24h | 7d | 30d

Overview

  • Unknown
  • Social Login & Sharing buttons with Analytics By SoClever

22 Aug 2026
Published
22 Aug 2026
Updated

CVSS
Pending
EPSS
0.19%

KEV

Description

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any existing user, including administrators. In the default case a session as the site's original administrator account is obtained without needing to know any account details at all.

Statistics

  • 1 Post

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-77001: CRITICAL vuln in Social Login & Sharing buttons with Analytics By SoClever (≤1.2.0). No auth checks — attackers can hijack any user session, including admin. Remove/disable plugin pending fix. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • F5
  • NGINX Plus

13 May 2026
Published
17 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
66.04%

KEV

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
Nginx Rift is a proof of concept for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module that allows unauthenticated remote code execution on servers using rewrite and set directives The README lists affected and fixed versions ➜ https://ku.bz/PQSlZ7Khl
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • jsonata-js
  • jsonata

21 Aug 2026
Published
21 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.51%

KEV

Description

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose and deconstruct JSONata functions or lambdas through $merge.*, replace proc.arguments.forEach used by applyProcedure, and forge internal lambda state. These primitives allowed an attacker to reach prototype getters, prototype and constructor access, and process.getBuiltinModule with child_process, executing code with the privileges of the host process. This issue is fixed in versions 1.8.8 and 2.2.1.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-77415 (CRITICAL, CVSS 9.3) in jsonata-js (<1.8.8, <2.2.1): Attackers can chain object-integrity flaws to achieve arbitrary code execution. Patch to 1.8.8/2.2.1 ASAP. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • HCL
  • Unica

16 Mar 2026
Published
17 Mar 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.28%

KEV

Description

Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Boolean conditions (TRUE or FALSE) into application input fields. Instead of returning database errors or visible data, the application responds differently depending on whether the injected condition evaluates to true or false. This allows an attacker to inject arbitrary SQL into backend configuration queries executed within the application.

Statistics

  • 1 Post

Last activity: 16 hours ago

Bluesky

Profile picture fallback
CVE-2025-62319 - Boolean-Based SQL Injection in Multiple Unica Components scq.ms/3PdDw0P
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Go standard library
  • net/http
  • net/http

22 May 2026
Published
21 Aug 2026
Updated

CVSS
Pending
EPSS
0.66%

KEV

Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
🔍 Lambda Watchdog detected that CVE-2026-39821 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/664 #AWS #Lambda #Security #CVE #DevOps #SecOps
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Go standard library
  • net
  • net

21 Jul 2026
Published
14 Aug 2026
Updated

CVSS
Pending
EPSS
0.35%

KEV

Description

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
🔍 Lambda Watchdog detected that CVE-2026-46600 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/665 #AWS #Lambda #Security #CVE #DevOps #SecOps
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • TrueConf
  • TrueConf Server

19 Aug 2026
Published
21 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.97%

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • TrueConf
  • TrueConf Server

19 Aug 2026
Published
21 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.78%

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • cisagov
  • Malcolm

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.25%

KEV

Description

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries causes the filebeat processing container to create an unbounded number of filesystem objects, exhausting inodes or filesystem metadata and denying service to the processing pipeline and any service sharing the same mount. Version 26.07.0 fixes the issue.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Canadian Cyber Centre published 5 advisories covering Splunk, Apple, Mozilla, Zimbra, and Malcolm vulnerabilities. - IOCs: CVE-2026-73570, CVE-2026-55676, CVE-2026-63133 - #CVE #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • cisagov
  • Malcolm

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.30%

KEV

Description

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default (`file-upload/php/config.php:16`), so the type check is a no-op and every extension is accepted. The filename sanitizer keeps the `.php` extension intact. Committed files land in `/var/www/upload/server/php/files` (`file-upload/php/config.php:7`), and the component's nginx routes any URL ending in `.php` to php-fpm. An authenticated `GET /server/php/files/<name>.php` then executes the uploaded code as `www-data`. Prior to version 26.06.1, in RBAC mode, the upload endpoint is reachable by the granular `ROLE_UPLOAD` role (`nginx/lua/nginx_auth_helpers.lua:71`), a role intended only for submitting capture files. As a result, a user holding the upload-only role runs arbitrary PHP as `www-data` inside the file-upload container. Version 26.06.1 fixes the issue.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Canadian Cyber Centre published 5 advisories covering Splunk, Apple, Mozilla, Zimbra, and Malcolm vulnerabilities. - IOCs: CVE-2026-73570, CVE-2026-55676, CVE-2026-63133 - #CVE #ThreatIntel #VulnManagement
  • 0
  • 0
  • 0
  • 22h ago
Showing 31 to 40 of 40 CVEs