Vulnerability Alerts

Vulnerability Alerts

CVEs, zero-days, exploits, and security advisories

VULNhighCVE-2025-702909.8 CRITICALFull Disclosure10 days ago

Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293)

VULNhighCVE-2025-702909.8 CRITICALFull Disclosure10 days ago

[ADVISORY] Multiple Integer Overflows in U-Boot Filesystem Parsing (CVE-2025-70290 through CVE-2025-70293)

VULNFull Disclosure10 days ago

JSON Deserialiser Unconstrained Resource Consumption Proof of Concept

VULNFull Disclosure10 days ago

Dovecot Security Advisory 3/2026

VULNMicrosoft Security11 days ago

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

VULNPalo Alto Unit 4212 days ago

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

VULNMicrosoft Security13 days ago

​​​​​​What’s new in Microsoft Security: August 2026

VULNRecorded Future13 days ago

BlueDelta Targets Defense and Diplomacy with HOOKEDGE

VULNCVE-2026-650536.1 MEDIUMFull Disclosure14 days ago

FD - Half-click unauthenticated remote code execution on Horde Groupware IMP (from a stored XSS)

VULNhighCVE-2026-00138.4 HIGHFull Disclosure14 days ago

[NotCVE-2026-0013] CHIRP Kenwood ITM Driver Eval Injection Allows Arbitrary Code Execution via Crafted Radio File

VULNhighCVE-2026-00126.2 MEDIUMFull Disclosure14 days ago

[NotCVE-2026-0012] EmpManageX Hardcoded Administrative Credentials in Login API Allow Full Access to Employee Records

VULNhighCVE-2026-00118.4 HIGHFull Disclosure14 days ago

[NotCVE-2026-0011] Nmap 7.99 and Earlier nselib/packet.lua Zero-Length TCP Option Infinite Loop Allows Remote Denial of Service

FD
VULNhighCVE-2026-00108.4 HIGHFull Disclosure14 days ago

[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM

FD
VULNhighCVE-2026-00097.8 HIGHFull Disclosure14 days ago

[NotCVE-2026-0009] NitroShare Desktop 0.3.4 Path Traversal Allows LAN-Adjacent Arbitrary File Write

VULNMicrosoft Security14 days ago

When AI infrastructure becomes the target: Securing gateways and control points

VULNFull Disclosure14 days ago

Escargot v4.3.0-214-gfaee4437 Unauthenticated Remote Debugger Allows Arbitrary JavaScript Evaluation and Local File Disclosure

VULNFull Disclosure14 days ago

Escargot v4.3.0-214-gfaee4437 OS Command Injection in Crash Handler via Unsanitized Executable Path

VULNFull Disclosure14 days ago

Escargot v4.3.0-214-gfaee4437 Debugger WebSocket Off-by-One Stack Buffer Overflow

VULNFull Disclosure14 days ago

UltraJSON v5.13.0-6-g733f9e1 Length-Boundary Violation Causes Out-of-Bounds Read During Incomplete JSON Parsing

VULNFull Disclosure14 days ago

Realtek edimax 52fc10d19 In-Band Ioctl Response Length Confusion Causes Heap Buffer Overflow

VULNFull Disclosure14 days ago

WatsonWebserver v7.1.0 HTTP/1 Chunked Request Processing Bypasses MaxRequestBodySize

FD
VULNFull Disclosure14 days ago

Chronicle Wire v2026.8 Arbitrary Class Instantiation During YAML Deserialization via Externally Controlled YAML Type Tags

FD
VULNFull Disclosure14 days ago

Chronicle Wire v2026.8 Insecure Reflection Allows Unvalidated Method Invocation

VULNFull Disclosure14 days ago

Chronicle Wire v2026.8 FileMarshallableOut Append Operations Follow Symbolic Links and Allow File Write Redirection

VULNhighFull Disclosure14 days ago

Multiple Vulnerabilities in TBEA TLogger Communication Box 3rd Generation

FD
VULNcriticalFull Disclosure14 days ago

[0day-rubbish] VitalPBX 4.5.2 (Asterisk 20.20.1) Authenticated root RCE via asterisk_cli to dialplan System() (8.8)

FD
VULNcriticalFull Disclosure14 days ago

[0day-rubbish] Seeq Server R65.2.3 (default deployment with Data Lab installed via the official CLI) Unauthenticated RCE (open self-registration + Data Lab Jupyter missing authorization) (9.8)

FD
VULNcriticalFull Disclosure14 days ago

[0day-rubbish] Raritan EMX firmware emx_ecx_3.6.1_46982 (EMX/ECX gateway) Authenticated config injection to root RCE (8.8)

FD
VULNcriticalFull Disclosure14 days ago

[0day-rubbish] mySCADA PRO Runtime 9.4.0 (container deployment msxrun; earlier versions with the same upgrade branch are likely affected) Unauthenticated OS command injection to root RCE (9.4)

FD
VULNcriticalFull Disclosure14 days ago

[0day-rubbish] Maian Gallery v2.1 Authenticated unrestricted file upload to PHP RCE (7.2)