Robuta

https://www.postgresql.org/support/security/CVE-2022-2625/
postgresqlcveextensionscriptsreplace
https://www.kaspersky.it/blog/canon-ttf-vulnerability-printer-risk/30315/
Nov 28, 2025 - Cosa rende pericolosa la vulnerabilità Canon CVE-2024-12649 e come viene compromessa la rete di un'organizzazione tramite il semplice invio in...
cvenellttf
https://www.fastly.com/blog/fastlys-proactive-protection-critical-react-rce-cve-2025-55182
Jan 8, 2026 - Protect your apps from the critical React RCE bugs (CVE-2025-55182/66478). Fastly's NGWAF Virtual Patch provides proactive defense.
rcecveprotectionfastly
https://www.zscaler.com/blogs/security-research/security-advisory-remote-code-execution-vulnerability-cve-2023-3519
Aug 27, 2025 - This article provides coverage details of the latest RCE vulnerability CVE-2023-3519 found in NetScaler ADC and NetScaler Gateway.
cve
https://www.herodevs.com/vulnerability-directory/cve-2021-41184
A Cross‑Site Scripting (XSS) vulnerability in jQuery UI’s .position() utility (CVE‑2021‑41184) allows script injection through unsafe handling of the of...
vulnerability directorycvejqueryherodevs
https://www.openoffice.org/security/cves/CVE-2020-13958.html
cve
https://horizon3.ai/attack-research/vulnerabilities/n-able-n-central-vulnerabilities-cve-2025-9316-cve-2025-11700/
Nov 14, 2025 - Horizon3.ai uncovered 0-days in N-able N-central (CVE-2025-9316, CVE-2025-11700). Use NodeZero® Rapid Response to validate...
cve
https://securitybridge.com/blog/cve-2025-42957-sap-remote-code-execution/
Dec 2, 2025 - The SecurityBridge Research Labs has identified a critical Remote Code Execution vulnerability in SAP S/4HANA, registered as CVE-2025-42957.
remote code executioncvesap
https://www.herodevs.com/vulnerability-directory/cve-2018-14042
Patch CVE-2018-14042 immediately to secure your systems from critical vulnerabilities. Protect your applications and prevent exploits with the latest updates...
vulnerability directorycvebootstrapherodevs
https://blog.r-project.org/2024/05/10/statement-on-cve-2024-27322/index.html
r blogstatementcve
https://feedly.com/cve/CVE-2026-26030
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the...
cveexploitsseverityfeedly
https://zeropath.com/blog/cve-2025-30377-microsoft-office-preview-pane-rce
May 13, 2025 - CVE-2025-30377, a critical use-after-free vulnerability in Microsoft Office, enables attackers to execute arbitrary code via Outlook's Preview Pane...
microsoft officesilentthreatcveexploits
https://www.kaspersky.com.au/blog/update-unity-games-cve-2025-59489/35538/
Oct 7, 2025 - Exploring a dangerous vulnerability in the Unity game engine, and how to protect your devices
cvevulnerabilityunity
https://blog.huntr.com/hunting-with-vulnhuntr-getting-your-first-cve
Nov 19, 2025 - Learn how to use Vulnhuntr to find vulnerabilities in open-source projects and secure your first CVE with this comprehensive step-by-step guide.
huntinggettingfirstcveblog
https://wazuh.com/blog/detecting-chrome-cve-2025-13223-vulnerability-with-wazuh/
Nov 27, 2025 - Learn how to quickly detect and respond to the actively exploited Chrome CVE-2025-13223 code execution vulnerability using Wazuh's capabilities.
detectingchromecvevulnerabilitywazuh
https://kb.isc.org/v1/docs/cve-2023-5517
cve
https://www.greynoise.io/blog/reconnaissance-beyondtrust-rce-cve-2026-1731
A PoC for CVE-2026-1731 hit GitHub on Feb 10. Within 24 hours, GreyNoise observed reconnaissance probing for vulnerable BeyondTrust instances.
reconnaissancenewbeyondtrustrcecve
https://horizon3.ai/attack-research/disclosures/cve-2025-64155-three-years-of-remotely-rooting-the-fortinet-fortisiem/
Jan 13, 2026 - Horizon3.ai details CVE-2025-64155, revealing chained FortiSIEM vulnerabilities enabling remote code execution and root access, analysis of the root cause, and...
