#vuln — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.
-
CVE-2026-65603: HIGH severity privilege escalation in Grav Login plugin (<=3.8.11). Low-priv users can gain super-admin & RCE. Patch to v3.8.12 ASAP! https://radar.offseq.com/threat/cve-2026-65603-improper-privilege-management-in-getgrav-grav-12319d7ebec99910 #OffSeq #GravCMS #Vuln #PrivilegeEscalation
-
Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
-
CVE-2026-62549 (CRITICAL, CVSS 9.6) in Oracle HRMS (UK) 12.2.3 – 12.2.15 lets low-priv attackers compromise critical data & impact other Oracle apps. Patch status unclear — check https://radar.offseq.com/threat/cve-2026-62549-easily-exploitable-vulnerability-allows-low-privileged-attacker-with-network-access-via-2a35d285e3bf086c & restrict network access. #OffSeq #Oracle #CVE2026_62549 #Vuln
-
CVE-2026-16412: CRITICAL memory safety issues in Firefox ESR 140.12 & 152 allow code execution, sandbox escape, info disclosure. Public exploits exist, but no in-the-wild attacks. Patch to 153/ESR 140.13. https://radar.offseq.com/threat/cve-2026-16412-vulnerability-in-mozilla-firefox-4b126d3842b74077 #OffSeq #Firefox #Vuln #Security
-
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
-
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
-
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
-
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
-
Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. https://radar.offseq.com/threat/zimbra-update-patches-critical-vulnerabilities-8b90415ad76d6649 #OffSeq #Zimbra #InfoSec #Vuln
-
Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. https://radar.offseq.com/threat/zimbra-update-patches-critical-vulnerabilities-8b90415ad76d6649 #OffSeq #Zimbra #InfoSec #Vuln
-
Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. https://radar.offseq.com/threat/zimbra-update-patches-critical-vulnerabilities-8b90415ad76d6649 #OffSeq #Zimbra #InfoSec #Vuln
-
Zimbra ZCS 10.1.20 patches CRITICAL vulnerabilities: command injection, XSS, mail forwarding bypass (CVE-2026-50055), EWS access flaws, SSRF. No attacks seen yet. Update ASAP to secure servers. https://radar.offseq.com/threat/zimbra-update-patches-critical-vulnerabilities-8b90415ad76d6649 #OffSeq #Zimbra #InfoSec #Vuln
-
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
-
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
-
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
-
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
-
CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. https://radar.offseq.com/threat/cve-2026-15901-use-after-free-in-google-chrome-8afb124627400a01 #OffSeq #Chrome #Vuln #InfoSec
-
CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. https://radar.offseq.com/threat/cve-2026-15901-use-after-free-in-google-chrome-8afb124627400a01 #OffSeq #Chrome #Vuln #InfoSec
-
CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. https://radar.offseq.com/threat/cve-2026-15901-use-after-free-in-google-chrome-8afb124627400a01 #OffSeq #Chrome #Vuln #InfoSec
-
CVE-2026-15901: CRITICAL use-after-free in Chrome <150.0.7871.128 allows remote heap corruption via crafted HTML. No active exploits, patch status unclear — monitor advisories. https://radar.offseq.com/threat/cve-2026-15901-use-after-free-in-google-chrome-8afb124627400a01 #OffSeq #Chrome #Vuln #InfoSec
-
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
-
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
-
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
-
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
-
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
-
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
-
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
-
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln