24h | 7d | 30d

Overview

  • Tautulli
  • Tautulli

21 Sep 2026
Published
22 Sep 2026
Updated

CVSS v4.0
MEDIUM (4.8)
EPSS
0.60%

KEV

Description

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletter_config.html into a JavaScript string without safe JSON encoding. An administrator or caller with the Tautulli API key can store a crafted cron value, and an administrator who later opens the newsletter configuration modal passively triggers script execution in the Tautulli web context. The stored value persists in the database and can continue to execute after credential rotation until it is removed. This issue is fixed in version 2.17.2.

Statistics

  • 1 Post

Last activity: 20 hours ago

Fediverse

Profile picture fallback

CVE-2026-49995 Tautulli stored XSS via newsletter cron field, CVSS 4.8. Admin opening the config modal triggers script execution. Patch under review, update to 2.17.2 when ready. valtersit.com/cve/CVE-2026-499 #CVE #infosec

  • 0
  • 0
  • 0
  • 20h ago

Overview

  • NetScaler
  • ADC

08 Oct 2026
Published
10 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.47%

KEV

Description

Memory overflow vulnerability leading to Remote Code Execution or Denial of Service Vulnerability in NetScaler ADC. NetScaler ADC or NetScaler Gateway must be configured as a SAML SP or SAML IdP, subject to the following version-specific requirements:   * For the following versions: Applicable only when configured as a SAML IdP: * NetScaler ADC and NetScaler Gateway between 14.1-73.37 and 14.1-73.41, inclusive * NetScaler ADC 14.1-FIPS between 14.1-73.37 FIPS and 14.1-73.41 FIPS, inclusive * NetScaler ADC and NetScaler Gateway between 13.1-64.23 and 13.1-64.28, inclusive * NetScaler ADC 13.1-FIPS between 13.1-NDcPP 13.1-37.279 and 13.1- 37.282, inclusive   For the following versions: Applicable only when configured as a SAML SP or SAML IdP: * NetScaler ADC and NetScaler Gateway before 14.1-73.37  * NetScaler ADC 14.1-FIPS before 14.1-73.37 FIPS  * NetScaler ADC and NetScaler Gateway before 13.1-64.23 * NetScaler ADC 13.1-FIPS before13.1-NDcPP 13.1-37.279

Statistics

  • 1 Post

Last activity: 12 hours ago

Fediverse

Profile picture fallback

🚨 Critical Citrix NetScaler Vulnerability Disclosed

Citrix has disclosed CVE-2026-107406, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway, with a CVSS 4.0 score of 9.5.

The vulnerability could potentially allow remote code execution or denial of service on affected systems.

Exploitation requires specific SAML Service Provider or Identity Provider configurations, depending on the installed version.

#SecPoint #Citrix #NetScaler #CyberSecurity #VulnerabilityManagement

  • 0
  • 0
  • 0
  • 12h ago

Overview

  • TomWright
  • dasel

21 Sep 2026
Published
21 Sep 2026
Updated

CVSS v3.1
MEDIUM (6.2)
EPSS
0.19%

KEV

Description

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the source at the exhausted index without an end-of-input check. A selector ending in whitespace, including input passed through lexer.NewTokenizer(...).Tokenize() or dasel.Query, can therefore cause an index-out-of-range panic and terminate the process. This issue is fixed in version 3.11.2.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

CVE-2026-62866 Dasel 3.0.0-3.11.2 (CVSS 6.2): a selector ending in whitespace passes an unchecked index in parseCurRune, causing an out-of-range panic that kills the process. Denial of service. Patched in 3.11.2, update now. valtersit.com/cve/CVE-2026-628 #CVE #infosec #Dasel

