24h | 7d | 30d

Overview

  • Pending

08 Jul 2013
Published
06 Aug 2024
Updated

CVSS
Pending
EPSS
78.57%

KEV

Description

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

Statistics

  • 3 Posts
  • 3 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.

@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"

borncity.com/blog/2026/08/01/m

#sicherheit #security

  • 0
  • 1
  • 0
  • 5h ago

Bluesky

Profile picture fallback
Jemand einen #Server mit #BMC im Einsatz, der per Internet erreichbar ist? Im vom Baseboard Management Controller (BMC)-Interface verwendeten IPMI 2.0-Protokoll gibt es eine Authentifizierungsschwachstelle (CVE-2013-4786). In Deutschland sind ~3.200 Systeme betroffen. borncity.com/blog/2026/08...
  • 1
  • 1
  • 1
  • 9h ago

Overview

  • rails
  • rails

30 Jul 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.70%

KEV

Description

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming applications are affected when configured to use libvips and accept image uploads from untrusted users. An unauthenticated attacker may exploit this behavior to read arbitrary files accessible to the Rails process, including environment variables and application secrets. Exposure of credentials such as secret_key_base or external-service tokens may enable remote code execution or lateral movement. This issue has been fixed in versions 7.2.3.2, 8.0.5.1 and 8.1.3.1.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.

securityonline.info/cve-2026-6

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Ruby on Rails fixed CVE-2026-66066, a critical 9.5 flaw in Active Storage with libvips image processing that could let unauthenticated attackers read files and expose secret_key_base. #RubyOnRails #ActiveStorage #libvips
  • 0
  • 0
  • 0
  • 5h ago
Profile picture fallback
Rails Active Storage CVE-2026-66066 can allow arbitrary file reads and, with libvips, possible RCE in vulnerable apps. Rails patches are out. #Rails #ActiveStorage #libvips
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Comfy-Org
  • ComfyUI

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.62%

KEV

Description

ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. Attackers can upload a malicious shard_*.pkl file via the unauthenticated POST /upload/image endpoint and then queue a workflow graph via POST /prompt referencing the uploaded file, causing torch.load to deserialize the attacker-controlled pickle payload using __reduce__ and execute arbitrary commands as the ComfyUI process user.

Statistics

  • 2 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

CVE-2026-68771 - Critical RCE in ComfyUI. Unsafe deserialization in LoadTrainingDataset. CVSS 9.8. No patch; stop using /upload/image and /prompt. #CVE #ComfyUI #infosec

valtersit.com/cve/CVE-2026-687

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • CyberTimon
  • RapidRAW

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v4.0
HIGH (7.1)
EPSS
0.27%

KEV

Description

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The vulnerable code path is reachable through two vectors: community presets fetched automatically from the remote preset repository when the victim opens the Community tab, and individual preset files imported directly by the victim via the preset import feature (handle_import_presets_from_file in file_management.rs). The second vector does not require control of the community preset repository and is triggered when a user imports a preset file shared through Discord, forums, or similar channels.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Bluesky

Profile picture fallback
[26.05] rapidraw: fix CVE-2026-64816 https://github.com/NixOS/nixpkgs/pull/547877 https://tracker.security.nixos.org/issues/NIXPKGS-2026-2329 #security
  • 1
  • 0
  • 0
  • 7h ago

Overview

  • Cisco
  • Cisco Secure Firewall Management Center (FMC)

29 Jul 2026
Published
01 Aug 2026
Updated

CVSS v3.1
MEDIUM (5.3)
EPSS
0.79%

Description

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback
  • 0
  • 1
  • 0
  • 4h ago

Overview

  • GNOME
  • gnome-remote-desktop

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS
Pending
EPSS
0.43%

KEV

Description

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations until timeout, exhausting resources and preventing legitimate users from establishing RDP sessions. This issue does not affect the upstream version.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-18358 - DoS in Gnome-Remote-Desktop on RHEL. Unauthenticated RDP flood exhausts resources, blocking legit sessions. CVSS 7.5. No patch yet; restrict RDP access. #CVE #infosec #Linux

valtersit.com/cve/CVE-2026-183

  • 0
  • 1
  • 0
  • 7h ago

Overview

  • Unknown
  • User Profile Builder

01 Aug 2026
Published
01 Aug 2026
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind the automatic login performed after user registration to the newly created account, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators, on sites using a supported but non-default configuration.

Statistics

  • 1 Post

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. radar.offseq.com/threat/cve-20 🔒

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • realtyna
  • Realtyna Organic IDX plugin + WPL Real Estate

31 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.63%

KEV

Description

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2026-16236 - Critical RCE in Realtyna Organic IDX WP plugin. Arbitrary file upload from subscriber-level. CVSS 8.8. No patch. Disable plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-162

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • bitpressadmin
  • Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation

01 Aug 2026
Published
01 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.84%

KEV

Description

The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

Statistics

  • 1 Post

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 15h ago

Overview

  • tigroumeow
  • AI Engine – The Chatbot, AI Framework & MCP for WordPress

01 Aug 2026
Published
01 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.22%

KEV

Description

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-based REST authentication bypass, granted they can trick a site administrator into performing an action such as clicking on a link. This bypass can be combined with WordPress's ?_method=POST method-override support to convert a top-navigation GET request into an authenticated POST to the REST users endpoint, requiring no existing account on the attacker's part.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-15988 - CSRF in AI Engine WordPress plugin enables attacker to create admin accounts via REST auth bypass. CVSS 8.8. Unpatched - disable plugin now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-159

  • 0
  • 0
  • 0
  • 1h ago
Showing 1 to 10 of 25 CVEs