Overview
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.
#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit
Bluesky
Overview
- Comfy-Org
- ComfyUI
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. https://radar.offseq.com/threat/cve-2026-68771-deserialization-of-untrusted-data-in-comfy-org-comfyui-029fe0d26fda144c #OffSeq #CVE202668771 #infosec
Overview
- CyberTimon
- RapidRAW
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Overview
- GNOME
- gnome-remote-desktop
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Unknown
- User Profile Builder
Description
Statistics
- 1 Post
Fediverse
CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. https://radar.offseq.com/threat/cve-2026-15368-cwe-269-improper-privilege-management-in-user-profile-builder-7cbf3fdcef75f1fb #OffSeq #WordPress #Infosec #CVE202615368 🔒
Overview
- realtyna
- Realtyna Organic IDX plugin + WPL Real Estate
Description
Statistics
- 1 Post
Fediverse
CVE-2026-16236 - Critical RCE in Realtyna Organic IDX WP plugin. Arbitrary file upload from subscriber-level. CVSS 8.8. No patch. Disable plugin now. #CVE #WordPress #infosec
Overview
- bitpressadmin
- Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation
Description
Statistics
- 1 Post
Fediverse
CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-15006-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ee5b332d75a54eb5 #OffSeq #WordPress #Vuln
Overview
- tigroumeow
- AI Engine – The Chatbot, AI Framework & MCP for WordPress
Description
Statistics
- 1 Post
Fediverse
CVE-2026-15988 - CSRF in AI Engine WordPress plugin enables attacker to create admin accounts via REST auth bypass. CVSS 8.8. Unpatched - disable plugin now. #CVE #WordPress #infosec