Sign in

STACKFLAG

@stackflag.bsky.social
53 followers 13 following 5.2K posts

Every critical CVE (CVSS 9+), explained in plain English - what it is, how bad it is, and what to do about it. Too many to follow? Exactly. That is why we built stackflag.com - track only the vulnerabilities that affect your stack. #CVE #infosec

PostsRepliesMedia
STACKFLAG @stackflag.bsky.social · 21h
CVE-2026-95357 - chromium The Chrome browser on Android devices (including the Debian Chromium package) can be tricked by a specially crafted web page to write data outside its safe memory area.… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95357: Chrome on Android can run malicious code via web page
The Chrome browser on Android devices (including the Debian Chromium package) can be tricked by a specially crafted web page to write data outside its.
000
STACKFLAG @stackflag.bsky.social · 21h
CVE-2026-95350 - chromium The Android version of Google Chrome (and the Debian Chromium package) can be tricked by a specially crafted web page to run code outside its normal safety walls. This… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95350: Chrome on Android can run code from malicious web page
The Android version of Google Chrome (and the Debian Chromium package) can be tricked by a specially crafted web page to run code outside its normal.
000
STACKFLAG @stackflag.bsky.social · 21h
CVE-2026-95347 - chromium The Chrome web browser on Mac computers (including the Debian‑packaged Chromium version) can be tricked by specially crafted network data to run code on the computer,… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95347: Chrome on Mac can run malicious code
The Chrome web browser on Mac computers (including the Debian‑packaged Chromium version) can be tricked by specially crafted network data to run code on.
000
STACKFLAG @stackflag.bsky.social · 22h
CVE-2026-95331 - chromium The version of Chrome and Chromium packaged for Debian can be tricked by a specially crafted web page to run unwanted code on your computer. This could let an attacker… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95331: Chrome and Chromium on Debian may run malicious code
The version of Chrome and Chromium packaged for Debian can be tricked by a specially crafted web page to run unwanted code on your computer.
000
STACKFLAG @stackflag.bsky.social · 22h
CVE-2026-95325 - chromium Chrome on Debian versions before 154.0.8037.57 can be tricked by a specially crafted web page to execute code on the computer, bypassing the browser’s safety sandbox.… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95325: Chrome on Debian may run malicious code from web page
Chrome on Debian versions before 154.0.8037.57 can be tricked by a specially crafted web page to execute code on the computer, bypassing the browser’s.
001
STACKFLAG @stackflag.bsky.social · 22h
CVE-2026-95313 - chromium Versions of Chromium on Debian and Google Chrome older than 154.0.8037.57 may let a crafted web page execute unwanted code on a user's computer. This could let an attacker… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95313: Chrome on Debian can run malicious code via web page
Versions of Chromium on Debian and Google Chrome older than 154.0.8037.57 may let a crafted web page execute unwanted code on a user's computer.
010
STACKFLAG @stackflag.bsky.social · 22h
CVE-2026-95310 - chromium A bug in Chrome's ad‑filtering feature can let a specially crafted web page cause the browser to run any program the attacker chooses, breaking the protection that… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95310: Chrome on Debian lets attackers run code via web page
A bug in Chrome's ad‑filtering feature can let a specially crafted web page cause the browser to run any program the attacker chooses, breaking the.
020
STACKFLAG @stackflag.bsky.social · 22h
CVE-2026-95284 - chromium A problem in the Chrome browser on Android and the Chromium version used on Debian lets a specially crafted web page cause the browser to run unwanted programs. This could… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95284: Chrome or Chromium on Android can run malicious code
A problem in the Chrome browser on Android and the Chromium version used on Debian lets a specially crafted web page cause the browser to run unwanted.
010
STACKFLAG @stackflag.bsky.social · 22h
CVE-2026-95281 - chromium Older versions of Google Chrome for Android (earlier than version 154.0.8037.57) can be tricked by a malicious web page into running code outside its normal protection… Too many irrelevant or confusing CVEs? Use stackflag.com #chromium #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-95281: Chrome on Android before 154 allows remote code execution
Older versions of Google Chrome for Android (earlier than version 154.0.8037.57) can be tricked by a malicious web page into running code outside its.
