##
Updated at UTC 2026-08-16T22:47:20.429294
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-74791 | 8.6 | 0.00% | 2 | 0 | 2026-08-16T15:30:38 | Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when Template | |
| CVE-2026-74790 | 9.1 | 0.00% | 2 | 0 | 2026-08-16T15:30:27 | Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering | |
| CVE-2026-74795 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:57.590000 | Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its rec | |
| CVE-2026-74794 | 7.5 | 0.00% | 3 | 0 | 2026-08-16T14:16:57.450000 | Scriban before 6.6.0 contains an infinite recursion vulnerability in object rend | |
| CVE-2026-74792 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:57.317000 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vuln | |
| CVE-2026-74789 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:56.917000 | Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only t | |
| CVE-2026-74788 | 7.5 | 0.00% | 3 | 0 | 2026-08-16T14:16:56.787000 | Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memor | |
| CVE-2026-74787 | 7.5 | 0.00% | 3 | 0 | 2026-08-16T14:16:56.653000 | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the obj | |
| CVE-2026-74783 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:56.133000 | Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimi | |
| CVE-2026-73062 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.903000 | Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability i | |
| CVE-2026-73061 | 9.8 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.770000 | Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedOb | |
| CVE-2026-73060 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.640000 | Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerabil | |
| CVE-2026-73057 | 7.5 | 0.00% | 2 | 0 | 2026-08-16T14:16:55.230000 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy en | |
| CVE-2026-73056 | 9.8 | 0.00% | 4 | 0 | 2026-08-16T14:16:55.083000 | SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive | |
| CVE-2026-17087 | 7.5 | 0.41% | 1 | 0 | 2026-08-16T07:16:30.423000 | The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for W | |
| CVE-2026-19714 | None | 0.16% | 1 | 0 | 2026-08-16T06:30:37 | The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audien | |
| CVE-2026-18316 | 9.1 | 0.32% | 2 | 0 | 2026-08-16T06:30:37 | The Solace Extra plugin for WordPress is vulnerable to unauthorized modification | |
| CVE-2026-18432 | 9.8 | 0.45% | 3 | 0 | 2026-08-16T06:30:32 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege | |
| CVE-2026-16098 | 9.8 | 0.64% | 2 | 0 | 2026-08-16T06:30:32 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File U | |
| CVE-2026-14524 | 9.1 | 0.70% | 2 | 0 | 2026-08-16T06:30:32 | The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file d | |
| CVE-2026-16099 | 8.8 | 0.59% | 1 | 0 | 2026-08-16T06:30:32 | The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary fi | |
| CVE-2026-17123 | 8.8 | 0.36% | 1 | 0 | 2026-08-16T06:30:32 | The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Req | |
| CVE-2026-14498 | 8.8 | 0.55% | 1 | 0 | 2026-08-16T06:30:31 | The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution i | |
| CVE-2026-19924 | 9.8 | 0.90% | 2 | 0 | 2026-08-16T03:31:11 | A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01 | |
| CVE-2026-73053 | 9.0 | 0.28% | 2 | 0 | 2026-08-16T00:31:35 | SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in th | |
| CVE-2026-73052 | 9.0 | 0.30% | 2 | 0 | 2026-08-16T00:31:34 | SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and | |
| CVE-2026-73041 | 9.0 | 0.23% | 1 | 0 | 2026-08-16T00:31:34 | SiYuan versions before v3.7.4 fail to validate or escape annotation fields writt | |
| CVE-2026-73055 | 4.8 | 0.21% | 1 | 0 | 2026-08-16T00:31:29 | Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde ( | |
| CVE-2026-73050 | 9.0 | 0.25% | 1 | 0 | 2026-08-16T00:31:28 | SiYuan versions before v3.7.4 fail to validate or escape the color field in attr | |
| CVE-2026-73044 | 9.0 | 0.25% | 1 | 0 | 2026-08-16T00:31:27 | SiYuan versions before v3.7.4 fail to validate or escape table column width valu | |
| CVE-2026-73043 | 9.0 | 0.37% | 1 | 0 | 2026-08-16T00:31:26 | SiYuan versions before v3.7.4 contain a remote code execution vulnerability in t | |
| CVE-2026-73054 | 7.5 | 0.31% | 1 | 0 | 2026-08-15T22:16:55.290000 | SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in | |
| CVE-2026-73046 | 9.8 | 0.43% | 1 | 0 | 2026-08-15T22:16:54.600000 | SiYuan before v3.7.4 improperly restricts excessive authentication attempts in t | |
| CVE-2026-73045 | 7.5 | 0.30% | 1 | 0 | 2026-08-15T22:16:54.463000 | SiYuan before 3.7.4 contains an improper restriction of excessive authentication | |
| CVE-2026-73042 | 9.0 | 0.30% | 1 | 0 | 2026-08-15T22:16:54.030000 | SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML int | |
| CVE-2026-18855 | 9.1 | 1.21% | 1 | 0 | 2026-08-15T21:31:01 | The Link Library plugin for WordPress is vulnerable to arbitrary file deletion d | |
| CVE-2026-19900 | 8.1 | 0.45% | 1 | 0 | 2026-08-15T18:31:25 | A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted el | |
| CVE-2026-19901 | 8.1 | 0.45% | 1 | 0 | 2026-08-15T18:16:24.830000 | A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affec | |
