##
Updated at UTC 2026-10-10T19:08:29.063031
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-106609 | 7.5 | 0.00% | 2 | 0 | 2026-10-10T18:31:27 | Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcas | |
| CVE-2026-105889 | 9.3 | 0.00% | 2 | 0 | 2026-10-10T18:31:27 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-103071 | 7.5 | 0.00% | 2 | 0 | 2026-10-10T18:31:26 | Improper Control of Generation of Code ('Code Injection') vulnerability in Villa | |
| CVE-2026-104398 | 9.8 | 0.00% | 2 | 0 | 2026-10-10T17:16:59.937000 | Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate M | |
| CVE-2026-108546 | 7.5 | 0.00% | 2 | 0 | 2026-10-10T15:30:30 | Spotweb through 1.5.8 contains an OS command injection vulnerability in the runc | |
| CVE-2026-105885 | 8.8 | 0.00% | 2 | 0 | 2026-10-10T15:30:29 | Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider- | |
| CVE-2026-108549 | 8.1 | 0.00% | 2 | 0 | 2026-10-10T15:30:29 | cc-connect through 1.5.0 contains a missing authentication vulnerability in the | |
| CVE-2026-108551 | 9.8 | 0.00% | 2 | 0 | 2026-10-10T15:30:29 | openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit | |
| CVE-2026-108550 | 8.8 | 0.00% | 2 | 0 | 2026-10-10T15:30:24 | SkillHub before 0.2.22 contains an incorrect authorization vulnerability in Acco | |
| CVE-2026-108553 | 7.5 | 0.00% | 2 | 0 | 2026-10-10T15:16:58.410000 | OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in | |
| CVE-2026-108161 | 7.5 | 0.00% | 2 | 0 | 2026-10-10T14:16:37.223000 | FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_r | |
| CVE-2026-104803 | 9.8 | 0.45% | 2 | 0 | 2026-10-10T09:30:37 | The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in | |
| CVE-2026-91136 | 7.5 | 0.56% | 2 | 0 | 2026-10-10T09:16:39.360000 | The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versi | |
| CVE-2026-96662 | 7.5 | 0.39% | 2 | 0 | 2026-10-10T08:17:08.033000 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | |
| CVE-2026-93950 | 7.5 | 0.20% | 2 | 0 | 2026-10-10T08:17:07.307000 | Missing Authorization vulnerability in StylemixThemes Motors motors allows Explo | |
| CVE-2026-93945 | 9.8 | 0.33% | 4 | 0 | 2026-10-10T08:17:07.057000 | Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance a | |
| CVE-2026-93944 | 9.8 | 0.31% | 2 | 0 | 2026-10-10T08:17:06.930000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia cameli | |
| CVE-2026-93941 | 9.8 | 0.33% | 2 | 0 | 2026-10-10T08:17:06.557000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema al | |
| CVE-2026-93940 | 9.8 | 0.33% | 2 | 0 | 2026-10-10T08:17:06.433000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny | |
| CVE-2026-93938 | 9.8 | 0.33% | 2 | 0 | 2026-10-10T08:17:06.310000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwo | |
| CVE-2026-93937 | 9.8 | 0.33% | 2 | 0 | 2026-10-10T08:17:06.187000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia al | |
| CVE-2026-93936 | 9.8 | 0.33% | 2 | 0 | 2026-10-10T08:17:06.060000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm | |
| CVE-2026-62046 | 9.8 | 0.32% | 2 | 0 | 2026-10-10T08:17:04.777000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gute | |
| CVE-2026-62045 | 9.8 | 0.32% | 2 | 0 | 2026-10-10T08:17:04.647000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers boo | |
| CVE-2026-97670 | 9.1 | 0.37% | 1 | 0 | 2026-10-10T06:31:08 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization b | |
| CVE-2026-94589 | 9.8 | 0.66% | 1 | 0 | 2026-10-10T06:31:06 | The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirect | |
| CVE-2026-96207 | 10.0 | 0.48% | 2 | 0 | 2026-10-10T04:18:19.870000 | Improper certificate validation in Microsoft Partner Center allows an unauthoriz | |
| CVE-2026-94510 | 9.9 | 0.40% | 2 | 0 | 2026-10-10T04:18:19.577000 | Authorization bypass through user-controlled key in Microsoft Bookings allows an | |
| CVE-2026-84249 | 9.8 | 0.41% | 1 | 0 | 2026-10-10T04:18:18.437000 | IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to e | |
| CVE-2026-84058 | 8.1 | 0.36% | 1 | 0 | 2026-10-10T04:18:17.540000 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer over | |
| CVE-2026-82344 | 8.1 | 0.40% | 1 | 0 | 2026-10-10T04:18:16.730000 | IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer ove | |
| CVE-2026-78406 | 9.8 | 0.50% | 1 | 0 | 2026-10-10T04:18:15.970000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-18740 | 8.8 | 0.35% | 1 | 0 | 2026-10-10T04:18:12.470000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-16823 | 9.1 | 0.33% | 1 | 0 | 2026-10-10T04:18:12.110000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-108474 | 9.8 | 0.32% | 1 | 0 | 2026-10-10T00:17:03.673000 | In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped strin | |
| CVE-2026-108268 | 0 | 0.13% | 1 | 0 | 2026-10-09T22:16:59.643000 | Enclave OS Virtual runs container workloads inside confidential virtual machines | |
| CVE-2026-75351 | 7.5 | 0.40% | 1 | 0 | 2026-10-09T21:31:18 | OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side Et | |
| CVE-2026-75346 | 7.5 | 0.54% | 1 | 0 | 2026-10-09T21:31:17 | An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast | |
| CVE-2026-92705 | 7.8 | 0.13% | 1 | 0 | 2026-10-09T21:17:06.360000 | Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegis | |
| CVE-2026-108264 | 9.1 | 0.38% | 1 | 0 | 2026-10-09T21:17:04.703000 | Wizarr is an advanced user invitation and management system for Jellyfin, Plex, | |
| CVE-2026-108259 | 8.2 | 0.25% | 1 | 0 | 2026-10-09T21:17:04.017000 | Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads | |
| CVE-2026-107805 | 7.5 | 0.44% | 1 | 0 | 2026-10-09T20:57:10 | ## Summary In Nginx UI versions 2.5.0 through 2.5.x, the node-signature authent | |
| CVE-2026-108261 | 9.3 | 0.16% | 1 | 0 | 2026-10-09T20:56:50 | ### Summary The TinaCMS admin builds its preview `<iframe src>` from the `/~/*` | |
| CVE-2026-108260 | 7.6 | 0.21% | 1 | 0 | 2026-10-09T20:56:46 | ### Summary `<tina-markdown>` renders a rich-text AST into the DOM and, for `a` | |
| CVE-2026-107845 | 9.3 | 0.27% | 1 | 0 | 2026-10-09T20:53:52 | An unauthenticated front end visitor can post a comment containing a XSS injecti | |
| CVE-2026-62376 | 8.1 | 0.21% | 1 | 0 | 2026-10-09T20:49:15 | ### Summary Vikunja stores password-reset, email-confirmation, and account-dele | |
| CVE-2026-107806 | None | 0.33% | 1 | 1 | 2026-10-09T20:45:03 | ## Summary An authenticated nginx-ui user can call `POST /api/restore`, upload | |
| CVE-2026-107839 | 7.5 | 0.34% | 1 | 0 | 2026-10-09T20:44:55 | ### Summary The AoE3 `POST /game/cloud/getFileURL` handler in `luskaner/ageLANSe | |
| CVE-2026-57458 | 8.1 | 0.27% | 1 | 0 | 2026-10-09T20:40:28 | ## Summary A scoped API token can bypass its declared permissions by using the | |
| CVE-2026-107840 | 7.5 | 0.44% | 1 | 0 | 2026-10-09T20:17:09.900000 | yopass is a service for securely sharing secrets, passwords, and files. Prior to | |
| CVE-2026-103413 | 8.8 | 0.39% | 1 | 0 | 2026-10-09T18:32:43 | Improper input validation vulnerability in Apache Camel Karavan. When a deplo | |
| CVE-2026-75347 | 7.5 | 0.42% | 1 | 0 | 2026-10-09T18:31:53 | EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired poi | |
| CVE-2026-108113 | 8.8 | 0.64% | 1 | 0 | 2026-10-09T18:31:48 | ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerab | |
| CVE-2026-75349 | 7.5 | 0.45% | 1 | 0 | 2026-10-09T18:31:48 | EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bound | |
| CVE-2026-108160 | 7.5 | 0.15% | 1 | 0 | 2026-10-09T18:31:48 | AstronRPA through 1.1.6 contains a download of code without integrity check vuln | |
| CVE-2026-104084 | 8.8 | 0.25% | 1 | 0 | 2026-10-09T18:31:47 | SmarterMail before build 9777 contains a privilege escalation vulnerability wher | |
| CVE-2026-75345 | 7.5 | 0.45% | 1 | 0 | 2026-10-09T18:31:47 | OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected | |
| CVE-2026-90983 | 8.2 | 0.26% | 1 | 0 | 2026-10-09T18:31:47 | Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. | |
| CVE-2026-108157 | 8.1 | 0.53% | 1 | 0 | 2026-10-09T18:31:44 | Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vu | |
| CVE-2026-78795 | 7.5 | 0.45% | 1 | 0 | 2026-10-09T18:17:14.903000 | An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless route | |
| CVE-2026-75350 | 7.5 | 0.48% | 1 | 0 | 2026-10-09T18:17:14.037000 | EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in | |
| CVE-2026-75348 | 7.5 | 0.51% | 1 | 0 | 2026-10-09T18:17:13.893000 | An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast | |
| CVE-2026-107818 | 8.4 | 0.34% | 1 | 0 | 2026-10-09T18:17:03.373000 | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until | |
| CVE-2026-108159 | 7.5 | 0.33% | 1 | 0 | 2026-10-09T17:41:47.060000 | AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the des | |
| CVE-2026-107815 | 8.5 | 0.57% | 1 | 0 | 2026-10-09T17:41:29.727000 | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until | |
| CVE-2026-107826 | 7.5 | 0.46% | 1 | 0 | 2026-10-09T17:33:55 | ### Summary The JSON body processor (`internal/bodyprocessors/json.go`) can be | |
| CVE-2026-15340 | 9.8 | 0.60% | 1 | 0 | 2026-10-09T17:29:33.410000 | lwIP SMTP client does not check the size of inputs, potentially allowing a buffe | |
| CVE-2026-107814 | 8.4 | 0.28% | 1 | 0 | 2026-10-09T17:16:45.853000 | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until | |
| CVE-2026-107809 | 8.8 | 0.18% | 1 | 0 | 2026-10-09T17:16:45.730000 | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5. | |
| CVE-2026-107812 | 7.5 | 0.17% | 1 | 0 | 2026-10-09T17:08:21 | ## Summary The self-upgrade downloads the release binary and its checksum (`*.ta | |
| CVE-2026-107808 | 8.1 | 0.41% | 1 | 0 | 2026-10-09T17:08:16 | ## Summary nginx-ui supports two second-factor methods — TOTP (OTP) and WebAuth | |
| CVE-2026-107813 | 8.8 | 0.30% | 1 | 0 | 2026-10-09T17:08:07 | ## Summary Incomplete fix of GHSA-5v7c-xpfp-p65m: the secure-session (OTP step- | |
| CVE-2026-107807 | 8.8 | 0.31% | 1 | 0 | 2026-10-09T17:07:11 | ## 1. Vulnerability Summary nginx-ui's `Node.Secret` is a master credential tha | |
| CVE-2026-107810 | 8.1 | 0.36% | 1 | 0 | 2026-10-09T17:07:06 | ### Summary An authenticated user who can create and restore a backup can craft | |
| CVE-2026-108106 | 7.5 | 0.37% | 1 | 0 | 2026-10-09T17:06:17.770000 | Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulne | |
| CVE-2026-100730 | 9.8 | 0.62% | 1 | 0 | 2026-10-09T16:41:53.540000 | A service console interface on openPDC and openHistorian deserializes a client-s | |
| CVE-2026-107811 | 8.8 | 0.36% | 1 | 0 | 2026-10-09T16:38:57.820000 | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5. | |
| CVE-2026-55797 | 8.8 | 1.55% | 1 | 0 | 2026-10-09T16:37:27 | ### Impact Argo CD runs a shell command in the repo-server when it clones or fe | |
| CVE-2026-103412 | 8.8 | 0.52% | 1 | 0 | 2026-10-09T16:33:39.007000 | Improper limitation of a pathname to a restricted directory ('path traversal') v | |
| CVE-2026-93947 | 9.3 | 0.24% | 1 | 0 | 2026-10-09T16:17:32.090000 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-107375 | 8.8 | 0.34% | 1 | 0 | 2026-10-09T16:17:22.297000 | JHipster is a development platform to quickly generate, develop, and deploy mode | |
