Robuta

Sponsor of the Day: Jerkmate
https://www.openwall.com/lists/oss-security/2021/03/11/2 oss-security - CVE-2021-20269: kexec-tools: incorrect permissions on vmcore-dmesg.txt file oss security cvekexec toolstxt file202120269 https://www.openwall.com/lists/oss-security/2022/04/02/5 oss-security - CVE-2022-1199 kernel: Null pointer dereference and use-after-free in ax25_release() oss security cvekernel null pointer20221199dereference https://seclists.org/oss-sec/2026/q2/244 oss-sec: [oss-security][CVE-2026-3087] shutil.unpack_archive() doesn't check for Windows absolute... security cve 2026oss3087unpackarchive https://www.openwall.com/lists/oss-security/2026/03/30/9 oss-security - CVE-2026-32794: Apache Airflow Provider for Databricks: TLS Certificate Verification... oss security cveapache airflowtls certificate2026provider https://www.openwall.com/lists/oss-security/2022/04/02/4 oss-security - CVE-2022-1205 kernel: Null pointer dereference and use-after-free in... oss security cvekernel null pointer20221205dereference https://www.openwall.com/lists/oss-security/2026/03/27/3 oss-security - CVE-2026-1961: Foreman: Remote Code Execution via command injection in WebSocket... oss security cveremote code executionvia command20261961 https://www.openwall.com/lists/oss-security/2026/03/31/8 oss-security - CVE-2024-14031: Sereal::Encoder versions from 4.000 through 4.009_002 for Perl is... oss security cve4 0002024encoderversions https://www.openwall.com/lists/oss-security/2024/03/13/3 oss-security - CVE-2024-24549: Apache Tomcat: HTTP/2 header handling DoS oss security cveapache tomcathttp 22024 https://www.openwall.com/lists/oss-security/2026/03/26/2 oss-security - CVE-2014-125112: Plack::Middleware::Session::Cookie versions through 0.21 for Perl... oss security cvesession cookie0 212014plack https://seclists.org/oss-sec/2020/q4/69 oss-sec: [SECURITY][CVE-2020-13937] Unauthenticated Configuration Disclosure oss secsecurity cve2020unauthenticatedconfiguration https://www.openwall.com/lists/oss-security/2026/04/06/4 oss-security - CVE-2026-33227: Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ,... oss security cveapache activemq2026clientbroker https://www.openwall.com/lists/oss-security/2021/08/16/1 oss-security - [CVE-2021-3653, CVE-2021-3656] SVM nested virtualization issues in KVM oss security cvenested virtualization202136533656 https://www.openwall.com/lists/oss-security/2026/03/30/1 oss-security - CVE-2026-4176: Perl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before... oss security cve5 941 020264176 https://matrix.org/blog/2024/10/security-disclosure-matrix-js-sdk-and-matrix-react-sdk/ Matrix.org - Security disclosure for matrix-js-sdk (CVE-2024-47080) and matrix-react-sdk... Matrix, the open protocol for secure decentralised communications security disclosurejs sdkcve 2024matrixreact https://www.openwall.com/lists/oss-security/2026/03/31/15 oss-security - [ADVISORY] CVE-2026-34956: Open vSwitch: Invalid memory access in conntrack FTP alg. security advisory cveopen vswitchmemory accessoss2026 https://blogs.opera.com/security/2026/02/update-your-browser-security-fix-for-chrome-zero-day-cve-2026-2441/ Update your browser: Security fix for Chrome zero-day CVE-2026-2441 | Opera Security browser security fixchrome zero daycve 2026update2441 https://seclists.org/oss-sec/2026/q2/247 oss-sec: Xen Security Advisory 485 v2 (CVE-2026-31786) - Linux kernel out of bounds read via... oss sec xenv2 cve 2026security advisorylinux kernelbounds read https://www.oracle.com/security-alerts/alert-cve-2026-21992.html Oracle Security Alert Advisory - CVE-2026-21992 Oracle Security Alert Advisory - CVE-2026-21992 advisory cve 2026oracle securityalert21992 https://www.turnkeylinux.org/node/18003 CVE-2015-8103: TurnKey Jenkins critical security hole | TurnKey GNU/Linux Existing deployments of TurnKey Jenkins are still vulnerable to CVE-2015-8103, a critical issue that allows remote code execution by unauthenticated users. Due... cve 