Tag: ArbitraryCodeExecution

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No41

    Critical Microsoft UFO Flaw Exposes ADB-Connected Android Devices • Nagios Notification Macros Enable Authenticated RCE • Nagios NRDP Macro Injection Opens Path to RCE • Nagios CSRF Bypass Can Trigger Commands as Authorized Users • IBM i Navigator Spoofing Flaw Enables Credential Harvesting…

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No24

    Brace Expansion Bypass Enables Memory Exhaustion • Angular i18n Flaw Turns Translations into JavaScript • Angular Server Rendering Exposes High-Severity XSS • Angular Cache-Key Collision Can Return the Wrong Data • OpenEMR OAuth Flow Bypasses Multi-Factor Authentication…

  • Vulnerability Watch No19

    Xendit Payment Access-Control Flaw Exposes Unauthenticated Attack Surface • Contest Gallery Hit by Unauthenticated XSS Vulnerability • Kali Forms Vulnerable to Unauthenticated Script Injection • BackWPup XSS Flaw Threatens WordPress Administrators • FormCraft SSRF Flaw Could Reach Internal Services…

  • Vulnerability Watch No6

    Critical GitHub Actions Supply Chain Flaw in Meshtastic • Meshtastic BLE Sync Bug Can Disable iOS Device Management • Unsafe Keras Deserialization Enables Arbitrary Code Execution

  • Vulnerability Watch No3

    Netty STOMP Header Flood Can Crash Servers • Hard-Coded Credentials Found in IBM Langflow OSS • IBM Langflow File Boundary Bypass Exposes User Data • Path Traversal Enables Arbitrary File Writes in Langflow • Langflow Privilege Escalation Can Fully Compromise Service…

  • Topics Everyone Is Talking About No375

    Why Im All In on USB-C • Cursor 0-Day: When Full Disclosure Is the Only Defense • Smartphones Can Strengthen Public Accountability • The Manufacturing Limits of Self-Replicating Space Probes • Juggler: An Open-Source GUI AI Coding Agent…