| CVE-2026-19598 | 9.8 | 0.43% | 1 | 0 | 2026-08-15T18:16:23.860000 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to | |
| CVE-2026-19474 | 7.5 | 0.28% | 1 | 0 | 2026-08-15T14:17:07.710000 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from | |
| CVE-2026-18549 | 7.5 | 0.34% | 1 | 0 | 2026-08-15T14:17:07.590000 | @fastify/multipart is a multipart form-data parser for Fastify. In versions from | |
| CVE-2026-73635 | None | 0.19% | 1 | 0 | 2026-08-15T12:30:25 | Allocation of resources without limits or throttling vulnerability in Apache Str | |
| CVE-2026-73634 | 0 | 0.23% | 1 | 0 | 2026-08-15T11:16:27.427000 | Uncontrolled resource consumption vulnerability in Apache Struts. An application | |
| CVE-2026-72362 | 0 | 0.20% | 1 | 0 | 2026-08-15T06:22:09.627000 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: | |
| CVE-2026-65400 | 9.8 | 0.50% | 7 | 0 | 2026-08-15T04:18:24.470000 | An authentication issue was addressed with improved state management. This issue | |
| CVE-2021-4034 | 7.8 | 94.92% | 1 | 100 | 2026-08-15T04:17:57.927000 | A local privilege escalation vulnerability was found on polkit's pkexec utility. | |
| CVE-2026-13196 | None | 0.10% | 1 | 0 | 2026-08-14T18:31:38 | Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in | |
| CVE-2026-73633 | 7.5 | 0.32% | 1 | 1 | 2026-08-14T15:32:50 | Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Str | |
| CVE-2026-55040 | 9.1 | 3.97% | 2 | 2 | 2026-08-13T15:34:13 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attack | |
| CVE-2026-58231 | 10.0 | 0.73% | 2 | 1 | 2026-08-12T05:17:56.963000 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authent | |
| CVE-2026-64638 | 0 | 0.89% | 1 | 23 | 2026-08-07T19:18:51.610000 | WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login s | |
| CVE-2026-6837 | 7.2 | 0.95% | 2 | 1 | 2026-08-05T05:17:14.873000 | A post-authentication command injection vulnerability in the "export-cgi" CGI pr | |
| CVE-2026-12569 | 9.8 | 30.20% | 1 | 1 | 2026-08-01T05:16:55.023000 | A critical remote code execution (RCE) vulnerability has been reported in PTC Wi | |
| CVE-2026-59310 | 9.8 | 1.14% | 3 | 0 | 2026-07-30T15:31:51 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-42228 | 6.5 | 0.38% | 1 | 1 | 2026-06-17T10:47:32.723000 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, | |
| CVE-2020-0968 | 7.5 | 30.02% | 1 | 0 | 2026-06-17T02:47:06.173000 | A remote code execution vulnerability exists in the way that the scripting engin | |
| CVE-2016-0189 | 7.5 | 93.71% | 1 | 2 | 2026-06-17T00:37:05.163000 | The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in I | |
| CVE-2026-33696 | 9.9 | 0.77% | 2 | 0 | 2026-03-26T16:41:02 | ## Impact An authenticated user with permission to create or modify workflows co | |
| CVE-2020-0618 | 8.8 | 99.02% | 1 | 4 | 2025-10-22T00:32:53 | A remote code execution vulnerability exists in Microsoft SQL Server Reporting S | |
| CVE-2018-0798 | 8.8 | 90.99% | 1 | 1 | 2025-10-22T00:32:31 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Offic | |
| CVE-2018-0802 | 7.8 | 87.42% | 1 | 7 | 2025-10-22T00:31:30 | Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Offic | |
| CVE-2025-49091 | 8.2 | 0.57% | 1 | 1 | 2025-06-18T03:32:00 | KDE Konsole before 25.04.2 allows remote code execution in a certain scenario. I | |
| CVE-2026-65640 | 0 | 0.00% | 1 | 1 | N/A | ||
| CVE-2026-49261 | 0 | 1.58% | 1 | 0 | N/A | ||
| CVE-2026-18500 | 0 | 0.15% | 1 | 0 | N/A |
updated 2026-08-16T15:30:38
2 posts
🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74791 - High (8.6)
Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist across reused contexts. Attackers can exploit request-dependent ITemplateLoader implementations to acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74791/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T15:30:27
2 posts
🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-74790 - Critical (9.1)
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74790/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.590000
2 posts
🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74795 - High (7.5)
Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.450000
3 posts
CVE-2026-74794 – Unpatched DoS in Scriban template engine. Infinite recursion via circular refs crashes host process. CVSS 7.5. Update to 6.6.0 or limit recursion. #CVE #infosec #Scriban
##🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74794 - High (7.5)
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74794/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:57.317000
2 posts
🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74792 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array initializers recurse through a path (ParseArrayInitializer → ParseExpression → ParseArrayInit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74792/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.917000
2 posts
🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74789 - High (7.5)
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.787000
3 posts
CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74788 - High (7.5)
Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to ....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74788/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.653000
