Tag: privilegeEscalation

  • Vulnerability Watch No50

    GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…

  • Vulnerability Watch No46

    Unauthenticated Stored XSS Hits Invisible Anti-Spam WordPress Plugin • Cookie Consent Plugin Exposes WordPress Sites to Stored XSS • MaxUpload Flaw Enables Unauthenticated File Upload and Possible RCE • User Session Synchronizer Bug Allows Full WordPress Account Takeover • Propovoice Manager Accounts Can Escalate to WordPress Administrator…

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No43

    Biagiotti Core Vulnerable to Unauthenticated Local File Inclusion • Reviewer Subscriber Accounts Can Trigger SQL Injection • Multicluster Engine Tenant Isolation Flaw Enables Cross-Tenant Access • WP Directory Kit Hit by Unauthenticated SQL Injection • Critical Unauthenticated SQL Injection Affects WP Directory Kit…

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…

  • Vulnerability Watch No41

    Critical Microsoft UFO Flaw Exposes ADB-Connected Android Devices • Nagios Notification Macros Enable Authenticated RCE • Nagios NRDP Macro Injection Opens Path to RCE • Nagios CSRF Bypass Can Trigger Commands as Authorized Users • IBM i Navigator Spoofing Flaw Enables Credential Harvesting…

  • Vulnerability Watch No39

    Windows DHCP Client Heap Overflow Enables Privilege Escalation • Browserslist Cache Exhaustion Can Crash Processes • Browserslist Stats Parsing Opens Door to Crashes and Prototype Changes • Nanoid Integer Bug Can Make Security Tokens Predictable • Windows CLFS Race Condition Enables Local Privilege Escalation…