Skip to content

  • Home
  • Tools
    • IOC Defang/Refang Tool
    • Universal Encoder Decoder
    • File Hash Calculator
    • Password Crack Time Simulator
    • Multi-URL IOC Checker
  • CyberSecurity News
  • Latest Cyber Attack
  • Vulnerabilities
  • Threat Advisories
  • MITRE ATT&CK
    • Collection
    • Command and Control
    • Credential Access
    • Defense Evasion
    • Discovery
    • Execution
    • Exfiltration
    • Impact
    • Initial Access
    • Lateral Movement
    • Persistence
    • Privilege Escalation
    • Reconnaissance
    • Resource Development
  • Ransomware
  • Malware
  • Cyber Kill Chain

  • Home
  • Tools
    • IOC Defang/Refang Tool
    • Universal Encoder Decoder
    • File Hash Calculator
    • Password Crack Time Simulator
    • Multi-URL IOC Checker
  • CyberSecurity News
  • Latest Cyber Attack
  • Vulnerabilities
  • Threat Advisories
  • MITRE ATT&CK
    • Collection
    • Command and Control
    • Credential Access
    • Defense Evasion
    • Discovery
    • Execution
    • Exfiltration
    • Impact
    • Initial Access
    • Lateral Movement
    • Persistence
    • Privilege Escalation
    • Reconnaissance
    • Resource Development
  • Ransomware
  • Malware
  • Cyber Kill Chain

CVE-2025-69285: Unauthenticated File Upload in SQLBot Allows Silent Database Overwrite

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20269 mins0
Unauthenticated File Upload Leading to Database Overwrite Vulnerability Overview CVE ID: CVE-2025-69285Affected Product: SQLBotVulnerability Type: Missing Authentication…
continue reading..

CVE-2026-22849: Saleor Stored XSS Flaw Enabling Silent Token Theft and Admin Session Takeover

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20269 mins0
CVE ID: CVE-2026-22849Product: Saleor (e-commerce platform)Vulnerability Type: Stored Cross-Site Scripting (XSS)Impact Focus: Authentication token theft, session hijackingCVSS…
continue reading..

CVE-2026-22807: Pre-Authentication Remote Code Execution via Unsafe Model Loading in vLLM

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 202611 mins0
CVE ID: CVE-2026-22807Affected Component: vLLM (model loading / auto_map resolution)Vulnerability Type: Unsafe model loading leading to Remote…
continue reading..

Critical Seroval Vulnerabilities Expose Servers to Remote Takeover and Denial-of-Service Attacks

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20268 mins0
Product Security Overview Product Name: SerovalProduct Type: Server-side JavaScript–based application framework / service runtimeDeployment Models Affected: On-premise,…
continue reading..

CVE-2026-23960: Stored XSS in Argo Workflows Enables Browser-Based Privilege Abuse

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20269 mins0
Vulnerability Overview CVE ID: CVE-2026-23960Product: Argo WorkflowsVulnerability Type: Stored Cross-Site Scripting (Stored XSS)Impact Category: Privilege Abuse /…
continue reading..

Critical CVAT Vulnerabilities Enable Full Admin Takeover and Silent Session Hijacking

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20269 mins0
Product overview Product: CVAT (Computer Vision Annotation Tool)Category: Web-based data annotation platform for images and videosTypical usage:…
continue reading..

CVE-2026-22822: Critical External Secrets Operator Flaw Enabling Cross-Namespace Secret Theft

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20269 mins0
CVE-2026-22822 — External Secrets Operator Cross-Namespace Secret Disclosure CVE: CVE-2026-22822Affected Product: External Secrets Operator (ESO)Severity: CriticalCVSS Score:…
continue reading..

CVE-2025-56005: Critical Remote Code Execution via Unsafe Pickle Deserialization in PLY

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 202611 mins0
CVE: CVE-2025-56005Name: Unsafe picklefile deserialization in PLY yacc()CVSS Score: 9.8 (Critical)Severity: CriticalExploitability: Remote code execution via untrusted…
continue reading..

CRYPTOGRAPHIC TRUST FAILURE: Critical SM2 Vulnerabilities Enable Key Theft, Signature Forgery, and Authentication Bypass

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 20268 mins0
sm-crypto – SM2 Cryptographic Implementation Failures Product & Component Details (At a Glance) Field Value Product sm-crypto…
continue reading..

CVE-2026-23518: Critical JWT Authentication Bypass Enables Rogue Windows Device Enrollment in Fleet

  • Vulnerabilities
AegironJanuary 22, 2026January 22, 202613 mins0
CVE-2026-23518 Overview CVE Identifier: CVE-2026-23518Severity: CriticalCVSS v4 Base Score: 9.3 – very high severityPrimary Affected Component: Fleet…
continue reading..
  • 1
  • …
  • 120
  • 121
  • 122
  • 123
  • 124
  • …
  • 215

Recent Posts

  • New SHEET#CREEP Variant Abuses Google Sheets to Evade Detection and Ma…
    Jun 12, 2026
  • Critical LangGraph Vulnerabilities Allow Attackers to Chain SQL Inject…
    Jun 12, 2026
  • Researchers Discover Advanced WooCommerce Payment Skimmer Using Fake S…
    Jun 12, 2026
  • The Dark Side of AI Hype: Cybercriminals Use Fake AI Guides to Deploy …
    Jun 12, 2026
  • OceanLotus Expands Domestic Surveillance Operations Through Supply-Cha…
    Jun 12, 2026
  • Researchers Uncover Expanding FIFA World Cup 2026 Scam Ecosystem Targe…
    Jun 12, 2026
  • Cybercriminals Target Developers Through Fake Repositories in New UNK_…
    Jun 11, 2026
  • Microsoft’s Largest-Ever Patch Tuesday Closes 206 Security Flaws…
    Jun 11, 2026
  • Cybersecurity Researchers Trace Advanced Espionage Activity to Emergin…
    Jun 11, 2026
  • Researchers Uncover Argamal RAT Hidden Inside Trojanized Hentai Games …
    Jun 11, 2026

Popular Posts

  • Storm-2949 Unleashed: How Hackers Exploited Microsoft 365 and Azure to…
    May 19, 2026
  • China-Aligned ‘Webworm’ APT Group Shifts Focus to Europe, Deploying St…
    May 21, 2026
  • Malaysian Government Networks Targeted Through Stealth Azure-Based C2 …
    May 19, 2026
  • Security researchers warn of a highly sophisticated shift toward autom…
    May 25, 2026
  • Cybersecurity Researchers Uncover Expanding Badiis Malware-as-a-Servic…
    May 20, 2026
  • CYBER CONFLICT ESCALATION: State-Sponsored ‘Nimbus Manticore&#82…
    May 25, 2026
  • TAX#TRIDENT: Sophisticated Cyber Campaign Weaponizes Indian Tax Lures …
    May 20, 2026
  • Telecom Under Siege: Infamous Hacking Group Resurges with Stealthy &#8…
    May 25, 2026
  • Banana RAT: Researchers Recover Both Attacker Infrastructure and Victi…
    May 20, 2026
  • New ‘GhostTree’ Technique Uses Infinite Windows Folder Loo…
    May 20, 2026

Find Me On

© 2026 CyberP1. All Rights Reserved.
  • Contact
  • Privacy Policy
  • Terms of Service