CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,853
Known exploited
1,782
Sources online
24
Last sync
5H AGO
9,404 records · page 20 / 189 · nvd firehose hidden — show all

GHSA-c96f-x56v-gq3h: find-my-way: DDoS with HTTP2

Impact Remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The short version is that lookup() passes req.method into find(), and find() indexes this.trees[method]. Since this.trees is a normal object, HTTP/2 method values like constructor, toString

highCVSS 7.5CVE-2026-47219ghsa2026-07-23

USN-8601-1: PAM vulnerability

It was discovered that PAM had a timing discrepancy in the pam_userdb module when comparing plaintext passwords. An attacker could possibly use this issue to obtain sensitive information by measuring response-timing differences during repeated authentication attempts.

unknownCVE-2026-54411ubuntu2026-07-23

USN-8600-1: libXpm vulnerability

Naoki Wakamatsu discovered that libXpm did not properly validate file boundaries when processing XPM image files. An attacker could possibly use this issue to cause libXpm to crash, resulting in a denial of service.

unknownCVE-2026-4367ubuntu2026-07-23

JetBrains security advisory (AV26-739)

Serial number: AV26-739 Date: July 23, 2026 On July 23, 2026, JetBrains published security advisories to address vulnerabilities in the following products: JetBrains GoLand - versions prior to 2026.2 JetBrains IntelliJ IDEA - version prior to 2026.2 JetBrains PhpStorm - version p

unknowncccs2026-07-23

USN-8599-1: HTTP-Date vulnerability

It was discovered that HTTP-Date incorrectly handled parsing certain date strings. An attacker could possibly use this issue to cause HTTP-Date to use excessive resources, leading to a denial of service.

unknownCVE-2026-14741ubuntu2026-07-23

USN-8598-1: rsyslog vulnerabilities

It was discovered that rsyslog incorrectly handled regex-based TCP framing in the imptcp module. A remote attacker could possibly use this issue to cause rsyslog to crash, resulting in a denial of service. It was discovered that rsyslog incorrectly handled oversized RFC5424 struc

unknownCVE-2026-61548ubuntu2026-07-23

Check Point security advisory (AV26-735) – Update 1

Serial number: AV26-735 Date: July 22, 2026 Updated: July 23, 2026 On July 22, 2026, Check Point published a security advisory to address vulnerabilities in the following products. Included was a critical update for the following : Security Management, Multi-Domain Management – m

criticalexploitedpublic exploitCVE-2026-16232cccs2026-07-23

Rockwell Automation ThinManager

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected:

criticalCVE-2026-11917cisa2026-07-23

Johnson Controls XAAP Android

View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected: XAAP Android <1.53 CVSS Vendor Equipment Vulnerabilities v3 3.3 Jo

criticalCVE-2026-34490cisa2026-07-23

MZ Automation lib60870

View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870 <=2.4.0 CVSS Vendor Equipment Vulnerabilities v3 8.2 MZ Automati

criticalCVE-2026-16002cisa2026-07-23
← NewerOlder →