#CVE20
IBM Concert (v1.0.0 – 3.0.0) is affected by a CRITICAL use-after-free vulnerability (CVSS 9.8). Remote exploitation possible — patch status unconfirmed. Monitor IBM advisories: https://radar.offseq.com/threat/cve-2026-6928-cwe-416-use-after-free-in-ibm-concert-2eb5c8a4bd6982d7 #OffSeq #IBM #CVE20...
CVE-2026-6928: CWE-416 Use After Free in IBM Concert
IBM Concert versions 1.0.0 through 3.0.0 contain a use-after-free vulnerability (CWE-416) where the software references or accesses memory after it has been freed. This memory corruption issue can be exploited by an attacker able to influen
radar.offseq.com
September 24, 2026 at 1:30 AM
CRITICAL: tobychui zoraxy 3.2.3 – 3.3.4 has auth bypass (CVE-2026-100390) via IPv6 X-Forwarded-For spoofing. Restrict IPv6 or avoid IP-based controls until patched. https://radar.offseq.com/threat/cve-2026-100390-authentication-bypass-by-spoofing-in-tobychui-zoraxy-92a9e1620a0f6d01 #OffSeq #CVE20...
CVE-2026-100390: Authentication Bypass by Spoofing in tobychui zoraxy
The vulnerability in tobychui's Zoraxy product affects versions 3.2.3 through 3.3.4. The software fails to correctly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers, specifically the X-Forwarded-For header. This
radar.offseq.com
September 26, 2026 at 1:30 AM
Altium Enterprise Server faces CRITICAL path traversal (CVSS 10). Unauth'd attackers can write/read files, risking RCE. Restrict NIS access & watch for patches. Cloud not affected. https://radar.offseq.com/threat/cve-2026-11420-cwe-22-improper-limitation-of-a-pat-24b2eaa0 #OffSeq #security #CVE20...
CVE-2026-11420: CWE-22 Improper Limitation of a Pathname to a Restricted Directo
This vulnerability involves two path traversal flaws in the Network Installation Service component of Altium Enterprise Server. An unauthenticated network attacker can exploit these flaws to write arbitrary files to any writable location on
radar.offseq.com
June 6, 2026 at 3:00 AM
langgenius Dify ≤1.14.1 hit by CRITICAL auth bypass (CVE-2026-41947): editors can redirect app data to attacker endpoints. Free signup = higher risk. Limit editor roles, monitor configs now. https://radar.offseq.com/threat/cve-2026-41947-authorization-bypass-through-user-c-da35e5dc #OffSeq #CVE20...
CVE-2026-41947: Authorization Bypass Through User-Controlled Key in langgenius d
CVE-2026-41947 is an authorization bypass vulnerability in langgenius's Dify product (version 1.14.1 and prior). Authenticated users with editor privileges can exploit missing tenant ownership checks in trace configuration endpoints to set
radar.offseq.com
May 19, 2026 at 6:00 AM
CRITICAL: CleanTalk Spam Protection plugin for WordPress allows unauthenticated plugin installs if API key is invalid (CVSS 9.8). Audit your sites & restrict plugin installs ASAP. https://radar.offseq.com/threat/cve-2026-1490-cwe-350-reliance-on-reverse-dns-reso-0fc3066a #OffSeq #WordPress #CVE20...
CVE-2026-1490: CWE-350 Reliance on Reverse DNS Resolution for a Security-Critica
The vulnerability identified as CVE-2026-1490 affects the CleanTalk Spam protection, Honeypot, Anti-Spam plugin for WordPress, a widely used security plugin designed to prevent spam and malicious activity. The root cause is a reliance on re
radar.offseq.com
February 15, 2026 at 4:00 AM
Critical RCE in zyddnys manga-image-translator (beta-0.3 & earlier). Unsafe deserialization lets attackers run code via public APIs — no auth needed. Disable endpoints & monitor for threats. https://radar.offseq.com/threat/cve-2026-26215-cwe-502-deserialization-of-untruste-e3572f04 #OffSeq #CVE20...
CVE-2026-26215: CWE-502 Deserialization of Untrusted Data in zyddnys manga-image
CVE-2026-26215 is a critical vulnerability in the manga-image-translator software, specifically versions beta-0.3 and earlier, which operate in shared API mode. The core issue is unsafe deserialization of untrusted data via Python's pickle.
radar.offseq.com
February 12, 2026 at 6:00 AM
CRITICAL: dripadmin CRM Memberships plugin allows unauthenticated password resets & email leaks via insecure AJAX endpoints. Block access, monitor resets, and patch ASAP. Details: https://radar.offseq.com/threat/cve-2025-13313-cwe-862-missing-authorization-in-dr-61158105 #OffSeq #WordPress #CVE20...
December 5, 2025 at 5:35 AM