##
Updated at UTC 2026-10-11T19:13:51.532679
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-19935 | 7.5 | 0.00% | 2 | 0 | 2026-10-11T18:16:59.410000 | The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) da | |
| CVE-2026-19736 | 7.8 | 0.00% | 2 | 0 | 2026-10-11T18:16:58.810000 | The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed t | |
| CVE-2026-19669 | 7.8 | 0.00% | 2 | 0 | 2026-10-11T18:16:58.563000 | The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_ga | |
| CVE-2026-91136 | 7.5 | 0.56% | 1 | 0 | 2026-10-11T17:17:07.010000 | The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versi | |
| CVE-2026-33367 | 8.1 | 0.29% | 1 | 0 | 2026-10-11T17:17:04.760000 | SNMP can be used to perform administrative actions such as retrieving configurat | |
| CVE-2026-28745 | 7.5 | 0.22% | 1 | 0 | 2026-10-11T17:17:04.303000 | Usernames and passwords, including the default credentials, are stored in the co | |
| CVE-2026-105281 | 7.5 | 0.31% | 1 | 0 | 2026-10-11T17:17:01.723000 | The internal data publisher on openPDC accepts network connections without authe | |
| CVE-2026-104759 | 8.1 | 0.52% | 1 | 0 | 2026-10-11T17:17:00.237000 | The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin | |
| CVE-2026-96341 | 8.2 | 0.28% | 1 | 0 | 2026-10-11T13:17:29.907000 | Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator a | |
| CVE-2026-93944 | 9.8 | 0.31% | 2 | 0 | 2026-10-11T13:17:28.283000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia cameli | |
| CVE-2026-93943 | 9.8 | 0.31% | 1 | 0 | 2026-10-11T13:17:28.180000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex | |
| CVE-2026-93940 | 9.8 | 0.33% | 1 | 0 | 2026-10-11T13:17:27.850000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny | |
| CVE-2026-93937 | 9.8 | 0.33% | 1 | 0 | 2026-10-11T13:17:27.643000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia al | |
| CVE-2026-93934 | 9.8 | 0.31% | 1 | 0 | 2026-10-11T13:17:27.323000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partis | |
| CVE-2026-93932 | 9.8 | 0.31% | 1 | 0 | 2026-10-11T13:17:27.100000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa sma | |
| CVE-2026-93931 | 9.8 | 0.31% | 1 | 0 | 2026-10-11T13:17:26.997000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash al | |
| CVE-2026-62045 | 9.8 | 0.32% | 2 | 0 | 2026-10-11T13:17:24.780000 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers boo | |
| CVE-2026-108753 | 9.4 | 0.00% | 2 | 0 | 2026-10-11T13:17:20.237000 | Agnaistic agnai through 1.0.555 contains a hard-coded credentials vulnerability | |
| CVE-2026-106610 | 9.8 | 0.48% | 2 | 1 | 2026-10-11T13:17:12.430000 | Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verifi | |
| CVE-2026-105892 | 9.8 | 0.42% | 1 | 0 | 2026-10-11T13:17:11.910000 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') v | |
| CVE-2026-104398 | 9.8 | 0.34% | 2 | 0 | 2026-10-11T13:17:11.270000 | Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate M | |
| CVE-2026-103071 | 7.5 | 0.25% | 1 | 0 | 2026-10-11T13:17:10.180000 | Improper Control of Generation of Code ('Code Injection') vulnerability in Villa | |
| CVE-2026-93550 | 4.3 | 0.14% | 2 | 0 | 2026-10-11T12:32:13 | The Veeqo for WooCommerce WordPress plugin through 2.2.8 does not restrict who c | |
| CVE-2026-96227 | 8.8 | 0.17% | 2 | 0 | 2026-10-11T12:32:13 | The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or valid | |
| CVE-2026-86717 | 9.1 | 0.15% | 2 | 0 | 2026-10-11T12:17:24.653000 | The Insurify WordPress plugin through 1.0 does not have authorisation and nonce | |
| CVE-2026-81797 | 9.8 | 0.32% | 1 | 0 | 2026-10-11T12:17:22.500000 | Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordP | |
| CVE-2026-78535 | 9.8 | 0.34% | 1 | 0 | 2026-10-11T12:17:21.310000 | Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions. | |
| CVE-2026-78533 | 9.8 | 0.34% | 1 | 0 | 2026-10-11T12:17:21.103000 | Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions. | |
| CVE-2026-66569 | 9.8 | 0.31% | 1 | 0 | 2026-10-11T12:17:20.693000 | Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions. | |
| CVE-2026-66568 | 9.8 | 0.31% | 1 | 0 | 2026-10-11T12:17:20.590000 | Unauthenticated PHP Object Injection in Original <= 1.9.0 versions. | |
| CVE-2026-108540 | 9.9 | 1.70% | 2 | 0 | 2026-10-11T09:30:32 | A flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknow | |
| CVE-2026-108707 | 9.8 | 0.55% | 2 | 0 | 2026-10-11T03:30:24 | Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit | |
| CVE-2026-78530 | 7.7 | 0.40% | 1 | 0 | 2026-10-10T21:31:28 | Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions. | |
| CVE-2026-78529 | 9.8 | 0.31% | 1 | 0 | 2026-10-10T21:31:28 | Unauthenticated PHP Object Injection in Alliance <= 3.11 versions. | |
| CVE-2026-66566 | 8.1 | 0.28% | 1 | 0 | 2026-10-10T21:31:28 | Unauthenticated Local File Inclusion in Ambient <= 1.7 versions. | |
| CVE-2026-66567 | 9.8 | 0.33% | 1 | 0 | 2026-10-10T21:31:27 | Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions. | |
| CVE-2026-108598 | 9.8 | 0.73% | 1 | 0 | 2026-10-10T21:31:20 | Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE | |
| CVE-2026-106609 | 7.5 | 0.22% | 1 | 0 | 2026-10-10T18:31:27 | Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcas | |
| CVE-2026-105889 | 9.3 | 0.26% | 1 | 0 | 2026-10-10T18:31:27 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-108546 | 7.5 | 0.80% | 1 | 0 | 2026-10-10T15:30:30 | Spotweb through 1.5.8 contains an OS command injection vulnerability in the runc | |
| CVE-2026-105885 | 8.8 | 0.29% | 1 | 0 | 2026-10-10T15:30:29 | Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider- | |
| CVE-2026-108550 | 8.8 | 0.30% | 1 | 0 | 2026-10-10T15:30:24 | SkillHub before 0.2.22 contains an incorrect authorization vulnerability in Acco | |
| CVE-2026-108161 | 7.5 | 1.10% | 1 | 0 | 2026-10-10T15:30:22 | FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_r | |
| CVE-2026-108553 | 7.5 | 0.18% | 1 | 0 | 2026-10-10T15:16:58.410000 | OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in | |
| CVE-2026-108551 | 9.8 | 0.41% | 1 | 0 | 2026-10-10T15:16:58.273000 | openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit | |
| CVE-2026-108549 | 8.1 | 0.45% | 1 | 0 | 2026-10-10T15:16:58.087000 | cc-connect through 1.5.0 contains a missing authentication vulnerability in the | |
| CVE-2026-19494 | 8.1 | 0.29% | 1 | 0 | 2026-10-10T13:17:32.163000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-96662 | 7.5 | 0.39% | 1 | 0 | 2026-10-10T09:30:41 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress | |
| CVE-2026-93936 | 9.8 | 0.33% | 2 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm | |
| CVE-2026-93945 | 9.8 | 0.33% | 3 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance a | |
| CVE-2026-93935 | 9.8 | 0.31% | 2 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play pla | |
| CVE-2026-62046 | 9.8 | 0.32% | 2 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gute | |
| CVE-2026-104803 | 9.8 | 0.45% | 2 | 0 | 2026-10-10T09:30:37 | The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in | |
| CVE-2026-93933 | 9.8 | 0.31% | 1 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosa | |
| CVE-2026-93929 | 9.8 | 0.32% | 1 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia trave | |
| CVE-2026-93942 | 9.8 | 0.31% | 1 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell al | |
| CVE-2026-93941 | 9.8 | 0.33% | 1 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema al | |
| CVE-2026-93938 | 9.8 | 0.33% | 1 | 0 | 2026-10-10T09:30:37 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwo | |
| CVE-2026-93950 | 7.5 | 0.20% | 1 | 0 | 2026-10-10T09:30:37 | Missing Authorization vulnerability in StylemixThemes Motors motors allows Explo | |
| CVE-2026-94538 | 8.1 | 0.25% | 1 | 0 | 2026-10-10T09:30:36 | The WP File Download plugin for WordPress is vulnerable to authorization bypass | |
| CVE-2026-93746 | 7.5 | 0.53% | 1 | 0 | 2026-10-10T09:30:36 | The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping | |
| CVE-2026-93930 | 9.8 | 0.31% | 1 | 0 | 2026-10-10T09:30:36 | Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra | |
| CVE-2026-93927 | 9.8 | 0.32% | 1 | 0 | 2026-10-10T09:30:36 | Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows | |
| CVE-2026-97670 | 9.1 | 0.37% | 1 | 0 | 2026-10-10T06:31:08 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization b | |
| CVE-2026-94589 | 9.8 | 0.66% | 1 | 0 | 2026-10-10T06:31:06 | The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirect | |
| CVE-2026-88131 | 9.8 | 0.84% | 2 | 0 | 2026-10-10T04:18:19.240000 | Deserialization of untrusted data in Microsoft Dataverse allows an unauthorized | |
| CVE-2026-84875 | 7.5 | 0.42% | 1 | 0 | 2026-10-10T04:18:19.087000 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker | |
| CVE-2026-84035 | 8.1 | 0.37% | 1 | 0 | 2026-10-10T04:18:17.220000 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker | |
| CVE-2026-77900 | 9.8 | 0.49% | 2 | 0 | 2026-10-10T04:18:14.030000 | Missing authentication for critical function in Azure App Service allows an unau | |
| CVE-2026-69435 | 9.6 | 0.39% | 2 | 0 | 2026-10-10T04:18:13.347000 | Missing authorization in Azure SRE Agent allows an authorized attacker to elevat | |
| CVE-2026-107406 | 0 | 0.47% | 10 | 4 | 2026-10-10T04:18:09.503000 | Memory overflow vulnerability leading to Remote Code Execution or Denial of Serv | |
| CVE-2026-108474 | 9.8 | 0.32% | 1 | 0 | 2026-10-10T00:17:03.673000 | In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped strin | |
| CVE-2026-108268 | 0 | 0.13% | 1 | 0 | 2026-10-09T22:16:59.643000 | Enclave OS Virtual runs container workloads inside confidential virtual machines | |
| CVE-2026-75351 | 7.5 | 0.40% | 1 | 0 | 2026-10-09T21:31:18 | OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side Et | |
| CVE-2026-75346 | 7.5 | 0.54% | 1 | 0 | 2026-10-09T21:17:05.800000 | An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast | |
| CVE-2026-62376 | 8.1 | 0.21% | 1 | 0 | 2026-10-09T21:17:05.627000 | Vikunja is an open-source self-hosted task management platform. Versions prior t | |
| CVE-2026-57458 | 8.1 | 0.27% | 1 | 0 | 2026-10-09T21:17:05.190000 | Vikunja is an open-source self-hosted task management platform. In version 2.3.0 | |
| CVE-2026-108264 | 9.1 | 0.38% | 1 | 0 | 2026-10-09T21:17:04.703000 | Wizarr is an advanced user invitation and management system for Jellyfin, Plex, | |
| CVE-2026-108263 | 9.9 | 0.43% | 1 | 0 | 2026-10-09T21:17:04.527000 | Astron Agent is an agentic workflow platform for building and running AI agents. | |
| CVE-2026-108259 | 8.2 | 0.25% | 1 | 0 | 2026-10-09T20:56:53 | ### Summary `@tinacms/cli` inserts the raw Git branch value into the generated | |
| CVE-2026-108261 | 9.3 | 0.16% | 1 | 0 | 2026-10-09T20:56:50 | ### Summary The TinaCMS admin builds its preview `<iframe src>` from the `/~/*` | |
| CVE-2026-108260 | 7.6 | 0.21% | 1 | 0 | 2026-10-09T20:56:46 | ### Summary `<tina-markdown>` renders a rich-text AST into the DOM and, for `a` | |
| CVE-2026-107845 | 9.3 | 0.27% | 1 | 0 | 2026-10-09T20:53:52 | An unauthenticated front end visitor can post a comment containing a XSS injecti | |
| CVE-2026-107806 | None | 0.33% | 1 | 1 | 2026-10-09T20:45:03 | ## Summary An authenticated nginx-ui user can call `POST /api/restore`, upload | |
| CVE-2026-107840 | 7.5 | 0.44% | 1 | 0 | 2026-10-09T20:17:09.900000 | yopass is a service for securely sharing secrets, passwords, and files. Prior to | |
| CVE-2026-104084 | 8.8 | 0.25% | 1 | 0 | 2026-10-09T20:17:09.050000 | SmarterMail before build 9777 contains a privilege escalation vulnerability wher | |
| CVE-2026-103412 | 8.8 | 0.52% | 1 | 0 | 2026-10-09T18:32:43 | Improper limitation of a pathname to a restricted directory ('path traversal') v | |
| CVE-2026-75350 | 7.5 | 0.48% | 1 | 0 | 2026-10-09T18:31:52 | EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in | |
| CVE-2026-108113 | 8.8 | 0.64% | 1 | 0 | 2026-10-09T18:31:48 | ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerab | |
| CVE-2026-108160 | 7.5 | 0.15% | 1 | 0 | 2026-10-09T18:31:48 | AstronRPA through 1.1.6 contains a download of code without integrity check vuln | |
| CVE-2026-108159 | 7.5 | 0.33% | 1 | 0 | 2026-10-09T18:31:48 | AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the des | |
| CVE-2026-75345 | 7.5 | 0.45% | 1 | 0 | 2026-10-09T18:31:47 | OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected | |
| CVE-2026-90983 | 8.2 | 0.26% | 1 | 0 | 2026-10-09T18:31:47 | Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. | |
| CVE-2026-78795 | 7.5 | 0.45% | 1 | 0 | 2026-10-09T18:31:42 | An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless route | |
| CVE-2026-75348 | 7.5 | 0.51% | 1 | 0 | 2026-10-09T18:17:13.893000 | An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and mast | |
| CVE-2026-108157 | 8.1 | 0.53% | 1 | 0 | 2026-10-09T18:17:07.240000 | Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vu | |
| CVE-2026-107839 | 7.5 | 0.34% | 1 | 0 | 2026-10-09T18:17:05.797000 | ageLANServer provides a cross-platform web server and launcher for offline multi | |
| CVE-2026-107818 | 8.4 | 0.34% | 1 | 0 | 2026-10-09T18:17:03.373000 | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until | |
| CVE-2026-107808 | 8.1 | 0.41% | 1 | 0 | 2026-10-09T18:17:02.773000 | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5. | |
| CVE-2026-107807 | 8.8 | 0.31% | 1 | 0 | 2026-10-09T18:17:02.610000 | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5. | |
| CVE-2026-75347 | 7.5 | 0.42% | 1 | 0 | 2026-10-09T17:41:47.060000 | EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired poi | |
| CVE-2026-107815 | 8.5 | 0.57% | 1 | 0 | 2026-10-09T17:41:29.727000 | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until | |
| CVE-2026-107826 | 7.5 | 0.46% | 1 | 0 | 2026-10-09T17:33:55 | ### Summary The JSON body processor (`internal/bodyprocessors/json.go`) can be | |
