OpenAirInterface Version 2
Description
OpenAirInterface Version 2
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 21637 vulnerabilities with AI analyst insights
OpenAirInterface Version 2
OpenAirInterface Version 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local pr...
Successful exploitation of the race condition vulnerability could allow an attacker to trigger a kernel heap overflow, potentially leading to local privilege escalation and granting system-level access to the affected software
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and...
The Vagaro Booking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘vagaro_code’ parameter in all versions up to, and including, 0
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
IDExpert Windows Logon Agent is vulnerable to unauthenticated remote code execution via unauthorized remote DLL downloads and execution.
IDExpert Windows Logon Agent is vulnerable to unauthenticated remote code execution via unauthorized remote DLL downloads and execution.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
A remote code execution vulnerability in IDExpert Windows Logon Agent allows unauthenticated attackers to force arbitrary file downloads and execution...
A remote code execution vulnerability in IDExpert Windows Logon Agent allows unauthenticated attackers to force arbitrary file downloads and execution from remote sources.
---METADATA---
VENDOR: Changing
PRODUCT: IDExpert Windows Logon Agent
AFFECTED_VERSIONS: See vendor advisory
---END_METADATA---
Description Summary:
A remote code execution vulnerability in IDExpert Windows Logon Agent allows unauthenticated attackers to force arbitrary file downloads and execution from remote sources.
Executive Summary:
Unauthenticated remote attackers can achieve full system compromise on hosts running IDExpert Windows Logon Agent by forcing the execution of malicious remote files.
Vulnerability Details
CVE-ID: CVE-2026-2999
Affected Software: Changing IDExpert Windows Logon Agent
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This is a Remote Code Execution (RCE) vulnerability. It allows an unauthenticated remote attacker to manipulate the agent into downloading arbitrary executable files from an attacker-controlled remote source and executing them with system-level privileges.
Business Impact
A successful exploit grants an attacker the ability to execute arbitrary code, leading to complete takeover of the affected Windows workstation or server. This presents a severe risk of data exfiltration, ransomware deployment, and lateral movement within the corporate network. The CVSS score of 9.8 reflects the critical nature of this flaw due to the lack of required authentication and high impact on system integrity.
Remediation Plan
Immediate Action: Update the IDExpert Windows Logon Agent to the latest available version provided by Changing immediately to close the execution vector.
Proactive Monitoring: Monitor network traffic for unauthorized outbound connections to unknown external IP addresses from logon agents and review Windows event logs for unexpected process creations.
Compensating Controls: Restrict outbound internet access for internal agents to only known-good update servers and utilize Endpoint Detection and Response (EDR) tools to block unauthorized file executions.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 2, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw and the critical 9.8 CVSS score, the potential for rapid exploitation by threat actors is extremely high.
Analyst Recommendation
This vulnerability is categorized as Critical and requires immediate attention from security teams. Organizations using Changing's IDExpert solution must prioritize the deployment of the vendor's patch to prevent unauthenticated remote code execution.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same di...
ERP developed by eAI Technologies has a DLL Hijacking vulnerability, allowing authenticated local attackers to place a crafted DLL file in the same directory as the program, thereby executing arbitrary code
---METADATA---
VENDOR: eAI Technologies
PRODUCT: ERP
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A DLL Hijacking vulnerability in eAI Technologies ERP allows authenticated local attackers to execute arbitrary code by placing a malicious DLL in the application directory.
Executive Summary:
Authenticated local attackers can achieve arbitrary code execution on systems running eAI Technologies ERP by exploiting a DLL hijacking flaw.
Vulnerability Details
CVE-ID: CVE-2026-2998
Affected Software: eAI Technologies ERP
Affected Versions: See vendor advisory for affected versions
Vulnerability: The application fails to securely validate or specify the full path of required DLL files. This allows an authenticated local attacker to place a malicious DLL in the program's directory, which the application then loads and executes with the program's privileges.
Business Impact
Successful exploitation allows an attacker to escalate privileges or maintain persistence on a local workstation or server. This could lead to the theft of corporate data or further lateral movement within the corporate network. The CVSS score of 7.8 indicates a High severity, primarily limited by the requirement for local access and authentication.
