Tag: CriticalVulnerability

  • Vulnerability Watch No57

    Monkeytype Rate Limit Bypass Enables Abuse • Plate DOCX Conversion Flaw Exposes Internal Services • Link Preview JS DNS Rebinding Bypasses SSRF Protection • dbx Authentication Bypass Enables Database Takeover • NanaZip Archive Parsing Bug Risks Data Exposure…

  • Vulnerability Watch No55

    FFmpeg DASH Demuxer Vulnerable to Negative Array Index • FFmpeg AV1 RTP Packetizer Out-of-Bounds Read • FFmpeg VC-2 RTP Packetizer Heap Overflow • Critical FFmpeg RIST Reader Heap Buffer Overflow • FFmpeg MPEG-PS Muxer Stack Buffer Overflow…

  • Vulnerability Watch No54

    acmailer Authorization Flaw Enables Admin-Level Sub-Accounts • Atarim WordPress Plugin File Deletion Can Lead to RCE • TRENDnet Router Ping Interface Exposed to Command Injection • armeria-xds TLS Verification Flaw Enables MITM Attacks • TRENDnet TEW-823DRU Admin Endpoint Allows Command Injection…

  • Vulnerability Watch No51

    Zephyr Flash Syscall Flaw Enables Kernel Privilege Escalation • Glances Action Templates Can Reconstruct Shell Operators • Malformed Host Header Can Crash WebSocket Servers • Endpoint Privilege Management Tamper Protection Can Be Bypassed • PyCharm Jupyter MCP Tools Expose Unauthenticated Code Execution…

  • Vulnerability Watch No50

    GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No43

    Biagiotti Core Vulnerable to Unauthenticated Local File Inclusion • Reviewer Subscriber Accounts Can Trigger SQL Injection • Multicluster Engine Tenant Isolation Flaw Enables Cross-Tenant Access • WP Directory Kit Hit by Unauthenticated SQL Injection • Critical Unauthenticated SQL Injection Affects WP Directory Kit…

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…

  • Vulnerability Watch No41

    Critical Microsoft UFO Flaw Exposes ADB-Connected Android Devices • Nagios Notification Macros Enable Authenticated RCE • Nagios NRDP Macro Injection Opens Path to RCE • Nagios CSRF Bypass Can Trigger Commands as Authorized Users • IBM i Navigator Spoofing Flaw Enables Credential Harvesting…