3 posts
CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74787 - High (7.5)
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74787/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:56.133000
2 posts
🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-74783 - High (7.5)
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-74783/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.903000
2 posts
🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73062 - High (7.5)
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multipli...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73062/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.770000
2 posts
🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-73061 - Critical (9.8)
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73061/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.640000
2 posts
🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73060 - High (7.5)
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73060/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.230000
2 posts
🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-73057 - High (7.5)
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T14:16:55.083000
4 posts
🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##🔴 CVE-2026-73056 - Critical (9.8)
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73056/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 https://radar.offseq.com/threat/cve-2026-73056-improper-restriction-of-excessive-authentication-attempts-in-siyuan-note-siyuan-28d3540593a8ef28 #OffSeq #CVE202673056 #infosec
##updated 2026-08-16T07:16:30.423000
1 posts
🟠 CVE-2026-17087 - High (7.5)
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.8.4. This is due to the plugin not properly verifying that a user is authori...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17087/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:37
1 posts
CVE-2026-19714 (CRITICAL): Simple JWT Login <3.6.8 for WordPress fails to validate Google token audiences. Sites with Google sign-in enabled risk admin impersonation & takeover. Disable Google sign-in or update ASAP. https://radar.offseq.com/threat/cve-2026-19714-cwe-287-improper-authentication-in-simple-jwt-login-2d90d2253c004239 #OffSeq #WordPress #CVE202619714
##updated 2026-08-16T06:30:37
2 posts
🔴 CVE-2026-18316 - Critical (9.1)
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_act...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18316/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-18316: CRITICAL auth bypass in Solace Extra WordPress plugin (≤1.6.0). Subscriber-level users can perform destructive actions — no patch yet. Restrict user roles & monitor import_zip() activity. https://radar.offseq.com/threat/cve-2026-18316-cwe-862-missing-authorization-in-solacewp-solace-extra-02691f8987449b12 #OffSeq #WordPress #Vuln #CVE202618316
##updated 2026-08-16T06:30:32
3 posts
CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##CVE-2026-18432 (CVSS 9.8): CRITICAL privilege escalation in DynamiApps Frontend Admin <=3.29.9. Unauthenticated attackers can become admins via flawed user ID checks. Restrict access to vulnerable forms & endpoints. https://radar.offseq.com/threat/cve-2026-18432-cwe-269-improper-privilege-management-in-shabti-frontend-admin-by-dynamiapps-0c7e8a2e9b4496ea #OffSeq #WordPress #PrivilegeEscalation #CVE
##🔴 CVE-2026-18432 - Critical (9.8)
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnerability exists because `ActionUser::conditions_logic()` gates the `current_user_can('edit_user', $u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18432/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
2 posts
CVE-2026-16098 (CRITICAL): ProSolution WP Client <=2.0.10 lets unauthenticated attackers upload dangerous files via nonce leak, leading to remote code execution. Restrict plugin use & monitor for patches. https://radar.offseq.com/threat/cve-2026-16098-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-prosolution-prosolution-wp-b1b65fccc57ffd67 #OffSeq #WordPress #CVE202616098 #Infosec
##🔴 CVE-2026-16098 - Critical (9.8)
The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_handleFileUpload function. This is due to missing validation of the attacker-controlled Content-Dispo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16098/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
2 posts
CRITICAL: CVE-2026-14524 in ProSolution WP Client ≤2.0.8 enables unauthenticated file deletion via path traversal — risking RCE if key files are removed. No patch; restrict or disable plugin. https://radar.offseq.com/threat/cve-2026-14524-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-2ffa65eefa2c3a5d #OffSeq #WordPress #CVE202614524 #Vuln
##🔴 CVE-2026-14524 - Critical (9.1)
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unaut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
1 posts
🟠 CVE-2026-16099 - High (8.8)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_link_item function in all versions up to, and including, 4.5.3. This makes it possible for authentic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16099/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:32
1 posts
🟠 CVE-2026-17123 - High (8.8)
