#VulnAlert
🚨 CVE-2024-52938
📅 Published: 2025-01-13
🏢 Vendor: Imagination Technologies
💾 Product: Graphics DDK
🏗️ Affected Version: <= 24.2 RTM2
🐛 CWE-823
🏆 Base Score: 7.8
⚠️ Base Severity: HIGH
🔗 https://s.mtrbio.com/chlctdvjtk
#VulnAlert #InfoSec #PotatoSecurity
January 14, 2025 at 9:45 PM
🛡️ Stay Protected: BaseFortify.eu offers detailed vulnerability insights and risk assessments to help you monitor and mitigate such threats. Register for free at basefortify.eu/register #CyberSecurity #VulnAlert #AttackSurface
BaseFortify
Welcome to BaseFortify, the Threat Intelligence application that uses Deep Learning to create up-to-date warnings on cyber vulnerabilities & exploits. BaseFortify is free to use, so register now! Chec...
BaseFortify.eu
March 24, 2025 at 12:26 PM
WordPress Contact Form CFDB7 (≤1.3.2) hit by CRITICAL pre-auth SQL injection & PHP object injection. Disable plugin or apply WAF rules until patched. High risk for web admins! https://radar.offseq.com/threat/cve-2025-4665-cwe-89-improper-neutralization-of-sp-5cca9eab #OffSeq #WordPress #VulnAlert
October 29, 2025 at 1:31 AM
🚨 CVE-2024-46919
📅 Published: 2025-01-13
🏢 Vendor: #Samsung
💾 Product: n/a
🏗️ Affected Version: n/a
🏆 Base Score: 5.3
⚠️ Base Severity: MEDIUM
🔗 https://s.mtrbio.com/imvuovoiqa
#VulnAlert #InfoSec #CyberSecurity
January 14, 2025 at 7:45 PM
🚨 CVE-2024-12083
📅 Published: 2025-01-14
🏢 Vendor: OMRON Corporation
💾 Product: Machine Automation Controller NJ-series
🏗️Affected Version:NJ101-[][][][] Ver.1.64.05 and lower
🐛 CWE-22
🏆 Base Score: 6.6
⚠️ Base Severity: MEDIUM
#VulnAlert #InfoSec #CyberSecurity
January 14, 2025 at 11:15 AM
🚨 CVE-2024-13348
📅 Published: 2025-01-14
🏢 Vendor: smartagenda
💾 Product: Smart Agenda – Prise de rendez-vous en ligne
🏗️ Affected Version: *
🐛 CWE-352
🏆 Base Score: 6.1
⚠️ Base Severity: MEDIUM
#VulnAlert #InfoSec #CyberSecurity
January 14, 2025 at 10:35 AM
HIGH severity in WebDyne::Session ≤2.075: Predictable session IDs may allow unauthorized access. No patch yet — use secure session management or restrict access. https://radar.offseq.com/threat/cve-2026-5084-cwe-340-generation-of-predictable-nu-706ca625 #OffSeq #VulnAlert #SessionSecurity
CVE-2026-5084: CWE-340 Generation of Predictable Numbers or Identifiers in ASPEE
WebDyne::Session versions up to 2.075 generate session identifiers by hashing an MD5 digest seeded with the Perl built-in rand() function. The rand() function is seeded with a 32-bit value based on process ID, epoch time, and object referen
radar.offseq.com
May 11, 2026 at 9:00 AM
npitre cramfs-tools v2.0/2.1 have a MEDIUM path traversal flaw — local users can access restricted files. Patch with v2.2 now! 🔒 https://radar.offseq.com/threat/cve-2026-8274-path-traversal-in-npitre-cramfs-tool-1c0c3b74 #OffSeq #Linux #VulnAlert
CVE-2026-8274: Path Traversal in npitre cramfs-tools
The vulnerability in npitre cramfs-tools (up to version 2.1) resides in the do_directory function of the cramfsck.c file, part of the Directory Handler component. It allows local attackers with low privileges to perform path traversal attac
radar.offseq.com
May 11, 2026 at 6:00 AM
EFM ipTIME A8004T (v14.18.2) hit by HIGH severity stack buffer overflow. No patch out — disable remote mgmt & limit device exposure now. Stay tuned for updates. https://radar.offseq.com/threat/cve-2026-8234-stack-based-buffer-overflow-in-efm-i-fc36030f #OffSeq #RouterSecurity #VulnAlert
CVE-2026-8234: Stack-based Buffer Overflow in EFM ipTIME A8004T
The EFM ipTIME A8004T router firmware version 14.18.2 contains a stack-based buffer overflow vulnerability in the formWifiBasicSet function located in /goform/WifiBasicSet. This vulnerability arises from improper handling of the security_5g
radar.offseq.com
May 10, 2026 at 7:30 AM
🚨 CVE-2026-22562: CRITICAL path traversal in Ubiquiti UniFi Play PowerAmp & Audio Port. Enables unauth RCE. Patch PowerAmp to 1.0.38+ & Audio Port to 1.1.9+ now! https://radar.offseq.com/threat/cve-2026-22562-cwe-22-path-traversal-in-ubiquiti-i-464fb9b6 #OffSeq #Ubiquiti #VulnAlert
