#vuln — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
-
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
-
WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. https://radar.offseq.com/threat/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now-99579d9a7c571599 #OffSeq #WordPress #RCE #Vuln
-
CVE-2026-13446: IBM Langflow OSS 1.0.0 – 1.10.1 contains hard-coded credentials (CRITICAL, CVSS 9.8). Total system compromise possible. No patch yet — restrict access, monitor activity. More: https://radar.offseq.com/threat/cve-2026-13446-cwe-798-use-of-hard-coded-credentia-e33f708cc1420dc3 #OffSeq #Vuln #Cybersecurity #IBM
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
MohibShaikh clawvet API server <0.7.5 (CVE-2026-62241) suffers a CRITICAL flaw: hard-coded JWT secret enables unauthenticated user data access and session cookie forgery. Change secrets & limit endpoint access. https://radar.offseq.com/threat/cve-2026-62241-missing-authentication-for-critical-b8ebafbae06b4bce #OffSeq #CVE202662241 #vuln
-
CRITICAL: CVE-2026-63305 impacts WWBN AVideo ≤29.0. OS command injection in ffmpeg.json.php allows arbitrary command execution as the web-server user. No patch yet — restrict access & monitor logs. Details: https://radar.offseq.com/threat/cve-2026-63305-improper-neutralization-of-special--2152563144062b29 #OffSeq #Vuln #WWBN #CVE202663305
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
CVE-2026-54052: CRITICAL auth bypass in czlonkowski n8n-mcp <2.56.1. Multi-tenant HTTP mode allows tenants to access/delete others’ sensitive workflow backups. Patch to 2.56.1 ASAP. https://radar.offseq.com/threat/cve-2026-54052-cwe-639-authorization-bypass-throug-04ca76ef25ff4df2 #OffSeq #CVE #infosec #vuln
-
CVE-2026-55445: Qinglong <2.20.1 has a CRITICAL improper authentication bug (CVSS 9.3). Attackers can reset admin credentials on initialized systems via /open/user/init. Upgrade to 2.20.1 ASAP. https://radar.offseq.com/threat/cve-2026-55445-cwe-287-improper-authentication-in--3a378a9a77ee78d0 #OffSeq #CVE202655445 #Vuln #Qinglong
-
CRITICAL RCE in ServiceNow AI platform (CVE-2026-6875) allows unauthenticated code execution. Patched — no active exploitation. Ivanti & Fortinet also released key updates. Patch all affected systems promptly. https://radar.offseq.com/threat/vulnerabilities-patched-by-fortinet-ivanti-service-e42e461913c3f486 #OffSeq #Vuln #ServiceNow #Ivanti #Fortinet
-
Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. https://radar.offseq.com/threat/critical-vulnerabilities-patched-with-fresh-chrome-e977806d68193e89 #OffSeq #Vuln #PatchNow #BrowserSecurity
-
Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. https://radar.offseq.com/threat/critical-vulnerabilities-patched-with-fresh-chrome-e977806d68193e89 #OffSeq #Vuln #PatchNow #BrowserSecurity
-
CVE-2026-48324 (CRITICAL, CVSS 9.1): Adobe ColdFusion 2025 suffers from an SQL Injection (CWE-89) allowing arbitrary code execution. No patch confirmed — restrict access & monitor SQL activity. https://radar.offseq.com/threat/cve-2026-48324-improper-neutralization-of-special--e4f7ad5cedb0440f #OffSeq #ColdFusion #SQLInjection #Vuln
-
CRITICAL: CVE-2026-48334 impacts Adobe Illustrator Desktop 2026 (CVSS 9.3). Improper input validation lets attackers run code if a user opens a malicious file. No patch — open only trusted files. https://radar.offseq.com/threat/cve-2026-48334-improper-input-validation-cwe-20-in-92b003786ac4de7b #OffSeq #Adobe #Vuln #CVE202648334
-
ASUS routers face CRITICAL risk (CVE-2026-13385, CVSS 9.5) due to improper integrity and certificate checks. MITM attackers can execute arbitrary commands. No patch yet — monitor ASUS advisories. https://radar.offseq.com/threat/cve-2026-13385-cwe-354-improper-validation-of-inte-022c4477d04d4a24 #OffSeq #ASUS #infosec #CVE #vuln
