#cve β Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve, aggregated by home.social.
-
π¨ SIGINT // Cybersecurity Watch β 2026-07-21
SonicWall zero-days exploited to deliver custom malware for weeks before a patch existed β perimeter devices remain prime attacker targets.
https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/
#CVE #ZeroDay #InfoSec #Cybersecurity -
Security Tip: Verify the integrity of every software package. π‘οΈ In an era of supply chain attacks, downloading from a 'trusted' site isn't enough. Always check digital signatures or SHA-256 checksums provided by the vendor. This ensures the file hasn't been tampered with mid-transit or on the mirror server. For the latest vulnerability intelligence, visit: https://cvedatabase.com #CVE #InfoSec #CyberSecurity #SupplyChain #AppSec
-
Security Tip: Buy time with Virtual Patching. π‘οΈ When a critical CVE drops, immediate patching isn't always feasible due to testing requirements. Virtual patching uses security controls like WAFs or IPS to intercept exploit attempts at the network layer. This provides a stop-gap defense while you prepare the permanent fix. Don't leave the window openβshield first, then remediate. Explore vulnerabilities: https://cvedatabase.com #InfoSec #CyberSecurity #PatchManagement #CVE
-
282,000+ VEX records are now in Vulnerability-Lookup π
π https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source β so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
π§βπ» https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
-
282,000+ VEX records are now in Vulnerability-Lookup π
π https://vulnerability.circl.lu/vex
SUSE just joined Red Hat and Microsoft as a VEX source β so from any CVE you can see whether a vendor says a product is affected, fixed, or not affected.
VEX statements are attached directly to each vulnerability and available via the open API.
π§βπ» https://github.com/vulnerability-lookup/vulnerability-lookup
#VEX #CSAF #VulnerabilityManagement #OpenSource #InfoSec #GCVE #CVE #CYberSecurity #Vulnerability
-
π¨ Lambda Watchdog CVE Report π¨
Latest AWS Lambda image scan detected 24 CVEs across 26 images:
β’ π΄ Critical: 1
β’ π High: 5
β’ π‘ Medium: 13
β’ π΅ Low: 5
Check the full report π https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
π¨ Security Alert: Our Weekly CVE Roundup is live! This week, we analyze CVE-2026-31022, a critical RCE in Next.js, and explore the evolving threat landscape for server-side rendering and edge architectures. Stay informed and secure: https://cvedatabase.com/blog/weekly-cve-roundup-next-js-critical-rce-and-the-evolving-threat-to-modern-web-fr-2026-07-05 #CVE #NextJS #InfoSec #CyberSecurity #WebDev #RCE
-
Security Tip: Automate your dependency audits. π‘οΈ Modern apps rely on hundreds of third-party libraries. Manually checking for vulnerabilities is impossible. Integrate tools like Snyk, Trivy, or OWASP Dependency-Check directly into your CI/CD pipeline. This ensures every build is scanned against known CVEs before deployment. Stay informed on the latest threats and vulnerability intelligence at https://cvedatabase.com #CyberSecurity #InfoSec #AppSec #CVE #DevSecOps
-
π¨ EUVD-2026-45876
π Score: n/a
π¦ Product: Unlimited Elements For Elementor
π’ Vendor: Unknown
π Updated: 2026-07-20π The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45876
-
π¨ EUVD-2026-45876
π Score: n/a
π¦ Product: Unlimited Elements For Elementor
π’ Vendor: Unknown
π Updated: 2026-07-20π The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45876
-
π¨ EUVD-2026-45876
π Score: n/a
π¦ Product: Unlimited Elements For Elementor
π’ Vendor: Unknown
π Updated: 2026-07-20π The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45876
-
π¨ EUVD-2026-45876
π Score: n/a
π¦ Product: Unlimited Elements For Elementor
π’ Vendor: Unknown
π Updated: 2026-07-20π The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API before rendering it in the Google Reviews widget output, allowing unauthenticated attackers who submit a...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45876
-
π¨ EUVD-2026-45877
π Score: n/a
π¦ Product: Reviews Feed
π’ Vendor: Unknown
π Updated: 2026-07-20π The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45877
-
π¨ EUVD-2026-45877
π Score: n/a
π¦ Product: Reviews Feed
π’ Vendor: Unknown
π Updated: 2026-07-20π The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45877
-
π¨ EUVD-2026-45877
π Score: n/a
π¦ Product: Reviews Feed
π’ Vendor: Unknown
π Updated: 2026-07-20π The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45877
-
π¨ EUVD-2026-45877
π Score: n/a
π¦ Product: Reviews Feed
π’ Vendor: Unknown
π Updated: 2026-07-20π The Reviews Feed WordPress plugin before 2.6.5 does not neutralize WordPress shortcodes contained in third-party review content before rendering it through its dynamic block, allowing unauthenticated attackers to execute arbitrary shortcodes on pages that display the...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45877
-
π¨ EUVD-2026-45880
π Score: n/a
π¦ Product: WP Travel
π’ Vendor: Unknown
π Updated: 2026-07-20π The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45880
-
π¨ EUVD-2026-45880
π Score: n/a
π¦ Product: WP Travel
π’ Vendor: Unknown
π Updated: 2026-07-20π The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45880
-
π¨ EUVD-2026-45880
π Score: n/a
π¦ Product: WP Travel
π’ Vendor: Unknown
π Updated: 2026-07-20π The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45880
-
π¨ EUVD-2026-45880
π Score: n/a
π¦ Product: WP Travel
π’ Vendor: Unknown
π Updated: 2026-07-20π The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also exposed to unauthenticated users, allowing them to cancel arbitrary bookings on the site.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45880
-
π¨ EUVD-2026-45879
π Score: n/a
π¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
π’ Vendor: Unknown
π Updated: 2026-07-20π The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45879
-
π¨ EUVD-2026-45879
π Score: n/a
π¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
π’ Vendor: Unknown
π Updated: 2026-07-20π The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45879
-
π¨ EUVD-2026-45879
π Score: n/a
π¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
π’ Vendor: Unknown
π Updated: 2026-07-20π The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45879
-
π¨ EUVD-2026-45879
π Score: n/a
π¦ Product: Modern Events Calendar Lite, Modern Event Calendar Pro
π’ Vendor: Unknown
π Updated: 2026-07-20π The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a request parameter before using it in a SQL statement, through an AJAX action...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45879
-
π¨ EUVD-2026-45878
π Score: n/a
π¦ Product: All in One SEO
π’ Vendor: Unknown
π Updated: 2026-07-20π The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45878
-
π¨ EUVD-2026-45878
π Score: n/a
π¦ Product: All in One SEO
π’ Vendor: Unknown
π Updated: 2026-07-20π The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45878
-
π¨ EUVD-2026-45878
π Score: n/a
π¦ Product: All in One SEO
π’ Vendor: Unknown
π Updated: 2026-07-20π The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45878
-
π¨ EUVD-2026-45878
π Score: n/a
π¦ Product: All in One SEO
π’ Vendor: Unknown
π Updated: 2026-07-20π The All in One SEO WordPress plugin before 4.9.9 does not correctly restrict access to some of its AI integration REST API endpoints, allowing users with low-level privileges such as Contributors to overwrite or reset the site-wide AI integration state.
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45878
-
π¨ EUVD-2026-45881
π Score: n/a
π¦ Product: SlimStat Analytics
π’ Vendor: Unknown
π Updated: 2026-07-20π The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45881
-
π¨ EUVD-2026-45884
π Score: n/a
π¦ Product: All-in-One WP Migration and Backup
π’ Vendor: Unknown
π Updated: 2026-07-20π The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45884
-
π¨ EUVD-2026-45881
π Score: n/a
π¦ Product: SlimStat Analytics
π’ Vendor: Unknown
π Updated: 2026-07-20π The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45881
-
π¨ EUVD-2026-45884
π Score: n/a
π¦ Product: All-in-One WP Migration and Backup
π’ Vendor: Unknown
π Updated: 2026-07-20π The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45884
-
π¨ EUVD-2026-45881
π Score: n/a
π¦ Product: SlimStat Analytics
π’ Vendor: Unknown
π Updated: 2026-07-20π The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45881
-
π¨ EUVD-2026-45884
π Score: n/a
π¦ Product: All-in-One WP Migration and Backup
π’ Vendor: Unknown
π Updated: 2026-07-20π The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45884
-
π¨ EUVD-2026-45881
π Score: n/a
π¦ Product: SlimStat Analytics
π’ Vendor: Unknown
π Updated: 2026-07-20π The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analytics reports, allowing unauthenticated visitors to store a cross-site scripting payload that executes in the browse...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45881
-
π¨ EUVD-2026-45884
π Score: n/a
π¦ Product: All-in-One WP Migration and Backup
π’ Vendor: Unknown
π Updated: 2026-07-20π The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file path, allowing unauthenticated attackers to create or append a log file in arbitrary locations o...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45884
-
π¨ EUVD-2026-45883
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45883
-
π¨ EUVD-2026-45883
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45883
-
π¨ EUVD-2026-45883
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45883
-
π¨ EUVD-2026-45883
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not sanitise or escape the email subject and body values supplied in a request before including them in the password-reset email it sends as HTML, allowing unauthenticated users to inject arbitrary HTML into the message delivere...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45883
-
π¨ EUVD-2026-45882
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45882
-
π¨ EUVD-2026-45882
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45882
-
π¨ EUVD-2026-45882
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45882
-
π¨ EUVD-2026-45882
π Score: n/a
π¦ Product: Kirki
π’ Vendor: Unknown
π Updated: 2026-07-20π The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overwrite the content of arbitrary existing comments and to create pre-approved comments under a spoofed identity, bypassing commen...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45882
-
π¨ EUVD-2026-45885
π Score: n/a
π¦ Product: LearnPress
π’ Vendor: Unknown
π Updated: 2026-07-20π The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45885
-
π¨ EUVD-2026-45885
π Score: n/a
π¦ Product: LearnPress
π’ Vendor: Unknown
π Updated: 2026-07-20π The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45885
-
π¨ EUVD-2026-45885
π Score: n/a
π¦ Product: LearnPress
π’ Vendor: Unknown
π Updated: 2026-07-20π The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45885
-
π¨ EUVD-2026-45885
π Score: n/a
π¦ Product: LearnPress
π’ Vendor: Unknown
π Updated: 2026-07-20π The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cross-Site Scripting that executes in the browser of a logged-in instructor or administrator who is tricked into opening a ...
π https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-45885