| CVE-2026-107814 | 8.4 | 0.28% | 1 | 0 | 2026-10-09T17:16:45.853000 | MariaDB server is a community developed fork of MySQL server. From 10.6.1 until | |
| CVE-2026-107812 | 7.5 | 0.17% | 1 | 0 | 2026-10-09T17:08:21 | ## Summary The self-upgrade downloads the release binary and its checksum (`*.ta | |
| CVE-2026-107809 | 8.8 | 0.18% | 1 | 0 | 2026-10-09T17:08:11 | ## Summary Nginx-UI v2.4.3 stores the API JWT in a browser cookie named `token` | |
| CVE-2026-107813 | 8.8 | 0.30% | 1 | 0 | 2026-10-09T17:08:07 | ## Summary Incomplete fix of GHSA-5v7c-xpfp-p65m: the secure-session (OTP step- | |
| CVE-2026-107810 | 8.1 | 0.36% | 1 | 0 | 2026-10-09T17:07:06 | ### Summary An authenticated user who can create and restore a backup can craft | |
| CVE-2026-108106 | 7.5 | 0.37% | 1 | 0 | 2026-10-09T17:06:17.770000 | Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulne | |
| CVE-2026-75349 | 7.5 | 0.45% | 1 | 0 | 2026-10-09T16:40:29.800000 | EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bound | |
| CVE-2026-107805 | 7.5 | 0.44% | 1 | 0 | 2026-10-09T16:38:57.820000 | Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6. | |
| CVE-2026-107811 | 8.8 | 0.36% | 1 | 0 | 2026-10-09T16:38:57.820000 | Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5. | |
| CVE-2026-55797 | 8.8 | 1.55% | 1 | 0 | 2026-10-09T16:37:27 | ### Impact Argo CD runs a shell command in the repo-server when it clones or fe | |
| CVE-2026-103413 | 8.8 | 0.39% | 1 | 0 | 2026-10-09T16:33:39.007000 | Improper input validation vulnerability in Apache Camel Karavan. When a deplo | |
| CVE-2026-93947 | 9.3 | 0.24% | 1 | 0 | 2026-10-09T16:17:32.090000 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injecti | |
| CVE-2026-79842 | 9.1 | 0.33% | 2 | 0 | 2026-10-09T15:32:29 | An authentication bypass vulnerability exists in HPE Intelligent Management Cent | |
| CVE-2026-39460 | 8.1 | 0.29% | 1 | 0 | 2026-10-09T15:31:42 | Usernames and passwords, including the default factory credentials, are stored i | |
| CVE-2026-108101 | 7.5 | 0.39% | 1 | 0 | 2026-10-09T15:31:38 | HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulne | |
| CVE-2026-100730 | 9.8 | 0.62% | 1 | 0 | 2026-10-09T15:31:37 | A service console interface on openPDC and openHistorian deserializes a client-s | |
| CVE-2026-15340 | 9.8 | 0.60% | 1 | 0 | 2026-10-09T15:31:35 | lwIP SMTP client does not check the size of inputs, potentially allowing a buffe | |
| CVE-2026-39453 | 8.3 | 0.29% | 1 | 0 | 2026-10-09T15:31:35 | Navigating to a certain URL on the switch’s web server causes the switch to rebo | |
| CVE-2026-108107 | 9.8 | 0.41% | 1 | 0 | 2026-10-09T15:31:34 | PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerabi | |
| CVE-2026-108109 | 9.1 | 0.39% | 1 | 0 | 2026-10-09T15:31:34 | PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the c | |
| CVE-2026-83943 | 8.7 | 0.38% | 1 | 0 | 2026-10-09T15:31:32 | Exposure of sensitive information to an unauthorized actor in Azure API Center a | |
| CVE-2016-3081 | 8.1 | 96.05% | 2 | 0 | 2026-10-09T14:43:05.703000 | Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when | |
| CVE-2026-11318 | 7.8 | 0.19% | 1 | 1 | 2026-10-09T14:17:20.393000 | Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com. | |
| CVE-2026-17189 | 8.2 | 0.15% | 1 | 0 | 2026-10-09T14:15:54.050000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19493 | 7.5 | 0.36% | 1 | 0 | 2026-10-09T14:15:19.050000 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-86405 | 9.8 | 0.20% | 1 | 0 | 2026-10-09T13:21:13.267000 | Improper verification of cryptographic signature vulnerability in Sipay Electron | |
| CVE-2026-94503 | 10.0 | 0.28% | 1 | 1 | 2026-10-09T12:31:48 | Unrestricted Upload of File with Dangerous Type vulnerability in PX-lab Zombify | |
| CVE-2026-96207 | 10.0 | 0.48% | 2 | 0 | 2026-10-09T00:31:56 | Improper certificate validation in Microsoft Partner Center allows an unauthoriz | |
| CVE-2026-94510 | 9.9 | 0.40% | 2 | 0 | 2026-10-09T00:31:56 | Authorization bypass through user-controlled key in Microsoft Bookings allows an | |
| CVE-2026-83947 | 7.7 | 0.37% | 1 | 0 | 2026-10-09T00:31:56 | Missing authorization in Azure Event Grid allows an authorized attacker to perfo | |
| CVE-2026-84058 | 8.1 | 0.36% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer over | |
| CVE-2026-84057 | 8.1 | 0.36% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to e | |
| CVE-2026-84249 | 9.8 | 0.41% | 1 | 0 | 2026-10-09T00:31:56 | IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to e | |
| CVE-2026-89091 | 8.8 | 0.48% | 1 | 0 | 2026-10-09T00:31:56 | A flaw was found in ansible-core. When installing a collection with `ansible-gal | |
| CVE-2026-107782 | 7.8 | 0.11% | 1 | 0 | 2026-10-08T21:34:48.800000 | System Informer before 4.0.26241.138 contains an incorrect authorization vulnera | |
| CVE-2026-19482 | 8.8 | 0.42% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-16823 | 9.1 | 0.33% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-19491 | 9.1 | 0.33% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-78406 | 9.8 | 0.50% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-78401 | 9.8 | 0.57% | 1 | 0 | 2026-10-08T21:33:42 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-18740 | 8.8 | 0.35% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-16916 | 9.1 | 0.42% | 1 | 0 | 2026-10-08T21:33:41 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access | |
| CVE-2026-107779 | 9.8 | 0.54% | 1 | 0 | 2026-10-08T21:27:15.010000 | Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains | |
| CVE-2026-20362 | 7.2 | 0.47% | 1 | 0 | 2026-10-08T20:08:45.857000 | A vulnerability in the web-based management interface of Cisco Finesse could all | |
| CVE-2026-103663 | None | 0.71% | 2 | 0 | 2026-10-08T15:33:06 | Ollama is vulnerable to path traversal in the `/api/pull` endpoint due to insuff | |
| CVE-2025-64393 | 0 | 0.36% | 2 | 0 | 2026-10-08T04:16:55.397000 | This vulnerability in Veeam Backup & Replication allows a Backup Viewer to execu | |
| CVE-2026-102255 | 10.0 | 0.48% | 3 | 0 | 2026-10-07T18:33:12 | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Pla | |
| CVE-2026-107181 | 8.1 | 0.34% | 4 | 1 | 2026-10-07T17:16:53.520000 | Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnera | |
| CVE-2026-21589 | 0 | 1.77% | 3 | 12 | 2026-10-07T13:17:22.273000 | This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira S | |
| CVE-2026-105192 | 9.8 | 0.48% | 1 | 1 | 2026-10-07T12:31:58 | LMCache multiprocess mode, also called distributed mode, opens an unauthenticate | |
| CVE-2026-59346 | 9.3 | 0.26% | 1 | 1 | 2026-10-07T06:33:08 | VMware Workstation and Fusion contain an integer-overflow vulnerability. A malic | |
| CVE-2026-105141 | 6.3 | 0.34% | 2 | 0 | 2026-10-06T15:04:52.637000 | A security flaw has been discovered in topoteretes cognee up to 1.5.4. The affec | |
| CVE-2026-79820 | 9.0 | 0.27% | 1 | 0 | 2026-10-05T18:34:22 | A remote user validation failure vulnerability exists in HPE Integrated Lights-O | |
| CVE-2026-105133 | 7.3 | 0.38% | 5 | 0 | 2026-10-04T09:30:21 | A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the fu | |
| CVE-2026-105134 | 10.0 | 1.84% | 5 | 1 | 2026-10-04T09:30:21 | A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects | |
| CVE-2026-88772 | 8.1 | 1.30% | 1 | 8 | 2026-09-28T12:32:09 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue | |
| CVE-2026-88771 | 9.8 | 1.08% | 2 | 14 | 2026-09-28T12:32:08 | Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetSc | |
| CVE-2026-25264 | 8.8 | 0.07% | 1 | 0 | 2026-09-25T13:37:47.870000 | Privilege escalation due to weak configuration during package extraction process | |
| CVE-2026-25254 | 9.8 | 0.32% | 1 | 0 | 2026-09-25T13:37:41.860000 | Improper authorization leads to Remote Code Execution via SocketIO interface. | |
| CVE-2026-62866 | 6.2 | 0.19% | 1 | 0 | 2026-09-24T21:25:27.050000 | Dasel is a command-line tool and library for querying, modifying, and transformi | |
| CVE-2026-82077 | None | 0.74% | 2 | 0 | 2026-09-24T09:32:00 | An improper limitation of a pathname to a restricted directory (path traversal) | |
| CVE-2026-93952 | 10.0 | 1.06% | 1 | 0 | 2026-09-23T14:32:12.417000 | VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may a | |
| CVE-2026-85219 | 3.7 | 0.41% | 1 | 0 | 2026-09-22T19:41:38.447000 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an | |
| CVE-2026-19658 | 9.8 | 0.53% | 1 | 1 | 2026-09-22T06:30:35 | The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in | |
| CVE-2026-13355 | 9.8 | 0.44% | 1 | 1 | 2026-09-22T06:30:35 | The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to A | |
| CVE-2026-93485 | 7.1 | 0.38% | 1 | 4 | 2026-09-18T06:32:17 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-82078 | 9.1 | 63.53% | 2 | 2 | 2026-09-14T00:16:56.777000 | An unsafe dynamic class loading vulnerability exists in the database connection | |
| CVE-2026-0310 | None | 0.37% | 1 | 0 | 2026-09-10T06:31:55 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto | |
| CVE-2026-80093 | 7.0 | 0.32% | 1 | 0 | 2026-09-09T00:31:34 | Use after free in Windows Cloud Files Mini Filter Driver allows an authorized at | |
| CVE-2025-30156 | 8.9 | 0.09% | 2 | 0 | 2026-09-08T21:11:56.250000 | Ceph is an open-source distributed storage platform providing object, block, and | |
| CVE-2026-6726 | 7.9 | 0.19% | 1 | 0 | 2026-09-08T14:09:00.860000 | An information leakage vulnerability was reported in the TCG TPM 2.0 reference c | |
| CVE-2026-6727 | 5.9 | 0.15% | 1 | 4 | 2026-09-08T14:09:00.860000 | A timing side-channel vulnerability exists in the RSA OAEP decryption implementa | |
| CVE-2026-31431 | 7.8 | 3.44% | 1 | 100 | template | 2026-09-08T09:36:36 | In the Linux kernel, the following vulnerability has been resolved: crypto: alg |
| CVE-2026-81578 | 9.8 | 85.58% | 2 | 2 | 2026-08-31T21:31:56 | An improper access control vulnerability exists in the web management interface | |
| CVE-2026-48710 | 6.5 | 7.06% | 1 | 5 | 2026-08-28T18:31:00 | ### Summary In affected versions, the HTTP `Host` request header was not validat | |
| CVE-2026-73570 | 8.9 | 71.66% | 1 | 10 | 2026-08-24T13:19:17.577000 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) befor | |
| CVE-2026-72898 | 10.0 | 19.05% | 1 | 10 | 2026-08-12T15:18:30.347000 | Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via t | |
| CVE-2026-47483 | 8.2 | 0.34% | 1 | 0 | 2026-07-28T18:33:11 | NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pp | |
| CVE-2025-47818 | 2.2 | 0.24% | 1 | 0 | 2026-06-17T09:28:43.993000 | Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for | |
| CVE-2025-31200 | 9.8 | 20.90% | 1 | 4 | 2026-06-17T09:10:00.550000 | A memory corruption issue was addressed with improved bounds checking. This issu | |
| CVE-2025-24201 | 10.0 | 3.85% | 1 | 3 | 2026-06-17T08:58:17.950000 | An out-of-bounds write issue was addressed with improved checks to prevent unaut | |
| CVE-2026-0257 | 9.1 | 96.89% | 2 | 8 | 2026-06-09T12:32:02 | Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of | |
| CVE-2024-3094 | 10.0 | 85.97% | 1 | 90 | 2024-03-29T18:30:50 | Malicious code was discovered in the upstream tarballs of xz, starting with vers | |
| CVE-2026-87902 | 0 | 39.98% | 1 | 27 | N/A | ||
| CVE-2026-108269 | 0 | 0.13% | 1 | 0 | N/A | ||
| CVE-2026-92705 | 0 | 0.13% | 1 | 0 | N/A | ||
| CVE-2026-107821 | 0 | 0.48% | 1 | 0 | N/A | ||
| CVE-2026-107838 | 0 | 0.34% | 1 | 0 | N/A | ||
| CVE-2026-107837 | 0 | 0.38% | 1 | 0 | N/A | ||
| CVE-2026-61746 | 0 | 0.40% | 1 | 0 | N/A |
updated 2026-10-11T18:16:59.410000
2 posts
🟠 CVE-2026-19935 - High (7.5)
The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_process()) whenever the channel uses a dynamic PS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19935 - High (7.5)
The Bluetooth LE host queues received L2CAP connection-oriented channel (CoC) data for deferred processing through a struct k_work embedded in the channel object (le_chan->rx_work, handler l2cap_rx_process()) whenever the channel uses a dynamic PS...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T18:16:58.810000
2 posts
🟠 CVE-2026-19736 - High (7.8)
The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19736 - High (7.8)
The NXP MCUX TRNG entropy driver in drivers/entropy/entropy_mcux_trng.c passed the caller's byte count straight to the vendor SDK routine TRNG_GetRandomData(). On i.MX RT5xx and RT6xx parts the SDK compiles its TRNG_SW_HEALTH_TESTS variant, which ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19736/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T18:16:58.563000
2 posts
🟠 CVE-2026-19669 - High (7.8)
The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19669/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-19669 - High (7.8)
The user-mode syscall verifiers z_vrfy_fuel_gauge_get_props() and z_vrfy_fuel_gauge_set_props() in drivers/fuel_gauge/fuel_gauge_syscall_handlers.c declared two variable-length arrays, union fuel_gauge_prop_val k_vals[len] and fuel_gauge_prop_t k_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19669/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T17:17:07.010000
1 posts
🟠 CVE-2026-91136 - High (7.5)
The Divi Plus plugin for WordPress is vulnerable to Arbitrary File Read in versions up to, and including, 2.4.0 via the 'svg_image' parameter of the /wp-json/elicus/v1/dipl-modules/svg-animator REST endpoint. This is due to the endpoint's permissi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-91136/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T17:17:04.760000
1 posts
🟠 CVE-2026-33367 - High (8.1)
SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33367/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T17:17:04.303000
1 posts
🟠 CVE-2026-28745 - High (7.5)
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-28745/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T17:17:01.723000
1 posts
Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.