cveyearsremotelyfortisiem
https://kb.isc.org/v1/docs/cve-2022-0635
CVE-2022-0635: DNAME insist with synth-from-dnssec enabled
cveinsistsynthdnssecenabled
https://aisle.com/blog/a-high-severity-webassembly-boundary-condition-vulnerability-in-firefox-cve-2025-13016
Discover how a single line of faulty pointer arithmetic in Firefox's WebAssembly engine created CVE-2025-13016, affecting 180M+ users.
highseverityvulnerabilityfirefoxcve
https://discourse.mailinabox.email/t/critical-security-vulnerability-in-linux-cve-2015-7547-getaddrinfo/1101
A critical security issue in Linux in a core system library has come to light. Although exploits are considered improbable, there's a risk that malicious...
security vulnerabilitycriticallinuxcveannouncements
https://aisle.com/blog/command-injection-in-nasa-cryptolib-cve-2025-59534
NASA's CryptoLib had a critical 3-year-old authentication flaw. AISLE's AI detected it and helped ship CVE-2025-59534 fix in just 4 days.
commandinjectionnasacveaisle
https://canonical-robotics.readthedocs-hosted.com/en/latest/how-to-guides/maintenance/check-cves/
If you’re running ROS in production, it’s important to know whether a specific CVE has been patched in your environment. You can find detailed step-by-step...
checkcvefixedenvironmentrobotics
https://www.netspi.com/blog/technical-blog/adversary-simulation/pipe-dreams-remote-code-execution-via-quest-desktop-authority-named-pipe/
Feb 2, 2026 - Discover the risks of the CVE-2025-67813 vulnerability in Quest Desktop Authority. Learn how this RCE flaw impacts your organization and how to mitigate it.
questdesktopauthorityrcenamed
https://projectdiscovery.io/blog/ingressnightmare-unauth-rce-in-ingress-nginx
ingress nginxrcecve
https://www.openoffice.org/security/cves/CVE-2022-40674.html
cve
https://jfrog.com/blog/exploiting-remote-code-execution-in-redis/
Jan 14, 2026 - Learn how the JFrog Security research team discovered and disclosed CVE-2025-11953 which poses a threat to developers using the popular React Native CLI.
react nativecvecriticalrcecli
https://www.herodevs.com/vulnerability-directory/cve-2024-6484
A cross-site scripting (XSS) vulnerability has been identified within the Bootstrap 3 Carousel component.
vulnerability directorycvebootstrapherodevs
https://www.cybersecuritydive.com/news/cisa-second-beyondtrust-cve-exploited/737288/
Federal authorities are still working with the company to investigate a hack of Treasury Department workstations, but have not yet explained the CVEs’...
cisaaddssecondbeyondtrustcve
https://www.canva.dev/blog/engineering/when-url-parsers-disagree-cve-2023-38633/
Discovery and walkthrough of CVE-2023-38633 in librsvg, when two URL parser implementations (Rust and Glib) disagree on file scheme parsing leading to path...
canva engineeringurldisagreecveblog
https://www.kaspersky.co.uk/blog/update-unity-games-cve-2025-59489/29596/
Oct 7, 2025 - Exploring a dangerous vulnerability in the Unity game engine, and how to protect your devices
cvevulnerabilityunity
https://www.helpnetsecurity.com/2023/09/27/cve-2023-5129/
Sep 29, 2023 - The exploited Chrome zero-day exploited recently patched by Google is actually in the libwebp library and has a new ID: CVE-2023-5129.
zero daygooglequotconfirmsexploited
https://sean.heelan.io/2025/05/22/how-i-used-o3-to-find-cve-2025-37899-a-remote-zeroday-vulnerability-in-the-linux-kernels-smb-implementation/
In this post I’ll show you how I found a zeroday vulnerability in the Linux kernel using OpenAI’s o3 model. I found the vulnerability with nothing...
usedfindcve
https://www.fortinet.com/blog/psirt-blogs/cve-2022-39952-fortinac-perspective
Fortinet published a Critical Advisory (FG-IR-22-300 / CVE-2022-39952) for FortiNAC on February 16, 2023. This article adds perspective to that Advisory to...
fortinet blogperspectivescve
https://jfrog.com/blog/2025-6514-critical-mcp-remote-rce-vulnerability/
Jul 9, 2025 - Learn how the JFrog Security research team discovered and disclosed CVE-6514, a critical vulnerability in the mcp-remote project used by Model Context Protocol...
cvethreatensllmclients
https://security.archlinux.org/CVE-2022-4379
cvelinuxltshardenedzen
https://kb.isc.org/v1/docs/cve-2023-5680
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can...
cve
https://www.kaspersky.com.au/blog/canon-ttf-vulnerability-printer-risk/35661/
Nov 18, 2025 - What makes the Canon vulnerability CVE-2024-12649 dangerous and how to compromise an organization’s network by simply sending a document to print.
