CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
21,654
Known exploited
1,794
Sources online
24
Last sync
22M AGO
9,646 records · page 111 / 193 · nvd firehose hidden — show all

Broadcom VMware security advisory (AV26-625)

Serial number: AV26-625 Date: June 23, 2026 Between June 22 and 23, 2026, Broadcom published security advisories to address vulnerabilities in multiple products. Included were critical updates for the following: VMware Tanzu Data Flow on Kubernetes – versions prior to 2.1.3 VMwar

criticalcccs2026-06-23

Siemens SIPROTEC 5 Using DIGSI5 Protocol

View CSAF Summary SIPROTEC 5 is vulnerable to arbitrary file uploads by authenticated users using the DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, potentially causing a permanent denial of service condition. As a mitigation measure, user

unknownCVE-2025-40808cisa2026-06-23

ABB Freelance Security Lock

View CSAF Summary Successful exploitation of this vulnerability could allow access to underlying OS functions even when Freelance Operations is active, depending on system configuration and user permissions. The following versions of ABB Freelance Security Lock are affected: ABB

criticalCVE-2025-7064cisa2026-06-23

Siemens Products using OpenSSL

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to u

unknownCVE-2025-15467cisa2026-06-23

GHSA-35c4-rvc8-frhm: Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials

Summary The Budibase server route POST /api/attachments/:datasourceId/url (packages/server/src/api/routes/static.ts) is registered with only the recaptcha middleware. There is no authorized(...) middleware in the chain. The controller (packages/server/src/api/controllers/static/

highCVSS 9.4CVE-2026-50137ghsa2026-06-22

GHSA-c4v7-xg93-qf8g: Gogs has SSRF in webhook deliveries

Summary The fix for CVE-2022-1285 prevents adding webooks or running webhooks with URLs with a hostname that resolves in localCIDRs. However, webhooks still follow redirects allowing to access hostname inside localCIDRs. This was already communicated in the initial report but it

highCVSS 8.3CVE-2026-47267ghsa2026-06-22
← NewerOlder →