The Royal Elementor Addons plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.7.1064 via the Form Builder widget's 'webhook_url' setting. The widget's render() method persists the attacker-control...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17123/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T06:30:31
1 posts
🟠 CVE-2026-14498 - High (8.8)
The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' parameter parameter. This is due to missing capability check and nonce verification on the wp_ajax_qw_for...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14498/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T03:31:11
2 posts
🔴 CVE-2026-19924 - Critical (9.8)
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19924/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Tenda AC10 (16.03.10.09_multi_TDE01) hit by CRITICAL auth bypass (CVE-2026-19924) via R7WebsSecurityHandler. Public exploit available — remote compromise possible. Update or restrict access! https://radar.offseq.com/threat/cve-2026-19924-improper-authentication-in-tenda-ac10-b84751472c0f965f #OffSeq #CVE202619924 #Tenda #Vuln
##updated 2026-08-16T00:31:35
2 posts
CVE-2026-73053: CRITICAL XSS in SiYuan (pre-v3.7.4) risks code execution on host via crafted icons when Node integration is enabled. No patch confirmed — disable Node integration or avoid untrusted files. https://radar.offseq.com/threat/cve-2026-73053-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-1654398c24cf93d4 #OffSeq #XSS #Vuln #SiYuan
##🔴 CVE-2026-73053 - Critical (9)
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:34
2 posts
CVE-2026-73052: CRITICAL XSS in SiYuan (<3.7.4) enables arbitrary JS & potential code execution if Node integration is enabled. Desktop users most at risk — upgrade ASAP & disable Node integration where possible. https://radar.offseq.com/threat/cve-2026-73052-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-c5f0eb8b5e84714b #OffSeq #XSS #SiYuan #Infosec
##🔴 CVE-2026-73052 - Critical (9)
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:34
1 posts
🔴 CVE-2026-73041 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73041/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:29
1 posts
CVE-2026-73055: CRITICAL vuln in ericcornelissen shescape (<2.1.15, 3.0.0<3.0.2). Improper tilde (~) escaping lets attackers leak home dir & alter cmd targets on BusyBox /bin/sh. Avoid untrusted input in escape APIs. Patch pending. https://radar.offseq.com/threat/cve-2026-73055-improper-encoding-or-escaping-of-output-in-ericcornelissen-shescape-3ef90f5f16672f7b #OffSeq #CVE202673055 #infosec
##updated 2026-08-16T00:31:28
1 posts
🔴 CVE-2026-73050 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73050/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:27
1 posts
🔴 CVE-2026-73044 - Critical (9)
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73044/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-16T00:31:26
1 posts
🔴 CVE-2026-73043 - Critical (9)
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and Jav...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73043/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:55.290000
1 posts
🟠 CVE-2026-73054 - High (7.5)
SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parameters between authentication exemption and session quarantine checks. Unauthenticated attackers can...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73054/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.600000
1 posts
🔴 CVE-2026-73046 - Critical (9.8)
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode)...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.463000
1 posts
🟠 CVE-2026-73045 - High (7.5)
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T22:16:54.030000
1 posts
🔴 CVE-2026-73042 - Critical (9)
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-73042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T21:31:01
1 posts
🔴 CVE-2026-18855 - Critical (9.1)
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T18:31:25
1 posts
🟠 CVE-2026-19900 - High (8.1)
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree o...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19900/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T18:16:24.830000
1 posts
🟠 CVE-2026-19901 - High (8.1)
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19901/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T18:16:23.860000
1 posts
🔴 CVE-2026-19598 - Critical (9.8)
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19598/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T14:17:07.710000
1 posts
🟠 CVE-2026-19474 - High (7.5)
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19474/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T14:17:07.590000
1 posts
🟠 CVE-2026-18549 - High (7.5)
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-15T12:30:25
1 posts
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-15T11:16:27.427000
1 posts
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-15T06:22:09.627000
1 posts
CVE-2026-72362 - Linux kernel NULL pointer deref in drm/xe/pt. Unpatched, crash risk. No CVSS. Update when patch lands. #CVE #Linux #infosec
##updated 2026-08-15T04:18:24.470000
7 posts
🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
🏆 New Achievement! Screen Sharing Is Caring (About My Monero Wallet)!