| CVE-2026-105436 | 8.8 | 0.25% | 1 | 0 | 2026-10-09T16:17:21.427000 | Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-ch | |
| CVE-2015-3306 | 10.0 | 99.50% | 2 | 18 | template | 2026-10-09T16:17:18.210000 | The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write t |
| CVE-2026-79842 | 9.1 | 0.33% | 2 | 0 | 2026-10-09T15:32:29 | An authentication bypass vulnerability exists in HPE Intelligent Management Cent | |
| CVE-2026-39460 | 8.1 | 0.29% | 1 | 0 | 2026-10-09T15:31:42 | Usernames and passwords, including the default factory credentials, are stored i | |
| CVE-2026-108101 | 7.5 | 0.39% | 1 | 0 | 2026-10-09T15:31:38 | HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulne | |
| CVE-2026-105281 | 7.5 | 0.31% | 1 | 0 | 2026-10-09T15:31:37 | The internal data publisher on openPDC accepts network connections without authe | |
| CVE-2026-28745 | 7.5 | 0.22% | 1 | 0 | 2026-10-09T15:31:35 | Usernames and passwords, including the default credentials, are stored in the co | |
| CVE-2026-39453 | 8.3 | 0.29% | 1 | 0 | 2026-10-09T15:31:35 | Navigating to a certain URL on the switch’s web server causes the switch to rebo | |
| CVE-2026-33367 | 8.1 | 0.29% | 1 | 0 | 2026-10-09T15:31:35 | SNMP can be used to perform administrative actions such as retrieving configurat | |
| CVE-2026-108107 | 9.8 | 0.41% | 1 | 0 | 2026-10-09T15:31:34 | PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerabi | |
| CVE-2026-108109 | 9.1 | 0.39% | 1 | 0 | 2026-10-09T15:31:34 | PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the c | |
| CVE-2026-83943 | 8.7 | 0.38% | 1 | 0 | 2026-10-09T15:31:32 | Exposure of sensitive information to an unauthorized actor in Azure API Center a | |
| CVE-2026-86405 | 9.8 | 0.20% | 1 | 0 | 2026-10-09T15:31:30 | Improper verification of cryptographic signature vulnerability in Sipay Electron | |
| CVE-2026-107406 | None | 0.47% | 9 | 3 | 2026-10-09T15:31:27 | Memory overflow vulnerability leading to Remote Code Execution or Denial of Serv | |
| CVE-2026-94503 | 10.0 | 0.28% | 1 | 1 | 2026-10-09T12:31:48 | Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify | |
| CVE-2026-15762 | 9.8 | 0.52% | 1 | 0 | 2026-10-09T04:18:09.937000 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-14497 | 8.1 | 0.59% | 1 | 0 | 2026-10-09T04:18:05.817000 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-69435 | 9.6 | 0.39% | 2 | 0 | 2026-10-09T00:31:56 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevat | |
| CVE-2026-83947 | 7.7 | 0.37% | 1 | 0 | 2026-10-09T00:31:56 | Missing authorization in Azure Event Grid allows an authorized attacker to perfo | |
| CVE-2026-77900 | 9.8 | 0.49% | 2 | 0 | 2026-10-09T00:31:56 | Missing authentication for critical function in Azure App Service allows an unau | |
| CVE-2026-88131 | 9.8 | 0.84% | 2 | 0 | 2026-10-09T00:31:56 | Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized | |
| CVE-2026-84057 | 8.1 | 0.36% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to e | |
| CVE-2026-84035 | 8.1 | 0.37% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker | |
| CVE-2026-84875 | 7.5 | 0.42% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker | |
| CVE-2026-89091 | 8.8 | 0.48% | 1 | 0 | 2026-10-09T00:31:56 | A flaw was found in ansible-core. When installing a collection with `ansible-gal | |
| CVE-2026-107701 | 8.2 | 0.33% | 1 | 0 | 2026-10-08T21:35:53.890000 | dot-access through 1.0.0 contains a prototype pollution vulnerability that allow | |
| CVE-2026-9209 | 9.8 | 0.69% | 1 | 1 | 2026-10-08T21:35:53.890000 | mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulne | |
| CVE-2026-19482 | 8.8 | 0.42% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19491 | 9.1 | 0.33% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19493 | 7.5 | 0.36% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-78401 | 9.8 | 0.57% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-17189 | 8.2 | 0.15% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-16916 | 9.1 | 0.42% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19494 | 8.1 | 0.29% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-84275 | 7.5 | 0.33% | 1 | 0 | 2026-10-08T21:33:34 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM fil | |
| CVE-2026-107704 | 9.8 | 1.66% | 1 | 0 | 2026-10-08T21:33:34 | The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injectio | |
| CVE-2026-11318 | 7.8 | 0.19% | 1 | 1 | 2026-10-08T21:33:33 | Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com. | |
| CVE-2026-107703 | 9.8 | 1.85% | 1 | 0 | 2026-10-08T21:33:33 | @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerabilit | |
| CVE-2026-107699 | 9.8 | 1.47% | 1 | 0 | 2026-10-08T21:33:33 | ppt2png through 0.0.6 contains an OS command injection vulnerability that allows | |
| CVE-2026-107700 | 9.8 | 0.50% | 1 | 0 | 2026-10-08T21:33:33 | dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allo | |
| CVE-2026-107782 | 7.8 | 0.11% | 1 | 0 | 2026-10-08T21:33:32 | System Informer before 4.0.26241.138 contains an incorrect authorization vulnera | |
| CVE-2026-84244 | 9.3 | 0.18% | 1 | 0 | 2026-10-08T21:33:28 | IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulne | |
| CVE-2026-84276 | 7.5 | 0.33% | 1 | 0 | 2026-10-08T21:33:26 | IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerabi | |
| CVE-2026-95210 | 9.1 | 0.23% | 1 | 0 | 2026-10-08T21:33:23 | Improper certificate validation in gnutls v3.8.13 causes the application to acce | |
| CVE-2026-107779 | 9.8 | 0.54% | 1 | 0 | 2026-10-08T21:27:15.010000 | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains | |
| CVE-2026-107333 | 8.1 | 0.98% | 1 | 0 | 2026-10-08T21:03:43.847000 | Malcolm's nginx based reverse proxy contains a URL path normalization inconsiste | |
| CVE-2026-107383 | 7.5 | 0.39% | 1 | 0 | 2026-10-08T20:25:00.647000 | MariaDB Connector/Node.js is used to connect applications developed on Node.js t | |
| CVE-2026-107322 | 7.8 | 0.13% | 1 | 0 | 2026-10-08T20:17:31.590000 | An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS database | |
| CVE-2026-76463 | 8.8 | 0.14% | 1 | 0 | 2026-10-08T20:08:45.857000 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-107384 | 8.1 | 0.45% | 1 | 0 | 2026-10-08T19:42:25 | ### Description With the non-default permitSetMultiParamEntries option enabled, | |
| CVE-2015-5477 | 7.5 | 99.41% | 2 | 8 | 2026-10-08T18:32:53 | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote | |
| CVE-2021-3199 | 9.8 | 19.35% | 2 | 0 | 2026-10-08T18:32:52 | Directory traversal with remote code execution can occur in /upload in ONLYOFFIC | |
| CVE-2026-104078 | 7.8 | 0.29% | 1 | 0 | 2026-10-08T18:32:32 | Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bun | |
| CVE-2026-104077 | 7.8 | 0.35% | 1 | 0 | 2026-10-08T18:32:31 | Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability th | |
| CVE-2026-107377 | 7.5 | 0.45% | 1 | 0 | 2026-10-08T17:58:02 | ## Summary When processing an attacker-controlled Protobuf schema, vulnerable v | |
| CVE-2026-107303 | 7.6 | 0.26% | 1 | 0 | 2026-10-08T17:40:32 | ## Summary Applications generated by generator-jhipster v9.2.0 can persist user- | |
| CVE-2026-107302 | 7.5 | 0.43% | 1 | 0 | 2026-10-08T17:40:11 | ### Impact A truncated `map32` header causes an out-of-bounds buffer read and t | |
| CVE-2026-107300 | 7.5 | 0.43% | 1 | 0 | 2026-10-08T17:40:07 | ### Impact The streaming decoder recursively invokes itself for every complete | |
| CVE-2026-107295 | 7.6 | 0.16% | 1 | 0 | 2026-10-08T17:16:37 | ### Summary The Pydantic AI development web chat UI (`Agent.to_web()`, `clai we | |
| CVE-2026-93017 | 7.7 | 0.21% | 1 | 0 | 2026-10-08T15:33:15 | The `insights-operator-gather` ClusterRole grants the operator's service account | |
| CVE-2026-14992 | 9.8 | 0.31% | 1 | 0 | 2026-10-08T15:33:11 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-14502 | 9.8 | 0.39% | 1 | 0 | 2026-10-08T15:33:10 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-16340 | 9.8 | 0.49% | 1 | 0 | 2026-10-08T15:33:05 | IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0. | |
| CVE-2026-102255 | 10.0 | 0.48% | 4 | 0 | 2026-10-07T18:33:12 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-76471 | 9.8 | 0.52% | 1 | 0 | 2026-10-07T18:32:21 | A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an una | |
| CVE-2026-76467 | 7.5 | 0.25% | 1 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-76464 | 9.6 | 0.19% | 1 | 0 | 2026-10-07T18:32:20 | As part of Cisco's ongoing commitment to proactive security and product quality, | |
| CVE-2026-20362 | 7.2 | 0.47% | 1 | 0 | 2026-10-07T18:32:14 | A vulnerability in the web-based management interface of Cisco Finesse could all | |
| CVE-2026-107181 | 8.1 | 0.34% | 7 | 1 | 2026-10-07T15:32:07 | Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnera | |
| CVE-2026-21589 | 0 | 1.77% | 4 | 12 | template | 2026-10-07T13:17:22.273000 | This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira S |
| CVE-2026-105192 | 9.8 | 0.48% | 1 | 1 | 2026-10-07T12:31:58 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticate | |
| CVE-2025-64393 | None | 0.36% | 2 | 0 | 2026-10-07T09:32:29 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu | |
| CVE-2026-59346 | 9.3 | 0.26% | 2 | 1 | 2026-10-07T06:33:08 | VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic | |
| CVE-2026-79820 | 9.0 | 0.27% | 1 | 0 | 2026-10-06T15:15:48.310000 | A remote user validation failure vulnerability exists in HPE Integrated Lights-O | |
| CVE-2026-105134 | 10.0 | 1.84% | 5 | 1 | 2026-10-06T15:04:52.637000 | A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects | |
| CVE-2026-105133 | 7.3 | 0.38% | 5 | 0 | 2026-10-04T09:30:21 | A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the fu | |
| CVE-2026-88467 | 6.2 | 0.12% | 1 | 0 | 2026-10-01T18:33:43 | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification fu | |
| CVE-2026-48710 | 6.5 | 7.06% | 1 | 5 | template | 2026-10-01T18:17:18.153000 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the H |
| CVE-2026-46649 | 0 | 0.50% | 1 | 0 | 2026-09-28T21:17:17.733000 | Joplin is an open source note-taking and to-do application that organises notes | |
| CVE-2026-88771 | 9.8 | 1.08% | 3 | 14 | 2026-09-28T12:32:08 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc | |
| CVE-2026-88772 | 8.1 | 1.30% | 1 | 8 | 2026-09-28T12:26:47.670000 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue | |
| CVE-2026-82077 | None | 0.74% | 3 | 0 | 2026-09-24T09:32:00 | An improper limitation of a pathname to a restricted directory (path traversal) | |
| CVE-2026-88404 | 9.8 | 0.75% | 1 | 0 | 2026-09-22T15:33:37 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.exe | |
| CVE-2026-88402 | 9.8 | 0.47% | 1 | 0 | 2026-09-22T15:33:36 | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allow | |
| CVE-2026-61647 | None | 0.32% | 1 | 0 | 2026-09-22T14:43:27 | ## Summary The `vault_batch` MCP tool (and the equivalent `POST /batch-to-vault | |
