Sign in

stemshop.bsky.social

@stemshop.bsky.social
23 followers 18 following 1.9K posts

Critical CVEs, vulnerability research, PoCs and security intelligence. Tracking high-impact vulnerabilities and affected products. stemshop.top/cve #CVE #CyberSecurity #InfoSec #Vulnerability #SecurityResearch

PostsRepliesMedia
stemshop.bsky.social @stemshop.bsky.social · 2h
🚨 CVE-2026-103264 — CVSS 9.3 CRITICAL Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts ... 🔎 stemshop.top/cve/CVE-2026-103264 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 2h
🚨 CVE-2026-103244 — CVSS 9.3 CRITICAL ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore co... 🔎 stemshop.top/cve/CVE-2026-103244 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 2h
🚨 CVE-2026-101148 — CVSS 10 CRITICAL The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integra... 🔎 stemshop.top/cve/CVE-2026-101148 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 4h
🚨 CVE-2026-103655 — CVSS 9.3 CRITICAL MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a v... 🔎 stemshop.top/cve/CVE-2026-103655 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 4h
🚨 CVE-2026-75957 — CVSS 9.8 CRITICAL The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Aut... 🔎 stemshop.top/cve/CVE-2026-75957 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 4h
🚨 CVE-2026-15989 — CVSS 9.8 CRITICAL The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in al... 🔎 stemshop.top/cve/CVE-2026-15989 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 6h
🚨 CVE-2025-41753 — CVSS 9.3 CRITICAL The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficien... 🔎 stemshop.top/cve/CVE-2025-41753 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-92966 — CVSS 9.1 CRITICAL The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress i... 🔎 stemshop.top/cve/CVE-2026-92966 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-82829 — CVSS 9.3 CRITICAL Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which ... 🔎 stemshop.top/cve/CVE-2026-82829 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-82827 — CVSS 9.3 CRITICAL Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The ... 🔎 stemshop.top/cve/CVE-2026-82827 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-82825 — CVSS 9.3 CRITICAL Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Funct... 🔎 stemshop.top/cve/CVE-2026-82825 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-82824 — CVSS 9.3 CRITICAL Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows ... 🔎 stemshop.top/cve/CVE-2026-82824 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-76142 — CVSS 9.3 CRITICAL Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTN... 🔎 stemshop.top/cve/CVE-2026-76142 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 10h
🚨 CVE-2026-14157 — CVSS 9.4 CRITICAL Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user ... 🔎 stemshop.top/cve/CVE-2026-14157 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-101283 — CVSS 9.2 CRITICAL iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA... 🔎 stemshop.top/cve/CVE-2026-101283 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102149 — CVSS 9.4 CRITICAL Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assig... 🔎 stemshop.top/cve/CVE-2026-102149 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102147 — CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to s... 🔎 stemshop.top/cve/CVE-2026-102147 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102115 — CVSS 9.8 CRITICAL Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthen... 🔎 stemshop.top/cve/CVE-2026-102115 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102106 — CVSS 9.1 CRITICAL Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative s... 🔎 stemshop.top/cve/CVE-2026-102106 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102105 — CVSS 9.1 CRITICAL Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF)... 🔎 stemshop.top/cve/CVE-2026-102105 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102104 — CVSS 9.1 CRITICAL Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF)... 🔎 stemshop.top/cve/CVE-2026-102104 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102103 — CVSS 9.1 CRITICAL Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF)... 🔎 stemshop.top/cve/CVE-2026-102103 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102102 — CVSS 9.1 CRITICAL Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF)... 🔎 stemshop.top/cve/CVE-2026-102102 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102095 — CVSS 9.1 CRITICAL Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kitew... 🔎 stemshop.top/cve/CVE-2026-102095 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-101276 — CVSS 9.2 CRITICAL iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test wat... 🔎 stemshop.top/cve/CVE-2026-101276 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-103547 — CVSS 9.2 CRITICAL In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results a... 🔎 stemshop.top/cve/CVE-2026-103547 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102992 — CVSS 9.2 CRITICAL piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores Thre... 🔎 stemshop.top/cve/CVE-2026-102992 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 18h
