CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,853
Known exploited
1,782
Sources online
24
Last sync
3H AGO
9,404 records · page 17 / 189 · nvd firehose hidden — show all

GHSA-w8x7-h2px-xmq8: Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings

Summary When an authenticated recipient of a single-file share opens the file event stream (GET /api/v4/file/events?uri=<share-root>), Cloudreve validates the URI by listing it and then subscribes the caller to parent.ID(). For a single-file share, the share navigator resolves t

mediumCVSS 4.3CVE-2026-55499ghsa2026-07-24

Progress security advisory (AV26-746)

Serial number: AV26-746 Date: July 24, 2026 On July 23, 2026, Progress published security advisories to address vulnerabilities in the following product: MOVEit Transfer – versions prior to 2025.1.5 MOVEit Transfer – versions prior to 2026.0.3 The Cyber Centre encourages users an

unknowncccs2026-07-24

HPE security advisory (AV26-745)

Serial number: AV26-745 Date: July 24, 2026 On July 24, 2026, HPE published a security advisory to address vulnerabilities in the following product: HPE Unified Correlation Analyzer (UCA) – versions 4.4.11 and prior The Cyber Centre encourages users and administrators to review t

unknowncccs2026-07-24

MongoDB security advisory (AV26-744)

Serial number: AV26-744 Date: July 24, 2026 On July 22, 2026, MongoDB published security advisories to address vulnerabilities in the following products: MongoDB Compass – versions prior to 1.49.7 MongoDB Server – versions prior to 7.0.39 MongoDB Server – versions prior to 8.0.28

unknowncccs2026-07-24

Ericsson security advisory (AV26-743)

Serial number: AV26-743 Date: July 24, 2026 On July 24, 2026, Ericsson published a security advisory to address vulnerabilities in the following product: Packet Core Controller (PCC) – versions prior to 1.38 Packet Core Controller (PCC) – versions prior to 1.39 The Cyber Centre e

unknowncccs2026-07-24
← NewerOlder →