Overview
Description
Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.
Statistics
- 1 Post
- 1 Interaction
Last activity: 5 hours ago
Overview
Description
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in the endpoint that allow unauthenticated attackers to manipulate database queries through GET parameters. Attackers can inject SQL code into parameters like emlak_durumu, emlak_tipi, il, ilce, kelime, and semt to extract sensitive database information or perform time-based blind SQL injection attacks.
Statistics
- 1 Post
- 1 Interaction
Last activity: 6 hours ago
Overview
Description
A flaw was identified in Moodleโs backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
Statistics
- 1 Post
- 1 Interaction
Last activity: 2 hours ago
Overview
Description
Versions of the Traccar open-source GPS tracking system starting with 6.11.1 contain an issue in which authenticated users can execute arbitrary JavaScript in the context of other users' browsers by uploading malicious SVG files as device images. The application accepts SVG file uploads without sanitization and serves them with the `image/svg+xml` Content-Type, allowing embedded JavaScript to execute when victims view the image. As of time of publication, it is unclear whether a fix is available.
Statistics
- 1 Post
- 1 Interaction
Last activity: 9 hours ago
Overview
- Copeland
- Copeland XWEB 300D PRO
27 Feb 2026
Published
27 Feb 2026
Updated
CVSS v3.1
CRITICAL (10.0)
EPSS
Pending
KEV
Description
An authentication bypass vulnerability exists in Copeland XWEB Pro
version 1.12.1 and prior, enabling any attackers to bypass the
authentication requirement and achieve pre-authenticated code execution
on the system.
Statistics
- 1 Post
Last activity: 1 hour ago
Fediverse
๐จ CVE-2026-21718: CRITICAL auth bypass in Copeland XWEB 300D PRO (โค1.12.1). Remote code exec possible โ no user interaction. No patch yet. Segment & monitor ICS networks! https://radar.offseq.com/threat/cve-2026-21718-cwe-327-in-copeland-copeland-xweb-3-124474ba #OffSeq #ICS #Vulnerability #Cybersecurity
Overview
- Webwiz
- Web Wiz Forums
22 Feb 2026
Published
25 Feb 2026
Updated
CVSS v4.0
HIGH (8.8)
EPSS
0.07%
KEV
Description
Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. Attackers can send GET requests to member_profile.asp with malicious PF values to extract sensitive database information.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- JetBrains
- YouTrack
25 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.00%
KEV
Description
In JetBrains YouTrack before 2025.3.121962 apps were able to send requests to the app permissions endpoint
Statistics
- 1 Post
Last activity: 10 hours ago
Overview
Description
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Statistics
- 1 Post
Last activity: 6 hours ago
Overview
Description
DHCP can add routes to a clientโs routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Statistics
- 1 Post
Last activity: 5 hours ago
Fediverse
Hmm, is this it?
https://nvd.nist.gov/vuln/detail/CVE-2024-3661
Was looking at something recently used to overload ICMP echo Requests for denial of service, this stuff is really interesting
Overview
- Web-ofisi
- Ticaret
22 Feb 2026
Published
25 Feb 2026
Updated
CVSS v4.0
HIGH (8.8)
EPSS
0.07%
KEV
Description
Web Ofisi E-Ticaret v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'a' parameter. Attackers can send GET requests to with malicious 'a' parameter values to extract sensitive database information.
Statistics
- 1 Post
Last activity: 4 hours ago