##updated 2026-10-11T17:17:00.237000
1 posts
🟠 CVE-2026-104759 - High (8.1)
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::proc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104759/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:29.907000
1 posts
🟠 CVE-2026-96341 - High (8.2)
Incorrect Privilege Assignment vulnerability in WPMU DEV Forminator forminator allows Privilege Escalation.This issue affects Forminator: from n/a through 1.57.3.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:28.283000
2 posts
🔴 CVE-2026-93944 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93944/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 https://radar.offseq.com/threat/cve-2026-93944-deserialization-of-untrusted-data-in-themerex-group-camelia-9f283474b74167fd #OffSeq #Infosec #Vulnerability
##updated 2026-10-11T13:17:28.180000
1 posts
🔴 CVE-2026-93943 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Convex convex allows Object Injection.This issue affects Convex: from n/a through 1.16.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93943/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:27.850000
1 posts
🔴 CVE-2026-93940 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Greeny greeny allows Object Injection.This issue affects Greeny: from n/a through 2.10.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93940/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:27.643000
1 posts
🔴 CVE-2026-93937 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hygia hygia allows Object Injection.This issue affects Hygia: from n/a through 1.21.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:27.323000
1 posts
🔴 CVE-2026-93934 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:27.100000
1 posts
🔴 CVE-2026-93932 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smart Casa smart-casa allows Object Injection.This issue affects Smart Casa: from n/a through 1.0.12.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93932/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:26.997000
1 posts
🔴 CVE-2026-93931 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Smash smash allows Object Injection.This issue affects Smash: from n/a through 1.12.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93931/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:24.780000
2 posts
🔴 CVE-2026-62045 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62045/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: https://radar.offseq.com/threat/cve-2026-62045-deserialization-of-untrusted-data-in-themerex-group-booklovers-71a61b206a138f37 #OffSeq #CVE202662045 #WordPress #Vuln #infosec
##updated 2026-10-11T13:17:20.237000
2 posts
CVE-2026-108753 | agnaistic agnai ≤1.0.555: CRITICAL hard-coded admin creds in docker-compose enable full admin compromise. Restrict config file access & monitor for abuse. Patch status unconfirmed. https://radar.offseq.com/threat/cve-2026-108753-use-of-hard-coded-credentials-in-agnaistic-agnai-58e8164af214c753 #OffSeq #CVE2026108753 #infosec #vuln
##CVE-2026-108753 | agnaistic agnai ≤1.0.555: CRITICAL hard-coded admin creds in docker-compose enable full admin compromise. Restrict config file access & monitor for abuse. Patch status unconfirmed. https://radar.offseq.com/threat/cve-2026-108753-use-of-hard-coded-credentials-in-agnaistic-agnai-58e8164af214c753 #OffSeq #CVE2026108753 #infosec #vuln
##updated 2026-10-11T13:17:12.430000
2 posts
1 repos
https://github.com/KevineCharles/CVE-2026-106610-miniorange-otp-ato
🔴 New security advisory:
CVE-2026-106610 affects multiple systems.
• Impact: Remote code execution or complete system compromise possible
• Risk: Attackers can gain full control of affected systems
• Mitigation: Patch immediately or isolate affected systems
Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-106610-miniorange-otp-auth-bypass-grants-admin-poc
by Yazoul AI
##🔴 CVE-2026-106610 - Critical (9.8)
Incorrect Privilege Assignment vulnerability in miniOrange miniorange otp verification miniorange-otp-verification allows Privilege Escalation.This issue affects miniorange otp verification: from n/a through 5.5.7.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106610/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:11.910000
1 posts
🔴 CVE-2026-105892 - Critical (9.8)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, BuddyPress a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105892/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:11.270000
2 posts
Deserialization of untrusted data in VillaTheme AFFI for WooCommerce (<=1.0.10) — CVE-2026-104398 (CRITICAL, CVSS 9.8) enables remote code execution with no auth/user input. Restrict or remove plugin until patched. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-villatheme-affi-affiliate-marketing-for-woocommerce-3d8236ba80fe5b3c #OffSeq #CVE2026104398 #WordPress #Infosec
##🔴 CVE-2026-104398 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104398/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T13:17:10.180000
1 posts
🟠 CVE-2026-103071 - High (7.5)
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-103071/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T12:32:13
2 posts
CVE-2026-93550 (HIGH): Veeqo for WooCommerce ≤2.2.8 lets Subscriber+ users upload arbitrary PHP files via insufficient URL validation, risking full site compromise. Restrict access & monitor plugin activity. https://radar.offseq.com/threat/cve-2026-93550-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-veeqo-for-woocommerce-e80aa084e9f36826 #OffSeq #WordPress #Vuln #BlueTeam
##CVE-2026-93550 (HIGH): Veeqo for WooCommerce ≤2.2.8 lets Subscriber+ users upload arbitrary PHP files via insufficient URL validation, risking full site compromise. Restrict access & monitor plugin activity. https://radar.offseq.com/threat/cve-2026-93550-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-veeqo-for-woocommerce-e80aa084e9f36826 #OffSeq #WordPress #Vuln #BlueTeam
##updated 2026-10-11T12:32:13
2 posts
Piotnet Forms <=1.0.30 impacted by HIGH severity stored XSS (CVE-2026-96227). Unauthenticated file uploads allow arbitrary JS execution. Restrict uploads & validate files. Await vendor patch. Details: https://radar.offseq.com/threat/cve-2026-96227-cwe-79-cross-site-scripting-xss-in-piotnet-forms-5a16ad1f17e57c01 #OffSeq #XSS #WordPress #Infosec
##Piotnet Forms <=1.0.30 impacted by HIGH severity stored XSS (CVE-2026-96227). Unauthenticated file uploads allow arbitrary JS execution. Restrict uploads & validate files. Await vendor patch. Details: https://radar.offseq.com/threat/cve-2026-96227-cwe-79-cross-site-scripting-xss-in-piotnet-forms-5a16ad1f17e57c01 #OffSeq #XSS #WordPress #Infosec
##updated 2026-10-11T12:17:24.653000
2 posts
CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-86717-cwe-862-missing-authorization-in-insurify-d0d6b23b34928b39 #OffSeq #WordPress #CVE202686717 #infosec
##CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-86717-cwe-862-missing-authorization-in-insurify-d0d6b23b34928b39 #OffSeq #WordPress #CVE202686717 #infosec
##updated 2026-10-11T12:17:22.500000
1 posts
🔴 CVE-2026-81797 - Critical (9.8)
Unauthenticated PHP Object Injection in Buzz Stone | Magazine & Viral Blog WordPress Theme <= 1.0.2 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-81797/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T12:17:21.310000
1 posts
🔴 CVE-2026-78535 - Critical (9.8)
Unauthenticated PHP Object Injection in Photolia <= 1.0.3 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78535/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T12:17:21.103000
1 posts
🔴 CVE-2026-78533 - Critical (9.8)
Unauthenticated PHP Object Injection in Qwery <= 3.6.1 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78533/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T12:17:20.693000
1 posts
🔴 CVE-2026-66569 - Critical (9.8)
Unauthenticated PHP Object Injection in Kicker <= 2.2.1 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66569/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T12:17:20.590000
1 posts
🔴 CVE-2026-66568 - Critical (9.8)
Unauthenticated PHP Object Injection in Original <= 1.9.0 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66568/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-11T09:30:32
2 posts
CVE-2026-108540: CRITICAL OS command injection in OpenSpug Spug 3.0 – 4.0.1. Remote attackers can execute arbitrary OS commands. Exploit code is public. Restrict access/disable vulnerable features until a patch arrives. https://radar.offseq.com/threat/cve-2026-108540-os-command-injection-in-openspug-spug-6b899c3d670ff1c9 #OffSeq #Vuln #Exploit #Infosec
##CVE-2026-108540: CRITICAL OS command injection in OpenSpug Spug 3.0 – 4.0.1. Remote attackers can execute arbitrary OS commands. Exploit code is public. Restrict access/disable vulnerable features until a patch arrives. https://radar.offseq.com/threat/cve-2026-108540-os-command-injection-in-openspug-spug-6b899c3d670ff1c9 #OffSeq #Vuln #Exploit #Infosec
##updated 2026-10-11T03:30:24
2 posts
CVE-2026-108707 - Critical Auth Bypass in Wukong_HRM allows full API takeover & sensitive HR data theft. CVSS 9.8. Restrict API access immediately. #CVE #infosec #cybersecurity
##CRITICAL: CVE-2026-108707 in WuKong_HRM (≤ commit 186115e) enables auth bypass — attackers can access all HRM APIs, gaining admin rights and exposing sensitive HR data. Restrict endpoints & monitor for unauthorized access. https://radar.offseq.com/threat/cve-2026-108707-improper-authentication-in-wukongopensource-wukonghrm-13cec42117273b1c #OffSeq #CVE2026108707 #infosec #vulnerability
##updated 2026-10-10T21:31:28
1 posts
🟠 CVE-2026-78530 - High (7.7)
Subscriber Arbitrary File Deletion in FoodBakery <= 4.6 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78530/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T21:31:28
1 posts
🔴 CVE-2026-78529 - Critical (9.8)
Unauthenticated PHP Object Injection in Alliance <= 3.11 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78529/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T21:31:28
1 posts
🟠 CVE-2026-66566 - High (8.1)
Unauthenticated Local File Inclusion in Ambient <= 1.7 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T21:31:27
1 posts
🔴 CVE-2026-66567 - Critical (9.8)
Unauthenticated PHP Object Injection in Anesta <= 1.5.3 versions.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66567/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T21:31:20
1 posts
🔴 CVE-2026-108598 - Critical (9.8)
Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration wh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108598/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T18:31:27
1 posts
🟠 CVE-2026-106609 - High (7.5)
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-106609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T18:31:27
1 posts
🔴 CVE-2026-105889 - Critical (9.3)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105889/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:30
1 posts
🟠 CVE-2026-108546 - High (7.5)
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108546/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:29
1 posts
🟠 CVE-2026-105885 - High (8.8)
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-105885/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:24
1 posts
🟠 CVE-2026-108550 - High (8.8)
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge init...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108550/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:30:22
1 posts
🟠 CVE-2026-108161 - High (7.5)
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename templat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108161/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:16:58.410000
1 posts
🟠 CVE-2026-108553 - High (7.5)
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108553/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:16:58.273000
1 posts
🔴 CVE-2026-108551 - Critical (9.8)
openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108551/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T15:16:58.087000
1 posts
🟠 CVE-2026-108549 - High (8.1)
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webho...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108549/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T13:17:32.163000
1 posts
🟠 CVE-2026-19494 - High (8.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19494/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:41
1 posts
🟠 CVE-2026-96662 - High (7.5)
The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to generic SQL Injection via 'booking[service_id]' Parameter in all versions up to, and including, 5.7.2 due to insufficient esca...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-96662/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
2 posts
ThemeREX IPharm ipharm ≤1.2.4 hit by CRITICAL deserialization vuln (CVE-2026-93936, CVSS 9.8) 🛡️ Allows object injection & potential system compromise. No patch yet — restrict access, increase monitoring. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-themerex-group-ipharm-ipharm-allows-object-9d61996241f7bf9e #OffSeq #vuln #CVE202693936 #infosec
##🔴 CVE-2026-93936 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group IPharm ipharm allows Object Injection.This issue affects IPharm: from n/a through 1.2.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
3 posts
CVE-2026-93945: CRITICAL object injection via deserialization in Axiomthemes Balance (<=1.12.0). Full compromise risk — no patch yet. Check vendor guidance & mitigate if possible. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-axiomthemes-balance-balance-allows-object-f802d57a201c6245 #OffSeq #CVE202693945 #WordPress #Vuln #Infosec
##🔴 CVE-2026-93945 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93945/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-93945 in Axiomthemes Balance (<=1.12.0) allows remote object injection via deserialization of untrusted data. No auth or user action needed — full system compromise possible. Restrict access & monitor vendor updates. https://radar.offseq.com/threat/cve-2026-93945-deserialization-of-untrusted-data-in-axiomthemes-balance-4f56b1b48493a9aa #OffSeq #CVE #Vuln
##updated 2026-10-10T09:30:37
2 posts
CVE-2026-93935: ThemeREX Let's Play playhockey ≤1.1.15 affected by CRITICAL deserialization flaw (CWE-502). Enables remote object injection and full compromise. Patch pending — monitor vendor updates & restrict plugin use. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-themerex-group-lets-play-playhockey-allows-object-6b9f9ae91683af07 #OffSeq #CVE202693935 #WordPress #Infosec
