Skip to content
Threat Feed

Tag

Web-Application-Security

9 briefs RSS
medium advisory

Cross-Site Request Forgery Vulnerability in djust SSE Transport

The djust library before version 1.0.7 is vulnerable to CSRF via its SSE transport, allowing cross-origin requests to execute state-changing event handlers as an authenticated victim.

djust web-application-security csrf sse vulnerability
1r 1c
high advisory

Unrestricted File Upload Vulnerability in Anil-matcha Open-Generative-AI

Anil-matcha Open-Generative-AI is vulnerable to unrestricted file uploads via the /api/upload-binary endpoint, allowing remote attackers to manipulate the x-proxy-target-url argument to upload arbitrary files.

Open-Generative-AI vulnerability remote-code-execution web-application-security
1r 1c
high advisory

CSRF Vulnerability in Komari Management Interface

The Komari management interface lacks CSRF protections and secure cookie attributes, allowing an attacker to perform unauthorized administrative actions including arbitrary code execution.

komari web-application-security csrf session-management
1r 2t
medium advisory

Prototype Pollution Vulnerability in Node.js JSON Merge Patch Implementations

A prototype pollution vulnerability, tracked as CVE-2026-3030, allows attackers to inject malicious properties into the global Object.prototype via insecure deep merge functions, potentially leading to privilege escalation.

Node.js web-application-security prototype-pollution nodejs privilege-escalation
1r 1t
medium advisory

Unauthenticated Remote Shutdown in TypeSpec Spector

The TypeSpec Spector mock server lacks authentication on its administrative shutdown endpoint, allowing any network-reachable attacker to terminate the server process via a single POST request.

TypeSpec Spector denial-of-service web-application-security typespec
1r 1t
critical advisory

Authentication Bypass in Team Password Manager via Password Reset Flow

Team Password Manager versions prior to 14.184.308 contain a critical authentication bypass vulnerability in the local account password reset workflow that allows unauthenticated attackers to perform account takeovers.

Team Password Manager authentication-bypass web-application-security credential-theft
1t 1c
high advisory

Improper Access Control in HyperDX Team Management

HyperDX versions through 1.10.1 contain an improper access control vulnerability allowing authenticated users to perform unauthorized administrative actions via team management API endpoints.

HyperDX privilege-escalation web-application-security
1t 1c
critical advisory

Authentication Bypass in 6Storage Rentals WordPress Plugin

The 6Storage Rentals WordPress plugin contains a critical authentication bypass vulnerability (CVE-2026-15303) that allows unauthenticated attackers to impersonate any user, including administrators, via the six_storage_create_wp_user AJAX handler.

6Storage Rentals wordpress authentication-bypass web-application-security
1r 1t 1c
critical advisory

Stored XSS Vulnerability in OpenClaw Dashboard

An unauthenticated stored XSS vulnerability in the OpenClaw Dashboard allows remote attackers to execute arbitrary JavaScript in administrative sessions via the sessions API.

OpenClaw Dashboard web-application-security xss cve-2026-66421
1t 1c