-Infinity
0

Linux KernelTOCTOU double-fetch in `zsock_sendmsg`/`recvmsg` userspace verifiers allows kernel-heap out-of-bounds write

Risk 65
Severity
7.8
First published (updated )

Velociraptor VelociraptorVelociraptor collect_client() Permissions Bypass

Risk 60
Severity
8.2
First published (updated )

WordPress plugin: Social Login, Passkeys, Magic Link & Email OTP – Passwordless LoginSocial Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback

Risk 75
Severity
8.1
First published (updated )

Red Hat Red Hat Advanced Cluster Management (RHACM)Multicloud-operators-channel: multicloud-operators-channel: auto-generated role grants every managed-cluster agent secrets:get,list,watch in channel namespaces

Risk 44
Severity
7.7
First published (updated )

multicloud-operators-subscriptionMulticloud-operators-subscription: multicloud-operators-subscription: fetchchannelreferences honours channel.spec.secretref.namespace enabling cross-namespace secret exfiltration

Risk 44
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CVE-2026-6484Lack of verified boot to certain FV may cause arbitrary code execution

Risk 64
Severity
8.2
First published (updated )

Red Hat Red Hat Enterprise Linux for x86_64 - Extended Life CycleImportant: kernel security, bug fix, and enhancement update

Risk 33
Severity
7
First published (updated )

redhat/microshiftImportant: Red Hat build of MicroShift 4.19.42 security update

Risk 33
Severity
7
First published (updated )

MongoDB driverCleartext Storage of Sensitive Information in MongoDB Driver Logging During Client Initialization

Risk 41
Severity
8.2
First published (updated )

calibre calibre Content Servercalibre Content Server `/book-update-annotations` Missing Write Authorization Check Allows Unauthorized Annotation Modification

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Calibre Calibrecalibre: Bypass of Python template restrictions via nested `template()` leading to RCE

Risk 72
Severity
8.5
First published (updated )

Kestra KestraKestra: SSRF via Pebble http() function allows unauthenticated access to internal services & cloud metadata

Risk 49
Severity
8.6
First published (updated )

KestraKestra: Unauthenticated management `/worker` endpoint exposes live task configuration and plaintext credentials

Risk 43
Severity
7.5
First published (updated )

Mira Hormone MonitorMira Hormone Monitor, Mira Android App Missing authentication for critical function

Risk 79
Severity
8.7
First published (updated )

cJSON cJSONcJSON 1.7.19 Wrong-Key Modification via JSON Pointer Escape Decoding

Risk 47
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mira Hormone Monitor device firmwareMira Hormone Monitor, Mira Android App Missing authentication for critical function

Risk 40
Severity
7.1
First published (updated )

Mira Android companion appMira Hormone Monitor, Mira Android App Authentication bypass by spoofing

Risk 52
Severity
8.2
First published (updated )

Typebot TypebotTypeBot has Arbitrary S3 Object Write in deprecated public upload endpoint via attacker-controlled filePath

Risk 54
Severity
8.2
First published (updated )

FileRun FileRunFileRun 2026.2.0 RCE via Thumbnail Generation Command Injection

Risk 79
Severity
8.7
First published (updated )

OpenResty Nginx Lua RBACMalcolm Vulnerable to Authorization Bypass via URI Normalization Differential in Nginx Lua RBAC

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

DynamiApps Frontend AdminFrontend Admin by DynamiApps <= 3.29.9 - Authenticated (Subscriber+) Arbitrary Password Reset via Encrypted Object Token

Risk 79
Severity
8.8
First published (updated )

Malcolm file-upload component (FilePond PHP backend)Malcolm vulnerable to RCE via unrestricted .php upload to the file-upload component

Risk 79
Severity
8.8
First published (updated )

SonicWall SonicWall Email SecurityCode Injection

Risk 69
Severity
7.8
First published (updated )

SonicWall SonicWall Email SecurityCode Injection

Risk 69
Severity
7.8
First published (updated )

CivetWeb CivetWebCivetWeb Heap/Stack Buffer Overflow via WebSocket permessage-deflate Decompression

Risk 52
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

GMS applicationAn insufficient certificate validation in a privileged communication workflow, was identified in a G…

Risk 72
Severity
8.3
First published (updated )

Pulsetto Vagus Nerve StimulatorPulsetto Vagus Nerve Stimulator Hidden Functionality

Risk 60
Severity
7.2
First published (updated )

FreeRDP freerdpFreeRDP: Kerberos GSS Wrap-token `EC` field is unbounded, causing an out-of-bounds decrypt in `kerberos_DecryptMessage`

Risk 57
Severity
8.3
First published (updated )

FreeRDP freerdpFreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)

Risk 52
Severity
8.3
First published (updated )

nuget/Microsoft.WindowsDesktop.App.Runtime.win-x86Buffer Overflow

Risk 68
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203