##🔴 CVE-2026-93935 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
2 posts
🔴 CVE-2026-62046 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62046/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-62046: CRITICAL deserialization flaw in ThemeREX Gutentype (≤2.1.12) allows object injection — full system compromise possible. Patch status unknown, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-62046-deserialization-of-untrusted-data-in-themerex-group-gutentype-f4d0a8ac3919ab35 #OffSeq #WordPress #Vulnerability #Infosec
##updated 2026-10-10T09:30:37
2 posts
🔴 CVE-2026-104803 - Critical (9.8)
The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability ex...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104803/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. https://radar.offseq.com/threat/cve-2026-104803-cwe-287-improper-authentication-in-whyun-wpcom-member-4f47db1288fd1984 #OffSeq #WordPress #Infosec #CVE2026104803
##updated 2026-10-10T09:30:37
1 posts
🔴 CVE-2026-93933 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
1 posts
🔴 CVE-2026-93929 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93929/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
1 posts
🔴 CVE-2026-93942 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Dwell dwell allows Object Injection.This issue affects Dwell: from n/a through 1.16.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93942/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
1 posts
🔴 CVE-2026-93941 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Edema edema allows Object Injection.This issue affects Edema: from n/a through 1.2.2.2.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93941/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
1 posts
🔴 CVE-2026-93938 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Hogwords hogwords allows Object Injection.This issue affects Hogwords: from n/a through 1.2.7.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93938/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:37
1 posts
🟠 CVE-2026-93950 - High (7.5)
Missing Authorization vulnerability in StylemixThemes Motors motors allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Motors: from n/a through 1.4.108.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93950/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:36
1 posts
🟠 CVE-2026-94538 - High (8.1)
The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-94538/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:36
1 posts
🟠 CVE-2026-93746 - High (7.5)
The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 5.0.2 via the 'email' parameter of the guest print_doc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93746/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:36
1 posts
🔴 CVE-2026-93930 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T09:30:36
1 posts
🔴 CVE-2026-93927 - Critical (9.8)
Deserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-93927/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T06:31:08
1 posts
CVE-2026-97670: Avada (Fusion) Builder ≤7.16.1 has a CRITICAL code injection flaw. Unauthenticated attackers can invoke arbitrary WP action hooks — risks include content deletion & DoS. Disable vulnerable forms, await patch. https://radar.offseq.com/threat/cve-2026-97670-cwe-94-improper-control-of-generation-of-code-code-injection-in-themefusion-avada-f8cd8b04809f86cf #OffSeq #WordPress #Vuln #CVE202697670
##updated 2026-10-10T06:31:06
1 posts
CVE-2026-94589: CRITICAL RCE in Extensions For CF7 (<=3.4.5) for WordPress. Unauth attackers can upload and run malicious files — full compromise possible. Restrict uploads, monitor activity, and check for fixes. https://radar.offseq.com/threat/cve-2026-94589-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-htplugins-extensions-for-cf7-1b07904cb30ec057 #OffSeq #WordPress #CVE202694589 #infosec
##updated 2026-10-10T04:18:19.240000
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
Microsoft Dataverse is affected by CVE-2026-88131 (CRITICAL, CVSS 9.8): deserialization of untrusted data allows unauthenticated RCE. Patch available — apply ASAP! https://radar.offseq.com/threat/cve-2026-88131-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-dataverse-eba5097c3e4671bb #OffSeq #CVE202688131 #Microsoft #RCE #Infosec
##updated 2026-10-10T04:18:19.087000
1 posts
🟠 CVE-2026-84875 - High (7.5)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84875/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:17.220000
1 posts
🟠 CVE-2026-84035 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84035/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-10T04:18:14.030000
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
Microsoft Azure App Service for Linux hit by CVE-2026-77900 (CRITICAL, CVSS 9.8): missing authentication enables unauthenticated remote code execution. Patch released — update now. https://radar.offseq.com/threat/cve-2026-77900-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-app-service-for-806c7a8fa62ffe41 #OffSeq #Azure #CVE202677900 #Infosec #CloudSecurity
##updated 2026-10-10T04:18:13.347000
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
CVE-2026-69435: CRITICAL SSRF (CVSS 9.6) in Microsoft Azure SRE Agent. Missing authorization controls let authorized attackers escalate privileges, risking confidentiality & integrity. Microsoft has issued a fix. https://radar.offseq.com/threat/cve-2026-69435-cwe-918-server-side-request-forgery-ssrf-in-microsoft-azure-sre-agent-10f6e62769899cfe #OffSeq #Azure #SSRF #Infosec
##updated 2026-10-10T04:18:09.503000
10 posts
4 repos
https://github.com/techupdate24/citrix-netscaler-rce-cve-2026-107406
https://github.com/ctroy999/CVE-2026-107406
https://github.com/ApexBreach/CVE-2026-107406-Poc
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
🚨 Critical Citrix NetScaler Vulnerability Disclosed
Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway, with a CVSS 4.0 score of 9.5.
The vulnerability could potentially allow remote code execution or denial of service on affected systems.
Exploitation requires specific SAML Service Provider or Identity Provider configurations, depending on the installed version.
#SecPoint #Citrix #NetScaler #CyberSecurity #VulnerabilityManagement
##CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. https://www.theregister.com/security/2026/10/09/citrix-gives-netscaler-admins-another-critical-reason-to-patch/5302212
##https://thecybersecguru.com/uncategorized/citrix-netscaler-cve-2026-107406-rce/
##Citrix emitiu um aviso urgente para corrigir uma vulnerabilidade crítica nas soluções de rede NetScaler ADC e plataformas de acesso remoto NetScaler Gateway. A falha, identificada como CVE-2026-107406, permite a execução remota de código arbitrário ou negação de serviço. 🚨
##Citrix NetScaler instances with SAML enabled are affected by CVE-2026-107406, which can cause remote code execution and crash. Exposed ADC and Gateway systems risk takeover or service disruption, so patching and log review for malicious SAML requests is critical. #NetScaler #Citrix #PatchManagement
https://cyberworldops.eu/en/netscaler-saml-deployments-face-rce-and-crash-risk-from-cve-2026
##Critical Citrix NetScaler vulnerability CVE-2026-107406 (CVSS 9.5) can lead to RCE on SAML-configured ADC and Gateway. Upgrade now.
#Citrix #NetScaler #NetScalerGateway #CVE2026107406 #SAML #RCE #PatchNow #Vulnerability
##I thought it was a Sunday because Citrix posted another yet another NetScaler security advisory:
CVE-2026-107406 (9.5 critical) pre-auth memory overflow > RCE or DoS
As of the publication of the bulletin, Citrix is not aware of any unmitigated exploits of this vulnerability.
https://support.citrix.com/external/article/CTX697191
https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
There’s yet another Citrix Netscaler vuln (new patch today) which allows unauth RCE - CVE-2026-107406
Same attack surface (SAML) as two of the other vulns exploited in the wild during the past month.
##@GossiTheDog https://community.citrix.com/techzone-blogs/110_security-updates/protecting-customers-immediate-guidance-for-cve-2026-107406-in-netscaler-adc-and-netscaler-gateway-r1631/
They did it again :D
##I'm tired, boss.
A new #Citrix CVE affecting SAML IdP/SP-configured devices is out.
https://ifin.network/t/cve-2026-107406-somehow-another-citrix-netscaler-saml-vulnerability/891
##updated 2026-10-10T00:17:03.673000
1 posts
CVE-2026-108474: JetBrains Exposed (<1.5.1) faces CRITICAL SQL injection (CWE-89). Exploitation can fully compromise DBs — upgrade to 1.5.1+ now! CVSS 9.8. https://radar.offseq.com/threat/cve-2026-108474-cwe-89-in-jetbrains-exposed-73385fdc0142aed6 #OffSeq #SQLi #JetBrains #AppSec
##updated 2026-10-09T22:16:59.643000
1 posts
CVE-2026-108268 (CRITICAL, CVSS 9.1): Privasys enclave-os-virtual <0.2.43/<0.6.27 origin validation error lets attackers relay attestation quotes if they have the enclave TLS private key. Upgrade to patched versions ASAP. https://radar.offseq.com/threat/cve-2026-108268-cwe-346-origin-validation-error-in-privasys-enclave-os-virtual-3494df223a867096 #OffSeq #CVE2026108268 #Vuln
##updated 2026-10-09T21:31:18
1 posts
🟠 CVE-2026-75351 - High (7.5)
OpENer v2.3/commit 76b95cf, contains an out-of-bounds read in the server-side EtherNet/IP ForwardOpen connection-path parser. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:05.800000
1 posts
🟠 CVE-2026-75346 - High (7.5)
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master through commit 76b95cf in the server-side CIP SetAttributeList service. This allows a remote attacker to cause a denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:05.627000
1 posts
🟠 CVE-2026-62376 - High (8.1)
Vikunja is an open-source self-hosted task management platform. Versions prior to 2.4.0 store password-reset, email-confirmation, and account-deletion tokens in the `user_tokens` table in plaintext. If an attacker gains read access to the database...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62376/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:05.190000
1 posts
🟠 CVE-2026-57458 - High (8.1)
Vikunja is an open-source self-hosted task management platform. In version 2.3.0, a scoped API token limited to the `oauth.authorize` permission can call `POST /api/v1/oauth/authorize`, obtain an OAuth authorization code, and exchange the code at ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-57458/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:04.703000
1 posts
🔴 CVE-2026-108264 - Critical (9.1)
Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108264/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T21:17:04.527000
1 posts
🔴 CVE-2026-108263 - Critical (9.9)
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108263/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:56:53
1 posts
🟠 CVE-2026-108259 - High (8.2)
Tina is a headless content management system. Prior to 3.0.0, @tinacms/cli reads Git branch values from VERCEL_GIT_COMMIT_REF, GITHUB_BRANCH, or HEAD, incorporates the raw value into the API URL, and interpolates that URL into JavaScript string li...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108259/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:56:50
1 posts
🔴 CVE-2026-108261 - Critical (9.3)
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL thr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108261/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:56:46
1 posts
🟠 CVE-2026-108260 - High (7.6)
Tina is a headless content management system. Prior to 0.2.1, the tina-markdown element in packages/@tinacms/web-components/src/tina-markdown.js assigns a rich-text node.url value directly to an anchor href without validating the URL scheme. A con...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108260/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:53:52
1 posts
🔴 CVE-2026-107845 - Critical (9.3)
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107845/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:45:03
1 posts
1 repos
A critical Nginx UI RCE vulnerability (CVE-2026-107806) is publicly disclosed with PoC exploit code. Admins must patch now to prevent system takeover.
##updated 2026-10-09T20:17:09.900000
1 posts
🟠 CVE-2026-107840 - High (7.5)
yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_req...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107840/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T20:17:09.050000
1 posts
🟠 CVE-2026-104084 - High (8.8)
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refre...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-104084/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:32:43
1 posts
Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.
#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412
##updated 2026-10-09T18:31:52
1 posts
🟠 CVE-2026-75350 - High (7.5)
EIPStackGroup OpENer v2.3 / master commit 76b95cf contains a buffer overflow in the GetAttributeList() implementation for the EtherNet/IP Get_Attribute_List service. This allows a remote attacker to cause a denial of service
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75350/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:48
1 posts
🟠 CVE-2026-108113 - High (8.8)
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import ri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108113/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:48
1 posts
🟠 CVE-2026-108160 - High (7.5)
AstronRPA through 1.1.6 contains a download of code without integrity check vulnerability that allows network attackers to deliver malicious updates by abusing the desktop client's auto-update mechanism. Attackers positioned between the client and...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108160/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:48
1 posts
🟠 CVE-2026-108159 - High (7.5)
AstronRPA through 1.1.6 contains a cross-site scripting vulnerability in the desktop client's smart-component chat that allows remote attackers to execute OS commands by abusing unsanitized LLM output rendered via v-html. Attackers can embed promp...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108159/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:47
1 posts
🟠 CVE-2026-75345 - High (7.5)
OpENer v2.3.0 / commit 76b95cf contains an out-of-bounds read in the unconnected explicit messaging path. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75345/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:47
1 posts
🟠 CVE-2026-90983 - High (8.2)
Use of Client-Side authentication vulnerability in Hayat Health Facilities Inc. (Hayat Hospital) Hayat Mobile allows Authentication Bypass.
