24h | 7d | 30d

Overview

  • RocketGenius
  • Gravity SMTP

31 Mar 2026
Published
08 Apr 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
2.98%

KEV

Description

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report. This makes it possible for unauthenticated attackers to retrieve detailed system configuration data including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and any API keys/tokens configured in the plugin.

Statistics

  • 5 Posts
  • 2 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

Hackers are mass-exploiting a Gravity SMTP flaw to steal API keys from 100,000 WordPress sites
thenextweb.com/news/gravity-sm

Posted into Sustainability @sustainability-thenextweb

  • 1
  • 0
  • 1
  • 23h ago
Profile picture fallback

A Gravity SMTP WordPress plugin flaw is already being exploited.

CVE-2026-4020 can expose API keys, OAuth tokens, and system data through an unauthenticated REST API endpoint.

Wordfence says it has blocked 17M+ exploit attempts.

Read the full story: thehackernews.com/2026/06/hack

  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback

📰 Hackers Actively Exploit Gravity SMTP Flaw (CVE-2026-4020) to Steal API Keys from 100K WordPress Sites

📢 ATTENTION WordPress Admins: A flaw in the Gravity SMTP plugin (CVE-2026-4020) is being mass-exploited to steal API keys. 100K sites at risk. Update to v2.1.5 & rotate all email service credentials NOW! #WordPress #Vulnerability #CyberSecurity

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/gr

  • 0
  • 0
  • 0
  • 19h ago

Bluesky

Profile picture fallback
Gravity SMTP Vulnerability Under Active Exploitation, Over 17 Million Attack Attempts Detected #CVE20264020 #GravitySMTPexploit #GravitySMTPvulnerability
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Splunk
  • Splunk Enterprise

10 Jun 2026
Published
19 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
10.04%

Description

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

Statistics

  • 3 Posts
  • 5 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CISA: Splunk Enterprise flaw actively exploited, patch by Sunday

CVE-2026-20253 in Splunk Enterprise is actively exploited in the wild, allowing attackers to create or truncate arbitrary files on vulnerable systems. Federal agencies are mandated to patch by Sunday. Any organization running unpatched Splunk Enterprise is at immediate risk of file manipulation and…

threatnoir.com/focus

  • 0
  • 0
  • 1
  • 21h ago

Bluesky

Profile picture fallback
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security www.helpnetsecurity.com/2026/06/19/s...
  • 2
  • 3
  • 0
  • 7h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 14 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

29-year-old bug in Squid that can leak internal memory, works in default configs

blog.calif.io/p/squidbleed-cve

  • 8
  • 6
  • 0
  • 19h ago

Overview

  • crmperks
  • Database for Contact Form 7, WPforms, Elementor forms

20 Jun 2026
Published
20 Jun 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
Pending

KEV

Description

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Successful exploitation requires an administrator to view or edit the poisoned form entry, at which point PHP's bracket parser reshapes the attacker-crafted JSON key to bypass the stored-path isset check and trigger deletion of the traversal-specified file.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-9843 - Critical RCE in Database for Contact Form 7, WPforms, Elementor forms for WordPress. Arbitrary file deletion via insufficient path validation. CVSS 8.1. No patch available. Immediately review and restrict plugin usage. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-984

  • 1
  • 0
  • 0
  • 11h ago

Overview

  • EaseUS
  • Partition Master

21 Jun 2026
Published
21 Jun 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
Pending

KEV

Description

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor explains: "We have confirmed that this issue was present only in older versions of the product. Our product has since been updated, and the issue has been resolved in the latest version, so it no longer exists."

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-12781 (HIGH, CVSS 8.5) found in EaseUS Partition Master 14.0 – 14.5: improper access controls in kernel driver epmntdrv.sys enable local privilege escalation. Upgrade to latest version ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • BerriAI
  • litellm

21 Jun 2026
Published
21 Jun 2026
Updated

CVSS v4.0
MEDIUM (5.3)
EPSS
Pending

KEV

Description

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/rest_endpoints.py of the component MCP Server Connection Testing. The manipulation leads to server-side request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

CVE-2026-12774: SSRF in BerriAI litellm v1.82.0 – 1.82.2 (MEDIUM, CVSS 5.3). Remote attackers can manipulate server requests via _execute_with_mcp_client. No patch yet — monitor vendor advisories. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Checkmk GmbH
  • Checkmk