| CVE-2026-94571 | None | 0.53% | 1 | 0 | 2026-09-21T21:32:01 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject c | |
| CVE-2026-92382 | 4.1 | 0.14% | 1 | 0 | 2026-09-21T18:32:14 | An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT s | |
| CVE-2026-87491 | 8.8 | 3.14% | 1 | 2 | 2026-09-21T13:17:11.283000 | Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remo | |
| CVE-2026-93485 | 7.1 | 0.38% | 1 | 4 | 2026-09-18T06:32:17 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-82078 | 9.1 | 63.53% | 3 | 2 | 2026-09-14T00:16:56.777000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-0310 | None | 0.37% | 1 | 0 | 2026-09-10T06:31:55 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto | |
| CVE-2026-80093 | 7.0 | 0.32% | 1 | 0 | 2026-09-09T00:31:34 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at | |
| CVE-2026-31431 | 7.8 | 3.44% | 1 | 100 | template | 2026-09-08T09:36:36 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg |
| CVE-2026-85046 | 8.8 | 48.88% | 1 | 8 | 2026-09-06T03:30:24 | Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote at | |
| CVE-2026-81578 | 9.8 | 85.58% | 3 | 2 | template | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface |
| CVE-2026-73570 | 8.9 | 71.66% | 1 | 10 | template | 2026-08-21T18:34:48 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor |
| CVE-2026-47483 | 8.2 | 0.34% | 1 | 0 | 2026-07-28T18:33:11 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp | |
| CVE-2025-31200 | 9.8 | 20.90% | 1 | 4 | 2026-06-17T09:10:00.550000 | A memory corruption issue was addressed with improved bounds checking. This issu | |
| CVE-2025-24201 | 7.1 | 3.85% | 1 | 3 | 2025-11-13T21:31:15 | An out-of-bounds write issue was addressed with improved checks to prevent unaut | |
| CVE-2025-47818 | 2.2 | 0.24% | 1 | 0 | 2025-10-24T18:32:04 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for | |
| CVE-2024-3094 | 10.0 | 85.97% | 1 | 90 | template | 2024-03-29T18:30:50 | Malicious code was discovered in the upstream tarballs of xz, starting with vers |
| CVE-2023-22894 | 7.5 | 3.61% | 2 | 2 | 2023-11-07T05:05:45 | ### Summary Strapi through 4.7.1 allows unauthenticated attackers to discover s | |
| CVE-2016-3081 | 8.1 | 96.05% | 6 | 0 | template | 2023-11-01T19:47:30 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when |
| CVE-2026-85219 | 0 | 0.41% | 2 | 0 | N/A | ||
| CVE-2026-87902 | 0 | 39.98% | 2 | 27 | template | N/A | |
| CVE-2026-108269 | 0 | 0.13% | 1 | 0 | N/A | ||
| CVE-2026-108263 | 0 | 0.43% | 1 | 0 | N/A | ||
| CVE-2026-107821 | 0 | 0.48% | 1 | 0 | N/A | ||
| CVE-2026-107838 | 0 | 0.34% | 1 | 0 | N/A | ||
| CVE-2026-107837 | 0 | 0.38% | 1 | 0 | N/A | ||
| CVE-2026-61746 | 0 | 0.40% | 1 | 0 | N/A | ||
| CVE-2026-72898 | 0 | 19.05% | 1 | 10 | template | N/A | |
| CVE-2026-106433 | 0 | 0.27% | 1 | 0 | N/A | ||
| CVE-2026-107376 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-107332 | 0 | 0.11% | 1 | 0 | N/A |
updated 2026-10-10T18:31:27
2 posts
🟠 CVE-2026-106609 - High (7.5)
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-106609 - High (7.5)
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T18:31:27
2 posts
🔴 CVE-2026-105889 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-105889 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T18:31:26
2 posts
🟠 CVE-2026-103071 - High (7.5)
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-103071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-103071 - High (7.5)
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-103071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T17:16:59.937000
2 posts
🔴 CVE-2026-104398 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104398/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-104398 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104398/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:30
2 posts
🟠 CVE-2026-108546 - High (7.5)
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108546/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-108546 - High (7.5)
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108546/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:29
2 posts
🟠 CVE-2026-105885 - High (8.8)
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-105885 - High (8.8)
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:29
2 posts
🟠 CVE-2026-108549 - High (8.1)
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-108549 - High (8.1)
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:29
2 posts
🔴 CVE-2026-108551 - Critical (9.8)
openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108551/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-108551 - Critical (9.8)
openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108551/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:24
2 posts
🟠 CVE-2026-108550 - High (8.8)
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108550/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-108550 - High (8.8)
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108550/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:16:58.410000
2 posts
🟠 CVE-2026-108553 - High (7.5)
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-108553 - High (7.5)
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T14:16:37.223000
2 posts
🟠 CVE-2026-108161 - High (7.5)
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename templat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-108161 - High (7.5)
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename templat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
2 posts
WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. https://radar.offseq.com/threat/cve-2026-104803-cwe-287-improper-authentication-in-whyun-wpcom-member-4f47db1288fd1984 #OffSeq #WordPress #Infosec #CVE2026104803
##WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. https://radar.offseq.com/threat/cve-2026-104803-cwe-287-improper-authentication-in-whyun-wpcom-member-4f47db1288fd1984 #OffSeq #WordPress #Infosec #CVE2026104803
##updated 2026-10-10T09:16:39.360000
2 posts
🟠 CVE-2026-91136 - High (7.5)
The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permissi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91136/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-91136 - High (7.5)
The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permissi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91136/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:08.033000
2 posts
🟠 CVE-2026-96662 - High (7.5)
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient esca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96662/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-96662 - High (7.5)
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient esca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96662/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:07.307000
2 posts
🟠 CVE-2026-93950 - High (7.5)
Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-93950 - High (7.5)
Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:07.057000
4 posts
🔴 CVE-2026-93945 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-93945 in Axiomthemes Balance (<=1.12.0) allows remote object injection via deserialization of untrusted data. No auth or user action needed — full system compromise possible. Restrict access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-93945-deserialization-of-untrusted-data-in-axiomthemes-balance-4f56b1b48493a9aa #OffSeq #CVE #Vuln
##🔴 CVE-2026-93945 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-93945 in Axiomthemes Balance (<=1.12.0) allows remote object injection via deserialization of untrusted data. No auth or user action needed — full system compromise possible. Restrict access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-93945-deserialization-of-untrusted-data-in-axiomthemes-balance-4f56b1b48493a9aa #OffSeq #CVE #Vuln
##updated 2026-10-10T08:17:06.930000
2 posts
CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 https://radar.offseq.com/threat/cve-2026-93944-deserialization-of-untrusted-data-in-themerex-group-camelia-9f283474b74167fd #OffSeq #Infosec #Vulnerability
##CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 https://radar.offseq.com/threat/cve-2026-93944-deserialization-of-untrusted-data-in-themerex-group-camelia-9f283474b74167fd #OffSeq #Infosec #Vulnerability
##updated 2026-10-10T08:17:06.557000
2 posts
🔴 CVE-2026-93941 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93941 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:06.433000
2 posts
🔴 CVE-2026-93940 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93940 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:06.310000
2 posts
🔴 CVE-2026-93938 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93938 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:06.187000
2 posts
🔴 CVE-2026-93937 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93937 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:06.060000
2 posts
🔴 CVE-2026-93936 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-93936 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T08:17:04.777000
2 posts
CVE-2026-62046: CRITICAL deserialization flaw in ThemeREX Gutentype (≤2.1.12) allows object injection — full system compromise possible. Patch status unknown, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-62046-deserialization-of-untrusted-data-in-themerex-group-gutentype-f4d0a8ac3919ab35 #OffSeq #WordPress #Vulnerability #Infosec
##CVE-2026-62046: CRITICAL deserialization flaw in ThemeREX Gutentype (≤2.1.12) allows object injection — full system compromise possible. Patch status unknown, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-62046-deserialization-of-untrusted-data-in-themerex-group-gutentype-f4d0a8ac3919ab35 #OffSeq #WordPress #Vulnerability #Infosec
##updated 2026-10-10T08:17:04.647000
2 posts
Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: https://radar.offseq.com/threat/cve-2026-62045-deserialization-of-untrusted-data-in-themerex-group-booklovers-71a61b206a138f37 #OffSeq #CVE202662045 #WordPress #Vuln #infosec
##Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: https://radar.offseq.com/threat/cve-2026-62045-deserialization-of-untrusted-data-in-themerex-group-booklovers-71a61b206a138f37 #OffSeq #CVE202662045 #WordPress #Vuln #infosec
##updated 2026-10-10T06:31:08
1 posts
CVE-2026-97670: Avada (Fusion) Builder ≤7.16.1 has a CRITICAL code injection flaw. Unauthenticated attackers can invoke arbitrary WP action hooks — risks include content deletion & DoS. Disable vulnerable forms, await patch. https://radar.offseq.com/threat/cve-2026-97670-cwe-94-improper-control-of-generation-of-code-code-injection-in-themefusion-avada-f8cd8b04809f86cf #OffSeq #WordPress #Vuln #CVE202697670
##updated 2026-10-10T06:31:06
1 posts
CVE-2026-94589: CRITICAL RCE in Extensions For CF7 (<=3.4.5) for WordPress. Unauth attackers can upload and run malicious files — full compromise possible. Restrict uploads, monitor activity, and check for fixes. https://radar.offseq.com/threat/cve-2026-94589-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-htplugins-extensions-for-cf7-1b07904cb30ec057 #OffSeq #WordPress #CVE202694589 #infosec
