Overview
- Red Hat
- Red Hat Directory Server 11.5 E4S for RHEL 8
- redhat-ds:11
Description
Statistics
- 1 Post
Overview
- chamilo
- chamilo-lms
Description
Statistics
- 2 Posts
Fediverse
๐ CVE-2026-33698: Chamilo LMS (<1.11.38) has a CRITICAL flaw โ exposed install/ dir lets unauth attackers execute PHP & modify files. Upgrade to 1.11.38+ & restrict install/ directory access now! Details: https://radar.offseq.com/threat/cve-2026-33698-cwe-552-files-or-directories-access-2b2046ff #OffSeq #Chamilo #Vuln
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- tomdever
- wpForo Forum
Description
Statistics
- 1 Post
Fediverse
๐ก๏ธ CVE-2026-5809: HIGH severity vuln in wpForo Forum plugin โค3.0.2 lets subscriber+ users delete arbitrary files (e.g., wp-config.php). No patch yet โ restrict permissions & monitor topic edits for abuse. https://radar.offseq.com/threat/cve-2026-5809-cwe-73-external-control-of-file-name-7d1ff4ec #OffSeq #WordPress #Vuln #InfoSec
Overview
- wolfSSL
- wolfSSL
Description
Statistics
- 1 Post
Overview
- Microsoft
- Windows Server 2025
Description
Statistics
- 2 Posts
Overview
- Sonos
- Era 300
Description
Statistics
- 2 Posts
Fediverse
๐จ CRITICAL: CVE-2026-4149 in Sonos Era 300 (v17.5) allows unauth RCE via SMB out-of-bounds flaw (CVSS 10.0). No patch yet โ restrict SMB access, monitor advisories. https://radar.offseq.com/threat/cve-2026-4149-cwe-119-improper-restriction-of-oper-dcf90312 #OffSeq #Sonos #Vuln #RCE
โ ๏ธ CVE-2026-4149: Sonos Era 300 (v17.5) has a CRITICAL remote code execution vulnerability via SMB, allowing kernel-level compromise without auth. No patch yet โ restrict SMB access! https://radar.offseq.com/threat/cve-2026-4149-cwe-119-improper-restriction-of-oper-dcf90312 #OffSeq #Sonos #Infosec #RCE
Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 1 Post
Fediverse
From over a week ago but anyway, CVE-2026-34504 in OpenClaw's image generation pipeline is a reminder that AI agent frameworks inherit all the classic web vulnerabilities plus their own unique attack surface.
An SSRF in the Fal provider means a malicious relay can have the agent fetch internal URLs and leak metadata through the generated output.
I switched from OpenClaw to Hermes Agent a couple of weeks ago, and I need to explore in detail how Hermes handles this stuff.