● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak Component.
The KeycloakSecurityPolicy of camel-keycloak guards a route by running KeycloakSecurityProcessor.beforeProcess(), which …
Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component.
The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operation parameter is not …
An attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in Internet Systems Consortium BIND to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Gitea to bypass security measures, disclose information, conduct a cross-site scripting attack, and manipulate files.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or perform other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in libarchive to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack and cause unspecified effects.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or other unspecified attacks.
A remote, anonymous attacker can exploit a vulnerability in FasterXML Jackson to conduct a Denial of Service attack.
A local attacker can exploit a vulnerability in FasterXML Jackson to disclose information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to manipulate data or trigger a Denial of Service.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack or an unspecified attack.
A remote anonymous or authenticated attacker can exploit multiple vulnerabilities in Eclipse Jetty to generate a Denial of Service attack and manipulate data.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack and achieve further unspecified impacts.
A local attacker can exploit multiple vulnerabilities in Linux Kernel to conduct a Denial of Service attack or carry out an unspecified attack.
A remote anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to conduct a Denial of Service attack.
A remote anonymous attacker can exploit a vulnerability in Apache Ivy to disclose information.
A remote authenticated attacker can exploit multiple vulnerabilities in Eclipse Jetty to execute arbitrary code, bypass security measures, or conduct an HTTP cache poisoning attack.
A remote anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to conduct a Denial of Service attack or disclose information.
A remote anonymous attacker can exploit multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform to execute arbitrary code, conduct a Cross-Site Scripting attack, disclose information, create a Denial of Service state, or bypass security measures.
An attacker can exploit multiple vulnerabilities in FasterXML Jackson to conduct a Denial of Service attack.
A remote authenticated attacker can exploit multiple vulnerabilities in Gitea to escalate privileges, bypass security measures, manipulate data, disclose confidential information, or cause a Denial of Service state.
An attacker can exploit multiple vulnerabilities in MediaWiki to conduct an unspecified attack, disclose information, execute arbitrary program code, and conduct a cross-site scripting attack.
An attacker can exploit multiple vulnerabilities in Gitea to gain elevated privileges, impersonate users, bypass security measures, manipulate data, and disclose confidential information.
An attacker can exploit multiple vulnerabilities in Gitea to disclose information, bypass security precautions, and conduct a cross-site scripting attack.
A remote, anonymous attacker can exploit a vulnerability in Eclipse Jetty to manipulate data.
A remote attacker can exploit a vulnerability in libarchive to execute arbitrary code.
A local attacker can exploit a vulnerability in Red Hat Enterprise Linux (ncurses) to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in Gitea to potentially gain elevated privileges, bypass security measures, or manipulate and disclose data.
A remote, anonymous attacker can exploit multiple vulnerabilities in libarchive to disclose information and to create a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in Eclipse Jetty to bypass security measures.
Multiple vulnerabilities have been discovered in OpenSSH. Some of them allow an attacker to bypass security policy, cause a denial of service, and an unspecified security issue by the vendor.
Multiple vulnerabilities have been discovered in Roundcube. Some of them allow an attacker to cause a remote denial of service, server-side request forgery (SSRF), and indirect remote code injection (XSS).
A vulnerability has been discovered in PostgreSQL JDBC. It allows an attacker to bypass security policy.
Multiple security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in information disclosure, code execution via unsafe deserialisation or cross-site scripting. https://security-tracker.debian.org/tracker/DSA-6380-1
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. https://security-tracker.debian.org/tracker/DSA-6378-1
Multiple security vulnerabilities were discovered in the BIRD internet routing daemon, which could result in denial of service. https://security-tracker.debian.org/tracker/DSA-6379-1
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. https://security-tracker.debian.org/tracker/DSA-6381-1
It was discovered that a buffer overflow in the implementation of AES Key Wrap with Padding in the openssl extension of PHP, a widely-used open source general purpose scripting language, could result in memory corruption. https://security-tracker.debian.org/tracker/DSA-6377-1
Serial number: AV26-651 Date: July 3, 2026 On July 2, 2026, Erlang published security advisories to address vulnerabilities in the following products: OTP – versions prior to 27.3.4.14, 28.5.0.3 and 29.0.3 SSL (OTP) – versions prior to 11.7.3, 11.6.0.3 and 11.2.12.10 The Cyber Ce…
Serial number: AV26-650 Date: July 3, 2026 On June 30, 2026, GitHub published security advisories to address vulnerabilities in the following products: GitHub Enterprise Server – versions 3.21.x prior to 3.21.2 GitHub Enterprise Server – versions 3.20.x prior to 3.20.4 GitHub Ent…
Serial number: AV26-649 Date: July 3, 2026 On July 2, 2026, WatchGuard published security advisories to address vulnerabilities in the following products: Fireware OS 2025.1 – version 2026.2 and prior Fireware OS 11.x - version 11.12.4_Update1 and prior Fireware OS 12.0 – version…
A remote, anonymous attacker can exploit multiple vulnerabilities in WatchGuard Firebox to execute arbitrary code, cause a denial of service, manipulate or disclose data, and perform cross-site scripting attacks.
An attacker can exploit multiple vulnerabilities in ffmpeg to conduct an unspecified attack or to cause a denial-of-service condition.
An attacker can exploit a vulnerability in ffmpeg to execute arbitrary code, and potentially to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in ffmpeg to conduct a denial of service attack.