🚨 CVE-2026-55107 — CVSS 10 CRITICAL Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution ... 🔎 stemshop.top/cve/CVE-2026-55107 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 18h
🚨 CVE-2026-103475 — CVSS 9.3 CRITICAL yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowed... 🔎 stemshop.top/cve/CVE-2026-103475 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 18h
🚨 CVE-2026-103473 — CVSS 9.2 CRITICAL Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_proces... 🔎 stemshop.top/cve/CVE-2026-103473 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 18h
🚨 CVE-2026-100512 — CVSS 9.8 CRITICAL Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions. 🔎 stemshop.top/cve/CVE-2026-100512 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-75969 — CVSS 9.1 CRITICAL Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgra... 🔎 stemshop.top/cve/CVE-2026-75969 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-62308 — CVSS 9.1 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtai... 🔎 stemshop.top/cve/CVE-2026-62308 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-55494 — CVSS 9.8 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtai... 🔎 stemshop.top/cve/CVE-2026-55494 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-55181 — CVSS 9.4 CRITICAL Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtai... 🔎 stemshop.top/cve/CVE-2026-55181 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-19445 — CVSS 9.2 CRITICAL A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_cal... 🔎 stemshop.top/cve/CVE-2026-19445 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-102490 — CVSS 9.4 CRITICAL All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root. 🔎 stemshop.top/cve/CVE-2026-102490 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-102489 — CVSS 9.4 CRITICAL Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code exec... 🔎 stemshop.top/cve/CVE-2026-102489 #CVE #CyberSecurity #InfoSec
001
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-103470 — CVSS 9.3 CRITICAL In Internet2 Grouper before 7.5.1 (in some configurations), a user who is allowed to create or edit rules i... 🔎 stemshop.top/cve/CVE-2026-103470 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20h
🚨 CVE-2026-102427 — CVSS 10 CRITICAL Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - s... 🔎 stemshop.top/cve/CVE-2026-102427 #CVE #CyberSecurity #InfoSec
011
stemshop.bsky.social @stemshop.bsky.social · 22h
🚨 CVE-2026-76570 — CVSS 10 CRITICAL Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.... 🔎 stemshop.top/cve/CVE-2026-76570 #CVE #CyberSecurity #InfoSec
011
stemshop.bsky.social @stemshop.bsky.social · 22h
🚨 CVE-2026-18782 — CVSS 9.8 CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex ... 🔎 stemshop.top/cve/CVE-2026-18782 #CVE #CyberSecurity #InfoSec
001
stemshop.bsky.social @stemshop.bsky.social · 22h
🚨 CVE-2026-103395 — CVSS 9.3 CRITICAL LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle ena... 🔎 stemshop.top/cve/CVE-2026-103395 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22h
🚨 CVE-2026-93903 — CVSS 9.4 CRITICAL LiteSpeed Web Server (LSWS) before 6.3.7 build 1 mishandles internal redirect URL validation in a certain "... 🔎 stemshop.top/cve/CVE-2026-93903 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22h
🚨 CVE-2026-82307 — CVSS 9.8 CRITICAL Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolus... 🔎 stemshop.top/cve/CVE-2026-82307 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 30/09/2026
🚨 CVE-2026-97274 — CVSS 9.8 CRITICAL Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions. 🔎 stemshop.top/cve/CVE-2026-97274 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 30/09/2026
🚨 CVE-2026-97248 — CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions. 🔎 stemshop.top/cve/CVE-2026-97248 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 30/09/2026
🚨 CVE-2026-96822 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Books Gallery <= 4.8.3 versions. 🔎 stemshop.top/cve/CVE-2026-96822 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 30/09/2026
🚨 CVE-2026-96350 — CVSS 9.8 CRITICAL Subscriber Privilege Escalation in Estatik <= 4.3.5 versions. 🔎 stemshop.top/cve/CVE-2026-96350 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 30/09/2026
🚨 CVE-2026-96349 — CVSS 10 CRITICAL Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions. 🔎 stemshop.top/cve/CVE-2026-96349 #CVE #CyberSecurity #InfoSec
000