Most companies won't patch this for 3 weeks. Attackers need 3 hours.
Another critical flaw in OpenClaw.
CVE-2026-32973.
www.yazoul.net/advisory/cve/cve-2026-32...
#CVE #CyberSecurity
CVE-2025-15379 - Critical
🔴 CVE-2025-15379 - Critical (10)
A command injection vulnerability exists in MLflow's model serving container initialization code,...
www.thehackerwire.com/vulnerability/CVE-2025-1...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-3945 - High
🟠 CVE-2026-3945 - High (7.5)
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to...
www.thehackerwire.com/vulnerability/CVE-2026-3...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-2328 - High
🟠 CVE-2026-2328 - High (7.5)
An unauthenticated remote attacker can exploit insufficient input validation to access backend co...
www.thehackerwire.com/vulnerability/CVE-2026-2...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-4416 - High
🟠 CVE-2026-4416 - High (7.8)
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vuln...
www.thehackerwire.com/vulnerability/CVE-2026-4...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-4415 - High
🟠 CVE-2026-4415 - High (8.1)
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the...
www.thehackerwire.com/vulnerability/CVE-2026-4...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
MLflow logo displayed on a blue background with network-style lines, representing the affected machine learning platform involved in CVE-2025-15036.
🚨 CVE-2025-15036 (CRITICAL 9.6)
MLflow archive extraction flaw allows attackers to overwrite arbitrary files via path traversal (“../”) in tar.gz files, potentially leading to privilege escalation and sandbox escape.
🔎 basefortify.eu/cve_reports/...
#CVE #CyberSecurity #MLflow #PathTraversal
Breach & Build — cybersecurity news
🔴 CVE-2026-33897 | CRITICAL (CVSS 9.9) Incus users, beware! A flaw allows root access to host servers. Immediate action is REQUIRED. Read our blog for full details NOW!
#CVE #BreachAndBuild #Incus #RootAccess #ContainerSecurity
breachandbuild.com/cve-2026-33897-cve-2026-...
#OT #Advisory VDE-2026-021
WAGO: Multiple Vulnerabilities in WAGO VC Hub
The VC Hub incorporates the Magick.NET‑Q16‑AnyCPU component, derived from ImageMagick, to process user‑uploaded images and generate thumbnails within the projects image library. Only authenticated users with the Design […]
#OT #Advisory VDE-2026-010
WAGO: Multiple Vulnerabilities in WAGO Solution Builder and WAGO Device Sphere
Multiple vulnerabilities have been identified in WAGO Solution Builder and WAGO Device Sphere that affect components responsible for authentication and system communication.
#CVE […]
CVE-2025-15036 - Critical
🔴 CVE-2025-15036 - Critical (9.6)
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow...
www.thehackerwire.com/vulnerability/CVE-2025-1...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-3124 - High
🟠 CVE-2026-3124 - High (7.5)
The Download Monitor plugin for WordPress is vulnerable to Insecure Direct Object Reference in al...
www.thehackerwire.com/vulnerability/CVE-2026-3...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-2370 - High
🟠 CVE-2026-2370 - High (8.1)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.3 before 18.8.7, 18...
www.thehackerwire.com/vulnerability/CVE-2026-2...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
The CVE program is "saved" by a mystery contract with a mystery number. Transparency? Not so much.
Plus: lookup.disclose.io beta is live, EU CRA hits 6 months, exploited vulns up 105%.
Policy Pulse #8: blog.disclose.io/policy-pulse-issue-8-wee... #CVE #PolicyPulse
CVE-2026-4946 - High
🟠 CVE-2026-4946 - High (8.8)
Ghidra versions prior to 12.0.3 improperly process annotation directives embedded in automaticall...
www.thehackerwire.com/vulnerability/CVE-2026-4...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-0558 - High
🟠 CVE-2026-0558 - High (7.5)
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated use...
www.thehackerwire.com/vulnerability/CVE-2026-0...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-0562 - High
🟠 CVE-2026-0562 - High (8.3)
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticate...
www.thehackerwire.com/vulnerability/CVE-2026-0...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-0560 - High
🟠 CVE-2026-0560 - High (7.5)
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2....
www.thehackerwire.com/vulnerability/CVE-2026-0...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
🔴 CVE-2026-34374 — CRITICAL (CVSS 9.1)
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by…
#CVE202634374 #CVE #cybersecurity
breachandbuild.com/cve-2026-34374-cve-2026-...
🔴 CVE-2026-30533 — CRITICAL (CVSS 9.8)
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
#CVE202630533 #CVE #cybersecurity
breachandbuild.com/cve-2026-30533-cve-2026-...
🔴 CVE-2026-30532 — CRITICAL (CVSS 9.8)
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
#CVE202630532 #CVE #cybersecurity
breachandbuild.com/cve-2026-30532-cve-2026-...
🔴 CVE-2026-30530 — CRITICAL (CVSS 9.8)
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action).…
#CVE202630530 #CVE #cybersecurity
breachandbuild.com/cve-2026-30530-cve-2026-...
🔴 CVE-2026-30302 — CRITICAL (CVSS 10.0)
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism…
#CVE202630302 #CVE #cybersecurity
breachandbuild.com/cve-2026-30302-cve-2026-...
🔴 CVE-2026-34205 — CRITICAL (CVSS 9.6)
Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with…
#CVE202634205 #CVE #cybersecurity
breachandbuild.com/cve-2026-34205-cve-2026-...
🔴 CVE-2026-33875 — CRITICAL (CVSS 9.3)
Gematik Authenticator securely authenticates users for login to digital health applications. Versions prior to 4.16.0 are vulnerable to authentication…
#CVE202633875 #CVE #cybersecurity
breachandbuild.com/cve-2026-33875-cve-2026-...
When a major breach hits, every minute counts. ⚠️ That's why our community-first approach at Yazoul Security prioritizes real-time alerts to help you stay informed and respond faster.
We monitor emerging threats so you don't have to.
https://www.yazoul.net
#CVE #CyberSecurity
CVE-2026-34005 - High
🟠 CVE-2026-34005 - High (8.8)
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command in...
www.thehackerwire.com/vulnerability/CVE-2026-3...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-34005 - High
🟠 CVE-2026-34005 - High (8.8)
In Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command in...
www.thehackerwire.com/vulnerability/CVE-2026-3...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-32915 - High
🟠 CVE-2026-32915 - High (8.8)
OpenClaw before 2026.3.11 contains a sandbox boundary bypass vulnerability allowing leaf subagent...
www.thehackerwire.com/vulnerability/CVE-2026-3...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack
CVE-2026-32914 - High
🟠 CVE-2026-32914 - High (8.8)
OpenClaw before 2026.3.12 contains an insufficient access control vulnerability in the /config an...
www.thehackerwire.com/vulnerability/CVE-2026-3...
#infosec #cybersecurity #CVE #vulnerability #security #patchstack