Sign in

VulnSea

@vulnsea.com
23 followers 1 following 557 posts
PostsRepliesMedia
VulnSea @vulnsea.com · 9h
🌊 ABYSSAL · critical with a public exploit CVE-2026-102992: piscina is a node.js worker pool implementation CVSS 9.2 beta.vulnsea.com/cve/CVE-2026-102992 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-102992 — piscina is a node.js worker pool implementation
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollu…
000
VulnSea @vulnsea.com · 13h
🌊 ABYSSAL · critical with a public exploit CVE-2026-55494: Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-55494 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-55494 — Tugtainer: Unauthenticated access to Tugtainer Agent Docker management APIs when AGENT_SECRET is unset
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request sign…
010
VulnSea @vulnsea.com · 13h
🌊 ABYSSAL · critical with a public exploit CVE-2026-102911: A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7 CVSS 9.9 · EPSS 1.8% beta.vulnsea.com/cve/CVE-2026-102911 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-102911 — A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7
A flaw has been found in zosmaai pi-llm-wiki up to 0.11.7. Affected is an unknown function of the file mcp/index.ts of the component wiki_capture_source MCP tool. Executing a manipulation of the argument url can lead to os command inject…
010
VulnSea @vulnsea.com · 16h
🌊 ABYSSAL · critical with a public exploit CVE-2026-102794: A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0 CVSS 9.1 · EPSS 2.4% beta.vulnsea.com/cve/CVE-2026-102794 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-102794 — A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0
A vulnerability has been found in Ziroom ZHOME A0101 1.0.1.0. This issue affects some unknown processing of the file /api/ZRnetwork/ping. Such manipulation of the argument url leads to command injection. It is possible to launch the atta…
000
VulnSea @vulnsea.com · 16h
🌊 ABYSSAL · critical with a public exploit CVE-2026-103041: LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfac… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-103041 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-103041 — LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces
LightLLM through 1.2.0 multimodal deployments expose an unauthenticated RPyC cache service with pickle deserialization enabled on all interfaces. Attackers can send crafted serialized objects to exposed cache methods to execute arbitrary…
000
VulnSea @vulnsea.com · 29/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-39117: An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary cod… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-39117 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-39117 — An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php
An issue in AltumCode 66Uptime before v.54.0.0 and 66Uptime ping-servers plugin before v.2.0.0 allows a remote attacker to execute arbitrary code via the index.php
000
VulnSea @vulnsea.com · 29/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-77177: Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt i… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-77177 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-77177 — Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluati…
Open GenAI Stack (aka ogx-ai) 2026-06-11, as used in the Meta AI backend for WhatsApp and other products, allows code execution because prompt injection (with Jinja2 template syntax) can be used to achieve server-side expression evaluati…
000
VulnSea @vulnsea.com · 29/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-102240: A vulnerability was found in Netcore NAP930 0.1.241010.141410 CVSS 10 · EPSS 2.0% beta.vulnsea.com/cve/CVE-2026-102240 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-102240 — A vulnerability was found in Netcore NAP930 0.1.241010.141410
A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/network_tools of the component Network Tools CGI. The manipulation of the argument sid results in os command injection…
000
VulnSea @vulnsea.com · 29/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101354: A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4 CVSS 9.6 beta.vulnsea.com/cve/CVE-2026-101354 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101354 — A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4
A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of the component MmtAtePrase Parser. Performing a manipulation results in stack-based buffer overflow. The attacker must…
001
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101081: D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow CVSS 9.1 beta.vulnsea.com/cve/CVE-2026-101081 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101081 — D-Link DI-8400 Web Administration Service menu_nat_more.asp menu_nat_more_asp stack-based overflow
A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The manipulation of the argument opt result…
000
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101077: Netcore NR289-GE boa_temp process_request missing authentication CVSS 10 beta.vulnsea.com/cve/CVE-2026-101077 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101077 — Netcore NR289-GE boa_temp process_request missing authentication
A flaw has been found in Netcore NR289-GE 1.4.5102. This impacts the function process_request of the component boa_temp Handler. This manipulation causes missing authentication. The attack is possible to be carried out remotely. The expl…
000
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101074: A weakness has been identified in Netcore NR289-GE 1.4.5102 CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-101074 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101074 — A weakness has been identified in Netcore NR289-GE 1.4.5102
A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the file /bin/boa of the component Authentication. Executing a manipulation of the argument Username can lead to stack-ba…
000
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-85526: Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD CVSS 9.9 beta.vulnsea.com/cve/CVE-2026-85526 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-85526 — Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD
Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with instance creation privileges to delete or replace arbitrary files and directories on the host filesystem as root via a …
000
