Tag: remoteExploitation

  • Vulnerability Watch No63

    Critical TOTOLINK NR1800X Buffer Overflow Exposes Remote Attack Surface • Medicine Delivery Password Recovery Hit by SQL Injection • Product Category Filter in Medicine Delivery App Vulnerable to SQL Injection • AshPhoenix Tenant Authorization Bug Can Bypass Scoped Access Checks • Medicine Delivery Product Detail Page Exposes SQL Injection…

  • Vulnerability Watch No54

    acmailer Authorization Flaw Enables Admin-Level Sub-Accounts • Atarim WordPress Plugin File Deletion Can Lead to RCE • TRENDnet Router Ping Interface Exposed to Command Injection • armeria-xds TLS Verification Flaw Enables MITM Attacks • TRENDnet TEW-823DRU Admin Endpoint Allows Command Injection…

  • Vulnerability Watch No50

    GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…

  • Vulnerability Watch No44

    Tenda G0 Port Mapping Flaw Enables Remote Buffer Overflow • Tenda G0 Static Route Bug Triggers Remote Stack Overflow • Tenda G0 Port Mirroring Endpoint Hit by Buffer Overflow • Tenda AC1206 Guest Wi-Fi Handler Exposed to Remote Overflow • Tenda AC1206 Device Naming Flaw Enables Remote Buffer Overflow…

  • Vulnerability Watch No35

    MingSoft MCMS SQL Injection Exposes Remote Attack Surface • node-sql-query SQL Injection Fixed in 0.1.29 • Aitemi M300 Command Injection Enables Remote Attacks • Tenda CH22 Command Injection Disclosed Publicly • Task Management System Hit by SQL Injection…

  • Vulnerability Watch No27

    H3C NX15 Web API Exposes Dangerous Routine • UTT HiPER 1200GW Hit by Remote Buffer Overflow • UTT HiPER 1250GW TempName Overflow Exposed • UTT HiPER 1250GW 5 GHz Endpoint Overflow • ESAFENET CDG KeyID Parameter Enables SQL Injection…

  • Vulnerability Watch No24

    Brace Expansion Bypass Enables Memory Exhaustion • Angular i18n Flaw Turns Translations into JavaScript • Angular Server Rendering Exposes High-Severity XSS • Angular Cache-Key Collision Can Return the Wrong Data • OpenEMR OAuth Flow Bypasses Multi-Factor Authentication…