CVE-2021-47753: Unauthenticated File Upload Leads to Full Server Takeover in phpKF CMS
CVE: CVE-2021-47753Product: phpKF CMS 3.00 Beta y6Severity: CriticalCVSS (v3.1): 9.8 (Critical)Exploitability: Official patch / upgrade:🔗 Download the…
continue reading..
CVE-2026-23490: Malformed ASN.1 RELATIVE-OID Triggers Remote Memory Exhaustion Denial-of-Service in pyasn1
Executive Summary CVE ID: CVE-2026-23490Affected Component: pyasn1 (Python ASN.1 decoding library)Vulnerability Type: Uncontrolled resource consumption (memory exhaustion)Severity:…
continue reading..
CVE-2025-67079: One File Upload, Full Server Takeover — Critical RCE in Omnispace Agora
Vulnerability Summary CVE ID: CVE-2025-67079Product: Omnispace Agora (self-hosted deployments)Affected Versions: All versions prior to 25.10Vulnerability Type: Unrestricted…
continue reading..
CVE-2026-23535: Weblate wlc Enables Arbitrary File Write Through Path Traversal
What this vulnerability actually is wlc is a command-line client used to talk to Weblate servers and…
continue reading..
CVE-2026-23735: Silent Token Leakage via GraphQL Parallel Request Context Mix-Up
CVE: CVE-2026-23735Product: graphql-modules (Node.js GraphQL framework)Affected Versions: All releases between 2.2.1 up to 2.4.0 and 3.0.0 up…
continue reading..
CVE-2026-23742: Skipper Inline Lua Filters Enable Unauthorized File Access and Secret Disclosure
CVE: CVE-2026-23742Alias: Skipper inline Lua filter vulnerabilityCVSS v3.1 Score: 8.8 (High)Severity: HighExploitability: What the Vulnerability Is Skipper…
continue reading..
CVE-2026-20960: Power Apps Authorization Flaw Enables High-Risk Remote Code Execution
CVE: CVE-2026-20960Product Affected: Microsoft Power AppsVulnerability Type: Improper Authorization → leads to Remote Code ExecutionCVSSv3.1 Score: 8.0…
continue reading..
CVE-2026-23745: node-tar Link Path Traversal Flaw Enables Arbitrary File Overwrite via Malicious TAR Archives
CVE: CVE-2026-23745Name: node-tar — Arbitrary File Overwrite & Link Path TraversalCVSS Score: 8.2 (High)Severity: HighExploitability: Moderate —…
continue reading..
High-Risk Supply Chain Exposure: Gradle Dependency Resolution Flaws Put CI/CD Pipelines at Risk
Product Name: Gradle Build ToolVendor / Maintainer: Gradle, Inc.Component Affected: Dependency Resolution & Repository HandlingEnvironment Impacted: CI/CD…
continue reading..