##updated 2026-10-10T04:18:19.870000
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. https://radar.offseq.com/threat/cve-2026-96207-cwe-295-improper-certificate-validation-in-microsoft-microsoft-partner-center-0f13dc5f1a15e1f3 #OffSeq #Microsoft #CVE202696207 #Infosec
##updated 2026-10-10T04:18:19.577000
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: https://radar.offseq.com/threat/cve-2026-94510-cwe-639-authorization-bypass-through-user-controlled-key-in-microsoft-microsoft-bookings-0e362c50ebe161b6 #OffSeq #Microsoft #Vuln #CVE #Infosec
##updated 2026-10-10T04:18:18.437000
1 posts
🔴 CVE-2026-84249 - Critical (9.8)
IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:17.540000
1 posts
🟠 CVE-2026-84058 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84058/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:16.730000
1 posts
🟠 CVE-2026-82344 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An unauthenticated remote attacker can send crafted TDS login fragments that exceed the fixed-size r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-82344/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:15.970000
1 posts
🔴 CVE-2026-78406 - Critical (9.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:12.470000
1 posts
🟠 CVE-2026-18740 - High (8.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:12.110000
1 posts
🔴 CVE-2026-16823 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16823/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T00:17:03.673000
1 posts
CVE-2026-108474: JetBrains Exposed (<1.5.1) faces CRITICAL SQL injection (CWE-89). Exploitation can fully compromise DBs — upgrade to 1.5.1+ now! CVSS 9.8. https://radar.offseq.com/threat/cve-2026-108474-cwe-89-in-jetbrains-exposed-73385fdc0142aed6 #OffSeq #SQLi #JetBrains #AppSec
##updated 2026-10-09T22:16:59.643000
1 posts
CVE-2026-108268 (CRITICAL, CVSS 9.1): Privasys enclave-os-virtual <0.2.43/<0.6.27 origin validation error lets attackers relay attestation quotes if they have the enclave TLS private key. Upgrade to patched versions ASAP. https://radar.offseq.com/threat/cve-2026-108268-cwe-346-origin-validation-error-in-privasys-enclave-os-virtual-3494df223a867096 #OffSeq #CVE2026108268 #Vuln
##updated 2026-10-09T21:31:18
1 posts
🟠 CVE-2026-75351 - High (7.5)
OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:31:17
1 posts
🟠 CVE-2026-75346 - High (7.5)
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:06.360000
1 posts
🟠 CVE-2026-92705 - High (7.8)
Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:04.703000
1 posts
🔴 CVE-2026-108264 - Critical (9.1)
Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:04.017000
1 posts
🟠 CVE-2026-108259 - High (8.2)
Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string li...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:57:10
1 posts
🟠 CVE-2026-107805 - High (7.5)
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107805/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:56:50
1 posts
🔴 CVE-2026-108261 - Critical (9.3)
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108261/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:56:46
1 posts
🟠 CVE-2026-108260 - High (7.6)
Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:53:52
1 posts
🔴 CVE-2026-107845 - Critical (9.3)
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107845/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:49:15
1 posts
🟠 CVE-2026-62376 - High (8.1)
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62376/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:45:03
1 posts
1 repos
A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover.
##updated 2026-10-09T20:44:55
1 posts
🟠 CVE-2026-107839 - High (7.5)
ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:40:28
1 posts
🟠 CVE-2026-57458 - High (8.1)
Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:17:09.900000
1 posts
🟠 CVE-2026-107840 - High (7.5)
yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_req...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107840/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:32:43
1 posts
Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.
#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412
##updated 2026-10-09T18:31:53
1 posts
🟠 CVE-2026-75347 - High (7.5)
EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:48
1 posts
🟠 CVE-2026-108113 - High (8.8)
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import ri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108113/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:48
1 posts
🟠 CVE-2026-75349 - High (7.5)
EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:48
1 posts
🟠 CVE-2026-108160 - High (7.5)
AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108160/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:47
1 posts
🟠 CVE-2026-104084 - High (8.8)
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:47
1 posts
🟠 CVE-2026-75345 - High (7.5)
OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:47
1 posts
🟠 CVE-2026-90983 - High (8.2)
Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass.
This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:44
1 posts
🟠 CVE-2026-108157 - High (8.1)
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can registe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108157/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:14.903000
1 posts
🟠 CVE-2026-78795 - High (7.5)
An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:14.037000
1 posts
🟠 CVE-2026-75350 - High (7.5)
EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75350/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:13.893000
1 posts
🟠 CVE-2026-75348 - High (7.5)
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognize...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:03.373000
1 posts
🟠 CVE-2026-107818 - High (8.4)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user wi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107818/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:41:47.060000
1 posts
🟠 CVE-2026-108159 - High (7.5)
AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed promp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108159/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:41:29.727000
1 posts
🟠 CVE-2026-107815 - High (8.5)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyon...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107815/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:33:55
1 posts
🟠 CVE-2026-107826 - High (7.5)
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:29:33.410000
1 posts
🔴 CVE-2026-15340 - Critical (9.8)
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:16:45.853000
1 posts
🟠 CVE-2026-107814 - High (8.4)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107814/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:16:45.730000
1 posts
🟠 CVE-2026-107809 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not univ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107809/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:08:21
1 posts
🟠 CVE-2026-107812 - High (7.5)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107812/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:08:16
1 posts
🟠 CVE-2026-107808 - High (8.1)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:08:07
1 posts
🟠 CVE-2026-107813 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:07:11
1 posts
🟠 CVE-2026-107807 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Nod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:07:06
1 posts
🟠 CVE-2026-107810 - High (8.1)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx config...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107810/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:06:17.770000
1 posts
🟠 CVE-2026-108106 - High (7.5)
Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:41:53.540000
1 posts
Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.
##updated 2026-10-09T16:38:57.820000
1 posts
🟠 CVE-2026-107811 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:37:27
1 posts
🟠 CVE-2026-55797 - High (8.8)
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55797/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:33:39.007000
1 posts
Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.
#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412
##updated 2026-10-09T16:17:32.090000
1 posts
CVE-2026-93947: CRITICAL SQL Injection in Shinetheme Traveler (0 – 3.2.9). Blind SQLi risk — attackers may access sensitive DB data. Patch when available & monitor your systems. https://radar.offseq.com/threat/cve-2026-93947-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-in-e7412128f2cf3852 #OffSeq #CVE202693947 #SQLInjection #InfoSec
##updated 2026-10-09T16:17:22.297000
1 posts
🟠 CVE-2026-107375 - High (8.8)
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107375/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:17:21.427000
1 posts
🟠 CVE-2026-105436 - High (8.8)
Deserialization of Untrusted Data vulnerability in MainWP MainWP Child mainwp-child allows Object Injection.This issue affects MainWP Child: from n/a through 6.2.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105436/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:17:18.210000
2 posts
18 repos
https://github.com/JoseLRC97/ProFTPd-1.3.5-mod_copy-Remote-Command-Execution
https://github.com/xyk0x/cpx_proftpd
https://github.com/cd6629/CVE-2015-3306-Python-PoC
https://github.com/nootropics/propane
https://github.com/davidtavarez/CVE-2015-3306
https://github.com/cved-sources/cve-2015-3306
https://github.com/cybersensei-EH/hackviser_labs_CVE-2015-3306
https://github.com/0xm4ud/ProFTPD_CVE-2015-3306
https://github.com/diegslva/cve-2015-3306-lab
https://github.com/cdedmondson/Modified-CVE-2015-3306-Exploit
https://github.com/Z3R0space/CVE-2015-3306
https://github.com/t0kx/exploit-CVE-2015-3306
https://github.com/canpilayda/proftpd-mod_copy-cve-2015-3306
https://github.com/bcononugbor-source/OpenVAS-Vulnerability-Analysis-Incident-Response-Report
https://github.com/donmedfor/CVE-2015-3306
https://github.com/netw0rk7/CVE-2015-3306-Home-Lab
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2015-3306
Vendor: ProFTPD
Product: ProFTPD
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-3306
updated 2026-10-09T15:32:29
2 posts
HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##🔴 CVE-2026-79842 - Critical (9.1)
An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:42
1 posts
🟠 CVE-2026-39460 - High (8.1)
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device thro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:38
1 posts
🟠 CVE-2026-108101 - High (7.5)
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108101/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:37
1 posts
Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.
