Overview
- JetBrains
- Exposed
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-108474: JetBrains Exposed (<1.5.1) faces CRITICAL SQL injection (CWE-89). Exploitation can fully compromise DBs — upgrade to 1.5.1+ now! CVSS 9.8. https://radar.offseq.com/threat/cve-2026-108474-cwe-89-in-jetbrains-exposed-73385fdc0142aed6 #OffSeq #SQLi #JetBrains #AppSec
Discover the latest JetBrains software vulnerabilities, including TeamCity RCE bugs and Exposed SQLi flaws. Apply security patches immediately.
#JetBrains #Vulnerability #TeamCity #CyberSecurity #CVE2026108474
Overview
- NetScaler
- ADC
Description
Statistics
- 2 Posts
Fediverse
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix has released patches for CVE-2026-107406, a critical (CVSS 9.5) memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial-of-service in SAML deployments. The flaw is distinct from the NetScaler zero-day Citrix warned about earlier this week. Administrators are urged to patch immediately. https://thehackernews.com/2026/10/citrix-patches-critical-netscaler-flaw.html
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.
https://linuxmint.hu/hir/2026/10/riasztas-a-wordpress-core-t-erinto-serulekenysegrol
#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság
Overview
- Thinkst Applied Research
- OpenCanary
- opencanary
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. https://www.valtersit.com/cve/CVE-2026-85219/ #CVE #infosec #cybersecurity
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-67827: unauthenticated RCE in ZLMediaKit HTTP API (CVSS 9.8). setServerConfig lets attackers inject shell commands into ffmpeg.snap, executed via getSnap. No patch yet. Disable or restrict the API now. https://www.valtersit.com/cve/CVE-2026-67827/ #CVE #infosec #cybersecurity
Overview
- htplugins
- Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-94589: CRITICAL RCE in Extensions For CF7 (<=3.4.5) for WordPress. Unauth attackers can upload and run malicious files — full compromise possible. Restrict uploads, monitor activity, and check for fixes. https://radar.offseq.com/threat/cve-2026-94589-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-htplugins-extensions-for-cf7-1b07904cb30ec057 #OffSeq #WordPress #CVE202694589 #infosec
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-88402 NocoBase v2.1.21 SQL injection in checkSQL, CVSS 9.8, unpatched. Crafted SQL exposes sensitive database data. Patch status unknown, so restrict exposure now. https://www.valtersit.com/cve/CVE-2026-88402/ #CVE #infosec
Overview
- whyun
- WPCOM Member
Description
Statistics
- 1 Post
Fediverse
WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. https://radar.offseq.com/threat/cve-2026-104803-cwe-287-improper-authentication-in-whyun-wpcom-member-4f47db1288fd1984 #OffSeq #WordPress #Infosec #CVE2026104803
Overview
- ThemeREX Group
- Booklovers
- booklovers
Description
Statistics
- 1 Post
Fediverse
Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: https://radar.offseq.com/threat/cve-2026-62045-deserialization-of-untrusted-data-in-themerex-group-booklovers-71a61b206a138f37 #OffSeq #CVE202662045 #WordPress #Vuln #infosec
Overview
- ThemeREX Group
- Camelia
- camelia
Description
Statistics
- 1 Post
Fediverse
CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 https://radar.offseq.com/threat/cve-2026-93944-deserialization-of-untrusted-data-in-themerex-group-camelia-9f283474b74167fd #OffSeq #Infosec #Vulnerability