` that does not start with a leading slash is immediately rejected with a `codes.Unimplemented` error, preventing it from reaching authorization interceptors or handlers with a non-canonical path string. While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation); infrastructure-level normalization; and/or policy hardening.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • micromatch
  • picomatch

26 Mar 2026
Published
27 Mar 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.40%

KEV

Description

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) when processing crafted extglob patterns. Certain patterns using extglob quantifiers such as `+()` and `*()`, especially when combined with overlapping alternatives or nested extglobs, are compiled into regular expressions that can exhibit catastrophic backtracking on non-matching input. Applications are impacted when they allow untrusted users to supply glob patterns that are passed to `picomatch` for compilation or matching. In those cases, an attacker can cause excessive CPU consumption and block the Node.js event loop, resulting in a denial of service. Applications that only use trusted, developer-controlled glob patterns are much less likely to be exposed in a security-relevant way. This issue is fixed in picomatch 4.0.4, 3.0.2 and 2.3.2. Users should upgrade to one of these versions or later, depending on their supported release line. If upgrading is not immediately possible, avoid passing untrusted glob patterns to `picomatch`. Possible mitigations include disabling extglob support for untrusted patterns by using `noextglob: true`, rejecting or sanitizing patterns containing nested extglobs or extglob quantifiers such as `+()` and `*()`, enforcing strict allowlists for accepted pattern syntax, running matching in an isolated worker or separate process with time and resource limits, and applying application-level request throttling and input validation for any endpoint that accepts glob patterns.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

🔄 CSAF advisory updated (version 2.0.0)

VDE-2026-088
METTLER TOLEDO: LabX Standard and Enterprise Report on External Component Analysis - v21.4
CVE-2026-4800, CVE-2026-33186, CVE-2026-39821, CVE-2026-33671, CVE-2026-0915 (+60 more)

Changes: corrected version

HTML: certvde.com/en/advisories/VDE-
CSAF JSON: mettler-toledo.csaf-tp.certvde

  • 0
  • 0
  • 0
  • 21h ago
Showing 71 to 80 of 83 CVEs