##updated 2026-10-09T15:31:35
1 posts
🟠 CVE-2026-28745 - High (7.5)
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:35
1 posts
🟠 CVE-2026-39453 - High (8.3)
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39453/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:35
1 posts
🟠 CVE-2026-33367 - High (8.1)
SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33367/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:34
1 posts
🔴 CVE-2026-108107 - Critical (9.8)
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid par...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:34
1 posts
🔴 CVE-2026-108109 - Critical (9.1)
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108109/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:32
1 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
updated 2026-10-09T15:31:30
1 posts
CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. https://radar.offseq.com/threat/cve-2026-86405-cwe-347-improper-verification-of-cryptographic-signature-in-sipay-electronic-money-and-d1d195a6023ad286 #OffSeq #CVE #vuln #cybersecurity
##updated 2026-10-09T15:31:27
9 posts
3 repos
https://github.com/ApexBreach/CVE-2026-107406-Poc
https://github.com/techupdate24/citrix-netscaler-rce-cve-2026-107406
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. https://www.theregister.com/security/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch/5302212
##https://thecybersecguru.com/uncategorized/citrix-netscaler-cve-2026-107406-rce/
##Citrix emitiu um aviso urgente para corrigir uma vulnerabilidade crítica nas soluções de rede NetScaler ADC e plataformas de acesso remoto NetScaler Gateway. A falha, identificada como CVE-2026-107406, permite a execução remota de código arbitrário ou negação de serviço. 🚨
##Citrix NetScaler instances with SAML enabled are affected by CVE-2026-107406, which can cause remote code execution and crash. Exposed ADC and Gateway systems risk takeover or service disruption, so patching and log review for malicious SAML requests is critical. #NetScaler #Citrix #PatchManagement
https://cyberworldops.eu/en/netscaler-saml-deployments-face-rce-and-crash-risk-from-cve-2026
##Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.
#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability
##I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:
CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
https://support.citrix.com/external/article/CTX697191
https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406
Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.
##@GossiTheDog https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
They did it again :D
##I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.
https://ifin.network/t/cve-2026-107406-somehow-another-citrix-netscaler-saml-vulnerability/891
##updated 2026-10-09T12:31:48
1 posts
1 repos
PX-lab Zombify ≤1.7.7 is affected by CVE-2026-94503 (CRITICAL, CVSS 10): unrestricted upload of dangerous files enables remote code execution. No patch yet — restrict uploads & monitor for updates. https://radar.offseq.com/threat/cve-2026-94503-unrestricted-upload-of-file-with-dangerous-type-in-px-lab-zombify-8e6fe0b08d444b23 #OffSeq #CVE202694503 #WebSecurity #Infosec
##updated 2026-10-09T04:18:09.937000
1 posts
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
##updated 2026-10-09T04:18:05.817000
1 posts
🟠 CVE-2026-14497 - High (8.1)
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote authenticated attacker to bypass security restrictions due to improper verification of cryptogr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14497/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. https://radar.offseq.com/threat/cve-2026-69435-cwe-918-server-side-request-forgery-ssrf-in-microsoft-azure-sre-agent-10f6e62769899cfe #OffSeq #Azure #SSRF #Infosec
##updated 2026-10-09T00:31:56
1 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
updated 2026-10-09T00:31:56
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. https://radar.offseq.com/threat/cve-2026-77900-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-app-service-for-806c7a8fa62ffe41 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity
##updated 2026-10-09T00:31:56
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! https://radar.offseq.com/threat/cve-2026-88131-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-dataverse-eba5097c3e4671bb #OffSeq #CVE202688131 #Microsoft #RCE #Infosec
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84057 - High (8.1)
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84035 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84875 - High (7.5)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84875/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-89091 - High (8.8)
A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89091/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:35:53.890000
1 posts
🟠 CVE-2026-107701 - High (8.2)
dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107701/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:35:53.890000
1 posts
1 repos
🔴 CVE-2026-9209 - Critical (9.8)
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9209/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🟠 CVE-2026-19482 - High (8.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-19491 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🟠 CVE-2026-19493 - High (7.5)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19493/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-78401 - Critical (9.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78401/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🟠 CVE-2026-17189 - High (8.2)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus alt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🔴 CVE-2026-16916 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16916/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🟠 CVE-2026-19494 - High (8.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:34
1 posts
🟠 CVE-2026-84275 - High (7.5)
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this vulnerability to write arbitrary files to the Collector.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84275/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:34
1 posts
🔴 CVE-2026-107704 - Critical (9.8)
The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabled. Atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107704/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
1 repos
🟠 CVE-2026-11318 - High (7.8)
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
🔴 CVE-2026-107703 - Critical (9.8)
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107703/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
🔴 CVE-2026-107699 - Critical (9.8)
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:33
1 posts
🔴 CVE-2026-107700 - Critical (9.8)
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107700/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:32
1 posts
🟠 CVE-2026-107782 - High (7.8)
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Micr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107782/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:28
1 posts
🔴 CVE-2026-84244 - Critical (9.3)
IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84244/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:26
1 posts
🟠 CVE-2026-84276 - High (7.5)
IBM Guardium Data Protection 12.2.2 is affected by a denial-of-service vulnerability in the edge-controller. An unauthenticated remote attacker with network access to the edge-controller gRPC service can provide malformed task data that triggers a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84276/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:23
1 posts
🔴 CVE-2026-95210 - Critical (9.1)
Improper certificate validation in gnutls v3.8.13 causes the application to accept certificates containing invalid extensions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-95210/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:27:15.010000
1 posts
🔴 CVE-2026-107779 - Critical (9.8)
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107779/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:03:43.847000
1 posts
🟠 CVE-2026-107333 - High (8.1)
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially forma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:25:00.647000
1 posts
🟠 CVE-2026-107383 - High (7.5)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, the GeoJSON Polygon and MultiPolygon binary encoders size a Buffer.allocUnsafe() allocation fro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107383/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:17:31.590000
1 posts
🟠 CVE-2026-107322 - High (7.8)
An incomplete list of disallowed inputs in Amazon Agent Plugins for AWS databases-on-aws plugin before 1.7.1 might allow a remote unauthenticated actor to execute arbitrary operating system commands on the host running the helper via a crafted dat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
1 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##updated 2026-10-08T19:42:25
1 posts
🟠 CVE-2026-107384 - High (8.1)
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are exp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107384/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T18:32:53
2 posts
8 repos
https://github.com/likekabin/ShareDoc_cve-2015-5477
https://github.com/elceef/tkeypoc
https://github.com/robertdavidgraham/cve-2015-5477
https://github.com/knqyf263/cve-2015-5477
https://github.com/tintinweb/pub
https://github.com/ilanyu/cve-2015-5477
https://github.com/xycloops123/TKEY-remote-DoS-vulnerability-exploit
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2015-5477
Vendor: ISC
Product: BIND
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2015-5477
updated 2026-10-08T18:32:52
2 posts
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2021-3199
Vendor: ONLYOFFICE
Product: Docs
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3199
updated 2026-10-08T18:32:32
1 posts
🟠 CVE-2026-104078 - High (7.8)
Obsidian Desktop before 1.14.0 contains a filter bypass vulnerability in the bundled MathJax 3.2.2 Safe component that allows attackers to execute arbitrary code by embedding a crafted \href value with a TAB byte in the URL scheme, causing filterU...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104078/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T18:32:31
1 posts
🟠 CVE-2026-104077 - High (7.8)
Obsidian Desktop before 1.14.0 contains a remote code execution vulnerability that allows attackers to craft malicious Markdown notes exploiting insufficient sanitization of the data-background-iframe attribute, which bypasses DOMPurify and is pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104077/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:58:02
1 posts
🟠 CVE-2026-107377 - High (7.5)
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_mi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107377/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:40:32
1 posts
🟠 CVE-2026-107303 - High (7.6)
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107303/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:40:11
1 posts
🟠 CVE-2026-107302 - High (7.5)
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore caus...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107302/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:40:07
1 posts
🟠 CVE-2026-107300 - High (7.5)
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder recursively invokes itself for each complete MessagePack value remaining in a chunk. A remote peer can send one chunk containing many small ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T17:16:37
1 posts
🟠 CVE-2026-107295 - High (7.6)
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A webs...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107295/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:15
1 posts
🟠 CVE-2026-93017 - High (7.7)
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster.
...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93017/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:11
1 posts
🔴 CVE-2026-14992 - Critical (9.8)
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 vulnerable to buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14992/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:10
1 posts
🔴 CVE-2026-14502 - Critical (9.8)
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during LDAP a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14502/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T15:33:05
1 posts
IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.
#IBM #DataPower #APIGateway #CVE202615762 #CVE202616340 #CVE202614990 #RCE #Vulnerability
##updated 2026-10-07T18:33:12
4 posts
Max severity SonicWall SMA1000 flaw now exploited in attacks
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days...
🔗️ [Bleepingcomputer] https://link.is.it/pvDc7j
##Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/
##Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.
##SonicWall Patches Critical Pre-Auth SSRF in SMA 1000 Series Appliances
SonicWall patched four vulnerabilities in its SMA 1000 series appliances, including a critical pre-authentication SSRF (CVE-2026-102255) with a CVSS score of 10.0. The flaws allow unauthenticated attackers to access internal services and authenticated users to execute arbitrary code.
