Overview
- fastify
- middie
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2026-22031 - High (8.4)
@fastify/middie is the plugin that adds middleware support on steroids to Fastify. A security vulnerability exists in @fastify/middie prior to version 9.1.0 where middleware registered with a specific path prefix can be bypassed using URL-encoded ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-22031/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Fediverse
GNU C Library fixes a security Issue present since 1996 (getnetbyaddr and getnetbyaddr_r functions can leak the stack contents to the DNS resolver) CVE-2026-0915 #Infosec https://sourceware.org/git/?p=glibc.git;a=commit;h=e56ff82d5034ec66c6a78f517af6faa427f65b0b
Overview
- ibericode
- koko-analytics
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2026-22850 - High (8.3)
Koko Analytics is an open-source analytics plugin for WordPress. Versions prior to 2.1.3 are vulnerable to arbitrary SQL execution through unescaped analytics export/import and permissive admin SQL import. Unauthenticated visitors can submit arbit...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-22850/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 2 Posts
Fediverse
🟠 CVE-2026-1139 - High (8.8)
A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The expl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-1139/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- siyuan-note
- siyuan
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
Ever named your own CVE? We sure did. 😏
Meet PTT-2025-021 (aka CVE-2025-63261).
A vulnerability in AWStats hiding inside cPanel.
One misplaced "|" flips log analysis into command execution.
No magic. Just unsafe open() and legacy code trusting input.
On our blog, we walk through how we traced it, proved it, and why this vulnerability class still bites.
Special thanks to Matei Badanoiu for the research. 👏
See the full attack path in Part 1: https://pentest-tools.com/blog/cpanel-cve-ptt-2025-021-part-1
Overview
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2025-61684 - High (7.5)
Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process usin...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-61684/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 1 Post
Overview
- fastify
- fastify-express
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2026-22037 - High (8.4)
The @fastify/express plugin adds full Express compatibility to Fastify. A security vulnerability exists in @fastify/express prior to version 4.0.3 where middleware registered with a specific path prefix can be bypassed using URL-encoded characters...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-22037/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Totolink
- LR350
Description
Statistics
- 2 Posts
Fediverse
🟠 CVE-2026-1155 - High (8.8)
A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack ma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-1155/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack