Category: Security

  • Vulnerability Watch No41

    Critical Microsoft UFO Flaw Exposes ADB-Connected Android Devices • Nagios Notification Macros Enable Authenticated RCE • Nagios NRDP Macro Injection Opens Path to RCE • Nagios CSRF Bypass Can Trigger Commands as Authorized Users • IBM i Navigator Spoofing Flaw Enables Credential Harvesting…

  • Vulnerability Watch No39

    Windows DHCP Client Heap Overflow Enables Privilege Escalation • Browserslist Cache Exhaustion Can Crash Processes • Browserslist Stats Parsing Opens Door to Crashes and Prototype Changes • Nanoid Integer Bug Can Make Security Tokens Predictable • Windows CLFS Race Condition Enables Local Privilege Escalation…

  • Vulnerability Watch No38

    Critical SQL Injection Hits Travel Agency Management System • ASUS Utility Flaw Can Enable Local Privilege Escalation • Hard-Coded Key Puts SAP BusinessObjects Credentials at Risk • SAP ABAP Authorization Flaw Exposes Database Operations • SAP Approuter Token Validation Flaw Can Leak Credentials…

  • Vulnerability Watch No37

    Discourse Rich Text Editor Flaw Enables Stored XSS • Multicluster Global Hub Flaw Lets Compromised Hubs Falsify Data • Malicious Git Config Can Trigger Code Execution in Goose Review • SPIP SQLite Installations Exposed to Authenticated Command Execution • Malicious use-context-selector Commits Compromised Developer Machines…

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No35

    MingSoft MCMS SQL Injection Exposes Remote Attack Surface • node-sql-query SQL Injection Fixed in 0.1.29 • Aitemi M300 Command Injection Enables Remote Attacks • Tenda CH22 Command Injection Disclosed Publicly • Task Management System Hit by SQL Injection…

  • Vulnerability Watch No34

    lollms Path Traversal Exposes Arbitrary Server Files • MSI Radix AXE6600 OpenVPN Flaw Enables Root Command Execution • MSI Radix AXE6600 Mac Filter Bug Allows Root Commands • MSI Router Telnet Configuration Flaw Leads to Root Access • MSI Router SSH Configuration Flaw Enables Root Command Injection…

  • Vulnerability Watch No33

    Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs • Bouncy Castle FIPS Entropy Failure Can Hang Applications • Klever-Go REST APIs Exposed to Slow-Header Denial of Service • Klever-Go Peer Can Trigger Unbounded Goroutine Creation • Tiny Malformed Transaction Can Crash Klever-Go Nodes…

  • Vulnerability Watch No32

    go-git Symlink Escape Can Reach Files Outside Worktrees • ZenML Artifact Poisoning Enables Remote Code Execution • Absinthe Federation Atom Exhaustion Can Crash Erlang Nodes • ClamAV XAR Parser Memory Corruption Can Trigger DoS • Crafted Mach-O Files Can Crash ClamAV Scanners…