**If you use SonicWall SMA 1000 series appliances (SMA 6210, SMA 7210 or SMA 8200v), update them ASAP to firmware 12.4.3-03670 or 12.5.0-03082 or newer. Make sure the management console is reachable only from trusted internal networks, and check the appliance logs for unusual activity, since these gateways are a favorite entry point for ransomware groups.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/sonicwall-patches-critical-pre-auth-ssrf-in-sma-1000-series-appliances-5-j-n-v-v/gD2P6Ple2L
updated 2026-10-07T18:32:21
1 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##updated 2026-10-07T18:32:20
1 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##updated 2026-10-07T18:32:20
1 posts
Two more Cisco advisories today addressing critical vulnerabilities:
- CVE-2026-76471: Cisco NX-OS Software NX-API Remote Code Execution Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
- CVE-2026-76463, CVE-2026-76464, and CVE-2026-76467: Cisco Meraki Security Hardening Release: October 2026 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH @TalosSecurity #infosec #Cisco #vulnerability
##updated 2026-10-07T18:32:14
1 posts
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
https://isc.sans.edu/podcastdetail/10130
updated 2026-10-07T15:32:07
7 posts
1 repos
⚠️ Un clic en un enllaç extern podia acabar amb el segrest de Telegram Desktop: una fallada IPC permetia llegir i exfiltrar fitxers locals. CVE-2026-107181; corregida a 7.2.9. Actualitza. #Telegram #Ciberseguretat https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
##🚨 TELEGRAM DESKTOP: ONE CLICK. FULL ACCOUNT TAKEOVER.
Full technical breakdown 👉 https://thecybersecguru.com/exploits/telegram-desktop-cve-2026-107181/
A critical flaw, CVE-2026-107181, reportedly chains IPC injection with local session file theft to let attackers hijack Telegram accounts through a malicious link.
⚠️ No traditional malware installer. Just one click.
🔴 IPC command injection
🔴 Local file theft
🔴 Session hijacking
🔴 Account takeover
The article reports that Telegram Desktop 7.2.9 fixes the flaw. Update now, set a local passcode, and review auto-download settings.
CC @durov
##https://thecybersecguru.com/exploits/telegram-desktop-cve-2026-107181/
##⚠️ Un clic en un enllaç extern podia acabar amb el segrest de Telegram Desktop: una fallada IPC permetia llegir i exfiltrar fitxers locals. CVE-2026-107181; corregida a 7.2.9. Actualitza. #Telegram #Ciberseguretat https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
##https://thecybersecguru.com/exploits/telegram-desktop-cve-2026-107181/
##🚨 PoC released for Telegram Desktop account takeover vulnerability; CVE-2026-107181
https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
A vulnerability in Telegram Desktop allows attackers to steal local files, including session keys, by tricking users into opening a specially crafted tg:// link.
Stolen session data could allow attackers to hijack Telegram accounts without knowing the victim's password.
CVSS: 8.1 (High, v3.1) / 8.6 (High, v4.0)
Affected: Telegram Desktop before 7.2.9
Fixed: Version 7.2.9
The published PoC demonstrates how a malicious link can trigger file exfiltration through Telegram's IPC handler.
##A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.
#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC
##updated 2026-10-07T13:17:22.273000
4 posts
12 repos
https://github.com/gotr00t0day/CVE-2026-21589
https://github.com/BimBoxH4/CVE-2026-21589
https://github.com/murrez/CVE-2026-21589
https://github.com/webserverdude/f5_CVE-2026-21589_mitigation
https://github.com/rxsklife/CVE-2026-21589
https://github.com/renzi25031469/CVE-2026-21589
https://github.com/MarcusProgram/CVE-2026-21589
https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit
https://github.com/aduli198/CVE-2026-21589
https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589
Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.
##You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
##CVE-2026-21589 kritikus arbitrary file access hiba érinti több Atlassian Data Center terméket (Jira, Confluence, Bitbucket) és bejelentkezés nélkül hozzáférhetők lehetnek fájlok. Van internetre kitett példányod, ami veszélyben lehet, aggódsz? A végleges megoldás a frissítés; ideiglenes WAF/Tomcat RewriteValve mitigációk lehetségesek.
https://linuxmint.hu/hir/2026/10/kritikus-fajleleresi-hiba-az-atlassian-data-center-termekekben
#Atlassian #CVE202621589 #Jira #Confluence #Bitbucket #DataCenter #WAF #Tomcat #kiberbiztonság #infosec
##Oh, Atlassian, never change! 😭
"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"
CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".
APT /../../../../../../etc/passwd strikes again.
##updated 2026-10-07T12:31:58
1 posts
1 repos
Explore the critical LMCache vulnerability CVE-2026-105192. Learn how insecure ZeroMQ configurations and Python pickle deserialization lead to RCE attacks.
##updated 2026-10-07T09:32:29
2 posts
🏆 New Achievement! The Keys to the Vault Were Under the Mat!
Magnificent. Truly, someone looked at a backup server — the one room that holds the skeleton keys to your entire infrastructure — and said, let's let low-privileged users knock it over. CVE-2025-64393 is a critical remote code execution flaw in Veeam Backup & Replication version 12, and it hands full control of the backup server to anyone with the Backup Viewer role. (1/3)
##Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software
Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.
**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-remote-code-execution-flaw-in-backup-replication-software-9-s-8-u-1/gD2P6Ple2L
updated 2026-10-07T06:33:08
2 posts
1 repos
CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution
#CVE_2026_59346
https://socprime.com/blog/cve-2026-59346-analysis/
https://thecybersecguru.com/exploits/cve-2026-59346-vmware-vmxnet3-poc/
##updated 2026-10-06T15:15:48.310000
1 posts
HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##updated 2026-10-06T15:04:52.637000
5 posts
1 repos
⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…
🤖 AI generated summary
##⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…
🤖 AI generated summary
##Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec
https://cyberworldops.eu/en/huntress-ahsaycbs-bugs-cve-2026-105133-and-cve-2026-105134-exploited
##Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:
##Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.
Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers
Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.
**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-chain-ahsaycbs-vulnerabilities-to-deploy-webshells-and-cryptominers-o-j-b-o-b/gD2P6Ple2L
updated 2026-10-04T09:30:21
5 posts
⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…
🤖 AI generated summary
##⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…
🤖 AI generated summary
##Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec
https://cyberworldops.eu/en/huntress-ahsaycbs-bugs-cve-2026-105133-and-cve-2026-105134-exploited
##Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:
##Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.
Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers
Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.
**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-chain-ahsaycbs-vulnerabilities-to-deploy-webshells-and-cryptominers-o-j-b-o-b/gD2P6Ple2L
updated 2026-10-01T18:33:43
1 posts
CVE-2026-88467: CRMEB Knowledge-Paid System 1.4.4 leaks sensitive info via a backend verification flaw. CVSS 6.2, no patch yet. Restrict access and monitor. Details: https://www.valtersit.com/cve/CVE-2026-88467/ #CVE #infosec #CRMEB
##updated 2026-10-01T18:17:18.153000
1 posts
5 repos
https://github.com/eris-ths/supply-chain-guard
https://github.com/xtremebeing/starlette-host-header-lab
https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
We have published our writeup about the discovery and details of the #BadHost vulnerability (CVE-2026-48710) at https://x41-dsec.de/lab/research/2026/10/07/badhost/
##updated 2026-09-28T21:17:17.733000
1 posts
CVE-2026-46649: Joplin Server pre-3.7.2 SSO code endpoint skips brute-force limits, letting unauthenticated attackers guess 9-digit codes and steal session tokens for full note access. CVSS 9.1. Patch under review - restrict https://www.valtersit.com/cve/CVE-2026-46649/ #CVE #infosec #Joplin
##updated 2026-09-28T12:32:08
3 posts
14 repos
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
https://github.com/SwiftSecur/CVE-2026-88771-HuntScript
https://github.com/EXEcution-py/CVE-2026-88771-POC
https://github.com/technion/netscaler_scanner
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script
https://github.com/watchtowrlabs/citrix-netscaler-cve-2026-88771-iocs
https://github.com/LETHAL-FORENSICS/Get-NetScalerTimeline
https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce
https://github.com/emilstahl/pitscaler
https://github.com/grupooruss/netscaler-defensive-checker
https://github.com/securekomodo/citrixInspector
https://github.com/craigsblackie/cve-2026-88771-netscaler
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.
#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN
##@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.
Visualization (empty so far):
##Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.
Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.
##updated 2026-09-28T12:26:47.670000
1 posts
8 repos
https://github.com/murrez/CVE-2026-88772
https://github.com/FollowerSeize/CVE-2026-88772-POC
https://github.com/technion/netscaler_scanner
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/emilstahl/pitscaler
https://github.com/securekomodo/citrixInspector
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.
#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN
##updated 2026-09-24T09:32:00
3 posts
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
##updated 2026-09-22T15:33:37
1 posts
CVE-2026-88404: RCE in Univer v1.0.0-alpha.2 via UniscriptExecutionService.execute(). CVSS 9.8, unpatched. Patch now.
https://www.valtersit.com/cve/CVE-2026-88404/
#CVE #infosec #cybersecurity
updated 2026-09-22T15:33:36
1 posts
CVE-2026-88402 NocoBase v2.1.21 SQL injection in checkSQL, CVSS 9.8, unpatched. Crafted SQL exposes sensitive database data. Patch status unknown, so restrict exposure now. https://www.valtersit.com/cve/CVE-2026-88402/ #CVE #infosec
##updated 2026-09-22T14:43:27
1 posts
CVE-2026-61647: Path traversal in NotebookLM MCP 1.6.0-2.0.2 lets attacker-controlled vault_dir write files anywhere on disk via POST /batch-to-vault. CVSS 9.1. Patch under review, so restrict endpoint access now. https://www.valtersit.com/cve/CVE-2026-61647/ #CVE #infosec #cybersecurity
##updated 2026-09-21T21:32:01
1 posts
CVE-2026-94571: OpenStack Octavia before 18.0.1 lets an authenticated load balancer owner inject newlines via redirect_url, writing arbitrary HAProxy directives on the amphora. CVSS 8.8. Patch under review. Track it: https://www.valtersit.com/cve/CVE-2026-94571/ #CVE #infosec #OpenStack
##updated 2026-09-21T18:32:14
1 posts
CVE-2026-92382: OOB write in usbredir. A peer can write past the packet descriptor array. CVSS 4.1, no patch yet. Audit your usbredir exposure now.
https://www.valtersit.com/cve/CVE-2026-92382/
#CVE #infosec #cybersecurity
updated 2026-09-21T13:17:11.283000
1 posts
2 repos
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
New.
Picus: How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491 https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491 #infosec #vulnerability #Chrome #Google #threatresearch
##updated 2026-09-18T06:32:17
1 posts
4 repos
https://github.com/686f6c61/POC-WP-CORE-CVE-2026-93485
https://github.com/DeathShotXD/Comment2Shell
Ataki na strony WordPress chwilę po wydaniu poprawki
17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...
