24h | 7d | 30d

Overview

  • timstrifler
  • Exclusive Addons for Elementor

13 Mar 2024
Published
01 Aug 2024
Updated

CVSS v3.1
MEDIUM (6.4)
EPSS
6.68%

KEV

Description

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Statistics

  • 1 Post

Last activity: 20 hours ago

Bluesky

Profile picture fallback
Unmasking the Latest MOVEit Transfer Zero-Day: A Deep Dive into the CVE-2024-1234 SQLi Exploit and Digital Forensics + Video Introduction: The digital supply chain has once again proven to be the Achilles' heel of enterprise security. Recent threat intelligence reports indicate a sophisticated…
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • rustdesk-client
  • RustDesk Client
  • rustdesk-client

05 Mar 2026
Published
05 Mar 2026
Updated

CVSS v4.0
HIGH (8.2)
EPSS
0.02%

KEV

Description

Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop, strategy processing modules) allows Protocol Manipulation. This vulnerability is associated with program files src/hbbs_http/sync.Rs and program routines stop-service handler in heartbeat loop. This issue affects RustDesk Client: through 1.4.5.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
CVE-2026-30798 - RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload scq.ms/40hDDe2
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • libxml2

02 Feb 2026
Published
17 Feb 2026
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

A flaw was identified in the interactive shell of the xmllint utility, part of the libxml2 project, where memory allocated for user input is not properly released under certain conditions. When a user submits input consisting only of whitespace, the program skips command execution but fails to free the allocated buffer. Repeating this action causes memory to continuously accumulate. Over time, this can exhaust system memory and terminate the xmllint process, creating a denial-of-service condition on the local system.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
🚨 New LOW CVE detected in AWS Lambda 🚨 CVE-2026-1757 impacts libxml2 in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/434 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Doditsolutions
  • Homey BNB (Airbnb Clone Script)

27 Feb 2026
Published
27 Feb 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.11%

KEV

Description

Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id values to extract sensitive database information or cause denial of service.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
📌 CVE-2019-25489 - Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through... https://www.cyberhub.blog/cves/CVE-2019-25489
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • SimStudioAI
  • sim

02 Mar 2026
Published
02 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%

KEV

Description

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-3431 - On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host... https://www.cyberhub.blog/cves/CVE-2026-3431
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Tenda
  • A21

21 Feb 2026
Published
23 Feb 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.08%

KEV

Description

A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a manipulation of the argument ssid can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-2874 - A flaw has been found in Tenda A21 1.0.0.0. Impacted is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set. Executing a... https://www.cyberhub.blog/cves/CVE-2026-2874
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Python Software Foundation
  • CPython

20 Jan 2026
Published
03 Mar 2026
Updated

CVSS v4.0
MEDIUM (5.7)
EPSS
0.04%

KEV

Description

When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not be preserved. This could be used for injecting headers into email messages where addresses are user-controlled and not sanitized.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2025-11468 impacts python in 7 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/441 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Go standard library
  • crypto/x509
  • crypto/x509

06 Mar 2026
Published
06 Mar 2026
Updated

CVSS
Pending
EPSS
0.01%

KEV

Description

When verifying a certificate chain which contains a certificate containing multiple email address constraints which share common local portions but different domain portions, these constraints will not be properly applied, and only the last constraint will be considered.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
🚨 New UNKNOWN CVE detected in AWS Lambda 🚨 CVE-2026-27137 impacts stdlib in 27 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/436 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

13 Jan 2026
Published
26 Feb 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.02%

KEV

Description

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Chasing the Ghost in the Log: A Deep Dive into CVE-2026-20820
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • getsentry
  • sentry

21 Feb 2026
Published
24 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.05%

KEV

Description

Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML SSO implementation which allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance. Self-hosted users are only at risk if the following criteria is met: ore than one organizations are configured (SENTRY_SINGLE_ORGANIZATION = True), or malicious user has existing access and permissions to modify SSO settings for another organization in a multo-organization instance. This issue has been fixed in version 26.2.0. To workaround this issue, implement user account-based two-factor authentication to prevent an attacker from being able to complete authentication with a victim's user account. Organization administrators cannot do this on a user's behalf, this requires individual users to ensure 2FA has been enabled for their account.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-27197 - Sentry is a developer-first error tracking and performance monitoring tool. Versions 21.12.0 through 26.1.0 have a critical vulnerability in its SAML ... https://www.cyberhub.blog/cves/CVE-2026-27197
  • 0
  • 0
  • 0
  • 8h ago
Showing 11 to 20 of 50 CVEs