010
STACKFLAG @stackflag.bsky.social · 23h
CVE-2025-71365 - picklescan The Picklescan tool, used to check Python pickle files for safety, can be tricked into missing harmful content. If an attacker hides malicious code in a pickle… Too many irrelevant or confusing CVEs? Use stackflag.com #picklescan #matthieumaitre #pip #CVE #infosec
stackflag.com
CVE-2025-71365: Picklescan may let malicious pickle files run code
The Picklescan tool, used to check Python pickle files for safety, can be tricked into missing harmful content.
000
STACKFLAG @stackflag.bsky.social · 23h
CVE-2025-71341 - picklescan The Picklescan tool does not notice a specially crafted pickle file that uses Python's built-in profile.runctx function to run code. If a system checks a pickle… Too many irrelevant or confusing CVEs? Use stackflag.com #picklescan #matthieumaitre #pip #CVE #infosec
stackflag.com
CVE-2025-71341: Picklescan fails to block malicious pickle in Python
The Picklescan tool does not notice a specially crafted pickle file that uses Python's built-in profile.runctx function to run code.
000
STACKFLAG @stackflag.bsky.social · 01/10/2026
CVE-2026-91048 - apache karaf In Apache Karaf, a missing permission file means even a user with only view rights can execute all JDBC‑related shell commands. One of those commands can store a… Too many irrelevant or confusing CVEs? Use stackflag.com #apachekaraf #apachefoundation #CVE #infosec
stackflag.com
CVE-2026-91048: Apache Karaf lets viewer users run any JDBC command
In Apache Karaf, a missing permission file means even a user with only view rights can execute all JDBC‑related shell commands.
010
STACKFLAG @stackflag.bsky.social · 01/10/2026
CVE-2026-91012 - apache karaf Apache Karaf lets users with the manager role change any configuration file the service can write to, including files that control admin permissions. By supplying… Too many irrelevant or confusing CVEs? Use stackflag.com #apachekaraf #apachefoundation #CVE #infosec
stackflag.com
CVE-2026-91012: Apache Karaf allows manager to become admin via file write
Apache Karaf lets users with the manager role change any configuration file the service can write to, including files that control admin permissions.
010
STACKFLAG @stackflag.bsky.social · 01/10/2026
CVE-2025-47949 - samlify A security issue in the samlify library for Node.js allows an attacker to pretend to be any user by forging a SAML response. This requires the attacker to have a signed document… Too many irrelevant or confusing CVEs? Use stackflag.com #samlify #tngan #npm #CVE #infosec
stackflag.com
CVE-2025-47949: Node.js SAML Library Allows Impersonation by Attacker
A security issue in the samlify library for Node.js allows an attacker to pretend to be any user by forging a SAML response.
010
STACKFLAG @stackflag.bsky.social · 01/10/2026
CVE-2026-40982 - org.springframework.cloud:spring-cloud-config-server The Spring Cloud Config Server libraries from Spring Framework, VMware, and Root are affected by a security weakness that could let… Too many irrelevant or confusing CVEs? Use stackflag.com #springframework #Java #CVE #infosec
stackflag.com
CVE-2026-40982: Spring Cloud Config Server may let attackers run code
The Spring Cloud Config Server libraries from Spring Framework, VMware, and Root are affected by a security weakness that could let an attacker execute.
000
STACKFLAG @stackflag.bsky.social · 01/10/2026
CVE-2025-41243 - org.springframework.cloud:spring-cloud-gateway-server-webflux If your application uses Spring Cloud Gateway Server Webflux, Spring Boot actuator, and exposes actuator endpoints without… Too many irrelevant or confusing CVEs? Use stackflag.com #springframework #Java #CVE #infosec
stackflag.com
CVE-2025-41243: Spring Cloud Gateway Server Webflux may allow attackers to modify settings
If your application uses Spring Cloud Gateway Server Webflux, Spring Boot actuator, and exposes actuator endpoints without security, an attacker could.
