ZCyberNews
中文

Articles

460 articles

CashDro 3 ATM Panel Weak PINs Enable Brute-Force AccessHIGH
Vulnerabilities

CashDro 3 ATM Panel Weak PINs Enable Brute-Force Access

CVE-2026-8076: CashDro 3 ATM admin panel (v24.01.00.26) accepts numeric PINs for authentication, enabling brute-force attacks that can compromise cash dispenser controls.

CVE-2026-8076
3 min read
CVE-2023-47268: PrusaSlicer 3MF Files Can Execute Arbitrary CodeMEDIUM
Vulnerabilities

CVE-2023-47268: PrusaSlicer 3MF Files Can Execute Arbitrary Code

CVE-2023-47268 (CVSS 5.3): A crafted 3mf project file in PrusaSlicer through 2.6.1 executes arbitrary code when sliced — no user interaction beyond opening the file.

CVE-2023-47268
3 min read
CVE-2024-30167: Atlona Matrix Switcher Flaw Lets Authenticated UsersMEDIUM
Vulnerabilities

CVE-2024-30167: Atlona Matrix Switcher Flaw Lets Authenticated Users

CVE-2024-30167 (CVSS 6.3): Authenticated users can execute arbitrary commands as root on Atlona AT-OME-MS42 Matrix Switcher 1.1.2 via a crafted POST to /cgi-bin/time.cgi.

CVE-2024-30167
3 min read
CVE-2025-69690: Netgate pfSense CE Module Installer RCE via BackupCRITICAL
Vulnerabilities

CVE-2025-69690: Netgate pfSense CE Module Installer RCE via Backup

CVE-2025-69690 (CVSS 9.1) lets authenticated admins achieve remote code execution on pfSense CE 2.7.2 by crafting a backup file with a serialized PHP object.

CVE-2025-69690
3 min read
CVE-2025-69691: Netgate pfSense XMLRPC API Allows Admin Code ExecutionCRITICAL
Vulnerabilities

CVE-2025-69691: Netgate pfSense XMLRPC API Allows Admin Code Execution

CVE-2025-69691 (CVSS 9.9) in Netgate pfSense CE 2.8.0 lets authenticated admins execute arbitrary PHP via XMLRPC's pfsense.exec_php; Netgate disputes the severity.

CVE-2025-69691
3 min read
DrayTek Vigor 2960 OS Command Injection Flaw Allows UnauthenticatedHIGH
Vulnerabilities

DrayTek Vigor 2960 OS Command Injection Flaw Allows Unauthenticated

CVE-2022-50994 (CVSS 8.1): Unauthenticated attackers can inject shell commands via the formpassword parameter in the CGI login handler of DrayTek Vigor 2960 routers running...

CVE-2022-50994
3 min read
Fake OpenAI Repo on Hugging Face Pushes Rust InfostealerHIGH
Malware

Fake OpenAI Repo on Hugging Face Pushes Rust Infostealer

A typosquatted OpenAI repository reached #1 on Hugging Face with 244,000 downloads, delivering a Rust-based infostealer that targets browser credentials, crypto wallets, and VPN...

3 min readWinos 4.0
LibreNMS Pre-24.10.0 RCE via OS Command Injection (CVE-2024-51092)CRITICAL
Vulnerabilities

LibreNMS Pre-24.10.0 RCE via OS Command Injection (CVE-2024-51092)

CVE-2024-51092 (CVSS 9.1): LibreNMS before 24.10.0 allows unauthenticated remote attackers to execute arbitrary OS commands via AboutController.php, SettingsController.php, and...

CVE-2024-51092
4 min read
MikroTik RouterOS SMB DoS Flaw CVE-2024-27686 Lets Remote AttackersHIGH
Vulnerabilities

MikroTik RouterOS SMB DoS Flaw CVE-2024-27686 Lets Remote Attackers

CVE-2024-27686 (CVSS 7.5) affects MikroTik RouterOS x86 versions 6.40.5 through 6.49.10 — a crafted SMB packet on TCP 445 triggers a device crash. No authentication required.

CVE-2024-27686
3 min read
PraisonAI Flaw Lets Agents Execute Arbitrary Python ToolsHIGH
Vulnerabilities

PraisonAI Flaw Lets Agents Execute Arbitrary Python Tools

CVE-2026-44339 (CVSS 8.6) in PraisonAI multi-agent framework lets agents resolve undeclared tool names against module globals, enabling arbitrary Python execution.

CVE-2026-44339
3 min read
SourceCodester Pharmacy System XSS Flaw CVE-2026-8136 PublishedLOW
Vulnerabilities

SourceCodester Pharmacy System XSS Flaw CVE-2026-8136 Published

CVE-2026-8136 (CVSS 3.3) enables remote stored XSS in SourceCodester Pharmacy Sales and Inventory System 1.0 via the Name parameter in /index.php?page=users.

CVE-2026-8136
3 min read
Thruk Monitoring XSS Flaw CVE-2022-23961 Lets Attackers HijackMEDIUM
Vulnerabilities

Thruk Monitoring XSS Flaw CVE-2022-23961 Lets Attackers Hijack

CVE-2022-23961 (CVSS 6.1) in Thruk Monitoring through 2.46.3 enables unauthenticated reflected XSS via the login field, risking session theft for admins.

CVE-2022-23961
3 min read
← PrevPage 14 of 39Next →