● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
It was discovered that Gzip's gzexe utility handled temporary files in an insecure manner. When the mktemp utility was not available, gzexe constructed a temporary file path based on the process ID, which could be predicted. A local attacker could possibly use this issue to overw…
It was discovered that socat incorrectly handled the SOCKS5 proxy server reply parser. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2026-56123) It was discovered that socat incorrectly handled a sample script. A local attacker could possibly use…
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a cra…
It was discovered that tar incorrectly handled symlinks when extracting archives. An attacker could possibly use this issue to overwrite arbitrary files.
It was discovered that Python incorrectly normalized paths in the tarfile module. An attacker could possibly use this issue to bypass path restrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-13462) It was discovered that Python's HTMLParser inc…
An attacker can exploit multiple vulnerabilities in Microsoft Windows and Windows Server to escalate privileges, execute arbitrary code, conduct a denial of service attack, bypass security measures, disclose information, and present false information.
A remote, authenticated attacker can exploit a vulnerability in Pega Platform to escalate privileges.
A remote, authenticated attacker can exploit a vulnerability in WSO2 API Manager to disclose information.
An attacker can exploit multiple vulnerabilities in Samsung Exynos to conduct a denial of service attack or disclose confidential information.
An attacker can exploit multiple vulnerabilities in Apache Camel to bypass security measures and execute arbitrary code.
An attacker can exploit multiple vulnerabilities in Apache Camel to execute arbitrary program code, manipulate data, or disclose confidential information.
A remote, authenticated attacker can exploit a vulnerability in Apache Camel to manipulate data.
A remote, authenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux to execute arbitrary program code.
A remote anonymous attacker can exploit multiple vulnerabilities in Red Hat products to manipulate files, execute arbitrary code, and create a denial-of-service condition.
An attacker can exploit multiple vulnerabilities in Apache Commons to carry out an unspecified attack.
A remote anonymous attacker can exploit multiple vulnerabilities in Apache Camel to create a denial-of-service condition.
A remote, anonymous attacker can exploit a vulnerability in various http/2 implementations to carry out a denial of service attack.
A local attacker can exploit a vulnerability in Puppet to disclose information.
An attacker can exploit a vulnerability in n8n to execute arbitrary program code, which can lead to data exfiltration, service interruptions, or complete system compromise.
A local attacker can exploit a vulnerability in Dell Computer to bypass security measures.
A remote, authenticated attacker can exploit a vulnerability in Icinga to display false information.
An attacker can exploit multiple vulnerabilities in Keycloak to disclose information, bypass security measures, manipulate data, or gain elevated privileges.
A remote, anonymous attacker can exploit a vulnerability in lxml to disclose information.
Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component.
The camel-dns producers read DNS operation parameters - the resolver to query, the name or domain to look up, the record type and class, and the search term - from Exchange…
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.
The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which …
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not …
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in Internet Systems Consortium BIND to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Gitea to bypass security measures, disclose information, conduct a cross-site scripting attack, and manipulate files.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or perform other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in libarchive to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack and cause unspecified effects.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in FasterXML Jackson to conduct a Denial of Service attack.
A local attacker can exploit a vulnerability in FasterXML Jackson to disclose information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to manipulate data or trigger a Denial of Service.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack or an unspecified attack.
A remote anonymous or authenticated attacker can exploit multiple vulnerabilities in Eclipse Jetty to generate a Denial of Service attack and manipulate data.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack and achieve further unspecified impacts.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack or carry out an unspecified attack.
A remote anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to conduct a Denial of Service attack.
A remote authenticated attacker can exploit multiple vulnerabilities in Eclipse Jetty to execute arbitrary code, bypass security measures, or conduct an HTTP cache poisoning attack.
A remote anonymous attacker can exploit a vulnerability in Apache Ivy to disclose information.
A remote anonymous attacker can exploit multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform to execute arbitrary code, conduct a Cross-Site Scripting attack, disclose information, create a Denial of Service state, or bypass security measures.
A remote anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to conduct a Denial of Service attack or disclose information.
An attacker can exploit multiple vulnerabilities in FasterXML Jackson to conduct a Denial of Service attack.
A remote authenticated attacker can exploit multiple vulnerabilities in Gitea to escalate privileges, bypass security measures, manipulate data, disclose confidential information, or cause a Denial of Service state.
An attacker can exploit multiple vulnerabilities in MediaWiki to conduct an unspecified attack, disclose information, execute arbitrary program code, and conduct a cross-site scripting attack.
An attacker can exploit multiple vulnerabilities in Gitea to gain elevated privileges, impersonate users, bypass security measures, manipulate data, and disclose confidential information.
An attacker can exploit multiple vulnerabilities in Gitea to disclose information, bypass security precautions, and conduct a cross-site scripting attack.