● Live advisory feed
Security Advisory Fusion for CSIRTs, SOCs & Defenders
Security advisories from 24 sources — CISA, CERT-EU, NCSC-UK, BSI, CERT-FR, NCSC-NL, JPCERT/CC, JVN, HKCERT, the Canadian Cyber Centre, NVD, GitHub, Microsoft, Cisco, Fortinet, Palo Alto Networks and more — normalized, translated to English and flagged against the CISA KEV catalog. One global feed for CSIRTs, SOCs and defenders.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - RISC-V architecture; - Cryptographic API; - InfiniBand drivers; - IOMMU subsystem; - Network drive…
A remote, anonymous attacker can exploit a vulnerability in Kyocera Printer to disclose information.
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - x86 architecture; - Block layer…
A remote, authenticated attacker can exploit multiple vulnerabilities in Django to perform SQL injections, disclose confidential information, or cause a Denial-of-Service condition.
A remote, authenticated attacker can exploit a vulnerability in MISP to bypass security measures.
An attacker can exploit multiple vulnerabilities in RabbitMQ to execute arbitrary code, gain elevated privileges, bypass security measures, conduct cross-site scripting attacks, manipulate data, disclose confidential information, or cause a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in LangChain to disclose information.
A remote, anonymous attacker can exploit a vulnerability in vllm to execute arbitrary code.
A local attacker can exploit a vulnerability in Python to conduct a path traversal attack.
A local attacker can exploit a vulnerability in CPython to manipulate files.
A local attacker can exploit a vulnerability in CPython to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Red Hat OpenShift Container Platform to conduct a Denial of Service attack.
A local attacker can exploit multiple vulnerabilities in Xen to escalate their privileges and conduct an unspecified attack.
An attacker can exploit a vulnerability in CPython regarding Base64 data to conduct an unspecified attack.
A remote, anonymous attacker can exploit a vulnerability in cPython to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit a vulnerability in libpng to conduct a Denial of Service attack and disclose information.
A remote, anonymous attacker can exploit multiple vulnerabilities in Python to conduct a Denial of Service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in libpng to conduct a Denial of Service attack and execute code.
An attacker can exploit multiple vulnerabilities in Vercel Next.js to bypass security precautions, conduct cross-site scripting attacks, manipulate data, disclose confidential information, or cause a denial-of-service condition.
A remote, anonymous attacker can exploit a vulnerability in the zipfile module of CPython to manipulate files.
An attacker can exploit multiple vulnerabilities in Xen to carry out a denial-of-service attack, disclose information, or escalate privileges.
An attacker can exploit multiple vulnerabilities in Palo Alto Networks PAN-OS to perform a Cross-Site Scripting attack, execute arbitrary code, bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition.
A remote, anonymous attacker can exploit a vulnerability in Python to carry out a denial of service attack.
A local attacker can exploit a vulnerability in Palo Alto Networks Cortex XDR Broker VM to escalate their privileges.
A remote, anonymous attacker can exploit a vulnerability in Python to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in GStreamer to carry out a denial of service attack.
An attacker can exploit multiple vulnerabilities in Coolify to execute arbitrary code, escalate privileges, disclose information, present false information, manipulate files, conduct a denial of service attack, and bypass security measures.
An attacker can exploit multiple vulnerabilities in Splunk Splunk Enterprise to bypass security measures, disclose confidential information, manipulate data, execute code, cause a denial-of-service condition, and cause further unspecified impacts.
A remote, authenticated attacker can exploit a vulnerability in Python to disclose information.
A remote, authenticated attacker can exploit a vulnerability in Python to manipulate files.
A remote, anonymous attacker can exploit a vulnerability in Python to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in cURL to disclose information.
A remote, anonymous attacker can exploit multiple vulnerabilities in GStreamer to conduct a denial of service attack.
A local attacker can exploit a vulnerability in Python and Red Hat Enterprise Linux to execute arbitrary program code.
An attacker from an adjacent network can exploit a vulnerability in TianoCore EDK2 to conduct a denial of service attack.
A remote, anonymous attacker can exploit a vulnerability in cURL to bypass security measures.
A remote, authenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux to manipulate files.
A remote, anonymous attacker can exploit a vulnerability in Python to conduct a denial of service attack.
A remote, anonymous or local attacker can exploit multiple vulnerabilities in NGINX NGINX Plus and NGINX to conduct a denial of service attack.
A remote, anonymous attacker can exploit multiple vulnerabilities in Python to manipulate files and bypass security measures.
A local attacker can exploit a vulnerability in TianoCore EDK2 to conduct a denial of service attack.
An attacker can exploit multiple vulnerabilities in Python to execute arbitrary code or cause a denial-of-service condition.
An attacker from the adjacent network or a remote, anonymous attacker can exploit multiple vulnerabilities in the EDK2 NetworkPkg IP stack implementation to execute arbitrary program code, disclose confidential information, and trigger a denial of service condition.
A remote, anonymous attacker can exploit a vulnerability in Python to bypass security mechanisms or achieve other effects.
A remote, anonymous attacker can exploit multiple vulnerabilities in Apache CXF to execute arbitrary program code, manipulate data, and disclose confidential information.
A remote, anonymous attacker can exploit a vulnerability in Python to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Python to bypass security measures.
A remote, anonymous attacker can exploit a vulnerability in Python to carry out a Denial of Service attack.
A local attacker can exploit a vulnerability in Python to elevate their privileges.
A remote, anonymous attacker can exploit a vulnerability in Python to execute arbitrary program code.