24h | 7d | 30d

Overview

  • X.Org
  • xorg-x11-server
  • xorg-x11-server

08 Jul 2026
Published
08 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.0)
EPSS
0.22%

KEV

Description

Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

We released the #XLibre Xserver 25.0.0.25, 25.1.9, and beta 25.2.2 during the last 4 days containing #security fixes for #CVE-2026-55999 and CVE-2026-56000. We recommend everyone update ASAP.

github.com/X11Libre/xserver/re
github.com/X11Libre/xserver/re
github.com/X11Libre/xserver/re

  • 3
  • 2
  • 0
  • 7h ago

Overview

  • X.Org
  • xorg-server
  • xorg-server

08 Jul 2026
Published
09 Jul 2026
Updated

CVSS v3.1
HIGH (8.5)
EPSS
0.27%

KEV

Description

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap buffer overflow via SetFont due to missing glyph boundary checks.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

We released the #XLibre Xserver 25.0.0.25, 25.1.9, and beta 25.2.2 during the last 4 days containing #security fixes for #CVE-2026-55999 and CVE-2026-56000. We recommend everyone update ASAP.

github.com/X11Libre/xserver/re
github.com/X11Libre/xserver/re
github.com/X11Libre/xserver/re

  • 3
  • 2
  • 0
  • 7h ago

Overview

  • PowerDNS
  • Recursor
  • pdns-recursor

23 Jul 2026
Published
23 Jul 2026
Updated

CVSS v3.1
LOW (3.7)
EPSS
0.11%

KEV

Description

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-52688、 CVE-2026-52686) https://jprs.jp/tech/security/2026-07-27-powerdns-recursor.html
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • PowerDNS
  • Recursor
  • pdns-recursor

23 Jul 2026
Published
23 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.13%

KEV

Description

RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
PowerDNS Recursorの脆弱性情報が公開されました(CVE-2026-52688、 CVE-2026-52686) https://jprs.jp/tech/security/2026-07-27-powerdns-recursor.html
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • redis
  • redis

05 May 2026
Published
16 Jul 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
3.30%

KEV

Description

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This is patched in version 8.6.3.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.

meterpreter.org/redis-rce-expl

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • RedisBloom
  • RedisBloom

05 May 2026
Published
05 May 2026
Updated

CVSS v4.0
HIGH (7.7)
EPSS
1.38%

KEV

Description

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code execution. A workaround is to restrict access to the RESTORE command with ACL rules. This issue is fixed in version 2.8.20.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Discover how new Redis RCE exploit PoC code bypasses fixes for CVE-2026-25243 and CVE-2026-25589 across multiple Redis versions.

meterpreter.org/redis-rce-expl

  • 0
  • 0
  • 0
  • 10h ago
Showing 31 to 36 of 36 CVEs