This issue affects Hayat Mobile: from 3.3.0 before 3.4.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-90983/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:31:42
1 posts
🟠 CVE-2026-78795 - High (7.5)
An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78795/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:13.893000
1 posts
🟠 CVE-2026-75348 - High (7.5)
An out-of-bounds read vulnerability exists in EIPStackGroup OpENer v2.3 and master up to commit 76b95cf in the EtherNet/IP TCP SendRRData Common Packet Format parser. The issue occurs in CreateCommonPacketFormatStructure() when it parses recognize...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75348/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:07.240000
1 posts
🟠 CVE-2026-108157 - High (8.1)
Pingvin Share X from 0.19.0 before 1.22.0 contains an improper authentication vulnerability that allows remote unauthenticated attackers to take over accounts by abusing automatic OAuth email linking in OAuthService.signUp(). Attackers can registe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108157/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:05.797000
1 posts
🟠 CVE-2026-107839 - High (7.5)
ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no re...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107839/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:03.373000
1 posts
🟠 CVE-2026-107818 - High (8.4)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the mariadb.service unit used /run/mysqld/wsrep-new-cluster during the next service restart. A database user wi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107818/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:02.773000
1 posts
🟠 CVE-2026-107808 - High (8.1)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /api/login checks EnabledOTP but does not require a WebAuthn assertion when EnabledPasskey is true and no TOTP secret is configured. A passkey-only account is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T18:17:02.610000
1 posts
🟠 CVE-2026-107807 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, Nginx UI accepts the Node.Secret master credential through the node_secret query parameter in HTTP and WebSocket authentication paths instead of requiring the X-Nod...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:41:47.060000
1 posts
🟠 CVE-2026-75347 - High (7.5)
EIPStackGroup OpENer v2.3 and master up to commit 76b95cf contain an expired pointer dereference vulnerability in the EtherNet/IP Common Packet Format (CPF) handling logic. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:41:29.727000
1 posts
🟠 CVE-2026-107815 - High (8.5)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, the CONNECT engine's DOS table type used an incorrect boundary check that permitted a one-byte null write beyon...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107815/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:33:55
1 posts
🟠 CVE-2026-107826 - High (7.5)
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. From 3.0.0 until 3.8.1, readJSON in internal/bodyprocessors/json.go can stop its bounded flattening walk after reaching SecArgumentsLimit or the byte budget and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107826/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:16:45.853000
1 posts
🟠 CVE-2026-107814 - High (8.4)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB RPM packages created the dedicated mysql service account with the database data directory as its home d...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107814/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:08:21
1 posts
🟠 CVE-2026-107812 - High (7.5)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the self-upgrade mechanism validates a downloaded binary only with a same-origin digest obtained from the same upgrade mirror. A compromised mirror or network attac...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107812/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:08:11
1 posts
🟠 CVE-2026-107809 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not univ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107809/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:08:07
1 posts
🟠 CVE-2026-107813 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, the api/cluster router exposes node and namespace mutation operations and cluster-wide Nginx reload or restart operations with AuthRequired but without RequireSecur...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107813/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:07:06
1 posts
🟠 CVE-2026-107810 - High (8.1)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, internal/backup/restore.go extracts inner archives before applying the restore_nginx and restore_nginx_ui flags and permits symlinks targeting the live Nginx config...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107810/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T17:06:17.770000
1 posts
🟠 CVE-2026-108106 - High (7.5)
Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.u...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108106/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:40:29.800000
1 posts
🟠 CVE-2026-75349 - High (7.5)
EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-75349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:38:57.820000
1 posts
🟠 CVE-2026-107805 - High (7.5)
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107805/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:38:57.820000
1 posts
🟠 CVE-2026-107811 - High (8.8)
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107811/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:37:27
1 posts
🟠 CVE-2026-55797 - High (8.8)
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 2.11.0 until 3.3.15, 3.4.10, 3.5.4, and 3.6.0-rc2, the Argo CD repo-server is vulnerable to command injection when it clones, tests, or fetches an SSH Git repository co...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-55797/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T16:33:39.007000
1 posts
Discover how critical Apache Camel Karavan vulnerabilities (CVE-2026-103413 and CVE-2026-103412) allow code execution. Update to version 4.22.1 now.
#ApacheCamel #CyberSecurity #Vulnerability #CVE2026103413 #CVE2026103412
##updated 2026-10-09T16:17:32.090000
1 posts
CVE-2026-93947: CRITICAL SQL Injection in Shinetheme Traveler (0 – 3.2.9). Blind SQLi risk — attackers may access sensitive DB data. Patch when available & monitor your systems. https://radar.offseq.com/threat/cve-2026-93947-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-in-e7412128f2cf3852 #OffSeq #CVE202693947 #SQLInjection #InfoSec
##updated 2026-10-09T15:32:29
2 posts
HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##🔴 CVE-2026-79842 - Critical (9.1)
An authentication bypass vulnerability exists in HPE Intelligent Management Center (iMC) prior to v7.3 E0713
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-79842/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:42
1 posts
🟠 CVE-2026-39460 - High (8.1)
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device thro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39460/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:38
1 posts
🟠 CVE-2026-108101 - High (7.5)
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108101/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:37
1 posts
Fix critical openPDC openHistorian vulnerabilities like CVE-2026-100730 and CVE-2026-105281. CISA urges patching these severe RCE flaws immediately.
##updated 2026-10-09T15:31:35
1 posts
🔴 CVE-2026-15340 - Critical (9.8)
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:35
1 posts
🟠 CVE-2026-39453 - High (8.3)
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-39453/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:34
1 posts
🔴 CVE-2026-108107 - Critical (9.8)
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid par...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108107/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:34
1 posts
🔴 CVE-2026-108109 - Critical (9.1)
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer us...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-108109/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T15:31:32
1 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
updated 2026-10-09T14:43:05.703000
2 posts
(CISA CS-MAN) The Cyber Mind CSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability
A strategic C-Suite threat brief covering CVE-2016-3081 Apache Struts command injection vulnerability, featuring active mitigation, asset inventory management, and endpoint hardening....
##(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2016-3081 – Apache Struts Command Injection Vulnerability
Unpack CVE-2016-3081 with our technical TSUITE brief. Get advanced detection rules, Splunk SPL, KQL, and forensic triage priorities for active CISA KEV threats....
##updated 2026-10-09T14:17:20.393000
1 posts
1 repos
🟠 CVE-2026-11318 - High (7.8)
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers to execute arbitrary installer packages as root by connecting to the root-owned service w...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-11318/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T14:15:54.050000
1 posts
🟠 CVE-2026-17189 - High (8.2)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus alt...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17189/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T14:15:19.050000
1 posts
🟠 CVE-2026-19493 - High (7.5)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to perform an arbitrary file write due to path traversal.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19493/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T13:21:13.267000
1 posts
CVE-2026-86405 (CRITICAL, CVSS 9.8) in Sipay PrestaShop Virtual POS Module (26.8.1 – 26.9.1): Improper cryptographic signature checks allow spoofing & data tampering. Patch not confirmed — monitor vendor. https://radar.offseq.com/threat/cve-2026-86405-cwe-347-improper-verification-of-cryptographic-signature-in-sipay-electronic-money-and-d1d195a6023ad286 #OffSeq #CVE #vuln #cybersecurity
##updated 2026-10-09T12:31:48
1 posts
1 repos
PX-lab Zombify ≤1.7.7 is affected by CVE-2026-94503 (CRITICAL, CVSS 10): unrestricted upload of dangerous files enables remote code execution. No patch yet — restrict uploads & monitor for updates. https://radar.offseq.com/threat/cve-2026-94503-unrestricted-upload-of-file-with-dangerous-type-in-px-lab-zombify-8e6fe0b08d444b23 #OffSeq #CVE202694503 #WebSecurity #Infosec
##updated 2026-10-09T00:31:56
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
CVE-2026-96207 (CRITICAL, CVSS 10) affects Microsoft Partner Center: improper certificate validation (CWE-295) allows remote privilege escalation. Patch available — apply ASAP. No public exploits seen. https://radar.offseq.com/threat/cve-2026-96207-cwe-295-improper-certificate-validation-in-microsoft-microsoft-partner-center-0f13dc5f1a15e1f3 #OffSeq #Microsoft #CVE202696207 #Infosec
##updated 2026-10-09T00:31:56
2 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
CVE-2026-94510 (CRITICAL, CVSS 9.9) in Microsoft Bookings enables remote privilege escalation via authorization bypass (CWE-639). Apply the official Microsoft patch now: https://radar.offseq.com/threat/cve-2026-94510-cwe-639-authorization-bypass-through-user-controlled-key-in-microsoft-microsoft-bookings-0e362c50ebe161b6 #OffSeq #Microsoft #Vuln #CVE #Infosec
##updated 2026-10-09T00:31:56
1 posts
Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.
updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84058 - High (8.1)
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to a buffer overrun in the TDS (Microsoft SQL Server) PRELOGIN packet decoder. A remote attacker who can send a specially crafted TDS PRELOGIN packet to a network monitored by an IBM...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84058/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-84057 - High (8.1)
IBM Guardium Data Protection 12.2.2, and 12.1 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84057/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🔴 CVE-2026-84249 - Critical (9.8)
IBM Guardium Data Protection 12.2, and 12.2.2 could allow a remote attacker to execute arbitrary management operations due to missing authentication for critical function.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-84249/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-09T00:31:56
1 posts
🟠 CVE-2026-89091 - High (8.8)
A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection install`, the archive extractor validates member
paths using lexical path normalisation (os.path.abspath) instead of resolving
symbolic links (os.path.r...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-89091/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:34:48.800000
1 posts
🟠 CVE-2026-107782 - High (7.8)
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged APIs by connecting from any Authenticode-signed process. Attackers can load code into a Micr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107782/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🟠 CVE-2026-19482 - High (8.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of command arguments.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19482/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-16823 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass security restrictions due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16823/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-19491 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to bypass authentication due to improper authentication.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-19491/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-78406 - Critical (9.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78406/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:42
1 posts
🔴 CVE-2026-78401 - Critical (9.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote unauthenticated attacker to execute arbitrary code on the system due to the deserialization of untrusted data.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78401/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🟠 CVE-2026-18740 - High (8.8)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform unauthorized actions due to argument injection.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18740/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:33:41
1 posts
🔴 CVE-2026-16916 - Critical (9.1)
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to execute arbitrary code due to a protection mechanism failure.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16916/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T21:27:15.010000
1 posts
🔴 CVE-2026-107779 - Critical (9.8)
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a missing authentication vulnerability in bundled xxl-job-admin JobInfoController endpoints annotated with @PermissionLimit(limit = false). Unauthenticated attackers c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107779/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-10-08T20:08:45.857000
1 posts
SANS Stormcast Friday, October 9th, 2026: AI Agent Forensics; AI-Assisted Attack on South Korean Banks; IDN Typosquatting; Cisco Finesse SSRF (CVE-2026-20362)
https://isc.sans.edu/podcastdetail/10130
updated 2026-10-08T15:33:06
2 posts
🚨 Critical Ollama Vulnerability: CVE-2026-103663
A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure.
The vulnerability allows unauthenticated attackers to exploit a path traversal weakness in the model-pull functionality, potentially writing malicious files outside the intended model directory.
#SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement
##🚨 Critical Ollama Vulnerability: CVE-2026-103663
A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure.
The vulnerability allows unauthenticated attackers to exploit a path traversal weakness in the model-pull functionality, potentially writing malicious files outside the intended model directory.
#SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement
##updated 2026-10-08T04:16:55.397000
2 posts
🏆 New Achievement! The Keys to the Vault Were Under the Mat!
Magnificent. Truly, someone looked at a backup server — the one room that holds the skeleton keys to your entire infrastructure — and said, let's let low-privileged users knock it over. CVE-2025-64393 is a critical remote code execution flaw in Veeam Backup & Replication version 12, and it hands full control of the backup server to anyone with the Backup Viewer role. (1/3)
##Veeam Patches Critical Remote Code Execution Flaw in Backup & Replication Software
Veeam patched four vulnerabilities in Backup & Replication version 12, including a critical RCE flaw (CVE-2025-64393) that allows low-privileged users to take control of the backup server.
**If you use Veeam Backup & Replication version 12, update ASAP to 12.3.2 P4 (build 12.3.2.4934). Review and remove the Backup Viewer role from anyone who doesn't really need it, and keep your backup servers isolated from the rest of the network.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/veeam-patches-critical-remote-code-execution-flaw-in-backup-replication-software-9-s-8-u-1/gD2P6Ple2L
updated 2026-10-07T18:33:12
3 posts
Max severity SonicWall SMA1000 flaw now exploited in attacks
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days...
🔗️ [Bleepingcomputer] https://link.is.it/pvDc7j
##Tracked as CVE-2026-102255, the flaw affects the Appliance WorkPlace interface on SMA1000 6210, 7210, and 8200v models, but does not affect the SMA 100 Series product line or SSL-VPN running on SonicWall firewalls. https://www.bleepingcomputer.com/news/security/max-severity-sonicwall-sma1000-flaw-now-exploited-in-attacks/
##Attackers target a critical SonicWall SMA1000 vulnerability in the wild. Apply vendor hotfixes to secure remote access gateways against CVE-2026-102255.
##updated 2026-10-07T17:16:53.520000
4 posts
1 repos
⚠️ Un clic en un enllaç extern podia acabar amb el segrest de Telegram Desktop: una fallada IPC permetia llegir i exfiltrar fitxers locals. CVE-2026-107181; corregida a 7.2.9. Actualitza. #Telegram #Ciberseguretat https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
##https://thecybersecguru.com/exploits/telegram-desktop-cve-2026-107181/
##🚨 PoC released for Telegram Desktop account takeover vulnerability; CVE-2026-107181
https://beaksec.github.io/posts/telegram-desktop-one-click-account-takeover/
A vulnerability in Telegram Desktop allows attackers to steal local files, including session keys, by tricking users into opening a specially crafted tg:// link.
Stolen session data could allow attackers to hijack Telegram accounts without knowing the victim's password.
CVSS: 8.1 (High, v3.1) / 8.6 (High, v4.0)
Affected: Telegram Desktop before 7.2.9
Fixed: Version 7.2.9
The published PoC demonstrates how a malicious link can trigger file exfiltration through Telegram's IPC handler.
##A critical Telegram Desktop account takeover vulnerability (CVE-2026-107181) exposes users to session hijacking. Exploit details and PoC are now public.
#Telegram #Cybersecurity #CVE2026107181 #AccountTakeover #PoC
##updated 2026-10-07T13:17:22.273000
3 posts
12 repos
https://github.com/BimBoxH4/CVE-2026-21589
https://github.com/rxsklife/CVE-2026-21589
https://github.com/aduli198/CVE-2026-21589
https://github.com/watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589
https://github.com/tc4dy/CVE-2026-21589-PoC-Exploit
https://github.com/murrez/CVE-2026-21589
https://github.com/MarcusProgram/CVE-2026-21589
https://github.com/renzi25031469/CVE-2026-21589
https://github.com/gotr00t0day/CVE-2026-21589
https://github.com/webserverdude/f5_CVE-2026-21589_mitigation
🖲️ #Noticia de #CiberSeguridad #CiberGuerra #CiberAtaque #CiberNoticia
⚫ Exploit para falla crítica de Atlassian que permite acceso admin a Jira
🔗 http://blog.segu-info.com.ar/2026/10/exploit-para-falla-critica-de-atlassian.html
Se ha publicado un exploit de prueba de concepto para la vulnerabilidad
CVE-2026-21589, un fallo crítico de lectura arbitraria de archivos que afecta a varios
productos autogestionados de Atlassian. Esta vulnerabilidad puede exponer
archivos sensibles y, en
Hackers rapidly exploit the Atlassian vulnerability CVE-2026-21589. Learn how this critical flaw compromises Jira, Confluence, and Bitbucket security.
