Doorzoek en filter alle geregistreerde cyberdreigingen voor gemeenten.
367 dreigingen gevonden · pagina 14 van 31
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
CVE-2025-39964
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Comm
CVE-2026-20274
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle VM VirtualBox, waaronder mogelijkheden voor lokale en geauthenticeerde kwaadwillenden om ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van laag tot hoog. Van de in totaal 19 kwetsbaarheden kan volgens Oracle één kwetsbaarheid zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het verkrijgen van ongeautoriseerde toegang tot gevoelige informatie, het wijzigen van gegevens en
CVE-2026-87273
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.
Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek aangemerkt. Op basis van de door Cisco gepubliceerde CVSS-scores kunnen vier kwetsbaarheden zonder auth
CVE-2026-20130
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If
CVE-2026-20316
A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands. This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative cred
CVE-2026-20350
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future at
CVE-2026-20235
Oracle heeft 16 kwetsbaarheden verholpen in diverse Oracle PeopleSoft-producten, waaronder PeopleSoft Enterprise PeopleTools, PeopleSoft Enterprise PRTL Interaction Hub en PeopleSoft Enterprise CC Common Application Objects. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle PeopleSoft-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores in de categorie hoog. Van de in totaal 16 kwetsbaarheden kunnen volgens Oracle vier kwetsba
CVE-2026-73954
Oracle heeft 3 kwetsbaarheden verholpen in Oracle Java SE, waaronder Oracle GraalVM for JDK en Oracle GraalVM Enterprise Edition. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Java SE-producten, waarbij niet-geauthenticeerde kwaadwillenden via netwerktoegang kwetsbaarheden in de Compiler-component kunnen misbruiken. De kwetsbaarheden hebben CVSS-scores in de categorie hoog. Alle drie de kwetsbaarheden kunnen volgens Oracle zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden tot het verkrijgen van ongeautoriseerde toegang tot ge
CVE-2026-83357
Oracle heeft 7 kwetsbaarheden verholpen in diverse Oracle Enterprise Manager-producten, waaronder Oracle Enterprise Manager Base Platform, Oracle Enterprise Manager for Fusion Middleware en Oracle Enterprise Manager for Oracle Database. De beveiligingsupdates zijn niet van toepassing op client-only installaties waarop Oracle Enterprise Manager niet is geïnstalleerd. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Enterprise Manager-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerd
CVE-2026-2332