24h | 7d | 30d

Overview

  • wpdecent
  • Flexi Product Slider and Grid for WooCommerce

14 Feb 2026
Published
14 Feb 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.12%

KEV

Description

The Flexi Product Slider and Grid for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.5 via the `flexipsg_carousel` shortcode. This is due to the `theme` parameter being directly concatenated into a file path without proper sanitization or validation, allowing directory traversal. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary PHP files on the server via the `theme` parameter granted they can create posts with shortcodes.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

📢 HIGH severity: CVE-2026-1988 in wpdecent Flexi Product Slider & Grid for WooCommerce allows Contributor+ users to exploit the 'theme' parameter for LFI and potential RCE. No patch yet — restrict roles, audit users, and monitor logs. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Fortinet
  • FortiOS

10 Feb 2026
Published
11 Feb 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.07%

KEV

Description

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
The latest update for #Foresiet includes "Top Dark Web Forums to Watch in 2026" and "FortiOS VPN Auth Bypass Flaw (CVE-2026-22153) Exposes Remote Access". #cybersecurity #infosec https://opsmtrs.com/3J3CMGz
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • ImageMagick
  • ImageMagick

20 Jan 2026
Published
21 Jan 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.06%

KEV

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated heap buffer when processing a maliciously crafted image file. Any operation that reads or identifies an image can trigger the overflow, making it exploitable via common image upload and processing pipelines. Versions 7.1.2-13 and 6.9.13-38 fix the issue.

Statistics

  • 2 Posts

Last activity: 12 hours ago

Bluesky

Profile picture fallback
🚨 URGENT: #SUSE #Linux Security Update 🚨 Patch critical #ImageMagick flaws NOW! CVE-2026-23876 allows potential remote code execution via malicious images. Check your SLES & openSUSE systems. Read more: 👉 tinyurl.com/3cbu7an9 #Security
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
🛡️ URGENT: Critical ImageMagick Security Patch for SUSE/openSUSE! A new update (SUSE-SU-2026:0503-1) is live, addressing three major vulnerabilities, including CVE-2026-23876—a critical remote code execution flaw (CVSS 9.8). Read more: 👉 tinyurl.com/3xn7nmdj #Security
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Ivanti
  • Endpoint Manager Mobile

29 Jan 2026
Published
30 Jan 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
54.26%

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
The latest update for #Indusface includes "CVE-2026-1281 & CVE-2026-1340: Actively Exploited Pre-Authentication RCE in Ivanti EPMM" and "CVE-2025-11953 – Metro4Shell RCE in #ReactNative Metro Server". #cybersecurity #infosec https://opsmtrs.com/3ySs2VF
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Ivanti
  • Endpoint Manager Mobile

29 Jan 2026
Published
30 Jan 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
40.23%

KEV

Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
The latest update for #Indusface includes "CVE-2026-1281 & CVE-2026-1340: Actively Exploited Pre-Authentication RCE in Ivanti EPMM" and "CVE-2025-11953 – Metro4Shell RCE in #ReactNative Metro Server". #cybersecurity #infosec https://opsmtrs.com/3ySs2VF
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • @react-native-community/cli-server-api

03 Nov 2025
Published
06 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
8.45%

Description

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attackers to send a POST request to the server and run arbitrary executables. On Windows, the attackers can also execute arbitrary shell commands with fully controlled arguments.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
The latest update for #Indusface includes "CVE-2026-1281 & CVE-2026-1340: Actively Exploited Pre-Authentication RCE in Ivanti EPMM" and "CVE-2025-11953 – Metro4Shell RCE in #ReactNative Metro Server". #cybersecurity #infosec https://opsmtrs.com/3ySs2VF
  • 0
  • 0
  • 0
  • 19h ago
Showing 21 to 26 of 26 CVEs