Tag
Chromium Use-After-Free in Extensions
1 CVEA use-after-free vulnerability in the Chromium Extensions component allows for potential arbitrary code execution or application instability across affected browsers.
Cross-Site Scripting Vulnerability in jsoup Library
1 TTP 1 CVEA vulnerability in the jsoup library allows a remote attacker to execute arbitrary scripts in the context of a user's browser via Cross-Site Scripting (XSS).
Guzzle Hostname Validation Bypass via Transport Discrepancy
1 TTP 1 CVEGuzzle versions before 7.15.2 and 8.0.1 are vulnerable to a host-based security check bypass where transport handlers interpret non-canonical URI hostnames differently than application-level validation, potentially enabling SSRF.
Open Redirect Vulnerability in better-auth via trustedOrigins Bypass
1 TTP 1 CVEThe better-auth library contains a vulnerability in its trustedOrigins validation logic that allows attackers to perform open redirects and steal sensitive tokens by manipulating the callbackURL parameter.
VaahCMS OTP Template Cross-Site Scripting and Code Execution
3 TTPs 1 CVEVaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload in OTP email templates that executes unauthorized code in victim browsers, enabling credential theft and DOM manipulation.
SSRF Bypass Vulnerability in V Library
1 TTP 1 CVEThe V library (versions 0.5.2 and below) contains a server-side request forgery (SSRF) bypass vulnerability allowing attackers to circumvent host-based allowlists via URL parsing differentials.
Suspicious User-Agents Related To Recon Tools
1 rule 3 TTPsThis brief details the detection of reconnaissance and scanning tools through their characteristic User-Agent strings observed in web server logs, providing an early warning of potential targeted scanning activity against public-facing applications by adversaries seeking initial access.