Remediation Plan
Immediate Action: Apply the official security updates from eAI Technologies immediately to ensure the application uses secure library loading mechanisms.
Proactive Monitoring: Monitor for the creation of unexpected DLL files in application directories and review system logs for unauthorized administrative-level process executions.
Compensating Controls: Implement strict folder permissions to prevent non-administrative users from writing files to the ERP application directory.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 23, 2026, there is no public information indicating active exploitation of this vulnerability. However, DLL hijacking is a well-understood attack vector that is frequently used in multi-stage compromises.
Analyst Recommendation
While this vulnerability requires local access, the potential for arbitrary code execution makes it a significant risk for environments where multiple users share systems. IT administrators should verify directory permissions and deploy the vendor's patch as soon as possible to mitigate the risk of privilege escalation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
lwjson 1
lwjson 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An issue was discovered in kosma minmea 0
An issue was discovered in kosma minmea 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
nanoMODBUS through v1
nanoMODBUS through v1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HSC MailInspector 5
HSC MailInspector 5
---METADATA---
VENDOR: HSC
PRODUCT: MailInspector
AFFECTED_VERSIONS: See vendor advisory
CONFIDENCE: low
MISSING: versions, patch, technical_details
---END_METADATA---
Description Summary:
A Local File Inclusion (LFI) and path traversal vulnerability in HSC MailInspector 5 allows unauthorized access to files on the host system.
Executive Summary:
A critical LFI and path traversal vulnerability in HSC MailInspector 5 allows unauthenticated attackers to read arbitrary files from the server.
Vulnerability Details
CVE-ID: CVE-2026-29963
Affected Software: HSC MailInspector 5
Affected Versions: See vendor advisory
Vulnerability: The vulnerability involves Local File Inclusion (LFI) and path traversal, allowing an unauthenticated attacker (AV:N/AC:L/PR:N) to bypass directory restrictions and access sensitive files on the underlying file system.
Business Impact
An LFI vulnerability allows attackers to read configuration files, application source code, or sensitive system files, potentially leading to full system compromise. With a CVSS score of 7.5, this vulnerability represents a significant risk to the integrity and confidentiality of the host server.
Remediation Plan
Immediate Action: Contact the vendor (HSC) immediately for security updates and verify if your specific version is vulnerable.
Proactive Monitoring: Monitor file system access logs for suspicious traversal patterns (e.g., ../../) and unauthorized attempts to access system-level files.
Compensating Controls: Utilize a Web Application Firewall (WAF) with rules configured to detect and block path traversal and LFI payloads.
Exploitation Status
Public Exploit Available: Yes — a public proof-of-concept is available via the researcher's GitHub repository.
Analyst Notes: As of May 20, 2026, there is no confirmed active exploitation in the wild; however, a public proof-of-concept exists, so exploitation risk should be treated as credible. The availability of a public PoC significantly increases the likelihood of opportunistic exploitation.
Analyst Recommendation
This vulnerability is highly dangerous due to the existence of public exploit code. Administrators must treat this as an urgent issue and immediately implement WAF protections while awaiting a formal patch from the vendor.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
HSC MailInspector v5
HSC MailInspector v5
---METADATA---
VENDOR: HSC
PRODUCT: MailInspector
AFFECTED_VERSIONS: See vendor advisory
CONFIDENCE: medium
MISSING: versions, patch, technical_details
---END_METADATA---
Description Summary:
HSC MailInspector v5 is affected by a Local File Inclusion (LFI) and path traversal vulnerability, potentially allowing unauthorized access to sensitive files.
Executive Summary:
A critical Local File Inclusion and path traversal vulnerability in HSC MailInspector v5 may allow unauthenticated attackers to read arbitrary files from the underlying system.
Vulnerability Details
CVE-ID: CVE-2026-29962
Affected Software: HSC MailInspector
Affected Versions: See vendor advisory
Vulnerability: The application is susceptible to Local File Inclusion (LFI) and path traversal due to improper input validation, allowing an unauthenticated remote attacker to access sensitive local files.
