## Updated at UTC 2026-07-24T21:26:04.358297

Access data as JSON

CVE CVSS EPSS Posts Repos Nuclei Updated Description
CVE-2026-17107 8.5 0.00% 2 0 2026-07-24T20:49:03.140000 A flaw was found in the cluster-proxy service-proxy component used in Red Hat Ad
CVE-2026-62835 9.3 0.00% 2 0 2026-07-24T20:48:18.380000 Improper authorization in Azure Portal allows an unauthorized attacker to disclo
CVE-2026-58630 10.0 0.00% 4 0 2026-07-24T20:48:18.380000 Improper access control in Azure App Service allows an unauthorized attacker to
CVE-2026-60217 10.0 0.45% 1 0 2026-07-24T20:41:08.940000 Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (compo
CVE-2026-66035 7.5 0.00% 2 0 2026-07-24T19:17:10.700000 libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication h
CVE-2026-65709 8.3 0.00% 2 0 2026-07-24T19:17:10.580000 sysPass through version 3.2.11 contains a missing object-level authorization vul
CVE-2026-54342 8.1 0.00% 2 0 2026-07-24T19:16:59.200000 In epa4all, prior to version 2026-05-20, an attacker on the network path between
CVE-2026-48021 9.1 0.00% 2 0 2026-07-24T19:16:58.033000 In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS c
CVE-2026-66027 8.3 0.00% 2 0 2026-07-24T18:31:37 Suna before 0.9.102 contains a broken access control vulnerability in the messag
CVE-2026-66034 7.5 0.00% 2 0 2026-07-24T18:18:09.050000 libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check
CVE-2026-66032 8.8 0.00% 2 0 2026-07-24T18:18:08.923000 libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerab
CVE-2026-65708 8.1 0.00% 2 0 2026-07-24T18:18:08.653000 sysPass through version 3.2.11 contains an insecure direct object reference vuln
CVE-2026-66033 7.5 0.00% 2 0 2026-07-24T17:17:35.263000 libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication i
CVE-2026-8789 8.1 0.00% 2 0 2026-07-24T15:33:10 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modific
CVE-2026-57106 10.0 0.00% 2 0 2026-07-24T15:33:03 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attack
CVE-2026-64600 0 0.64% 1 2 2026-07-24T15:19:06.087000 In the Linux kernel, the following vulnerability has been resolved: xfs: resamp
CVE-2026-16730 5.5 0.00% 1 0 2026-07-24T12:31:03 A flaw was found in dbus-broker. When the process file-descriptor limit is reach
CVE-2026-14172 7.8 0.11% 1 0 2026-07-24T09:32:22 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables
CVE-2026-15704 9.8 0.35% 1 0 2026-07-24T09:32:16 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled
CVE-2026-24727 None 0.67% 1 0 2026-07-24T09:32:16 An unrestricted upload of file with dangerous type vulnerability in the e-paper
CVE-2026-16870 8.8 0.36% 1 0 2026-07-24T06:34:17 Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior
CVE-2026-54120 9.9 0.71% 1 0 2026-07-24T03:31:56 Improper input validation in Microsoft Surface allows an authorized attacker to
CVE-2026-56160 9.1 0.65% 1 0 2026-07-24T03:31:56 Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized att
CVE-2026-47056 10.0 0.33% 1 0 2026-07-23T18:31:02 Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware
CVE-2026-16232 9.1 12.68% 4 1 2026-07-23T15:44:54.743000 An authentication bypass vulnerability in the Check Point SmartConsole login pro
CVE-2026-50522 9.8 57.10% 1 1 2026-07-22T21:31:51 Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut
CVE-2026-54121 8.8 0.80% 5 1 2026-07-21T19:54:33.623000 Improper authorization in Active Directory Certificate Services (AD CS) allows a
CVE-2026-16242 9.4 0.37% 1 0 2026-07-20T09:31:15 A flaw was found in the Konnectivity proxy-server configuration for hosted contr
CVE-2026-42533 8.1 2.79% 1 6 2026-07-15T15:33:14 A vulnerability exists in NGINX Plus and NGINX Open Source when a mapย directive
CVE-2026-50454 7.8 0.44% 1 0 2026-07-14T18:32:32 Relative path traversal in Windows User Interface Core allows an authorized atta
CVE-2025-66376 7.2 21.62% 2 0 2026-06-17T09:56:44.753000 Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas
CVE-2025-0679 4.3 0.29% 1 0 2026-06-17T08:26:57.313000 An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 be
CVE-2026-0770 None 53.46% 1 7 template 2026-02-19T22:09:33 Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere R
CVE-2026-61884 0 0.00% 1 0 N/A
CVE-2026-63030 0 97.92% 2 67 template N/A
CVE-2026-60137 0 77.97% 1 42 N/A

