##
Updated at UTC 2026-08-16T07:07:33.244504
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18316 | 9.1 | 0.00% | 2 | 0 | 2026-08-16T06:16:51.683000 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification | |
| CVE-2026-18432 | 9.8 | 0.00% | 2 | 0 | 2026-08-16T05:16:48.307000 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege | |
| CVE-2026-17123 | 8.8 | 0.00% | 2 | 0 | 2026-08-16T05:16:48.033000 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | |
| CVE-2026-16099 | 8.8 | 0.00% | 2 | 0 | 2026-08-16T05:16:47.780000 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-16098 | 9.8 | 0.00% | 2 | 0 | 2026-08-16T05:16:47.667000 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | |
| CVE-2026-14524 | 9.1 | 0.00% | 2 | 0 | 2026-08-16T05:16:46.493000 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | |
| CVE-2026-14498 | 8.8 | 0.00% | 2 | 0 | 2026-08-16T05:16:46.360000 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-19924 | 9.8 | 0.00% | 4 | 0 | 2026-08-16T02:16:47.247000 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01 | |
| CVE-2026-73054 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in | |
| CVE-2026-73045 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T00:31:27 | SiYuan before 3.7.4 contains an improper restriction of excessive authentication | |
| CVE-2026-73044 | 9.0 | 0.00% | 2 | 0 | 2026-08-16T00:31:27 | SiYuan versions before v3.7.4 fail to validate or escape table column width valu | |
| CVE-2026-73043 | 9.0 | 0.00% | 2 | 0 | 2026-08-16T00:31:26 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t | |
| CVE-2026-73055 | 4.8 | 0.00% | 2 | 0 | 2026-08-15T22:16:55.427000 | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde ( | |
| CVE-2026-73053 | 9.0 | 0.00% | 4 | 0 | 2026-08-15T22:16:55.157000 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th | |
| CVE-2026-73052 | 9.0 | 0.00% | 4 | 0 | 2026-08-15T22:16:55.017000 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and | |
| CVE-2026-73050 | 9.0 | 0.00% | 2 | 0 | 2026-08-15T22:16:54.870000 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attr | |
| CVE-2026-73046 | 9.8 | 0.00% | 2 | 0 | 2026-08-15T22:16:54.600000 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t | |
| CVE-2026-73042 | 9.0 | 0.00% | 2 | 0 | 2026-08-15T22:16:54.030000 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int | |
| CVE-2026-73041 | 9.0 | 0.00% | 2 | 0 | 2026-08-15T22:16:53.883000 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt | |
| CVE-2026-18855 | 9.1 | 0.00% | 3 | 0 | 2026-08-15T19:16:32.160000 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d | |
| CVE-2026-19900 | 8.1 | 0.00% | 2 | 0 | 2026-08-15T18:31:25 | A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted el | |
| CVE-2026-19598 | 9.8 | 0.00% | 2 | 0 | 2026-08-15T18:31:24 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to | |
| CVE-2026-19901 | 8.1 | 0.00% | 2 | 0 | 2026-08-15T18:16:24.830000 | A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affec | |
| CVE-2026-73634 | None | 0.00% | 1 | 0 | 2026-08-15T12:30:25 | Uncontrolled resource consumption vulnerability in Apache Struts. An application | |
| CVE-2026-18438 | 8.8 | 0.98% | 1 | 0 | 2026-08-15T12:30:25 | The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready | |
| CVE-2026-73635 | 0 | 0.00% | 1 | 0 | 2026-08-15T11:16:27.540000 | Allocation of resources without limits or throttling vulnerability in Apache Str | |
| CVE-2026-15826 | 9.8 | 0.80% | 3 | 0 | 2026-08-15T09:34:13 | The User Profile Builder plugin for WordPress is vulnerable to Authentication By | |
| CVE-2026-16142 | 9.8 | 0.38% | 2 | 0 | 2026-08-15T09:34:09 | The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all ver | |
| CVE-2026-15142 | 7.5 | 0.21% | 1 | 0 | 2026-08-15T09:16:28.557000 | The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Esca | |
| CVE-2026-14279 | 8.8 | 0.28% | 1 | 0 | 2026-08-15T07:16:19.120000 | The Wholesale Market plugin for WordPress is vulnerable to privilege escalation | |
| CVE-2022-21882 | 7.0 | 54.55% | 1 | 8 | 2026-08-15T04:18:00.220000 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2019-5591 | 6.5 | 18.42% | 1 | 1 | 2026-08-15T04:17:41.413000 | A Default Configuration vulnerability in FortiOS may allow an unauthenticated at | |
| CVE-2026-15965 | 8.8 | 0.58% | 1 | 0 | 2026-08-15T03:30:32 | The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for | |
| CVE-2026-15341 | 9.8 | 0.33% | 1 | 0 | 2026-08-15T03:30:32 | The User Session Synchronizer plugin for WordPress is vulnerable to Authenticati | |
| CVE-2026-14484 | 9.1 | 0.76% | 1 | 0 | 2026-08-15T03:30:27 | The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress | |
| CVE-2026-15303 | 9.8 | 0.44% | 1 | 0 | 2026-08-15T03:16:47.670000 | The 6Storage Rentals plugin for WordPress is vulnerable to authentication bypass | |
| CVE-2026-69414 | 7.8 | 0.24% | 1 | 0 | 2026-08-15T00:31:32 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-73683 | 8.1 | 0.44% | 1 | 0 | 2026-08-14T22:17:11.550000 | Laravel Socialite's Facebook provider contains an authentication bypass vulnerab | |
| CVE-2026-17181 | 9.3 | 0.59% | 1 | 0 | 2026-08-14T21:31:35 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write fi | |
| CVE-2026-17182 | 9.8 | 0.77% | 1 | 0 | 2026-08-14T21:31:35 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass a | |
| CVE-2026-17186 | 9.9 | 0.47% | 1 | 0 | 2026-08-14T21:31:35 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute | |
| CVE-2026-67365 | 0 | 0.23% | 1 | 0 | 2026-08-14T20:16:55.850000 | Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4. | |
| CVE-2026-19909 | 7.5 | 0.33% | 1 | 0 | 2026-08-14T20:16:52.437000 | PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnera | |
| CVE-2026-17184 | 9.8 | 0.80% | 1 | 0 | 2026-08-14T20:16:51.010000 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute | |
| CVE-2026-66456 | 6.5 | 0.21% | 1 | 0 | 2026-08-14T19:09:20.713000 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= | |
| CVE-2026-73633 | 7.5 | 0.32% | 1 | 1 | 2026-08-14T15:32:50 | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Str | |
| CVE-2026-67614 | 9.8 | 0.55% | 1 | 0 | 2026-08-14T13:19:06.033000 | CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the We | |
| CVE-2026-19789 | 8.8 | 0.47% | 1 | 0 | 2026-08-14T06:31:05 | A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vuln | |
| CVE-2026-59310 | 9.8 | 1.14% | 2 | 0 | 2026-08-14T05:16:59.407000 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-65400 | 7.1 | 0.50% | 5 | 0 | 2026-08-14T03:31:24 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2026-68432 | 8.8 | 0.13% | 1 | 0 | 2026-08-14T00:33:05 | In the Linux kernel, the following vulnerability has been resolved: vxlan: requ | |
| CVE-2026-62911 | 8.0 | 0.72% | 1 | 0 | 2026-08-13T18:57:39.290000 | Authentication bypass by capture-replay in Microsoft Exchange Server allows an a | |
| CVE-2026-70328 | 6.5 | 0.85% | 1 | 0 | 2026-08-13T16:18:59.837000 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to | |
| CVE-2026-55040 | 9.1 | 3.97% | 4 | 2 | 2026-08-13T15:34:13 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack | |
| CVE-2026-14863 | 8.8 | 1.67% | 1 | 0 | 2026-08-13T14:16:54.583000 | FileRun up to and including version 2026.2.0 contains an OS command injection vu | |
| CVE-2026-50656 | 7.8 | 10.75% | 1 | 3 | 2026-08-12T17:17:27.983000 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protect | |
| CVE-2026-18704 | 6.5 | 0.21% | 1 | 0 | 2026-08-11T21:17:33.203000 | An issue in MongoDB Server's aggregation framework could allow an authenticated | |
| CVE-2026-71362 | 9.1 | 0.48% | 1 | 1 | 2026-08-11T18:32:00 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul | |
| CVE-2026-62837 | 6.5 | 0.86% | 1 | 0 | 2026-08-11T18:31:33 | Relative path traversal in Microsoft Office SharePoint allows an authorized atta | |
| CVE-2026-44758 | 9.1 | 0.51% | 1 | 0 | 2026-08-11T15:17:29.603000 | SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig | |
| CVE-2026-58231 | 10.0 | 0.73% | 9 | 1 | 2026-08-11T12:30:28 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-34265 | 9.8 | 0.44% | 1 | 0 | 2026-08-11T03:31:57 | SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl | |
| CVE-2026-28318 | 7.5 | 8.35% | 1 | 2 | 2026-07-22T20:10:00.127000 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash t | |
| CVE-2026-58427 | None | 0.34% | 1 | 0 | 2026-07-21T21:49:02 | ## Summary PR #38145 fixed ListPublicMembers and IsPublicMember but missed List | |
| CVE-2025-60710 | 7.8 | 4.60% | 1 | 2 | 2026-06-17T09:50:01.133000 | Improper link resolution before file access ('link following') in Host Process f | |
| CVE-2025-49091 | 8.2 | 0.57% | 2 | 1 | 2026-06-17T09:30:46.797000 | KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. I | |
| CVE-2019-0803 | 7.8 | 45.23% | 1 | 3 | 2026-06-17T02:08:56.287000 | An elevation of privilege vulnerability exists in Windows when the Win32k compon | |
| CVE-2018-0798 | 8.8 | 90.99% | 1 | 1 | 2026-06-17T01:31:40.897000 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Offic | |
| CVE-2016-0189 | 7.5 | 93.71% | 1 | 2 | 2026-06-17T00:37:05.163000 | The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in I | |
| CVE-2021-4034 | 7.8 | 94.92% | 1 | 100 | 2025-10-22T00:33:35 | A local privilege escalation vulnerability was found on polkit's pkexec utility. | |
| CVE-2020-0618 | 8.8 | 99.02% | 1 | 4 | 2025-10-22T00:32:53 | A remote code execution vulnerability exists in Microsoft SQL Server Reporting S | |
| CVE-2020-29574 | 9.8 | 4.73% | 1 | 0 | 2025-10-22T00:32:01 | An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 | |
| CVE-2020-0968 | 7.5 | 30.02% | 1 | 0 | 2025-10-22T00:31:52 | A remote code execution vulnerability exists in the way that the scripting engin | |
| CVE-2018-0802 | 7.8 | 87.42% | 1 | 7 | 2025-10-22T00:31:30 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Offic | |
| CVE-2026-49261 | 0 | 1.58% | 2 | 0 | N/A | ||
| CVE-2026-56864 | 0 | 0.25% | 1 | 0 | N/A | ||
| CVE-2026-19474 | 0 | 0.00% | 2 | 0 | N/A | ||
| CVE-2026-18549 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-18500 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-44772 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 10.40% | 1 | 5 | template | N/A |
updated 2026-08-16T06:16:51.683000
2 posts
CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##updated 2026-08-16T05:16:48.307000
2 posts
🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:48.033000
2 posts
🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:47.780000
2 posts
🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:47.667000
2 posts
🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:46.493000
2 posts
🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T05:16:46.360000
2 posts
🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T02:16:47.247000
4 posts
🔴 CVE-2026-19924 - Critical (9.8)
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19924/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! https://radar.offseq.com/threat/cve-2026-19924-improper-authentication-in-tenda-ac10-b84751472c0f965f #OffSeq #CVE202619924 #Tenda #Vuln
##🔴 CVE-2026-19924 - Critical (9.8)
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19924/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! https://radar.offseq.com/threat/cve-2026-19924-improper-authentication-in-tenda-ac10-b84751472c0f965f #OffSeq #CVE202619924 #Tenda #Vuln
##updated 2026-08-16T00:31:35
2 posts
🟠 CVE-2026-73054 - High (7.5)
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73054 - High (7.5)
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:27
2 posts
🟠 CVE-2026-73045 - High (7.5)
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73045 - High (7.5)