Allow me to monologue, as any proper villain must. CVE-2026-65400 — a gorgeous authentication bypass in macOS Screen Sharing — handed attackers root access through port 5900, wide open to the internet like a velvet rope with no bouncer. Apple patched it August 6 in macOS Tahoe 26.6.1. You simply... did not apply it. Delicious. (1/2)
##⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…
🤖 AI generated summary
##Critical macOS Screen Sharing flaw gives attackers remote root access — CISA bumps bug to 9.8 severity following active Monero cryptojacking attacks
The Dutch National Cyber Security Centre (NCSC-NL) says that attackers are actively exploiting CVE-2026-65400, an authentication bypass in macOS Screen Sharing.
#hardware
https://www.tomshardware.com/tech-industry/cyber-security/macos-screen-sharing-flaw-exploited-to-root-macs-and-plant-monero-miners
Apple Patches Actively Exploited macOS Screen Sharing Vulnerability Used in Crypto Mining Attacks
Apple patched a macOS Screen Sharing vulnerability (CVE-2026-65400) that allows remote attackers to bypass authentication and gain root access. Attackers are actively exploiting the flaw to install Monero crypto miners on systems with port 5900 exposed to the internet.
**If you use a Mac, update macOS now to Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 to fix CVE-2026-65400, which attackers are already using to take full control of Macs without a password. Also turn off Screen Sharing when you don't need it and make sure port 5900 is not reachable from the internet.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/apple-patches-actively-exploited-macos-screen-sharing-vulnerability-used-in-crypto-mining-attacks-n-5-j-v-1/gD2P6Ple2L
updated 2026-08-15T04:17:57.927000
1 posts
100 repos
https://github.com/OXDBXKXO/ez-pwnkit
https://github.com/usmansec/-CVE-2021-4034
https://github.com/TanmoyG1800/CVE-2021-4034
https://github.com/joeammond/CVE-2021-4034
https://github.com/Pol-Ruiz/CVE-2021-4034
https://github.com/ly4k/PwnKit
https://github.com/evdenis/lsm_bpf_check_argc0
https://github.com/ryaagard/CVE-2021-4034
https://github.com/DanaEpp/pwncat_pwnkit
https://github.com/locksec/CVE-2021-4034
https://github.com/cd80-ctf/CVE-2021-4034
https://github.com/PeterGottesman/pwnkit-exploit
https://github.com/ck00004/CVE-2021-4034
https://github.com/an0n7os/CVE-2021-4034
https://github.com/callrbx/pkexec-lpe-poc
https://github.com/ashutoshrohilla/CVE-2021-4034
https://github.com/0x4ndy/CVE-2021-4034-PoC
https://github.com/luijait/PwnKit-Exploit
https://github.com/rvzsec/CVE-2021-4034
https://github.com/TheJoyOfHacking/berdav-CVE-2021-4034
https://github.com/arthepsy/CVE-2021-4034
https://github.com/LJP-TW/CVE-2021-4034
https://github.com/hohn/codeql-sample-polkit
https://github.com/Ayrx/CVE-2021-4034
https://github.com/G01d3nW01f/CVE-2021-4034
https://github.com/JoyGhoshs/CVE-2021-4034
https://github.com/drapl0n/pwnKit
https://github.com/tahaafarooq/poppy
https://github.com/dadvlingd/CVE-2021-4034
https://github.com/Kirill89/CVE-2021-4034
https://github.com/FDlucifer/Pwnkit-go
https://github.com/boro03/CVE-2021-4034
https://github.com/teelrabbit/Polkit-pkexec-exploit-for-Linux
https://github.com/zxybfq/CVE-2021-4034
https://github.com/scent2d/PoC-CVE-2021-4034
https://github.com/NeonWhiteRabbit/CVE-2021-4034
https://github.com/knqyf263/CVE-2021-40346
https://github.com/navisec/CVE-2021-4034-PwnKit
https://github.com/Pixailz/CVE-2021-4034