010
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2022-23305 - log4j:log4j The log4j library used in several products can be tricked into executing arbitrary commands. Updating to the latest patched version removes this risk. Apply the… Too many irrelevant or confusing CVEs? Use stackflag.com #log4jlog4j #oracle #Java #CVE #infosec
stackflag.com
CVE-2022-23305: log4j can let attackers run code
The log4j library used in several products can be tricked into executing arbitrary commands. Updating to the latest patched version removes this risk.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2023-42282 - ip The ip package used in Node.js applications can mistakenly treat some private addresses as public, allowing a request to be sent to internal systems. This can let a remote user trick the… Too many irrelevant or confusing CVEs? Use stackflag.com #ip #indutny #npm #CVE #infosec
stackflag.com
CVE-2023-42282: ip library may let attackers reach internal network
The ip package used in Node.js applications can mistakenly treat some private addresses as public, allowing a request to be sent to internal systems.
010
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2026-44791 - n8n An authenticated user with permission to create or modify workflows in n8n can bypass a security patch and potentially gain full control over the host. This can happen if users… Too many irrelevant or confusing CVEs? Use stackflag.com #n8n #GitHubActions #npm #CVE #infosec
stackflag.com
CVE-2026-44791: n8n XML Node Allows Unauthorized Access
An authenticated user with permission to create or modify workflows in n8n can bypass a security patch and potentially gain full control over the host.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2026-44789 - n8n An attacker with permission to edit workflows can exploit a weakness in n8n's HTTP Request node, potentially allowing them to execute malicious code on the instance. This issue… Too many irrelevant or confusing CVEs? Use stackflag.com #n8n #GitHubActions #npm #CVE #infosec
stackflag.com
CVE-2026-44789: n8n: Unvalidated HTTP Request Node Exposes to RCE
An attacker with permission to edit workflows can exploit a weakness in n8n's HTTP Request node, potentially allowing them to execute malicious code on.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2023-29017 - vm2 Versions of vm2 before 3.9.15 do not correctly handle certain error objects, allowing a malicious script to break out of the sandbox. This could let an attacker execute commands on the… Too many irrelevant or confusing CVEs? Use stackflag.com #vm2 #rootio #npm #CVE #infosec
stackflag.com
CVE-2023-29017: vm2 sandbox can let attackers run code on host
Versions of vm2 before 3.9.15 do not correctly handle certain error objects, allowing a malicious script to break out of the sandbox.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2023-27482 - rootio-supervisor The Supervisor component used in Alpine 3.19 can be tricked into running malicious code, which could give an attacker control over the system.… Too many irrelevant or confusing CVEs? Use stackflag.com #rootiosupervisor #homeassistant #RootAlpine319 #CVE #infosec
stackflag.com
CVE-2023-27482: RootIO Supervisor may let attackers run code
The Supervisor component used in Alpine 3.19 can be tricked into running malicious code, which could give an attacker control over the system.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2024-23771 - rootio-darkhttpd The darkhttpd web server included in Alpine Linux can be tricked into running unwanted code. This could let an attacker take control of the server or… Too many irrelevant or confusing CVEs? Use stackflag.com #rootiodarkhttpd #alpine #RootAlpine318 #CVE #infosec
stackflag.com
CVE-2024-23771: darkhttpd on Alpine can allow unauthorized code execution
The darkhttpd web server included in Alpine Linux can be tricked into running unwanted code.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2025-7783 - form-data Versions of the form-data library (up to 2.5.3, 3.0.0‑3.0.3, and 4.0.0‑4.0.3) may generate predictable values, letting an attacker add extra parameters to web requests. This… Too many irrelevant or confusing CVEs? Use stackflag.com #formdata #ljharb #npm #CVE #infosec
stackflag.com
CVE-2025-7783: form-data library can be tricked to alter request data
Versions of the form-data library (up to 2.5.3, 3.0.0‑3.0.3, and 4.0.0‑4.0.3) may generate predictable values, letting an attacker add extra parameters to.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2026-4738 - gdal Versions of GDAL older than 3.11 contain a flaw in the zlib component that can corrupt memory and potentially allow an attacker to execute code on the server. This could happen… Too many irrelevant or confusing CVEs? Use stackflag.com #gdal #canonical #Debian11 #CVE #infosec
stackflag.com
CVE-2026-4738: GDAL before 3.11 may let attackers run code
Versions of GDAL older than 3.11 contain a flaw in the zlib component that can corrupt memory and potentially allow an attacker to execute code on the.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2026-96538 - warehousepg In WarehousePG version 7.x before 7.6.0, any logged‑in database user can run built‑in functions to write, rename, delete, or list files in the database’s data and log… Too many irrelevant or confusing CVEs? Use stackflag.com #warehousepg #enterprisedb #CVE #infosec
stackflag.com
CVE-2026-96538: WarehousePG lets regular users modify server files
In WarehousePG version 7.x before 7.6.0, any logged‑in database user can run built‑in functions to write, rename, delete, or list files in the database’s.