11 Mar 2024
Published
13 Feb 2025
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.34%

KEV

Description

Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Las PYMEs enfrentan crecientes ciberataques que demandan diagnósticos expertos para eliminar vulnerabilidades; mientras, ataques avanzados a Active Directory y nuevas cepas de ransomware como Prinz Eugen amenazan con control total y cifrado estratégico sin aviso, haciendo urgente mejorar defensa y monitoreo en redes empresariales. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 21/06/26 📆 |====

🔒 CÓMO PROTEGER TU PYME DE VULNERABILIDADES TECNOLÓGICAS

Con el crecimiento digital, las PYMEs son un blanco creciente para ciberataques. Realizar un diagnóstico gratuito con expertos en ciberseguridad como ironGate CyberSecurity es vital para identificar y corregir vulnerabilidades en tu software antes de que los atacantes las exploten. La prevención es la mejor defensa para mantener seguros tus datos y operaciones. Conoce más sobre cómo proteger tu empresa aquí 👉 djar.co/nZAKx

💀 ATAQUE AVANZADO A ACTIVE DIRECTORY CON ESCALADA DE PRIVILEGIOS

Un nuevo método para comprometer sistemas Windows a través de Active Directory ha sido detectado, utilizando archivos maliciosos en formato comprimido y técnicas sofisticadas de escalada de privilegios, incluyendo la explotación de la vulnerabilidad CVE-2024-0670. Esta amenaza permite a los atacantes obtener control total sobre el entorno empresarial, representando un riesgo crítico para la infraestructura TI. Infórmate sobre cómo identificar y mitigar esta amenaza 👉 djar.co/zsk0

🛡️ NUEVO RANSOMWARE 'PRINZ EUGEN' FOCALIZADO EN ARCHIVOS RECIENTES

El ransomware Prinz Eugen está evolucionando: prioriza archivos modificados recientemente para cifrar, aumentando el impacto en las víctimas. Además, se destaca porque no deja notas de rescate visibles, dificultando la respuesta inmediata. Comprender esta variante es clave para fortalecer las estrategias de respaldo y respuesta ante incidentes. Aprende más sobre esta amenaza y cómo protegerte 👉 djar.co/5Grol

⚠️ AMENAZAS CIBERNÉTICAS AVANZADAS QUE ATACAN REDES EMPRESARIALES

Se han detectado nuevas campañas de malware avanzado dirigidas a redes corporativas, que emplean técnicas de evasión para evitar ser detectadas por sistemas tradicionales. Estas amenazas explotan vulnerabilidades poco conocidas, poniendo en riesgo la integridad y confidencialidad de la información. Mantenerse actualizado en defensa y monitoreo proactivo es imprescindible para enfrentar estos ataques. Descubre las últimas estrategias para proteger tu red 👉 djar.co/Ejcn

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • moby
  • spdystream

16 Apr 2026
Published
17 Apr 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.43%

KEV

Description

spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.

Statistics

  • 3 Posts

Last activity: Last hour

Bluesky

Profile picture fallback
🔐 A CVE-2026-35469 expõe clusters #Kubernetes a DoS via SPDY. Aprenda a verificar, corrigir e mitigar no Fedora com um script pronto. Saiba mais: -> tinyurl.com/5fmjhyeb #Fedora
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
🛡️ ATENÇÃO ADMINISTRADORES KUBERNETES A CVE-2026-35469 expõe clusters Fedora a ataques de negação de serviço via SPDY. Um frame manipulado = memória esgotada = serviço fora do ar. Saiba mais: -> tinyurl.com/5xwvthw7
  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback
🔐 CVE-2026-35469: vulnerabilidade DoS no #Kubernetes 1.35 via SPDY streaming. Atualize para 1.35.6 AGORA. Saiba mais: -> tinyurl.com/ysrzhtbr #Fedora
  • 0
  • 0
  • 0
  • Last hour

Overview

  • joomshaper.net
  • SP LMS extension for Joomla

20 Jun 2026
Published
20 Jun 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
Pending

KEV

Description

SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

JoomShaper SP LMS for Joomla (v1.0.0 – 4.1.3) hit by CRITICAL vuln (CVE-2026-48909): unsafe cookie deserialization enables unauth RCE. No patch yet — restrict access & monitor traffic. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
Atenção, admins Debian! A CVE-2026-52717 no plugin ffmpeg do GStreamer (gst-libav1.0) pode comprometer seu sistema com um simples arquivo de mídia. Saiba mais: -> tinyurl.com/2s4htzrr #Debian
  • 0
  • 0
  • 0
  • 22h ago
Showing 1 to 10 of 30 CVEs