CVE-2026-17107
(8.5 HIGH)

EPSS: 0.00%

updated 2026-07-24T20:49:03.140000

2 posts

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an

thehackerwire@mastodon.social at 2026-07-24T20:00:24.000Z ##

๐ŸŸ  CVE-2026-17107 - High (8.5)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T20:00:24.000Z ##

๐ŸŸ  CVE-2026-17107 - High (8.5)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-62835
(9.3 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T20:48:18.380000

2 posts

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

DarkWebInformer at 2026-07-24T20:45:57.195Z ##

๐Ÿšจ CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability

CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.

CVSS: 9.3

More information: msrc.microsoft.com/update-guid

##

DarkWebInformer@infosec.exchange at 2026-07-24T20:45:57.000Z ##

๐Ÿšจ CVE-2026-62835: Microsoft Azure Portal Information Disclosure Vulnerability

CVE-2026-62835 involves a flaw in the authorization process of Online Services, enabling attackers to access restricted information. The vulnerability documented by this CVE requires no customer action to resolve.

CVSS: 9.3

More information: msrc.microsoft.com/update-guid

##

CVE-2026-58630
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T20:48:18.380000

4 posts

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

DarkWebInformer at 2026-07-24T19:09:34.207Z ##

โ€ผ๏ธ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVSS: 10

Details: msrc.microsoft.com/update-guid

##

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

๐Ÿ”ด CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:09:34.000Z ##

โ€ผ๏ธ CVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

CVSS: 10

Details: msrc.microsoft.com/update-guid

##

thehackerwire@mastodon.social at 2026-07-24T17:00:38.000Z ##

๐Ÿ”ด CVE-2026-58630 - Critical (10)

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-60217
(10.0 CRITICAL)

EPSS: 0.45%

updated 2026-07-24T20:41:08.940000

1 posts

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additi

sayzard@mastodon.sayzard.org at 2026-07-24T17:38:47.000Z ##

Oracle drops 1,449 security patches like it's the new normal

Oracle๊ฐ€ ๋ถ„๊ธฐ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ์—์„œ 1,449๊ฑด์˜ ํŒจ์น˜๋ฅผ ๋ฐฐํฌํ–ˆ์œผ๋ฉฐ, ์ด ์ค‘ Oracle Fusion Middleware ๊ด€๋ จ ์ทจ์•ฝ์  10๊ฑด์€ CVSS 10.0์ด๋‹ค. ํŠนํžˆ ์ธ์ฆ ์—†์ด HTTP๋กœ Oracle Data Integrator๋ฅผ ์žฅ์•…ํ•  ์ˆ˜ ์žˆ๋Š” CVE-2026-47056๊ณผ TCP๋ฅผ ํ†ตํ•ด Oracle Coherence๋ฅผ ์žฅ์•…ํ•  ์ˆ˜ ์žˆ๋Š” CVE-2026-60217์€ ์ฆ‰์‹œ ํŒจ์น˜ ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’๋‹ค. Oracle Database Server์—๋„ ์ €๊ถŒํ•œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ๊ฐ€...

theregister.com/security/2026/

##

CVE-2026-66035
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-24T19:17:10.700000

2 posts

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller than the cipher's block size during Encrypt-then-MAC cipher negotiation. In the fullpacket() function in src/transport.c, the ETM path allocates a buffe

thehackerwire@mastodon.social at 2026-07-24T20:00:59.000Z ##

๐ŸŸ  CVE-2026-66035 - High (7.5)

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T20:00:59.000Z ##

๐ŸŸ  CVE-2026-66035 - High (7.5)

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server to corrupt heap metadata in any connecting client by sending a packet with a packet_length smaller...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65709
(8.3 HIGH)

EPSS: 0.00%

updated 2026-07-24T19:17:10.580000

2 posts

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without per-account access control. Attackers can invoke AccountController methods such as viewAction, editAction, deleteAction, and editPassAction without Account

thehackerwire@mastodon.social at 2026-07-24T20:01:19.000Z ##

๐ŸŸ  CVE-2026-65709 - High (8.3)

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T20:01:19.000Z ##

๐ŸŸ  CVE-2026-65709 - High (8.3)

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enumerate account metadata, overwrite passwords, and delete accounts across the entire vault without pe...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54342
(8.1 HIGH)

EPSS: 0.00%

updated 2026-07-24T19:16:59.200000

2 posts

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnektor, IDP), this allows direct read and modification of the inner traffic, including smartcard operations and OIDC authentication exchanges. For the ePA b

thehackerwire@mastodon.social at 2026-07-24T20:00:02.000Z ##

๐ŸŸ  CVE-2026-54342 - High (8.1)

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T20:00:02.000Z ##

๐ŸŸ  CVE-2026-54342 - High (8.1)

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can present a self-signed TLS certificate and intercept the connection. For non-VAU connections (Konnek...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-48021
(9.1 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T19:16:58.033000

2 posts

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traffic (patient consent decisions, medication data, document operations, authorization tokens, and entitlement queries) becomes readable and modifiable. The

thehackerwire@mastodon.social at 2026-07-24T20:00:12.000Z ##

๐Ÿ”ด CVE-2026-48021 - Critical (9.1)

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T20:00:12.000Z ##

๐Ÿ”ด CVE-2026-48021 - Critical (9.1)

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU handshake with attacker-controlled keys and obtain the session encryption keys. All inner HTTP traff...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66027
(8.3 HIGH)

EPSS: 0.00%

updated 2026-07-24T18:31:37

2 posts

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

๐ŸŸ  CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T16:59:50.000Z ##

๐ŸŸ  CVE-2026-66027 - High (8.3)

Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66034
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-24T18:18:09.050000

2 posts

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsystem. In libssh2_publickey_list_fetch(), the version 1 response parser reads a server-controlled comment_len value and advances the parse pointer without

thehackerwire@mastodon.social at 2026-07-24T18:00:34.000Z ##

๐ŸŸ  CVE-2026-66034 - High (7.5)

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T18:00:34.000Z ##

๐ŸŸ  CVE-2026-66034 - High (7.5)

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbitrary-length heap out-of-bounds read and a free of an uninitialized pointer via the publickey subsy...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66032
(8.8 HIGH)

EPSS: 0.00%

updated 2026-07-24T18:18:08.923000

2 posts

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a server responds to SSH_FXP_OPEN with SSH_FXP_STATUS containing FX_OK, the response data buffer is freed, and if a subsequent sftp_packet_require() call retur

thehackerwire@mastodon.social at 2026-07-24T18:00:10.000Z ##

๐ŸŸ  CVE-2026-66032 - High (8.8)

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T18:00:10.000Z ##

๐ŸŸ  CVE-2026-66032 - High (8.8)

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. When a serv...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-65708
(8.1 HIGH)

EPSS: 0.00%

updated 2026-07-24T18:18:08.653000

2 posts

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing authorization checks in AccountFileController. Attackers can supply arbitrary numeric file IDs through the download, view, delete, upload, and list actions

thehackerwire@mastodon.social at 2026-07-24T20:01:09.000Z ##

๐ŸŸ  CVE-2026-65708 - High (8.1)

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T20:01:09.000Z ##

๐ŸŸ  CVE-2026-65708 - High (8.1)

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account file attachments belonging to accounts they do not have ACL permissions for by exploiting missing au...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-66033
(7.5 HIGH)

EPSS: 0.00%

updated 2026-07-24T17:17:35.263000

2 posts

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AES-GCM ciphers during handshake. Attackers can exploit the underflow in the expression computing blocksize minus aadlen minus authentication tag length to

thehackerwire@mastodon.social at 2026-07-24T18:00:20.000Z ##

๐ŸŸ  CVE-2026-66033 - High (7.5)

