-
Vulnerability Watch No33
Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs • Bouncy Castle FIPS Entropy Failure Can Hang Applications • Klever-Go REST APIs Exposed to Slow-Header Denial of Service • Klever-Go Peer Can Trigger Unbounded Goroutine Creation • Tiny Malformed Transaction Can Crash Klever-Go Nodes…
-
Vulnerability Watch No29
Forminator Upload-Record Flaw Enables Stored XSS • File Manager Flaw Can Delete Server Files and Enable RCE • NanoClaw Path Traversal Exploit Is Public • LettaBot API Status Route Lacks Authentication • Super Agent Party Proxy Route Exposes SSRF Flaw…
-
Vulnerability Watch No28
Cisco IOS XE Resource-Lifecycle Control Flaw • IBM Langflow MCP Endpoint Authentication Bypass • Cisco Catalyst SD-WAN File Access Link Flaw • Cisco Catalyst SD-WAN Stores Sensitive Data in Cleartext • Critical Cisco Catalyst SD-WAN Link Resolution Vulnerability…
-
Vulnerability Watch No22
Yggdrasil Package Manager Flaw Enables Root Code Execution • Advantech ECU-1251D Exposes Passwordless Root SSH Access • Joomla Gridbox Admin Interface Hit by Multiple CSRF Flaws • Hospital Management System Report Page Exposed to Critical SQL Injection