Sponsor of the Day:
Jerkmate
https://www.openwall.com/lists/oss-security/2021/03/11/2
oss-security - CVE-2021-20269: kexec-tools: incorrect permissions on vmcore-dmesg.txt file
oss security cvekexec toolstxt file202120269
https://www.openwall.com/lists/oss-security/2022/04/02/5
oss-security - CVE-2022-1199 kernel: Null pointer dereference and use-after-free in ax25_release()
oss security cvekernel null pointer20221199dereference
https://seclists.org/oss-sec/2026/q2/244
oss-sec: [oss-security][CVE-2026-3087] shutil.unpack_archive() doesn't check for Windows absolute...
security cve 2026oss3087unpackarchive
https://www.openwall.com/lists/oss-security/2026/03/30/9
oss-security - CVE-2026-32794: Apache Airflow Provider for Databricks: TLS Certificate Verification...
oss security cveapache airflowtls certificate2026provider
https://www.openwall.com/lists/oss-security/2022/04/02/4
oss-security - CVE-2022-1205 kernel: Null pointer dereference and use-after-free in...
oss security cvekernel null pointer20221205dereference
https://www.openwall.com/lists/oss-security/2026/03/27/3
oss-security - CVE-2026-1961: Foreman: Remote Code Execution via command injection in WebSocket...
oss security cveremote code executionvia command20261961
https://www.openwall.com/lists/oss-security/2026/03/31/8
oss-security - CVE-2024-14031: Sereal::Encoder versions from 4.000 through 4.009_002 for Perl is...
oss security cve4 0002024encoderversions
https://www.openwall.com/lists/oss-security/2024/03/13/3
oss-security - CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS
oss security cveapache tomcathttp 22024
https://www.openwall.com/lists/oss-security/2026/03/26/2
oss-security - CVE-2014-125112: Plack::Middleware::Session::Cookie versions through 0.21 for Perl...
oss security cvesession cookie0 212014plack
https://seclists.org/oss-sec/2020/q4/69
oss-sec: [SECURITY][CVE-2020-13937] Unauthenticated Configuration Disclosure
oss secsecurity cve2020unauthenticatedconfiguration
https://www.openwall.com/lists/oss-security/2026/04/06/4
oss-security - CVE-2026-33227: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ,...
oss security cveapache activemq2026clientbroker
https://www.openwall.com/lists/oss-security/2021/08/16/1
oss-security - [CVE-2021-3653, CVE-2021-3656] SVM nested virtualization issues in KVM
oss security cvenested virtualization202136533656
https://www.openwall.com/lists/oss-security/2026/03/30/1
oss-security - CVE-2026-4176: Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before...
oss security cve5 941 020264176
https://matrix.org/blog/2024/10/security-disclosure-matrix-js-sdk-and-matrix-react-sdk/
Matrix.org - Security disclosure for matrix-js-sdk (CVE-2024-47080) and matrix-react-sdk...
Matrix, the open protocol for secure decentralised communications
security disclosurejs sdkcve 2024matrixreact
https://www.openwall.com/lists/oss-security/2026/03/31/15
oss-security - [ADVISORY] CVE-2026-34956: Open vSwitch: Invalid memory access in conntrack FTP alg.
security advisory cveopen vswitchmemory accessoss2026
https://blogs.opera.com/security/2026/02/update-your-browser-security-fix-for-chrome-zero-day-cve-2026-2441/
Update your browser: Security fix for Chrome zero-day CVE-2026-2441 | Opera Security
browser security fixchrome zero daycve 2026update2441
https://seclists.org/oss-sec/2026/q2/247
oss-sec: Xen Security Advisory 485 v2 (CVE-2026-31786) - Linux kernel out of bounds read via...
oss sec xenv2 cve 2026security advisorylinux kernelbounds read
https://www.oracle.com/security-alerts/alert-cve-2026-21992.html
Oracle Security Alert Advisory - CVE-2026-21992
Oracle Security Alert Advisory - CVE-2026-21992
advisory cve 2026oracle securityalert21992
https://www.turnkeylinux.org/node/18003
CVE-2015-8103: TurnKey Jenkins critical security hole | TurnKey GNU/Linux
Existing deployments of TurnKey Jenkins are still vulnerable to CVE-2015-8103, a critical issue that allows remote code execution by unauthenticated users. Due...
