Critical exposure
CVE-2020-27372 Brandy Project Brandy Buffer Overflow
- CVSS 9.8
New critical Brandy Project Brandy Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
New critical Brandy Project Brandy Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Miniftpd Project Miniftpd Buffer Overflow (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Os4ed Opensis SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firm...
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
There is an improper authentication vulnerability in Hero-CT060 before 1.0.0.200.
A Buffer Overflow vulnerability exists in the latest version of Miniftpd in the do_retr function in ftpproto.c
Opensis-Classic Version 8.0 is affected by a SQL injection vulnerability due to a lack of sanitization of input data at two parameters $_...
An SQL Injection vulnerability exists in openSIS Community Edition version 8.0 via ForgotPassUserName.php.
Projectsend version r1295 is affected by a directory traversal vulnerability.
CMSUno version 1.7.2 is affected by a PHP code execution vulnerability.
Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.