Skip to content
Threat Feed

Tag

Software-Vulnerability

7 briefs RSS
high advisory

Authorization Bypass in OpenClaw Feishu Package

The OpenClaw feishu package is susceptible to an authorization bypass vulnerability where per-account disablement settings are ignored, potentially allowing lower-trust entities to execute unauthorized actions.

feishu authorization-bypass software-vulnerability supply-chain
1t
medium advisory

Denial of Service Vulnerability in Node.js

A vulnerability in Node.js allows a remote, unauthenticated attacker to trigger a Denial of Service condition, impacting the availability of applications running on the affected environment.

Node.js denial-of-service nodejs software-vulnerability
1t
critical advisory

Arbitrary Code Execution in JSONata

The JSONata library contains a critical vulnerability (CVE-2026-77415) allowing unauthenticated attackers to achieve arbitrary code execution via maliciously crafted JSONata expressions.

jsonata +2 remote-code-execution cve-2026-77415 software-vulnerability nodejs
1t 1c
high threat

IBM Langflow OSS Vulnerability Allows FAISS Namespace Reuse and Information Disclosure (CVE-2026-13442)

A critical vulnerability, CVE-2026-13442, in IBM Langflow OSS versions 1.0.0 through 1.10.1 enables an authenticated attacker to reuse other users' FAISS namespaces, leading to cross-user information disclosure of owner-only vector content and potential limited integrity impact via persistent poisoning of query results.

exploited Langflow OSS 1.0.0 +1 information-disclosure software-vulnerability access-control-bypass
5t 1c
high advisory

Bitdefender Internet and Total Security Vulnerability Allows Privilege Escalation

A local attacker can exploit a vulnerability in Bitdefender Internet Security and Bitdefender Total Security to elevate their privileges on the affected system.

Bitdefender Internet Security +1 privilege-escalation antivirus software-vulnerability
1t
high threat

Multiple Arbitrary Code Execution Vulnerabilities in Labcenter Proteus 9

CISA has issued an advisory for multiple high-severity vulnerabilities (CVE-2026-42953, CVE-2026-49033, CVE-2026-42958) in Labcenter Proteus 9.1_SP4_Build_42914 that could allow a malicious user to achieve arbitrary code execution and information disclosure through user interaction with specially crafted files.

exploited Labcenter Proteus 9 ics ot software-vulnerability cve code-execution information-disclosure
2t
high advisory

CVE-2026-25865: Punto Switcher Unquoted Search Path Vulnerability

CVE-2026-25865 describes an unquoted search path element vulnerability in Yandex Punto Switcher through version 4.5.0.583, allowing local attackers to execute arbitrary code by placing a malicious `RunDll32.exe` earlier in the system's PATH to hijack the application's insecure `WinExec` call, leading to arbitrary code execution with affected user privileges.

Punto Switcher privilege-escalation local-exploitation windows software-vulnerability path-interception
2r 2t