000
STACKFLAG @stackflag.bsky.social · 30/09/2026
CVE-2026-73030 - unearth The unearth software version 0.18.2 allows attackers to create malicious archives that can write files to any location on the system. This is a security risk because it… Too many irrelevant or confusing CVEs? Use stackflag.com #unearth #debian #Debian12 #CVE #infosec
stackflag.com
CVE-2026-73030: unearth 0.18.2: Malicious Archives Can Write Files Anywhere
The unearth software version 0.18.2 allows attackers to create malicious archives that can write files to any location on the system.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-8066 - rtu500 series cmu firmware The RTU500 series can be tricked into accepting a crafted file upload that writes to any location on its internal storage, even without logging in. This could let an… Too many irrelevant or confusing CVEs? Use stackflag.com #hitachienergy #CVE #infosec
stackflag.com
CVE-2026-8066: Hitachi Energy RTU500 lets attackers overwrite device files
The RTU500 series can be tricked into accepting a crafted file upload that writes to any location on its internal storage, even without logging in.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-96429 - agentflow 4.0 The web interface of Flowring Agentflow 4.0 (versions released before August 8, 2025) lets a remote user send specially crafted data in the 'id' field, causing the system to run… Too many irrelevant or confusing CVEs? Use stackflag.com #flowring #CVE #infosec
stackflag.com
CVE-2026-96429: Flowring Agentflow 4.0 lets attackers run any database command
The web interface of Flowring Agentflow 4.0 (versions released before August 8, 2025) lets a remote user send specially crafted data in the 'id' field,.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-84154 - geovia geospatial data manager The GEOVIA Geospatial Data Manager versions released between 2024x and 2026x may let a malicious user send specially crafted data that causes the server to run unwanted… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec
stackflag.com
CVE-2026-84154: GEOVIA Geospatial Data Manager can run attacker code
The GEOVIA Geospatial Data Manager versions released between 2024x and 2026x may let a malicious user send specially crafted data that causes the server.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-102240 - nap930 The web-based Network Tools page in Netcore NAP930 can be tricked into running operating‑system commands by sending a crafted sid parameter. An attacker from anywhere on the internet… Too many irrelevant or confusing CVEs? Use stackflag.com #nap930 #netcore #CVE #infosec
stackflag.com
CVE-2026-102240: Netcore NAP930 allows remote command execution
The web-based Network Tools page in Netcore NAP930 can be tricked into running operating‑system commands by sending a crafted sid parameter.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-102361 The mall4j system (versions up to 4.0) lets anyone send a request to change a customer's password without first proving who they are. This means an attacker could take over any shopper’s account and see orders… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec
stackflag.com
CVE-2026-102361: mall4j lets anyone reset a user password
The mall4j system (versions up to 4.0) lets anyone send a request to change a customer's password without first proving who they are.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-102334 - nginx-proxy-manager The Nginx Proxy Manager version 2.16.0 and earlier does not limit how often someone can try to log in, so an attacker can repeatedly guess passwords and verification… Too many irrelevant or confusing CVEs? Use stackflag.com #nginxproxymanager #CVE #infosec
stackflag.com
CVE-2026-102334: Nginx Proxy Manager allows unlimited login guesses
The Nginx Proxy Manager version 2.16.0 and earlier does not limit how often someone can try to log in, so an attacker can repeatedly guess passwords and.
