Tag: RemoteAttack

  • Vulnerability Watch No61

    NLTK XML Parser Weakness Causes Denial of Service • node-poppler Flaw Allows Remote Argument Injection • Critical OCPP Buffer Overflow Threatens EV Charging Clients • WordPress InfusedWoo Pro Bug Enables Account Takeover • NLTK Deserialization Flaw Enables Python Code Execution…

  • Vulnerability Watch No55

    FFmpeg DASH Demuxer Vulnerable to Negative Array Index • FFmpeg AV1 RTP Packetizer Out-of-Bounds Read • FFmpeg VC-2 RTP Packetizer Heap Overflow • Critical FFmpeg RIST Reader Heap Buffer Overflow • FFmpeg MPEG-PS Muxer Stack Buffer Overflow…

  • Vulnerability Watch No51

    Zephyr Flash Syscall Flaw Enables Kernel Privilege Escalation • Glances Action Templates Can Reconstruct Shell Operators • Malformed Host Header Can Crash WebSocket Servers • Endpoint Privilege Management Tamper Protection Can Be Bypassed • PyCharm Jupyter MCP Tools Expose Unauthenticated Code Execution…

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No44

    Tenda G0 Port Mapping Flaw Enables Remote Buffer Overflow • Tenda G0 Static Route Bug Triggers Remote Stack Overflow • Tenda G0 Port Mirroring Endpoint Hit by Buffer Overflow • Tenda AC1206 Guest Wi-Fi Handler Exposed to Remote Overflow • Tenda AC1206 Device Naming Flaw Enables Remote Buffer Overflow…

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No29

    Forminator Upload-Record Flaw Enables Stored XSS • File Manager Flaw Can Delete Server Files and Enable RCE • NanoClaw Path Traversal Exploit Is Public • LettaBot API Status Route Lacks Authentication • Super Agent Party Proxy Route Exposes SSRF Flaw…

  • Vulnerability Watch No28

    Cisco IOS XE Resource-Lifecycle Control Flaw • IBM Langflow MCP Endpoint Authentication Bypass • Cisco Catalyst SD-WAN File Access Link Flaw • Cisco Catalyst SD-WAN Stores Sensitive Data in Cleartext • Critical Cisco Catalyst SD-WAN Link Resolution Vulnerability…