Overview
- mdjnelson
- moodle-mod_customcert
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CRITICAL: CVE-2026-30884 in mdjnelson moodle-mod_customcert (<4.4.9, 5.0.0 – 5.0.3) enables cross-course certificate tampering by teachers. Update to 4.4.9/5.0.3+ and review permissions. https://radar.offseq.com/threat/cve-2026-30884-cwe-639-authorization-bypass-throug-1e3f429f #OffSeq #Moodle #Infosec #Vulnerability
Overview
- GL-iNet
- Comet KVM
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ CVE-2026-32292: CRITICAL vuln in GL-iNet Comet KVM (CVSS 9.3) — web UI lacks brute-force protections. No patch yet. Restrict access, use strong creds, monitor logs! Details: https://radar.offseq.com/threat/cve-2026-32292-cwe-307-improper-restriction-of-exc-7d4b6f55 #OffSeq #Vulnerability #Cybersecurity #BruteForce
Overview
- Kubernetes
- ingress-nginx
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 1 Post
Overview
- ANGEET
- ES3 KVM
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2026-32297 (CRITICAL, CVSS 9.3): ANGEET ES3 KVM allows unauthenticated remote file writes — attackers can take full control. Isolate & restrict access immediately. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-32297-cwe-306-missing-authentication-for--72cb42a6 #OffSeq #CVE202632297 #KVM #Vuln #Infosec
Overview
- Microsoft
- Windows 11 version 22H2
Description
Statistics
- 4 Posts
Overview
- GL-iNet
- Comet KVM
Description
Statistics
- 1 Post
Fediverse
Hey look, some security reporters made CVE-2026-32291 for one of the flaw I reported in January to GL.iNet, but their reporting is missing one more important detail: up until you setup a password in the user interface, root ssh access is also available without a password.
I was told by the vendor that this was as working as intended.
https://ap.samueldr.com/notice/B21lr6Uhi3Xs4qBiG8
Anyway, I guess I just don't know how to play the CVE game, as that would likely have applied I guess.
Overview
- Hitachi Vantara
- Pentaho Data Integration and Analytics
Description
Statistics
- 1 Post
Overview
- kanboard
- kanboard
Description
Statistics
- 1 Post
Fediverse
Published the writeup for the authenticated SQL injection vulnerability in Kanboard - CVE-2026-33058.
https://0dave.ch/posts/cve-2026-33058/
https://www.cve.org/CVERecord?id=CVE-2026-33058
https://github.com/kanboard/kanboard/security/advisories/GHSA-f62r-m4mr-2xhh