2015critical securitygnu linux8103turnkey https://krebsonsecurity.com/tag/cve-2026-26110/ CVE-2026-26110 – Krebs on Security cve 2026krebssecurity https://discuss.elastic.co/t/impact-of-cve-2025-46295/384442 Impact of CVE-2025-46295 - Elastic Security - Discuss the Elastic Stack CVE-2025-46295 I just downloaded elastic-9.2.3 for Windows. Our security scanner is flagging it because commons-text-1.4.jar is found in the directory... elastic security discusscve 2025impactstack https://www.openwall.com/lists/oss-security/2026/03/21/3 oss-security - Re: pyOpenSSL 26.0.0 released with two CVE fixes 26 0 releasedoss securitypyopenssltwocve https://www.redfoxsec.com/advisory Security Advisory & CVE Disclosures | Redfox Cybersecurity Published CVEs across Asus, Netgear, Tenda, and more. Redfox Cybersecurity follows a responsible 90-day vulnerability disclosure policy aligned with Google... security advisory cveredfox cybersecuritydisclosures https://blog.rust-lang.org/2024/09/04/cve-2024-43402/ Security advisory for the standard library (CVE-2024-43402) | Rust Blog Empowering everyone to build reliable and efficient software. security advisorystandard librarycve 2024rust blog https://krebsonsecurity.com/tag/cve-2026-21516/ CVE-2026-21516 – Krebs on Security cve 202621516krebssecurity https://mailman.nginx.org/pipermail/nginx-announce/2018/000221.html [nginx-announce] nginx security advisory (CVE-2018-16845) nginx announce securityadvisory cve2018 https://www.redpacketsecurity.com/cve-alert-cve-2026-32173-microsoft-azure-sre-agent-gateway-signalr-hub/ CVE Alert: CVE-2026-32173 - Microsoft - Azure SRE Agent Gateway - SignalR Hub - RedPacket Security Apr 3, 2026 - Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. cve alert 2026azure sre agentredpacket securitymicrosoft https://mailman.nginx.org/pipermail/nginx-announce/2013/000112.html [nginx-announce] nginx security advisory (CVE-2013-2028) nginx announce securityadvisory cve 20132028 https://krebsonsecurity.com/tag/cve-2026-25187/ CVE-2026-25187 – Krebs on Security cve 2026krebssecurity https://mailman.nginx.org/pipermail/nginx-announce/2013/000125.html [nginx-announce] nginx security advisory (CVE-2013-4547) nginx announce securityadvisory cve 20134547 https://mailman.nginx.org/pipermail/nginx-announce/2024/NW6MNW34VZ6HDIHH5YFBIJYZJN7FGNAV.html [nginx-announce] nginx security advisory (CVE-2024-24989, CVE-2024-24990) nginx announce securityadvisory cve2024 https://krebsonsecurity.com/tag/cve-2026-20805/ CVE-2026-20805 – Krebs on Security cve 2026krebssecurity https://krebsonsecurity.com/tag/cve-2026-24291/ CVE-2026-24291 – Krebs on Security cve 2026krebssecurity https://mariadb.com/docs/server/security/cve Security Vulnerabilities (CVE) Fixed in MariaDB | Server | MariaDB Documentation Lists of Security Vulnerabilities (CVE) fixed in MariaDB products. mariadb server documentationsecurity vulnerabilitiescvefixed https://www.openwall.com/lists/oss-security/2011/06/21/2 oss-security - Re: CVE request: crypt_blowfish 8-bit character mishandling oss securitycve request8 bitcryptblowfish https://seclists.org/oss-sec/2026/q2/245 oss-sec: Xen Security Advisory 483 v2 (CVE-2026-23556) - oxenstored keeps quota related use counts... oss sec xenv2 cve 2026security advisory https://krebsonsecurity.com/tag/cve-2026-20953/ CVE-2026-20953 – Krebs on Security cve 2026krebssecurity https://krebsonsecurity.com/tag/cve-2026-21533/ CVE-2026-21533 – Krebs on Security cve 2026krebssecurity https://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html [nginx-announce] nginx security advisory (CVE-2013-2070) nginx announce securityadvisory cve 20132070 https://seclists.org/oss-sec/2023/q3/98 oss-sec: Xen Security Advisory 435 v1 (CVE-2022-40982) - x86/Intel: Gather Data Sampling oss sec xencve 2022 40982gather data samplingsecurity advisory https://mailman.nginx.org/pipermail/nginx-announce/2016/000179.html [nginx-announce] nginx security advisory (CVE-2016-4450) nginx announce securityadvisory cve20164450