🚨 FreeIPMI Critical Buffer Overflow Exposes FRU Handling
Administrators using FreeIPMI should update to 1.6.19 as soon as possible, especially in environments managing BMC infrastructure. Prioritize systems exposed to untrusted or compromised BMC responses.
FreeIPMI before 1.6.19 contains a stack-based buffer overflow in _read_fru_data within libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested. The vulnerability affects FreeIPMI and is rated CRITICAL with CVSS 9.8. The flaw could allow memory corruption through malformed BMC responses.
🔗 Read more 🔗
Source: NVD
🚨 FreeIPMI Dell OEM Command Buffer Overflow Found
Patch FreeIPMI deployments running Dell OEM commands immediately. Infrastructure teams managing Dell servers through IPMI should treat this as a high-priority update.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in ipmi-oem Dell system information handling through _output_dell_system_info_cmc_ipv6_info. The vulnerability affects the Dell OEM command functionality and is rated CRITICAL with CVSS 9.8. Malformed responses from BMC systems may trigger the issue.
🔗 Read more 🔗
Source: NVD
🚨 FreeIPMI Dell CMC Info Parser Hit by Critical Flaw
Update FreeIPMI quickly on systems using Dell CMC information commands. This should be included in the next urgent infrastructure maintenance cycle.
FreeIPMI before 1.6.19 contains a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c. The issue affects Dell CMC information retrieval and is rated CRITICAL with CVSS 9.8. Attackers may exploit malformed BMC data to impact memory safety.
🔗 Read more 🔗
Source: NVD
🚨 FreeIPMI iDRAC Parser Vulnerability Rated Critical
Patch FreeIPMI installations that interact with Dell iDRAC immediately. Focus first on server management systems accessible beyond tightly controlled networks.
FreeIPMI before 1.6.19 contains a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c. The vulnerability affects Dell iDRAC information processing and is rated CRITICAL with CVSS 9.8. Crafted BMC responses may trigger unsafe memory handling.
🔗 Read more 🔗
Source: NVD
⚠️ FreeIPMI Fujitsu Response Parsing Issue Discovered
Upgrade FreeIPMI to 1.6.19, especially on systems using Fujitsu BMC integrations. Schedule this promptly as part of security patching.
FreeIPMI before 1.6.19 contains a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text when a BMC provides a short response. The vulnerability affects Fujitsu IPMI OEM handling and is rated HIGH with CVSS 7.5. It is a different vulnerability than CVE-2026-50031 with different affected versions.
🔗 Read more 🔗
Source: NVD
🚨 FreeIPMI Fujitsu SEL Buffer Overflow Alert
Organizations using FreeIPMI with Fujitsu hardware should patch immediately. Treat systems processing remote BMC data as priority assets.
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text through malformed Fujitsu SEL long-text responses. The vulnerability affects FreeIPMI SEL processing and is rated CRITICAL with CVSS 9.8. Specially crafted responses may cause memory corruption.
🔗 Read more 🔗
Source: NVD
🚨 WordPress Divi Ajax Filter Allows Critical File Inclusion
WordPress administrators using Divi Ajax Filter should update or remove the vulnerable plugin immediately. The unauthenticated execution potential makes this a priority fix.
The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in versions up to and including 5.1.2 via the custom_loop_template parameter. The flaw allows unauthenticated attackers to include and execute arbitrary PHP files in certain configurations and is rated CRITICAL with CVSS 9.8. Successful exploitation may lead to sensitive data exposure or code execution.
🔗 Read more 🔗
Source: NVD
💉 Doctor Appointment System SQL Injection Exploit Public
Users of this application should apply fixes or isolate the system immediately. Because the exploit is public, exposed deployments should be treated as urgent.
code-projects Doctor Appointment System 1.0 contains a SQL injection vulnerability in /contactus.php through the firstname argument. The vulnerability allows remote exploitation and is rated HIGH with CVSS 7.3. The exploit has been published and may be used.
🔗 Read more 🔗
Source: NVD
💉 Doctor Appointment System Booking SQL Injection Risk
Patch or replace affected Doctor Appointment System deployments quickly. Public exploit availability increases the likelihood of opportunistic attacks.
code-projects Doctor Appointment System 1.0 contains a SQL injection vulnerability in /patient/booking.php through the doc_id argument. The issue allows remote attacks and is rated HIGH with CVSS 7.3. The exploit is now public and may be used.
🔗 Read more 🔗
Source: NVD
💉 Hospital Information System SQL Injection Released
Healthcare operators running this system should patch or take the application offline if possible. Public exploit availability makes this an urgent review item.
code-projects Hospital Information System 1.0 contains a SQL injection flaw in the getSinglePresp function of includes/presp/PrespController.php through the ID argument. The vulnerability is remotely exploitable and rated HIGH with CVSS 7.3. The exploit has been released publicly and may be used for attacks.
🔗 Read more 🔗
Source: NVD
💉 Hospital Information System Request SQL Injection Flaw
Administrators should prioritize remediation because attackers can use the published exploit against exposed systems. Review database access controls while patching.
code-projects Hospital Information System 1.0 contains a SQL injection vulnerability in viewReq.php through manipulation of the ID argument. The issue is remotely exploitable and rated HIGH with CVSS 7.3. A public exploit is available and may be used.
🔗 Read more 🔗
Source: NVD
🔑 SmartIT Desktop Manager Hardcoded Credentials Exposed
Organizations using SmartIT Desktop Manager should patch or replace affected versions immediately and rotate exposed credentials. Check for unauthorized access using the compromised accounts.
SmartIT Desktop Manager by Lightstar contains a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain SSH service account credentials and SmartIT Agent passwords from application source code. The vulnerability is rated CRITICAL with CVSS 9.8.
🔗 Read more 🔗
Source: NVD