CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

● Live advisory feed

Security Advisory Fusion for CSIRTs, SOCs & Defenders

Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.

Advisories tracked
20,889
Known exploited
1,782
Sources online
24
Last sync
2H AGO
9,404 records · page 28 / 189 · nvd firehose hidden — show all

GHSA-qf2f-qh6p-7v89: Gitea CVE-2026-20800 sibling endpoints not covered: revoked user still reads private repo objects via `/api/v1/user/starred` and private issue titles via `/api/v1/user/times`

Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - GET /api/v1/user/starred — getStarredRepos() co

mediumCVSS 4.3CVE-2026-59766ghsa2026-07-21

HPE security advisory (AV26-727)

Serial number: AV26-727 Date: July 22, 2026 On July 21, 2026, HPE published security advisories to address vulnerabilities in the following products. Include was a critical update for the following: HPE Aruba Networking Private 5G Core – versions 1.26.1.1 and prior HPE Aruba Netw

criticalCVE-2026-48020cccs2026-07-21
← NewerOlder →