cvevulnerabilitycanonttfinterpreter
https://github.blog/security/vulnerability-research/bypassing-mte-with-cve-2025-0072/
May 23, 2025 - See how a vulnerability in the Arm Mali GPU can be exploited to gain kernel code execution even when Memory Tagging Extension (MTE) is enabled.
github blogbypassingcve
https://vertx.io/blog/CVE-2021-44228/
Vert.x | Reactive applications on the JVM
eclipsevertxcveblog
https://thehackernews.com/2026/02/new-chrome-zero-day-cve-2026-2441-under.html
Google fixes actively exploited Chrome zero-day CVE-2026-2441, a high-severity CSS use-after-free flaw enabling sandboxed remote code execution.
zero daynewchromecveactive
https://mazehq.com/blog/ai-vulnerability-analysis-in-action-cve-2025-27363
Cloud vulnerabilities prove to be increasingly difficult to manage. As networks grow more complex, the need to identify and mitigate security weaknesses...
aivulnerabilityanalysisactioncve
https://security.archlinux.org/CVE-2021-3669
cvelinuxltshardenedzen
https://www.herodevs.com/vulnerability-directory/cve-2010-5312
jQuery UI Dialog contains an XSS vulnerability (CVE-2010-5312) caused by unsafe title rendering with .html(). HeroDevs delivers a secure, backported fix for...
vulnerability directorycvejqueryherodevs
https://mailman.nginx.org/pipermail/nginx-announce/2016/000169.html
security advisorynginxannouncecve
https://www.haproxy.com/blog/october-2025-cve-2025-11230-haproxy-mjson-library-denial-of-service-vulnerability
Oct 6, 2025 - The latest versions of HAProxy Community and HAProxy Enterprise have patches for a high severity denial of service vulnerability in the mjson library.
cvedenialservicevulnerabilityhaproxy
https://www.aikido.dev/blog/mongobleed-mongodb-zlib-vulnerability-cve-2025-14847
MongoBleed, tracked as CVE-2025-14847, allows unauthenticated memory disclosure in MongoDB via zlib compression. See impact and remediation.
mongodbzlibvulnerabilitycve
https://www.cio.com/video/4123633/how-chainguard-helps-cios-reduce-open-source-risk-and-cve-overload.html
Jan 28, 2026
open sourcechainguardhelpsciosreduce
https://kb.isc.org/v1/docs/cve-2023-5679
A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolution, when both of these features are...
cve
https://www.fortinet.com/blog/psirt-blogs/analysis-of-cve-2023-27997-and-clarifications-on-volt-typhoon-campaign
Today, Fortinet published a CVSS Critical PSIRT Advisory (FG-IR-23-097 / CVE-2023-27997) along with several other SSL-VPN related fixes. This blog adds context...
analysiscvevolttyphoon
https://bugs.launchpad.net/bugs/cve
launchpadcvetracker
https://www.herodevs.com/vulnerability-directory/cve-2020-11022
Get instant remediation for CVE-2020-11022. This Medium level exploit can be found in jQuery versions greater than or equal to 1.2 and before 3.5.0. The...
vulnerability directorycvejqueryherodevs
https://blog.desdelinux.net/vulnerabilidad-bluetooth-android-cve-2025-48593-noviembre/
Nov 22, 2025 - Google confirma una vulnerabilidad crítica en el subsistema Bluetooth de Android que permite ejecución remota de código. Conoce cómo ...
cveunavulnerabilidadenbluetooth
https://www.scutum.jp/information/waf_tech_blog/2025/07/waf-blog-083.html
apacheackcvewaftech
https://hackread.com/update-firefox-patch-cve-2025-13016-vulnerability/
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
updatefirefoxpatchcvevulnerability
https://security.archlinux.org/CVE-2022-3061
cvelinuxltshardenedzen
https://www.itnews.com.au/news/mitres-cve-program-given-last-minute-reprieve-616628
Just as its funding was due to run out.
last minutemitrecveprogramgiven
https://www.catonetworks.com/rapid-cve-mitigation/
Dec 10, 2025 - Discover Cato Networks' Rapid CVE Mitigation, offering automated virtual patching for critical vulnerabilities, without customer involvement.
cato networksrapidcvemitigation
https://security.archlinux.org/CVE-2022-3649
cvelinuxltshardenedzen
https://www.kaspersky.co.in/blog/canon-ttf-vulnerability-printer-risk/29825/
Nov 18, 2025 - What makes the Canon vulnerability CVE-2024-12649 dangerous and how to compromise an organization's network by simply sending a document to...
