24h | 7d | 30d

Overview

  • JetBrains
  • Exposed

09 Oct 2026
Published
09 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.32%

KEV

Description

In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions

Statistics

  • 2 Posts

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-108474: JetBrains Exposed (<1.5.1) faces CRITICAL SQL injection (CWE-89). Exploitation can fully compromise DBs — upgrade to 1.5.1+ now! CVSS 9.8. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback

Discover the latest JetBrains software vulnerabilities, including TeamCity RCE bugs and Exposed SQLi flaws. Apply security patches immediately.

securityonline.info/jetbrains-

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • NetScaler
  • ADC

08 Oct 2026
Published
10 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.47%

KEV

Description

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Statistics

  • 2 Posts

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments

Citrix has released patches for CVE-2026-107406, a critical (CVSS 9.5) memory overflow vulnerability in NetScaler ADC and NetScaler Gateway that could enable remote code execution or denial-of-service in SAML deployments. The flaw is distinct from the NetScaler zero-day Citrix warned about earlier this week. Administrators are urged to patch immediately. thehackernews.com/2026/10/citr

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway memory overflow that could enable remote code execution or denial of service in deployments configured as SAML identity or service providers. No in-the-wild exploitation was reported.
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • WordPress
  • WordPress

22 Sep 2026
Published
26 Sep 2026
Updated

CVSS
Pending
EPSS
39.98%

Description

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 15 hours ago

Fediverse

Profile picture fallback

Figyelem: egy magas súlyosságú WordPress Core hiba (CVE-2026-87902) LFI-ből RCE-vé alakulhat — érint sok ágat és régi témát. Van aktív page- előtagú témád és régi PHP-d? Ellenőrizd a naplókat, és frissíts minél előbb.

linuxmint.hu/hir/2026/10/riasz

#WordPress #CVE2026-87902 #RCE #LFI #NKI #CISA #websecurity #PHP #themes #kiberbiztonság

  • 1
  • 1
  • 0
  • 15h ago

Overview

  • Thinkst Applied Research
  • OpenCanary
  • opencanary

21 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
LOW (3.7)
EPSS
0.41%

KEV

Description

Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 15 hours ago

Fediverse

Profile picture fallback

CVE-2026-85219: DoS in Thinkst Canary OpenCanary 0.9.9 Redis module. Unauthenticated remote attacker can exhaust memory. CVSS 3.7. Patch under review, watch for updates. valtersit.com/cve/CVE-2026-852 #CVE #infosec #cybersecurity

  • 1
  • 0
  • 0
  • 15h ago

Overview

  • Pending

21 Sep 2026
Published
24 Sep 2026
Updated

CVSS
Pending
EPSS
0.75%

KEV

Description

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffmpeg.snap configuration parameter with arbitrary shell commands. These commands are subsequently executed through the getSnap API endpoint with the privileges of the ZLMediaKit process.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-67827: unauthenticated RCE in ZLMediaKit HTTP API (CVSS 9.8). setServerConfig lets attackers inject shell commands into ffmpeg.snap, executed via getSnap. No patch yet. Disable or restrict the API now. valtersit.com/cve/CVE-2026-678 #CVE #infosec #cybersecurity

  • 0
  • 1
  • 0
  • 16h ago

Overview

  • htplugins
  • Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)

10 Oct 2026
Published
10 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.66%

KEV

Description

The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload directory and a sanitize_file_name() bypass that converts shell.php- into shell.php. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-94589: CRITICAL RCE in Extensions For CF7 (<=3.4.5) for WordPress. Unauth attackers can upload and run malicious files — full compromise possible. Restrict uploads, monitor activity, and check for fixes. radar.offseq.com/threat/cve-20

  • 0
  • 1
  • 0
  • 16h ago

Overview

  • Pending

21 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
0.47%

KEV

Description

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-88402 NocoBase v2.1.21 SQL injection in checkSQL, CVSS 9.8, unpatched. Crafted SQL exposes sensitive database data. Patch status unknown, so restrict exposure now. valtersit.com/cve/CVE-2026-884 #CVE #infosec

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • whyun
  • WPCOM Member

10 Oct 2026
Published
10 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.45%

KEV

Description

The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation in the session store, allowing an unauthenticated attacker to issue a crafted GET request that writes an attacker-named, attacker-valued entry into the global session namespace (bypassing the per-visitor prefix by prepending an underscore), then issue a second GET request triggering `weapp_new_user()` to read that forged entry and resolve the attacker-supplied `openid` value to a bound WordPress account before `wp_set_auth_cookie()` establishes a fully authenticated session. This makes it possible for unauthenticated attackers to log in as any WordPress user — including administrators — whose bound social provider identifier (openid/unionid) is known or discoverable. Successful exploitation requires that the target site has at least one social provider configured (which activates the vulnerable handler) and that the attacker knows or can enumerate the victim account's bound openid or unionid.

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

WPCOM Member plugin (≤1.7.27) suffers CRITICAL auth bypass (CVE-2026-104803, CVSS 9.8) 🛡️. Attackers can impersonate any WordPress user via social-login flaw. Disable social login & check vendor for fixes. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • ThemeREX Group
  • Booklovers
  • booklovers

10 Oct 2026
Published
10 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.32%

KEV

Description

Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

Deserialization of untrusted data in ThemeREX Booklovers (<=2.13.0) — CVE-2026-62045 (CRITICAL, CVSS 9.8) enables object injection. No patch yet, so restrict access & monitor. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • ThemeREX Group
  • Camelia
  • camelia

10 Oct 2026
Published
10 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.31%

KEV

Description

Deserialization of Untrusted Data vulnerability in ThemeREX Group Camelia camelia allows Object Injection.This issue affects Camelia: from n/a through 1.2.15.

Statistics

  • 1 Post

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-93944: CRITICAL deserialization vuln in ThemeREX Camelia (<=1.2.15). Allows remote object injection & full system compromise. No patch yet — limit exposure, monitor vendor. 🔎 radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 7h ago
Showing 1 to 10 of 38 CVEs