Overview
Description
The Java OpenWire protocol marshaller is vulnerable to Remote Code
Execution. This vulnerability may allow a remote attacker with network
access to either a Java-based OpenWire broker or client to run arbitrary
shell commands by manipulating serialized class types in the OpenWire
protocol to cause either the client or the broker (respectively) to
instantiate any class on the classpath.
Users are recommended to upgrade
both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3
which fixes this issue.
Statistics
- 1 Post
Last activity: 15 hours ago
Overview
- McAfee,LLC
- MVISION EDR
29 Jun 2021
Published
03 Aug 2024
Updated
CVSS v3.1
HIGH (8.4)
EPSS
2.89%
KEV
Description
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
Description
A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Port Forwarding Configuration Endpoint. This manipulation of the argument submit-url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
Statistics
- 1 Post
Last activity: 22 hours ago
Overview
- itsourcecode
- Vehicle Management System
21 Feb 2026
Published
23 Feb 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.02%
KEV
Description
A vulnerability was determined in itsourcecode Vehicle Management System 1.0. Affected is an unknown function of the file /billaction.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Statistics
- 1 Post
Last activity: 17 hours ago
Overview
- QuantumNous
- new-api
24 Feb 2026
Published
24 Feb 2026
Updated
CVSS v3.1
HIGH (7.6)
EPSS
0.04%
KEV
Description
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version 0.10.8-alpha.9 fixes the issue.
Statistics
- 1 Post
Last activity: 23 hours ago
Fediverse
π‘οΈ HIGH-severity XSS (CVE-2026-25802) in QuantumNous new-api (<0.10.8-alpha.9): Unsafe MarkdownRenderer.jsx allows script injection with user interaction. Upgrade ASAP & implement CSP! https://radar.offseq.com/threat/cve-2026-25802-cwe-79-improper-neutralization-of-i-48d25c61 #OffSeq #XSS #InfoSec #AIsecurity
Overview
Description
A weakness has been identified in UTT HiPER 810G up to 1.7.7-171114. This issue affects the function strcpy of the file /goform/ConfigExceptMSN. Executing a manipulation of the argument remark can lead to buffer overflow. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Statistics
- 1 Post
Last activity: 8 hours ago
Overview
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
Statistics
- 1 Post
Last activity: 11 hours ago
Bluesky
CVE-2025-40551 Exploited In The Wild Just 48 Hours After Disclosure β Your SolarWinds Helpdesk Is Already At Risk +Β Video
Introduction: The window between a software vulnerability being disclosed and attackers actively exploiting it has collapsed to mere days. A recent observation from a globalβ¦
Overview
Description
A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the file /goform/formPdbUpConfig of the component Web Management Interface. The manipulation of the argument policyNames leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Statistics
- 1 Post
Last activity: 10 hours ago
Overview
- itsourcecode
- Document Management System
24 Feb 2026
Published
24 Feb 2026
Updated
CVSS v4.0
MEDIUM (6.9)
EPSS
0.03%
KEV
Description
A weakness has been identified in itsourcecode Document Management System 1.0. This impacts an unknown function of the file /deluser.php. Executing a manipulation of the argument user2del can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Statistics
- 1 Post
Last activity: 4 hours ago
Overview
- openITCOCKPIT
- openITCOCKPIT
20 Feb 2026
Published
20 Feb 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.05%
KEV
Description
openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls PHP's unserialize() on job payloads without enforcing class restrictions or validating data origin. While the intended deployment assumes only trusted internal components enqueue Gearman jobs, this trust boundary is not enforced in application code. In environments where the Gearman service or worker is exposed to untrusted systems, an attacker may submit crafted serialized payloads to trigger PHP Object Injection in the worker process. This vulnerability is exploitable when Gearman listens on non-local interfaces, network access to TCP/4730 is unrestricted, or untrusted systems can enqueue jobs. Default, correctly hardened deployments may not be immediately exploitable, but the unsafe sink remains present in code regardless of deployment configuration. Enforcing this trust boundary in code would significantly reduce risk and prevent exploitation in misconfigured environments. This issue has been fixed in version 5.4.0.
Statistics
- 1 Post
Last activity: 6 hours ago