cvevulnerabilitycanonttf
https://www.sangfor.com/support/security-advisory
Stay informed with official vulnerability disclosures and remediation updates for Sangfor products. Browse CVE announcements, impact assessments, and patch...
security vulnerabilityadvisoriescvereportsamp
https://kb.isc.org/docs/cve-2025-8677
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
cveresourceexhaustionviamalformed
https://www.cvtotaal.nl/itho-daalderop-ventilatie-unit-cve-s-eco-se-vochtsensor-rft-n-afstandsbediening-perilexstekker.html
Dec 22, 2025 - Met een mechanisch ventilatiesysteem van Itho Daalderop zorg je voor een comfortabel, gezond en vochtvrij binnenklimaat. De Itho Daalderop CVE-S ECO SP is een...
cveecospen
https://kb.isc.org/docs/cve-2025-40775
When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm...
cvednsmessageinvalidcauses
https://unit42.paloaltonetworks.com/mongobleed-cve-2025-14847/
Database platform MongoDB disclosed CVE-2025-14847, called MongoBleed. This is an unauthenticated memory disclosure vulnerability with a CVSS score of 8.7.
threatbriefmongodbvulnerabilitycve
https://ubuntu.com/blog/securing-open-source-through-cve-prioritisation
According to a recent study, 96% of applications in the enterprise market use open-source software. As the open source landscape becomes more and more...
open sourcesecuringcveubuntu
https://www.kaspersky.co.in/blog/update-unity-games-cve-2025-59489/29707/
Oct 7, 2025 - Exploring a dangerous vulnerability in the Unity game engine, and how to protect your devices
cvevulnerabilityunity
https://kb.isc.org/docs/cve-2025-40777
If a named caching resolver is configured with serve-stale-enable yes, and with stale-answer-client-timeout set to 0 (the only allowable value other than...
cvepossibleassertionfailureusing
https://www.kaspersky.fr/blog/canon-ttf-vulnerability-printer-risk/23409/
Nov 28, 2025 - Qu’est-ce qui rend la vulnérabilité CVE 2024-12649 de Canon dangereuse et comment compromettre le réseau d’une organisation en envoyant simplement un...
cvedansttfdecanon
https://www.herodevs.com/vulnerability-directory/cve-2025-3573
Medium-severity XSS vulnerability (CVE-2025-3573) in jQuery Validation affects versions <1.20.0, allowing script injection via unsanitized placeholders.
vulnerability directorycvejqueryherodevs
https://www.lynx.com/blog/integrating-sbom-and-cve-monitoring-into-embedded-ci/cd-a-strategic-imperative-for-defense-aerospace
Secure embedded systems in defense and aerospace with SBOM, CVE, and VEX integration, enabling compliance, visibility, and proactive DevSecOps protection.
integratingsbomcvemonitoringembedded
https://www.brighttalk.com/webcast/11673/624753
There are several crucial developments in the cybersecurity landscape in 2024, including a significant rise in reported CVEs and the need for advanced d...
exploitedcveinsightsnavigatingstorm
https://www.zerodayinitiative.com/blog/2026/2/19/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad
Feb 19, 2026 - In this excerpt of a TrendAI Research Services vulnerability report, Nikolai Skliarenko and Yazhi Wang of the TrendAI Research team detail a recently patched...
zero daycode executioninitiativecvearbitrary
https://www.postgresql.org/support/security/CVE-2025-8713/
postgresqlcveoptimizerstatisticsexpose
https://witekio.com/maintenance-security/cve-scanner/
Oct 22, 2025 - We have more than 20 years of experience in IoT devices and embedded systems security, and software development.
embedded systemscvescanner
https://www.cybersecuritydive.com/news/cisa-extend-funding-cve/745531/
The information security industry feared a lapse would lead to industrywide exposures of software vulnerabilities.
mitrecveprogramregainsfunding
https://horizon3.ai/attack-research/vulnerabilities/cve-2025-61757/
Nov 24, 2025 - Safely validate exposure to Oracle Identity Manager CVE-2025-61757. Learn how attackers exploit it, what’s at risk, and how NodeZero Rapid Response...
identity manageroraclercecve
https://unit42.paloaltonetworks.com/microsoft-cve-2025-59287/
CVE-2025-59287 is a critical RCE vulnerability identified in Microsoft’s WSUS. Our observations from cases show a consistent methodology.
