Tag
Cross-Site Request Forgery Vulnerability in djust SSE Transport
1 rule 1 CVEThe djust library before version 1.0.7 is vulnerable to CSRF via its SSE transport, allowing cross-origin requests to execute state-changing event handlers as an authenticated victim.
Unrestricted File Upload Vulnerability in Anil-matcha Open-Generative-AI
1 rule 1 CVEAnil-matcha Open-Generative-AI is vulnerable to unrestricted file uploads via the /api/upload-binary endpoint, allowing remote attackers to manipulate the x-proxy-target-url argument to upload arbitrary files.
CSRF Vulnerability in Komari Management Interface
1 rule 2 TTPsThe Komari management interface lacks CSRF protections and secure cookie attributes, allowing an attacker to perform unauthorized administrative actions including arbitrary code execution.
Prototype Pollution Vulnerability in Node.js JSON Merge Patch Implementations
1 rule 1 TTPA prototype pollution vulnerability, tracked as CVE-2026-3030, allows attackers to inject malicious properties into the global Object.prototype via insecure deep merge functions, potentially leading to privilege escalation.
Unauthenticated Remote Shutdown in TypeSpec Spector
1 rule 1 TTPThe TypeSpec Spector mock server lacks authentication on its administrative shutdown endpoint, allowing any network-reachable attacker to terminate the server process via a single POST request.
Authentication Bypass in Team Password Manager via Password Reset Flow
1 TTP 1 CVETeam Password Manager versions prior to 14.184.308 contain a critical authentication bypass vulnerability in the local account password reset workflow that allows unauthenticated attackers to perform account takeovers.
Improper Access Control in HyperDX Team Management
1 TTP 1 CVEHyperDX versions through 1.10.1 contain an improper access control vulnerability allowing authenticated users to perform unauthorized administrative actions via team management API endpoints.
Authentication Bypass in 6Storage Rentals WordPress Plugin
1 rule 1 TTP 1 CVEThe 6Storage Rentals WordPress plugin contains a critical authentication bypass vulnerability (CVE-2026-15303) that allows unauthenticated attackers to impersonate any user, including administrators, via the six_storage_create_wp_user AJAX handler.
Stored XSS Vulnerability in OpenClaw Dashboard
1 TTP 1 CVEAn unauthenticated stored XSS vulnerability in the OpenClaw Dashboard allows remote attackers to execute arbitrary JavaScript in administrative sessions via the sessions API.