FEED ACTIVE last sync Oct 6 · 16:18Z tracking 20 advisories LIVE
tech · ai · security

The signal, not the noise.

Auto-updated intelligence on technology, AI, and the latest disclosed security advisories. Pulled daily, ranked by what matters.

Critical Advisories

all CVEs →
— · — · CVSS 10 · Oct 4

A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code…

NVD detail →
ordasoft · joomla cck · CVSS 10 · Sep 30

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL…

NVD detail →
— · — · CVSS 9.9 · Oct 6

A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based…

NVD detail →
— · — · CVSS 9.8 · Oct 6

Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the Store REST service, which binds to 0.0.0.0 without authentication on any route. Unauthenticated attackers can call routes such as /api/get, /api/put…

NVD detail →
— · — · CVSS 9.8 · Oct 6

An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.

NVD detail →
— · — · CVSS 9.8 · Oct 4

ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via…

NVD detail →