remote code executionmicrosoftcveactivelyexploited
https://security.archlinux.org/CVE-2022-47942
cvelinuxzenltshardened
https://www.sentinelone.com/vulnerability-database/cve-2026-23004/
CVE-2026-23004 is a use-after-free vulnerability in the Linux kernel. Learn about its impact, affected versions, and mitigation methods.
linux kernelcveusefreevulnerability
https://www.huntress.com/blog/cleo-software-vulnerability-malware-analysis
Team Huntress has analyzed Cleo's software vulnerability CVE-2024-55956. Take a look at the technical breakdown of a new family of malware we’ve named...
malware analysiscleocvehuntress
https://www.postgresql.org/support/security/CVE-2023-5869/
postgresqlcvebufferoverruninteger
https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities
Mar 24, 2025 - Wiz Research uncovered RCE vulnerabilities (CVE-2025-1097, 1098, 24514, 1974) in Ingress NGINX for Kubernetes allowing cluster-wide secret access.
cvekuberneteswizblog
https://www.greenbone.net/en/blog/a-lurking-fortiweb-vulnerability-proves-critical-amid-active-exploitation/
Nov 18, 2025 - FortiWeb faces a critical vulnerability ⚡ Greenbone provides accurate detection and protection for CVE-2025-64446.
fortiwebexploitcvecriticalthreat
https://www.postgresql.org/support/security/CVE-2025-12817/
postgresqlcvecreatestatisticscheck
https://www.chainguard.dev/unchained/chainguard-cve-visualizations-now-generally-available
Feb 5, 2025 - Chainguard CVE Visualizations, now generally available, is a capability that allows users to compare CVE numbers in both Chainguard Containers and upstream.
generally availablechainguardcvevisualizations
https://security-tracker.debian.org/tracker/CVE-2026-23490
cve
https://cti.wazuh.com/vulnerabilities/cves
Wazuh CTI provides access to a comprehensive database of vulnerabilities, enabling you to quickly identify and address potential risks.
cvesearchvulnerabilitydatabasewazuh
https://c2a-sec.com/webinar-from-cve-to-patient-risk/
Nov 20, 2025 - On-Demand Replay Webinar Replay: From CVE Alert to Patient Risk (streamed November 13, 2025) Why Context Matters in Medical Device Security (in collaboration...
webinar replaylpcvepatientrisk
https://securitybridge.com/blog/critical-sap-s-4hana-code-injection-vulnerability-cve-2025-42957/
Dec 2, 2025 - CVE-2025-42957 is a critical ABAP code injection flaw in SAP S/4HANA (CVSS 9.9) discovered by SecurityBridge - patching is imperative!
cvecriticalsapcodeinjection
https://edf.amd.com/sswreleases/rel-v2025.2/CVE_SBOM/
indexrelcvesbom
https://kb.isc.org/docs/cve-2025-13878
Malformed BRID/HHIT records can cause named to terminate unexpectedly. An attacker can cause named to crash via queries that create corrupt records.
cvemalformedbridrecordscause
https://cyberscoop.com/cve-program-funding-crisis-cve-foundation-mitre/
May 14, 2025 - The CVE program narrowly avoided shutdown after a funding crisis, prompting calls for alternative models and renewed debate about the future of global...
year endcvefoundationeyeslaunch
https://www.patrowl.io/en/actualites/cve-2025-55182-react2shell
CVE-2025-55182 (React2shell) sparked global confusion and false positives. Discover how Patrowl delivered real exploitability testing and clarity from day one.
truthcve
https://www.herodevs.com/vulnerability-directory/cve-2020-11023
Get instant remediation for CVE-2020-11023. This Medium level exploit is related to CVE-2020-11022; it can be found in jQuery versions greater than or equal to...
vulnerability directorycvejqueryherodevs
https://www.postgresql.org/support/security/CVE-2022-41862/
postgresqlcveclientmemorydisclosure
https://www.herodevs.com/vulnerability-directory/cve-2024-6531
A cross-site scripting (XSS) vulnerability has been identified within the Bootstrap 4 Carousel component.
vulnerability directorycvebootstrapherodevs
https://kb.isc.org/v1/docs/cve-2023-3341
Control channel messages call certain functions recursively during packet parsing. A large recursion depth may cause the packet-parsing code to run out of...
cve
https://security.paloaltonetworks.com/CVE-2026-0227
Palo Alto Networks Security Advisory: CVE-2026-0227 PAN-OS: Firewall Denial of Service (DoS) in GlobalProtect Gateway and Portal A vulnerability in Palo Alto...
cvepanosfirewalldenial
https://www.openoffice.org/security/cves/CVE-2012-5639.html
cve