FEED ACTIVE last sync Aug 8 · 10:18Z tracking 20 advisories LIVE
tech · ai · security

The signal, not the noise.

Auto-updated intelligence on technology, AI, and the latest disclosed security advisories. Pulled daily, ranked by what matters.

Critical Advisories

all CVEs →
— · — · CVSS 9.8 · Aug 8

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action…

NVD detail →
apache · nifi · CVSS 9.8 · Aug 3

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that…

NVD detail →
— · — · CVSS 9.8 · Aug 3

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command…

NVD detail →
— · — · CVSS 9.8 · Aug 3

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the…

NVD detail →
— · — · CVSS 9.8 · Aug 3

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc of the component ovpn-client.so Native Plugin. Executing a manipulation of the argument…

NVD detail →
dell · virtual storage integrator · CVSS 9.1 · Aug 6

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading…

NVD detail →