voidq.xyz is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin account
@hey@voidq.xyz

Search results for tag #cybersecurity

[?]TechWire ⚡ » 🤖 🌐
@techwire@social.gamefan.net

Apple Shelved Two Mac Pro Models, Including an Intel-Based One

Apple developed two Mac Pro models in recent years that never made it to market, according to Bloomberg's Mark Gurman. In his latest "Power On" newsletter, Gurman revealed that Apple internally developed two unreleased …

macrumors.com/2026/07/20/apple

[MacRumors]

    [?]Alonso Caballero / ReYDeS » 🌐
    @Alonso_ReYDeS@infosec.exchange

    🎭 El 90% de los ciberatacantes se esconden en el tráfico legítimo 👁️ Aprende a desenmascarar sus técnicas 🌐 ⚓️ Curso Forense de Redes 2026 💡 Jueves 23, Martes 28, Jueves 30 Julio y Martes 4 Agosto 🏅 De 3:00 pm a 6:00 pm (UTC -05:00) ⚔️ WhatsApp: https://wa.me/51949304030 🎞️ Info: https://www.reydes.com/e/Curso_Forense_de_Redes #DigitalEvidence #DFIR #DigitalForensics #Malware #CyberSecurity #CyberCrime #OSINT

      [?]urlDNA.io :verified: » 🤖 🌐
      @urldna@infosec.exchange

      Possible Phishing 🎣
      on: ⚠️hxxps[:]//exodus[.]webflow[.]io
      🧬 Analysis at: urldna.io/scan/6a5e2a0e3b77500

        [?]TechWire ⚡ » 🤖 🌐
        @techwire@social.gamefan.net

        AirTag 2 Returns to Best-Ever Price of $89 for 4-Pack

        Apple's AirTag 2 is available for the all-time low price of $89.00 this week, down from $99.00. This sale is on the 4-Pack of the AirTag 2, and it's a match of the record low price we last tracked during Prime Day. Note…

        macrumors.com/2026/07/20/airta

        [MacRumors]

          [?]James Cridland » 🌐
          @james@bne.social

          Last July, Qantas leaked private information of 4 million of its customers after a hack.

          The Office of the Australian Information Commissioner has just published its inquiry into that. Apparently it's all fine. Qantas holds your details for seven years, but that's fine. The data was "vished" (voice social engineering), and they really couldn't have done anything more. It's all just fine. Nothing to see here.

          oaic.gov.au/privacy/privacy-as

            [?]TechWire ⚡ » 🤖 🌐
            @techwire@social.gamefan.net

            Get $100 Off AirPods Max 2 With Amazon's New Sale

            Apple's AirPods Max 2 have hit $449.00 on Amazon today, down from $549.00. This sale is available in four colors and it's the best price we've seen on the headphones since Prime Day. Note: MacRumors is an affiliate part…

            macrumors.com/2026/07/20/airpo

            [MacRumors]

              [?]CyberIntel News » 🌐
              @cyberintelnews@mastodon.social

              From the CyberIntel archive: Legacy Vulnerabilities Persist in Financial Services, Healthcare

              cyberintelnews.com/

                [?]urlDNA.io :verified: » 🤖 🌐
                @urldna@infosec.exchange

                Possible Phishing 🎣
                on: ⚠️hxxps[:]//975b1fbf[.]1266b8dd0c622df28d9af103[.]workers[.]dev
                🧬 Analysis at: urldna.io/scan/6a5e31b33b77500

                  [?]EUVD Bot » 🤖 🌐
                  @EUVD_Bot@mastodon.social

                  🚨 EUVD-2026-46138

                  📊 Score: 6.9/10 (CVSS v3.1)
                  📦 Product: DNS-320
                  🏢 Vendor: D-Link
                  📅 Updated: 2026-07-21

                  📝 A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such manipulation of the argument Malicious Handler leads to unrestricted upload. The attack can be executed remotely...

                  🔗 euvd.enisa.europa.eu/vulnerabi

                    [?]EUVD Bot » 🤖 🌐
                    @EUVD_Bot@mastodon.social

                    🚨 EUVD-2026-46137

                    📊 Score: 6.9/10 (CVSS v3.1)
                    📦 Product: DNS-320
                    🏢 Vendor: D-Link
                    📅 Updated: 2026-07-21

                    📝 A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. This manipulation of the argument https:/ucn9h68n9289.feishu.cn/wiki/JJcTwHz7aiKeq6kSItMcoeSUnMc?from=from_copy...