##You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/
##updated 2026-10-07T12:31:58
1 posts
1 repos
Explore the critical LMCache vulnerability CVE-2026-105192. Learn how insecure ZeroMQ configurations and Python pickle deserialization lead to RCE attacks.
##updated 2026-10-07T06:33:08
1 posts
1 repos
CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution
#CVE_2026_59346
https://socprime.com/blog/cve-2026-59346-analysis/
updated 2026-10-06T15:04:52.637000
2 posts
@wdormann ikr? Seems like VulDB has a template of sorts (its not exact, see e.g. the different phrasing in https://www.cve.org/CVERecord?id=CVE-2026-105141 ) that expects a function name which.. just doesn't make sense most of the time? And the followup part of the template
The manipulation of the argument $argname results in $cwe-friendly-name.
just never makes sense for hardcoded credentials? I have said it before, I should become a CNA of my own, doesn't seem to be THAT hard...
##@wdormann ikr? Seems like VulDB has a template of sorts (its not exact, see e.g. the different phrasing in https://www.cve.org/CVERecord?id=CVE-2026-105141 ) that expects a function name which.. just doesn't make sense most of the time? And the followup part of the template
The manipulation of the argument $argname results in $cwe-friendly-name.
just never makes sense for hardcoded credentials? I have said it before, I should become a CNA of my own, doesn't seem to be THAT hard...
##updated 2026-10-05T18:34:22
1 posts
HPE fixes a critical HPE iLO 7 vulnerability, CVE-2026-79820, and iMC authentication bypass CVE-2026-79842. Update iLO to 1.25.01 now.
#HPE #iLO #iMC #CVE202679820 #CVE202679842 #AuthBypass #ServerSecurity #Vulnerability
##updated 2026-10-04T09:30:21
5 posts
🏆 New Achievement! Stand in the Fire, Lose the Server!
EVERYONE STOP WHAT YOU ARE DOING. No — too late, they already got in. Huntress is calling it out in raid chat: threat actors are actively chaining CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup software to bypass authentication, inject OS commands, and land unauthenticated remote code execution with SYSTEM privileges. Webshells deployed. The party wiped.
The latest version, 10.3.4, is still affected. There is no patch. (1/2)
##⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…
🤖 AI generated summary
##Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec
https://cyberworldops.eu/en/huntress-ahsaycbs-bugs-cve-2026-105133-and-cve-2026-105134-exploited
##Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:
##Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.
Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers
Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.
**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-chain-ahsaycbs-vulnerabilities-to-deploy-webshells-and-cryptominers-o-j-b-o-b/gD2P6Ple2L
updated 2026-10-04T09:30:21
5 posts
1 repos
🏆 New Achievement! Stand in the Fire, Lose the Server!
EVERYONE STOP WHAT YOU ARE DOING. No — too late, they already got in. Huntress is calling it out in raid chat: threat actors are actively chaining CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup software to bypass authentication, inject OS commands, and land unauthenticated remote code execution with SYSTEM privileges. Webshells deployed. The party wiped.
The latest version, 10.3.4, is still affected. There is no patch. (1/2)
##⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…
🤖 AI generated summary
##Huntress reports active exploitation of AhsayCBS CVE-2026-105133 and CVE-2026-105134 chained for auth bypass and OS command execution. Attackers deploy web shells and XMRig miners, gaining persistence on backup servers. Patch and hunt for indicators. #AhsayCBS #ThreatIntel #InfoSec
https://cyberworldops.eu/en/huntress-ahsaycbs-bugs-cve-2026-105133-and-cve-2026-105134-exploited
##Huntress is reporting AhsayCBS CVE-2026-105133 and CVE-2026-105134 exploitation to drop web shells and XMRig cryptominer:
##Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.
Threat Actors Chain AhsayCBS Vulnerabilities to Deploy Webshells and Cryptominers
Threat actors are chaining two vulnerabilities in AhsayCBS (CVE-2026-105133 and CVE-2026-105134) to bypass authentication and gain remote code execution on backup servers.
**If you run AhsayCBS (any version up to and including 10.3.4), be aware it's actively exploited with no patch available. Immediately make sure that the management console is off the internet and allow access only from trusted IPs or over VPN. Then check for signs of compromise, such as unusual processes started by cbssvcX64.exe. If you find any, fully re-image the server from a clean backup.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/threat-actors-chain-ahsaycbs-vulnerabilities-to-deploy-webshells-and-cryptominers-o-j-b-o-b/gD2P6Ple2L
updated 2026-09-28T12:32:09
1 posts
8 repos
https://github.com/FollowerSeize/CVE-2026-88772-POC
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/technion/netscaler_scanner
https://github.com/murrez/CVE-2026-88772
https://github.com/emilstahl/pitscaler
https://github.com/securekomodo/citrixInspector
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88772
Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.
#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN
##updated 2026-09-28T12:32:08
2 posts
14 repos
https://github.com/watchtowrlabs/citrix-netscaler-cve-2026-88771-iocs
https://github.com/EXEcution-py/CVE-2026-88771-POC
https://github.com/orjanj/netscaler_threat_hunt_helper
https://github.com/bkchaudhari/NetScaler-CTX697096-Assessment-Script
https://github.com/technion/netscaler_scanner
https://github.com/emilstahl/pitscaler
https://github.com/securekomodo/citrixInspector
https://github.com/techupdate24/citrix-netscaler-cve-2026-88771-rce
https://github.com/ThomasPoppelgaard/netscaler-ctx697096-checker
https://github.com/LETHAL-FORENSICS/Get-NetScalerTimeline
https://github.com/grupooruss/netscaler-defensive-checker
https://github.com/craigsblackie/cve-2026-88771-netscaler
https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-CVE-2026-88771
Riasztás: kritikus, aktívan kihasznált CVE-2026-88771 és CVE-2026-88772 sebezhetőségek érintik a NetScaler ADC/Gateway eszközöket. Telepítetted már az ajánlott javításokat, és gondoltál rá, hogy korábbi kompromittálódás miatt vizsgálatot indíts? A cikkben megtalálod a frissített kiadásokat és a javasolt teendőket.
#NetScaler #NetScalerADC #NetScalerGateway #CVE2026-88771 #CVE2026-88772 #Citrix #kiberbiztonság #patch #frissítés #CISA #VPN
##@GossiTheDog Meanwhile I've updated my Citrix honeypot to handle CVE-2026-88771 - but so far have seen absolutely no attacks. I'll run some tests later today to check if it doesn't miss them due to some kind of bug.
Visualization (empty so far):
##updated 2026-09-25T13:37:47.870000
1 posts
CVE-2026-25264 Qualcomm DLL hijacking, privilege escalation via weak package extraction config. CVSS 8.8. No patch yet. Audit your systems now. https://www.valtersit.com/cve/CVE-2026-25264/ #CVE #infosec #Qualcomm
##updated 2026-09-25T13:37:41.860000
1 posts
CVE-2026-25254 Qualcomm improper auth leads to RCE via SocketIO. CVSS 9.8, patch status unknown. Treat as unpatched and restrict exposure now. https://www.valtersit.com/cve/CVE-2026-25254/ #CVE #infosec #Qualcomm
##updated 2026-09-24T21:25:27.050000
1 posts
CVE-2026-62866 Dasel 3.0.0-3.11.2 (CVSS 6.2): a selector ending in whitespace passes an unchecked index in parseCurRune, causing an out-of-range panic that kills the process. Denial of service. Patched in 3.11.2, update now. https://www.valtersit.com/cve/CVE-2026-62866/ #CVE #infosec #Dasel
##updated 2026-09-24T09:32:00
2 posts
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
##updated 2026-09-23T14:32:12.417000
1 posts
CVE-2026-93952 Arista VeloCloud Orchestrator on-prem: remote attacker can reach privileged internal functionality, full CIA impact. CVSS 10. Patch under review; hosted already fixed. Patch now: https://www.valtersit.com/cve/CVE-2026-93952/ #CVE #infosec #Arista
##updated 2026-09-22T19:41:38.447000
1 posts
CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. https://www.valtersit.com/cve/CVE-2026-85219/ #CVE #infosec #cybersecurity
##updated 2026-09-22T06:30:35
1 posts
1 repos
CVE-2026-19658: PHP Object Injection in GiveWP Give Tributes plugin, all versions up to 2.3.1. CVSS 9.8, unauthenticated. No patch yet - remove the plugin or update immediately.
https://www.valtersit.com/cve/CVE-2026-19658/
#CVE #WordPress #infosec
updated 2026-09-22T06:30:35
1 posts
1 repos
CVE-2026-13355 Meta Box AIO for WordPress privilege escalation to admin, CVSS 9.8, unpatched. No fix available yet - restrict plugin access now. https://www.valtersit.com/cve/CVE-2026-13355/ #CVE #WordPress #infosec
##updated 2026-09-18T06:32:17
1 posts
4 repos
https://github.com/HORKimhab/CVE-2026-93485
https://github.com/DeathShotXD/Comment2Shell
Ataki na strony WordPress chwilę po wydaniu poprawki
17 września 2026 r. WordPress wydał wersję 7.1.1, w której załatano dwie podatności – kojarzone jako Click2Shell i Comment2Shell (CVE-2026-93485). To jednak dopiero początek historii. Kilka dni później – 22 września – wydano wersję 7.1.2 łatającą kolejną podatność. Atakujący nie czekali jednak na publikację jej szczegółów – wszystko wskazuje na...
#WBiegu #Podatność #Rce #Wordpress
https://sekurak.pl/ataki-na-strony-wordpress-chwile-po-wydaniu-poprawki/
##updated 2026-09-14T00:16:56.777000
2 posts
2 repos
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
##updated 2026-09-10T06:31:55
1 posts
Palo Alto has a a long list of advisories, addressing at least two critical vulnerabilities, among others: https://security.paloaltonetworks.com/
CRITICAL: CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing https://security.paloaltonetworks.com/CVE-2026-0310
CRITICAL: PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) https://security.paloaltonetworks.com/PAN-SA-2026-0012
- Tenable Research Advisories:
HIGH: Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion https://www.tenable.com/security/research/tra-2026-65
There are also two WordPress vulnerabilities and a few others here https://www.tenable.com/security/research #WorPress
- Microsoft:
In case you missed this, Microsoft posted quite a few patches yesterday https://msrc.microsoft.com/update-guide #infosec #vulnerability #Microsofot #Azure #Linux
##updated 2026-09-09T00:31:34
1 posts
Discover the details of the Windows Cloud Files Driver vulnerability, CVE-2026-80093. Learn how this flaw in cldflt.sys affects kernel privileges.
#WindowsSecurity #CVE202680093 #CyberSecurity #Microsoft #TechNews
##updated 2026-09-08T21:11:56.250000
2 posts
The issue now is: Ceph 20 is still on an older NFS Ganesha version which hasn't got the fix yet. Ceph 21 does have the fix, but it also has the fix for this CVE: https://medium.com/rook-io/rook-advisory-for-ceph-cve-2025-30156-cc1f8dee6da3
And this CVE fix, in turn, only works with kernels > 7.0. Which means I'm currently in a bit of a deadlock. I can't really update my hosts to the newer Ubuntu, because of the Ganesha bug. But I also can't update Ceph/Ganesha because I need a newer kernel.
##The issue now is: Ceph 20 is still on an older NFS Ganesha version which hasn't got the fix yet. Ceph 21 does have the fix, but it also has the fix for this CVE: https://medium.com/rook-io/rook-advisory-for-ceph-cve-2025-30156-cc1f8dee6da3
And this CVE fix, in turn, only works with kernels > 7.0. Which means I'm currently in a bit of a deadlock. I can't really update my hosts to the newer Ubuntu, because of the Ganesha bug. But I also can't update Ceph/Ganesha because I need a newer kernel.
##updated 2026-09-08T14:09:00.860000
1 posts
🚨🚨🚨 Did AMD and/or Gigabyte intentionally or unintentionally just make local "AI" models available to a lot more people?
I have an old AM4 Gigabyte GA-AX370-Gaming 5 motherboard with a 6 core 5600G processor in it. Gigabyte released a new BIOS for that motherboard on September 3rd 2026. Changelog story is that version F54d is a "Fix AMD TPM Reference Code Errata (CVE-2026-6726, CVE-2026-6727)"
https://www.gigabyte.com/Motherboard/GA-AX370-Gaming-5-rev-10/support#Support-Bios
I updated the motherboard to the shiny new F54d BIOS and it re-set the BIOS settings. This is annoying but not unusual when upgrading a BIOS. Thus, I had to poke around in the BIOS in order to restore my previous preferences and that's when I noticed something new that's not indicated in the changelog:
The area of the BIOS where you can choose how much RAM should be assigned to the integrated graphics part of the CPU (if you have one with integrated graphics) goes all the way up to 16 GB in BIOS F54d. The max used to be 2 GB, I've never seen any BIOS where you could assign more than 2 GB to the iGPU/APU.
I tried assigning 8GB to the 5600G in the BIOS and then I tried running the Q3_K_M version of the Kreamagine Krea 2 Turbo checkpoint on it. Krea 2 is a image generation model, so horsepower matters more than it does if you run some LLM. I didn't expect it to run very fast, but I was curious if it would run at all since that was previously not possible when the max assigned GPU RAM was limited to 2 GB.
Kreamagine Q3_K_M did run and I got a awfully slow 29.35 seconds per iteration. For context, the RX 6600 runs that model at around 4.93s/it. Half a minute times 10 iterations (what you ideally want for Krea 2 Turbo models) works out to 5 minutes compared to 50 seconds using the RX 6600. That's quite the execution time just to get an image resembling "1girl, confused, using computer running ai app, glasses, blond hair, tight shirt". You're not going to get lightning fast execution if you assign more RAM to GPU integrated in a CPU, but the more important detail is that it actually works.
