#cve — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve, aggregated by home.social.
-
CVE Alert: CVE-2026-78141 - Tenda - CH22 - https://www.redpacketsecurity.com/cve-alert-cve-2026-78141-tenda-ch22/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78141 #tenda #ch22
-
CVE Alert: CVE-2026-78143 - code-projects - Barangay Resident Profiling Management System - https://www.redpacketsecurity.com/cve-alert-cve-2026-78143-code-projects-barangay-resident-profiling-management-system/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78143 #code-projects #barangay-resident-profiling-management-system
-
CVE Alert: CVE-2026-78147 - ggml-org - llama.cpp - https://www.redpacketsecurity.com/cve-alert-cve-2026-78147-ggml-org-llama-cpp/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78147 #ggml-org #llama-cpp
-
🚨🐛 SIGINT // Cybersecurity Watch — 2026-08-24
Hackers actively exploiting an unpatched GeoServer zero-day, threatening geospatial infrastructure worldwide with no patch yet available.
https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/
#CVE #ZeroDay #InfoSec #Cybersecurity -
🟠 CVE-2026-18052 - High (8.1)
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18052/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-76793 - High (8.1)
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76793/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-76789 - High (8.8)
The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-76789/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
CVE-2026-47895 - Double-Free vulnerability in strongSwan EAP identity parsing. CVSS 7.5. Update to version 6.0.7 immediately. #CVE #strongSwan #infosec
-
🔴 CVE-2026-77002 - Critical (9.8)
The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77002/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-77001 - Critical (9.8)
The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77001/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-77000 - Critical (9.8)
The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, incl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-77000/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
Chińskie grupy APT wykorzystują podatność CVE-2026-59310 do masowych ataków na środowiska VMware vCenter
Zespół reagowania na incydenty firmy QUIRSO podczas analizy powłamaniowej serwera VMware vCenter natrafił na ślady globalnej kampanii, sterowanej najprawdopodobniej przez chińską grupę APT. Badania wykazały, że cyberprzestępcy wykorzystali krytyczną podatność CVE-2026-59310 (CVSS 9.8) w usłudze Syslog Server. Równolegle zidentyfikowali próby użycia drugiej luki CVE-2026-59309 (CVSS 9.8) jednak analitycy nie powiązali...
-
🔴 CVE-2026-5388 - Critical (9.8)
justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and several custom sanitization-policy edge cases. Dep...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-5388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-4671 - High (7.5)
justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate attacker-controlled selector strings (via query(), matches(), or selector-based transforms), run ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-8445 - Critical (9.8)
justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). While a small set of Markdown metacharacters ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8445/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-7808 - Critical (9.8)
justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scripting. The issues primarily affect advanced usa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-7808/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-9769 - High (7.5)
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-9769/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
CVE Alert: CVE-2026-9769 - EmilStenstrom - justhtml - https://www.redpacketsecurity.com/cve-alert-cve-2026-9769-emilstenstrom-justhtml/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-9769 #emilstenstrom #justhtml
-
CVE Alert: CVE-2026-4671 - EmilStenstrom - justhtml - https://www.redpacketsecurity.com/cve-alert-cve-2026-4671-emilstenstrom-justhtml/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-4671 #emilstenstrom #justhtml
-
CVE-2026-4703 - Critical PHP Object Injection in WS Form for WordPress leads to remote code execution via insecure deserialization. CVSS 9.8. Update now. #CVE #WordPress #infosec
-
🟠 CVE-2026-10053 - High (8.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10053/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-78155 - Critical (9.9)
privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-78155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
CVE Alert: CVE-2026-78062 - vas3k - TaxHacker - https://www.redpacketsecurity.com/cve-alert-cve-2026-78062-vas3k-taxhacker/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78062 #vas3k #taxhacker
-
CVE Alert: CVE-2026-78063 - Tenda - CH22 - https://www.redpacketsecurity.com/cve-alert-cve-2026-78063-tenda-ch22/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-78063 #tenda #ch22
-
🟠 CVE-2026-47827 - High (7.5)
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-47827/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack