Tag: ServerSideRequestForgery

  • Vulnerability Watch No57

    Monkeytype Rate Limit Bypass Enables Abuse • Plate DOCX Conversion Flaw Exposes Internal Services • Link Preview JS DNS Rebinding Bypasses SSRF Protection • dbx Authentication Bypass Enables Database Takeover • NanaZip Archive Parsing Bug Risks Data Exposure…

  • Vulnerability Watch No42

    UpSnap Fresh Installs Exposed to Unauthenticated Root RCE • Cedar Express Middleware Flaw Can Bypass Route Authorization • MRBS Vulnerable to Server-Side Request Forgery • OpenStack Designate Flaw Enables Cross-Tenant DNS Hijacking • UpSnap Device Fields Allow Authenticated Command Injection…

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No29

    Forminator Upload-Record Flaw Enables Stored XSS • File Manager Flaw Can Delete Server Files and Enable RCE • NanoClaw Path Traversal Exploit Is Public • LettaBot API Status Route Lacks Authentication • Super Agent Party Proxy Route Exposes SSRF Flaw…

  • Vulnerability Watch No23

    Hashi Vault JS Flaw Enables Path and Query Injection • Defaults Deep Library Vulnerable to Prototype Pollution • DSSRF DNS Handling Bug Reopens SSRF Paths • Vault Webhook Flaw Can Leak Kubernetes Service Account Tokens • cPanel Database Rename Flaw Enables Root-Context SQL Execution…

  • Vulnerability Watch No19

    Xendit Payment Access-Control Flaw Exposes Unauthenticated Attack Surface • Contest Gallery Hit by Unauthenticated XSS Vulnerability • Kali Forms Vulnerable to Unauthenticated Script Injection • BackWPup XSS Flaw Threatens WordPress Administrators • FormCraft SSRF Flaw Could Reach Internal Services…

  • Vulnerability Watch No15

    Pre-Auth Heap Overflow in libssh2 Clients • libssh2 Bounds Check Bug Leaks Memory • Stored XSS Hits Loytec OPC XML-DA • Loytec Privilege Management Flaw Enables Password Resets • Critical Symlink Attack Leads to Root on Loytec…