WHY I THINK THIS IS SO COOL: If you have a now nearly 10 year old computer with an AMD CPU with integrated graphics and 16 or 32 GB DDR4 bought back when it was less than half of today's price then you're now able to assign 8 or 16 GB RAM to the graphics part of the CPU and use that to do a whole range of useful things like as offloading an image models text encoder if you have some older graphics card like a RX 6600 with only 8 GB VRAM.
It's not like I bought anything new or expected to get this new feature. I just updated the BIOS and unexpectedly got the ability to assign up to 16 GB VRAM to the integrated graphics chip. If you have some old AM4 board with a G series CPU and you play around with local models then you should see if there is a new BIOS for your board that may or may not give you the ability to bump the iGPUs memory from 2 to 16 GB.
##updated 2026-09-08T14:09:00.860000
1 posts
4 repos
https://github.com/HORKimhab/CVE-2026-67276
https://github.com/shmaki4/CVE-2026-67279-Mikrotik-6.42-POC
🚨🚨🚨 Did AMD and/or Gigabyte intentionally or unintentionally just make local "AI" models available to a lot more people?
I have an old AM4 Gigabyte GA-AX370-Gaming 5 motherboard with a 6 core 5600G processor in it. Gigabyte released a new BIOS for that motherboard on September 3rd 2026. Changelog story is that version F54d is a "Fix AMD TPM Reference Code Errata (CVE-2026-6726, CVE-2026-6727)"
https://www.gigabyte.com/Motherboard/GA-AX370-Gaming-5-rev-10/support#Support-Bios
I updated the motherboard to the shiny new F54d BIOS and it re-set the BIOS settings. This is annoying but not unusual when upgrading a BIOS. Thus, I had to poke around in the BIOS in order to restore my previous preferences and that's when I noticed something new that's not indicated in the changelog:
The area of the BIOS where you can choose how much RAM should be assigned to the integrated graphics part of the CPU (if you have one with integrated graphics) goes all the way up to 16 GB in BIOS F54d. The max used to be 2 GB, I've never seen any BIOS where you could assign more than 2 GB to the iGPU/APU.
I tried assigning 8GB to the 5600G in the BIOS and then I tried running the Q3_K_M version of the Kreamagine Krea 2 Turbo checkpoint on it. Krea 2 is a image generation model, so horsepower matters more than it does if you run some LLM. I didn't expect it to run very fast, but I was curious if it would run at all since that was previously not possible when the max assigned GPU RAM was limited to 2 GB.
Kreamagine Q3_K_M did run and I got a awfully slow 29.35 seconds per iteration. For context, the RX 6600 runs that model at around 4.93s/it. Half a minute times 10 iterations (what you ideally want for Krea 2 Turbo models) works out to 5 minutes compared to 50 seconds using the RX 6600. That's quite the execution time just to get an image resembling "1girl, confused, using computer running ai app, glasses, blond hair, tight shirt". You're not going to get lightning fast execution if you assign more RAM to GPU integrated in a CPU, but the more important detail is that it actually works.
WHY I THINK THIS IS SO COOL: If you have a now nearly 10 year old computer with an AMD CPU with integrated graphics and 16 or 32 GB DDR4 bought back when it was less than half of today's price then you're now able to assign 8 or 16 GB RAM to the graphics part of the CPU and use that to do a whole range of useful things like as offloading an image models text encoder if you have some older graphics card like a RX 6600 with only 8 GB VRAM.
It's not like I bought anything new or expected to get this new feature. I just updated the BIOS and unexpectedly got the ability to assign up to 16 GB VRAM to the integrated graphics chip. If you have some old AM4 board with a G series CPU and you play around with local models then you should see if there is a new BIOS for your board that may or may not give you the ability to bump the iGPUs memory from 2 to 16 GB.
##updated 2026-09-08T09:36:36
1 posts
100 repos
https://github.com/gagaltotal/cve-2026-31431-copy-fail
https://github.com/Qengineering/RK35xx-CopyFail-Hotfix
https://github.com/haydenjames/CVE-2026-31431-check
https://github.com/mrunalp/block-copyfail
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Kubernetes-PoC
https://github.com/liamromanis101/CVE-2026-31431-Copy-Fail---Vulnerability-Detection-Script
https://github.com/ben-slates/CVE-2026-31431-Exploit
https://github.com/Sl4cK0TH/CVE-2026-31431-PoC
https://github.com/ErdemOzgen/copy-fail-cve-2026-31431
https://github.com/adityasingh108/CVE-2026-31431-Metasploit-exploit
https://github.com/pedromizz/copy-fail
https://github.com/MrAriaNet/cPanel-Fix
https://github.com/MartinPham/copy-fail-CVE-2026-31431-php
https://github.com/jbnetwork-git/copy-fail-check
https://github.com/diemoeve/copyfail-rs
https://github.com/rvzsec/CVE-2026-31431
https://github.com/Boos4721/copyfail-rs
https://github.com/Xerxes-2/CVE-2026-31431-rs
https://github.com/bootsareme/copyfail-deconstructed
https://github.com/bigwario/copy-fail-CVE-2026-31431-C
https://github.com/XsanFlip/CVE-2026-31431-Patch
https://github.com/Dullpurple-sloop726/CVE-2026-31431-Linux-Copy-Fail
https://github.com/sgkdev/page_inject
https://github.com/cs8425/copy-fail-go
https://github.com/TheMalwareGuardian/CVE-2026-31431
https://github.com/shadowabi/CVE-2026-31431-CopyFail-Universal-LPE
https://github.com/SeanRickerd/cve-2026-31431
https://github.com/xeloxa/copyfail-exploit
https://github.com/desultory/CVE-2026-31431
https://github.com/rootsecdev/cve_2026_31431
https://github.com/st4rburn/public-passwd
https://github.com/wgnet/wg.copyfail.patch
https://github.com/g1nt0n1x/copy-fail-CVE-2026-31431-shell
https://github.com/aestechno/cve-2026-31431-ansible
https://github.com/iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail
https://github.com/b5null/CVE-2026-31431-C
https://github.com/ZephrFish/CopyFail-CVE-2026-31431
https://github.com/atgreen/block-copyfail
https://github.com/tgies/copy-fail-c
https://github.com/sammwyy/copyfail-rs
https://github.com/cozystack/copy-fail-blocker
https://github.com/philfry/cve-2026-31431-ftrace
https://github.com/yuspring/cve-2026-31431-poc
https://github.com/ExploitEoom/CVE-2026-31431
https://github.com/samanzamani/copy-fail-checker
https://github.com/Percivalll/Copy-Fail-CVE-2026-31431-Statically-PoC
https://github.com/sudoytang/copyfail-arm64
https://github.com/painoob/Copy-Fail-Exploit-CVE-2026-31431
https://github.com/Iamliuxiaozhen/copy_fail
https://github.com/Huchangzhi/autorootlinux
https://github.com/cyber-joker/copy-fail-python
https://github.com/EynaExp/Copy-Fail-CVE-2026-31431-modernized
https://github.com/guiimoraes/CVE-2026-31431
https://github.com/KaraZajac/DIRTYFAIL
https://github.com/Smarttfoxx/copyfail
https://github.com/abdullaabdullazade/CVE-2026-31431
https://github.com/malwarekid/CVE-2026-31431
https://github.com/Sndav/CVE-2026-31431-Advanced-Exploit
https://github.com/yandex-cloud-examples/yc-mk8s-copy-fail-mitigation
https://github.com/st4rburn/RootRemover
https://github.com/TrevoCastles/CVE-2026-31431-copy-fail
https://github.com/badsectorlabs/copyfail-go
https://github.com/JuanBindez/CVE-2026-31431
https://github.com/kadir/copy-fail-CVE-2026-31431-IOC
https://github.com/KanbaraAkihito/CVE-2026-31431-copyfail-rs
https://github.com/infiniroot/ansible-mitigate-copyfail-dirtyfrag
https://github.com/lonelyor/CVE-2026-31431-exp
https://github.com/Alfredooe/CVE-2026-31431
https://github.com/erlangparasu/mitigate_cve_2026_31431-sh
https://github.com/beatbeast007/Linux-CopyFail-C-Version-CVE-2026-31431
https://github.com/luotian2/CVE-2026-31431
https://github.com/pascal-gujer/CVE-2026-31431
https://github.com/ZeroDayEvil/CVE-2026-31431
https://github.com/AliHzSec/CVE-2026-31431
https://github.com/Webhosting4U/Copy-Fail_Detect_and_mitigate_CVE-2026-31431
https://github.com/novysodope/copy-fail-CVE-2026-31431-C
https://github.com/adampielak/CVE-2026-31431_SCA_WAZUH
https://github.com/nisec-eric/cve-2026-31431
https://github.com/kinryulabs/rootpacket-cve-2026-31431
https://github.com/0xBlackash/CVE-2026-31431
https://github.com/ochebotar/copy-fail-CVE-2026-31431-detection-probe
https://github.com/Juguitos/copy-fail
https://github.com/Dabbleam/CVE-2026-31431-mitigation
https://github.com/pyroceper/copy-fail-CVE-2026-31431
https://github.com/sgkdev/ptrace_may_dream
https://github.com/theori-io/copy-fail-CVE-2026-31431
https://github.com/AdityaBhatt3010/CVE-2026-31431
https://github.com/povzayd/CVE-2026-31431
https://github.com/qi4L/CVE-2026-31431-Container-Escape
https://github.com/wesmar/CVE-2026-31431
https://github.com/Shotafry/CopyFail-Exploits-CVE-2026-31431
https://github.com/wuwu001/CVE-2026-31431-exploit
https://github.com/sec17br/CVE-2026-31431-Copy-Fail
https://github.com/0xShe/CVE-2026-31431
https://github.com/JnamerZ/CopyFail-CVE-2026-31431
https://github.com/mahdi13830510/CVE-2026-31431-mitigation-suite
https://github.com/Crihexe/copy-fail-tiny-elf-CVE-2026-31431
https://github.com/4xura/CVE-2026-31431-Copy-Fail
https://github.com/hans362/CVE-2026-31431-Copy-Fail-Container-Escape
This article examines why Copy Fail (CVE-2026-31431) breaks container assumptions and provides a small, safe Python check to determine whether your nodes can reach the vulnerable kernel path
##updated 2026-08-31T21:31:56
2 posts
2 repos
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
#PaperCutNG #PaperCutMF #CVE_2026_82077 #CVE_2026_82078 #CVE_2026_81578
https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs https://labs.watchtowr.com/death-by-a-thousand-papercuts-papercut-pre-auth-rce-chain-and-patch-bypasses-wt-2026-0141-0144-cve-2026-82077-cve-2026-82078-cve-2026-81578/
##updated 2026-08-28T18:31:00
1 posts
5 repos
https://github.com/Bhanunamikaze/BadHost-CVE-2026-48710-Exploit
https://github.com/sb-ox/repro-OXDEV-77637-uv-workspace
https://github.com/CuteeCat/CVE-2026-48710
We have published our writeup about the discovery and details of the #BadHost vulnerability (CVE-2026-48710) at https://x41-dsec.de/lab/research/2026/10/07/badhost/
##updated 2026-08-24T13:19:17.577000
1 posts
10 repos
https://github.com/dahnutz/zimbra-cve-2026-73570-ir
https://github.com/hainhc/CVE-2026-73570
https://github.com/alsyundawy/eradicate-zimbra-malware
https://github.com/0xBlackash/CVE-2026-73570
https://github.com/juanpoch/CVE-2026-73570
https://github.com/HORKimhab/CVE-2026-73570
https://github.com/BiuTrap/CVE-2026-73570
https://github.com/jishino567/CVE-2026-73570
----------------
🎯 Threat Intelligence
===================
Microsoft Threat Intelligence tracks CVE-2026-73570: unauthenticated command injection on internet-facing Zimbra mail servers
Microsoft Threat Intelligence published an analysis of CVE-2026-73570, described as an unauthenticated command injection vulnerability exploited in Zimbra on internet-facing mail servers. The post documents observed attack paths, detection opportunities, and mitigation guidance. The digest available here is thin, so this write-up keeps what the source states separate from general class context and flags everything the digest does not state.
🔹 Executive Summary
• CVE-2026-73570 is an unauthenticated command injection vulnerability in Zimbra.
• Exploitation observed in the wild, per Microsoft Threat Intelligence.
• Exposure model: internet-facing mail servers, no authentication required.
• The same post carries detection opportunities and mitigation guidance.
🔹 Technical Details
What the source states:
• Vulnerability class: command injection
• Authentication: none (pre-auth)
• Exposure: internet-facing mail servers
• Affected product: Zimbra
• Publisher and date: Microsoft Threat Intelligence, September 30, roughly a 20-minute read
Not stated in the digest: affected versions, CVSS score, CWE mapping, specific IOCs, named actor, ATT&CK mappings. Treat all of that as unconfirmed until the full post is read.
🔹 Analysis
Class context, not a source claim: pre-auth command injection on an internet-facing mail server is close to the worst property combination a CVE can carry. No credential barrier, no user interaction, and the target sits on the public edge. Mail hosts also concentrate mailbox contents, credentials in authentication flows, and internal trust relationships, which makes a pre-auth path on the edge a practical pivot for follow-on activity. Zimbra has a history as a target of mass exploitation campaigns on earlier CVEs; that is general background relevant to prioritization, not a claim from the current post.
🔹 Attack Chain Analysis
Only the entry step is confirmed by the digest:
1. Initial Access: unauthenticated exploitation of CVE-2026-73570 against an internet-facing Zimbra instance.
2. Post-exploitation: the original post describes observed attack paths, but the digest does not enumerate stages beyond initial access. Do not assume a specific chain from this summary.
🔹 Detection
The source says the post includes detection opportunities, but the digest does not contain the actual queries. Reasonable starting hypotheses for a command injection scenario on a mail host: unexpected process spawns from mail service modules, unusual outbound connections originating from the mail server itself, and anomalous request patterns in web access logs aimed at service and admin endpoints. Treat these as hypotheses to validate against the full post, not verified signatures.