#WBiegu #Podatność #Rce #Wordpress
https://sekurak.pl/ataki-na-strony-wordpress-chwile-po-wydaniu-poprawki/
##updated 2026-09-14T00:16:56.777000
3 posts
2 repos
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
##updated 2026-09-10T06:31:55
1 posts
Palo Alto has a a long list of advisories, addressing at least two critical vulnerabilities, among others: https://security.paloaltonetworks.com/
CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310
CRITICAL: PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) https://security.paloaltonetworks.com/PAN-SA-2026-0012
- Tenable Research Advisories:
HIGH: Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion https://www.tenable.com/security/research/tra-2026-65
There are also two WordPress vulnerabilities and a few others here https://www.tenable.com/security/research #WorPress
- Microsoft:
In case you missed this, Microsoft posted quite a few patches yesterday https://msrc.microsoft.com/update-guide #infosec #vulnerability #Microsofot #Azure #Linux
##updated 2026-09-09T00:31:34
1 posts
Discover the details of the Windows Cloud Files Driver vulnerability, CVE-2026-80093. Learn how this flaw in cldflt.sys affects kernel privileges.
#WindowsSecurity #CVE202680093 #CyberSecurity #Microsoft #TechNews
##updated 2026-09-08T09:36:36
1 posts
100 repos
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/st4rburn/public-passwd
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/st4rburn/RootRemover
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/pedromizz/copy-fail
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/pyroceper/copy-fail-CVE-2026-31431
https://github.com/Smarttfoxx/copyfail
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/sudoytang/copyfail-arm64
https://github.com/tgies/copy-fail-c
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/badsectorlabs/copyfail-go
https://github.com/malwarekid/CVE-2026-31431
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
https://github.com/cyber-joker/copy-fail-python
https://github.com/wesmar/CVE-2026-31431
https://github.com/0xShe/CVE-2026-31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/cozystack/copy-fail-blocker
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/b5null/CVE-2026-31431-C
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/sgkdev/page_inject
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/xeloxa/copyfail-exploit
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/desultory/CVE-2026-31431
https://github.com/povzayd/CVE-2026-31431
https://github.com/samanzamani/copy-fail-checker
https://github.com/atgreen/block-copyfail
https://github.com/rootsecdev/cve_2026_31431
https://github.com/M4xSec/CVE-2026-31431-RCE-Exploit
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/mrunalp/block-copyfail
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/TrevoCastles/CVE-2026-31431-copy-fail
https://github.com/cs8425/copy-fail-go
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/ZeroDayEvil/CVE-2026-31431
https://github.com/sammwyy/copyfail-rs
https://github.com/rvzsec/CVE-2026-31431
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/Boos4721/copyfail-rs
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/nisec-eric/cve-2026-31431
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/diemoeve/copyfail-rs
https://github.com/wgnet/wg.copyfail.patch
https://github.com/Huchangzhi/autorootlinux
https://github.com/luotian2/CVE-2026-31431
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/Juguitos/copy-fail
This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path
##updated 2026-09-06T03:30:24
1 posts
8 repos
https://github.com/SneakyNachos/CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm
https://github.com/HORKimhab/CVE-2026-85046
https://github.com/SneakyNachos/CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter
https://github.com/Eliot-code/CVE-2026-85046
https://github.com/adriyansyah-mf/cve-2026-85046-poc
New.
Picus: How BlueMoon Exploits Chrome CVE-2026-85046 and CVE-2026-87491 https://www.picussecurity.com/resource/blog/how-bluemoon-exploits-chrome-cve-2026-85046-and-cve-2026-87491 #infosec #vulnerability #Chrome #Google #threatresearch
##updated 2026-08-31T21:31:56
3 posts
2 repos
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
##updated 2026-08-21T18:34:48
1 posts
10 repos
https://github.com/dahnutz/zimbra-cve-2026-73570-ir
https://github.com/HORKimhab/CVE-2026-73570
https://github.com/alsyundawy/eradicate-zimbra-malware
https://github.com/gabrielunknown/CVE-2026-73570
https://github.com/INFOKOM-KI/Zimbra-CVE-2026-73570-Rules
https://github.com/BiuTrap/CVE-2026-73570
https://github.com/0xBlackash/CVE-2026-73570
https://github.com/jishino567/CVE-2026-73570
----------------
🎯 Threat Intelligence
===================
Microsoft Threat Intelligence tracks CVE-2026-73570: unauthenticated command injection on internet-facing Zimbra mail servers
Microsoft Threat Intelligence published an analysis of CVE-2026-73570, described as an unauthenticated command injection vulnerability exploited in Zimbra on internet-facing mail servers. The post documents observed attack paths, detection opportunities, and mitigation guidance. The digest available here is thin, so this write-up keeps what the source states separate from general class context and flags everything the digest does not state.
🔹 Executive Summary
• CVE-2026-73570 is an unauthenticated command injection vulnerability in Zimbra.
• Exploitation observed in the wild, per Microsoft Threat Intelligence.
• Exposure model: internet-facing mail servers, no authentication required.
• The same post carries detection opportunities and mitigation guidance.
🔹 Technical Details
What the source states:
• Vulnerability class: command injection
• Authentication: none (pre-auth)
• Exposure: internet-facing mail servers
• Affected product: Zimbra
• Publisher and date: Microsoft Threat Intelligence, September 30, roughly a 20-minute read
Not stated in the digest: affected versions, CVSS score, CWE mapping, specific IOCs, named actor, ATT&CK mappings. Treat all of that as unconfirmed until the full post is read.
🔹 Analysis
Class context, not a source claim: pre-auth command injection on an internet-facing mail server is close to the worst property combination a CVE can carry. No credential barrier, no user interaction, and the target sits on the public edge. Mail hosts also concentrate mailbox contents, credentials in authentication flows, and internal trust relationships, which makes a pre-auth path on the edge a practical pivot for follow-on activity. Zimbra has a history as a target of mass exploitation campaigns on earlier CVEs; that is general background relevant to prioritization, not a claim from the current post.
🔹 Attack Chain Analysis
Only the entry step is confirmed by the digest:
1. Initial Access: unauthenticated exploitation of CVE-2026-73570 against an internet-facing Zimbra instance.
2. Post-exploitation: the original post describes observed attack paths, but the digest does not enumerate stages beyond initial access. Do not assume a specific chain from this summary.
🔹 Detection
The source says the post includes detection opportunities, but the digest does not contain the actual queries. Reasonable starting hypotheses for a command injection scenario on a mail host: unexpected process spawns from mail service modules, unusual outbound connections originating from the mail server itself, and anomalous request patterns in web access logs aimed at service and admin endpoints. Treat these as hypotheses to validate against the full post, not verified signatures.
🔹 Mitigation
• The post publishes specific mitigation guidance, so apply it from the source directly.
• Interim hygiene: confirm patch status on every internet-facing Zimbra instance, trim unnecessary internet exposure, and test the detection hypotheses above against existing logs.
🔹 Source Note
The feed item also carried the headline "3 lessons from frontier AI vulnerability research" with no body content, so it is not covered here.
🔹 References
• Microsoft Threat Intelligence post: "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570", September 30
• CVE-2026-73570
🔹 CVE202673570 #Zimbra #ThreatIntelligence #CommandInjection #MailServers
##updated 2026-07-28T18:33:11
1 posts
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
##updated 2026-06-17T09:10:00.550000
1 posts
4 repos
https://github.com/serundengsapi/CVE-2025-31200-iOS-AudioConverter-RCE
https://github.com/hunters-sec/CVE-2025-31200
https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201
https://github.com/zhuowei/apple-positional-audio-codec-invalid-header
iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword
https://cyberworldops.eu/en/p7-darksword-ios-variant-steals-crypto-wallets-and-accepts-remote
##updated 2025-11-13T21:31:15
1 posts
3 repos
https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
https://github.com/The-Maxu/CVE-2025-24201-WebKit-Vulnerability-Detector-PoC-
https://github.com/5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201
iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword
https://cyberworldops.eu/en/p7-darksword-ios-variant-steals-crypto-wallets-and-accepts-remote
##updated 2025-10-24T18:32:04
1 posts
@briankrebs Every Flock CVE in existence (CVE-2025-47818 through -47824) came through MITRE off Jon Gaines' 2025 research, before Flock had any say in the numbering. The "outside parties requesting CVE IDs before a fix is ready" line reads like a reference to that.
As for who decides what's a bug, they've answered in writing. The new VDP gives Flock 120 days to publish, with an exception for anything it deems a "material safety risk to law enforcement or the public." Their advisories page lists nothing, two weeks after a pentest write-up with 2 criticals and 7 highs that Flock says needed no customer action, which is exactly the kind of finding a vendor CNA can decline to number. So yes, Flock decides now. The criteria just live on a legal page instead of a press release.
