Overview
- Hitachi
- Hitachi Virtual Storage Platform One Block 23, 24, 26, 28
29 Jun 2026
Published
29 Jun 2026
Updated
CVSS v3.1
LOW (3.7)
EPSS
0.08%
KEV
Description
Lack of validation for firmware update in Hitachi Hitachi Virtual Storage Platform One Block 23, 24, 26, 28.
This issue affects Hitachi Virtual Storage Platform One Block 23, 24, 26, 28: before DKCMAIN A3-04-21-40/00, ESM A3-04-21/00.
Statistics
- 4 Posts
Last activity: 6 hours ago
Bluesky
Уязвимость CVE-2025-0824 в Hitachi Virtual Storage Platform: угроза безопасности и способы защиты
https://kripta.biz/posts/64C690FA-193A-42B4-B050-3F9F8786AF71
深度解析CVE-2025-0824:日立虚拟存储平台固件更新漏洞的安全风险与应对策略
https://qian.cx/posts/8E972415-CF02-4392-A37E-AB6A60DE4AFC
Overview
- Edimax
- EW-7478APC
29 Jun 2026
Published
29 Jun 2026
Updated
CVSS v4.0
MEDIUM (5.3)
EPSS
Pending
KEV
Description
A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. The manipulation of the argument rootAPmac results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Statistics
- 2 Posts
Last activity: 9 hours ago
Overview
- opf
- openproject
26 Jun 2026
Published
29 Jun 2026
Updated
CVSS v3.1
CRITICAL (9.9)
EPSS
0.26%
KEV
Description
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources. A project-admin in one project can hijack the managed Nextcloud or OneDrive folder of another project on the same storage by writing the victim project's project_folder_id into the attacker's Storages::ProjectStorage row. The next managed-folder sync overwrites the ACL on the referenced folder with the attacker project's user list. This vulnerability is fixed in 17.3.3 and 17.4.1.
Statistics
- 2 Posts
Last activity: 11 hours ago
Overview
- videowhisper
- Paid Videochat Turnkey Site
- ppv-live-webcams
29 Jun 2026
Published
29 Jun 2026
Updated
CVSS v3.1
CRITICAL (9.9)
EPSS
Pending
KEV
Description
Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.
Statistics
- 2 Posts
Last activity: 10 hours ago
Overview
Description
A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/managers/ChannelBridge.ts of the component Contact Tracking. This manipulation of the argument _channelType causes improper authorization. The attack may be initiated remotely. A high degree of complexity is needed for the attack. The exploitability is told to be difficult. The exploit has been made available to the public and could be used for attacks. Patch name: 9b4aff0f106db424aa45a35aa89dd0b8f2eb9a48. It is suggested to install a patch to address this issue.
Statistics
- 5 Posts
Last activity: 7 hours ago
Bluesky
深度解析CVE-2026-13591:DeepMyst Mysti 0.4.0漏洞详情与安全防护指南
https://qian.cx/posts/77E97425-0165-409C-B562-D1BE4CB1A7AB
Уязвимость CVE-2026-13591 в DeepMyst Mysti 0.4.0: угрозы и способы защиты
https://kripta.biz/posts/25070812-BF2A-443F-9007-A58A3CB22A5E
深度解析CVE-2026-13591漏洞:DeepMyst Mysti 0.4.0的安全风险与应对策略
https://qian.cx/posts/8BC841DA-525C-461D-AC43-1F005D0072CA
Overview
- OpenStack
- Swift
23 Jun 2026
Published
23 Jun 2026
Updated
CVSS v4.0
MEDIUM (5.3)
EPSS
0.20%
KEV
Description
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
Statistics
- 2 Posts
Last activity: 2 hours ago
Overview
Description
A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Statistics
- 4 Posts
Last activity: 11 hours ago
Overview
- agentejo
- Cockpit CMS
29 Jun 2026
Published
29 Jun 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.29%
KEV
Description
A security vulnerability has been detected in agentejo Cockpit CMS up to 0.12.2. Affected by this issue is the function Spyc::YAMLLoad of the file /config/config.yaml of the component htaccess Handler. Such manipulation leads to files or directories accessible. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Configuration settings should be changed. The vendor was contacted early about this disclosure but did not respond in any way.
Statistics
- 4 Posts
Last activity: 6 hours ago
Bluesky
Уязвимость CVE-2026-13533 в agentejo Cockpit CMS: угроза безопасности и способы защиты
https://kripta.biz/posts/FF58B3EA-1277-4DE9-8EED-078F276C4D2C
深度解析CVE-2026-13533:agentejo Cockpit CMS 0.12.2版本的安全漏洞及应对策略
https://qian.cx/posts/3C81BA8E-8039-408E-94CD-F69889999E98
深度解析CVE-2026-13533:agentejo Cockpit CMS 0.12.2版本的安全漏洞及应对策略
https://qian.cx/posts/161D4114-E2FD-4836-A084-02810972E19E
Overview
Description
A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field).
Statistics
- 4 Posts
Last activity: 8 hours ago
Bluesky
深度解析CVE-2026-50765:跨站脚本攻击(XSS)漏洞对图书馆系统的潜在威胁
https://qian.cx/posts/EA66F629-3B37-44BC-9FDC-FF37E2E781F2
Уязвимость CVE-2026-50765: XSS в системе управления ограничениями пользователей
https://kripta.biz/posts/0F0CC577-0CD1-4C1F-93AA-3FDDAB04FF75
Угроза безопасности: Разбор уязвимости CVE-2026-50765 и её последствия для пользователей
https://kripta.biz/posts/AB8EFE91-DF22-42EB-A98C-9A08C499882B
Overview
Description
A flaw exists within the Linux kernel's handling of new TCP connections. The issue results from the lack of memory release after its effective lifetime. This vulnerability allows an unauthenticated attacker to create a denial of service condition on the system.
Statistics
- 2 Posts
Last activity: 2 hours ago