Overview
- WPEverest
- Everest Forms Pro
Description
Statistics
- 1 Post
Fediverse
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin to execute arbitrary code and seize administrative control of WordPress websites. Users should update to the patched version immediately and scan their systems for suspicious accounts like 'diksimarina'.
https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/
Overview
- GL.iNet
- GL-MT3000
Description
Statistics
- 1 Post
Fediverse
CVE-2026-11451: MEDIUM severity command injection in GL.iNet GL-MT3000 (v4.4.5). 🛡️ Remote attackers can exploit FTP handler via media_dir. Fixed in 4.8.1 — update now! https://radar.offseq.com/threat/cve-2026-11451-command-injection-in-glinet-gl-mt30-53c0e750 #OffSeq #Vulnerability #GLiNet #IoTSecurity
Overview
- LMS Community
- Lyrion Music Server
Description
Statistics
- 1 Post
Overview
- code-projects
- Vehicle Management System
Description
Statistics
- 1 Post
Fediverse
CVE-2026-11344 - Arbitrary file upload in Code-Projects Vehicle Management System. Unrestricted upload via newdriver.php. CVSS 7.3. Exploit public. No patch available. Isolate immediately. #CVE #infosec #cybersecurity
Overview
- hippooo
- Hippoo Mobile App for WooCommerce
Description
Statistics
- 1 Post
Fediverse
CVE-2026-10580 - Critical Authentication Bypass in Hippoo WordPress plugin. Flaw conflates admin and unauthenticated user permissions, allowing full admin takeover. CVSS 9.8. No patch available. Disable plugin now. #CVE #WordPress #infosec
Overview
- MongoDB, Inc.
- MongoDB Server
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
@j0nas Vielleicht Debian 12? Selbst nginx RIFT ist da noch rausgepatcht worden: https://security-tracker.debian.org/tracker/CVE-2026-42945
Wenn man so nginx versionen in den Fehlerseiten liest, denken die meissten Leute, OMG ist es alt, aber oft ist's einfach Debian und nur halb so wild.
Description
Statistics
- 1 Post
Fediverse
CISA has added the Linux kernel vulnerability CVE-2022-0492 to its Known Exploited Vulnerabilities catalog due to its use in privilege escalation attacks. This flaw allows attackers to manipulate cgroups to gain root-level access or escape containerized environments.
https://cybersecuritynews.com/linux-kernel-improper-authentication-vulnerability/