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:27
2 posts
🔴 CVE-2026-73044 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73044 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:26
2 posts
🔴 CVE-2026-73043 - Critical (9)
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73043 - Critical (9)
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:55.427000
2 posts
CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. https://radar.offseq.com/threat/cve-2026-73055-improper-encoding-or-escaping-of-output-in-ericcornelissen-shescape-3ef90f5f16672f7b #OffSeq #CVE202673055 #infosec
##CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. https://radar.offseq.com/threat/cve-2026-73055-improper-encoding-or-escaping-of-output-in-ericcornelissen-shescape-3ef90f5f16672f7b #OffSeq #CVE202673055 #infosec
##updated 2026-08-15T22:16:55.157000
4 posts
CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. https://radar.offseq.com/threat/cve-2026-73053-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-1654398c24cf93d4 #OffSeq #XSS #Vuln #SiYuan
##🔴 CVE-2026-73053 - Critical (9)
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. https://radar.offseq.com/threat/cve-2026-73053-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-1654398c24cf93d4 #OffSeq #XSS #Vuln #SiYuan
##🔴 CVE-2026-73053 - Critical (9)
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:55.017000
4 posts
CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. https://radar.offseq.com/threat/cve-2026-73052-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-c5f0eb8b5e84714b #OffSeq #XSS #SiYuan #Infosec
##🔴 CVE-2026-73052 - Critical (9)
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. https://radar.offseq.com/threat/cve-2026-73052-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-c5f0eb8b5e84714b #OffSeq #XSS #SiYuan #Infosec
##🔴 CVE-2026-73052 - Critical (9)
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.870000
2 posts
🔴 CVE-2026-73050 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73050 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.600000
2 posts
🔴 CVE-2026-73046 - Critical (9.8)
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73046 - Critical (9.8)
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.030000
2 posts
🔴 CVE-2026-73042 - Critical (9)
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73042 - Critical (9)
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:53.883000
2 posts
🔴 CVE-2026-73041 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73041 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T19:16:32.160000
3 posts
CVE-2026-18855 - Critical RCE in WordPress Link Library plugin. Unauthenticated arbitrary file deletion via ll_delete_link_fields. CVSS 9.1. Patch under review. Update immediately. #CVE #WordPress #infosec
##🔴 CVE-2026-18855 - Critical (9.1)
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-18855 - Critical (9.1)
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T18:31:25
2 posts
🟠 CVE-2026-19900 - High (8.1)
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19900/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19900 - High (8.1)
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19900/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T18:31:24
2 posts
🔴 CVE-2026-19598 - Critical (9.8)
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19598/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-19598 - Critical (9.8)
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19598/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T18:16:24.830000
2 posts
🟠 CVE-2026-19901 - High (8.1)
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19901/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19901 - High (8.1)
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19901/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T12:30:25
1 posts
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-15T12:30:25
1 posts
🟠 CVE-2026-18438 - High (8.8)
The Templately – Elementor & Gutenberg Template Library: 6500+ Free & Pro Ready Templates And Cloud! plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.7.1 via the fetch_remote_file function. This...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18438/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T11:16:27.540000
1 posts
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-15T09:34:13
3 posts
🔴 CVE-2026-15826 - Critical (9.8)
The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. This is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-15826: CRITICAL flaw in User Profile Builder (≤3.16.4) allows auth bypass via type conversion error. Attackers gain admin (user ID 1) access. Restrict registration or disable plugin. Details: https://radar.offseq.com/threat/cve-2026-15826-cwe-704-incorrect-type-conversion-or-cast-in-cozmoslabs-user-profile-builder-beautiful-03ed293eb36de594 #OffSeq #WordPress #Infosec #CVE
##CVE-2026-15826 (CVSS 9.8) is a User Profile Builder vulnerability letting attackers log in as WordPress admin. Over 40,000 sites affected; update to 3.16.5
##updated 2026-08-15T09:34:09
2 posts
🔴 CVE-2026-16142 - Critical (9.8)
The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_update() AJAX handler being registered for unauthenticated users and accepting an arbitrary truebo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-16142 (CRITICAL, CVSS 9.8): TrueBooker WP plugin ≤1.2.6 is vulnerable to auth bypass via user-controlled AJAX handler. Attackers can hijack any account by changing email & triggering password reset. Restrict or disable TrueBooker. https://radar.offseq.com/threat/cve-2026-16142-cwe-639-authorization-bypass-through-user-controlled-key-in-themetechmount-truebooker-17123cd1c5904122 #OffSeq #WordPress #CVE2026_16142
##updated 2026-08-15T09:16:28.557000
1 posts
🟠 CVE-2026-15142 - High (7.5)
The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15142/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T07:16:19.120000
1 posts
🟠 CVE-2026-14279 - High (8.8)
The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14279/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T04:18:00.220000
1 posts
8 repos
https://github.com/Ascotbe/Kernelhub
https://github.com/KaLendsi/CVE-2022-21882
https://github.com/jessica0f0116/cve_2022_21882-cve_2021_1732
https://github.com/r1l4-i3pur1l4/CVE-2022-21882
https://github.com/Al1ex/WindowsElevation
https://github.com/L4ys/CVE-2022-21882
CVE-2022-21882 - Changed to Known Ransomware Status
Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k contains an unspecified vulnerability that allows for privilege escalation.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 UTCDate Added to KEV: 2022-02-04View CVE Details
##updated 2026-08-15T04:17:41.413000
1 posts
1 repos
https://github.com/ayewo/fortios-ldap-mitm-poc-CVE-2019-5591
CVE-2019-5591 - Changed to Known Ransomware Status
Fortinet FortiOS Default Configuration VulnerabilityVendor: FortinetProduct: FortiOSFortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server.Status changed from Unknown to Known for ransomware campaign usage.Flip https://nvd.nist.gov/vuln/detail/CVE-2019-5591
##updated 2026-08-15T03:30:32
1 posts
🟠 CVE-2026-15965 - High (8.8)
The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation m...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15965/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T03:30:32
1 posts
CVE-2026-15341: CRITICAL auth bypass in rafasashi User Session Synchronizer ≤1.4.0. Attackers can impersonate any WP user — including admins. Disable plugin until fix is released. 🔓 https://radar.offseq.com/threat/cve-2026-15341-cwe-287-improper-authentication-in-rafasashi-user-session-synchronizer-d4decb8e5e90d3fb #OffSeq #WordPress #Vuln #Infosec
##updated 2026-08-15T03:30:27
1 posts
🔴 CVE-2026-14484 - Critical (9.1)
The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14484/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T03:16:47.670000
1 posts
CVE-2026-15303: CRITICAL auth bypass in sixstorage 6Storage Rentals <=2.27.0. Unauthenticated attackers can impersonate any WP user via exposed AJAX handler. Restrict endpoint or disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15303-cwe-287-improper-authentication-in-sixstorage-6storage-rentals-a7f565714ebb98e6 #OffSeq #WordPress #Vuln #Security
##updated 2026-08-15T00:31:32
1 posts
🟠 CVE-2026-69414 - High (7.8)
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnera...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-69414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-14T22:17:11.550000
1 posts
🟠 CVE-2026-73683 - High (8.1)
Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function wit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73683/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-14T21:31:35
1 posts
CVE-2026-17181: IBM Db2 Mirror for i 7.4 – 7.6 has a CRITICAL path traversal flaw (CVSS 9.3) enabling remote file writes — no auth needed. No patch yet. Restrict access & follow IBM updates. https://radar.offseq.com/threat/ibm-db2-mirror-for-i-74-75-and-76-could-allow-a-remote-attacker-to-write-files-to-arbitrary-locations-05bd59624b3ef1c8 #OffSeq #IBM #Db2 #Vulnerability #InfoSec
##updated 2026-08-14T21:31:35
1 posts
CRITICAL: IBM Db2 Mirror for i (7.4-7.6) vulnerable to remote authentication bypass (CVE-2026-17182) due to improper URI path validation. Sensitive data at risk — restrict service access until patch available. https://radar.offseq.com/threat/ibm-db2-mirror-for-i-74-75-and-76-could-allow-a-remote-attacker-to-bypass-authentication-and-obtain-or-13a675f43aebb05d #OffSeq #Db2 #Vuln #CVE202617182
##updated 2026-08-14T21:31:35
1 posts
IBM Db2 Mirror for i (7.4 – 7.6) faces CRITICAL OS command injection (CVE-2026-17186, CVSS 9.9) 🛡️. No patch yet — restrict access, monitor for abuse. No exploits seen in wild. https://radar.offseq.com/threat/cve-2026-17186-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-bb1e0c030a679943 #OffSeq #IBM #Vuln #OSCommandInjection
##updated 2026-08-14T20:16:55.850000
1 posts
CVE-2026-67365: Unauthenticated SQL injection in Joomla iCagenda (4.0.0 – 4.0.11). Exploitable via com_ajax, no auth needed. CRITICAL (CVSS 9.2). Restrict endpoint & monitor for attacks. https://radar.offseq.com/threat/cve-2026-67365-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-8f2e4ed9eff903b1 #OffSeq #CVE202667365 #Joomla #SQLi
##updated 2026-08-14T20:16:52.437000
1 posts
🟠 CVE-2026-19909 - High (7.5)
PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19909/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-14T20:16:51.010000
1 posts
CVE-2026-17184 (CRITICAL, CVSS 9.8): IBM Db2 Mirror for i 7.4 – 7.6 allows remote code execution via external file name/path control. No privileges needed. Restrict access, monitor advisories. https://radar.offseq.com/threat/ibm-db2-mirror-for-i-74-75-and-76-could-allow-a-remote-attacker-to-execute-arbitrary-code-due-to-9c0fd8c4bcffe5ba #OffSeq #IBM #Vuln #Cybersecurity
##updated 2026-08-14T19:09:20.713000
1 posts
CVE-2026-66456 - Stored XSS in BestWebSoft Profile Extra Fields ≤1.3.4. Subscriber-level attack. CVSS 6.5. Unpatched. Disable or restrict access now. #CVE #WordPress #infosec
##updated 2026-08-14T15:32:50
1 posts
1 repos
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-14T13:19:06.033000
1 posts
CyberPanel's hard-coded JWT secret grants an unauthenticated root shell
CyberPanel WebTerminal의 CVE-2026-67614는 2.4.2~2.4.6에서 소스에 하드코딩된 HS256 JWT 비밀키를 이용해 인증 없이 `ssh_user=root` 토큰을 위조하고 원격 루트 셸을 획득할 수 있는 CVSS 9.8 취약점입니다. WebTerminal은 기본적으로 root 권한으로 8888/TLS 포트에서 실행되므로, 인터넷에 노출된 해당 버전의 패널은 즉각적인 침해 위험이 있습니다. 2.4.7~3.0.0은 설치별 시크릿을 도입했지만 fallback 및 토큰 신뢰 설계 문제...
https://hellorecon.com/blog/cve-2026-67614-cyberpanel-webterminal-jwt-root-shell
##updated 2026-08-14T06:31:05
1 posts
CVE-2026-19789 – Critical stack buffer overflow in Tenda AC1206 via /goform/WifiGuestSet. Remote RCE possible. CVSS 8.8. Unpatched. Update or isolate now. #CVE #Tenda #infosec
##updated 2026-08-14T05:16:59.407000
2 posts
2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-08-14T03:31:24
5 posts
Critical macOS Screen Sharing Flaw Is Already Being Exploited: Attackers Gain Root Access and Install Monero Miners + Video
A Dangerous Race Between Apple’s Patch and Cybercriminals A critical vulnerability in macOS has moved from a security advisory to an active exploitation problem in remarkably little time. The Dutch National Cyber Security Centre (NCSC-NL) has confirmed that attackers are exploiting CVE-2026-65400, a critical authentication flaw in Apple’s built-in…
##Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #newsAtKukei https://masto.kukei.eu/browse/news category:
- **Indonesia earthquake**: Magnitude 7.7 quake off Flores Island kills at least 38, injures 13, with 2,000 evacuated and dozens of homes damaged.
- **AfD politician violence**: AfD politician Arno Bausemer injured a 14-year-old boy with a baseball bat in Stendal, Germany.
- **macOS security flaw**: CVE-2026-65400, a macOS Screen Sharing [1/3]
A severe macOS Screen Sharing vulnerability (CVE-2026-65400) is being exploited to install Monero miners on exposed systems. Apple has issued emergency updates; users should update their systems promptly to mitigate this risk.
#macOS #Security #CVE202665400 #Monero #Cybersecurity #Apple
https://thedailytechfeed.com/critical-macos-screen-sharing-flaw-exploited-to-deploy-monero-miner-2/
##Vulnerability giving attackers full control of Macs is under active exploitation
Apple이 지난주 패치한 macOS 화면 공유 취약점 CVE-2026-65400(심각도 7.1)이 실제 공격에 악용되고 있다. 네덜란드 NCSC는 인터넷에 VNC 포트(5900)를 노출한 여러 Mac에서 공격자가 root 권한을 획득하고 Monero 채굴기를 설치한 사례를 확인했다. 영향 대상은 macOS Tahoe, Sequoia, Sonoma이며, 화면 공유의 상태 관리 결함으로 인증 없는 원격 접근이 가능할 수...
##The Dutch NCSC reports active exploitation of CVE-2026-65400, an authentication flaw in macOS Screen Sharing. Attackers leverage public exploit code to deploy Monero miners on systems exposing the built-in VNC service on TCP/5900. Organizations running macOS with screen sharing enabled should audit their perimeter exposure immediately.
#CVE2026 #ScreenSharing #MoneroMiner #MacOSSecurity
https://cyberworldops.eu/en/macos-screen-sharing-actively-exploited-monero-miner-installed-on
##updated 2026-08-14T00:33:05
1 posts
🐧 SIGINT // Ubuntu Watch — 2026-08-16
VXLAN changelink missing CAP_NET_ADMIN check in device netns means unprivileged containers could reconfigure host tunnels. If you run VXLAN overlays for k8s or LXD networking, patch this before someone pivots across your virtual fabric.
##updated 2026-08-13T18:57:39.290000
1 posts
Microsoft has patched critical Exchange Server vulnerabilities, including CVE-2026-62911. Administrators should update systems immediately to prevent potential exploits.
#Microsoft #ExchangeServer #Cybersecurity #Vulnerabilities #SecurityUpdate #CVE202662911
##updated 2026-08-13T16:18:59.837000
1 posts
CVE-2026-70328 - OOB read in Microsoft Excel. Info disclosure over network. CVSS 6.5. Patch under review - monitor updates closely. #CVE #Microsoft #infosec
##updated 2026-08-13T15:34:13
4 posts
2 repos
Sentencing is swift and merciless: patch Microsoft SharePoint against CVE-2026-55040 without delay, or face consequences this court will not be held responsible for.
Reward: You've received the Gavel of Marginal Preparedness. It is mostly decorative at this point.
#SharePoint #CyberSecurity #CriticalVulnerability #Microsoft #Ransomware #ExploitInTheWild (2/2)
##🏆 New Achievement! The PoC Heard Round the World!
This court finds Microsoft SharePoint guilty of harboring CVE-2026-55040, a critical vulnerability of the highest order. Exhibit A: Rapid7 published proof-of-concept exploit code. Exhibit B: threat actors, punctual as a process server, immediately began active exploitation. The defense's argument of "maybe nobody will notice" is overruled and stricken from the record. (1/2)
##Sentencing is swift and merciless: patch Microsoft SharePoint against CVE-2026-55040 without delay, or face consequences this court will not be held responsible for.
Reward: You've received the Gavel of Marginal Preparedness. It is mostly decorative at this point.
#SharePoint #CyberSecurity #CriticalVulnerability #Microsoft #Ransomware #ExploitInTheWild (2/2)
##🏆 New Achievement! The PoC Heard Round the World!
This court finds Microsoft SharePoint guilty of harboring CVE-2026-55040, a critical vulnerability of the highest order. Exhibit A: Rapid7 published proof-of-concept exploit code. Exhibit B: threat actors, punctual as a process server, immediately began active exploitation. The defense's argument of "maybe nobody will notice" is overruled and stricken from the record. (1/2)
##updated 2026-08-13T14:16:54.583000
1 posts
New vulnerability disclosure from
@chocapikk_:
CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.
https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce
##updated 2026-08-12T17:17:27.983000
1 posts
3 repos
https://github.com/g0thamRabb1t/CVE-2026-50656-rogueplanet-validation
MSNightmare's ShieldBreak PoC claims to fully bypass Microsoft's July patch for CVE-2026-50656, achieving SYSTEM-level privileges on Windows 11 and Server 2025.
