-
Vulnerability Watch No62
Magma Integrity Validation Flaw Exposes Remote Attack Surface • ash_postgres Tenant Rename Flaw Can Cross Data Boundaries • Admidio Blind SQL Injection Exposes Credentials • SiYuan Block Metadata Enables Stored Script Execution • SiYuan Stored XSS Targets Package and Notebook Workflows…
-
Vulnerability Watch No52
WordPress WPAdverts Authorization Bypass Exposes Site Configuration • COMFAST Router Flaw Enables Remote OS Command Injection • PHPGurukul Complaint System Hit by Remote SQL Injection • SourceCodester Timetabling System Exposes SQL Injection Flaw • Second SourceCodester Timetabling Endpoint Vulnerable to SQL Injection…
-
Vulnerability Watch No40
Velociraptor Permission Bypass Enables Analyst-to-Investigator Escalation • Socket Syscall TOCTOU Race Can Corrupt Kernel Heap Memory • VentraConnect WordPress Login Flaw Enables Administrator Takeover • RHACM Channel Flaw Exposes Cross-Tenant Secrets and ConfigMaps • Multicloud Integrations Flaw Can Force Malicious ArgoCD Synchronization…
-
Vulnerability Watch No30
Quadratic HTML Traversal Enables Remote Resource Exhaustion • Malformed CSS Can Stall html_sanitize_ex Servers • Forged JWT Claims Bypass Neo4j GraphQL Subscription Controls • Unauthenticated Command Can Terminate Ground Station • OpenChamber Shutdown Endpoint Skips Authentication…
-
Vulnerability Watch No26
Flowise Permission Flaw Enables Cross-Type Flow Deletion • Flowise SQLite Path Override Leads to Root Command Execution • Public Flowise Chatflows Exposed to Configuration Injection • Flowise IPv6 Parsing Bypass Opens the Door to SSRF • Flowise CSV Agent Pickle Bypass Enables Command Execution…
-
Vulnerability Watch No10
Critical Unauthenticated RCE in Autel Maxi Charger • WordPress WP Foodbakery File Deletion Flaw Can Lead to RCE • Veeam Software Appliance Privilege Escalation to Root • Netty OCSP Validation Bug Enables Revocation Check Bypass • Netty HTTP2 Memory Leak Can Crash JVM…