-
Vulnerability Watch No43
Biagiotti Core Vulnerable to Unauthenticated Local File Inclusion • Reviewer Subscriber Accounts Can Trigger SQL Injection • Multicluster Engine Tenant Isolation Flaw Enables Cross-Tenant Access • WP Directory Kit Hit by Unauthenticated SQL Injection • Critical Unauthenticated SQL Injection Affects WP Directory Kit…
-
Vulnerability Watch No41
Critical Microsoft UFO Flaw Exposes ADB-Connected Android Devices • Nagios Notification Macros Enable Authenticated RCE • Nagios NRDP Macro Injection Opens Path to RCE • Nagios CSRF Bypass Can Trigger Commands as Authorized Users • IBM i Navigator Spoofing Flaw Enables Credential Harvesting…
-
Vulnerability Watch No35
MingSoft MCMS SQL Injection Exposes Remote Attack Surface • node-sql-query SQL Injection Fixed in 0.1.29 • Aitemi M300 Command Injection Enables Remote Attacks • Tenda CH22 Command Injection Disclosed Publicly • Task Management System Hit by SQL Injection…
-
Vulnerability Watch No34
lollms Path Traversal Exposes Arbitrary Server Files • MSI Radix AXE6600 OpenVPN Flaw Enables Root Command Execution • MSI Radix AXE6600 Mac Filter Bug Allows Root Commands • MSI Router Telnet Configuration Flaw Leads to Root Access • MSI Router SSH Configuration Flaw Enables Root Command Injection…
-
Vulnerability Watch No33
Bouncy Castle FIPS Key Zeroisation Can Fall Behind on Newer JVMs • Bouncy Castle FIPS Entropy Failure Can Hang Applications • Klever-Go REST APIs Exposed to Slow-Header Denial of Service • Klever-Go Peer Can Trigger Unbounded Goroutine Creation • Tiny Malformed Transaction Can Crash Klever-Go Nodes…
-
Vulnerability Watch No32
go-git Symlink Escape Can Reach Files Outside Worktrees • ZenML Artifact Poisoning Enables Remote Code Execution • Absinthe Federation Atom Exhaustion Can Crash Erlang Nodes • ClamAV XAR Parser Memory Corruption Can Trigger DoS • Crafted Mach-O Files Can Crash ClamAV Scanners…
-
Vulnerability Watch No22
Yggdrasil Package Manager Flaw Enables Root Code Execution • Advantech ECU-1251D Exposes Passwordless Root SSH Access • Joomla Gridbox Admin Interface Hit by Multiple CSRF Flaws • Hospital Management System Report Page Exposed to Critical SQL Injection