Tag

#Critical Vulnerability

newsCRITICAL 9.1

Critical Vulnerability in 微信二维码登陆 WordPress Plugin Allows Unauthenticated Login

A critical vulnerability (CVE-2026-13597, CVSS 9.1) in the 微信二维码登陆 WordPress plugin (version 1.3 and earlier) allows unauthenticated attackers to forge login events, read login codes, and log in as any user, including administrators, without a password. Immediate action is required to prevent exploitation.

1 source
articleCRITICAL 9.1

Critical Authentication Bypass Vulnerability in Check Point SmartConsole (CVE-2026-16232)

A critical authentication bypass vulnerability (CVE-2026-16232) has been discovered in Check Point SmartConsole, allowing unauthenticated remote attackers to obtain application login tokens and gain full administrative privileges. This vulnerability has a CVSS score of 9.1 and is actively being exploited. Affected products include various versions of Check Point Quantum Security Management and Multi-Domain Security Management. Immediate patching or mitigation is strongly recommended.

1 source
newsCRITICAL 10.0

Critical Shellcode Injection Vulnerability in openSUSE Build Service

A critical vulnerability (CVE-2026-56004) with a CVSS score of 10 has been discovered in the obs tar_scm source service before version 0.12.4. This vulnerability allows attackers to inject shellcode and execute code as the source service or local user. Immediate action is required to update to version 0.12.4 or later.

1 source
newsCRITICAL 10.0

Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12846)

A critical stack overflow vulnerability (CVE-2026-12846) with a CVSS score of 10 has been discovered in GeoVision GV-I/O Box 4E, a smart embedded device. The vulnerability affects version V2.09 and can be exploited by sending a crafted UDP message to the DVRSearch service listening on port 10001. Immediate action is required to update to a non-vulnerable version.

1 source
articleCRITICAL 9.1

Critical Insecure Default Credentials Vulnerability in NI grpc-device

A critical vulnerability (CVE-2026-9142) with a CVSS score of 9.1 has been discovered in NI grpc-device, affecting versions 2.17.0 and prior. The vulnerability allows unauthenticated access to the server on the local network when TLS configuration is not present and the server is bound beyond loopback. Immediate patching is recommended to prevent potential exploitation.

1 source