Overview
- Totolink
- A7100RU
09 Apr 2026
Published
09 Apr 2026
Updated
CVSS v4.0
CRITICAL (9.3)
EPSS
0.89%
KEV
Description
A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Statistics
- 1 Post
Last activity: 17 hours ago
Fediverse
🛑 CRITICAL: CVE-2026-5850 in Totolink A7100RU (fw 7.4cu.2313_b20191024) enables unauthenticated OS command injection via pptpPassThru. No patch yet — restrict access & monitor advisories. https://radar.offseq.com/threat/cve-2026-5850-os-command-injection-in-totolink-a71-c437d074 #OffSeq #CVE20265850 #RouterSecurity #Infosec
Overview
- Joomla! Project
- Joomla! CMS
01 Apr 2026
Published
02 Apr 2026
Updated
CVSS v4.0
HIGH (8.6)
EPSS
0.02%
KEV
Description
An improper access check allows unauthorized access to webservice endpoints.
Statistics
- 1 Post
- 1 Interaction
Last activity: 7 hours ago
Bluesky
Overview
- Joomla! Project
- Joomla! CMS
01 Apr 2026
Published
02 Apr 2026
Updated
CVSS v4.0
HIGH (8.6)
EPSS
0.02%
KEV
Description
Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.
Statistics
- 1 Post
- 1 Interaction
Last activity: 7 hours ago
Bluesky
Overview
Description
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Statistics
- 1 Post
Last activity: 9 hours ago
Bluesky
Overview
- FlowiseAI
- Flowise
22 Sep 2025
Published
22 Sep 2025
Updated
CVSS v3.1
CRITICAL (10.0)
EPSS
82.39%
KEV
Description
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string to build the MCP server configuration. However, during this process, it executes JavaScript code without any security validation. Specifically, inside the convertToValidJSONString function, user input is directly passed to the Function() constructor, which evaluates and executes the input as JavaScript code. Since this runs with full Node.js runtime privileges, it can access dangerous modules such as child_process and fs. This issue has been patched in version 3.0.6.
Statistics
- 1 Post
- 1 Interaction
Last activity: 2 hours ago
Overview
- WSO2
- WSO2 API Manager
16 Oct 2025
Published
16 Oct 2025
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.28%
KEV
Description
Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks for certain REST APIs can be bypassed, allowing them to be invoked without proper validation.
Successful exploitation of this vulnerability could lead to a malicious actor gaining administrative access and performing unauthenticated and unauthorized administrative operations.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
- WSO2
- WSO2 Identity Server as Key Manager
16 Oct 2025
Published
17 Oct 2025
Updated
CVSS v3.1
CRITICAL (9.6)
EPSS
0.03%
KEV
Description
An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform unauthorized operations, including accessing server-level information.
This vulnerability affects only internal administrative interfaces. APIs exposed through the WSO2 API Manager's API Gateway remain unaffected.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
- WSO2
- WSO2 API Manager
16 Oct 2025
Published
17 Oct 2025
Updated
CVSS v3.1
CRITICAL (9.8)
EPSS
0.08%
KEV
Description
An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorization checks in the keymanager-operations Dynamic Client Registration (DCR) endpoint.
A malicious user can exploit this flaw to generate access tokens with elevated privileges, potentially leading to administrative access and the ability to perform unauthorized operations.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
- Apache Software Foundation
- Apache Tomcat
09 Apr 2026
Published
09 Apr 2026
Updated
CVSS
Pending
EPSS
Pending
KEV
Description
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Statistics
- 1 Post
Last activity: 1 hour ago
Overview
- Apache Software Foundation
- Apache Tomcat
09 Apr 2026
Published
09 Apr 2026
Updated
CVSS
Pending
EPSS
Pending
KEV
Description
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.
This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Statistics
- 1 Post
Last activity: 1 hour ago