#vuln

43 posts · Last used 7h

Back to Timeline
OffSequence @offseq@infosec.exchange · 7h ago
SSRF in mf-yang openclaw-cn (CVE-2026-17458) affects v0.2.0 & v0.2.1. MEDIUM severity, CVSS 5.3. Exploit details public, no patch yet. Restrict outbound server requests as interim mitigation. https://radar.offseq.com/threat/cve-2026-17458-server-side-request-forgery-in-mf-yang-openclaw-cn-a8d78509307a6c7f #OffSeq #SSRF #Vuln #mfyang
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-56191-cwe-287-improper-authentication-in-microsoft-microsoft-exchange-online-2fb5560625ca8222 #OffSeq #CVE202656191 #ExchangeOnline #Vuln
0
1
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-42933: CRITICAL unintended proxy vuln (CVSS 10) in Pronetiqs Panduit Intravue ≤3.2.1a14 lets attackers bypass OT segmentation. No patch yet — restrict access & monitor vendor. https://radar.offseq.com/threat/cve-2026-42933-cwe-441-unintended-proxy-or-intermediary-confused-deputy-in-pronetiqs-panduit-intravue-95925181c2d7dbb4 #OffSeq #OTSecurity #Vuln #CVE202642933
0
0
0
OffSequence @offseq@infosec.exchange · 3d ago
CVE-2026-65907: CRITICAL RCE in JetBrains TeamCity (CVSS 9.1). Affects <2026.1.2, <2025.11.6. Exploitable via Git VCS roots — no patch yet. Restrict access, minimize Git user privileges. More info: https://radar.offseq.com/threat/cve-2026-65907-cwe-94-in-jetbrains-teamcity-0b7d157127b512e7 #OffSeq #TeamCity #Vuln #RCE
0
0
0
OffSequence @offseq@infosec.exchange · 3d ago
CVE-2026-46738: Dell PowerProtect Data Manager <20.2.0.0 faces a CRITICAL REST API input validation vuln. High privileged remote attackers can escalate privileges. Restrict API access & monitor privileged accounts. https://radar.offseq.com/threat/dell-powerprotect-data-manager-versions-prior-to-20200-contains-an-improper-input-validation-f763e60bc08bcc57 #OffSeq #Dell #CVE202646738 #Vuln
0
0
0
OffSequence @offseq@infosec.exchange · 4d ago
Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
0
0
0
OffSequence @offseq@infosec.exchange · 5d ago
Palo Alto Networks GlobalProtect VPN (PAN-OS) CRITICAL vuln (CVE-2026-0257) is under active Qilin ransomware exploitation. Auth bypass allows full domain compromise. Patch ASAP (released May 13, 2026). https://radar.offseq.com/threat/critical-palo-alto-vpn-bug-now-exploited-by-qilin-ransomware-gang-32a4cdf9eafc03de #OffSeq #PANOS #Ransomware #Vuln
0
0
0
OffSequence @offseq@infosec.exchange · 5d ago
FreeScout (<1.8.224) has a CRITICAL vuln (CVE-2026-53595, CVSS 9.4): improper invite_hash handling lets unauthenticated attackers overwrite + access the lowest-id activated user account. Patch to 1.8.224. Details: https://radar.offseq.com/threat/cve-2026-53595-cwe-178-improper-handling-of-case-sensitivity-in-freescout-help-desk-freescout-3a27bed6e9e122c1 #OffSeq #CVE202653595 #infosec #vuln
0
0
0
OffSequence @offseq@infosec.exchange · 6d ago
CVE-2026-57309 (CRITICAL, CVSS 9.3): Windu CMS 4.1 suffers from a blind SQL injection via HTTP header URL path. No patch yet — restrict exposed endpoints and monitor for abnormal DB activity. Details: https://radar.offseq.com/threat/cve-2026-57309-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-69fa2f89e7c44ad0 #OffSeq #SQLi #Vuln #CVE202657309
0
0
0
OffSequence @offseq@infosec.exchange · 6d ago
