Tag: fileUpload

  • Vulnerability Watch No59

    Joomla Fabrik List Controller Allows Unauthorized Data Deletion • Joomla Fabrik Reveals Database Structure to Unauthenticated Users • Joomla Fabrik Allows Unauthenticated Directory Listing • Joomla Fabrik Permits Unauthenticated File Uploads • WordPress WS Form Plugin Exposes Critical PHP Object Injection Flaw…

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No44

    Tenda G0 Port Mapping Flaw Enables Remote Buffer Overflow • Tenda G0 Static Route Bug Triggers Remote Stack Overflow • Tenda G0 Port Mirroring Endpoint Hit by Buffer Overflow • Tenda AC1206 Guest Wi-Fi Handler Exposed to Remote Overflow • Tenda AC1206 Device Naming Flaw Enables Remote Buffer Overflow…

  • Vulnerability Watch No29

    Forminator Upload-Record Flaw Enables Stored XSS • File Manager Flaw Can Delete Server Files and Enable RCE • NanoClaw Path Traversal Exploit Is Public • LettaBot API Status Route Lacks Authentication • Super Agent Party Proxy Route Exposes SSRF Flaw…

  • Vulnerability Watch No13

    Critical Joomla Easy Store SQL Injection Exposes Databases • Joomla Easy Store Flaw Reveals Other Customers Orders • Joomla Easy Store Payment Forgery Bug Enables Order Manipulation • Proxygen HTTP2 Bug Can Trigger Memory Exhaustion DoS • CyberPanel Backup IDOR Lets Users Access Other Tenants…

  • Vulnerability Watch No8

    FeliCa IC Chips Exposed by Missing Cryptographic Step • Zyxel Router Command Injection Enables OS Command Execution • Public D-Link NAS Upload Flaw Allows Remote File Uploads • D-Link DNS-320 Faces Another Remote Upload Vulnerability • D-Link DNS-320 Upload Endpoint Vulnerable to Remote Abuse…

  • Vulnerability Watch No1

    JLine Telnet Server Heap Exhaustion Flaw Hits Java Apps • Windows RDP Privacy Leak Exposes Private Information • HAPI FHIR Regex Bug Can Trigger Healthcare Service Outages • Avo Rails Framework Authorization Bypass Enables Data Exposure • ViewComponent XSS Flaw Risks Unsafe Rails Output…