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Email-Sender

21 Sep 2026
Published
22 Sep 2026
Updated

CVSS
Pending
EPSS
0.60%

KEV

Description

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipient go into a single command string, which open() passes to a shell. Every other platform gets the list form, which runs sendmail directly. When the caller supplies no envelope, Email::Sender::Simple takes the recipients from the To and Cc headers and the sender from the From header. An attacker who controls one of those header addresses runs commands as the sending process.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-93012: Email::Sender::Transport::Sendmail before 2.602 lets envelope addresses reach the shell on Windows, enabling command execution. CVSS 9.8. Patch available. Update now. valtersit.com/cve/CVE-2026-930 #CVE #Perl #infosec

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Unknown
  • Insurify

11 Oct 2026
Published
11 Oct 2026
Updated

CVSS
Pending
EPSS
0.15%

KEV

Description

The Insurify WordPress plugin through 1.0 does not have authorisation and nonce checks on one of its AJAX actions, allowing unauthenticated users to delete arbitrary WordPress options, which can take the site offline and strip every user of their role.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-86717 (CRITICAL) targets Insurify WP plugin ≤1.0. Missing auth & nonce checks in AJAX lets unauth users delete WordPress options — site can be taken offline, user roles wiped. Disable or restrict plugin. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • ThemeREX Group
  • Let's Play
  • playhockey

10 Oct 2026
Published
11 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.31%

KEV

Description

Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.

Statistics

  • 1 Post

Last activity: 22 hours ago

Fediverse

Profile picture fallback

CVE-2026-93935: ThemeREX Let's Play playhockey ≤1.1.15 affected by CRITICAL deserialization flaw (CWE-502). Enables remote object injection and full compromise. Patch pending — monitor vendor updates & restrict plugin use. radar.offseq.com/threat/deseri

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Axiomthemes
  • Balance
  • balance

10 Oct 2026
Published
11 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.33%

KEV

Description

Deserialization of Untrusted Data vulnerability in Axiomthemes Balance balance allows Object Injection.This issue affects Balance: from n/a through 1.12.0.

Statistics

  • 1 Post

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-93945: CRITICAL object injection via deserialization in Axiomthemes Balance (<=1.12.0). Full compromise risk — no patch yet. Check vendor guidance & mitigate if possible. radar.offseq.com/threat/deseri

  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Qualcomm, Inc.
  • Snapdragon

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.32%

KEV

Description

Improper authorization leads to Remote Code Execution via SocketIO interface.

Statistics

  • 1 Post

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-25254 Qualcomm improper auth leads to RCE via SocketIO. CVSS 9.8, patch status unknown. Treat as unpatched and restrict exposure now. valtersit.com/cve/CVE-2026-252 #CVE #infosec #Qualcomm

  • 0
  • 0
  • 0
  • 11h ago

Overview

  • Unknown
  • Piotnet Forms

11 Oct 2026
Published
11 Oct 2026
Updated

CVSS
Pending
EPSS
0.17%

KEV

Description

The Piotnet Forms WordPress plugin through 1.0.30 does not authenticate or validate a form-submission file-upload request and permits browser-renderable file types to be stored, allowing unauthenticated attackers to store a file that executes arbitrary JavaScript in the site's origin when it is opened (Stored XSS).

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

Piotnet Forms <=1.0.30 impacted by HIGH severity stored XSS (CVE-2026-96227). Unauthenticated file uploads allow arbitrary JS execution. Restrict uploads & validate files. Await vendor patch. Details: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • Vearch
  • vearch

11 Oct 2026
Published
11 Oct 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
Pending

KEV

Description

Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege levels for resources listed in a role. Authenticated non-root users can upsert and delete documents with read-only access, or call PUT /roles to grant their role WriteRead privileges, escalating toward cluster administrator access.

Statistics

  • 1 Post

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-108746 - Critical PrivEsc in Vearch. Broken authorization lets read-only users gain full cluster admin rights. CVSS 8.8. Audit roles now. #CVE #Vearch #infosec

valtersit.com/cve/CVE-2026-108

  • 0
  • 0
  • 0
  • Last hour
Showing 11 to 20 of 38 CVEs