CVE-2026-13142 | CRITICAL: Social Login, Passkeys, Magic Link & Email OTP WordPress plugin (pre-1.4.1) allows OTP brute-force due to no rate limiting + plaintext storage. Admin takeover possible. Disable or restrict plugin use until patched. https://radar.offseq.com/threat/cve-2026-13142-cwe-269-improper-privilege-management-in-social-login-passkeys-magic-link-email-otp-82bfc0c2a799f534 #OffSeq #WordPress #Vuln
0
0
0
OffSequence @offseq@infosec.exchange · Jul 19, 2026
CVE-2026-16229 (MEDIUM, CVSS 5.3): XSS in itsourcecode Courier Management System v1.0 via 'page' param in /index.php. Remote exploitation possible, user interaction needed. No patch yet — use WAF and input validation. https://radar.offseq.com/threat/cve-2026-16229-cross-site-scripting-in-itsourcecode-courier-management-system-ed5bf04aced8e4b0 #OffSeq #XSS #Vuln
0
0
0
OffSequence @offseq@infosec.exchange · Jul 19, 2026
guohongze adminset (v0.1 – 0.61) is vulnerable to authorization bypass (CVE-2026-16217) via delivery/deli.py. Remote exploitation is possible, exploit is public. Severity: MEDIUM. Patch unavailable. https://radar.offseq.com/threat/cve-2026-16217-authorization-bypass-in-guohongze-adminset-47f5be1f2f522b7f #OffSeq #CVE202616217 #Vuln #Infosec
0
0
0
OffSequence @offseq@infosec.exchange · Jul 19, 2026
CVE-2026-16210: Medium severity vuln in newpanjing simpleui 2026.01.13 allows remote, unauthenticated actions via AjaxAdmin AJAX Endpoint. Exploit is public — no vendor fix yet. Restrict access or disable endpoint until patched. https://radar.offseq.com/threat/cve-2026-16210-missing-authentication-in-newpanjing-simpleui-9641080cfd337cea #OffSeq #Vuln #SimpleUI
0
0
0
OffSequence @offseq@infosec.exchange · Jul 19, 2026
CVE-2026-12228: parisneo/lollms suffers HIGH severity stored XSS (CVSS 8.7) via POST /api/prompts/share. Authenticated users can execute JS in victims' browsers, risking account takeover. Patch status unknown — check vendor updates. https://radar.offseq.com/threat/cve-2026-12228-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-9a447d2fa5ce8bc8 #OffSeq #XSS #Vuln #InfoSec
0
0
0
OffSequence @offseq@infosec.exchange · Jul 18, 2026
7-Zip patched a CRITICAL RCE vulnerability — malicious archive files could allow attackers to execute code and fully compromise systems. Update to v26.02 ASAP. No CVE assigned. Full details: https://radar.offseq.com/threat/update-now-7-zip-fixes-rce-flaw-exploitable-with-malicious-archives-0fd30e36bd704721 #OffSeq #7zip #RCE #Vuln
0
0
0
OffSequence @offseq@infosec.exchange · Jul 17, 2026
CVE-2026-58644: CRITICAL RCE in Microsoft SharePoint enables remote, authenticated Site Owners to execute code via deserialization. Exploited in the wild — patch now (July 2026 updates). Details: https://radar.offseq.com/threat/fresh-sharepoint-vulnerability-exploited-soon-afte-951942a1c69ed88b #OffSeq #SharePoint #Vuln #KEV #Infosec
0
0
0
OffSequence @offseq@infosec.exchange · Jul 17, 2026
MohibShaikh clawvet API server <0.7.5 (CVE-2026-62241) suffers a CRITICAL flaw: hard-coded JWT secret enables unauthenticated user data access and session cookie forgery. Change secrets & limit endpoint access. https://radar.offseq.com/threat/cve-2026-62241-missing-authentication-for-critical-b8ebafbae06b4bce #OffSeq #CVE202662241 #vuln
0
0
0
OffSequence @offseq@infosec.exchange · Jul 16, 2026
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
0
0
0