24h | 7d | 30d

Overview

  • Mozilla
  • Firefox

02 Jun 2026
Published
15 Jul 2026
Updated

CVSS
Pending
EPSS
0.72%

KEV

Description

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.

Statistics

  • 2 Posts
  • 11 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Update Firefox, the Tor browser, and other derivatives if you are still running FF versions 147 through to 151.0.2.

Some interesting attacks exploiting CVE-2026-10702 are shoring up:

thehackernews.com/2026/07/rese

Note that thanks to Android's lazy sandbox,
this attack can be used as the entry point of a complete browser-to-kernel chain, giving the attacker root (CVE-2026-43499).

(Unclear if/how Firefox-ESR is affected)

#infosec

  • 4
  • 7
  • 0
  • 19h ago

Overview

  • SolarWinds
  • Web Help Desk

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.64%

KEV

Description

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.

securityonline.info/solarwinds

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
~Cybergcca~ Canadian Cyber Centre issued 3 advisories covering SolarWinds SAML bypass, Rails RCE, and Google Chrome vulnerabilities. - IOCs: CVE-2026-28323, CVE-2026-66066 - #CVE2026 #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • codeigniter4
  • CodeIgniter4

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.45%

KEV

Description

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploaded content outside the intended directory when the application exposes an upload path. This issue is fixed in version 4.7.4.

Statistics

  • 2 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-63222 - Path traversal in CodeIgniter. UploadedFile::move() unsanitized filename lets attackers write outside intended directory. CVSS 7.5. Update to 4.7.4 immediately. #CVE #CodeIgniter #infosec

valtersit.com/cve/CVE-2026-632

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Google
  • Chrome

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS
Pending
EPSS
0.36%

KEV

Description

Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Chrome CVE Report for the 2026-07-29 Stable channel: tbljrmp60k.joplinusercontent.c

Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)

Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)

Largest bounty: $36,000 β€” CVE-2026-17657 (Use after free in Navigation)

  • 1
  • 2
  • 0
  • 8h ago

Overview

  • Phoenix Contact
  • CHARX SEC-3150

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.40%

KEV

Description

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

CVE-2026-44090 - Critical missing auth in May MQTT broker. Unauthenticated remote access leads to full device compromise. CVSS 9.8. No patch available - isolate immediately. #CVE #infosec #IoT

valtersit.com/cve/CVE-2026-440

  • 1
  • 0
  • 0
  • 21h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.40%

KEV

Description

Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.

GitHub: github.com/777erp/CVE-2026-491

The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.

  • 0
  • 1
  • 0
  • 3h ago

Overview

  • Toptech Systems
  • RCU II+

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.28%

KEV

Description

The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service that does not require any authentication, allowing an attacker to directly interact with the Linux environment that powers the device. Once connected, an attacker can freely view and modify the filesystem, manipulate running processes, and control network interfaces, enabling deep alteration of system behavior.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-12562 – Unauthenticated TCF debug interface in Phoenix Contact RCU II+ and Multiload II+ grants full root access. CVSS 8.8. No patch yet. Isolate devices and restrict network exposure. #CVE #PhoenixContact #infosec

valtersit.com/cve/CVE-2026-125

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

03 Mar 2021
Published
06 Mar 2026
Updated

CVSS
Pending
EPSS
50.71%

Description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

Statistics

  • 2 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

Rockwell's own advisory says CVE-2021-22681 has no patch, ever, just "defense in depth." Five years unpatched, now weaponized against 30+ Minnesota towns running PLCs on consumer cellular modems nobody budgeted to secure.
tenable.com/blog/coordinated-c

  • 0
  • 0
  • 1
  • 6h ago

Overview

  • Zimbra
  • Collaboration

05 Jan 2026
Published
19 Mar 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
21.62%

Description

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
Laundry Bear Exploits Zimbra Zero-Click Vulnerability CVE-2025-66376 for Espionage https://malware-log.hatenablog.com/entry/2026/07/24/000000 https://flagthis.com/tldr/5520 ##Zimbra ##LaundryBear ##VoidBlizzard ##ZeroDay ##Espionage
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • zephyrproject
  • zephyr
  • zephyr

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
HIGH (7.6)
EPSS
Pending

KEV

Description

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0). Per the public GATT API, a notify callback with NULL data is the documented signal that the subscription has terminated and the bt_gatt_subscribe_params struct may be freed or reused by the application; calling subscribe() on the struct afterwards is a use-after-free, including an indirect call through the freed params->subscribe function pointer. The error branch is remotely (adjacent) reachable: a Zephyr device acting as a GATT client that calls bt_gatt_subscribe() can be driven into this ordering when a connected GATT server peer answers the CCC write with an ATT Error Response (the peer-supplied error code flows through att_error_rsp -> att_handle_rsp into gatt_write_ccc_rsp). For applications that free or recycle subscription parameters in their notification-termination handler, this results in memory corruption, a crash (denial of service), or potentially attacker-influenced control flow. The fix reorders the handler so the subscribe() callback runs before the terminating notify(NULL) in both the error and unsubscribe paths.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending β€” apply mitigations. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 5h ago
Showing 11 to 20 of 49 CVEs