CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,857
Known exploited
1,782
Sources online
24
Last sync
3H AGO
9,404 records · page 24 / 189 · nvd firehose hidden — show all

GHSA-wvh6-f5jh-8gw4: Dompdf: Chroot Validation Bypass

Summary The chroot check for local files uses a prefix string check to enforce chroot boundaries. The simple string comparison it performs allows paths like /var/www/root_secret/file.html when chroot is /var/www/root. This allows attacker-controlled document paths/resources to b

lowCVE-2026-55554ghsa2026-07-22

Drupal security advisory (AV26-738)

Serial number: AV26-738 Date: July 22, 2026 On July 22, 2026, Drupal published security advisories to address a vulnerability in the following product. Included was a critical update for the following: Internationalization Single Sign-On – versions prior to 1.8.0 The Cyber Centre

criticalcccs2026-07-22

Exim security advisory (AV26-737)

Serial number: AV26-737 Date: July 22, 2026 On July 22, 2026, Exim published a security advisory to address a vulnerability in the following product: Exim – version 4.88 to 4.99.4 The Cyber Centre encourages users and administrators to review the provided web links and apply the

unknowncccs2026-07-22

Progress security advisory (AV26-736)

Serial number: AV26-736 Date: July 22, 2026 On July 21, 2026, Progress published security advisories to address vulnerabilities in the following product: ShareFile Storage Zones Controller v5 – versions prior to 5.12.4 ShareFile Storage Zones Controller v6 – versions prior to 6.0

unknowncccs2026-07-22

Mitel security advisory (AV26-734)

Serial number: AV26-734 Date: July 22, 2026 On July 22, 2026, Mitel published security advisories to address vulnerabilities in the following products. Included were critical updates for the following:: MiCollab – multiple versions OpenScape UC – multiple versions The Cyber Centr

criticalcccs2026-07-22

n8n security advisory (AV26-733)

Serial number: AV26-733 Date: July 22, 2026 On July 22, 2026, n8n published security advisories to address vulnerabilities in the following product: n8n – versions prior to 1.123.67 n8n – versions prior to 2.32.1 n8n – versions prior to 2.31.5 The Cyber Centre encourages users an

unknowncccs2026-07-22

ISC BIND security advisory (AV26-732)

Serial number: AV26-732 Date: July 22, 2026 On July 22, 2026, ISC published security advisories to address vulnerabilities in the following products: ISC BIND 9 – versions 9.11.0 to 9.18.50 ISC BIND 9 – versions 9.20.0 to 9.20.24 ISC BIND 9 – versions 9.21.0 to 9.21.23 BIND Suppo

unknowncccs2026-07-22

USN-8590-1: Exim vulnerabilities

It was discovered that Exim incorrectly handled certain command line options. A local attacker could possibly use this issue to access files outside of the spool area. It was discovered that Exim incorrectly handled string expansion in .local files. A local attacker could possibl

unknownubuntu2026-07-22

Atlassian security advisory (AV26-731)

Serial number: AV26-731 Date: July 22, 2026 On July 21, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products: Bamboo Data Center and Server – multiple versions Bitbucket Data Center and Server – multiple

criticalcccs2026-07-22

Google Chrome security advisory (AV26-730)

Serial number: AV26-730 Date: July 22, 2026 On July 21, 2026, Google published a security advisory to address vulnerabilities in the following product: Stable Channel Chrome for Desktop – versions prior to 150.0.7871.181/.182 (Windows/Mac), and 150.0.7871.181 (Linux) The Cyber Ce

unknowncccs2026-07-22

USN-8477-3: tar regression

USN-8477-1 fixed a vulnerability in tar. That fix was incomplete and could cause tar to fail to extract old archives that recorded a nonzero size for directory entries, resulting in a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory

unknownCVE-2026-5704ubuntu2026-07-22

Oracle security advisory – July 2026 quarterly rollup (AV26-729)

Serial number: AV26-729 Date: July 22, 2026 On July 21, 2026, Oracle published a security advisory to address vulnerabilities in multiple products. Included were critical updates for the following: Oracle Database Server Oracle APEX Oracle Autonomous Health Framework Oracle Essba

criticalcccs2026-07-22

USN-8587-1: HTML-Parser vulnerability

It was discovered that HTML-Parser incorrectly handled entity references when the input string was identical to an entity value in the lookup table. An attacker could possibly use this issue to obtain sensitive information.

unknownCVE-2026-8829ubuntu2026-07-22

USN-8583-1: GIFLIB vulnerabilities

It was discovered that GIFLIB incorrectly handled certain GIF image files. If a user or automated system were tricked into opening a specially crafted GIF file, a remote attacker could use this issue to cause GIFLIB to crash, resulting in a denial of service, or possibly execute

← NewerOlder →