Skip to content
Threat Feed

Tag

Web-Application-Attack

5 briefs RSS
low advisory

Detection of Potential HTTP Downgrade Attacks

Attackers may force HTTP protocol downgrades from secure versions like HTTP/2 to legacy versions to exploit header parsing inconsistencies and facilitate request smuggling or cache poisoning.

Apache HTTP Server +3 web-application-attack defense-evasion network-security
1r 1t
critical advisory

Critical RCE Vulnerability in Apache Struts (S2-067)

A critical remote code execution vulnerability (CVE-2024-53677) in Apache Struts versions 2.0.0 through 6.3.0.2 allows attackers to leverage path traversal during file uploads to execute arbitrary code.

Struts apache-struts rce file-upload web-application-attack
1r 2t 1c
high advisory

Privilege Escalation in YITH WooCommerce Waitlist Premium Plugin

Authenticated attackers can exploit a missing capability check and nonce validation in the YITH WooCommerce Waitlist Premium plugin to elevate privileges to administrator.

WooCommerce Waitlist Premium privilege-escalation wordpress web-application-attack
1r 1t 1c
high advisory

Authentication Bypass in Support Genix WordPress Plugin

The Support Genix WordPress plugin is vulnerable to authentication bypass and administrator account takeover due to a weak cryptographic implementation in the guest ticket login feature.

Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System wordpress authentication-bypass web-application-attack
2t 1c
high threat

SQL Injection Vulnerability in SourceCodester Simple Student Information System

An unauthenticated remote SQL injection vulnerability in SourceCodester Simple Student Information System allows attackers to execute arbitrary database commands via the 'ID' parameter in 'view_department.php'.

exploited Simple Student Information System web-application-attack sql-injection cve-2026-19710
1r 1t 1c