CPE
Information Disclosure Vulnerability in Gitea
1 TTP 1 CVEA vulnerability in Gitea allows a remote, unauthenticated attacker to exploit an information disclosure flaw, potentially exposing sensitive repository or system data.
Remote Code Execution in Craft CMS via HMAC Signature Misuse
3 TTPs 2 CVEsCraft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a critical vulnerability allowing authenticated users to achieve remote code execution by injecting malicious payloads into improperly validated redirect parameters.
Information Disclosure Vulnerability in MISP
1 TTP 1 CVEAn authenticated remote attacker can exploit a vulnerability in MISP to gain unauthorized access to sensitive information due to improper access controls.
Authorization Bypass in Craft CMS assets/move-asset Endpoint
2 rules 4 TTPs 1 CVECraft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.
iCagenda Unrestricted File Upload Vulnerability Leading to RCE (CVE-2026-48939)
1 rule 2 TTPs 5 CVEs 7 IOCsAttackers are actively exploiting CVE-2026-48939, an unrestricted file upload vulnerability in iCagenda, to upload malicious PHP code and achieve remote code execution on affected web servers.