Tag
Authorization Bypass in OpenClaw Feishu Package
1 TTPThe OpenClaw feishu package is susceptible to an authorization bypass vulnerability where per-account disablement settings are ignored, potentially allowing lower-trust entities to execute unauthorized actions.
Denial of Service Vulnerability in Node.js
1 TTPA vulnerability in Node.js allows a remote, unauthenticated attacker to trigger a Denial of Service condition, impacting the availability of applications running on the affected environment.
Arbitrary Code Execution in JSONata
1 TTP 1 CVEThe JSONata library contains a critical vulnerability (CVE-2026-77415) allowing unauthenticated attackers to achieve arbitrary code execution via maliciously crafted JSONata expressions.
IBM Langflow OSS Vulnerability Allows FAISS Namespace Reuse and Information Disclosure (CVE-2026-13442)
5 TTPs 1 CVEA critical vulnerability, CVE-2026-13442, in IBM Langflow OSS versions 1.0.0 through 1.10.1 enables an authenticated attacker to reuse other users' FAISS namespaces, leading to cross-user information disclosure of owner-only vector content and potential limited integrity impact via persistent poisoning of query results.
Bitdefender Internet and Total Security Vulnerability Allows Privilege Escalation
1 TTPA local attacker can exploit a vulnerability in Bitdefender Internet Security and Bitdefender Total Security to elevate their privileges on the affected system.
Multiple Arbitrary Code Execution Vulnerabilities in Labcenter Proteus 9
2 TTPsCISA has issued an advisory for multiple high-severity vulnerabilities (CVE-2026-42953, CVE-2026-49033, CVE-2026-42958) in Labcenter Proteus 9.1_SP4_Build_42914 that could allow a malicious user to achieve arbitrary code execution and information disclosure through user interaction with specially crafted files.
CVE-2026-25865: Punto Switcher Unquoted Search Path Vulnerability
2 rules 2 TTPsCVE-2026-25865 describes an unquoted search path element vulnerability in Yandex Punto Switcher through version 4.5.0.583, allowing local attackers to execute arbitrary code by placing a malicious `RunDll32.exe` earlier in the system's PATH to hijack the application's insecure `WinExec` call, leading to arbitrary code execution with affected user privileges.