https://github.com/Audiobahn/CVE-2021-4034
https://github.com/Anonymous-Family/CVE-2021-4034
https://github.com/EstamelGG/CVE-2021-4034-NoGCC
https://github.com/x04000/AutoPwnkit
https://github.com/An00bRektn/CVE-2021-4034
https://github.com/nel0x/pwnkit-vulnerability
https://github.com/Al1ex/CVE-2021-4034
https://github.com/HellGateCorp/pwnkit
https://github.com/Al1ex/LinuxEelvation
https://github.com/Almorabea/pkexec-exploit
https://github.com/x04000/CVE-2021-4034
https://github.com/Rvn0xsy/CVE-2021-4034
https://github.com/PwnFunction/CVE-2021-4034
https://github.com/alexOarga/CVE-2021-40346
https://github.com/Y3A/CVE-2021-4034
https://github.com/kimusan/pkwner
https://github.com/moldabekov/CVE-2021-4034
https://github.com/codiobert/pwnkit-scanner
https://github.com/deoxykev/CVE-2021-4034-Rust
https://github.com/thatstraw/CVE-2021-4034
https://github.com/wechicken456/CVE-2021-4034-CTF-writeup
https://github.com/donky16/CVE-2021-40346-POC
https://github.com/mutur4/CVE-2021-4034
https://github.com/0x01-sec/CVE-2021-4034-
https://github.com/Vulnmachines/HAProxy_CVE-2021-40346
https://github.com/0xalwayslucky/log4j-polkit-poc
https://github.com/Fato07/Pwnkit-exploit
https://github.com/toecesws/CVE-2021-4034
https://github.com/pyhrr0/pwnkit
https://github.com/mebeim/CVE-2021-4034
https://github.com/ayypril/CVE-2021-4034
https://github.com/wudicainiao/cve-2021-4034
https://github.com/oreosec/pwnkit
https://github.com/nikip72/CVE-2021-4034
https://github.com/berdav/CVE-2021-4034
https://github.com/nikaiw/CVE-2021-4034
https://github.com/artemis-mike/cve-2021-4034
https://github.com/whokilleddb/CVE-2021-4034
https://github.com/gbrsh/CVE-2021-4034
https://github.com/Jesrat/make_me_root
https://github.com/sofire/polkit-0.96-CVE-2021-4034
https://github.com/nagorealbisu/CVE-2021-4034
https://github.com/Yakumwamba/POC-CVE-2021-4034
https://github.com/clubby789/CVE-2021-4034
https://github.com/c3l3si4n/pwnkit
https://github.com/alikarimi999/CVE-2021-40346
https://github.com/12bijaya/CVE-2021-4034-PwnKit-
https://github.com/Ankit-Ojha16/CVE-2021-4034
https://github.com/dzonerzy/poc-cve-2021-4034
https://github.com/Plethore/CVE-2021-4034
https://github.com/ArianeBlow/NagiosXI-RCE-all-version-CVE-2021-40345
https://github.com/chenaotian/CVE-2021-4034
https://github.com/jm33-m0/go-lpe
https://github.com/JohnHammond/CVE-2021-4034
https://github.com/Nero22k/CVE-2021-4034
https://github.com/jayhutajulu1/PwnKit-CVE-2021-4034
https://github.com/Nosferatuvjr/PwnKit
https://github.com/zhzyker/CVE-2021-4034
https://github.com/c3c/CVE-2021-4034
CVE-2021-4034 - Changed to Known Ransomware Status
Red Hat Polkit Out-of-Bounds Read and Write VulnerabilityVendor: Red HatProduct: PolkitThe Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 UTCDate Added to KEV: 2022-06-27View CVE https://nvd.nist.gov/vuln/detail/CVE-2021-4034
##updated 2026-08-14T18:31:38
1 posts
CVE-2026-13196 - OOB write in KUNBUS piControl 2.6.2. Local auth attacker can corrupt kernel memory, cause DoS. No CVSS yet, unpatched. Update immediately. #CVE #KUNBUS #infosec
##updated 2026-08-14T15:32:50
1 posts
1 repos
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
#ApacheStruts #Struts2 #DoS #CVE #JavaWeb #CyberSecurity #InfoSec #Vulnerability
##updated 2026-08-13T15:34:13
2 posts
2 repos
Sentencing is swift and merciless: patch Microsoft SharePoint against CVE-2026-55040 without delay, or face consequences this court will not be held responsible for.
