24h | 7d | 30d

Overview

  • themefusion
  • Avada (Fusion) Builder

10 Oct 2026
Published
10 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.37%

KEV

Description

The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data token; the 3.16.1 trust gate is_content_request_supplied() only inspects $_POST['args']/$_GET['args'], never the $_POST['formData'] the public form-submit endpoint parses). This makes it possible for unauthenticated attackers to invoke arbitrary WordPress action hooks (multiple per request), causing state changes up to permanent, irreversible destruction of site content: a verified unauthenticated request permanently deleted trashed posts, pages, and comments via the core wp_scheduled_delete action. Other non-deny-listed hooks extend the impact to denial of service (e.g. wp_maybe_auto_update) and, where vulnerable third-party handlers are installed, further privileged writes. The same unauthenticated dynamic-data pipeline additionally exposes a blind arbitrary user/post-meta read; the read result is delivered only to the site owner and is not attacker-exfiltrable through the plugin's own email/response paths. Exploitation requires a published Avada form with AJAX submission and a notification whose email_message template includes an [all_fields] or explicit [field] placeholder - the default form configuration.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-97670: Avada (Fusion) Builder ≤7.16.1 has a CRITICAL code injection flaw. Unauthenticated attackers can invoke arbitrary WP action hooks — risks include content deletion & DoS. Disable vulnerable forms, await patch. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Tautulli
  • Tautulli

21 Sep 2026
Published
21 Sep 2026
Updated

CVSS v4.0
HIGH (7.0)
EPSS
0.59%

KEV

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.filename or database_file.filename directly to CACHE_DIR without basename reduction or a containment check. An administrator or caller with the instance API key can submit a multipart filename containing parent-directory segments, causing the upload to be created or overwritten outside CACHE_DIR before file-content validation runs. The write is limited to paths permitted to the Tautulli process, but it can enable configuration tampering, service disruption, or code execution. This issue is fixed in version 2.17.2.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CVE-2026-52835 Tautulli code execution, CVSS 8.1. Path traversal in import handlers lets an API key holder write files outside CACHE_DIR. No fixed release yet, patch under review. Update immediately. valtersit.com/cve/CVE-2026-528 #CVE #infosec #Tautulli

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Telegram
  • Telegram Desktop

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.34%

KEV

Description

Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

Critical Telegram Desktop Vulnerability (CVE-2026-107181): A Technical Analysis of One-Click Account Takeover via IPC Injection

Telegram Desktop CVE-2026-107181 enables one-click account takeover through IPC injection and local session file theft. Learn how it works and how to protect your account

thecybersecguru.com/exploits/t

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.08%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 1 Post

Last activity: 6 hours ago

Bluesky

Profile picture fallback
Post-Exploitation Analysis & Artifacts - Citrix NetScaler CVE-2026-88771
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Pending

21 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
0.75%

KEV

Description

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-88404: RCE in Univer v1.0.0-alpha.2 via UniscriptExecutionService.execute(). CVSS 9.8, unpatched. Patch now.
valtersit.com/cve/CVE-2026-884
#CVE #infosec #cybersecurity

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Atlassian
  • Bamboo Data Center

05 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.77%

KEV

Description

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Statistics

  • 1 Post

Last activity: 10 hours ago

Bluesky

Profile picture fallback
Atlassian CVE-2026-21589 Exploited Hours After Public Disclosure #blockingunauthorizedaccess #CredentialSecurity #CVE
  • 0
  • 0
  • 0
  • 10h ago

Overview

  • Pending

21 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
0.40%

KEV

Description

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

Statistics

  • 1 Post

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2026-88403: SSRF in NocoBase v2.1.21 lets authenticated attackers scan internal resources. CVSS 6.5, no patch yet. Restrict network access and monitor. Details: valtersit.com/cve/CVE-2026-884 #CVE #infosec #cybersecurity

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • openSeaChest

02 Jun 2026
Published
03 Jun 2026
Updated

CVSS v4.0
MEDIUM (4.6)
EPSS
0.11%

KEV

Description

Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms allows for writing extra memory describing a range of LBAs to deallocate 16 bytes outside of the allocated space when running this operation.

Statistics

  • 1 Post

Last activity: 13 hours ago

Bluesky

Profile picture fallback
Telegram Desktop Vulnerability Could Let Hackers Hijack Accounts With One Click A high-severity Telegram Desktop vulnerability, CVE-2026-10718, could let attackers steal local files and hijack accounts through specially crafted links.
  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Ahsay
  • AhsayCBS

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
1.84%

KEV

Description

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Ahsay
  • AhsayCBS

04 Oct 2026
Published
05 Oct 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.38%

KEV

Description

A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.

Statistics

  • 1 Post

Last activity: 16 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service pers…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 16h ago
Showing 31 to 40 of 40 CVEs