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T18:00:20.000Z ##

๐ŸŸ  CVE-2026-66033 - High (7.5)

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in src/openssl.c that allows a malicious SSH server to crash any connecting client by negotiating AE...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-8789
(8.1 HIGH)

EPSS: 0.00%

updated 2026-07-24T15:33:10

2 posts

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including, 3.12.27. This makes it possible for authenticated attackers, with Contributor-level access and above, to delete arbitrary connection records from the `

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

๐ŸŸ  CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T17:00:27.000Z ##

๐ŸŸ  CVE-2026-8789 - High (8.1)

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_delete_multiple_connections` AJAX action in all versions up to, and including...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-57106
(10.0 CRITICAL)

EPSS: 0.00%

updated 2026-07-24T15:33:03

2 posts

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

๐Ÿ”ด CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

thehackerwire@mastodon.social at 2026-07-24T17:00:48.000Z ##

๐Ÿ”ด CVE-2026-57106 - Critical (10)

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-64600
(0 None)

EPSS: 0.64%

updated 2026-07-24T15:19:06.087000

1 posts

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers cycle the ILOCK to grab a transaction, which means that the mappings are stale as soon as we reacquire the ILOCK. Currently

2 repos

https://github.com/0xBlackash/CVE-2026-64600

https://github.com/HORKimhab/CVE-2026-64600

DailyCyberSecurity@infosec.exchange at 2026-07-24T13:31:15.000Z ##

Discover the RefluXFS Linux vulnerability (CVE-2026-64600) in XFS that allows local users to overwrite protected files and gain root privileges.

#RefluXFS #CVE202664600 #LinuxKernel #Cybersecurity #XFS

meterpreter.org/refluxfs-linux

##

CVE-2026-16730
(5.5 MEDIUM)

EPSS: 0.00%

updated 2026-07-24T12:31:03

1 posts

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connections to the user session bus can trigger this and deny service to the desktop session. Flatpak applications can reach the host session bus through the db

dotstdy@mastodon.social at 2026-07-24T16:31:03.000Z ##

got a red hat cve for the bug i found trying out superluminal on linux. this means that i'm a SECURITY RESEARCHER now! access.redhat.com/security/cve

##

CVE-2026-14172
(7.8 HIGH)

EPSS: 0.11%

updated 2026-07-24T09:32:22

1 posts

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.

thehackerwire@mastodon.social at 2026-07-24T12:00:22.000Z ##

๐ŸŸ  CVE-2026-14172 - High (7.8)

Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYS...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-15704
(9.8 CRITICAL)

EPSS: 0.35%

updated 2026-07-24T09:32:16

1 posts

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's `middleware.StripSlashes`, so a request such as `GET /shells/` was dispatched to the registered `GET /shells` route. However

thehackerwire@mastodon.social at 2026-07-24T12:00:12.000Z ##

๐Ÿ”ด CVE-2026-15704 - Critical (9.8)

In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router.

The shared rou...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-24727(CVSS UNKNOWN)

EPSS: 0.67%

updated 2026-07-24T09:32:16

1 posts

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System through v10.3 allows remote authenticated users with administrator privileges to execute arbitrary commands by uploading a crafted ZIP archive containing a server-executable file.

offseq@infosec.exchange at 2026-07-24T10:30:26.000Z ##

CVE-2026-24727 (CRITICAL, CVSS 9.3): SUNNET Corporate Training Mgmt System v10.3 allows admins to upload ZIP files with executable code, enabling server command execution. No patch yet โ€” restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #CVE202624727 #infosec ๐Ÿ›ก๏ธ

##

CVE-2026-16870
(8.8 HIGH)

EPSS: 0.36%

updated 2026-07-24T06:34:17

1 posts

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim proces

thehackerwire@mastodon.social at 2026-07-24T12:00:32.000Z ##

๐ŸŸ  CVE-2026-16870 - High (8.8)

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a...

