ZCyberNews
中文

Articles

460 articles

CyberPanel 2.1 Flaw Lets Authenticated Attackers Execute Remote CodeHIGH
Vulnerabilities

CyberPanel 2.1 Flaw Lets Authenticated Attackers Execute Remote Code

CVE-2021-47949 (CVSS 8.8) in CyberPanel 2.1 lets authenticated attackers read arbitrary files and execute code via symlink attacks through the filemanager controller endpoint.

CVE-2021-47949
3 min read
Emlog CSRF Flaw CVE-2026-42286 Lets Attackers Hijack Admin ActionsHIGH
Vulnerabilities

Emlog CSRF Flaw CVE-2026-42286 Lets Attackers Hijack Admin Actions

CVE-2026-42286: Missing CSRF protection in Emlog prior to 2.6.11 lets attackers trick authenticated admins into unauthorized plugin management and config changes.

CVE-2026-42286
3 min read
Google Ads, Claude Chats Push MacSync Infostealer to macOS UsersHIGH
Malware

Google Ads, Claude Chats Push MacSync Infostealer to macOS Users

Attackers abuse Google Ads linking to real claude.ai and shared Claude chats to deliver MacSync infostealer, harvesting browser credentials and Keychain data.

4 min read
Opencart TMD Vendor System 3.x SQLi Lets Attackers Dump UserHIGH
Vulnerabilities

Opencart TMD Vendor System 3.x SQLi Lets Attackers Dump User

CVE-2021-47928 (CVSS 8.2): Unauthenticated blind SQL injection in Opencart TMD Vendor System 3.x lets attackers extract usernames, emails, and password reset codes from the...

CVE-2021-47928
3 min read
Three WordPress Plugins Carry Stored XSS Flaws (CVE-2021-47926-929)MEDIUM
Vulnerabilities

Three WordPress Plugins Carry Stored XSS Flaws (CVE-2021-47926-929)

CVE-2021-47926, CVE-2021-47927, and CVE-2021-47929 each carry a CVSS 6.4 stored XSS in Filterable Portfolio Gallery, WP Symposium Pro, and Contact Form to Email — authenticated...

CVE-2021-47929CVE-2021-47927CVE-2021-47926
4 min read
uBidAuction 2.0.1 Reflected XSS Flaw Lets Attackers Inject ScriptsMEDIUM
Vulnerabilities

uBidAuction 2.0.1 Reflected XSS Flaw Lets Attackers Inject Scripts

CVE-2022-50966 (CVSS 6.1): uBidAuction 2.0.1 reflected XSS in the news/manage module allows remote attackers to inject scripts via unsanitized GET parameters date_created,...

CVE-2022-50966
3 min read
WordPress 3dady Stats Plugin Stored XSS Lets Attackers Hijack SessionsMEDIUM
Vulnerabilities

WordPress 3dady Stats Plugin Stored XSS Lets Attackers Hijack Sessions

CVE-2022-50945 (CVSS 6.4): Stored XSS in WordPress 3dady real-time web stats plugin 1.0 lets authenticated attackers inject JavaScript via unsanitized input fields, enabling...

CVE-2022-50945
3 min read
WordPress Curtain Plugin CSRF Lets Attackers Toggle Maintenance ModeMEDIUM
Vulnerabilities

WordPress Curtain Plugin CSRF Lets Attackers Toggle Maintenance Mode

CVE-2022-50955: WordPress Curtain 1.0.2 CSRF flaw lets attackers trick admins into toggling site maintenance mode via forged requests without nonce validation.

CVE-2022-50955
3 min read
WordPress GetPaid Plugin HTML Injection Flaw CVE-2021-47948MEDIUM
Vulnerabilities

WordPress GetPaid Plugin HTML Injection Flaw CVE-2021-47948

CVE-2021-47948 (CVSS 5.4): Authenticated attackers can inject arbitrary HTML via the Help Text field in GetPaid 2.4.6, enabling stored XSS attacks on payment forms.

CVE-2021-47948
3 min read
Acer PredatorSense LPE Lets Local Users Gain SYSTEM PrivilegesHIGH
Vulnerabilities

Acer PredatorSense LPE Lets Local Users Gain SYSTEM Privileges

CVE-2026-8069: Acer PredatorSense versions 3.00.3136 to 3.00.3196 expose a misconfigured named pipe, letting any authenticated local user execute code as SYSTEM and delete...

CVE-2026-8069
3 min read
Argo CD Flaw CVE-2026-42880 Leaks Kubernetes Secrets via Dry-RunCRITICAL
Vulnerabilities

Argo CD Flaw CVE-2026-42880 Leaks Kubernetes Secrets via Dry-Run

CVE-2026-42880 (CVSS 9.6) in Argo CD lets read-only attackers extract plaintext Kubernetes Secrets via ServerSideDiff endpoint using Server-Side Apply dry-run.

CVE-2026-42880
3 min read
Bouncy Castle BC-FJA Flaw CVE-2026-8149 Leaks GCM KeysHIGH
Vulnerabilities

Bouncy Castle BC-FJA Flaw CVE-2026-8149 Leaks GCM Keys

CVE-2026-8149 in Bouncy Castle BC-FJA 2.1.0–2.1.2 leaks AES-GCM authentication keys via side-channel in AVX-512f optimized gcm128w/gcm512w routines.

CVE-2026-8149
4 min read
← PrevPage 13 of 39Next →