● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The following versions of Rockwell Automation ThinManager are affected:…
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zim…
View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. The following vers…
A remote, authenticated attacker can exploit multiple vulnerabilities in pg_partman to perform a denial of service attack, bypass authorization, and conduct SQL injection attacks, allowing them to gain elevated privileges and execute arbitrary operating system commands.
An attacker can exploit multiple vulnerabilities in Samba to execute arbitrary code, conduct a denial of service attack, manipulate files, and bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in PowerDNS to bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in ffmpeg to execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.
A remote, authenticated attacker can exploit a vulnerability in Grafana to carry out a denial of service attack.
An attacker can exploit multiple vulnerabilities in n8n to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, perform an SQL injection attack, and execute arbitrary code.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a Denial of Service attack, manipulate data, and perform other unspecified attacks.
A local attacker can exploit multiple vulnerabilities in the Linux Kernel to conduct a denial of service attack or carry out a non-specific attack.
USN-8322-1 fixed a vulnerability in Apache Commons BeanUtils. It was discovered that for Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for CVE-2014-0114 and CVE-2019-10086 was incorrectly dropped. This update reintroduces the fix for CVE-2014-0114 and CVE-…
A remote, anonymous attacker can exploit a vulnerability in Mitel MiCollab to execute arbitrary code.
An attacker can exploit multiple vulnerabilities in MongoDB to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, cause memory corruption, or trigger a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in RabbitMQ to conduct denial-of-service attacks, bypass authorization and tenant boundaries, manipulate or disclose data, and perform cross-site scripting attacks.
A remote, authenticated attacker can exploit a vulnerability in Mitel OpenScape to conduct a cross-site scripting attack.
An attacker can exploit multiple vulnerabilities in Budibase to gain elevated permissions, perform SQL injection, bypass security measures, take over accounts, manipulate or disclose data, and trigger a denial-of-service condition.
A remote, authenticated attacker can exploit a vulnerability in Red Hat Advanced Cluster Management and Multicluster engine for Kubernetes to execute arbitrary program code or cause a denial-of-service condition.
A remote, anonymous attacker can exploit multiple vulnerabilities in libpng to execute arbitrary program code or cause a Denial of Service.
A remote, authenticated attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server Liberty to elevate their privileges, bypass security measures, and disclose information.
An attacker can exploit multiple vulnerabilities in IBM QRadar SIEM to execute arbitrary code, disclose information, conduct a denial of service attack, perform a cross-site scripting attack, and manipulate files.
A local attacker can exploit a vulnerability in vim to execute arbitrary code.
A remote, authenticated attacker can exploit a vulnerability in OpenSSL to bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in GStreamer to cause a denial-of-service state, perform memory corruption, and potentially execute arbitrary code.
An attacker can exploit multiple vulnerabilities in various Intel Ethernet products to create a denial-of-service condition and disclose confidential information.
A remote, anonymous attacker can exploit multiple vulnerabilities in libTIFF to conduct a denial of service attack.
A remote anonymous attacker can exploit multiple vulnerabilities in libTIFF to create a denial-of-service condition.
A local attacker can exploit a vulnerability in GNU tar to bypass security measures.
A local attacker can exploit a vulnerability in systemd to bypass security measures and manipulate data.
A local attacker can exploit a vulnerability in IBM i to execute arbitrary program code.
A remote, anonymous attacker can exploit a vulnerability in rsyslog to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Apache Tomcat to bypass security measures, disclose confidential information, manipulate data, trigger a Denial-of-Service condition, or conduct other unspecified attacks.
An attacker can exploit multiple vulnerabilities in dnsmasq to cause a denial-of-service condition, execute arbitrary code with root privileges, disclose confidential information, manipulate data, and redirect users to malicious domains.
A local attacker can exploit a vulnerability in expat to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in MIT Kerberos to conduct a denial of service attack.
A local attacker can exploit a vulnerability in the giflib component in Red Hat Enterprise Linux to corrupt memory, potentially leading to a denial-of-service state or the execution of arbitrary code.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Microsoft Visual Studio Code, .NET Framework, Microsoft .NET, Visual Studio 2022, and Visual Studio 2026 to gain elevated permissions, including administrative rights, execute arbitrary code, bypass security measures, manipulate…
A remote, anonymous attacker can exploit a vulnerability in IBM WebSphere Application Server Liberty to conduct a denial of service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.
A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Apache Tomcat to bypass security measures, cause a Denial-of-Service condition, conduct Cross-Site Scripting attacks, or trigger other unspecified impacts.
A remote, anonymous attacker can exploit a vulnerability in dnsmasq to disclose information.
A remote, anonymous attacker can exploit a vulnerability in dnsmasq to conduct a Denial of Service attack.
A remote, authenticated attacker can exploit a vulnerability in MIT Kerberos to carry out an unspecified attack.
An attacker can exploit multiple vulnerabilities in various versions of Microsoft Windows and Microsoft Windows Server to gain administrative rights, execute arbitrary code, bypass security measures, manipulate and disclose data, or conduct spoofing attacks.
A remote, anonymous attacker can exploit multiple vulnerabilities in MariaDB to conduct an unspecified attack.
An attacker can exploit multiple vulnerabilities in IBM HTTP Server to execute arbitrary program code and to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Splunk Splunk Enterprise to bypass security measures, manipulate data, disclose confidential information, or cause a Denial-of-Service condition.
A remote, authenticated attacker can exploit a vulnerability in NetApp Data ONTAP to bypass security measures.