Tag: AuthenticationBypass

  • Vulnerability Watch No60

    AWX Archive Extraction Path Traversal • HCL Hive Third-Party Component Vulnerability • GIMP PCX Plugin Memory Corruption Bug • rConfig Authentication Bypass Creates Admin Accounts • NetworkManager WPA-Enterprise Validation Flaw…

  • Vulnerability Watch No58

    LeafWiki Account Update Bug Enables Role Escalation • RaTeX Parser Crash Creates Denial of Service Risk • WordPress Plugin Flaw Enables Privilege Escalation • WeeChat Authentication Timing Bug Exposes Hashes • LeafWiki File Traversal Bug Can Expose Local Data…

  • Vulnerability Watch No57

    Monkeytype Rate Limit Bypass Enables Abuse • Plate DOCX Conversion Flaw Exposes Internal Services • Link Preview JS DNS Rebinding Bypasses SSRF Protection • dbx Authentication Bypass Enables Database Takeover • NanaZip Archive Parsing Bug Risks Data Exposure…

  • Vulnerability Watch No53

    Kubernetes managed-serviceaccount flaw exposes cluster secrets • OpenSearch Dashboards request flaw enables remote denial of service • Dell PowerStore SDNAS NFS flaw can enable command execution • RabbitMQ Java client nesting bug triggers pre-authentication crashes • RabbitMQ Java client flaw enables massive pre-auth memory allocation…

  • Vulnerability Watch No50

    GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…

  • Vulnerability Watch No46

    Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…