#vuln — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vuln, aggregated by home.social.
-
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
-
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16227: SQL injection in SourceCodester Class and Exam Timetabling System v1.0 (/edit_subject.php, ID param). MEDIUM severity (CVSS 6.9). No patch yet — use input validation & parameterized queries. https://radar.offseq.com/threat/cve-2026-16227-sql-injection-in-sourcecodester-class-and-exam-timetabling-system-bf78ed5f513695ba #OffSeq #SQLInjection #AppSec #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
CVE-2026-16223: SSRF in 1Panel-dev CordysCRM 1.4.0 & 1.4.1 (MEDIUM, CVSS 5.3). Exploitable via appSecret — enables unauthorized server requests. No patch yet: restrict endpoint, monitor logs. https://radar.offseq.com/threat/cve-2026-16223-server-side-request-forgery-in-1panel-dev-cordyscrm-b282fef55db79c7d #OffSeq #SSRF #CyberSecurity #Vuln
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-53994: ProFTPD mod_sftp heap buffer overflow (HIGH severity, CVSS 7.5) lets authenticated SFTP users crash session processes via crafted 0-length packets. Patch status unconfirmed — restrict SFTP access & monitor logs. https://radar.offseq.com/threat/cve-2026-53994-heap-based-buffer-overflow-in-proftpd-project-proftpd-fe4dcd4d99eab6eb #OffSeq #ProFTPD #infosec #vuln
-
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
-
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
-
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
-
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
-
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
-
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
-
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
-
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
-
WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. https://radar.offseq.com/threat/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now-99579d9a7c571599 #OffSeq #WordPress #RCE #Vuln
-
WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. https://radar.offseq.com/threat/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now-99579d9a7c571599 #OffSeq #WordPress #RCE #Vuln
-
WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. https://radar.offseq.com/threat/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now-99579d9a7c571599 #OffSeq #WordPress #RCE #Vuln
-
WordPress Core "wp2shell" CRITICAL RCE chain (CVE-2026-63030 & CVE-2026-60137) actively exploited. Affects 6.9.0 – 6.9.4 & 7.0.0 – 7.0.1. Public PoCs out. Patch to 6.9.5/7.0.2 ASAP. Block REST API endpoints as temp mitigation. https://radar.offseq.com/threat/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now-99579d9a7c571599 #OffSeq #WordPress #RCE #Vuln
-
CVE-2026-13446: IBM Langflow OSS 1.0.0 – 1.10.1 contains hard-coded credentials (CRITICAL, CVSS 9.8). Total system compromise possible. No patch yet — restrict access, monitor activity. More: https://radar.offseq.com/threat/cve-2026-13446-cwe-798-use-of-hard-coded-credentia-e33f708cc1420dc3 #OffSeq #Vuln #Cybersecurity #IBM
-
CVE-2026-13446: IBM Langflow OSS 1.0.0 – 1.10.1 contains hard-coded credentials (CRITICAL, CVSS 9.8). Total system compromise possible. No patch yet — restrict access, monitor activity. More: https://radar.offseq.com/threat/cve-2026-13446-cwe-798-use-of-hard-coded-credentia-e33f708cc1420dc3 #OffSeq #Vuln #Cybersecurity #IBM
-
CVE-2026-13446: IBM Langflow OSS 1.0.0 – 1.10.1 contains hard-coded credentials (CRITICAL, CVSS 9.8). Total system compromise possible. No patch yet — restrict access, monitor activity. More: https://radar.offseq.com/threat/cve-2026-13446-cwe-798-use-of-hard-coded-credentia-e33f708cc1420dc3 #OffSeq #Vuln #Cybersecurity #IBM
-
CVE-2026-13446: IBM Langflow OSS 1.0.0 – 1.10.1 contains hard-coded credentials (CRITICAL, CVSS 9.8). Total system compromise possible. No patch yet — restrict access, monitor activity. More: https://radar.offseq.com/threat/cve-2026-13446-cwe-798-use-of-hard-coded-credentia-e33f708cc1420dc3 #OffSeq #Vuln #Cybersecurity #IBM
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
-
MohibShaikh clawvet API server <0.7.5 (CVE-2026-62241) suffers a CRITICAL flaw: hard-coded JWT secret enables unauthenticated user data access and session cookie forgery. Change secrets & limit endpoint access. https://radar.offseq.com/threat/cve-2026-62241-missing-authentication-for-critical-b8ebafbae06b4bce #OffSeq #CVE202662241 #vuln
-
MohibShaikh clawvet API server <0.7.5 (CVE-2026-62241) suffers a CRITICAL flaw: hard-coded JWT secret enables unauthenticated user data access and session cookie forgery. Change secrets & limit endpoint access. https://radar.offseq.com/threat/cve-2026-62241-missing-authentication-for-critical-b8ebafbae06b4bce #OffSeq #CVE202662241 #vuln
-
MohibShaikh clawvet API server <0.7.5 (CVE-2026-62241) suffers a CRITICAL flaw: hard-coded JWT secret enables unauthenticated user data access and session cookie forgery. Change secrets & limit endpoint access. https://radar.offseq.com/threat/cve-2026-62241-missing-authentication-for-critical-b8ebafbae06b4bce #OffSeq #CVE202662241 #vuln
-
MohibShaikh clawvet API server <0.7.5 (CVE-2026-62241) suffers a CRITICAL flaw: hard-coded JWT secret enables unauthenticated user data access and session cookie forgery. Change secrets & limit endpoint access. https://radar.offseq.com/threat/cve-2026-62241-missing-authentication-for-critical-b8ebafbae06b4bce #OffSeq #CVE202662241 #vuln