Tag: adminCompromise

  • Vulnerability Watch No46

    Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…

  • Vulnerability Watch No25

    Crafted Images Can Trigger GIMP Memory Corruption • Zyxel Firewall Path Traversal Enables Malicious Config Execution • Zyxel WAX650S Command Injection Exposes Device OS • Node.js HTTP2 Flaw Enables Remote Memory Exhaustion • CustomSounds Path Traversal Exposes Arbitrary Files…

  • Vulnerability Watch No18

    Malformed Chunk Size Can Crash facil.io Servers • Partial Multipart Request Freezes facil.io Workers • Empty Multipart Field Crashes facil.io • Critical TeamCity Agent Protocol Flaw Enables Remote Code Execution • NVIDIA NeMo Command Injection Exposes Linux Hosts…