cve

25 stories and discussions about cve, aggregated from every source we track.

1.

SAFA details the full exploitation of CVE-2025-13032, turning a double-fetch vulnerability in Avast's kernel driver into a local privilege escalation to SYSTEM on Windows 11.

107 points•safateam•6 days ago•27 comments•
3.

A while ago when I was running my Talos II in hashed page table (HPT) mode for KVM-PR purposes , I started noticing some weird kernel behavi...

7 points•inactive-user•over 7 years ago•0 comments
5.

PHP's http:// stream wrapper sent Authorization, Cookie and Proxy-Authorization to any host a redirect pointed at, the bug curl fixed in 2018.

3 points•amvalex•6 days ago•1 comment•
6.

To combat the exponential growth of AI-driven CVEs, Canonical is shifting to a rapid 2-week Linux kernel SRU cycle published weekly. Read about the update.

3 points•speckx•6 days ago•0 comments•
7.

<p>Disclosure of, and fix for, a bug that could lead miners to inflate the Bitcoin supply.</p>

3 points•gerikson•about 8 years ago•0 comments
8.

Kestra Unauthenticated RCE. Contribute to EQSTLab/CVE-2026-49869 development by creating an account on GitHub.

2 points•soltanov•1 day ago•0 comments•
9.

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775, CVE-2026

2 points•wylie39•3 days ago•0 comments•
10.

The September 22, 2026 out-of-band security update for Next.js is now available

2 points•joshcsimmons•8 days ago•1 comment•
12.
1 points•ni5arga•about 1 hour ago•0 comments•
13.
1 points•joshcsimmons•about 14 hours ago•0 comments•
14.
1 points•soltanov•2 days ago•1 comment•
15.

Taking 'execute logging' a bit too literally - CVE-2026-88771

1 points•airhangerf15•2 days ago•0 comments•
16.
1 points•noktec•2 days ago•0 comments•
17.

The app showed two codes. The API returned all of them, master PIN included. The Planck Proof team's coordinated disclosure of CVE-2026-75960.

1 points•ninjahub•2 days ago•0 comments•
18.

CVE-2026-14540: an SSRF in Google's official MCP Toolbox for Databases, CVSS 8.0, credited by name in the fix. Why the bug class is invisible to standard dependency scanners.

1 points•AnasSyed28•3 days ago•1 comment•
19.

For almost a year, my jailexec connection plugin let a compromised FreeBSD jail redirect a root-owned write onto the jail host. The input validation was fine. The problem was on which side of the j...

1 points•zdw•3 days ago•0 comments•
20.
1 points•echelongraph•4 days ago•0 comments•
21.

Vulnerability-Lookup - Fast vulnerability lookup correlation from different sources.

1 points•anonyoum•6 days ago•0 comments•
22.

Neutralizing CISA active Linux kernel CVEs (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682) via modern eBPF, module disarmament, and containerd user namespaces. - mc493/linux-kernel-zero-day-mitiga...

1 points•mc493•6 days ago•0 comments•
23.

No CVE needed: how a GitHub issue hijacked an AI agent

1 points•kielltampubolon•8 days ago•1 comment
24.
1 points•spyc•8 days ago•0 comments•

Related topics