Overview
- lxsmnsyc
- seroval
Description
Statistics
- 1 Post
Fediverse
π CVE-2026-23956 - High (7.5)
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0
and below, overriding RegExp serialization with extremely large patterns can exhaust JavaScript runtime memory during ...
π https://www.thehackerwire.com/vulnerability/CVE-2026-23956/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Solvera Software Services Trade Inc.
- Teknoera
Description
Statistics
- 1 Post
Fediverse
π CVE-2025-10855 - High (7.5)
Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identifiers.This issue affects Teknoera: through 01102025.
π https://www.thehackerwire.com/vulnerability/CVE-2025-10855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Revive
- Revive Adserver
Description
Statistics
- 1 Post
Overview
- vllm-project
- vllm
Description
Statistics
- 1 Post
Fediverse
π CVE-2026-22807 - High (8.8)
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_code`, all...
π https://www.thehackerwire.com/vulnerability/CVE-2026-22807/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- appsmithorg
- appsmith
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-24042 - Critical (9.4)
Appsmith is a platform to build admin panels, internal tools, and dashboards. In versions 1.94 and below, publicly accessible apps allow unauthenticated users to execute unpublished (edit-mode) actions by sending viewMode=false (or omitting it) to...
π https://www.thehackerwire.com/vulnerability/CVE-2026-24042/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- lxsmnsyc
- seroval
Description
Statistics
- 1 Post
Fediverse
π CVE-2026-24006 - High (7.5)
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0
and below, serialization of objects with extreme depth can exceed the maximum call stack limit. In version 1.4.1, Sero...
π https://www.thehackerwire.com/vulnerability/CVE-2026-24006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- gristlabs
- grist-core
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-24002 - Critical (9)
Grist is spreadsheet software using Python as its formula language. Grist offers several methods for running those formulas in a sandbox, for cases where the user may be working with untrusted spreadsheets. One such method runs them in pyodide, bu...
π https://www.thehackerwire.com/vulnerability/CVE-2026-24002/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- horilla-opensource
- horilla
Description
Statistics
- 1 Post
Fediverse
π CVE-2026-24038 - High (8.1)
Horilla is a free and open source Human Resource Management System (HRMS). In version 1.4.0, the OTP handling logic has a flawed equality check that can be bypassed. When an OTP expires, the server returns None, and if an attacker omits the otp fi...
π https://www.thehackerwire.com/vulnerability/CVE-2026-24038/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- laravel
- reverb
Description
Statistics
- 1 Post
Fediverse
π΄ CVE-2026-23524 - Critical (9.8)
Laravel Reverb provides a real-time WebSocket communication backend for Laravel applications. In versions 1.6.3 and below, Reverb passes data from the Redis channel directly into PHPβs unserialize() function without restricting which classes can...
π https://www.thehackerwire.com/vulnerability/CVE-2026-23524/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- lxsmnsyc
- seroval
Description
Statistics
- 1 Post
Fediverse
π CVE-2026-23737 - High (7.5)
seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. In versions 1.4.0 and below, improper input handling in the JSON deserialization component can lead to arbitrary JavaScript code executi...
π https://www.thehackerwire.com/vulnerability/CVE-2026-23737/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack