Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

kb.cert.org

CERT Recently Published Vulnerability Notes

Get the latest updates from CERT Recently Published Vulnerability Notes directly as they happen.

Follow now 134 followers

Latest posts

Last updated 5 days ago

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities

5 days ago

Overview VPS.org's one-click deployment templates provision services with default passwords and predefined...

VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure

6 days ago

Overview Six vulnerabilities have been discovered within the SGLang project, including remote...

VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities

6 days ago

Overview Two vulnerabilities in the REST API were found in Golf Compete...

VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)

7 days ago

Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows...

VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure

7 days ago

Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution....

VU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface

8 days ago

Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway...

VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling

13 days ago

Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These...

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability

14 days ago

Overview Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside...

VU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability

14 days ago

Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server...

VU#762226: Plane contains multi-tenant authorization bypass vulnerability

15 days ago

Overview The project management tool Plane, versions 1.3.0 and earlier, contains a...

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions

20 days ago

Overview A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that...

VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem

20 days ago

Overview A Pickle deserialization vulnerability has been discovered within the SGLang project,...