24h | 7d | 30d

Overview

  • Cisco
  • Cisco Catalyst SD-WAN Manager

25 Feb 2026
Published
06 Mar 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.02%

KEV

Description

A vulnerability in the Data Collection Agent (DCA) feature of Cisco Catalyst SD-WAN Manager could allow an authenticated, local attacker to gain DCA user privileges on an affected system. To exploit this vulnerability, the attacker must have valid vmanage credentials on the affected system. This vulnerability is due to the presence of a credential file for the DCA user on an affected system. An attacker could exploit this vulnerability by accessing the filesystem as a low-privileged user and reading the file that contains the DCA password from that affected system. A successful exploit could allow the attacker to access another affected system and gain DCA user privileges. Note: Cisco Catalyst SD-WAN Manager releases 20.18 and later are not affected by this vulnerability.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 19 hours ago

Bluesky

Profile picture fallback
Cisco has confirmed active exploitation targeting two vulnerabilities in Cisco Catalyst SD-WAN Manager (formerly vManage), tracked as CVE-2026-20122 and CVE-2026-20128. socradar.io/blog/cisco-c...
  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback
Cisco advierte sobre la explotación de SD-WAN Manager y corrige 48 vulnerabilidades de firewall. Los hackers ya están explotando activamente dos fallos críticos (CVE-2026-20128 y CVE-2026-20122). Si usas equipos Cisco, ¡parcha ahora antes de que sea tarde! www.linkedin.com/pulse/cisco-...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • timstrifler
  • Exclusive Addons for Elementor

13 Mar 2024
Published
01 Aug 2024
Updated

CVSS v3.1
MEDIUM (6.4)
EPSS
6.68%

KEV

Description

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via data attribute in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
Unmasking the Latest MOVEit Transfer Zero-Day: A Deep Dive into the CVE-2024-1234 SQLi Exploit and Digital Forensics + Video Introduction: The digital supply chain has once again proven to be the Achilles' heel of enterprise security. Recent threat intelligence reports indicate a sophisticated…
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • SimStudioAI
  • sim

02 Mar 2026
Published
02 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%

KEV

Description

On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host restrictions. An attacker can leverage these endpoints to connect to any reachable MongoDB instance and perform unauthorized operations including reading, modifying, and deleting data.

Statistics

  • 1 Post

Last activity: 7 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-3431 - On SimStudio version below to 0.5.74, the MongoDB tool endpoints accept arbitrary connection parameters from the caller without authentication or host... https://www.cyberhub.blog/cves/CVE-2026-3431
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • wpeverest
  • User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

03 Mar 2026
Published
03 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.07%

KEV

Description

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

Statistics

  • 2 Posts

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Hackers are exploiting a WordPress plugin flaw (CVE-2026-1492) that lets attackers create admin accounts without authentication on

If you run WordPress, update or disable the plugin immediately.

bleepingcomputer.com/news/secu

  • 0
  • 0
  • 1
  • 19h ago

Overview

  • gogs
  • gogs

05 Mar 2026
Published
07 Mar 2026
Updated

CVSS v3.1
HIGH (8.7)
EPSS
0.03%

KEV

Description

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue description functionality. The application's HTML sanitizer explicitly allows data: URI schemes, enabling authenticated users to inject arbitrary JavaScript execution via malicious links. This issue has been patched in version 0.14.2.

Statistics

  • 1 Post

Last activity: 21 hours ago

Bluesky

Profile picture fallback
📌 CVE-2026-26022 - Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and i... https://www.cyberhub.blog/cves/CVE-2026-26022
  • 0
  • 0
  • 0
  • 21h ago

Overview

  • Anhui Seeker Electronic Technology Co., LTD.
  • XikeStor SKS8310-8X

07 Mar 2026
Published
07 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in the /goform/PingTestSet endpoint that allows unauthenticated remote attackers to execute arbitrary operating system commands. Attackers can inject malicious commands through the destIp parameter to achieve remote code execution with root privileges on the network switch.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CVE-2026-25070 in XikeStor SKS8310-8X allows unauthenticated remote OS command injection (CVSS 9.3). No patch yet. Restrict access, segment networks, and monitor endpoints. Full root risk! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • niteosoft
  • Simple Job Script

04 Mar 2026
Published
05 Mar 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.18%

KEV

Description

Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the landing_location parameter. Attackers can send POST requests to the searched endpoint with malicious SQL payloads to bypass authentication and extract sensitive database information.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
📌 CVE-2019-25498 - Simple Job Script contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code t... https://www.cyberhub.blog/cves/CVE-2019-25498
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Apache Software Foundation
  • Apache ZooKeeper
  • org.apache.zookeeper:zookeeper

07 Mar 2026
Published
07 Mar 2026
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive information stored in client configuration in the client's logfile. Configuration values are exposed at INFO level logging rendering potential production systems affected by the issue. Users are recommended to upgrade to version 3.8.6 or 3.9.5 which fixes this issue.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

💡 HIGH severity: CVE-2026-24308 in Apache ZooKeeper 3.8.0 – 3.9.4 logs sensitive config at INFO level. Risk of secret exposure via logs. Patch to 3.8.6/3.9.5 & restrict log access! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Doditsolutions
  • Homey BNB (Airbnb Clone Script)

27 Feb 2026
Published
27 Feb 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.09%

KEV

Description

Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter. Attackers can send GET requests to the admin/getrecord.php endpoint with malicious 'val' values to extract sensitive database information.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
📌 CVE-2019-25493 - Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code throug... https://www.cyberhub.blog/cves/CVE-2019-25493
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Mobiliti
  • e-mobi.hu

06 Mar 2026
Published
06 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
Pending

KEV

Description

WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP WebSocket endpoint using a known or discovered charging station identifier, then issue or receive OCPP commands as a legitimate charger. Given that no authentication is required, this can lead to privilege escalation, unauthorized control of charging infrastructure, and corruption of charging network data reported to the backend.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

⚠️ CVE-2026-26051 (CRITICAL, CVSS 9.4) in Mobiliti e-mobi.hu: Unauthenticated OCPP WebSocket endpoints allow charging station impersonation + backend manipulation. Enforce strong auth & monitor now. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 7h ago
Showing 11 to 20 of 77 CVEs