Business Impact
Successful exploitation allows an attacker to bypass directory restrictions and read sensitive configuration files or system data. Given the CVSS score of 7.5, this vulnerability represents a high risk to data confidentiality and could facilitate further system compromise or credential theft.
Remediation Plan
Immediate Action: Review the vendor's security disclosures and apply available patches or configuration changes provided by HSC.
Proactive Monitoring: Monitor server access logs for anomalous directory traversal patterns, such as sequences like "../" or access requests to sensitive system files (e.g., /etc/passwd).
Compensating Controls: Implement a Web Application Firewall (WAF) to detect and block malicious requests containing path traversal sequences directed at the application.
Exploitation Status
Public Exploit Available: Yes — a public proof-of-concept is available via the researcher's disclosure repository on GitHub.
Analyst Notes: As of May 20, 2026, there is no confirmed active exploitation in the wild; however, a public proof-of-concept exists, and the inherent exploitability is high due to the lack of required authentication.
Analyst Recommendation
This vulnerability poses a significant risk due to its unauthenticated nature and the availability of public exploit material. Administrators should prioritize identifying instances of MailInspector v5 and applying vendor-recommended mitigations immediately to prevent unauthorized data exfiltration.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In KubePlus 4
In KubePlus 4
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SQL Injection vulnerability in SchemaHero 0
SQL Injection vulnerability in SchemaHero 0
Apply vendor patches immediately. Review database access controls and enable query logging.
GitLab has remediated an issue in GitLab EE affecting all versions from 15
GitLab has remediated an issue in GitLab EE affecting all versions from 15
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Invoice Ninja v5
Invoice Ninja v5
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Grav CMS v1
Grav CMS v1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the...
The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
The KiviCare EHR plugin for WordPress suffers from an authentication bypass in its social login function, allowing unauthenticated attackers to log in...
The KiviCare EHR plugin for WordPress suffers from an authentication bypass in its social login function, allowing unauthenticated attackers to log in as any patient or capture administrator cookies.
---METADATA---
VENDOR: KiviCare
PRODUCT: Clinic & Patient Management System (EHR) plugin for WordPress
AFFECTED_VERSIONS: All versions up to, and including, 4.1.2
---END_METADATA---
Description Summary:
The KiviCare EHR plugin for WordPress suffers from an authentication bypass in its social login function, allowing unauthenticated attackers to log in as any patient or capture administrator cookies.
Executive Summary:
A critical authentication bypass in the KiviCare WordPress plugin allows unauthenticated attackers to gain full access to sensitive medical records and potentially hijack administrator sessions.
Vulnerability Details
CVE-ID: CVE-2026-2991
Affected Software: KiviCare Clinic & Patient Management System (EHR) plugin for WordPress
Affected Versions: All versions up to, and including, 4.1.2
Vulnerability: The patientSocialLogin() function fails to verify social provider access tokens. Attackers can bypass credential checks by providing a target email and an arbitrary token value. Crucially, authentication cookies are set in the response headers before role checks, potentially exposing administrator cookies even if a 403 error is returned.
Business Impact
This vulnerability represents a catastrophic risk to patient privacy and regulatory compliance (e.g., HIPAA). With a CVSS score of 9.8, attackers can access Protected Health Information (PHI), prescriptions, and billing data. Furthermore, the potential for administrator session hijacking could lead to a total site takeover, causing massive reputational and legal damage.
Remediation Plan
Immediate Action: Update the KiviCare plugin to the latest patched version immediately. If a patch is unavailable, disable the social login feature or the plugin entirely until a fix is applied.
Proactive Monitoring: Review WordPress user logs for suspicious login activity and check for unusual HTTP 403 responses that may have successfully set authentication cookies in the headers.
Compensating Controls: Deploy a Web Application Firewall (WAF) to filter requests to the patientSocialLogin endpoint and enforce Multi-Factor Authentication (MFA) for all administrative accounts.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 18, 2026, there is no public information indicating active exploitation. However, the simplicity of this bypass makes it a prime candidate for automated exploit scripts.
Analyst Recommendation
Due to the sensitivity of medical data and the high CVSS score, this is a top-priority remediation. Organizations must update the KiviCare plugin immediately to prevent unauthenticated access to sensitive EHR data and administrative functions.
Update WordPress is vulnerable to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-0...
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19)
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong A...
A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong AI News and Podcast Agent backend in FastAPI backend, stream-audio endpoint, in file routers/podcast_router
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A directory traversal vulnerability in the agentic-context-engine project versions up to 0
A directory traversal vulnerability in the agentic-context-engine project versions up to 0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A lack of path validation in aaPanel v7
A lack of path validation in aaPanel v7
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An issue in the VirtualHost configuration handling/parser component of aaPanel v7
An issue in the VirtualHost configuration handling/parser component of aaPanel v7
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
DedeCMS v5
DedeCMS v5
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was determined in SourceCodester Student Result Management System 1
A vulnerability was determined in SourceCodester Student Result Management System 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in UTT HiPER 810G up to 1
A vulnerability was found in UTT HiPER 810G up to 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in UTT HiPER 810G up to 1
A vulnerability has been found in UTT HiPER 810G up to 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A critical authentication flaw in OCPP WebSocket endpoints allows unauthenticated attackers to impersonate charging stations and manipulate backend co...
A critical authentication flaw in OCPP WebSocket endpoints allows unauthenticated attackers to impersonate charging stations and manipulate backend commands and data.
---METADATA---
VENDOR: OCPP Infrastructure
PRODUCT: WebSocket Endpoint
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A critical authentication flaw in OCPP WebSocket endpoints allows unauthenticated attackers to impersonate charging stations and manipulate backend commands and data.
Executive Summary:
The absence of authentication on OCPP WebSocket endpoints enables unauthenticated attackers to hijack charging station identities and compromise the integrity of the charging network.
Vulnerability Details
CVE-ID: CVE-2026-29796
Affected Software: OCPP Infrastructure WebSocket Endpoint
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability stems from a lack of proper authentication on WebSocket endpoints utilized by the Open Charge Point Protocol (OCPP). An unauthenticated attacker can establish a connection using a known station identifier, allowing them to impersonate a legitimate charger and interact with the backend system.
Business Impact
Successful exploitation could result in unauthorized control of the charging infrastructure, potential service outages, and the corruption of billing or usage data. With a CVSS score of 9.4, the risk to the business includes significant operational disruption and a loss of customer trust in the security of the charging platform.
Remediation Plan
Immediate Action: Update the affected software to the latest version immediately to enable required authentication for all WebSocket communications.
Proactive Monitoring: Review backend logs for anomalous command patterns or station identifiers connecting from unauthorized geographic locations.
Compensating Controls: Deploy a Web Application Firewall (WAF) capable of inspecting WebSocket traffic and enforcing connection limits or IP-based filtering.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 20, 2026, there is no public information indicating active exploitation of this vulnerability. The risk remains high due to the unauthenticated nature of the access required for exploitation.
Analyst Recommendation
Securing the communication channel between charging stations and the backend is critical for operational safety. Administrators should verify that all endpoints require strong authentication and consider implementing certificate-based authentication to prevent station impersonation. Apply the recommended vendor patches without delay.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Vito versions prior to 3.20.3 contain a missing authorization check in workflow site-creation actions, allowing authenticated attackers to manage site...
Vito versions prior to 3.20.3 contain a missing authorization check in workflow site-creation actions, allowing authenticated attackers to manage sites on unauthorized servers.
---METADATA---
VENDOR: Vito
PRODUCT: Vito
AFFECTED_VERSIONS: Prior to version 3.20.3
---END_METADATA---
Description Summary:
Vito versions prior to 3.20.3 contain a missing authorization check in workflow site-creation actions, allowing authenticated attackers to manage sites on unauthorized servers.
Executive Summary:
A critical authorization bypass in Vito allows authenticated users to create and manage websites on servers belonging to other projects, leading to unauthorized infrastructure access.
