-
Vulnerability Watch No63
Critical TOTOLINK NR1800X Buffer Overflow Exposes Remote Attack Surface • Medicine Delivery Password Recovery Hit by SQL Injection • Product Category Filter in Medicine Delivery App Vulnerable to SQL Injection • AshPhoenix Tenant Authorization Bug Can Bypass Scoped Access Checks • Medicine Delivery Product Detail Page Exposes SQL Injection…
-
Vulnerability Watch No54
acmailer Authorization Flaw Enables Admin-Level Sub-Accounts • Atarim WordPress Plugin File Deletion Can Lead to RCE • TRENDnet Router Ping Interface Exposed to Command Injection • armeria-xds TLS Verification Flaw Enables MITM Attacks • TRENDnet TEW-823DRU Admin Endpoint Allows Command Injection…
-
Vulnerability Watch No52
WordPress WPAdverts Authorization Bypass Exposes Site Configuration • COMFAST Router Flaw Enables Remote OS Command Injection • PHPGurukul Complaint System Hit by Remote SQL Injection • SourceCodester Timetabling System Exposes SQL Injection Flaw • Second SourceCodester Timetabling Endpoint Vulnerable to SQL Injection…
-
Vulnerability Watch No51
Zephyr Flash Syscall Flaw Enables Kernel Privilege Escalation • Glances Action Templates Can Reconstruct Shell Operators • Malformed Host Header Can Crash WebSocket Servers • Endpoint Privilege Management Tamper Protection Can Be Bypassed • PyCharm Jupyter MCP Tools Expose Unauthenticated Code Execution…
-
Vulnerability Watch No50
GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…
-
Vulnerability Watch No49
Scriban Parser Recursion Can Crash Hosting Processes • Circular Objects Trigger Fatal Scriban Stack Exhaustion • Nested Arrays Bypass Scriban Expression Depth Protection • Scriban Template Cache Can Leak Previously Authorized Content • Scriban Cache Flaw Breaks MemberFilter Sandbox Boundaries…
-
Vulnerability Watch No47
Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…
-
Vulnerability Watch No42
UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…
-
Vulnerability Watch No40
Velociraptor Permission Bypass Enables Analyst-to-Investigator Escalation • Socket Syscall TOCTOU Race Can Corrupt Kernel Heap Memory • VentraConnect WordPress Login Flaw Enables Administrator Takeover • RHACM Channel Flaw Exposes Cross-Tenant Secrets and ConfigMaps • Multicloud Integrations Flaw Can Force Malicious ArgoCD Synchronization…
-
Vulnerability Watch No38
Critical SQL Injection Hits Travel Agency Management System • ASUS Utility Flaw Can Enable Local Privilege Escalation • Hard-Coded Key Puts SAP BusinessObjects Credentials at Risk • SAP ABAP Authorization Flaw Exposes Database Operations • SAP Approuter Token Validation Flaw Can Leak Credentials…