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101072: Netcore NR289-GE CGI ap_ip.cgi system os command injection CVSS 10 beta.vulnsea.com/cve/CVE-2026-101072 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101072 — Netcore NR289-GE CGI ap_ip.cgi system os command injection
A vulnerability was identified in Netcore NR289-GE 1.4.5102. This issue affects the function system of the file /ap_ip.cgi of the component CGI Handler. Such manipulation of the argument ip leads to os command injection. The attack can b…
000
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101039: A vulnerability was identified in FAST FAC1900R 20190827_2.0.2 CVSS 10 beta.vulnsea.com/cve/CVE-2026-101039 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101039 — A vulnerability was identified in FAST FAC1900R 20190827_2.0.2
A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buffer overflow. The attack can be execu…
000
VulnSea @vulnsea.com · 28/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-101038: FAST FAC1200R MmtAtePrase stack-based overflow CVSS 9.9 beta.vulnsea.com/cve/CVE-2026-101038 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-101038 — FAST FAC1200R MmtAtePrase stack-based overflow
A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based buffer overflow. Remote exploitation…
000
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-88772: Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, b… CVSS 9.5 · exploited beta.vulnsea.com/cve/CVE-2026-88772 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-88772 — Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-…
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-…
010
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-88771: Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-7… CVSS 9.5 · exploited beta.vulnsea.com/cve/CVE-2026-88771 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-88771 — Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 1…
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 1…
000
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-82901: The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the … CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-82901 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-82901 — The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This mak…
100
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-97163: Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 CVSS 10 beta.vulnsea.com/cve/CVE-2026-97163 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-97163 — Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
010
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-97161: Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 CVSS 9.2 beta.vulnsea.com/cve/CVE-2026-97161 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-97161 — Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
010
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-97160: Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 CVSS 9.4 beta.vulnsea.com/cve/CVE-2026-97160 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-97160 — Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
010
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-94132: Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - … CVSS 9.5 beta.vulnsea.com/cve/CVE-2026-94132 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-94132 — Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, s…
Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_acym/upload/ with no extension check, s…
010
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-94130: Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video… CVSS 9.3 beta.vulnsea.com/cve/CVE-2026-94130 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-94130 — Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to inject SQL commands in read queries.
021
VulnSea @vulnsea.com · 27/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-18143: The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including… CVSS 9.8 · EPSS 0.4% beta.vulnsea.com/cve/CVE-2026-18143 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-18143 — The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function
The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME…
000
VulnSea @vulnsea.com · 25/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-97063: X-SpringBoot through 6.0 Authentication Bypass via Login Code CVSS 9.1 beta.vulnsea.com/cve/CVE-2026-97063 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-97063 — X-SpringBoot through 6.0 Authentication Bypass via Login Code
X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobile/code and GET /sys/email/code without sending them to account owners. Attackers can request codes using known mobil…
000
VulnSea @vulnsea.com · 25/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-39353: InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments CVSS 9.1 beta.vulnsea.com/cve/CVE-2026-39353 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-39353 — InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an …
000
VulnSea @vulnsea.com · 25/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-89055: The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including… CVSS 9.1 · EPSS 0.4% beta.vulnsea.com/cve/CVE-2026-89055 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-89055 — The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an actio…
011
VulnSea @vulnsea.com · 24/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-61742: DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite CVSS 9.3 beta.vulnsea.com/cve/CVE-2026-61742 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-61742 — DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite
DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport …
000
VulnSea @vulnsea.com · 24/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-61732: Decepticon is an autonomous hacking agent for red teams CVSS 10 beta.vulnsea.com/cve/CVE-2026-61732 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-61732 — Decepticon is an autonomous hacking agent for red teams
Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals.…
000
VulnSea @vulnsea.com · 24/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-93425: Dokploy is a free, self-hostable Platform as a Service (PaaS) CVSS 9.9 beta.vulnsea.com/cve/CVE-2026-93425 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-93425 — Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in…
010
VulnSea @vulnsea.com · 24/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-97360: HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, wri… CVSS 10 beta.vulnsea.com/cve/CVE-2026-97360 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-97360 — HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …
HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …
000
VulnSea @vulnsea.com · 23/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-96758: orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property name… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-96758 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-96758 — orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema…
000
VulnSea @vulnsea.com · 23/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-96757: orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-96757 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-96757 — orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications t…
000
VulnSea @vulnsea.com · 23/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-95848: Moquette is a lightweight Java MQTT broker CVSS 9.3 beta.vulnsea.com/cve/CVE-2026-95848 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-95848 — Moquette is a lightweight Java MQTT broker
Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no cu…
001
VulnSea @vulnsea.com · 23/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-96257: A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4 CVSS 10 beta.vulnsea.com/cve/CVE-2026-96257 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-96257 — A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4
A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of the component Device Discovery Service. Executing a manipulation can lead to stack-based buffer overflow. The attack…
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-91130: Home Assistant is open source home automation software focused on local control and privacy CVSS 9.3 beta.vulnsea.com/cve/CVE-2026-91130 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-91130 — Home Assistant is open source home automation software focused on local control and privacy
Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and compu…
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-77254: MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials CVSS 9.1 beta.vulnsea.com/cve/CVE-2026-77254 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-77254 — MCP Atlassian: Unauthenticated HTTP MCP requests can use globally configured Jira and Confluence credentials
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use global…
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-86059: Dokploy is a free, self-hostable Platform as a Service (PaaS) CVSS 9.6 beta.vulnsea.com/cve/CVE-2026-86059 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-86059 — Dokploy is a free, self-hostable Platform as a Service (PaaS)
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucke…
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-95675: D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers t… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-95675 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-95675 — D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-78847: An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when … CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-78847 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-78847 — An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.
An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-88404: A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Unive… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-88404 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-88404 — A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.
A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-88402: A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injectin… CVSS 9.8 beta.vulnsea.com/cve/CVE-2026-88402 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-88402 — A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.
A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.
000
VulnSea @vulnsea.com · 22/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-77521: MaxKB is an open-source AI assistant for enterprise CVSS 10 beta.vulnsea.com/cve/CVE-2026-77521 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-77521 — MaxKB is an open-source AI assistant for enterprise
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits exe…
000
VulnSea @vulnsea.com · 21/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-61674: Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows CVSS 9.2 beta.vulnsea.com/cve/CVE-2026-61674 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-61674 — Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows
Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the …
000
VulnSea @vulnsea.com · 21/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-83549: Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul… CVSS 7.8 · EPSS 8.5% · CISA KEV · 0day beta.vulnsea.com/cve/CVE-2026-83549 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-83549 — Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
000
VulnSea @vulnsea.com · 21/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-94101: A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246 CVSS 9.9 beta.vulnsea.com/cve/CVE-2026-94101 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-94101 — A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246
A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…
000
VulnSea @vulnsea.com · 21/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-94096: A vulnerability was found in Netcore NBR200V2 1.3.241127.071246 CVSS 9.9 beta.vulnsea.com/cve/CVE-2026-94096 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-94096 — A vulnerability was found in Netcore NBR200V2 1.3.241127.071246
A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4…
000
VulnSea @vulnsea.com · 20/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-89274: The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1 CVSS 9.1 · EPSS 0.4% beta.vulnsea.com/cve/CVE-2026-89274 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-89274 — The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and including, 10.8.1. The vulnerability exists because `WPRM_Metadata::sanitize_metadata()` recursively calls `do_shortcode()…
010
VulnSea @vulnsea.com · 20/09/2026
🌊 ABYSSAL · critical with a public exploit CVE-2026-92229: The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcod… CVSS 9.1 · EPSS 0.4% beta.vulnsea.com/cve/CVE-2026-92229 #CVE #infosec #cybersecurity #threatintel
beta.vulnsea.com
CVE-2026-92229 — The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2
The The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.57.2. This is due to the software allowing users to e…
010