๐Ÿ”— thehackerwire.com/vulnerabilit

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

##

CVE-2026-54120
(9.9 CRITICAL)

EPSS: 0.71%

updated 2026-07-24T03:31:56

1 posts

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

offseq@infosec.exchange at 2026-07-24T13:30:30.000Z ##

CVE-2026-54120 (CRITICAL, CVSS 9.9): Improper input validation in Microsoft Surface Management Services lets authorized attackers run code remotely. Patch now: radar.offseq.com/threat/cve-20 ๐Ÿ–ฅ๏ธ #OffSeq #infosec #Microsoft #CVE202654120

##

CVE-2026-56160
(9.1 CRITICAL)

EPSS: 0.65%

updated 2026-07-24T03:31:56

1 posts

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

offseq@infosec.exchange at 2026-07-24T12:00:29.000Z ##

CRITICAL improper authorization vuln (CVE-2026-56160) in Azure Red Hat OpenShift (ARO): privilege escalation risk for authorized users. No active exploits. Microsoft has released a fix โ€” ensure your ARO instances are updated. Details: radar.offseq.com/threat/cve-20 #OffSeq #Azure #CVE202656160

##

CVE-2026-47056
(10.0 CRITICAL)

EPSS: 0.33%

updated 2026-07-23T18:31:02

1 posts

Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact add

sayzard@mastodon.sayzard.org at 2026-07-24T17:38:47.000Z ##

Oracle drops 1,449 security patches like it's the new normal

Oracle๊ฐ€ ๋ถ„๊ธฐ ๋ณด์•ˆ ์—…๋ฐ์ดํŠธ์—์„œ 1,449๊ฑด์˜ ํŒจ์น˜๋ฅผ ๋ฐฐํฌํ–ˆ์œผ๋ฉฐ, ์ด ์ค‘ Oracle Fusion Middleware ๊ด€๋ จ ์ทจ์•ฝ์  10๊ฑด์€ CVSS 10.0์ด๋‹ค. ํŠนํžˆ ์ธ์ฆ ์—†์ด HTTP๋กœ Oracle Data Integrator๋ฅผ ์žฅ์•…ํ•  ์ˆ˜ ์žˆ๋Š” CVE-2026-47056๊ณผ TCP๋ฅผ ํ†ตํ•ด Oracle Coherence๋ฅผ ์žฅ์•…ํ•  ์ˆ˜ ์žˆ๋Š” CVE-2026-60217์€ ์ฆ‰์‹œ ํŒจ์น˜ ์šฐ์„ ์ˆœ์œ„๊ฐ€ ๋†’๋‹ค. Oracle Database Server์—๋„ ์ €๊ถŒํ•œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ๊ฐ€...

theregister.com/security/2026/

##

CVE-2026-16232
(9.1 CRITICAL)

EPSS: 12.68%

updated 2026-07-23T15:44:54.743000

4 posts

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server I

1 repos

https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

DarkWebInformer at 2026-07-24T19:30:19.396Z ##

โ€ผ๏ธ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVSS: 9.1

Scanner: github.com/WadesWeaponShed/Che

Details and Mitigation: support.checkpoint.com/results

##

netsecio@mastodon.social at 2026-07-24T17:48:06.000Z ##

๐Ÿ“ฐ Check Point Patches Actively Exploited SmartConsole Auth Bypass Flaw

๐Ÿšจ CRITICAL PATCH: Check Point fixes an actively exploited auth bypass zero-day (CVE-2026-16232, CVSS 9.3) in SmartConsole. Flaw allows full admin access. CISA added to KEV. Patch NOW. #CyberSecurity #ZeroDay #CheckPoint #Infosec

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— cyber.netsecops.io/articles/ch

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:30:19.000Z ##

โ€ผ๏ธ CVE-2026-16232: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVSS: 9.1

Scanner: github.com/WadesWeaponShed/Che

Details and Mitigation: support.checkpoint.com/results

##

youranonnewsirc@nerdculture.de at 2026-07-24T10:26:30.000Z ##

Geopolitical tensions escalated as US strikes on Iran continued and Houthi attacks on Saudi tankers raised oil prices. In cybersecurity, a critical Check Point zero-day (CVE-2026-16232) is actively exploited. US agencies warned of Iranian cyber campaigns targeting critical infrastructure PLCs and Russian state-backed phishing on Zimbra Collaboration Suite. AI agents are now a primary attack surface.