#ShieldBreak #CVE202650656 #MicrosoftDefender #PrivilegeEscalation #Windows11
##updated 2026-08-11T21:17:33.203000
1 posts
CVE-2026-18704 - Privilege escalation in MongoDB. Authenticated read-only users can perform unauthorized writes via aggregation framework. CVSS 6.5. No patch available. Restrict access and monitor. #CVE #MongoDB #infosec
##updated 2026-08-11T18:32:00
1 posts
1 repos
🏆 New Achievement! Add to Cart: One Critical Exploit, Final Sale!
LOOTBOX TERMS AND CONDITIONS — By operating Adobe Commerce, Commerce B2B, or Magento Open Source on or before the July 2026 patches, you have opted into the CVE-2026-71362 Prize Pool. Odds of receiving an unauthenticated attacker hijacking your customer accounts: improving daily. Sansec blocked initial exploitation attempts moments after Adobe's advisory went public. Disclosure-to-attack speedrun: essentially instantaneous. (1/2)
##updated 2026-08-11T18:31:33
1 posts
CVE-2026-62837 - Path traversal info disclosure in Microsoft Office SharePoint. CVSS 6.5. Patch under review. Monitor advisories and restrict access. #CVE #Microsoft #infosec
##updated 2026-08-11T15:17:29.603000
1 posts
Out-of-bounds writes in ABAP's DIAG protocol parsing, SSTI and SSRF in a servlet component, code injection in Manufacturing Integration and Intelligence. Four weak points, all exposed, all hitting simultaneously. Your raid team is screaming.
ENRAGE TIMER IS RUNNING. Apply SAP's security patches for CVE-2026-58231, CVE-2026-34265, CVE-2026-44772, and CVE-2026-44758 before unauthenticated attackers execute arbitrary code or crater your systems entirely. (2/3)
##updated 2026-08-11T12:30:28
9 posts
1 repos
Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
#cybersecurity #vulnerability #SAP
SAP Commerce Cloud Hit by a CVSS 100 Flaw as Attackers Move Within Days of the Patch + Video
A Critical Warning for SAP Commerce Cloud Operators A security patch is supposed to close a door. In the case of CVE-2026-58231, however, attackers appear to have started testing that door almost immediately after SAP released its fix. The vulnerability affects SAP Commerce Cloud and carries the maximum CVSS severity score of 10.0. More importantly, exploitation has reportedly…
##CVE-2026-58231, a critical SAP Commerce Cloud vulnerability, is being actively exploited. This flaw enables unauthenticated remote code execution. Organizations should apply patches immediately and monitor for suspicious activity to protect their systems.
#SAP #CyberSecurity #Vulnerability #CVE202658231 #PatchNow #InfoSec
https://thedailytechfeed.com/critical-sap-commerce-cloud-vulnerability-under-active-exploitation/
##Critical SAP Commerce Cloud RCE Vulnerability Under Active Attack
SAP Commerce Cloud flaw (CVE-2026-58231) is reportedly being actively exploited to gain full control over e-commerce platforms.
**If you run SAP Commerce Cloud (COM_CLOUD 2211, XMII 15.4, or ABAP Platform 7.53), apply the August 2026 SAP security updates immediately. Attackers are already exploiting CVE-2026-58231 to take over these systems. If you can't patch right away, restrict access to the Data Hub Adapter endpoint with IP filters so only trusted addresses can reach it, and treat any internet-exposed instance as a priority to check for signs of compromise.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/critical-sap-commerce-cloud-rce-vulnerability-under-active-attack-k-v-m-i-3/gD2P6Ple2L
SAP Commerce Cloud Faces a Maximum-Severity Attack: CVE-2026-58231 Is Being Actively Exploited + Video
A Critical SAP Vulnerability Has Moved From Patch Priority to Immediate Threat A critical security flaw in SAP Commerce Cloud has crossed a dangerous line. What began as a newly disclosed vulnerability has rapidly become an active exploitation concern, giving defenders very little time to treat the issue as a routine patching exercise. Tracked as CVE-2026-58231, the…
##Out-of-bounds writes in ABAP's DIAG protocol parsing, SSTI and SSRF in a servlet component, code injection in Manufacturing Integration and Intelligence. Four weak points, all exposed, all hitting simultaneously. Your raid team is screaming.
ENRAGE TIMER IS RUNNING. Apply SAP's security patches for CVE-2026-58231, CVE-2026-34265, CVE-2026-44772, and CVE-2026-44758 before unauthenticated attackers execute arbitrary code or crater your systems entirely. (2/3)
##🏆 New Achievement! SAP Has Entered the Chat (As the Final Boss)!
PHASE ONE ACTIVE. CVE-2026-58231 scores a perfect 10.0 — that is not a grade, that is a tombstone. SAP Commerce Cloud lets an unauthenticated attacker abuse a default auth client and feed malformed input to unvalidated functions. No login required. You are already in the wipe.
PHASE TWO: additional CVEs are spawning adds. (1/3)
##「SAP Commerce Cloudの脆弱性が最大レベルの攻撃の標的に。 」: #BLEEPINGCOMPUTER
「脅威インテリジェンス企業Defusedによると、3日前にパッチが適用されたSAP Commerce Cloudの深刻度最高レベルのリモートコード実行の脆弱性が、すでに攻撃の標的となっているという。
Commerce Cloud(旧称SAP Hybris)は、世界的に有名なブランドや大手小売業者が所有するオンラインストアで使用されているクラウドベースのeコマースプラットフォームです。
CVE-2026-58231 として追跡されている この重大な脆弱性は、Commerce Cloudの中核となるデータハブアダプタ拡張機能における不適切な認証の弱点に起因するもので、権限を持たない攻撃者が低複雑度の攻撃で悪用し、任意のコードを実行する可能性があります。 」
##Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
#cybersecurity #vulnerability #SAP
updated 2026-08-11T03:31:57
1 posts
Out-of-bounds writes in ABAP's DIAG protocol parsing, SSTI and SSRF in a servlet component, code injection in Manufacturing Integration and Intelligence. Four weak points, all exposed, all hitting simultaneously. Your raid team is screaming.