Reward: You've received the Gavel of Marginal Preparedness. It is mostly decorative at this point.
#SharePoint #CyberSecurity #CriticalVulnerability #Microsoft #Ransomware #ExploitInTheWild (2/2)
##🏆 New Achievement! The PoC Heard Round the World!
This court finds Microsoft SharePoint guilty of harboring CVE-2026-55040, a critical vulnerability of the highest order. Exhibit A: Rapid7 published proof-of-concept exploit code. Exhibit B: threat actors, punctual as a process server, immediately began active exploitation. The defense's argument of "maybe nobody will notice" is overruled and stricken from the record. (1/2)
##updated 2026-08-12T05:17:56.963000
2 posts
1 repos
📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack
Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow
##Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html
#cybersecurity #vulnerability #SAP
updated 2026-08-07T19:18:51.610000
1 posts
23 repos
https://github.com/4minx/CVE-2026-64638
https://github.com/renzi25031469/CVE-2026-64638-WordPress-Core-XSS2Shell
https://github.com/tc4dy/CVE-2026-64638-PoC-Exploit
https://github.com/HackSpeak/CVE-2026-64638
https://github.com/Alixploit22/CVEX2SHEL
https://github.com/wordsec/XSS2Shell
https://github.com/eh-amish/CVE-2026-64638-XSS-to-Shell-PoC
https://github.com/imbas007/CVE-2026-64638-POC
https://github.com/mohwahyudi/poc-CVE-2026-64638-
https://github.com/SanaullahAmanullah/xss2shell-check
https://github.com/ZSecur1ty/XSS2Shell-CVE-2026-64638
https://github.com/g0d150ne/XSS2Shell
https://github.com/686f6c61/POC-WP-XSS2Shell-CVE-2026-64638
https://github.com/yogaGymn/XSS2Shell-CVE-2026-64638
https://github.com/5yu4n/CVE-2026-64638
https://github.com/jendmaoul/XSS2Shell-CVE-2026-64638
https://github.com/Dungsocool/CVE-2026-64638
https://github.com/0xBlackash/CVE-2026-64638
https://github.com/MR-LeonardoGomes/XSS2Shell-CVE-2026-64638
https://github.com/ZildanZ/CVE-2026-64638
https://github.com/HORKimhab/CVE-2026-64638
📢 xss2shell (CVE-2026-64638) : XSS réfléchie non authentifiée menant à RCE sur WordPress < 7.0.3
📅 Source : flawfence.com, publié le 10 août 2026. Analyse technique détaillée de la vulnérabilité CVE-2026-64638, baptisée xss2shell, découverte par l'équipe de recherche pwn.ai et corrigée dans WordPress 7.0.3 le 6 août 2026.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-xss2shell-cve-2026-64638-xss-reflechie-non-authentifiee-menant-a-rce-sur-wordpress-7-0-3/
🌐 source : https://flawfence.com/blog/xss2shell-faille-wordpress-xss-rce-cve-2026-64638/
🟡 vérification factuelle moyenne
#RCE #WordPress #Cyberveille
updated 2026-08-05T05:17:14.873000
2 posts
1 repos
https://github.com/minanagehsalalma/CVE-2026-6837-zyxel-export-cgi-command-injection
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
##updated 2026-08-01T05:16:55.023000
1 posts
1 repos
📰 Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw
Clop ransomware group claims massive data theft from Shell, Philips, GE, and 40+ others by exploiting a critical PTC Windchill vulnerability (CVE-2026-12569). #Clop #Ransomware #SupplyChainAttack
##updated 2026-07-30T15:31:51
3 posts
vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##vCenter Flaw Exploited Just Five Days After Disclosure https://www.infosecurity-magazine.com/news/vcenter-cve-2026-59310-exploited/
##2026-W33 — Weekly Threat Roundup
🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…
https://threatnoir.com/weekly/2026-w33
#infosec #cybersecurity #threatintel
🤖 AI generated summary
##updated 2026-06-17T10:47:32.723000
1 posts
1 repos
Breaking AI Orchestration: Hijacking N8n HITL Chat Sessions
n8n의 HITL Chat 노드에서 인증 없이 활성 WebSocket 채팅 세션을 탐색·도청·메시지 주입할 수 있는 취약점이 발견됐다. 순차적인 executionId와 공개된 `/form-waiting` 상태 오라클, 클라이언트가 임의 지정 가능한 sessionId가 결합돼 실행 중인 에이전트 대화를 탈취할 수 있으며, 에이전트가 반환하는 도구 결과·검색 컨텍스트 등의 노출 및 대화 조작으로 이어질 수 있다. 이 이슈는 CVE-2026-42228(CVSS 6.3, Moderate)로 수정됐으며, n...
https://zerolabs.rubrik.com/blog/breaking-ai-orchestration-part-2-hijacking-n8n-hitl-chat-sessions
##updated 2026-06-17T02:47:06.173000
1 posts
CVE-2020-0968 - Changed to Known Ransomware Status
Microsoft Internet Explorer Scripting Engine Memory Corruption VulnerabilityVendor: MicrosoftProduct: Internet ExplorerMicrosoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: August 14, 2026 at 18:08:17 https://nvd.nist.gov/vuln/detail/CVE-2020-0968
##updated 2026-06-17T00:37:05.163000
1 posts
2 repos
CVE-2016-0189 - Changed to Known Ransomware Status
Microsoft Internet Explorer Memory Corruption VulnerabilityVendor: MicrosoftProduct: Internet ExplorerThe Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.Status changed from Unknown to Known for ransomware campaign usage.Flip detected on: Augusthttps://nvd.nist.gov/vuln/detail/CVE-2016-0189
##updated 2026-03-26T16:41:02
2 posts
CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce
##updated 2025-10-22T00:32:53
1 posts
4 repos
https://github.com/itstarsec/CVE-2020-0618
https://github.com/wortell/cve-2020-0618
CVE-2020-0618 - Changed to Known Ransomware Status
Microsoft SQL Server Reporting Services Remote Code Execution VulnerabilityVendor: MicrosoftProduct: SQL ServerMicrosoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.Status changed from Unknown to Known https://nvd.nist.gov/vuln/detail/CVE-2020-0618
##updated 2025-10-22T00:32:31
1 posts
1 repos
CVE-2018-0802 - Changed to Known Ransomware Status
Microsoft Office Memory Corruption VulnerabilityVendor: MicrosoftProduct: OfficeMicrosoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.Status changed from Unknown to Known for ransomware https://nvd.nist.gov/vuln/detail/CVE-2018-0802
##updated 2025-10-22T00:31:30
1 posts
7 repos
https://github.com/rxwx/CVE-2018-0802
https://github.com/Abdibimantara/Maldoc-Analysis
https://github.com/likekabin/CVE-2018-0802_CVE-2017-11882
https://github.com/zldww2011/CVE-2018-0802_POC
https://github.com/Ridter/RTF_11882_0802
CVE-2018-0802 - Changed to Known Ransomware Status
Microsoft Office Memory Corruption VulnerabilityVendor: MicrosoftProduct: OfficeMicrosoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.Status changed from Unknown to Known for ransomware https://nvd.nist.gov/vuln/detail/CVE-2018-0802
##updated 2025-06-18T03:32:00
1 posts
1 repos
https://github.com/thefreestyleresearcher/CVE-2025-49091-Gajim-RCE
‼️ CVE-2025-49091: Single click Remote Code Execution exploit targeting Gajim on devices with KDE Plasma.
GitHub PoC: https://github.com/thefreestyleresearcher/CVE-2025-49091-Gajim-RCE
##📢 Vulnérabilité critique d'exécution de code à distance dans WordPress (CVE-2026-65640)
Le CERT-FR a publié le 13 août 2026 l'avis CERTFR-2026-AVI-1018 signalant une vulnérabilité dans WordPress, basé sur le bulletin de sécurité officiel WordPress du 12 août 2026. CVE : CVE-2026-65640 Impact : Exécution de code arbitraire à distance (RCE) Produit affecté…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-16-vulnerabilite-critique-d-execution-de-code-a-distance-dans-wordpress-cve-2026-65640/
🌐 source : https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1018/
🟡 vérification factuelle moyenne
#WordPress #CERTFR #Cyberveille
🚨 Critical #MariaDB flaw enables remote code execution
CVE-2026-49261 can run arbitrary commands on vulnerable servers.
🔗 read more: securityonline.info/...
#ransomNews #cybersecurity
🟠 CVE-2026-18500 - High (8.1)
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##