24h | 7d | 30d

Overview

  • WebPros
  • WHMCS

03 Sep 2026
Published
03 Sep 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
Pending

KEV

Description

Missing authorization vulnerability has been discovered in 2Checkout payment gateway of WHMCS from 8.13.0 before 8.13.8, from 9.0.0 before 9.0.8, all other EOL versions from 4.5.0. The vulnerability allows an unauthenticated user to get WHMCS customer's data via 2Checkout payment gateway's endpoint under specific conditions.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

A critical WHMCS security update fixes CVE-2026-67399 and CVE-2026-67398. Apply the patch now to prevent remote code execution and data leaks.

securityonline.info/whmcs-secu

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Dolibarr
  • dolibarr

27 Aug 2026
Published
28 Aug 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.26%

KEV

Description

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords, comment markers, parentheses, spaces and quotes intact. import_insert() in htdocs/core/modules/import/import_csv.modules.php then iterates the submitted values and builds a filter with $where[] = $key.' = '.$data[$key], having first applied preg_replace('/^.*\./i', '', $key), an alias strip that does nothing to a value containing no dot. The assembled string is executed through $this->db->query(). The injected SELECT resolves the row id that the import then assigns to $lastinsertid, which becomes the WHERE target of a subsequent UPDATE, so a UNION SELECT returning an attacker-chosen integer both exfiltrates arbitrary table content and redirects which row the import overwrites; for category link tables the raw filter array is spliced into that UPDATE directly. The interface offers a fixed list of legitimate column codes but the server never checks the submitted values against it. A user holding the import permission can exploit this. Release 23.0.4 does not carry the fix; the allow-list test was added in 24.0.0.

Statistics

  • 1 Post

Last activity: 14 hours ago

Bluesky

Profile picture fallback
[26.05] dolibarr: fix CVE-2026-81728 and CVE-2026-82633 https://github.com/NixOS/nixpkgs/pull/558698 #security
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
なんか、vmxnet3の脆弱性やばそう --- VMSA-2026-0007: VMware Workstation and Fusion updates address integer-overflow and buffer overflow vulnerabilities (CVE-2026-59346, CVE-2026-59347) → https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38288
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

SonicWall patched critical SonicWall NSM vulnerabilities in on-prem software. Update now to protect your network against remote code execution.

securityonline.info/sonicwall-

  • 0
  • 1
  • 0
  • 5h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

SonicWall patched critical SonicWall NSM vulnerabilities in on-prem software. Update now to protect your network against remote code execution.

securityonline.info/sonicwall-

  • 0
  • 1
  • 0
  • 5h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 5 hours ago

Fediverse

Profile picture fallback

SonicWall patched critical SonicWall NSM vulnerabilities in on-prem software. Update now to protect your network against remote code execution.

securityonline.info/sonicwall-

  • 0
  • 1
  • 0
  • 5h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

04 Mar 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
31.23%

Description

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture fallback
~Recordedfuture~ Attackers increasingly abused exposed software, trusted tools, supply chains, and AI-assisted workflows. - IOCs: CVE-2026-20131, CVE-2025-68947, CVE-2023-27532 - #Malware #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

Apache released version 1.21.0 to patch critical Apache Allura security vulnerabilities. Update now to protect against XSS, SSRF, and data exposure flaws.

securityonline.info/apache-all

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

Apache released version 1.21.0 to patch critical Apache Allura security vulnerabilities. Update now to protect against XSS, SSRF, and data exposure flaws.

securityonline.info/apache-all

  • 0
  • 0
  • 0
  • Last hour

Overview

  • Veeam Backup & Replication

10 Mar 2023
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
77.61%

Description

Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture fallback
~Recordedfuture~ Attackers increasingly abused exposed software, trusted tools, supply chains, and AI-assisted workflows. - IOCs: CVE-2026-20131, CVE-2025-68947, CVE-2023-27532 - #Malware #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 11h ago
Showing 51 to 60 of 62 CVEs