Critical Flaw in TP-Link VIGI Cameras Lets Local Network Attackers Reset Admin Passwords Without Authentication
CVE-2026-0629 is a high-severity authentication bypass vulnerability affecting multiple VIGI and VIGI InSight IP camera models. The…
continue reading..
CVE-2026-1221: Hard-Coded Credentials Enable Remote Access to PrismX MX100 Infrastructure
CVE-2026-1221 describes a critical security flaw caused by hard-coded credentials embedded in the firmware of the PrismX…
continue reading..
“WhisperPair”: Bluetooth Fast Pair Flaw Enabling Eavesdropping and Tracking
CVE-2025-36911, also known by researchers as WhisperPair, is a serious security vulnerability affecting Bluetooth devices that implement…
continue reading..
Critical XSS Vulnerability Discovered in Movary Allows Attackers to Execute Malicious Scripts via Crafted Links
CVE-2026-23841 is a reflected cross-site scripting (XSS) vulnerability affecting Movary versions prior to 0.70.0.The issue arises from…
continue reading..
MyTube Flaw Allows Anyone to Access Protected Settings Without Authentication
CVE-2026-23837 is a critical authorization bypass vulnerability affecting the MyTube application in versions prior to 1.7.66. The…
continue reading..
Critical Apache bRPC Flaw Exposes Servers to Unauthenticated Remote Command Execution (CVE-2025-60021)
CVE-2025-60021 is a critical remote command injection vulnerability in Apache bRPC, a high-performance RPC framework commonly used…
continue reading..
CVE-2026-23722: Critical Reflected XSS Enables Silent Browser-Side Takeover in WeGIA
Executive Summary CVE-2026-23722 is a critical reflected XSS vulnerability in the WeGIA web application.The issue occurs because…
continue reading..
CVE-2012-10064: Legacy WordPress Plugin Bug Enabling Silent Remote Code Execution
Vulnerability Overview CVE ID: CVE-2012-10064Affected Component: Omni Secure Files WordPress PluginAffected Versions: ≤ 0.1.13Attack Type: Remote, UnauthenticatedImpact:…
continue reading..
Critical Stored XSS Vulnerability (CVE-2026-1181) Discovered in Altium Forum, Exposing Users to Account Takeover and Data Theft
CVE-2026-1181 is a stored (persistent) cross-site scripting vulnerability affecting the Altium Forum platform. The issue exists due…
continue reading..