🔹 Mitigation
• The post publishes specific mitigation guidance, so apply it from the source directly.
• Interim hygiene: confirm patch status on every internet-facing Zimbra instance, trim unnecessary internet exposure, and test the detection hypotheses above against existing logs.
🔹 Source Note
The feed item also carried the headline "3 lessons from frontier AI vulnerability research" with no body content, so it is not covered here.
🔹 References
• Microsoft Threat Intelligence post: "Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570", September 30
• CVE-2026-73570
🔹 CVE202673570 #Zimbra #ThreatIntelligence #CommandInjection #MailServers
##updated 2026-08-12T15:18:30.347000
1 posts
10 repos
https://github.com/EQSTLab/CVE-2026-72898
https://github.com/4minx/CVE-2026-72898
https://github.com/ubitquity/Metabase-Setup-Endpoint-SQLi-Fix
https://github.com/VuxNx/CVE-2026-72898
https://github.com/d-maggipinto/CVE-2026-72898-metabase-sqli
https://github.com/34zY/CVE-2026-72898
https://github.com/codeb0ssx/CVE-2026-72898-PoC
https://github.com/amier-ge/CVE-2026-72898
直近で相次いでいる国内組織における不正アクセスに関する注意喚起 https://www.jpcert.or.jp/m/at/2026/at260030.html 2026-10-08
JPCERT/CCに寄せられた情報などでは:
ケースA:...既知の脆弱性を探索し攻撃試行するもの
ケースB:API経由での不正な操作
ケースC:MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)
ケースBの場合:
(a)一般公開しているスマートフォンアプリを解析しAPIのエンドポイントやキーを特定する
(b)本来画面操作では実行できない内部APIに対する攻撃
(c)他のシステムの侵害で窃取したAPIキーを使用する
updated 2026-07-28T18:33:11
1 posts
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) https://lava.security/research/cve-2026-47483-nvidia-dcgm-exporter-vulnerability
##updated 2026-06-17T09:28:43.993000
1 posts
@briankrebs Every Flock CVE in existence (CVE-2025-47818 through -47824) came through MITRE off Jon Gaines' 2025 research, before Flock had any say in the numbering. The "outside parties requesting CVE IDs before a fix is ready" line reads like a reference to that.
As for who decides what's a bug, they've answered in writing. The new VDP gives Flock 120 days to publish, with an exception for anything it deems a "material safety risk to law enforcement or the public." Their advisories page lists nothing, two weeks after a pentest write-up with 2 criticals and 7 highs that Flock says needed no customer action, which is exactly the kind of finding a vendor CNA can decline to number. So yes, Flock decides now. The criteria just live on a legal page instead of a press release.
##updated 2026-06-17T09:10:00.550000
1 posts
4 repos
https://github.com/hunters-sec/CVE-2025-31200
https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201
https://github.com/zhuowei/apple-positional-audio-codec-invalid-header
https://github.com/serundengsapi/CVE-2025-31200-iOS-AudioConverter-RCE
iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword
https://cyberworldops.eu/en/p7-darksword-ios-variant-steals-crypto-wallets-and-accepts-remote
##updated 2026-06-17T08:58:17.950000
1 posts
3 repos
https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201
https://github.com/The-Maxu/CVE-2025-24201-WebKit-Vulnerability-Detector-PoC-
https://github.com/5ky9uy/glass-cage-i18-2025-24085-and-cve-2025-24201
iVerify reports a P7 DarkSword iOS variant combining crypto-wallet theft with remote command execution. It chains CVE-2025-24201 and CVE-2025-31200, both CISA KEV-listed, enabling persistent device control. Patching and wallet-device isolation are critical. #IosSecurity #CryptoTheft #DarkSword
https://cyberworldops.eu/en/p7-darksword-ios-variant-steals-crypto-wallets-and-accepts-remote
##updated 2026-06-09T12:32:02
2 posts
8 repos
https://github.com/tushargurav28/CVE-2026-0257
https://github.com/akashsingh0454/CVE-2026-0257-PoC
https://github.com/sfewer-r7/CVE-2026-0257
https://github.com/grayxploit/CVE-2026-0257
https://github.com/Mr-Robot-LP/CVE-2026-0257
https://github.com/HORKimhab/CVE-2026-0257
🚨 Ransomware gangs are exploiting a flaw in Palo Alto Networks GlobalProtect VPN to bypass authentication and gain unauthorized network access.
⚠️ CVE-2026-0257
🔴 Qilin & Settra named in reports
🛡️ Patch, audit VPN logs, hunt for suspicious access.
Your VPN could be the way in.
Full breakdown 👇
https://thecybersecguru.com/news/cve-2026-0257-globalprotect-vpn-ransomware/
https://thecybersecguru.com/news/cve-2026-0257-globalprotect-vpn-ransomware/
##updated 2024-03-29T18:30:50
1 posts
90 repos
https://github.com/stevehenderson/lab_xz_backdoor
https://github.com/HackerHermanos/CVE-2024-3094_xz_check
https://github.com/zpxlz/CVE-2024-3094
https://github.com/amlweems/xzbot
https://github.com/hariskhalil555000-sketch/What-utility-does-CVE-2024-3094-refer-to-
https://github.com/ThomRgn/xzutils_backdoor_obfuscation
https://github.com/been22426/CVE-2024-3094
https://github.com/ScrimForever/CVE-2024-3094
https://github.com/robertdfrench/ifuncd-up
https://github.com/harekrishnarai/xz-utils-vuln-checker
https://github.com/Horizon-Software-Development/CVE-2024-3094
https://github.com/0xBlackash/CVE-2024-3094
https://github.com/Titus-soc/-CVE-2024-3094-Vulnerability-Checker-Fixer-Public
https://github.com/x-cmd-build/xz
https://github.com/vesjolyjd/Kaspersky_CVE-2024-3094
https://github.com/brinhosa/CVE-2024-3094-One-Liner
https://github.com/ykhurshudyan-blip/CVE-2024-3094
https://github.com/neuralinhibitor/xzwhy
https://github.com/mightysai1997/CVE-2024-3094-info
https://github.com/namegabevictoire01-sys/cs50-cybersecurity-final-project
https://github.com/weltregie/liblzma-scan
https://github.com/0xlane/xz-cve-2024-3094
https://github.com/bioless/xz_cve-2024-3094_detection
https://github.com/mightysai1997/CVE-2024-3094
https://github.com/encikayelwhitehat-glitch/CVE-2024-3094
https://github.com/Michel-DV/xz-utils-backdoor-case-study
https://github.com/michalAshurov/writeup-CVE-2024-3094
https://github.com/emirkmo/xz-backdoor-github
https://github.com/fevar54/Detectar-Backdoor-en-liblzma-de-XZ-utils-CVE-2024-3094-
https://github.com/OpensourceICTSolutions/xz_utils-CVE-2024-3094
https://github.com/lypd0/CVE-2024-3094-Vulnerabity-Checker
https://github.com/BOSE122/CVE-2024-3094
https://github.com/ElinaNotElina/cve-2024-3094-analysis
https://github.com/h3raklez/CVE-2024-3094
https://github.com/TheTorjanCaptain/CVE-2024-3094-Checker
https://github.com/AndreaCicca/Sicurezza-Informatica-Presentazione
https://github.com/pentestfunctions/CVE-2024-3094
https://github.com/badsectorlabs/ludus_xz_backdoor
https://github.com/hackingetico21/revisaxzutils
https://github.com/devjanger/CVE-2024-3094-XZ-Backdoor-Detector
https://github.com/Preacher98/Report-XZ-Utils-CVE-2024-3094
https://github.com/bsekercioglu/cve2024-3094-Checker
https://github.com/Ikram124/CVE-2024-3094-analysis
https://github.com/jfrog/cve-2024-3094-tools
https://github.com/przemoc/xz-backdoor-links
https://github.com/gensecaihq/CVE-2024-3094-Vulnerability-Checker-Fixer
https://github.com/laxmikumari615/Linux---Security---Detect-and-Mitigate-CVE-2024-3094
https://github.com/mhicairo-hue/cs50-cybersecurity-final-project
https://github.com/mesutgungor/xz-backdoor-vulnerability
https://github.com/FabioBaroni/CVE-2024-3094-checker
https://github.com/hackura/xz-cve-2024-3094
https://github.com/24Owais/threat-intel-cve-2024-3094
https://github.com/hazemkya/CVE-2024-3094-checker
https://github.com/teyhouse/CVE-2024-3094
https://github.com/mrk336/CVE-2024-3094
https://github.com/MrBUGLF/XZ-Utils_CVE-2024-3094
https://github.com/lockness-Ko/xz-vulnerable-honeypot
https://github.com/wgetnz/CVE-2024-3094-check
https://github.com/byinarie/CVE-2024-3094-info
https://github.com/ashwani95/CVE-2024-3094
https://github.com/Yuma-Tsushima07/CVE-2024-3094
https://github.com/Simplifi-ED/CVE-2024-3094-patcher
https://github.com/buluma/ansible-role-cve_2024_3094
https://github.com/iheb2b/CVE-2024-3094-Checker
https://github.com/ackemed/detectar_cve-2024-3094
https://github.com/Juul/xz-backdoor-scan
https://github.com/Fractal-Tess/CVE-2024-3094
https://github.com/valeriot30/cve-2024-3094
https://github.com/extracoding-dozen/CVE-2024-3094
https://github.com/spidygal/CVE-2024-3094-Nmap-NSE-script
https://github.com/MagpieRYL/CVE-2024-3094-backdoor-env-container
https://github.com/M1lo25/CS50FinalProject
https://github.com/Security-Phoenix-demo/CVE-2024-3094-fix-exploits
https://github.com/robertdebock/ansible-playbook-cve-2024-3094
https://github.com/vnchk1/sec_review_cve-2024-3094
https://github.com/felipecosta09/cve-2024-3094
https://github.com/gustavorobertux/CVE-2024-3094
https://github.com/Dermot-lab/TryHack
https://github.com/dah4k/CVE-2024-3094
https://github.com/robertdebock/ansible-role-cve_2024_3094
https://github.com/shefirot/CVE-2024-3094
https://github.com/Bella-Bc/xz-backdoor-CVE-2024-3094-Check
https://github.com/Ava-Vispilio/CVE-2024-3094
https://github.com/isuruwa/CVE-2024-3094
https://github.com/r0binak/xzk8s
https://github.com/Mustafa1986/CVE-2024-3094
https://github.com/nnatsopoulos/xz-backdoor-research
https://github.com/KaminaDuck/ansible-CVE-2024-3094
https://github.com/galacticquest/cve-2024-3094-detect
https://github.com/jbnetwork-git/CVE-2024-3094-XZ-Utils-Check
An analysis by a Redditor, published on sheets.works, counted regular contributors on 23 core open source projects and found 11 had only one or two in the past year. xz, which shipped a backdoor in 2024 (CVE-2024-3094), again has one: Lasse Collin wrote 97 percent of its 2025 changes, and the analysis found no new funding. Eight projects, including SQLite, zlib and bash, show no grant from four named funders.
https://linuxstans.com/11-of-23-core-open-source-projects-run-on-1-or-2-people/
##1 posts
27 repos
https://github.com/bhideki/CVE-2026-87902
https://github.com/crowsec-edtech/CVE-2026-87902
https://github.com/vulpecuna/CVE-2026-87902
https://github.com/ynsmroztas/WPSniper
https://github.com/xiaxiu555/cve-2026-87902
https://github.com/Lutfifakee-Project/CVE-2026-87902
https://github.com/oliveiralimajr/CVE_2026_87902
https://github.com/zyphorixofficialmain-lab/cve-2026-87902
https://github.com/nextco/wordpress-cve-2026-87902
https://github.com/abatsakidis/wp-cve-2026-87902-checker
https://github.com/tonydelouvre/CVE-2026-87902
https://github.com/tc4dy/CVE-2026-87902-Toolkit
https://github.com/pwnVader/CVE-2026-87902-PoC-pwnVader
https://github.com/zer0dayf/CVE-2026-87902
https://github.com/MRdark-ops/CVE-2026-87902
https://github.com/ressl/cve-2026-87902-poc
https://github.com/itskill-jp/wordpress-upgrade-check
https://github.com/abraxas/CVE-2026-87902
https://github.com/Maalfer/CVE-2026-87902-exploit
https://github.com/HackfutSecRoot/CVE-2026-87902
https://github.com/rwxrwxs/CVE-2026-87902
https://github.com/SVTagan/WP-CVE-2026-87902
https://github.com/rabakuku/CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal
https://github.com/dinosn/cve-2026-87902-wordpress-lfi-lab
https://github.com/joaovicdev/EXPLOIT-CVE-2026-87902
Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.
https://linuxmint.hu/hir/2026/10/riasztas-a-wordpress-core-t-erinto-serulekenysegrol
#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság
##CVE-2026-108269 (CRITICAL, CVSS 9.1): Privasys ra-tls-clients <0.5.0 origin validation error lets attackers relay attestation quotes, compromising TLS trust. Upgrade to 0.5.0+ now. https://radar.offseq.com/threat/cve-2026-108269-cwe-346-origin-validation-error-in-privasys-ra-tls-clients-1e6de81a7e6f2eb8 #OffSeq #CVE2026108269 #Rust #Go #TLS
##🟠 CVE-2026-92705 - High (7.8)
Aegisub is a cross-platform advanced subtitle editor. From 3.2.0 to 3.4.2, Aegisub automatically loads Automation scripts referenced by `Automation Scripts` metadata in `ASS` subtitle projects without asking whether the user trusts the scripts or ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-92705/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107821 - High (8)
MariaDB server is a community developed fork of MySQL server. From 10.6.1 until 10.6.28, 10.11.19, 11.4.13, 11.8.9, 12.3.3, and 13.0.2, MariaDB insufficiently validated counts, offsets, lengths, and field boundaries in FRM metadata while opening b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107821/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107838 - High (7.5)
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107838/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-107837 - High (8.2)
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-107837/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-61746 InvenTree: unauthenticated info disclosure via plugin settings API before 1.4.0. CVSS 5.3. Patch under review - restrict API access now. https://www.valtersit.com/cve/CVE-2026-61746/ #CVE #infosec
##