                    🔗 euvd.enisa.europa.eu/vulnerabi

                      [?]EUVD Bot » 🤖 🌐
                      @EUVD_Bot@mastodon.social

                      🚨 EUVD-2026-46136

                      📊 Score: 6.9/10 (CVSS v3.1)
                      📦 Product: DNS-320
                      🏢 Vendor: D-Link
                      📅 Updated: 2026-07-21

                      📝 A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation of the argument Malicious Handler leads to unrestricted upload. The attack may be initiated remotely. The exp...

                      🔗 euvd.enisa.europa.eu/vulnerabi

                        [?]Daily CyberSecurity » 🌐
                        @DailyCyberSecurity@infosec.exchange

                        LG monitor adware installs itself via Windows device metadata and pushes McAfee pop-ups. Learn how a Group Policy tweak blocks the unwanted software.

                        securityonline.info/lg-monitor

                          [?]Linux Association of Canada » 🌐
                          @linuxassociation@thecanadian.social

                          🔒 Cybersecurity Monday
                          One of the simplest ways to improve your security is to keep your software up to date.
                          Updates don't just add new features—they fix vulnerabilities that attackers actively look for.
                          ✔️ Install security updates promptly. ✔️ Update your operating system and applications. ✔️ Don't forget your router and other network devices.
                          A few minutes today can prevent hours of recovery tomorrow.

                          A clean cybersecurity awareness infographic on a white background titled "Cybersecurity Monday – Patch Today, Protect Tomorrow." A laptop displaying "Update Complete" sits at the center, connected to a smartphone, server, router, and tablet, each showing update icons to emphasize keeping all devices current. A large green shield symbolizes security, with a faint map of Canada in the background. A checklist reminds users to update their operating system, applications, browser, router, remove unused software, and back up important data. A comparison at the bottom illustrates that unpatched vulnerabilities can be exploited, while updated systems are protected. The official Linux Association of Canada logo appears in the bottom-right corner.

                          Alt...A clean cybersecurity awareness infographic on a white background titled "Cybersecurity Monday – Patch Today, Protect Tomorrow." A laptop displaying "Update Complete" sits at the center, connected to a smartphone, server, router, and tablet, each showing update icons to emphasize keeping all devices current. A large green shield symbolizes security, with a faint map of Canada in the background. A checklist reminds users to update their operating system, applications, browser, router, remove unused software, and back up important data. A comparison at the bottom illustrates that unpatched vulnerabilities can be exploited, while updated systems are protected. The official Linux Association of Canada logo appears in the bottom-right corner.

                            [?]ChiefGyk3D » 🌐
                            @chiefgyk3d@social.chiefgyk3d.com

                            🔴 Get ready to level up your skills!

                            Chiefgyk3d is live, prepping new tools for the EDC|Hacker Summer Camp (in 2 weeks!). Expect cybersecurity deep dives, some rants, chill Linux vibes, and gaming. 🎮

                            Let's build something awesome!

                            twitch.tv/chiefgyk3d

                            🔴 LIVE • 5 viewers • Just Chatting

                            Alt...🔴 LIVE • 5 viewers • Just Chatting

                              [?]ChiefGyk3D » 🌐
                              @chiefgyk3d@social.chiefgyk3d.com

                              Chiefgyk3d is LIVE! 🔴

                              Get ready for a deep dive! 🤓 New tools for the EDC Hacker Summer Camp are on deck, plus some cybersecurity rants, chill vibes, and gaming on Linux. Let's build and watch the chaos unfold. 🎮

                              youtube.com/@chiefgyk3d/live

                              🔴 LIVE

                              Alt...🔴 LIVE

                                [?]ChiefGyk3D » 🌐
                                @chiefgyk3d@social.chiefgyk3d.com

                                Alright, let's dive in! 💻

                                New tools for the EDC Hacker Summer Camp are on deck! 🏕️

                                Cybersecurity deep dives, rants, chill vibes, and some Linux gaming to boot. 🎮

                                Two weeks 'til the camp – prepping now! Come watch the chaos unfold. 😉

                                kick.com/chiefgyk3d

                                🔴 LIVE • 1 viewers • Just Chatting

                                Alt...🔴 LIVE • 1 viewers • Just Chatting

                                  [?]Daily CyberSecurity » 🌐
                                  @DailyCyberSecurity@infosec.exchange

                                  Linux kernel CVEs surged to 440 advisories in just 24 hours, with many flaws found by AI. Most are already patched, so update your kernel promptly.

