Overview
- wpdecent
- Flexi Product Slider and Grid for WooCommerce
14 Feb 2026
Published
14 Feb 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.12%
KEV
Description
The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path without proper sanitization or validation, allowing directory traversal. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server via the `theme` parameter granted they can create posts with shortcodes.
Statistics
- 1 Post
Last activity: 14 hours ago
Fediverse
📢 HIGH severity: CVE-2026-1988 in wpdecent Flexi Product Slider & Grid for WooCommerce allows Contributor+ users to exploit the 'theme' parameter for LFI and potential RCE. No patch yet — restrict roles, audit users, and monitor logs. https://radar.offseq.com/threat/cve-2026-1988-cwe-98-improper-control-of-filename--9af2696b #OffSeq #WordPress #WooCommerce
Overview
- Fortinet
- FortiOS
10 Feb 2026
Published
11 Feb 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.07%
KEV
Description
An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
- ImageMagick
- ImageMagick
20 Jan 2026
Published
21 Jan 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
0.06%
KEV
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.
Statistics
- 2 Posts
Last activity: 12 hours ago
Bluesky
🚨 URGENT: #SUSE #Linux Security Update 🚨
Patch critical #ImageMagick flaws NOW! CVE-2026-23876 allows potential remote code execution via malicious images. Check your SLES & openSUSE systems. Read more: 👉 tinyurl.com/3cbu7an9 #Security
Overview
Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
- Ivanti
- Endpoint Manager Mobile
29 Jan 2026
Published
30 Jan 2026
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
40.23%
KEV
Description
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
Description
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.
Statistics
- 1 Post
Last activity: 19 hours ago