24h | 7d | 30d

Overview

  • IBM
  • Langflow OSS

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.42%

KEV

Description

IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-12942 - Path Traversal in IBM Langflow OSS. Remote attackers can read arbitrary files via /../ sequences. CVSS 7.5. No patch yet - restrict access immediately. #CVE #Langflow #infosec

valtersit.com/cve/CVE-2026-129

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • AT&T
  • Arris BGW210‑700

28 Jul 2026
Published
28 Jul 2026
Updated

CVSS
Pending
EPSS
0.25%

KEV

Description

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management endpoints, relying solely on client‑side CSS/JavaScript gating that can be bypassed by any HTTP client. This allows unauthenticated attackers on the LAN to read sensitive configuration data, modify persistent device settings, or trigger backend diagnostic operations. The issue appears systemic across the CGI handler chain.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

The Arris BGW210-700 vulnerability, CVE-2026-16771, is an authentication bypass in AT&T's gateway. A LAN user can read the WiFi password.

securityonline.info/arris-bgw2

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • openremote
  • openremote

25 Jul 2026
Published
29 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.39%

KEV

Description

OpenRemote before 1.26.2 contains an authentication bypass vulnerability in the console registration API that allows unauthenticated attackers to update existing console assets by supplying a known asset identifier. Attackers can overwrite push notification tokens and console metadata without authentication or ownership validation, redirecting notifications or denying delivery to legitimate consoles.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.

securityonline.info/openremote

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.74%

KEV

Description

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
borncity.com/blog/2026/07/31/v

  • 1
  • 2
  • 1
  • 12h ago

Bluesky

Profile picture fallback
VMware vCenterに認証回避とRCEの脆弱性、CVE-2026-59309とCVE-2026-59310はCVSS 9.8 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
borncity.com/blog/2026/07/31/v

  • 1
  • 2
  • 1
  • 12h ago

Bluesky

Profile picture fallback
VMware vCenterに認証回避とRCEの脆弱性、CVE-2026-59309とCVE-2026-59310はCVSS 9.8 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

  • 3
  • 1
  • 0
  • 9h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.

CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.

CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.

github.com/globaleaks/globalea and github.com/globaleaks/globalea

  • 3
  • 1
  • 0
  • 9h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
0.60%

KEV

Description

Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
WindowsイベントログサービスのRPCインターフェースで脆弱性(CVE-2026-50502)、修正済みのCVE-2025-29969検証ロジックの盲点を突くPoCが公開 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.

securityonline.info/openam-cve

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • IBM
  • WebSphere Application Server

29 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
0.33%

KEV

Description

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to server-side request forgery (SSRF) when the SIP container feature (sipServlet-1.1) is enabled.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.

securityonline.info/ibm-websph

  • 0
  • 0
  • 0
  • 21h ago
Showing 31 to 40 of 50 CVEs