000
STACKFLAG @stackflag.bsky.social · 29/09/2026
CVE-2026-101264 - zhome a0101 The Ziroom ZHOME A0101 device version 1.0.1.0 has a flaw in its /api/ZRnetwork/set_passwd function that lets an attacker send specially crafted password data and run commands… Too many irrelevant or confusing CVEs? Use stackflag.com #zhomea0101 #ziroom #CVE #infosec
stackflag.com
CVE-2026-101264: Ziroom ZHOME A0101 allows remote command injection via set_passwd
The Ziroom ZHOME A0101 device version 1.0.1.0 has a flaw in its /api/ZRnetwork/set_passwd function that lets an attacker send specially crafted password.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-101261 - zhome a0101 The Wi‑Fi setup function on Ziroom ZHOME A0101 devices can be tricked into running unauthorized commands when a specially crafted password is sent. An attacker on the network… Too many irrelevant or confusing CVEs? Use stackflag.com #zhomea0101 #ziroom #CVE #infosec
stackflag.com
CVE-2026-101261: Ziroom ZHOME A0101 allows remote command injection via Wi‑Fi setup
The Wi‑Fi setup function on Ziroom ZHOME A0101 devices can be tricked into running unauthorized commands when a specially crafted password is sent.
010
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-102268 - pyjwt The PyJWT library for Python, versions before 2.14.0, can be tricked into treating a modified public‑key file as a secret key. This lets anyone who knows the public key create… Too many irrelevant or confusing CVEs? Use stackflag.com #pyjwt #jpadilla #CVE #infosec
stackflag.com
CVE-2026-102268: PyJWT lets attackers forge tokens with altered public key
The PyJWT library for Python, versions before 2.14.0, can be tricked into treating a modified public‑key file as a secret key.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-101110 - book library (free) extension for joomla The free Book Library add‑on for Joomla can be tricked into running a database command that changes how book listings are sorted. An attacker can send specially… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec
stackflag.com
CVE-2026-101110: Joomla Book Library extension lets attackers change data order
The free Book Library add‑on for Joomla can be tricked into running a database command that changes how book listings are sorted.
010
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-100752 - real estate manager (free) extension for joomla The free Real Estate Manager extension for Joomla lets anyone on the internet send a specially crafted request that changes the way the site builds its… Too many irrelevant or confusing CVEs? Use stackflag.com #CVE #infosec
stackflag.com
CVE-2026-100752: Joomla Real Estate Manager lets attackers read database
The free Real Estate Manager extension for Joomla lets anyone on the internet send a specially crafted request that changes the way the site builds its.
010
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-49994 - bluehood In versions before 0.7.1, Bluehood's web interface required login only for its web pages, not for its API endpoints. This allowed anyone on the same network to view Bluetooth data… Too many irrelevant or confusing CVEs? Use stackflag.com #bluehood #dannymcc #CVE #infosec
stackflag.com
CVE-2026-49994: Bluehood lets anyone change settings via API
In versions before 0.7.1, Bluehood's web interface required login only for its web pages, not for its API endpoints.
010
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-101894 - decompress The decompress library used in Node.js applications may let a specially crafted archive place files outside the intended extraction folder. This could let an attacker modify… Too many irrelevant or confusing CVEs? Use stackflag.com #decompress #xhmikosr #CVE #infosec
stackflag.com
CVE-2026-101894: xhmikosr/decompress can write files outside target folder
The decompress library used in Node.js applications may let a specially crafted archive place files outside the intended extraction folder.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-86102 - watchguard ap The internal management interface of WatchGuard AP can be tricked into running any operating‑system command if an attacker can reach the device on the network. This… Too many irrelevant or confusing CVEs? Use stackflag.com #watchguardap #watchguard #CVE #infosec
stackflag.com
CVE-2026-86102: WatchGuard AP lets network attacker run commands
The internal management interface of WatchGuard AP can be tricked into running any operating‑system command if an attacker can reach the device on the.
