Tag
CSRF Vulnerability in Komari Management Interface
1 rule 2 TTPsThe Komari management interface lacks CSRF protections and secure cookie attributes, allowing an attacker to perform unauthorized administrative actions including arbitrary code execution.
Memos Refresh Token Revocation Failure
1 TTP 1 CVEMemos versions 0.26.0 through 0.30.0 fail to invalidate refresh tokens after a password change, enabling persistent unauthorized access via the RefreshToken RPC.
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
7 rules 15 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability
1 TTP 1 CVECVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.
Question2Answer Session Invalidation Vulnerability
2 TTPs 1 CVEAttackers can exploit CVE-2026-64829, a session invalidation vulnerability in Question2Answer through version 1.8.8, where the forgot-password reset flow fails to clear the sessioncode field, allowing an attacker with a previously obtained remember-me cookie to retain authenticated access even after the account's password has been reset.
Open WebUI CORS Misconfiguration and Session Validation Vulnerability Leads to RCE
2 rules 1 TTPOpen WebUI version v0.3.10 has a CORS misconfiguration and session validation issue that can lead to remote code execution due to a one-click attack against admin users.