ENRAGE TIMER IS RUNNING. Apply SAP's security patches for CVE-2026-58231, CVE-2026-34265, CVE-2026-44772, and CVE-2026-44758 before unauthenticated attackers execute arbitrary code or crater your systems entirely. (2/3)
##updated 2026-07-22T20:10:00.127000
1 posts
2 repos
@da_667 The SolarWinds Serv-U denial-of-service vulnerability (CVE-2026-28318) became a massive infosec meme and talking point because unauthenticated attackers can crash over 12,000 internet-exposed servers using a single HTTP POST request with a Content-Encoding: deflate header.
##updated 2026-07-21T21:49:02
1 posts
CVE-2026-58427 - Info disclosure via /members API leaks private org lists. Incomplete fix for PR #38145. CVSS 7.5. Update immediately. #CVE #infosec #privacy
##updated 2026-06-17T09:50:01.133000
1 posts
2 repos
CVE-2025-60710 - Changed to Known Ransomware Status
Microsoft Windows Link Following VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows contains a link following vulnerability that allows for privilege escalationStatus changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 UTCDate Added to KEV: 2026-04-13View CVE Details
##updated 2026-06-17T09:30:46.797000
2 posts
1 repos
https://github.com/thefreestyleresearcher/CVE-2025-49091-Gajim-RCE
‼️ CVE-2025-49091: Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.
GitHub PoC: https://github.com/thefreestyleresearcher/CVE-2025-49091-Gajim-RCE
##‼️ CVE-2025-49091: Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.
GitHub PoC: https://github.com/thefreestyleresearcher/CVE-2025-49091-Gajim-RCE
##updated 2026-06-17T02:08:56.287000
1 posts
3 repos
https://github.com/Al1ex/WindowsElevation
CVE-2019-0803 - Changed to Known Ransomware Status
Microsoft Win32k Privilege Escalation VulnerabilityVendor: MicrosoftProduct: Win32kMicrosoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 athttps://nvd.nist.gov/vuln/detail/CVE-2019-0803
##updated 2026-06-17T01:31:40.897000
1 posts
1 repos
CVE-2018-0802 - Changed to Known Ransomware Status
Microsoft Office Memory Corruption VulnerabilityVendor: MicrosoftProduct: OfficeMicrosoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.Status changed from Unknown to Known for ransomware https://nvd.nist.gov/vuln/detail/CVE-2018-0802
##updated 2026-06-17T00:37:05.163000
1 posts
2 repos
CVE-2016-0189 - Changed to Known Ransomware Status
Microsoft Internet Explorer Memory Corruption VulnerabilityVendor: MicrosoftProduct: Internet ExplorerThe Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: Augusthttps://nvd.nist.gov/vuln/detail/CVE-2016-0189
##updated 2025-10-22T00:33:35
1 posts
100 repos
https://github.com/12bijaya/CVE-2021-4034-PwnKit-
https://github.com/evdenis/lsm_bpf_check_argc0
https://github.com/kimusan/pkwner
https://github.com/ayypril/CVE-2021-4034
https://github.com/joeammond/CVE-2021-4034
https://github.com/mebeim/CVE-2021-4034
https://github.com/jm33-m0/go-lpe
https://github.com/ArianeBlow/NagiosXI-RCE-all-version-CVE-2021-40345
https://github.com/Nosferatuvjr/PwnKit
https://github.com/an0n7os/CVE-2021-4034
https://github.com/alexOarga/CVE-2021-40346
https://github.com/jayhutajulu1/PwnKit-CVE-2021-4034
https://github.com/0x4ndy/CVE-2021-4034-PoC
https://github.com/Ankit-Ojha16/CVE-2021-4034
https://github.com/toecesws/CVE-2021-4034
https://github.com/EstamelGG/CVE-2021-4034-NoGCC
https://github.com/0xalwayslucky/log4j-polkit-poc
https://github.com/deoxykev/CVE-2021-4034-Rust
https://github.com/Vulnmachines/HAProxy_CVE-2021-40346
https://github.com/ly4k/PwnKit
https://github.com/Rvn0xsy/CVE-2021-4034
https://github.com/clubby789/CVE-2021-4034
https://github.com/Pixailz/CVE-2021-4034
https://github.com/ck00004/CVE-2021-4034
https://github.com/zhzyker/CVE-2021-4034
https://github.com/PeterGottesman/pwnkit-exploit
https://github.com/G01d3nW01f/CVE-2021-4034
https://github.com/sofire/polkit-0.96-CVE-2021-4034
https://github.com/ashutoshrohilla/CVE-2021-4034
https://github.com/Pol-Ruiz/CVE-2021-4034
https://github.com/oreosec/pwnkit
https://github.com/Almorabea/pkexec-exploit
https://github.com/Kirill89/CVE-2021-4034
https://github.com/whokilleddb/CVE-2021-4034
https://github.com/pyhrr0/pwnkit
https://github.com/alikarimi999/CVE-2021-40346
https://github.com/An00bRektn/CVE-2021-4034
https://github.com/NeonWhiteRabbit/CVE-2021-4034
https://github.com/Plethore/CVE-2021-4034
https://github.com/knqyf263/CVE-2021-40346
https://github.com/tahaafarooq/poppy
https://github.com/Jesrat/make_me_root
https://github.com/wudicainiao/cve-2021-4034
https://github.com/nikaiw/CVE-2021-4034
https://github.com/wechicken456/CVE-2021-4034-CTF-writeup
https://github.com/Nero22k/CVE-2021-4034
https://github.com/Anonymous-Family/CVE-2021-4034
https://github.com/zxybfq/CVE-2021-4034
https://github.com/OXDBXKXO/ez-pwnkit
https://github.com/Y3A/CVE-2021-4034
https://github.com/thatstraw/CVE-2021-4034
https://github.com/c3l3si4n/pwnkit
https://github.com/boro03/CVE-2021-4034
https://github.com/Al1ex/LinuxEelvation
https://github.com/usmansec/-CVE-2021-4034
https://github.com/c3c/CVE-2021-4034
https://github.com/TheJoyOfHacking/berdav-CVE-2021-4034
https://github.com/nagorealbisu/CVE-2021-4034
