security-flaw
130 articles with this tag
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
CRITICAL
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
MEDIUM
INFO
INFO
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
LOW
MEDIUM
MEDIUM
MEDIUM
MEDIUM
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
Millions of vehicles vulnerable to Bluetooth car theft attacks
Leaking internal headers in Flask Ninja with deserialization
[NEU] [mittel] Netty: Mehrere Schwachstellen
USN-8570-1: Linux kernel vulnerabilities
[NEU] [mittel] Proxmox Virtual Environment: Mehrere Schwachstellen
[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [mittel] IBM i: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
CVE-2026-15714 Libsoup: soupmultipartinputstream: libsoup: out-of-bounds read in soup_multipart_input_stream_read_headers via an oversized multipart boundary string
CVE-2026-15712 Soupclientmessageiohttp2: libsoup3: libsoup: http/2 goaway frame parsing heap buffer over-read via invalid nul-termination assumption
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index
CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values
VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations
[NEU] [hoch] Netty: Mehrere Schwachstellen
Multiples vulnérabilités dans Wireshark (09 juillet 2026)
[NEU] [hoch] n8n: Mehrere Schwachstellen
[NEU] [hoch] rclone: Mehrere Schwachstellen
[NEU] [hoch] GitLab: Mehrere Schwachstellen
USN-8518-1: mailcap vulnerability
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
[NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen
Citrix Products Multiple Vulnerabilities
Secret Service lax phone security puts leaders at risk, report finds
CVE-2026-3634 Libsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-3632 Libsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-5119 Libsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
CVE-2026-3633 Libsoup: libsoup: header and http request injection via crlf injection
CVE-2026-3099 Libsoup: libsoup: authentication bypass via digest authentication replay attack
Multiples vulnérabilités dans le noyau Linux de Debian (26 juin 2026)
Multiples vulnérabilités dans les produits IBM (26 juin 2026)
Multiples vulnérabilités dans le noyau Linux de SUSE (26 juin 2026)
Multiples vulnérabilités dans Tenable Nessus (26 juin 2026)
Multiples vulnérabilités dans le noyau Linux de Red Hat (26 juin 2026)
Multiples vulnérabilités dans Asterisk (26 juin 2026)
[UPDATE] [mittel] Red Hat Enterprise Linux: Mehrere Schwachstellen in verschiedenen Komponenten
[UPDATE] [mittel] Red Hat Advanced Cluster Management: Mehrere Schwachstellen
Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed
Decades-Old Squid Proxy Flaw ‘Squidbleed’ Can Expose User Data
Vulnérabilité dans CPython pour Windows (22 juin 2026)
[NEU] [hoch] LiteLLM: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Critical Copilot vulnerability allowed hackers to seal 2FA code from users
[NEU] [hoch] Langflow: Mehrere Schwachstellen
[NEU] [mittel] Drupal: Mehrere Schwachstellen
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
Multiples vulnérabilités dans Apache HTTP Server (09 juin 2026)
Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals
CVE-2025-13462 tarfile: Skip DIRTYPE normalization during GNU LONGNAME/LONGLINK handling
Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
CVE-2026-45494 Microsoft Edge (Chromium-based) Spoofing Vulnerability
[NEU] [mittel] Samsung Exynos: Mehrere Schwachstellen
CVE-2026-42013 Gnutls: gnutls: certificate validation bypass due to oversized subject alternative name
CVE-2026-42015 Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling
Multiples vulnérabilités dans les produits Mattermost (29 mai 2026)
[NEU] [hoch] Synacor Zimbra: Mehrere Schwachstellen
[NEU] [mittel] Kibana: Mehrere Schwachstellen
[NEU] [hoch] Red Hat Enterprise Linux (Flatpak): Mehrere Schwachstellen
[NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen
[NEU] [mittel] Mattermost Server und Plugins: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff
USN-8325-1: tgt vulnerability
USN-8322-1: Apache Commons BeanUtils vulnerability
FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework
CVE-2026-43619 Rsync < 3.4.3 Symlink Race Condition via Path-Based Syscalls
CVE-2026-43618 Rsync < 3.4.3 Integer Overflow Information Disclosure
CVE-2026-43620 Rsync < 3.4.3 Out-of-Bounds Array Read via recv_files()
Google publishes exploit code threatening millions of Chromium users
USN-8276-1: Highlight.js vulnerability
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments
AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem?
[NEU] [hoch] BigBlueButton: Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [hoch] Adobe Connect: Mehrere Schwachstellen
Claude in Chrome is taking orders from the wrong extensions
[NEU] [mittel] MISP: Schwachstelle ermöglicht Cross-Site Scripting
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
Cline Kanban Flaw Lets Websites Hijack AI Coding Agents
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
Max-severity RCE flaw found in Google Gemini CLI
[NEU] [mittel] Dell integrated Dell Remote Access Controller: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [hoch] Xen und Citrix Systems XenServer: Mehrere Schwachstellen
[NEU] [hoch] OpenClaw: Mehrere Schwachstellen
Over 6,400 Apache ActiveMQ servers at risk of ongoing attacks
LABScon25 Replay | Are Your Chinese Cameras Spying For You Or On You?
Microsoft issues out-of-band patch for critical security flaw in update to ASP.NET Core
Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876)
Lovable AI coding platform faces scrutiny over data exposure
[NEU] [mittel] OpenBao: Mehrere Schwachstellen
[NEU] [hoch] nginx-ui: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
CVE-2026-3849 Buffer Overflow in HPKE via Oversized ECH Config
CVE-2026-3579 Non-constant time multiplication subroutine __muldi3 on RISC-V RV32I
CVE-2026-2645 Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
CVE-2026-2646 Heap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2026-33416 LIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
CVE-2026-33671 Picomatch has a ReDoS vulnerability via extglob quantifiers
CVE-2026-33895 Forge has signature forgery in Ed25519 due to missing S > L check
CVE-2026-33896 Forge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)