cve 2015critical securitygnu linux8103turnkey
https://krebsonsecurity.com/tag/cve-2026-26110/
CVE-2026-26110 – Krebs on Security
cve 2026krebssecurity
https://discuss.elastic.co/t/impact-of-cve-2025-46295/384442
Impact of CVE-2025-46295 - Elastic Security - Discuss the Elastic Stack
CVE-2025-46295 I just downloaded elastic-9.2.3 for Windows. Our security scanner is flagging it because commons-text-1.4.jar is found in the directory...
elastic security discusscve 2025impactstack
https://www.openwall.com/lists/oss-security/2026/03/21/3
oss-security - Re: pyOpenSSL 26.0.0 released with two CVE fixes
26 0 releasedoss securitypyopenssltwocve
https://www.redfoxsec.com/advisory
Security Advisory & CVE Disclosures | Redfox Cybersecurity
Published CVEs across Asus, Netgear, Tenda, and more. Redfox Cybersecurity follows a responsible 90-day vulnerability disclosure policy aligned with Google...
security advisory cveredfox cybersecuritydisclosures
https://blog.rust-lang.org/2024/09/04/cve-2024-43402/
Security advisory for the standard library (CVE-2024-43402) | Rust Blog
Empowering everyone to build reliable and efficient software.
security advisorystandard librarycve 2024rust blog
https://krebsonsecurity.com/tag/cve-2026-21516/
CVE-2026-21516 – Krebs on Security
cve 202621516krebssecurity
https://mailman.nginx.org/pipermail/nginx-announce/2018/000221.html
[nginx-announce] nginx security advisory (CVE-2018-16845)
nginx announce securityadvisory cve2018
https://www.redpacketsecurity.com/cve-alert-cve-2026-32173-microsoft-azure-sre-agent-gateway-signalr-hub/
CVE Alert: CVE-2026-32173 - Microsoft - Azure SRE Agent Gateway - SignalR Hub - RedPacket Security
Apr 3, 2026 - Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
cve alert 2026azure sre agentredpacket securitymicrosoft
https://mailman.nginx.org/pipermail/nginx-announce/2013/000112.html
[nginx-announce] nginx security advisory (CVE-2013-2028)
nginx announce securityadvisory cve 20132028
https://krebsonsecurity.com/tag/cve-2026-25187/
CVE-2026-25187 – Krebs on Security
cve 2026krebssecurity
https://mailman.nginx.org/pipermail/nginx-announce/2013/000125.html
[nginx-announce] nginx security advisory (CVE-2013-4547)
nginx announce securityadvisory cve 20134547
https://mailman.nginx.org/pipermail/nginx-announce/2024/NW6MNW34VZ6HDIHH5YFBIJYZJN7FGNAV.html
[nginx-announce] nginx security advisory (CVE-2024-24989, CVE-2024-24990)
nginx announce securityadvisory cve2024
https://krebsonsecurity.com/tag/cve-2026-20805/
CVE-2026-20805 – Krebs on Security
cve 2026krebssecurity
https://krebsonsecurity.com/tag/cve-2026-24291/
CVE-2026-24291 – Krebs on Security
cve 2026krebssecurity
https://mariadb.com/docs/server/security/cve
Security Vulnerabilities (CVE) Fixed in MariaDB | Server | MariaDB Documentation
Lists of Security Vulnerabilities (CVE) fixed in MariaDB products.
mariadb server documentationsecurity vulnerabilitiescvefixed
https://www.openwall.com/lists/oss-security/2011/06/21/2
oss-security - Re: CVE request: crypt_blowfish 8-bit character mishandling
oss securitycve request8 bitcryptblowfish
https://seclists.org/oss-sec/2026/q2/245
oss-sec: Xen Security Advisory 483 v2 (CVE-2026-23556) - oxenstored keeps quota related use counts...
oss sec xenv2 cve 2026security advisory
https://krebsonsecurity.com/tag/cve-2026-20953/
CVE-2026-20953 – Krebs on Security
cve 2026krebssecurity
https://krebsonsecurity.com/tag/cve-2026-21533/
CVE-2026-21533 – Krebs on Security
cve 2026krebssecurity
https://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html
[nginx-announce] nginx security advisory (CVE-2013-2070)
nginx announce securityadvisory cve 20132070
https://seclists.org/oss-sec/2023/q3/98
oss-sec: Xen Security Advisory 435 v1 (CVE-2022-40982) - x86/Intel: Gather Data Sampling
oss sec xencve 2022 40982gather data samplingsecurity advisory
https://mailman.nginx.org/pipermail/nginx-announce/2016/000179.html
[nginx-announce] nginx security advisory (CVE-2016-4450)
nginx announce securityadvisory cve20164450