Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

kb.cert.org

CERT Recently Published Vulnerability Notes

Get the latest updates from CERT Recently Published Vulnerability Notes directly as they happen.

Follow now 133 followers

Latest posts

Last updated about 19 hours ago

VU#273940: Enterprise Access Management EAM does not rotate RSA keys

about 19 hours ago

Overview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform...

VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

about 20 hours ago

Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does...

VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

2 days ago

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure...

VU#280377: Dokploy is vulnerable to OS command injection

7 days ago

Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on...

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

8 days ago

Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized...

VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

8 days ago

Overview A vulnerability exists in Sentry Seer when the system is configured...

VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

13 days ago

Overview An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has...

VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks

14 days ago

Overview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included...

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

16 days ago

Overview The UEFI Shell program may expose raw memory access capabilities that,...

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

16 days ago

Overview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a...

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

16 days ago

Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's...

VU#889462: Casdoor authentication server is vulnerable to authorization bypass

21 days ago

Overview Casdoor is an open-source Access Management (IAM) platform used to manage...