Overview
Description
A security flaw has been discovered in Tenda A21 1.0.0.0. Affected by this issue is the function set_qosMib_list of the file /goform/formSetQosBand. The manipulation of the argument list results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Statistics
- 1 Post
- 1 Interaction
Last activity: 12 hours ago
Overview
- Agenta-AI
- agenta
26 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.05%
KEV
Description
Agenta is an open-source LLMOps platform. A Server-Side Template Injection (SSTI) vulnerability exists in versions prior to 0.86.8 in Agenta's API server evaluator template rendering. Although the vulnerable code lives in the SDK package, it is executed server-side within the API process when running evaluators. This does not affect standalone SDK usage β it only impacts self-hosted or managed Agenta platform deployments. Version 0.86.8 contains a fix for the issue.
Statistics
- 1 Post
- 1 Interaction
Last activity: 5 hours ago
Overview
- discourse
- discourse
26 Feb 2026
Published
27 Feb 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.03%
KEV
Description
Discourse is an open source discussion platform. Prior to versions 2025.12.2, 2026.1.1, and 2026.2.0, when the `patreon_webhook_secret` site setting is blank, an attacker can forge valid webhook signatures by computing an HMAC-MD5 with an empty string as the key. Since the request body is known to the sender, the attacker can produce a matching signature and send arbitrary webhook payloads. This allows unauthorized creation, modification, or deletion of Patreon pledge data and triggering patron-to-group synchronization. This vulnerability is patched in versions 2025.12.2, 2026.1.1, and 2026.2.0. The fix rejects webhook requests when the webhook secret is not configured, preventing signature forgery with an empty key. As a workaround, configure the `patreon_webhook_secret` site setting with a strong, non-empty secret value. When the secret is non-empty, an attacker cannot forge valid signatures without knowing the secret.
Statistics
- 1 Post
- 1 Interaction
Last activity: 3 hours ago
Overview
Description
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user.
Statistics
- 1 Post
Last activity: 9 hours ago
Overview
- Chargemap
- chargemap.com
26 Feb 2026
Published
02 Mar 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.06%
KEV
Description
The WebSocket Application Programming Interface lacks restrictions on
the number of authentication requests. This absence of rate limiting may
allow an attacker to conduct denial-of-service attacks by suppressing
or misrouting legitimate charger telemetry, or conduct brute-force
attacks to gain unauthorized access.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- ImageMagick
- ImageMagick
24 Feb 2026
Published
26 Feb 2026
Updated
CVSS v3.1
HIGH (8.2)
EPSS
0.05%
KEV
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. `WriteUHDRImage` in `coders/uhdr.c` uses `int` arithmetic to compute the pixel buffer size. Prior to version 7.1.2-15, when image dimensions are large, the multiplication overflows 32-bit `int`, causing an undersized heap allocation followed by an out-of-bounds write. This can crash the process or potentially lead to an out of bounds heap write. Version 7.1.2-15 contains a patch.
Statistics
- 1 Post
Last activity: 16 hours ago
Overview
- OneUptime
- oneuptime
25 Feb 2026
Published
25 Feb 2026
Updated
CVSS v3.1
CRITICAL (10.0)
EPSS
0.24%
KEV
Description
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe server by injecting shell metacharacters into a monitor's destination field. Version 10.0.7 fixes the vulnerability.
Statistics
- 1 Post
Last activity: 6 hours ago
Overview
- Changing
- IDExpert Windows Logon Agent
02 Mar 2026
Published
02 Mar 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.10%
KEV
Description
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.
Statistics
- 1 Post
Last activity: 13 hours ago
Bluesky
Overview
- UnitreeRobotics
- Unitree Go2
26 Feb 2026
Published
27 Feb 2026
Updated
CVSS v4.0
HIGH (8.5)
EPSS
0.03%
KEV
Description
Unitree Go2 firmware versions V1.1.7 through V1.1.9 and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publish a crafted message (api_id=1002) containing arbitrary Python, which the robot writes to disk under /unitree/etc/programming/ and binds to a physical controller keybinding. When the keybinding is pressed, the code executes as root and the binding persists across reboots.
Statistics
- 2 Posts
Last activity: 3 hours ago
Bluesky
π’ Robots Unitree Go2 : deux failles RCE (CVE-2026-27509, CVE-2026-27510) via DDS et base Android
π Selon un billet technique publiΓ© par Oliβ¦
https://cyberveille.ch/posts/2026-03-02-robots-unitree-go2-deux-failles-rce-cve-2026-27509-cve-2026-27510-via-dds-et-base-android/ #CVE_2026_27509 #Cyberveille
Overview
- e-Excellence
- U-Office Force
02 Mar 2026
Published
02 Mar 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.40%
KEV
Description
U-Office Force developed by e-Excellence has a Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously crafted serialized content.
Statistics
- 1 Post
Last activity: 19 hours ago
Fediverse
π¨ CRITICAL: CVE-2026-3422 in e-Excellence U-Office Force enables unauthenticated remote code execution via insecure deserialization (CWE-502). No patch β restrict access, monitor traffic, use WAF/RASP. https://radar.offseq.com/threat/cve-2026-3422-cwe-502-deserialization-of-untrusted-c53bebca #OffSeq #Vulnerability #Infosec #CVE20263422