A vulnerability was found in firetree RockPress Plugin up to 1.0.17 on WordPress. It has been declared as problematic . This vulnerability affects the function current_user_can of the file profile.php…
cyberintel.kalymoon.com · 53481 articles · updated every 4 hours · grows forever
A vulnerability was found in firetree RockPress Plugin up to 1.0.17 on WordPress. It has been declared as problematic . This vulnerability affects the function current_user_can of the file profile.php…
A vulnerability was found in error311 FileRise up to 3.8.x . It has been rated as critical . This issue affects the function default_please_change_this_key of the component Environment Variable Handle…
A vulnerability categorized as critical has been discovered in error311 FileRise up to 3.7.x . Impacted is the function FileController::deleteShareLink of the component deleteShareLink Endpoint . The …
A vulnerability identified as critical has been detected in Stirling-Tools Stirling-PDF up to 2.5.1 . The affected element is an unknown function of the file /api/v1/convert/markdown/pdf of the compon…
A vulnerability labeled as problematic has been found in labring FastGPT up to 4.14.8.3 . The impacted element is the function pull_request_target . Such manipulation leads to download of code without…
A vulnerability marked as problematic has been reported in QwikDev qwik up to 1.19.1 . This affects an unknown function of the component FormData Parser . Performing a manipulation results in type con…
A vulnerability described as problematic has been identified in creativemindssolutions CM Custom Reports Plugin up to 1.2.7 on WordPress. This impacts an unknown function of the component Setting Hand…
A vulnerability classified as problematic has been found in filamentphp filament up to 4.8.4/5.3.4 . Affected is an unknown function. The manipulation leads to cross site scripting. This vulnerability…
A vulnerability classified as critical was found in sigmade Git-MCP-Server up to 785aa159f262a02d5791a5d8a8e13c507ac42880 . Affected by this vulnerability is the function child_process.exec of the fil…
A vulnerability, which was classified as critical , has been found in Totolink WA300 5.2cu.7112_B20190227 . Affected by this issue is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi . T…
A vulnerability, which was classified as problematic , was found in py-pdf pypdf up to 6.9.0 . This affects an unknown part of the component PDF Handler . Such manipulation leads to resource consumpti…
A vulnerability has been found in h3js h3 up to 1.15.5 and classified as problematic . This vulnerability affects the function formatEventStreamMessage of the component SSE Message Handler . Performin…
A vulnerability was found in PinchTab up to 0.8.2 and classified as critical . This issue affects the function validateDownloadURL of the file /download of the component Internal Service . Executing a…
A vulnerability was found in blakeblackshear frigate up to 0.16.2 . It has been classified as critical . Impacted is an unknown function. The manipulation leads to improper authorization. This vulnera…
A vulnerability was found in blakeblackshear frigate up to 0.16.x . It has been declared as critical . The affected element is an unknown function of the file /users/{username}/password of the compone…
A vulnerability was found in TotalSuite TotalContest Lite Plugin up to 2.9.1 on WordPress. It has been rated as problematic . The impacted element is an unknown function. This manipulation causes dese…
A vulnerability categorized as problematic has been discovered in louislam uptime-kuma up to 2.2.0 . This affects the function require.resolve of the file notification-provider.js . Such manipulation …
A vulnerability identified as problematic has been detected in h3js h3 up to 2.0.0-rc.8/2.0.1-rc.9 . This impacts the function requireBasicAuth . Performing a manipulation results in observable timing…
Yesterday, I discovered a malicious Bash script that installs a GSocket backdoor on the victim's computer. I don't know the source of the script not how it is delivered to the victim.
Phishing Campaign Used AsyncRAT to Maintain Long-Term Network Access A suspected cyberespionage campaign targeted a Libyan oil refinery using commodity malware and politically themed phishing lures. T…
A ransomware gang that claims to be a group of "investigative journalists"? Meet LeakNet - the group using fake CAPTCHA pages to trick employees into hacking themselves. Read more in my article on the…
Apex is an autonomous, AI-powered penetration testing agent designed to operate in black-box mode against live applications. It does not require access to source code, hints, or predefined attack path…
A newly discovered infostealer malware named Speagle has emerged as a serious threat targeting organizations that run Cobra DocGuard, a document security and encryption platform developed by Chinese c…
A high-severity security flaw has been addressed in Bamboo Data Center, an enterprise platform widely used for software build and release management. Tracked as CVE-2026-21570, this Remote Code Execut…