7.5

CVSS3.1

CVE-2026-25791 - Sliver has a DNS C2 OTP Bypass Allows Unauthenticated Session Flooding and Denial of Service

Sliver is a command and control framework that uses a custom Wireguard netstack. Prior to 1.7.0, the DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored wit…

📅 Published: Feb. 9, 2026, 8:34 p.m. 🔄 Last Modified: Feb. 9, 2026, 8:34 p.m.

5.8

CVSS3.1

CVE-2026-25765 - Faraday affected by SSRF via protocol-relative URL host override in build_exclusive_url

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Prior to 2.14.1, Faraday's build_exclusive_url method (in lib/faraday/connection.rb) uses Ruby's URI#merge to combine the connection's base URL with a user-supplied path. Per RFC 3986, protocol-…

📅 Published: Feb. 9, 2026, 8:30 p.m. 🔄 Last Modified: Feb. 9, 2026, 8:30 p.m.

8.8

CVSS3.1

CVE-2026-25761 - Command injection via crafted filenames in Super-linter Action

Super-linter is a combination of multiple linters to run as a GitHub Action or standalone. From 6.0.0 to 8.3.0, the Super-linter GitHub Action is vulnerable to command injection via crafted filenames. When this action is used in downstream GitHub Actions workflows, an attacker can submit a pull req…

📅 Published: Feb. 9, 2026, 8:27 p.m. 🔄 Last Modified: Feb. 9, 2026, 8:27 p.m.

5.8

CVSS4.0

CVE-2026-25740 - Privilege escalation to the `CAP_NET_RAW` capability via the `programs.captive-browser` NixOS module

captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localh…

📅 Published: Feb. 9, 2026, 8:17 p.m. 🔄 Last Modified: Feb. 9, 2026, 8:17 p.m.

7.5

CVSS3.1

CVE-2026-25639 - Axios affected by Denial of Service via __proto__ Key in mergeConfig

Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ as an own property. An attacker can trigger this by providing a malicious configuration object cre…

📅 Published: Feb. 9, 2026, 8:11 p.m. 🔄 Last Modified: Feb. 9, 2026, 8:11 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here