Sign in

stemshop.bsky.social

@stemshop.bsky.social
24 followers 18 following 2K posts

Critical CVEs, vulnerability research, PoCs and security intelligence. Tracking high-impact vulnerabilities and affected products. stemshop.top/cve #CVE #CyberSecurity #InfoSec #Vulnerability #SecurityResearch

PostsRepliesMedia
stemshop.bsky.social @stemshop.bsky.social · 20m
🚨 CVE-2026-42417 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions. 🔎 stemshop.top/cve/CVE-2026-42417 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 20m
🚨 CVE-2026-42415 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Porto Theme - Functionality <= 3.9.3 versions. 🔎 stemshop.top/cve/CVE-2026-42415 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-41555 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Newsletter Subscription Form – User Subscriptions Form, Capture Email <= 1... 🔎 stemshop.top/cve/CVE-2026-41555 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39797 — CVSS 9.8 CRITICAL Unauthenticated PHP Object Injection in GDPR Framework By Data443 <= 2.5.0 versions. 🔎 stemshop.top/cve/CVE-2026-39797 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39795 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in SendPress Newsletters <= 1.26.1.20 versions. 🔎 stemshop.top/cve/CVE-2026-39795 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39785 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Gmedia Photo Gallery <= 1.25.1 versions. 🔎 stemshop.top/cve/CVE-2026-39785 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39773 — CVSS 10 CRITICAL Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions. 🔎 stemshop.top/cve/CVE-2026-39773 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39770 — CVSS 10 CRITICAL Unauthenticated Arbitrary File Upload in Doctreat <= 1.7.0 versions. 🔎 stemshop.top/cve/CVE-2026-39770 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39764 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Radius Booking — Booking Calendar for Appointments &amp; Services <= 1.0.1... 🔎 stemshop.top/cve/CVE-2026-39764 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 21m
🚨 CVE-2026-39761 — CVSS 9.8 CRITICAL Unauthenticated Privilege Escalation in Meta Box AIO <= 3.7.1 versions. 🔎 stemshop.top/cve/CVE-2026-39761 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-39759 — CVSS 9.9 CRITICAL Employer / Sales Representative Arbitrary File Upload in Workreap Core <= 3.4.5 versions. 🔎 stemshop.top/cve/CVE-2026-39759 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-39757 — CVSS 9.9 CRITICAL Subscriber Arbitrary File Upload in Taskbot <= 6.6 versions. 🔎 stemshop.top/cve/CVE-2026-39757 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-39755 — CVSS 9.9 CRITICAL Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. 🔎 stemshop.top/cve/CVE-2026-39755 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-39753 — CVSS 9.8 CRITICAL Unauthenticated Privilege Escalation in Taskbot <= 6.6 versions. 🔎 stemshop.top/cve/CVE-2026-39753 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-39746 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in Booknetic <= 4.8.5 versions. 🔎 stemshop.top/cve/CVE-2026-39746 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-32579 — CVSS 10 CRITICAL Unauthenticated Arbitrary File Upload in Kognetiks Chatbot for WordPress <= 2.4.9 versions. 🔎 stemshop.top/cve/CVE-2026-32579 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 22m
🚨 CVE-2026-32568 — CVSS 9.9 CRITICAL Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions. 🔎 stemshop.top/cve/CVE-2026-32568 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 23m
🚨 CVE-2026-32557 — CVSS 9.3 CRITICAL Unauthenticated SQL Injection in WooCommerce Appointments <= 5.3.2 versions. 🔎 stemshop.top/cve/CVE-2026-32557 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 23m
🚨 CVE-2026-85153 — CVSS 9.3 CRITICAL This vulnerability exists in the Schmooze app due to the use of hardcoded credentials and cryptographic key... 🔎 stemshop.top/cve/CVE-2026-85153 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 1h
🔴 Citrix NetScaler CVE-2026-88779 — active exploitation confirmed Remote unauthenticated memory overflow targets NetScaler ADC/Gateway systems using SAML and can cause denial of service. CISA added the flaw to KE stemshop.top/blog/netscal... #CVE #CVE202688779 #Citrix #NetScaler #SAML #CyberSecurity
000
stemshop.bsky.social @stemshop.bsky.social · 2h
🚨 CVE-2026-94293 — CVSS 9.3 CRITICAL An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests a... 🔎 stemshop.top/cve/CVE-2026-94293 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 6h
🚨 CVE-2026-105484 — CVSS 10 CRITICAL A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element i... 🔎 stemshop.top/cve/CVE-2026-105484 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 8h
🚨 CVE-2026-105763 — CVSS 9.6 CRITICAL Twenty is an open-source CRM (customer relationship management) platform. From 1.20.10 until 2.7.0, the /me... 🔎 stemshop.top/cve/CVE-2026-105763 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 10h
🚨 CVE-2026-91107 — CVSS 9.3 CRITICAL openSIS Classic 9.3 allows an authenticated user with the built-in teacher role can select an arbitrary sta... 🔎 stemshop.top/cve/CVE-2026-91107 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 10h