#Cybersecurity #Geopolitics #TechNews

##

CVE-2026-50522
(9.8 CRITICAL)

EPSS: 57.10%

updated 2026-07-22T21:31:51

1 posts

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

1 repos

https://github.com/HORKimhab/CVE-2026-50522

thecybermind@infosec.exchange at 2026-07-24T15:22:59.000Z ##

(CISA TS-SOC) CVE-2026-50522 โ€“ Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Severity: CRITICAL Impact Summary: An unauthorized attacker can execute code over a network via deserialization of untrusted data....

thecybermind.co/2026/07/24/cis

##

CVE-2026-54121
(8.8 HIGH)

EPSS: 0.80%

updated 2026-07-21T19:54:33.623000

5 posts

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

1 repos

https://github.com/aniqfakhrul/CVE-2026-54121

undercodenews@mastodon.social at 2026-07-24T21:00:45.000Z ##

Certighost AD CS Vulnerability Exposes a Dangerous Path to Domain Controller Control, Microsoft Fixes Critical Identity Security Flaw + Video

Introduction: A New Warning for Active Directory Defenders A newly disclosed Active Directory security vulnerability is raising concerns among enterprise defenders because it demonstrates how a seemingly limited user account could become a stepping stone toward full domain compromise. The flaw, tracked as CVE-2026-54121 and knownโ€ฆ

undercodenews.com/certighost-a

##

DarkWebInformer at 2026-07-24T19:55:21.168Z ##

โ€ผ๏ธ PoC released for CVE-2026-54121 codenamed Certighost

CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.

GitHub: github.com/aniqfakhrul/cve-202

##

netsecio@mastodon.social at 2026-07-24T17:47:44.000Z ##

๐Ÿ“ฐ PoC Exploit 'Certighost' for Critical AD CS Flaw Now Public

PoC exploit 'Certighost' released for critical AD CS flaw CVE-2026-54121 (CVSS 8.8). Exploit allows low-privilege users to impersonate a Domain Controller, leading to full domain compromise. Patching is urgent. #ActiveDirectory #CyberSecurity #BlueTeam

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— cyber.netsecops.io/articles/ce

##

DarkWebInformer@infosec.exchange at 2026-07-24T19:55:21.000Z ##

โ€ผ๏ธ PoC released for CVE-2026-54121 codenamed Certighost

CVE-2026-54121 is a privilege escalation vulnerability in Active Directory Certificate Services that enables authorized attackers to elevate privileges.

GitHub: github.com/aniqfakhrul/cve-202

##

AAKL@infosec.exchange at 2026-07-24T15:49:06.000Z ##

New.

GitHub/H0j3n: Certighost (CVE-2026-54121) gist.github.com/H0j3n/a5ef2609

More:

The Hacker News: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller thehackernews.com/2026/07/cert @thehackernews #infosec #vulnerability #Microsoft #Windows

##

CVE-2026-16242
(9.4 CRITICAL)

EPSS: 0.37%

updated 2026-07-20T09:31:15

1 posts

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A remote attacker who can reach the Konnectivity cluster endpoint could connect as an unauthenticated agent, join the routing pool, and potentially proxy,

CVE-2026-42533
(8.1 HIGH)

EPSS: 2.79%

updated 2026-07-15T15:33:14

1 posts

A vulnerability exists in NGINX Plus and NGINX Open Source when a mapย directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyon

6 repos

https://github.com/gagaltotal/CVE-2026-42533-nginx

https://github.com/seguridadentrerios/CVE-2026-42533

https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner

https://github.com/srkyn/nginx-map-risk-audit

https://github.com/suominen/CVE-2026-42533

https://github.com/Daniyal48/ghostlock-vagrant-box

ChrisShort@hachyderm.io at 2026-07-24T15:29:13.000Z ##

15-Year-Old Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 โ€“ cyberstan #devopsish cyberstan.co.uk/nginx-rce/

##

CVE-2026-50454
(7.8 HIGH)

EPSS: 0.44%

updated 2026-07-14T18:32:32

1 posts

Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.