Vulnerability Details
CVE-ID: CVE-2026-29789
Affected Software: Vito Server Management Application
Affected Versions: Prior to version 3.20.3
Vulnerability: The application fails to validate if an authenticated user with workflow write access has permission to use a specific server_id. By supplying a foreign server_id during site-creation actions, an attacker can gain unauthorized control over servers linked to different projects within the same Vito instance.
Business Impact
With a CVSS score of 9.9, this vulnerability represents a near-total breakdown of multi-tenant or multi-project isolation. An attacker could deploy malicious applications, modify existing site configurations, or gain shell access to servers they do not own, resulting in massive data breaches and service disruption.
Remediation Plan
Immediate Action: Update the Vito application to version 3.20.3 or later immediately to enforce proper server-level authorization checks.
Proactive Monitoring: Review workflow logs and site creation history for any instances where sites were created on servers by users not officially assigned to those projects.
Compensating Controls: Restrict the ability to create workflows or sites to a very small number of highly trusted users until the patch can be applied.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 6, 2026, there is no public information indicating active exploitation. However, the high CVSS score and the nature of server management software make this an extremely attractive target for attackers.
Analyst Recommendation
The severity of this flaw demands immediate remediation. Vito administrators must apply the 3.20.3 update without delay to restore project isolation and prevent unauthorized server manipulation across their deployment environment.
Update HP applications into to the latest version. Monitor for exploitation attempts and review access logs.
Ghost is a Node
Ghost is a Node
---METADATA---
VENDOR: Ghost Foundation
PRODUCT: Ghost
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
A security vulnerability has been identified in the Ghost Node.js content management system that may impact system integrity.
Executive Summary:
The Ghost content management system is vulnerable to a security flaw that could allow attackers to compromise the Node.js-based application environment.
Vulnerability Details
CVE-ID: CVE-2026-29784
Affected Software: Ghost Foundation Ghost
Affected Versions: See vendor advisory for affected versions
Vulnerability: This vulnerability affects the Ghost CMS, a Node.js-based platform. While the specific technical mechanism is not fully detailed in the summary, the CVSS score suggests a significant flaw, likely related to improper input handling or a vulnerability in the underlying Node.js integration.
Business Impact
Successful exploitation could lead to unauthorized access to the CMS backend or the underlying server, potentially resulting in the defacement of websites or the theft of sensitive subscriber data. The CVSS score of 7.5 justifies a High severity rating, as it represents a significant risk to the availability and confidentiality of the hosted content.
Remediation Plan
Immediate Action: Update the Ghost CMS installation to the latest stable version to incorporate the necessary security fixes.
Proactive Monitoring: Review application logs for unusual administrative logins or unauthorized changes to site content and configurations.
Compensating Controls: Implement a robust Web Application Firewall (WAF) to detect and block common Node.js exploitation patterns and enforce strong multi-factor authentication for all users.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 9, 2026, there is no public information indicating active exploitation of this vulnerability. Security teams should remain vigilant as CMS platforms are frequent targets for automated exploitation scripts.
Analyst Recommendation
Maintaining an up-to-date CMS is critical for protecting web-facing assets. We recommend that administrators apply the latest Ghost updates immediately to mitigate the risk of unauthorized access and ensure the security of their digital publishing platform.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers
UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers
---METADATA---
VENDOR: UptimeFlare
PRODUCT: UptimeFlare
AFFECTED_VERSIONS: See vendor advisory for affected versions
---END_METADATA---
Description Summary:
UptimeFlare, a monitoring solution powered by Cloudflare Workers, contains a security vulnerability that could impact serverless monitoring operations.
Executive Summary:
A security vulnerability in the UptimeFlare serverless monitoring solution could allow attackers to disrupt monitoring services or access sensitive configuration data.
Vulnerability Details
CVE-ID: CVE-2026-29779
Affected Software: UptimeFlare (Cloudflare Workers based)
Affected Versions: See vendor advisory for affected versions
Vulnerability: UptimeFlare, which utilizes Cloudflare Workers for monitoring, has a vulnerability that could potentially allow an attacker to interfere with its serverless functions. The specific nature of the flaw likely involves improper handling of environment variables or unauthorized access to the status page configuration.
Business Impact
With a CVSS score of 7.5, this vulnerability is considered High severity. Successful exploitation could lead to "false positive" monitoring alerts, the silencing of legitimate downtime notifications, or the exposure of sensitive API keys used for monitoring, directly impacting operational visibility and response times.
Remediation Plan
Immediate Action: Update the UptimeFlare deployment to the latest version and rotate any secrets or API keys stored within the environment.
Proactive Monitoring: Audit Cloudflare Worker execution logs for unauthorized invocations or changes to the monitoring logic.
Compensating Controls: Implement IP whitelisting for the status page administration and use Cloudflare's security features to limit worker execution to trusted sources.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of March 9, 2026, there is no public information indicating active exploitation of this vulnerability. Users of serverless monitoring tools should ensure their configurations are hardened against unauthorized access.
Analyst Recommendation
It is critical to maintain the security of monitoring infrastructure to ensure accurate operational reporting. Administrators should apply the latest UptimeFlare updates and perform a security audit of their Cloudflare Worker configurations immediately to mitigate risk.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
pyLoad is a free and open-source download manager written in Python
pyLoad is a free and open-source download manager written in Python
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0
In OpenXiangShan NEMU, when Smstateen is enabled, clearing mstateen0
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
NEMU (OpenXiangShan/NEMU) before v2025
NEMU (OpenXiangShan/NEMU) before v2025
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvcfg (e
A local attacker who can execute privileged CSR operations (or can induce firmware to do so) performs carefully crafted reads/writes to menvcfg (e
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was found in D-Link DWR-M960 1
A vulnerability was found in D-Link DWR-M960 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been found in D-Link DWR-M960 1
A vulnerability has been found in D-Link DWR-M960 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenClaw versions prior to 2026
OpenClaw versions prior to 2026
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in D-Link DWR-M960 1
A flaw has been found in D-Link DWR-M960 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability was detected in D-Link DWR-M960 1
A vulnerability was detected in D-Link DWR-M960 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security vulnerability has been detected in D-Link DWR-M960 1
A security vulnerability has been detected in D-Link DWR-M960 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw has been found in Vaelsys 4
A flaw has been found in Vaelsys 4
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Lucee CFML Server versions across the 5
Lucee CFML Server versions across the 5
---METADATA---
VENDOR: Lucee
PRODUCT: Lucee
AFFECTED_VERSIONS: 5.3.1.95 through 7.0.0.395
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
Lucee CFML Server is affected by a reflected Cross-Site Scripting (XSS) vulnerability triggered via manipulated URL path parsing.
Executive Summary:
A reflected Cross-Site Scripting vulnerability in Lucee CFML Server allows unauthenticated attackers to execute arbitrary scripts in the context of a user's browser session.
Vulnerability Details
CVE-ID: CVE-2026-29519
Affected Software: Lucee Lucee
Affected Versions: 5.3.1.95 through 7.0.0.395
Vulnerability: The vulnerability involves improper neutralization of input during web page generation (CWE-79). An unauthenticated attacker can craft malicious URLs that, when processed by the server, inject scripts into the response delivered to the victim's browser.
Business Impact
Exploitation of this XSS vulnerability can lead to session hijacking, credential theft, or the execution of malicious actions on behalf of authenticated users. Given the CVSS score of 8.2 and the availability of a public proof-of-concept, the risk of targeted attacks against organizational users is elevated, potentially impacting internal service integrity.
Remediation Plan
Immediate Action: Check the official Lucee security advisories for the latest available security release and apply it to all affected servers.
Proactive Monitoring: Monitor web traffic for anomalous URL patterns containing script injection payloads and review logs for signs of suspicious client-side activity.
Compensating Controls: Implement a strong Content Security Policy (CSP) to restrict the execution of unauthorized scripts and utilize WAF rules to filter malicious input from URL paths.
Exploitation Status
Public Exploit Available: true
Analyst Notes: As of July 11, 2026, a public proof-of-concept exists for this vulnerability. While confirmed active exploitation is not currently reported, the availability of functional exploit code significantly increases the risk of near-term exploitation.