🚨 CVE-2026-21589 — CVSS 9.3 CRITICAL h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Manageme... 🔎 stemshop.top/cve/CVE-2026-21589 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 12h
🚨 CVE-2026-77226 — CVSS 9.2 CRITICAL Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web applicatio... 🔎 stemshop.top/cve/CVE-2026-77226 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 12h
🚨 CVE-2026-105740 — CVSS 9.9 CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, any authenti... 🔎 stemshop.top/cve/CVE-2026-105740 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 12h
🚨 CVE-2026-105697 — CVSS 9.9 CRITICAL Langflow is a tool for building and deploying AI-powered agents and workflows. Before Langflow 1.10.3, the ... 🔎 stemshop.top/cve/CVE-2026-105697 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 12h
🚨 CVE-2026-105691 — CVSS 9.9 CRITICAL Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attac... 🔎 stemshop.top/cve/CVE-2026-105691 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-97283 — CVSS 9.8 CRITICAL Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP Advanced Post Manager advanced-po... 🔎 stemshop.top/cve/CVE-2026-97283 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-105641 — CVSS 9.8 CRITICAL Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deploym... 🔎 stemshop.top/cve/CVE-2026-105641 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-105640 — CVSS 9.1 CRITICAL Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by G... 🔎 stemshop.top/cve/CVE-2026-105640 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-105639 — CVSS 9.8 CRITICAL Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in Us... 🔎 stemshop.top/cve/CVE-2026-105639 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-105638 — CVSS 9.1 CRITICAL Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-... 🔎 stemshop.top/cve/CVE-2026-105638 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-105637 — CVSS 9.6 CRITICAL Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/... 🔎 stemshop.top/cve/CVE-2026-105637 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-105636 — CVSS 9.9 CRITICAL Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plan... 🔎 stemshop.top/cve/CVE-2026-105636 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-103352 — CVSS 9.3 CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BA... 🔎 stemshop.top/cve/CVE-2026-103352 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 14h
🚨 CVE-2026-88395 — CVSS 9.8 CRITICAL GouGuOA v6.0.5 and before is vulnerable to SQL Injection in /home/message/rubbish via the keywords parameter. 🔎 stemshop.top/cve/CVE-2026-88395 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 16h
🚨 CVE-2026-102428 — CVSS 9.3 CRITICAL Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order... 🔎 stemshop.top/cve/CVE-2026-102428 #CVE #CyberSecurity #InfoSec
010
stemshop.bsky.social @stemshop.bsky.social · 22h
🚨 CVE-2026-105285 — CVSS 9.3 CRITICAL A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknow... 🔎 stemshop.top/cve/CVE-2026-105285 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-105284 — CVSS 9.3 CRITICAL A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the functi... 🔎 stemshop.top/cve/CVE-2026-105284 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-103510 — CVSS 9.5 CRITICAL P4 Search prior to 2026.4.2 does not fail securely when its service authentication token is blank. In affec... 🔎 stemshop.top/cve/CVE-2026-103510 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-100103 — CVSS 10 CRITICAL Perforce P4 Search container images prior to 2026.4.2 reset the service authentication token to a publicly ... 🔎 stemshop.top/cve/CVE-2026-100103 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-100102 — CVSS 9.5 CRITICAL Perforce P4 Search container images prior to 2026.4.2 enable an unauthenticated Java debug interface. An at... 🔎 stemshop.top/cve/CVE-2026-100102 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-105294 — CVSS 9.1 CRITICAL Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Disc... 🔎 stemshop.top/cve/CVE-2026-105294 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-105293 — CVSS 9.2 CRITICAL Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows scrip... 🔎 stemshop.top/cve/CVE-2026-105293 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-105223 — CVSS 9.1 CRITICAL maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() an... 🔎 stemshop.top/cve/CVE-2026-105223 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-105222 — CVSS 9.1 CRITICAL The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by defaul... 🔎 stemshop.top/cve/CVE-2026-105222 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 05/10/2026
🚨 CVE-2026-105221 — CVSS 9.1 CRITICAL The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path... 🔎 stemshop.top/cve/CVE-2026-105221 #CVE #CyberSecurity #InfoSec
000
stemshop.bsky.social @stemshop.bsky.social · 04/10/2026
🚨 CVE-2026-105218 — CVSS 9.1 CRITICAL gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allow... 🔎 stemshop.top/cve/CVE-2026-105218 #CVE #CyberSecurity #InfoSec
000