Security Intel Feed
Cyber Hose
Page 34 of 44
Vulnerabilities & CVEs
CVE-2026-16226 in SourceCodester Pizzafy Ecommerce System
Read digest- CVE-2026-16226 in SourceCodester Pizzafy Ecommerce System — CVE-2026-16226 with CVSS 4.7 affects the admin_class_novo.php save_settings function, posing a moderate risk.
- Multiple SQL Injection Flaws in SourceCodester Class and Exam Timetabling System — SQL injection vulnerabilities found in edit_subject.php and edit_schoolyr.php could allow data compromise.
- Linux Kernel Vulnerabilities Including iommu/vt-d and selinux Fixes — Several Linux kernel flaws affecting iommu/vt-d, RDMA, perf/x86/intel, udf, f2fs, and selinux have been disclosed.
Vulnerabilities & CVEs
CVE-2026-16219 Path Traversal in Croogo CMS Admin File Manager
Read digest- CVE-2026-16219 Path Traversal in Croogo CMS Admin File Manager — A path traversal flaw in Croogo CMS Admin File Manager's FileManager.php allows unauthorized file access.
- CVE-2026-16220 Cross-Site Scripting in Online Examination System — Cross-site scripting vulnerability found in code-projects Online Examination System's account.php.
- CVE-2026-16223 Third Party Edit Endpoint Issue in 1Panel-dev CordysCRM — Vulnerability in 1Panel-dev CordysCRM's Third Party Edit Endpoint IntegrationConfigService.java.
- CVE-2026-16222 Server-Side Request Forgery in 1Panel-dev CordysCRM TokenService.java — Server-side request forgery vulnerability in 1Panel-dev CordysCRM's TokenService.java.
Vulnerabilities & CVEs
CVE-2026-16215 in django-jet OAuth Credential Revoke Authorization
Read digest- CVE-2026-16215 in django-jet OAuth Credential Revoke Authorization — A security flaw in django-jet OAuth Credential Revoke authorization has been identified with CVSS 6.5.
- CVE-2026-16214 in django-jet Dashboard views.py Authorization — An authorization vulnerability was identified in django-jet Dashboard views.py with CVSS 6.3.
- CVE-2026-16212 Race Condition in django-shop Purchase Stock — A race condition vulnerability affects django-shop Purchase Stock inventory.py with CVSS 4.2.
Vulnerabilities & CVEs
CVE-2026-16206 in django-oauth-toolkit affects OAuth2 token validation
Read digest- CVE-2026-16206 in django-oauth-toolkit affects OAuth2 token validation — A CVSS 6.3 vulnerability in django-oauth-toolkit's oauth2_validators.py could allow session-related security issues.
- CVE-2026-16204 in zevorn rt-claw Telegram-to-AI Tool Execution Flow — A CVSS 6.3 flaw in zevorn rt-claw's script execution flow may allow unauthorized script execution.
- CVE-2026-16205 Pluck CMS Albums XSS vulnerability — A low-severity cross-site scripting issue affects Pluck CMS Albums via albums.admin.php.
Vulnerabilities & CVEs
CVE-2026-16200 zevorn rt-claw RPC authorization vulnerability
Read digest- CVE-2026-16200 zevorn rt-claw RPC authorization vulnerability — This CVSS 7.3 vulnerability in zevorn rt-claw's RPC claw_tool_invoke allows unauthorized access.
Threat Research & Deep Dives
Chinese Civic Apps Share Vulnerable Reward Backend Allowing Forged
Read digest- Chinese Civic Apps Share Vulnerable Reward Backend Allowing Forged Lottery Claims — Several Chinese civic and government-adjacent apps use a shared reward backend with a recoverable signing secret, allowing attackers to forge valid reward claims.
- CVE-2026-10130: QueryWeaver Authentication Bypass via Email Signup Token — An authentication bypass vulnerability in QueryWeaver allows attackers to bypass authentication via email signup token issuance.
Active Exploits & Incidents
WordPress Core Pre-Auth RCE CVE-2026-63030 Affects Versions 6.9.0
Read digest- WordPress Core Pre-Auth RCE CVE-2026-63030 Affects Versions 6.9.0 to 7.0.1 — A pre-authentication remote code execution vulnerability in WordPress Core versions 6.9.0 through 7.0.1 is actively exploited.
Active Exploits & Incidents
Critical WordPress 'wp2shell' RCE flaws get public exploits, patch now
Read digest- Critical WordPress 'wp2shell' RCE flaws get public exploits, patch now — Two chained pre-authentication vulnerabilities in WordPress Core allow remote code execution and have public exploits.
- Four-Stage Bitmap-Steganography Dropper Delivers AsyncRAT 0.5.8 via .NET Chain — A complex .NET dropper uses bitmap steganography and multiple obfuscation stages to deliver AsyncRAT malware.
- AstrBot API suffers authentication and authorization bypass vulnerabilities up to version 4.25.5 — AstrBot API versions up to 4.25.5 have bypass flaws allowing remote exploitation via spoofed Username arguments.
- Insecure PRNG in urwid Web Backend Exposes Session IDs and Enables Code Injection — Weak PRNG in urwid web backend exposes session IDs, enabling attackers to hijack sessions and execute code.
Active Exploits & Incidents
Microsoft Reports Surge in ACR Stealer Attacks Targeting Enterprise
Read digest- Microsoft Reports Surge in ACR Stealer Attacks Targeting Enterprise Customers — Microsoft has observed a significant increase in ACR Stealer malware attacks that steal browser passwords and tokens from enterprises.
Threat Research & Deep Dives
Multiple High-Severity Vulnerabilities Found in VMware Avi Load
Read digest- Multiple High-Severity Vulnerabilities Found in VMware Avi Load Balancer — VMware Avi Load Balancer versions 22.1.1 through 32.1.1 have critical vulnerabilities enabling remote code execution and privilege escalation.
Assess Your Exposure
Start with the free Posture Self-Check to see where you stand against the current threat landscape.
Free Posture Self-Check