24h | 7d | 30d

Overview

  • Apache Software Foundation
  • Apache ActiveMQ
  • org.apache.activemq:activemq-client

27 Oct 2023
Published
03 Nov 2025
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
94.44%

Description

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture fallback
The DFIR Report documents the exploitation of an unpatched ActiveMQ server by CVE-2023-46604. The threat actor used Metasploit tooling for privilege escalation, LSASS access and lateral movement, before LockBit was deployed via RDP using stolen credentials. thedfirreport.com/2026/02/23/a...
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • McAfee,LLC
  • MVISION EDR

29 Jun 2021
Published
03 Aug 2024
Updated

CVSS v3.1
HIGH (8.4)
EPSS
2.89%

KEV

Description

A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2021-31838 - A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execu... https://www.cyberhub.blog/cves/CVE-2021-31838
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • D-Link
  • DWR-M960

20 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.03%

KEV

Description

A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Port Forwarding Configuration Endpoint. This manipulation of the argument submit-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-2857 - A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the com... https://www.cyberhub.blog/cves/CVE-2026-2857
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • itsourcecode
  • Vehicle Management System

21 Feb 2026
Published
23 Feb 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.02%

KEV

Description

A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.

Statistics

  • 1 Post

Last activity: 17 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-2867 - A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a... https://www.cyberhub.blog/cves/CVE-2026-2867
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • QuantumNous
  • new-api

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v3.1
HIGH (7.6)
EPSS
0.04%

KEV

Description

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version 0.10.8-alpha.9 fixes the issue.

Statistics

  • 1 Post

Last activity: 23 hours ago

Fediverse

Profile picture fallback

πŸ›‘οΈ HIGH-severity XSS (CVE-2026-25802) in QuantumNous new-api (<0.10.8-alpha.9): Unsafe MarkdownRenderer.jsx allows script injection with user interaction. Upgrade ASAP & implement CSP! radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 23h ago

Overview

  • UTT
  • HiPER 810G

22 Feb 2026
Published
22 Feb 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.04%

KEV

Description

A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/ConfigExceptMSN. Executing a manipulation of the argument remark can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

Statistics

  • 1 Post

Last activity: 8 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-2935 - A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/ConfigExceptMSN. Execu... https://www.cyberhub.blog/cves/CVE-2026-2935
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • SolarWinds
  • Web Help Desk

28 Jan 2026
Published
04 Feb 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
78.63%

Description

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

Statistics

  • 1 Post

Last activity: 11 hours ago

Bluesky

Profile picture fallback
CVE-2025-40551 Exploited In The Wild Just 48 Hours After Disclosure – Your SolarWinds Helpdesk Is Already At Risk +Β Video Introduction: The window between a software vulnerability being disclosed and attackers actively exploiting it has collapsed to mere days. A recent observation from a global…
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • UTT
  • HiPER 520

20 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.12%

KEV

Description

A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-2846 - A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of ... https://www.cyberhub.blog/cves/CVE-2026-2846
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • itsourcecode
  • Document Management System

24 Feb 2026
Published
24 Feb 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.03%

KEV

Description

A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.

Statistics

  • 1 Post

Last activity: 4 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-3068 - A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a ... https://www.cyberhub.blog/cves/CVE-2026-3068
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • openITCOCKPIT
  • openITCOCKPIT

20 Feb 2026
Published
20 Feb 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.05%

KEV

Description

openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads without enforcing class restrictions or validating data origin. While the intended deployment assumes only trusted internal components enqueue Gearman jobs, this trust boundary is not enforced in application code. In environments where the Gearman service or worker is exposed to untrusted systems, an attacker may submit crafted serialized payloads to trigger PHP Object Injection in the worker process. This vulnerability is exploitable when Gearman listens on non-local interfaces, network access to TCP/4730 is unrestricted, or untrusted systems can enqueue jobs. Default, correctly hardened deployments may not be immediately exploitable, but the unsafe sink remains present in code regardless of deployment configuration. Enforcing this trust boundary in code would significantly reduce risk and prevent exploitation in misconfigured environments. This issue has been fixed in version 5.4.0.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
πŸ“Œ CVE-2026-24891 - openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below co... https://www.cyberhub.blog/cves/CVE-2026-24891
  • 0
  • 0
  • 0
  • 6h ago
Showing 71 to 80 of 89 CVEs