CVE-2025-66376
(7.2 HIGH)

EPSS: 21.62%

updated 2026-06-17T09:56:44.753000

2 posts

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

netsecio@mastodon.social at 2026-07-24T17:48:03.000Z ##

๐Ÿ“ฐ Russian APT 'Laundry Bear' Targets West with Zero-Click Zimbra Exploit

International advisory warns of Russian APT 'Laundry Bear' using a zero-click Zimbra exploit (CVE-2025-66376) in a widespread espionage campaign against Western targets. Actors steal emails & credentials. #ThreatIntel #Zimbra #CyberSecurity

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— cyber.netsecops.io/articles/ru

##

netsecio@mastodon.social at 2026-07-24T17:48:00.000Z ##

๐Ÿ“ฐ Russian Hackers Use Zero-Click Zimbra Exploit in Global Spy Campaign

Russian state actors (Void Blizzard) are exploiting a zero-click Zimbra vulnerability (CVE-2025-66376) to steal credentials and emails. The campaign uses JavaScript injection via phishing emails. Patching is critical. #CyberEspionage #Zimbra #ThreatI...

๐ŸŒ cyber[.]netsecops[.]io

๐Ÿ”— cyber.netsecops.io/articles/ru

##

CVE-2025-0679
(4.3 MEDIUM)

EPSS: 0.29%

updated 2026-06-17T08:26:57.313000

1 posts

An issue has been discovered in GitLab CE/EE affecting all versions from 17.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Under certain conditions un-authorised users can view full email addresses that should be partially obscured.

security_crawler_carl@infosec.exchange at 2026-07-24T12:21:18.000Z ##

CVE-2025-0679 named them. NVD and MITRE still can't agree on whether you had a fighting chance. You did not.

Update your Zimbra webmail client to the patched version immediately, or TA488 keeps the loot.

Reward: You've received a hollow Authenticator Token โ€” pre-drained.

#ZeroDay #Zimbra #Espionage #CyberSecurity #2FA #AchievementUnlocked (2/2)

##

CVE-2026-0770(CVSS UNKNOWN)

EPSS: 53.46%

updated 2026-02-19T22:09:33

1 posts

Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The

Nuclei template

7 repos

https://github.com/Yetazyyy/CVE-2026-0770

https://github.com/razureink/cve-2026-0770-langflow_rce_reproduction

https://github.com/0xBlackash/CVE-2026-0770

https://github.com/0xgh057r3c0n/CVE-2026-0770

https://github.com/affix/CVE-2026-0770-PoC

https://github.com/diamorphine666/CVE-2026-0770

https://github.com/Ez4rd1x1/CVE-2026-0770

thecybermind@infosec.exchange at 2026-07-24T11:06:41.000Z ##

(CISA TS-SOC) CVE-2026-0770 โ€“ Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

Severity: UNKNOWN Impact Summary: Remote attackers can execute arbitrary code on affected installations. Timestamp: 2026-07-24T01:31:37.336Z ATT&CK Mappingโ€ฆ...

thecybermind.co/2026/07/24/cis

##

CVE-2026-61884
(0 None)

EPSS: 0.00%

1 posts

N/A

CVE-2026-63030
(0 None)

EPSS: 97.92%

2 posts

N/A

Nuclei template

67 repos

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/Lutfifakee-Project/wp2shell

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/ekomsSavior/wp2shell

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/kulichr/wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/CybersecSpirit/CVE-2026-63030

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/TomorrowX6/CVE-2026-63030-poc

https://github.com/shinthink/CVE-2026-63030

https://github.com/c0gnit00/Wp2Shell

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/InstaWP/wp2shell-scan

https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause

https://github.com/4B3R4M4-607D/CVE-2026-63030-POC

https://github.com/Iqbalx7/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/yoerivegt/wp2shell-poc

https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030

https://github.com/0xjessie21/wp2shell-checker

https://github.com/0xWhoknows/wp2shell

https://github.com/Ch4120N/CVE-2026-63030

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/securelayer7/WordPresShell

https://github.com/4minx/CVE-2026-63030

https://github.com/mhtsec/CVE-2026-63030

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/ZenithGenius/wordpress-batch-rce-lab