001
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-12249 - github.com/ubuntu/adsys The ADSys component used in Ubuntu can pull code from a source that is not fully trusted, which could allow unwanted changes to be introduced. This could affect the… Too many irrelevant or confusing CVEs? Use stackflag.com #ubuntu #Golang #CVE #infosec
stackflag.com
CVE-2026-12249: Ubuntu ADSys may download code from less trusted source
The ADSys component used in Ubuntu can pull code from a source that is not fully trusted, which could allow unwanted changes to be introduced.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-101081 - di-8400 The router’s web‑based settings page contains a coding mistake that can be triggered by sending specially crafted data, causing the device to run unintended code. An attacker who can… Too many irrelevant or confusing CVEs? Use stackflag.com #di8400 #dlink #CVE #infosec
stackflag.com
CVE-2026-101081: D-Link DI-8400 router allows remote takeover via web admin
The router’s web‑based settings page contains a coding mistake that can be triggered by sending specially crafted data, causing the device to run.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-88804 - rancher In Rancher versions prior to the latest patches, anyone on the internet can modify public interface settings without logging in. This lets attackers insert hidden scripts that run… Too many irrelevant or confusing CVEs? Use stackflag.com #rancher #suse #CVE #infosec
stackflag.com
CVE-2026-88804: Rancher allows anyone to change UI settings and run code
In Rancher versions prior to the latest patches, anyone on the internet can modify public interface settings without logging in.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2025-32460 - graphicsmagick The GraphicsMagick image‑processing tool in the Alpine 3.22 environment could be tricked into running unwanted programs. This could let an attacker take control… Too many irrelevant or confusing CVEs? Use stackflag.com #graphicsmagick #RootAlpine322 #CVE #infosec
stackflag.com
CVE-2025-32460: GraphicsMagick can let attackers execute code
The GraphicsMagick image‑processing tool in the Alpine 3.22 environment could be tricked into running unwanted programs.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-101077 - nr289-ge The Netcore NR289‑GE version 1.4.5102 lets anyone on the network send a request to the boa_temp component and skip the normal login check. This could let attackers view or change… Too many irrelevant or confusing CVEs? Use stackflag.com #nr289ge #netcore #CVE #infosec
stackflag.com
CVE-2026-101077: Netcore NR289‑GE allows remote access without login
The Netcore NR289‑GE version 1.4.5102 lets anyone on the network send a request to the boa_temp component and skip the normal login check.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-101075 - nr289-ge The NR289-GE video intercom running version 1.4.5102 can be tricked into executing operating system commands when an attacker supplies a crafted MAC address to its… Too many irrelevant or confusing CVEs? Use stackflag.com #nr289ge #netcore #CVE #infosec
stackflag.com
CVE-2026-101075: Netcore NR289-GE allows remote command injection
The NR289-GE video intercom running version 1.4.5102 can be tricked into executing operating system commands when an attacker supplies a crafted MAC.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-73642 - payroll The payroll system’s file‑download feature can be tricked into returning any file on the server, even system files. An attacker does not need to log in to exploit this, potentially… Too many irrelevant or confusing CVEs? Use stackflag.com #payroll #dayforce #CVE #infosec
stackflag.com
CVE-2026-73642: Dayforce Payroll allows attackers to download any file
The payroll system’s file‑download feature can be tricked into returning any file on the server, even system files.
001
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-90924 - logsign siem The Logsign SIEM version 6.4.101 through 6.4.116 accepts the factory‑set username and password, so anyone who knows these defaults can log in. This could let an attacker view or… Too many irrelevant or confusing CVEs? Use stackflag.com #logsignsiem #CVE #infosec
stackflag.com
CVE-2026-90924: Logsign SIEM can be accessed with default admin credentials
The Logsign SIEM version 6.4.101 through 6.4.116 accepts the factory‑set username and password, so anyone who knows these defaults can log in.
000
STACKFLAG @stackflag.bsky.social · 28/09/2026
CVE-2026-87799 - lxd Versions of Canonical LXD (4.0 and newer) let a user who can create containers or a malicious migration source place specially crafted files that cause the system to write wherever they… Too many irrelevant or confusing CVEs? Use stackflag.com #lxd #canonical #CVE #infosec
stackflag.com
CVE-2026-87799: LXD can let attacker write files as root
Versions of Canonical LXD (4.0 and newer) let a user who can create containers or a malicious migration source place specially crafted files that cause.
010