CVE-2026-22562: CWE-22 Path Traversal in Ubiquiti Inc UniFi Play PowerAmp
This vulnerability (CVE-2026-22562) involves a path traversal flaw (CWE-22) in the firmware of Ubiquiti UniFi Play PowerAmp and UniFi Play Audio Port devices. Exploitation requires network access to the UniFi Play network and allows an atta
radar.offseq.com
April 14, 2026 at 10:30 AM
CRITICAL: PraisonAI <4.5.139 OS command injection via YAML files lets attackers run arbitrary code. Upgrade to 4.5.139+ now to prevent system takeover. https://radar.offseq.com/threat/cve-2026-40288-cwe-78-improper-neutralization-of-s-06bb92e7 #OffSeq #PraisonAI #VulnAlert
CVE-2026-40288: CWE-78: Improper Neutralization of Special Elements used in an O
The vulnerability in PraisonAI affects the workflow engine's handling of YAML files with type: job. Specifically, the JobWorkflowExecutor processes steps that execute shell commands (via subprocess.run()), inline Python code (via exec()), a
radar.offseq.com
April 14, 2026 at 7:30 AM
Belkin F9K1015 (v1.00.10) faces HIGH-severity buffer overflow (CVE-2026-5629) — remote exploit possible, public code available, no patch yet. Restrict access & monitor updates. https://radar.offseq.com/threat/cve-2026-5629-stack-based-buffer-overflow-in-belki-abbd3417 #OffSeq #Belkin #VulnAlert
CVE-2026-5629: Stack-based Buffer Overflow in Belkin F9K1015
This vulnerability affects the Belkin F9K1015 router firmware version 1.00.10. The issue is a stack-based buffer overflow in the formSetFirewall function located in the /goform/formSetFirewall endpoint. By manipulating the 'webpage' argumen
radar.offseq.com
April 6, 2026 at 7:30 AM
CRITICAL: gematik app-Authenticator <4.16.0 vulnerable to auth hijack via deep links. No workarounds — update to 4.16.0+ now to secure health data! https://radar.offseq.com/threat/cve-2026-33875-cwe-940-improper-verification-of-so-189b5f61 #OffSeq #CVE202633875 #VulnAlert
CVE-2026-33875: CWE-940: Improper Verification of Source of a Communication Chan
CVE-2026-33875 is a critical security vulnerability identified in the gematik app-Authenticator, a tool used to securely authenticate users for access to digital health applications. The vulnerability arises from improper verification of th
radar.offseq.com
March 28, 2026 at 12:00 AM
🚨 VMware Spring AI 1.0.x & 1.1.x face HIGH risk (CVE-2026-22729): JSONPath injection lets users bypass access controls for sensitive docs. Upgrade or sanitize filter inputs now. https://radar.offseq.com/threat/cve-2026-22729-vulnerability-in-vmware-spring-ai-96356f4f #OffSeq #SpringAI #VulnAlert
CVE-2026-22729: Vulnerability in VMware Spring AI
CVE-2026-22729 is a JSONPath injection vulnerability found in VMware Spring AI's AbstractFilterExpressionConverter component, specifically affecting versions 1.0.x and 1.1.x. The vulnerability arises because user-supplied input used in filt
radar.offseq.com
March 18, 2026 at 9:00 AM
Craft CMS faces a CRITICAL flaw: CVE-2026-32267 lets remote attackers escalate to admin via shared URLs. Upgrade to 4.17.6/5.9.12 now! 🔒 https://radar.offseq.com/threat/cve-2026-32267-cwe-863-incorrect-authorization-in--65bf3522 #OffSeq #CraftCMS #VulnAlert
CVE-2026-32267: CWE-863: Incorrect Authorization in craftcms cms
Craft CMS, a widely used content management system, suffers from a critical authorization vulnerability identified as CVE-2026-32267. This vulnerability exists in versions 4.0.0-RC1 through 4.17.5 and 5.0.0-RC1 through 5.9.11. The root caus
radar.offseq.com
March 17, 2026 at 1:30 AM
🛑 DLL hijacking in TR-VISION HOME (≤2.0.5) - HIGH severity. Local attackers can escalate privileges. Restrict directory access & monitor for suspicious DLLs. https://radar.offseq.com/threat/cve-2026-4255-cwe-829-inclusion-of-functionality-f-64ab002d #OffSeq #VulnAlert #Windows
CVE-2026-4255: CWE-829 Inclusion of functionality from untrusted control sphere