https://github.com/PwnFunction/CVE-2021-4034
https://github.com/luijait/PwnKit-Exploit
https://github.com/Al1ex/CVE-2021-4034
https://github.com/Fato07/Pwnkit-exploit
https://github.com/drapl0n/pwnKit
https://github.com/artemis-mike/cve-2021-4034
https://github.com/LJP-TW/CVE-2021-4034
https://github.com/scent2d/PoC-CVE-2021-4034
https://github.com/moldabekov/CVE-2021-4034
https://github.com/locksec/CVE-2021-4034
https://github.com/dzonerzy/poc-cve-2021-4034
https://github.com/HellGateCorp/pwnkit
https://github.com/cd80-ctf/CVE-2021-4034
https://github.com/nikip72/CVE-2021-4034
https://github.com/chenaotian/CVE-2021-4034
https://github.com/rvzsec/CVE-2021-4034
https://github.com/codiobert/pwnkit-scanner
https://github.com/navisec/CVE-2021-4034-PwnKit
https://github.com/x04000/CVE-2021-4034
https://github.com/x04000/AutoPwnkit
https://github.com/donky16/CVE-2021-40346-POC
https://github.com/nel0x/pwnkit-vulnerability
https://github.com/Yakumwamba/POC-CVE-2021-4034
https://github.com/berdav/CVE-2021-4034
https://github.com/FDlucifer/Pwnkit-go
https://github.com/mutur4/CVE-2021-4034
https://github.com/0x01-sec/CVE-2021-4034-
https://github.com/dadvlingd/CVE-2021-4034
https://github.com/JohnHammond/CVE-2021-4034
https://github.com/arthepsy/CVE-2021-4034
https://github.com/Ayrx/CVE-2021-4034
https://github.com/TanmoyG1800/CVE-2021-4034
https://github.com/gbrsh/CVE-2021-4034
https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux
https://github.com/jpmcb/pwnkit-go
https://github.com/hohn/codeql-sample-polkit
https://github.com/Audiobahn/CVE-2021-4034
https://github.com/JoyGhoshs/CVE-2021-4034
https://github.com/callrbx/pkexec-lpe-poc
https://github.com/NiS3x/CVE-2021-4034
CVE-2021-4034 - Changed to Known Ransomware Status
Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityVendor: Red HatProduct: PolkitThe Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 UTCDate Added to KEV: 2022-06-27View CVE https://nvd.nist.gov/vuln/detail/CVE-2021-4034
##updated 2025-10-22T00:32:53
1 posts
4 repos
https://github.com/wortell/cve-2020-0618
https://github.com/euphrat1ca/CVE-2020-0618
CVE-2020-0618 - Changed to Known Ransomware Status
Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityVendor: MicrosoftProduct: SQL ServerMicrosoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.Status changed from Unknown to Known https://nvd.nist.gov/vuln/detail/CVE-2020-0618
##updated 2025-10-22T00:32:01
1 posts
CVE-2020-29574 - Changed to Known Ransomware Status
CyberoamOS (CROS) SQL Injection VulnerabilityVendor: SophosProduct: CyberoamOSCyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 UTCDate Added to KEV: 2025-02-06View CVE https://nvd.nist.gov/vuln/detail/CVE-2020-29574
##updated 2025-10-22T00:31:52
1 posts
CVE-2020-0968 - Changed to Known Ransomware Status
Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityVendor: MicrosoftProduct: Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 https://nvd.nist.gov/vuln/detail/CVE-2020-0968
##updated 2025-10-22T00:31:30
1 posts
7 repos
https://github.com/Ridter/RTF_11882_0802
https://github.com/rxwx/CVE-2018-0802
https://github.com/roninAPT/CVE-2018-0802
https://github.com/Palvinder-Singh/PS_CVE2018-0802
https://github.com/zldww2011/CVE-2018-0802_POC
CVE-2018-0802 - Changed to Known Ransomware Status
Microsoft Office Memory Corruption VulnerabilityVendor: MicrosoftProduct: OfficeMicrosoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.Status changed from Unknown to Known for ransomware https://nvd.nist.gov/vuln/detail/CVE-2018-0802
##🚨 Critical #MariaDB flaw enables remote code execution
CVE-2026-49261 can run arbitrary commands on vulnerable servers.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity
🚨 Critical #MariaDB flaw enables remote code execution
CVE-2026-49261 can run arbitrary commands on vulnerable servers.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity
CVE-2026-56864 - High severity Go module supply chain attack. Malicious GOSUMDB can serve unverified content bypassing transparency log. CVSS 7.5. Update Go toolchain and verify sums immediately. #CVE #GoLang #infosec
##🟠 CVE-2026-19474 - High (7.5)
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19474 - High (7.5)
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18549 - High (7.5)
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-18500 - High (8.1)
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Out-of-bounds writes in ABAP's DIAG protocol parsing, SSTI and SSRF in a servlet component, code injection in Manufacturing Integration and Intelligence. Four weak points, all exposed, all hitting simultaneously. Your raid team is screaming.
ENRAGE TIMER IS RUNNING. Apply SAP's security patches for CVE-2026-58231, CVE-2026-34265, CVE-2026-44772, and CVE-2026-44758 before unauthenticated attackers execute arbitrary code or crater your systems entirely. (2/3)
##1 posts
5 repos
https://github.com/4minx/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
Nearly 14,000 Trezor customers had their data stolen via CVE-2026-72898, a critical Metabase zero-day exploited through logistics partner ShipMonk.
##