[UPDATE] [low] expat: Vulnerability allows Denial of Service
A local attacker can exploit a vulnerability in expat to conduct a Denial of Service attack.
● Live advisory feed
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
A local attacker can exploit a vulnerability in expat to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in Fortinet FortiSandbox to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Fortinet FortiClient EMS to bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in Fortinet FortiOS and Fortinet FortiProxy to bypass security measures, manipulate data, and disclose information.
An attacker can exploit multiple vulnerabilities in Fortinet FortiOS and Fortinet FortiProxy to execute arbitrary code, conduct a Cross Site Scripting attack, and manipulate data.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - Cryptographic API; - DMA engine subsystem; - Infini…
A remote, authenticated attacker can exploit a vulnerability in Grafana to disclose information.
A remote, authenticated attacker can exploit a vulnerability in Grafana to bypass security measures.
An attacker can exploit multiple vulnerabilities in Microsoft SQL Server and Microsoft Power BI to escalate privileges, execute arbitrary code, present false information, and disclose information.
An attacker can exploit multiple vulnerabilities in Microsoft Exchange to execute arbitrary code, gain elevated permissions, or conduct spoofing attacks.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Block layer subsystem; - Cryptographic API; - DMA engine subsystem; - Infini…
A remote, anonymous attacker can exploit a vulnerability in Microsoft Dynamics NAV to execute arbitrary code.
A local attacker can exploit a vulnerability in several Microsoft Surface products to gain administrator rights.
An attacker can exploit multiple vulnerabilities in Microsoft Malware Protection Engine and Microsoft Defender to execute arbitrary code, gain elevated permissions, or disclose sensitive information.
A remote, anonymous attacker can exploit a vulnerability in Spotfire Server to bypass security measures.
An attacker can exploit multiple vulnerabilities in Zabbix to conduct a denial of service attack and to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in IBM App Connect Enterprise and IBM Integration Bus to execute arbitrary code.
An attacker can exploit multiple vulnerabilities in Apple macOS to disclose information, conduct a denial of service attack, bypass security measures, manipulate files, and escalate their privileges.
An attacker can exploit multiple vulnerabilities in cPanel/WHM to manipulate files and disclose confidential information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apple macOS Sequoia, Sonoma, and Ventura to gain root privileges, execute arbitrary code, cause a denial-of-service condition, disclose confidential information, alter data, or bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux (jq) to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in wget to conduct an unspecified attack.
A remote anonymous attacker can exploit a vulnerability in OpenSSL to execute arbitrary code, cause a denial-of-service condition, disclose confidential information, and manipulate data.
A remote, anonymous attacker can exploit a vulnerability in OpenSSL to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in BusyBox to manipulate files.
A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux in python-pillow to conduct a Denial of Service attack and disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in NGINX to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Python to conduct a Denial of Service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in Elasticsearch to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in win.rar WinRAR to execute arbitrary program code.
An attacker can exploit multiple vulnerabilities in NATS Server to execute arbitrary code, gain elevated permissions, bypass security measures, manipulate or disclose data, or cause a Denial-of-Service condition.
An attacker can exploit multiple vulnerabilities in Apple macOS to bypass security measures, conduct a Denial of Service attack, disclose information, manipulate files, and escalate privileges.
A remote, authenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux to execute arbitrary program code, and potentially to carry out a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in NGINX and NGINX Plus to manipulate files.
A remote, anonymous attacker can exploit multiple vulnerabilities in Eclipse Jetty to conduct a Denial of Service attack, bypass security measures, and disclose confidential information.
An attacker from an adjacent network can exploit a vulnerability in Siemens SIMATIC S7 to carry out a denial of service attack.
A remote, authenticated attacker can exploit multiple vulnerabilities in rclone to read and write arbitrary files, as well as disclose information and bypass security mechanisms.
A remote, authenticated attacker can exploit a vulnerability in etcd to bypass security measures.
A remote, anonymous attacker can exploit multiple vulnerabilities in ffmpeg to conduct a Denial of Service attack.
An attacker can exploit multiple vulnerabilities in Erlang/OTP to conduct a denial of service attack, disclose information, and bypass security measures.
Installer of HYPER SBI 2 provided by SBI SECURITIES Co.,Ltd. insecurely loads Dynamic Link Libraries.
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
Multiple vulnerabilities have been discovered in Microsoft Office. They allow an attacker to cause remote arbitrary code execution, privilege escalation, and a data confidentiality breach.
Multiple vulnerabilities have been discovered in Citrix products. Some of them allow an attacker to cause privilege escalation, data confidentiality breaches, and a security policy bypass.
Multiple vulnerabilities have been discovered in Microsoft Windows. Some of them allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service. Microsoft states that the vulnerability CVE-2026-56155...
KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device.