                                  securityonline.info/linux-kern

                                    [?] Politico.eu (Unofficial RSS) » 🤖 🌐
                                    @politico_eu_bot@social.espeweb.net

                                    [?]TheHackerWire » 🤖 🌐
                                    @thehackerwire@mastodon.social

                                    🟠 CVE-2026-47198 - High (8.5)

                                    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pair...

                                    🔗 thehackerwire.com/vulnerabilit

                                    CVE Alert: CVE-2026-47198

                                    Alt...CVE Alert: CVE-2026-47198

                                      [?]TheHackerWire » 🤖 🌐
                                      @thehackerwire@mastodon.social

                                      🔴 CVE-2026-53595 - Critical (9.4)

                                      FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `...

                                      🔗 thehackerwire.com/vulnerabilit

                                      CVE Alert: CVE-2026-53595

                                      Alt...CVE Alert: CVE-2026-53595

                                        [?]TheHackerWire » 🤖 🌐
                                        @thehackerwire@mastodon.social

                                        🟠 CVE-2026-56452 - High (7.5)

                                        Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.

                                        The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" co...

                                        🔗 thehackerwire.com/vulnerabilit

                                        CVE Alert: CVE-2026-56452

                                        Alt...CVE Alert: CVE-2026-56452

                                          [?]TechWire ⚡ » 🤖 🌐
                                          @techwire@social.gamefan.net

                                          The PlayStation replica ornament is an homage to a great, yet fragile console

                                          The ornament requires three 1.5-volt coin batteries, which are included in the box. | Photo: Cameron Faulkner/The Verge You probably know the signature PlayStation boot sound. Did you know that it's technically a multi-…

                                          theverge.com/tech/967989/hallm

                                          [The Verge]

                                            [?]TechWire ⚡ » 🤖 🌐
                                            @techwire@social.gamefan.net

                                            Get Borderlands 3, Risk of Rain 2 and 13 other great PC games for $15

                                            Borderlands 3 is among the 15 games in the 2K Megahits 2026 Bundle. | 2K Games The aptly-named “2K Megahits 2026 Bundle” from Humble includes 15 Steam games for $15. It’s a smattering of the publisher 2K’s biggest games…

                                            theverge.com/gadgets/968191/hu

                                            [The Verge]

                                              [?]TechWire ⚡ » 🤖 🌐
                                              @techwire@social.gamefan.net

                                              Samsung Galaxy Card announced: Say hello to Samsung’s first credit card in US

                                              Samsung says its credit card offers a range of benefits, but no annual fees.

                                              androidauthority.com/samsung-g

                                              [Android Authority]

                                                [?]TechWire ⚡ » 🤖 🌐
                                                @techwire@social.gamefan.net

                                                Best Galaxy Z Fold 8 images yet show off Samsung’s wide foldable before Unpacked

                                                Galaxy Unpacked is right around the corner, and the leaks are rolling in.

                                                androidauthority.com/galaxy-z-

                                                [Android Authority]

                                                  [?]TechWire ⚡ » 🤖 🌐
                                                  @techwire@social.gamefan.net

                                                  Samsung Galaxy S26 FE and Galaxy Tab S12 make an early appearance on the road to launch

                                                  Forget foldables: Evidence is already arriving for Samsung's next big launches

                                                  androidauthority.com/galaxy-s2

                                                  [Android Authority]

                                                    [?]TechWire ⚡ » 🤖 🌐
                                                    @techwire@social.gamefan.net

                                                    SpaceX in your index fund, explained

                                                    AUUUUUGH | Image: Cath Virginia / The Verge, Getty Images Index funds are touted as one of the safest ways to invest. Rather than picking and choosing individual stocks, index funds let you bet on the market as a whole.…

                                                    theverge.com/business/968257/s

                                                    [The Verge]

                                                      [?]Jason » 🌐
                                                      @machine@social.tchncs.de

                                                      Let us hope that many more of Starmer's harebrained, anti-people, economy destroying, ill-informed, subhuman schemes get scrapped.

                                                      Good move, Burnham. Send my share of the £1.8bn to me directly and asap, please.

