advisories
20 articles
[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection
Linksys E1200_2.0.
[webapps] Langflow 1.8.4 - Path Traversal to Remote Code Execution
Langflow 1.8.
[webapps] CubeCart 6.7.4 - SQL injection
CubeCart 6.7.
[webapps] CubeCart 6.7.4 - SQL
CubeCart 6.7.
[webapps] CubeCart 6.7.4 - Stored XSS
CubeCart 6.7.
[webapps] CubeCart 6.7.4 - Cross-Site Scripting
CubeCart 6.7.
[webapps] C-MOR 6.0104 - Directory Traversal
C-MOR 6.
[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)
C-MOR 6.
YARA-X 1.20.0 Release, (Sun, Aug 30th)
YARA-X&#;x26;#;39;s 1.20.
Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of month...
ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)
Mitsubishi Electric Multiple FA Products (Update D)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, ...
Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to i...
All-Line Equipment Company Fuel-Boss
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. ...
Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force a...
Xiiaozet LK100W
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaoze...
Mitsubishi Electric CNC Series (Update A)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-servic...
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-49105 ownCl...
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us...