Analyst Recommendation
The presence of a public exploit makes this vulnerability highly actionable for threat actors. Organizations utilizing Lucee must prioritize the identification of affected instances and apply the necessary vendor patches or security configurations immediately to prevent user compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
NetBox versions 4
NetBox versions 4
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1
A security flaw has been discovered in Tosei Online Store Management System ネット店舗管理システム 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, enabling potential Remote...
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, enabling potential Remote Code Execution.
---METADATA---
VENDOR: WordPress
PRODUCT: ProSolution WP Client
AFFECTED_VERSIONS: Up to and including 1.9.9
---END_METADATA---
Description Summary:
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation, enabling potential Remote Code Execution.
Executive Summary:
A critical arbitrary file upload vulnerability in the ProSolution WP Client plugin allows unauthenticated attackers to achieve Remote Code Execution.
Vulnerability Details
CVE-ID: CVE-2026-2942
Affected Software: WordPress ProSolution WP Client Plugin
Affected Versions: Up to and including 1.9.9
Vulnerability: The proSol_fileUploadProcess function fails to validate file types, allowing unauthenticated attackers to upload malicious files (e.g., PHP scripts) to the server, resulting in Remote Code Execution.
Business Impact
The 9.8 CVSS score reflects the extreme risk of total server compromise. Attackers can upload web shells to gain persistent, unauthorized access to the site, steal data, or deface the website.
Remediation Plan
Immediate Action: Update the ProSolution WP Client plugin to the latest version immediately. If an update is unavailable, deactivate and remove the plugin.
Proactive Monitoring: Scan the site for any unauthorized files in the uploads directory and review server access logs for suspicious requests to uploaded files.
Compensating Controls: Use a WAF to restrict file uploads and block attempts to access or execute scripts in user-writable directories.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Apr 8, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Arbitrary file upload vulnerabilities are critical and highly dangerous. Administrators must ensure the plugin is updated immediately to prevent remote attackers from taking control of the WordPress installation.
Update WordPress is vulnerable to the latest version. Check vendor security advisory for specific patch details. Monitor for exploitation attempts and review access logs.
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy...
The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'linksy_search_and_replace_item_details' function in all versions up to, and including, 1
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b
A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Changing
PRODUCT: IDExpert Windows Logon Agent
AFFECTED_VERSIONS: See vendor advisory
---END_METADATA---
Description Summary:
IDExpert Windows Logon Agent is vulnerable to unauthenticated remote code execution via unauthorized remote DLL downloads and execution.
Executive Summary:
The IDExpert Windows Logon Agent is susceptible to a critical remote code execution flaw that allows unauthenticated attackers to execute malicious DLLs on target systems.
Vulnerability Details
CVE-ID: CVE-2026-3000
Affected Software: Changing IDExpert Windows Logon Agent
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The software contains a Remote Code Execution (RCE) vulnerability. An unauthenticated attacker can remotely force the system to download arbitrary DLL files from a malicious source and execute them, bypassing standard security boundaries.
Business Impact
The impact of this vulnerability is critical, as it allows for unauthorized code execution at the system level without requiring user interaction or credentials. This could lead to the total compromise of sensitive authentication infrastructure and the theft of user credentials. The CVSS score of 9.8 underscores the extreme risk to organizational security and business continuity.
Remediation Plan
Immediate Action: Apply the latest security updates for IDExpert Windows Logon Agent as provided by the vendor to mitigate this RCE risk.
Proactive Monitoring: Inspect system logs for the loading of unsigned or suspicious DLLs and monitor for unusual network activity originating from the logon agent service.
Compensating Controls: Implement strict firewall rules to prevent the logon agent from initiating connections to untrusted external domains and employ application whitelisting.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Mar 2, 2026, there is no public information indicating active exploitation of this vulnerability. However, the technical ease of exploiting unauthenticated RCE flaws makes this a high-priority target for attackers.
Analyst Recommendation
Given the Critical severity and the potential for complete system takeover, IT administrators should treat this as a top-priority patching task. Immediate remediation is necessary to protect Windows logon environments from remote compromise.