Overview
- Qode Interactive
- Tiare Membership
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2025-13540 (CRITICAL): Qode Tiare Membership plugin lets unauth'd users register as admins via REST API. All versions ≤1.2 affected. No patch—disable or restrict endpoint ASAP! More: https://radar.offseq.com/threat/cve-2025-13540-cwe-269-improper-privilege-manageme-f3141125 #OffSeq #WordPress #CVE202513540 #Infosec
Overview
Description
Statistics
- 1 Post
Fediverse
ASUS warns of new critical auth-bypass flaw in AiCloud routers
https://www.bleepingcomputer.com/news/security/asus-warns-of-new-critical-auth-bypass-flaw-in-aicloud-routers/
ASUS has issued new firmware updates to address nine security vulnerabilities, including a critical authentication bypass flaw affecting routers with the AiCloud feature enabled.
AiCloud is a remote-access service built into many ASUS routers, allowing users to stream media or access files from their personal devices as if they were cloud-hosted.
According to the company, the critical vulnerability CVE-2025-59366 stems from an “unintended side effect” of the router’s Samba functionality. This flaw may allow certain functions to be executed without proper authorization.
In its Monday advisory, ASUS urged all customers to update their router firmware to the latest version immediately to ensure protection.
Overview
- The Ray Team
- Anyscale Ray
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2025-34351 (CRITICAL): Anyscale Ray 2.52.0 has token auth OFF by default—remote attackers can execute code via mgmt interfaces! Enable RAY_AUTH_MODE=token, restrict access, audit configs. Full details: https://radar.offseq.com/threat/cve-2025-34351-cwe-1188-insecure-default-initializ-f281119f #OffSeq #CVE202534351 #Ray #Security
Overview
- Automated Logic
- WebCTRL
Description
Statistics
- 1 Post
Overview
- djangoproject
- Django
- django
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- DirectoryThemes
- Tiger
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2025-13675 in DirectoryThemes Tiger (WordPress) allows unauthenticated privilege escalation via 'paypal-submit.php.' All versions ≤101.2.1 affected. Disable the file & monitor admin accounts. https://radar.offseq.com/threat/cve-2025-13675-cwe-269-improper-privilege-manageme-85b1b12c #OffSeq #WordPress #Vuln #InfoSec
Overview
- Zenitel
- TCIV-3+
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2025-64128 (CVSS 10) in Zenitel TCIV-3+—unauthenticated remote OS command injection. No patch yet. Segment, restrict access, monitor for attacks. ICS & public safety devices at risk! https://radar.offseq.com/threat/cve-2025-64128-cwe-78-in-zenitel-tciv-3-0d3761ca #OffSeq #Vulnerability #ICS #Infosec
Overview
Description
Statistics
- 1 Post
Bluesky
Overview
Description
Statistics
- 1 Post