##updated 2024-03-29T18:30:50
1 posts
90 repos
https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094
https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094
https://github.com/x-cmd-build/xz
https://github.com/Horizon-Software-Development/CVE-2024-3094
https://github.com/robertdebock/ansible-role-cve_2024_3094
https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector
https://github.com/lockness-Ko/xz-vulnerable-honeypot
https://github.com/badsectorlabs/ludus_xz_backdoor
https://github.com/jfrog/cve-2024-3094-tools
https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer
https://github.com/nnatsopoulos/xz-backdoor-research
https://github.com/zpxlz/CVE-2024-3094
https://github.com/mightysai1997/CVE-2024-3094-info
https://github.com/bsekercioglu/cve2024-3094-Checker
https://github.com/neuralinhibitor/xzwhy
https://github.com/dah4k/CVE-2024-3094
https://github.com/wgetnz/CVE-2024-3094-check
https://github.com/Michel-DV/xz-utils-backdoor-case-study
https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project
https://github.com/0xlane/xz-cve-2024-3094
https://github.com/galacticquest/cve-2024-3094-detect
https://github.com/bioless/xz_cve-2024-3094_detection
https://github.com/ElinaNotElina/cve-2024-3094-analysis
https://github.com/gustavorobertux/CVE-2024-3094
https://github.com/extracoding-dozen/CVE-2024-3094
https://github.com/stevehenderson/lab_xz_backdoor
https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check
https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public
https://github.com/Yuma-Tsushima07/CVE-2024-3094
https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script
https://github.com/hazemkya/CVE-2024-3094-checker
https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-
https://github.com/Ava-Vispilio/CVE-2024-3094
https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker
https://github.com/mightysai1997/CVE-2024-3094
https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094
https://github.com/emirkmo/xz-backdoor-github
https://github.com/hackingetico21/revisaxzutils
https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check
https://github.com/M1lo25/CS50FinalProject
https://github.com/isuruwa/CVE-2024-3094
https://github.com/mrk336/CVE-2024-3094
https://github.com/24Owais/threat-intel-cve-2024-3094
https://github.com/pentestfunctions/CVE-2024-3094
https://github.com/HackerHermanos/CVE-2024-3094_xz_check
https://github.com/shefirot/CVE-2024-3094
https://github.com/KaminaDuck/ansible-CVE-2024-3094
https://github.com/ScrimForever/CVE-2024-3094
https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione
https://github.com/harekrishnarai/xz-utils-vuln-checker
https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker
https://github.com/mesutgungor/xz-backdoor-vulnerability
https://github.com/ThomRgn/xzutils_backdoor_obfuscation
https://github.com/teyhouse/CVE-2024-3094
https://github.com/amlweems/xzbot
https://github.com/Mustafa1986/CVE-2024-3094
https://github.com/buluma/ansible-role-cve_2024_3094
https://github.com/robertdebock/ansible-playbook-cve-2024-3094
https://github.com/0xBlackash/CVE-2024-3094
https://github.com/Simplifi-ED/CVE-2024-3094-patcher
https://github.com/brinhosa/CVE-2024-3094-One-Liner
https://github.com/weltregie/liblzma-scan
https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094
https://github.com/encikayelwhitehat-glitch/CVE-2024-3094
https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container
https://github.com/ykhurshudyan-blip/CVE-2024-3094
https://github.com/mhicairo-hue/cs50-cybersecurity-final-project
https://github.com/Ikram124/CVE-2024-3094-analysis
https://github.com/Fractal-Tess/CVE-2024-3094
https://github.com/byinarie/CVE-2024-3094-info
https://github.com/Dermot-lab/TryHack
https://github.com/vnchk1/sec_review_cve-2024-3094
https://github.com/iheb2b/CVE-2024-3094-Checker
https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094
https://github.com/przemoc/xz-backdoor-links
https://github.com/BOSE122/CVE-2024-3094
https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits
https://github.com/FabioBaroni/CVE-2024-3094-checker
https://github.com/felipecosta09/cve-2024-3094
https://github.com/ashwani95/CVE-2024-3094
https://github.com/r0binak/xzk8s
https://github.com/robertdfrench/ifuncd-up
https://github.com/ackemed/detectar_cve-2024-3094
https://github.com/h3raklez/CVE-2024-3094
https://github.com/Juul/xz-backdoor-scan
https://github.com/valeriot30/cve-2024-3094
https://github.com/been22426/CVE-2024-3094
An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and found 11 had only one or two in the past year. xz, which shipped a backdoor in 2024 (CVE-2024-3094), again has one: Lasse Collin wrote 97 percent of its 2025 changes, and the analysis found no new funding. Eight projects, including SQLite, zlib and bash, show no grant from four named funders.
https://linuxstans.com/11-of-23-core-open-source-projects-run-on-1-or-2-people/
##updated 2023-11-07T05:05:45
2 posts
2 repos
🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2023-22894
Vendor: Strapi
Product: Strapi
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2023-22894
updated 2023-11-01T19:47:30
6 posts
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability
A strategic C-Suite threat brief covering CVE-2016-3081 Apache Struts command injection vulnerability, featuring active mitigation, asset inventory management, and endpoint hardening....
##(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability
Unpack CVE-2016-3081 with our technical TSUITE brief. Get advanced detection rules, Splunk SPL, KQL, and forensic triage priorities for active CISA KEV threats....
##(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability
A strategic C-Suite threat brief covering CVE-2016-3081 Apache Struts command injection vulnerability, featuring active mitigation, asset inventory management, and endpoint hardening....
##(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability
Unpack CVE-2016-3081 with our technical TSUITE brief. Get advanced detection rules, Splunk SPL, KQL, and forensic triage priorities for active CISA KEV threats....
##🚨 [CISA-2026:1008] CISA Adds 5 Known Exploited Vulnerabilities to Catalog (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:1008)
CISA has added 5 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.
⚠️ CVE-2015-3306 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-3306)
- Name: ProFTPD Improper Access Control Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ProFTPD
- Product: ProFTPD
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: http://www.proftpd.org/ ; https://lists.debian.org/debian-security-announce/2015/msg00154.html ; https://lists.opensuse.org/archives/list/updates@lists.opensuse.org/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/ ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-3306
⚠️ CVE-2015-5477 (https://secdb.nttzen.cloud/cve/detail/CVE-2015-5477)
- Name: ISC BIND Data Processing Errors Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ISC
- Product: BIND
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://web.archive.org/web/20150729014733/https://kb.isc.org/article/AA-01272 ; https://access.redhat.com/errata/RHSA-2015:1513.html; https://supportportal.juniper.net/s/article/2016-01-Security-Bulletin-Junos-Vulnerability-in-ISC-BIND-named-CVE-2015-5477 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2015-5477
⚠️ CVE-2016-3081 (https://secdb.nttzen.cloud/cve/detail/CVE-2016-3081)
- Name: Apache Struts Command Injection Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Apache
- Product: Struts
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cwiki.apache.org/confluence/display/WW/S2-032 ; ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2016-3081
⚠️ CVE-2021-3199 (https://secdb.nttzen.cloud/cve/detail/CVE-2021-3199)
- Name: ONLYOFFICE Docs Server Path Traversal Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: ONLYOFFICE
- Product: Docs
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: ; https://github.com/ONLYOFFICE/DocumentServer/blob/903fe5ab7a275bd69c3c3346af2d21cf87ebeabf/CHANGELOG.md#563 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-3199
⚠️ CVE-2023-22894 (https://secdb.nttzen.cloud/cve/detail/CVE-2023-22894)
- Name: Strapi Cleartext Storage of Sensitive Information Vulnerability
- Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Known To Be Used in Ransomware Campaigns? Unknown
- Vendor: Strapi
- Product: Strapi
- Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve ; https://github.com/strapi/strapi/releases ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2023-22894
#ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20261008 #cisa20261008 #cve_2015_3306 #cve_2015_5477 #cve_2016_3081 #cve_2021_3199 #cve_2023_22894 #cve20153306 #cve20155477 #cve20163081 #cve20213199 #cve202322894
##CVE ID: CVE-2016-3081
Vendor: Apache
Product: Struts
Date Added: 2026-10-08
CVE URL: https://nvd.nist.gov/vuln/detail/CVE-2016-3081
CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. https://www.valtersit.com/cve/CVE-2026-85219/ #CVE #infosec #cybersecurity
##CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. https://www.valtersit.com/cve/CVE-2026-85219/ #CVE #infosec #cybersecurity
##2 posts
27 repos
https://github.com/Hassham1/CVE-2026-87902
https://github.com/zer0dayf/CVE-2026-87902
https://github.com/langz337/CVE-2026-87902
https://github.com/bhideki/CVE-2026-87902
https://github.com/Lutfifakee-Project/CVE-2026-87902
https://github.com/ynsmroztas/WPSniper
https://github.com/Maalfer/CVE-2026-87902-exploit
https://github.com/SVTagan/WP-CVE-2026-87902
https://github.com/nextco/wordpress-cve-2026-87902
https://github.com/oliveiralimajr/CVE_2026_87902
https://github.com/joaovicdev/EXPLOIT-CVE-2026-87902
https://github.com/MRdark-ops/CVE-2026-87902
https://github.com/dinosn/cve-2026-87902-wordpress-lfi-lab
https://github.com/zyphorixofficialmain-lab/cve-2026-87902
https://github.com/tonydelouvre/CVE-2026-87902
https://github.com/abraxas/CVE-2026-87902
https://github.com/vulpecuna/CVE-2026-87902
https://github.com/xiaxiu555/cve-2026-87902
https://github.com/ressl/cve-2026-87902-poc
https://github.com/itskill-jp/wordpress-upgrade-check
https://github.com/crowsec-edtech/CVE-2026-87902
https://github.com/tc4dy/CVE-2026-87902-Toolkit
https://github.com/abatsakidis/wp-cve-2026-87902-checker
https://github.com/pwnVader/CVE-2026-87902-PoC-pwnVader
https://github.com/rwxrwxs/CVE-2026-87902
https://github.com/HackfutSecRoot/CVE-2026-87902
https://github.com/rabakuku/CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal
Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.
https://linuxmint.hu/hir/2026/10/riasztas-a-wordpress-core-t-erinto-serulekenysegrol
#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság
##Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.
https://linuxmint.hu/hir/2026/10/riasztas-a-wordpress-core-t-erinto-serulekenysegrol
#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság
##CVE-2026-108269 (CRITICAL, CVSS 9.1): Privasys ra-tls-clients <0.5.0 origin validation error lets attackers relay attestation quotes, compromising TLS trust. Upgrade to 0.5.0+ now. https://radar.offseq.com/threat/cve-2026-108269-cwe-346-origin-validation-error-in-privasys-ra-tls-clients-1e6de81a7e6f2eb8 #OffSeq #CVE2026108269 #Rust #Go #TLS
##🔴 CVE-2026-108263 - Critical (9.9)
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107821 - High (8)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107838 - High (7.5)
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107837 - High (8.2)
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107837/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-61746 InvenTree: unauthenticated info disclosure via plugin settings API before 1.4.0. CVSS 5.3. Patch under review - restrict API access now. https://www.valtersit.com/cve/CVE-2026-61746/ #CVE #infosec
##1 posts
10 repos
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
https://github.com/34zY/CVE-2026-72898
https://github.com/VuxNx/CVE-2026-72898
https://github.com/amier-ge/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/Franc-Zar/CVE-2026-72898-safe-detection
https://github.com/4minx/CVE-2026-72898
https://github.com/codeb0ssx/CVE-2026-72898-PoC
直近で相次いでいる国内組織における不正アクセスに関する注意喚起 https://www.jpcert.or.jp/m/at/2026/at260030.html 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)
ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する
🟠 CVE-2026-106433 - High (8.8)
Improper state management in MongoDB libmongocrypt can cause provider-specific data to be treated as an incompatible type when cleaning up a key document containing duplicate masterKey fields. An authenticated actor who can modify key vault docume...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106433/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107376 - High (8.2)
webonyx graphql-php is a PHP implementation of the GraphQL specification. Prior to 15.32.3, GraphQL\Language\Parser performs recursive descent without a recursion limit in parseSelectionSet, parseValueLiteral, and parseTypeReference. A remote atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107376/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-107332 - Insecure default file permissions on cached credentials in AWS Toolkit for Visual Studio Code
Bulletin ID: 2026-129-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 10/08/2026 10:30 PM PDT
Description:
AWS Toolkit for Visual Studio Code is an open source extension that lets developers ...
https://aws.amazon.com/security/security-bulletins/rss/2026-129-aws/
##