24h | 7d | 30d

Overview

  • Microsoft
  • Windows 10 Version 1507

13 May 2025
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
1.06%

KEV

Description

Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
WindowsイベントログサービスのRPCインターフェースで脆弱性(CVE-2026-50502)、修正済みのCVE-2025-29969検証ロジックの盲点を突くPoCが公開 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • goshs-labs
  • goshs

28 Jul 2026
Published
29 Jul 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.23%

KEV

Description

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler split part.FileName() on / but did not reject .., allowing an unauthenticated upload with filename .. to create a file outside the served tree. This issue is fixed in version 2.1.5.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture fallback
goshs: fix CVE-2026-66063 and CVE-2026-66064 https://github.com/NixOS/nixpkgs/pull/547661 #security
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • IBM
  • WebSphere Application Server

28 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.54%

KEV

Description

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attacker to bypass authentication or execute arbitrary code.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

Four IBM WebSphere vulnerabilities are fixed, including a 9.8 pre-auth RCE (CVE-2026-14512) and a 9.4 SSRF (CVE-2026-14529). Patch now.

securityonline.info/ibm-websph

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • goshs-labs
  • goshs

28 Jul 2026
Published
29 Jul 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.31%

KEV

Description

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened files using a cleaned path but derived the authorization filename from raw req.URL.Path, so a trailing slash could bypass .goshs ACL-file protection and block-list checks. This issue is fixed in version 2.1.5.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture fallback
goshs: fix CVE-2026-66063 and CVE-2026-66064 https://github.com/NixOS/nixpkgs/pull/547661 #security
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • codeigniter4
  • CodeIgniter4

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
0.38%

KEV

Description

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values to be interpreted as SQL. This affects only the deleteBatch() code path. Regular delete() operations escape where() binds correctly. This issue is fixed in version 4.7.4.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • codeigniter4
  • CodeIgniter4

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
MEDIUM (4.8)
EPSS
0.14%

KEV

Description

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecureRequests, or similar logic to enforce HTTPS-only access or make security-sensitive decisions. Exploitability depends on deployment configuration. Applications are most exposed if the backend is reachable directly over HTTP, or if a reverse proxy/load balancer forwards client-supplied forwarding headers without stripping or overwriting them. This issue has been fixed in version 4.7.4.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

So, apperently there is a CodeIgniter RCE via file upload tracked as CVE-2026-63223.

Other than that there are also 3 more critical CVEs:
- SQL Injection (CVE-2026-63221)
- Path traversal (CVE-2026-63222)
- HTTP Header Spoofing (CVE-2026-63220)

Did people still use CodeIgniter?

Anyway, if your org still using it and it has anything related to file upload, might be a good time to update it.

securityonline.info/codeignite

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
HIGH (7.6)
EPSS
0.56%

KEV

Description

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host process. On Workstation and Fusion, the impact of this vulnerability is restricted to information disclosure.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
borncity.com/blog/2026/07/31/v

  • 1
  • 2
  • 1
  • 11h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.28%

KEV

Description

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
borncity.com/blog/2026/07/31/v

  • 1
  • 2
  • 1
  • 11h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
LOW (2.7)
EPSS
0.38%

KEV

Description

VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Teils kritische Schwachstellen (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) in VMware by Broadcom-Produkten (VMware ESX, vCenter, Workstation, Fusion). Updates sind laut Adversory vorhanden.
borncity.com/blog/2026/07/31/v

  • 1
  • 2
  • 1
  • 11h ago
Showing 41 to 49 of 49 CVEs