-
SAP July 2026 patch day delivers CRITICAL fixes: NetWeaver (CVE-2026-44747, memory corruption), Approuter (CVE-2026-27690, HTTP smuggling), Commerce Cloud (CVE-2026-44761, hardcoded creds). Patch ASAP. https://radar.offseq.com/threat/sap-patches-critical-vulnerabilities-in-netweaver--aa75f703df9065e4 #OffSeq #SAP #Vuln #PatchTuesday
-
Eclipse BaSyx Java Server SDK (MongoDB backend) CRITICAL vuln: CVE-2026-57898 (CVSS 9.0) allows unauthenticated path traversal & arbitrary file writes — potential RCE. Upgrade to 2.0.0-milestone-13. Details: https://radar.offseq.com/threat/cve-2026-57898-cwe-22-improper-limitation-of-a-pat-230a166ac74035f0 #OffSeq #Vuln #Java #Eclipse
-
Deserialization of untrusted data (CVE-2026-12583, CRITICAL) in Newsletters WP plugin <4.15 allows unauthenticated RCE via public form. Disable or restrict plugin until patch is confirmed. https://radar.offseq.com/threat/cve-2026-12583-cwe-502-deserialization-of-untruste-c97ca770117c8a32 #OffSeq #WordPress #Vuln #RCE
-
SAP Commerce Cloud impacted by CRITICAL CVE-2026-44761 (CVSS 9.1): Default OAuth2 credentials can let unauthenticated attackers access APIs & modify data. Change/remove sample creds now. No patch yet. https://radar.offseq.com/threat/cve-2026-44761-cwe-1392-use-of-default-credentials-009b0a23096bbf37 #OffSeq #SAP #OAuth2 #Vuln
-
CVE-2026-62327 (CRITICAL): decolua 9Router ≤0.4.41 exposes plaintext API keys & usage stats via unauthenticated /api/usage/stats. No patch yet — restrict access or add auth controls. Details: https://radar.offseq.com/threat/cve-2026-62327-missing-authentication-for-critical-4c8f1eac7b8172c7 #OffSeq #CVE #APIsecurity #Vuln
-
CVE-2026-62327 (CRITICAL): decolua 9Router ≤0.4.41 exposes plaintext API keys & usage stats via unauthenticated /api/usage/stats. No patch yet — restrict access or add auth controls. Details: https://radar.offseq.com/threat/cve-2026-62327-missing-authentication-for-critical-4c8f1eac7b8172c7 #OffSeq #CVE #APIsecurity #Vuln
-
CVE-2026-62327 (CRITICAL): decolua 9Router ≤0.4.41 exposes plaintext API keys & usage stats via unauthenticated /api/usage/stats. No patch yet — restrict access or add auth controls. Details: https://radar.offseq.com/threat/cve-2026-62327-missing-authentication-for-critical-4c8f1eac7b8172c7 #OffSeq #CVE #APIsecurity #Vuln
-
CVE-2026-62327 (CRITICAL): decolua 9Router ≤0.4.41 exposes plaintext API keys & usage stats via unauthenticated /api/usage/stats. No patch yet — restrict access or add auth controls. Details: https://radar.offseq.com/threat/cve-2026-62327-missing-authentication-for-critical-4c8f1eac7b8172c7 #OffSeq #CVE #APIsecurity #Vuln
-
CVE-2026-58596 (HIGH, CVSS 8.3): Microsoft Edge (Chromium-based) suffers from untrusted pointer dereference, enabling remote privilege escalation. Patch ASAP: https://radar.offseq.com/threat/cve-2026-58596-cwe-822-untrusted-pointer-dereferen-74291c1991697a5a 🛡️ #OffSeq #MicrosoftEdge #Vuln #Infosec
-
CVE-2026-15506: HIGH severity heap-based buffer overflow in SecureAge CatchPulse (v10.9.0 – 10.9.3, saappctl.sys). Exploitable by local attackers for code execution or DoS. No patch yet — restrict access & monitor updates. https://radar.offseq.com/threat/cve-2026-15506-heap-based-buffer-overflow-in-secur-a85caef566d01d76 #OffSeq #vuln #BlueTeam
-
CVE-2026-15483: HIGH (CVSS 8.7) buffer overflow in TRENDnet TEW-821DAP 1.12B01. Remote exploitation possible via /goform/tools_nslookup. No patch — device is EOL. Upgrade or replace to secure your network. https://radar.offseq.com/threat/cve-2026-15483-buffer-overflow-in-trendnet-tew-821-d5ed5e2a19a9e62f #OffSeq #CVE2026_15483 #TRENDnet #Vuln
-
CVE-2026-15484: HIGH-severity buffer overflow (CVSS 8.7) in TRENDnet TEW-821DAP v1.12B01 — remote code execution possible. Device is EOL; no patch. Mitigate by isolating or replacing affected units. https://radar.offseq.com/threat/cve-2026-15484-buffer-overflow-in-trendnet-tew-821-ae7b66a07ffeec9b #OffSeq #infosec #vuln #TRENDnet
-
Dell PowerFlex Manager <5.1.0.1 faces CRITICAL OS command injection (CVE-2026-56688, CVSS 9.1). High-priv attackers can execute root commands — full compromise risk. No patch yet. Limit admin remote access & monitor activity. https://radar.offseq.com/threat/cve-2026-56688-cwe-78-improper-neutralization-of-s-de5ccc00f15b9022 #OffSeq #Dell #Vuln #Infosec
-
CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. https://radar.offseq.com/threat/cve-2026-14781-improper-validation-of-consistency--d19be74f7ead5808 #OffSeq #Keycloak #Vuln #IAM
-
CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. https://radar.offseq.com/threat/cve-2026-14781-improper-validation-of-consistency--d19be74f7ead5808 #OffSeq #Keycloak #Vuln #IAM
-
CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. https://radar.offseq.com/threat/cve-2026-14781-improper-validation-of-consistency--d19be74f7ead5808 #OffSeq #Keycloak #Vuln #IAM
-
CVE-2026-14781 (MEDIUM): Red Hat Build of Keycloak flaw in OIDC broker email_verified claim sync. If trustEmail=true & userinfo enabled, attacker can mark emails as verified. Review config & monitor fixes. https://radar.offseq.com/threat/cve-2026-14781-improper-validation-of-consistency--d19be74f7ead5808 #OffSeq #Keycloak #Vuln #IAM
-
CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. https://radar.offseq.com/threat/cve-2026-14570-cwe-330-use-of-insufficiently-rando-539cd2ae349f5a7a #OffSeq #Vuln #Perl #Crypto
-
CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. https://radar.offseq.com/threat/cve-2026-13601-protection-mechanism-failure-in-red-844c9044ecdb0d62 #OffSeq #Linux #Vuln #RedHat
-
CVE-2026-13491: MEDIUM severity DoS flaw in 78 xiaozhi-esp32 (v2.2.0 – 2.2.6) via MQTT Goodbye Handler. Exploitable remotely with public exploit. Patch via commit e182471f8c5a. https://radar.offseq.com/threat/cve-2026-13491-denial-of-service-in-78-xiaozhi-esp-7a05af4bbbaaa50e #OffSeq #Vuln #IoT #DoS
-
CVE-2026-13486 | SQL injection in SourceCodester Class and Exam Timetabling System (v1.0/6.php). MEDIUM severity. Exploit public for /preview6.php — remote attackers can target course_year_section param. Monitor & mitigate. https://radar.offseq.com/threat/cve-2026-13486-sql-injection-in-sourcecodester-cla-1dca720c361e2250 #OffSeq #Vuln #SQLi #AppSec
-
CVE-2026-53753: CRITICAL code injection in unclecode crawl4ai (<0.8.7). Unauthenticated RCE via /crawl POST request due to insufficient AST validation. Patch to 0.8.7 ASAP. https://radar.offseq.com/threat/cve-2026-53753-cwe-94-improper-control-of-generati-9d9fc678b9a0404e #OffSeq #CVE202653753 #infosec #vuln
-
CVE-2026-44914: HIGH severity in Apache NiFi (1.12.0 – 2.9.0). Missing authorization lets users with write access add restricted components. Upgrade to 2.9.0 or enforce specific controls. https://radar.offseq.com/threat/cve-2026-44914-cwe-862-missing-authorization-in-ap-41e3d5d03a56632c #OffSeq #NiFi #Vuln #Infosec
-
🔥🔥🔥 Cuevasanta, by Vuln
https://v-u-l-n.bandcamp.com/track/cuevasanta
#NowPlaying #Musique #Vuln -
CVE-2026-12780: HIGH severity vuln in AOMEI Backupper ≤8.3.0. Local attackers can abuse improper access controls in amwrtdrv.sys for potential privilege escalation. No patch available — limit local access & watch for updates. https://radar.offseq.com/threat/cve-2026-12780-improper-access-controls-in-aomei-b-bd5bc4597d816b66 #OffSeq #Vuln #AOMEI