24h | 7d | 30d

Overview

  • FileRun
  • FileRun

11 Aug 2026
Published
14 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
1.67%

KEV

Description

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in shell double-quotes directly to exec() without escapeshellarg() sanitization, allowing filenames such as $(PAYLOAD).mp4 to survive the filename sanitizer and be evaluated as shell commands when ffmpeg, ImageMagick, vips, or stl-thumb processes the file during thumbnail generation.

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

New vulnerability disclosure from
@chocapikk_:

CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.

vulncheck.com/blog/filerun-thu

  • 3
  • 3
  • 0
  • 5h ago

Overview

  • TOTOLINK
  • A800R

14 Aug 2026
Published
14 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.47%

KEV

Description

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument Comment results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-19811 - Critical stack buffer overflow in TOTOLINK A800R routers via setIpQosRules. Remote RCE possible, CVSS 8.8. Public exploit available, unpatched. Update firmware or isolate device now. #CVE #IoT #infosec

valtersit.com/cve/CVE-2026-198

  • 2
  • 0
  • 0
  • 13h ago

Overview

  • F5
  • BIG-IP

15 Oct 2025
Published
31 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
2.21%

Description

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE).   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 2 Posts
  • 5 Interactions

Last activity: 18 hours ago

Bluesky

Profile picture fallback
We are scanning & reporting F5 BIG-IP APM CVE-2025-53521 instances thanks to collaboration with the NCSC-NL SRT. 10 months after vuln disclosure, we still see over 850 IPs vulnerable to potential RCE. Top affected: US with 199 & Japan 182. IP data in Vulnerable HTTP reporting.
  • 1
  • 4
  • 0
  • 18h ago
Profile picture fallback
This vulnerability is known to be exploited in the wild and on CISACyber KEV www.cisa.gov/known-exploi... F5 Advisory: my.f5.com/manage/s/art... Check your reports for IPs tagged 'cve-2025-53521'! Public Dashboard World Map: dashboard.shadowserver.org/statistics/c...
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Wishlist Member
  • Wishlist Member

14 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.34%

KEV

Description

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-12949 - Critical Account Takeover in Wishlist Member WordPress plugin. Insufficient verification allows attacker to merge accounts. CVSS 9.8. Unpatched. Update immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-129

  • 1
  • 1
  • 0
  • 19h ago

Overview

  • Microsoft
  • Microsoft Configuration Manager

14 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.54%

KEV

Description

Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

SCCM sits in your infrastructure like a master key. One HTTP POST from literally anyone in your domain and an attacker owns the whole thing. Patch CVE-2026-47301 now. The rest of the chain stays broken until October 2026.

api.cyfluencer.com/s/potential

  • 0
  • 1
  • 1
  • 11h ago

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
0.87%

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 20 hours ago

Fediverse

Profile picture fallback

🚨 THREAT ALERT: CVE-2026-20349

Active exploitation verified on Cisco ASA & FTD firewalls via a high-severity heap inspection flaw. IT leadership must enforce immediate patch protocols and audit perimeter logs.
thecybermind.co/z7x3

👉 Watch breakdown: youtube.com/shorts/xzFNHt3De3I

  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.05%

KEV

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Statistics

  • 1 Post

Last activity: 21 hours ago

Fediverse

Profile picture fallback

Certighost: cuando un usuario de dominio puede acabar obteniendo un certificado de un Domain Controller (CVE-2026-54121)

Si durante los últimos años ha habido una tecnología de Active Directory que ha pasado de ser la gran olvidada a convertirse en uno de los objetivos favoritos de Red Teams y atacantes reales, esa es Active Directory Certificate Services (AD CS).

hackplayers.com/2026/07/certig

  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Go standard library
  • net
  • net

21 Jul 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.35%

KEV

Description

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-46600 impacts stdlib in 25 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/665 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Go standard library
  • encoding/xml
  • encoding/xml

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.18%

KEV

Description

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-56859 impacts stdlib in 25 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/669 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • getgrav
  • grav

14 Aug 2026
Published
14 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that execute via Symfony Process for remote code execution.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Grav API plugin <1.0.13 has a CRITICAL flaw (CVE-2026-72830): scoped API keys can inject arbitrary commands into scheduler config, leading to remote code execution. Patch now! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago
Showing 11 to 20 of 60 CVEs