24h | 7d | 30d

Overview

  • Pending

19 Apr 2023
Published
09 Oct 2026
Updated

CVSS
Pending
EPSS
3.43%

Description

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Pending

29 Jul 2015
Published
09 Oct 2026
Updated

CVSS
Pending
EPSS
91.81%

Description

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Pending

18 May 2015
Published
09 Oct 2026
Updated

CVSS
Pending
EPSS
98.03%

Description

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after their use by China-linked Flax Typhoon: ProFTPD (CVE-2015-3306), ONLYOFFICE Docs (CVE-2021-3199), Strapi (CVE-2023-22894), Apache Struts (CVE-2016-3081) and ISC BIND (CVE-2015-5477).

The wider operations targeted eight vulnerabilities to gain initial access to organizations and remove sensitive data.

US federal agencies must install require…

en.hacks.gr/i-cisa-prosthetei-

#FlaxTyphoon #ProFTPD #ONLYOFFICE #ISC_BIND

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Microsoft
  • Microsoft Partner Center

08 Oct 2026
Published
09 Oct 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.48%

KEV

Description

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

  • 1
  • 0
  • 0
  • 10h ago

Overview

  • Microsoft
  • Azure Event Grid System

08 Oct 2026
Published
09 Oct 2026
Updated

CVSS v3.1
HIGH (7.7)
EPSS
0.37%

KEV

Description

Missing authorization in Azure Event Grid allows an authorized attacker to perform spoofing over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

  • 1
  • 0
  • 0
  • 10h ago

Overview

  • Microsoft
  • Azure API Center

08 Oct 2026
Published
09 Oct 2026
Updated

CVSS v3.1
HIGH (8.7)
EPSS
0.38%

KEV

Description

Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Microsoft dropped seven security advisories for their Cloud vulnerabilities. The worst is Microsoft Partner Center Elevation of Privilege Vulnerability CVE-2026-96207 (10.0 critical). None of them are publicly disclosed or exploited at least.

  1. msrc.microsoft.com/update-guid (10.0 critical)
  2. msrc.microsoft.com/update-guid (9.9 critical)
  3. msrc.microsoft.com/update-guid (9.8 critical)
  4. msrc.microsoft.com/update-guid (9.8 critical)
  5. msrc.microsoft.com/update-guid (9.6 critical)
  6. msrc.microsoft.com/update-guid (8.7 high)
  7. msrc.microsoft.com/update-guid (7.7 high)

  • 1
  • 0
  • 0
  • 10h ago
Showing 71 to 76 of 76 CVEs