Aggregator
AiLock
You must login to view this content
Submit #802265: BigSweetPotatoStudio HyperChat 2.0.0-alpha.63 Server-Side Request Forgery [Accepted]
CVE-2026-7220 | jackwrichards FastlyMCP up to 6f3d0b0e654fc51076badc7fa16c03c461f95620 fastly_cli Tool fastly-mcp.mjs command os command injection
Submit #802264: code-projects Coaching Management System in PHP Unknown Cross Site Scripting [Accepted]
APT73
You must login to view this content
Submit #802230: TencentCloudBase CloudBase-MCP 2.16.1 Server-Side Request Forgery [Accepted]
ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants
A publicly accessible JavaScript file on ClickUp’s homepage has been silently leaking nearly a thousand corporate and government email addresses, including employees from Fortinet, Home Depot, Tenable, Mayo Clinic, and U.S. state government workers, through a hardcoded third-party API key that was first reported in January 2025 and remains unrotated as of April 2026. The […]
The post ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants appeared first on Cyber Security News.
CVE-2026-7219 | Totolink N300RT 3.4.0-B20250430 /boafrm/formIpQoS entry_name buffer overflow
CVE-2026-7218 | Totolink N300RT 3.4.0-B20250430 libapmib.so /boafrm/formWsc is_cmd_string_valid localPin buffer overflow
Submit #802138: jackwrichards fastly-mcp-server 6f3d0b0e654fc51076badc7fa16c03c461f95620 Command Injection [Accepted]
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
欧洲批准了 Moderna 的流感和 COVID-19 联合疫苗
CVE-2026-7217 | Deepractice PromptX up to 2.4.0 Document File index.ts path absolute path traversal (Issue 571)
Submit #808194: TOTOLINK N300RT Router V3.4.0-B20250430 Buffer Overflow [Accepted]
Submit #802127: Totolink N300RT Router V3.4.0-B20250430 Buffer Overflow [Accepted]
Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit
Kerlab A Rust implementation of Kerberos for FUn and Detection Kerlab was developed just to drill down kerberos protocol and
The post Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit appeared first on Penetration Testing Tools.