                                                      bbc.com/news/articles/c5y08z25

                                                        [?]PrivacyDigest » 🌐
                                                        @PrivacyDigest@mas.to

                                                        Pay up or not? surge has victims facing tough choices.

                                                        Nearly half of companies that are targets of a ransomware end up paying a to release their data or systems, according to 2025 research from group , while the median amount demanded is rising.

                                                        arstechnica.com/security/2026/

                                                          [?]PrivacyDigest » 🌐
                                                          @PrivacyDigest@mas.to

                                                          [?]EUVD Bot » 🤖 🌐
                                                          @EUVD_Bot@mastodon.social

                                                          🚨 EUVD-2026-46100

                                                          📊 Score: 6.3/10 (CVSS v3.1)
                                                          📦 Product: rsync
                                                          🏢 Vendor: RsyncProject
                                                          📅 Updated: 2026-07-20

                                                          📝 Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fixes for symlink races in open() calls missed races in other path based system calls like chmod() and chown(...

                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                            [?]EUVD Bot » 🤖 🌐
                                                            @EUVD_Bot@mastodon.social

                                                            🚨 EUVD-2026-46099

                                                            📊 Score: 7.5/10 (CVSS v3.1)
                                                            📦 Product: Apache Mina SSHD, Apache Mina SSHD
                                                            🏢 Vendor: Apache Software Foundation
                                                            📅 Updated: 2026-07-20

                                                            📝 Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.

                                                            The implementation of receiving files or directories via SCP did not valid...

                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                              [?]EUVD Bot » 🤖 🌐
                                                              @EUVD_Bot@mastodon.social

                                                              🚨 EUVD-2026-46098

                                                              📊 Score: 6.3/10 (CVSS v3.1)
                                                              📦 Product: @ai-sdk/harness-opencode
                                                              🏢 Vendor: vercel
                                                              📅 Updated: 2026-07-20

                                                              📝 The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (`host-to...

                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                [?]EUVD Bot » 🤖 🌐
                                                                @EUVD_Bot@mastodon.social

                                                                🚨 EUVD-2026-46097

                                                                📊 Score: 5.3/10 (CVSS v3.1)
                                                                📦 Product: Paymenter
                                                                🏢 Vendor: Paymenter
                                                                📅 Updated: 2026-07-20

                                                                📝 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an activ...

                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                  [?]EUVD Bot » 🤖 🌐
                                                                  @EUVD_Bot@mastodon.social

                                                                  🚨 EUVD-2026-46096

                                                                  📊 Score: 8.5/10 (CVSS v3.1)
                                                                  📦 Product: Paymenter
                                                                  🏢 Vendor: Paymenter
                                                                  📅 Updated: 2026-07-20

                                                                  📝 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into ...

                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                    [?]EUVD Bot » 🤖 🌐
                                                                    @EUVD_Bot@mastodon.social

                                                                    🚨 EUVD-2026-46095

                                                                    📊 Score: 5.3/10 (CVSS v3.1)
                                                                    📦 Product: freescout
                                                                    🏢 Vendor: freescout-help-desk
                                                                    📅 Updated: 2026-07-20

                                                                    📝 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with uploa...

                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                      [?]TheHackerWire » 🤖 🌐
                                                                      @thehackerwire@mastodon.social

                                                                      🟠 CVE-2026-44508 - High (8.1)

                                                                      Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's compressed-token decoder accumulated a 32-bit signed counter without checking for overflow. A mali...

                                                                      🔗 thehackerwire.com/vulnerabilit

                                                                      CVE Alert: CVE-2026-44508

                                                                      Alt...CVE Alert: CVE-2026-44508

                                                                        [?]EUVD Bot » 🤖 🌐
                                                                        @EUVD_Bot@mastodon.social

                                                                        🚨 EUVD-2026-46094

                                                                        📊 Score: 9.4/10 (CVSS v3.1)
                                                                        📦 Product: freescout
                                                                        🏢 Vendor: freescout-help-desk
                                                                        📅 Updated: 2026-07-20

                                                                        📝 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by it...

                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                          [?]EUVD Bot » 🤖 🌐
                                                                          @EUVD_Bot@mastodon.social

                                                                          🚨 EUVD-2026-46095

                                                                          📊 Score: 5.3/10 (CVSS v3.1)
                                                                          📦 Product: freescout
                                                                          🏢 Vendor: freescout-help-desk
                                                                          📅 Updated: 2026-07-20

                                                                          📝 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with uploa...