https://github.com/vulnquest58/PressVector

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ikow/wp2shell

https://github.com/0xBlackash/CVE-2026-63030

https://github.com/ananay/wp2shell-lab

https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t

https://github.com/zeroc00I/CVE-2026-63030

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030

https://github.com/0xh7ml/CVE-2026-63030

https://github.com/mrx-arafat/CVE-2026-63030-POC

https://github.com/47Cid/wp2shell-lab

https://github.com/mverschu/CVE-2026-63030

https://github.com/administrator-01001/CVE-2026-63030

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/fullhunt/wp2shell-scan

https://github.com/dinosn/wp2shell-lab

https://github.com/ebrasha/abdal-cve-2026-63030

https://github.com/Icex0/wp2shell-poc

https://github.com/ChiefYoru/CVE-2026-63030_PoC

https://github.com/raphy76/wp2shell-poc-fulljs

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/gbrsh/CVE-2026-63030

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/zi3lak/wp2shell_scanner

https://github.com/mcipekci/wp2shell

https://github.com/0xsha/wp2shell

https://github.com/attackercan/wp2shell-poc2

thecybermind@infosec.exchange at 2026-07-24T11:29:34.000Z ##

(CISA TS-SOC) CVE-2026-60137 โ€“ WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

thecybermind@infosec.exchange at 2026-07-24T11:19:33.000Z ##

(CISA TS-SOC) CVE-2026-63030 โ€“ WordPress Core Interpretation Conflict Vulnerability

Severity: CRITICAL Impact Summary: An attacker can exploit an interpretation conflict in WordPress Core to perform SQL Injection, which may be chained to achieve Remote Code Execution....

thecybermind.co/2026/07/24/cis

##

CVE-2026-60137
(0 None)

EPSS: 77.97%

1 posts

N/A

42 repos

https://github.com/Senanfurkan/wordpress-cve-2026-63030

https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner

https://github.com/ebrasha/abdal-cve-2026-60137

https://github.com/ekomsSavior/wp2shell

https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction

https://github.com/kulichr/wp2shell

https://github.com/Crypto-Cat/wp2shell

https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress

https://github.com/shinthink/CVE-2026-63030

https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN

https://github.com/Iqbalx7/wp2shell

https://github.com/NULL200OK/WP2Shell

https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin

https://github.com/JohenLastGen-JLG/wp2shell

https://github.com/yoerivegt/wp2shell-poc

https://github.com/0xjessie21/wp2shell-checker

https://github.com/0xWhoknows/wp2shell

https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell

https://github.com/securelayer7/WordPresShell

https://github.com/Colere-Sys/wp2shell-poc

https://github.com/vulnquest58/PressVector

https://github.com/bahartanir/wp2shell-scanner

https://github.com/ikow/wp2shell

https://github.com/ananay/wp2shell-lab

https://github.com/hidden-investigations/wp2shell-scanner

https://github.com/SentinelXofficial/sxwp2shell

https://github.com/47Cid/wp2shell-lab

https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137

https://github.com/dinosn/wp2shell-lab

https://github.com/Icex0/wp2shell-poc

https://github.com/own2pwn-fr/wp2shell-detect

https://github.com/Lukols-Dev/wp-cve-2026-63030-check

https://github.com/HackingLZ/wp2shell_stock_chain

https://github.com/codeb0ssx/Ultimate-wp2shell

https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC

https://github.com/h4cd0c/wp2shell

https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc

https://github.com/ZephrFish/wp2shell-scanner

https://github.com/AkbarWiraN/holy-wp2shell

https://github.com/zi3lak/wp2shell_scanner

https://github.com/mcipekci/wp2shell

https://github.com/0xsha/wp2shell

thecybermind@infosec.exchange at 2026-07-24T11:29:34.000Z ##

(CISA TS-SOC) CVE-2026-60137 โ€“ WordPress Core SQL Injection Vulnerability

Severity: MEDIUM Impact Summary: Allows unauthenticated attackers to perform SQL injection, which can be chained with CVE-2026-63030 to achieve remote code execution on default WordPress installations....

thecybermind.co/2026/07/24/cis

##

Visit counter For Websites