A DLL search order hijacking vulnerability in Thermalright TR-VISION HOME on Windows (64-bit) allows a local attacker to escalate privileges via DLL side-loading. The application loads certain dynamic-link library (DLL) dependencies using t
radar.offseq.com
March 16, 2026 at 7:30 AM
LiteSpeed OpenLiteSpeed & LSWS Enterprise hit by HIGH-severity OS command injection flaw (admin access needed). Act now: review admin access, monitor logs, prep for patch. https://radar.offseq.com/threat/cve-2026-31386-improper-neutralization-of-special--9aa4ef0e #OffSeq #LiteSpeed #VulnAlert
CVE-2026-31386: Improper neutralization of special elements used in an OS comman
CVE-2026-31386 is an OS command injection vulnerability identified in all versions of LiteSpeed Technologies' OpenLiteSpeed and LSWS Enterprise web servers. The vulnerability arises from improper neutralization of special elements used in O
radar.offseq.com
March 16, 2026 at 6:00 AM
Tenda F453 (v1.0.0.3) hit by HIGH severity buffer overflow — remote code execution possible, no auth needed. Restrict access & monitor /goform/SetIpBind traffic. Patch when available! https://radar.offseq.com/threat/cve-2026-3379-buffer-overflow-in-tenda-f453-63a79945 #OffSeq #VulnAlert #NetworkS...
CVE-2026-3379: Buffer Overflow in Tenda F453
CVE-2026-3379 identifies a critical buffer overflow vulnerability in the Tenda F453 router firmware version 1.0.0.3. The vulnerability is located in the fromSetIpBind function, specifically in the handling of the 'page' argument within the
radar.offseq.com
March 1, 2026 at 3:00 AM
Hyland OnBase 8.0 hit by CRITICAL vuln: unauth .NET Remoting on TCP/8900 enables RCE & file writes. Restrict port, monitor, patch ASAP. 🛡️ https://radar.offseq.com/threat/cve-2026-26221-cwe-502-deserialization-of-untruste-9949df79 #OffSeq #Hyland #VulnAlert
CVE-2026-26221: CWE-502 Deserialization of Untrusted Data in Hyland OnBase Workf
CVE-2026-26221 is a critical security vulnerability affecting Hyland OnBase Workflow Timer Service version 8.0. The flaw arises from an unauthenticated .NET Remoting exposure in the OnBase Workflow Timer Service (Hyland.Core.Workflow.NTServ
radar.offseq.com
February 14, 2026 at 6:00 AM
CRITICAL: Code injection in goauthentik authentik (CVE-2026-25227). Users with certain permissions can execute code. Upgrade to patched versions now! https://radar.offseq.com/threat/cve-2026-25227-cwe-94-improper-control-of-generati-cc39f642 #OffSeq #authentik #VulnAlert
CVE-2026-25227: CWE-94: Improper Control of Generation of Code ('Code Injection'
CVE-2026-25227 is a critical vulnerability classified under CWE-94 (Improper Control of Generation of Code, or Code Injection) found in the open-source identity provider authentik. The flaw exists in the handling of delegated permissions re
radar.offseq.com
February 13, 2026 at 6:00 AM
🚨 Umbraco CMS 16.3.3 hit by CRITICAL vuln (CVE-2025-67288): attackers can upload crafted PDFs to run code. No patch—apply strict file upload controls & monitor closely! https://radar.offseq.com/threat/cve-2025-67288-na-ea93a173 #OffSeq #Umbraco #VulnAlert
December 23, 2025 at 4:04 AM
CRITICAL: CVE-2025-14700 in Crafty Controller 4.6.1 lets authenticated users run code via SSTI. Limit access, monitor closely, and prep for patches. Details: https://radar.offseq.com/threat/cve-2025-14700-cwe-1336-improper-neutralization-of-bf9964e9 #OffSeq #VulnAlert #SSTI
December 17, 2025 at 1:34 AM
🚨 Critical RFI in Stockholm WP theme (≤9.14.1) allows remote code execution. Patch or disable immediately; harden PHP configs. No public exploits yet, but risk is high. https://radar.offseq.com/threat/cve-2025-68068-improper-control-of-filename-for-in-75f2f7ba #OffSeq #WordPress #VulnAlert
December 16, 2025 at 9:04 AM
🚩 HIGH severity: wpchill Image Gallery (v2.13.1) path traversal lets Author+ users delete critical files—remote code execution possible. Audit & restrict access. Details: https://radar.offseq.com/threat/cve-2025-13645-cwe-22-improper-limitation-of-a-pat-1c73e0b1 #OffSeq #WordPress #VulnAlert
December 3, 2025 at 6:34 AM