CVE Notify
19.7K subscribers
4 photos
301K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
🚨 CVE-2021-31196
Microsoft Exchange Server Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-31979
Windows Kernel Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-33771
Windows Kernel Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-34473
Microsoft Exchange Server Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-34523
Microsoft Exchange Server Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-34448
Scripting Engine Memory Corruption Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-34484
Windows User Profile Service Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-34486
Windows Event Tracing Elevation of Privilege Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2021-38646
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability

πŸŽ–@cveNotify
🚨 CVE-2025-9242
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.
If the Firebox was previously configured with the mobile user VPN with IKEv2 or a branch office VPN using IKEv2 to a dynamic gateway peer, and both of those configurations have since been deleted, that Firebox may still be vulnerable if a branch office VPN to a static gateway peer is still configured.

πŸŽ–@cveNotify
🚨 CVE-2026-16232
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

πŸŽ–@cveNotify
🚨 CVE-2026-12118
IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data.

πŸŽ–@cveNotify
🚨 CVE-2026-12733
IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.

πŸŽ–@cveNotify
🚨 CVE-2026-12943
IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

πŸŽ–@cveNotify
🚨 CVE-2026-18140
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server.



To remediate this issue, users should upgrade to aws-smithy-json 0.62.7 or later and rebuild.

πŸŽ–@cveNotify
🚨 CVE-2026-18245
Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio component or theme schema values due to insufficient coverage and effectiveness of the input validation introduced for CVE-2025-4318.



To remediate this issue, users should upgrade to version 2.20.6

πŸŽ–@cveNotify
🚨 CVE-2026-10569
IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This exposure could allow an attacker with access to the logs to potentially obtain senstive values related to that step.

πŸŽ–@cveNotify
🚨 CVE-2026-21662
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.

This issue affects FM Systems Employee: before 2025.3.1.

πŸŽ–@cveNotify
🚨 CVE-2026-34490
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.

This issue affects XAAP Application: before 1.53.

πŸŽ–@cveNotify
🚨 CVE-2026-34497
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).

This issue affects FM Systems Employee: before 2025.3.1.

πŸŽ–@cveNotify