Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
π CVE-2025-13928 - High (7.5)
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.6.4, 18.7 before 18.7.2, and 18.8 before 18.8.2 that could have allowed an unauthenticated user to cause a denial of service condition by exploiting incorrec...
π https://www.thehackerwire.com/vulnerability/CVE-2025-13928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- livewire
- livewire
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
βΌοΈLivepyre: A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
GitHub: https://github.com/synacktiv/Livepyre
Writeup: https://www.synacktiv.com/en/publications/livewire-remote-command-execution-through-unmarshaling
CVSS: 9.2
Description: Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.
Overview
- SmarterTools
- SmarterMail
Description
Statistics
- 1 Post
- 1 Interaction
Bluesky
Overview
- AlchemyCMS
- alchemy_cms
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
βΌοΈCVE-2026-23885: AlchemyCMS has Authenticated Remote Code Execution (RCE) via eval injection in ResourcesHelper
CVSS: 6.4
CVE Published: January 19th, 2026
Advisory/Exploit/PoC: https://github.com/advisories/GHSA-2762-657x-v979
Description: Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby `eval()` function to dynamically execute a string provided by the `resource_handler.engine_name` attribute in `Alchemy::ResourcesHelper#resource_url_proxy`. The vulnerability exists in `app/helpers/alchemy/resources_helper.rb` at line 28. The code explicitly bypasses security linting with `# rubocop:disable Security/Eval`, indicating that the use of a dangerous function was known but not properly mitigated. Since `engine_name` is sourced from module definitions that can be influenced by administrative configurations, it allows an authenticated attacker to escape the Ruby sandbox and execute arbitrary system commands on the host OS. Versions 7.4.12 and 8.0.3 fix the issue by replacing `eval()` with `send()`.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
π΄ CVE-2025-69764 - Critical (9.8)
Tenda AX3 firmware v16.03.12.11 contains a stack-based buffer overflow in the formGetIptv function due to improper handling of the stbpvid stack buffer, which may result in memory corruption and remote code execution.
π https://www.thehackerwire.com/vulnerability/CVE-2025-69764/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Solvera Software Services Trade Inc.
- Teknoera
Description
Statistics
- 1 Post
Fediverse
π CVE-2025-10856 - High (8.1)
Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection.This issue affects Teknoera: through 01102025.
π https://www.thehackerwire.com/vulnerability/CVE-2025-10856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
π CVE-2025-27378 - High (8.6)
AES contains a SQL injection vulnerability due to an inactive configuration that prevents the latest SQL parsing logic from being applied. When this configuration is not enabled, crafted input may be improperly handled, allowing attackers to injec...
π https://www.thehackerwire.com/vulnerability/CVE-2025-27378/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Dell
- Unisphere for PowerMax
Description
Statistics
- 1 Post
Fediverse
π CVE-2025-36588 - High (8.8)
Dell Unisphere for PowerMax, version(s) 10.2.0.x, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnera...
π https://www.thehackerwire.com/vulnerability/CVE-2025-36588/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- EXERT Computer Technologies Software Ltd. Co.
- Education Management System
Description
Statistics
- 1 Post
Fediverse
π CVE-2025-10024 - High (7.5)
Authorization Bypass Through User-Controlled Key vulnerability in EXERT Computer Technologies Software Ltd. Co. Education Management System allows Parameter Injection.This issue affects Education Management System: through 23.09.2025.
π https://www.thehackerwire.com/vulnerability/CVE-2025-10024/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack