CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,853
Known exploited
1,782
Sources online
24
Last sync
1H AGO
20,853 records · page 7 / 418 · showing all sources — curated view

CVE-2026-18446: fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward slash) is parsed with no authorit

highCVSS 7.5CVE-2026-18446nvd2026-07-31

CVE-2026-10685: The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback w

highCVSS 7.6CVE-2026-10685nvd2026-07-31

Google security advisory (AV26-768)

Serial number: AV26-768 Date: July 31, 2026 As of July 30, 2026, Google is affected by vulnerabilities in the following product: Chrome - Prior to 151.0.7922.72 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as

unknowncccs2026-07-31

CVE-2026-65636: Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inject arbitrary content into generated YAML documents through

Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ymlr (Elixir.Ymlr module) allows attackers to inject arbitrary content into generated YAML documents through document comments. Ymlr.document!/2 interpolates each caller-supplied comment string into the output

unknownCVE-2026-65636nvd2026-07-31

CVE-2026-18358: A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasse

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-au

highCVSS 7.5CVE-2026-18358nvd2026-07-31

Rails security advisory (AV26-767)

Serial Number: AV26-767 Date: July 31, 2026 As of July 30, 2026, Rails is affected by a vulnerability in the following product: Rails Prior to 8.0.5.1 Prior to 8.1.3.1 Prior to 7.2.3.2 The Cyber Centre encourages users and administrators to review the provided web links and apply

unknownpublic exploitCVE-2026-66066cccs2026-07-31

SolarWinds security advisory (AV26-766)

Serial number: AV26-766 Date: July 30, 2026 As of July 30, 2026, SolarWinds is affected by a vulnerability in the following product: Web Help Desk (WHD) Prior to 2026.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary

unknownCVE-2026-28323cccs2026-07-31

CVE-2026-46594: A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when ope

A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. This issue was fixed in vers

unknownCVE-2026-46594nvd2026-07-31

CVE-2026-46593: A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint al

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminPolls.controller.php endpoint allows an authenticated attacker to perform SQL Injection attacks. This issue was fixed in version 4.1

unknownCVE-2026-46593nvd2026-07-31

CVE-2025-67651: A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSite attributes allows an attacker to send unauthorized requests in the context of an authenticated user, leading to unauthorized admi

unknownCVE-2025-67651nvd2026-07-31

CVE-2025-67650: An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an authenticated user into parameters responsible for sorting functions allows an attacker to perform SQL Injection attacks. This issue w

unknownCVE-2025-67650nvd2026-07-31

CVE-2025-67649: A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting fun

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into parameters responsible for sorting functions allows an unauthenticated attacker to perform SQL Injection attacks. This issue was fixed in

unknownCVE-2025-67649nvd2026-07-31
← NewerOlder →