[
News
|
Newsletters
|
Blogs
|
Lists
|
Media
|
Jobs
]
HoneyDB
[
vulnerabilities
|
tools
]
CISA Advisories
US-CERT
FullDisclosure
A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
Synology stale DNS allows practical interception of traffic from vulnerable DSM clients
Amplitude customers using domain proxies should update their configuration immediately.
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver
New Release: UFONet v2.0 - "R3DST4R!"...
XSSer v.1.9 - "Bl4ck Swarm!" released
NotCVE registry index — public records of vulnerabilities that shipped without a CVE
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
CVE-2026-56877 - Skillable SCORM userId authorisation bypass
US CERT Weekly
Open Source Security
Re: 432 Linux kernel CVEs
CVE-2026-16766: Catalyst::View::Wkhtmltopdf versions before 0.6.1 for Perl allow shell command injection (RCE) via PDF render options
GNU Inetutils talkd buffer overflow with long DNS names.
CVE-2026-53910: GNU diffutils bug, and some thoughts on "security" reports
Fwd: The GNU C Library version 2.44 is now available, fixes 3 CVEs
CVE-2026-66053: Apache Thrift: Python TSSLSocket Hostname Matcher Import
CVE-2026-58662: Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
CVE-2026-58389: Apache Thrift: Rust binary protocol non-strict path missing string size limit
CVE-2026-55971: Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()
CVE-2026-58023: Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path
© 2026 RiskDiscovery | Sponsored by:
Deception Logic