                                                                          🔗 euvd.enisa.europa.eu/vulnerabi

                                                                            [?]EUVD Bot » 🤖 🌐
                                                                            @EUVD_Bot@mastodon.social

                                                                            🚨 EUVD-2026-46094

                                                                            📊 Score: 9.4/10 (CVSS v3.1)
                                                                            📦 Product: freescout
                                                                            🏢 Vendor: freescout-help-desk
                                                                            📅 Updated: 2026-07-20

                                                                            📝 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by it...

                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                              [?]EUVD Bot » 🤖 🌐
                                                                              @EUVD_Bot@mastodon.social

                                                                              🚨 EUVD-2026-46093

                                                                              📊 Score: 8.7/10 (CVSS v3.1)
                                                                              📦 Product: Clinic, Clinic
                                                                              🏢 Vendor: VSee
                                                                              📅 Updated: 2026-07-20

                                                                              📝 VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belongin...

                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                [?]EUVD Bot » 🤖 🌐
                                                                                @EUVD_Bot@mastodon.social

                                                                                🚨 EUVD-2026-46093

                                                                                📊 Score: 8.7/10 (CVSS v3.1)
                                                                                📦 Product: Clinic, Clinic
                                                                                🏢 Vendor: VSee
                                                                                📅 Updated: 2026-07-20

                                                                                📝 VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belongin...

                                                                                🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                  [?]EUVD Bot » 🤖 🌐
                                                                                  @EUVD_Bot@mastodon.social

                                                                                  🚨 EUVD-2026-46092

                                                                                  📊 Score: 4.9/10 (CVSS v3.1)
                                                                                  📦 Product: freescout
                                                                                  🏢 Vendor: freescout-help-desk
                                                                                  📅 Updated: 2026-07-20

                                                                                  📝 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then p...

                                                                                  🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                    [?]EUVD Bot » 🤖 🌐
                                                                                    @EUVD_Bot@mastodon.social

                                                                                    🚨 EUVD-2026-46092

                                                                                    📊 Score: 4.9/10 (CVSS v3.1)
                                                                                    📦 Product: freescout
                                                                                    🏢 Vendor: freescout-help-desk
                                                                                    📅 Updated: 2026-07-20

                                                                                    📝 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then p...

                                                                                    🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                      [?]EUVD Bot » 🤖 🌐
                                                                                      @EUVD_Bot@mastodon.social

                                                                                      🚨 EUVD-2026-46091

                                                                                      📊 Score: 9.0/10 (CVSS v3.1)
                                                                                      📦 Product: Clinic, Clinic
                                                                                      🏢 Vendor: VSee
                                                                                      📅 Updated: 2026-07-20

                                                                                      📝 VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the applicatio...

                                                                                      🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                        [?]EUVD Bot » 🤖 🌐
                                                                                        @EUVD_Bot@mastodon.social

                                                                                        🚨 EUVD-2026-46090

                                                                                        📊 Score: 5.4/10 (CVSS v3.1)
                                                                                        📦 Product: Paymenter
                                                                                        🏢 Vendor: Paymenter
                                                                                        📅 Updated: 2026-07-20

                                                                                        📝 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated us...

                                                                                        🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                          [?]TheHackerWire » 🤖 🌐
                                                                                          @thehackerwire@mastodon.social

                                                                                          🟠 CVE-2026-47129 - High (8.1)

                                                                                          NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails t...

                                                                                          🔗 thehackerwire.com/vulnerabilit

                                                                                          CVE Alert: CVE-2026-47129

                                                                                          Alt...CVE Alert: CVE-2026-47129

                                                                                            [?]EUVD Bot » 🤖 🌐
                                                                                            @EUVD_Bot@mastodon.social

                                                                                            🚨 EUVD-2026-46089

                                                                                            📊 Score: 5.3/10 (CVSS v3.1)
                                                                                            📦 Product: Paymenter
                                                                                            🏢 Vendor: Paymenter
                                                                                            📅 Updated: 2026-07-20

                                                                                            📝 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the PAYPAL-CERT-URL HTTP header without validation, allowing attackers t...

                                                                                            🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                              [?]EUVD Bot » 🤖 🌐
                                                                                              @EUVD_Bot@mastodon.social

                                                                                              🚨 EUVD-2026-46091

                                                                                              📊 Score: 9.0/10 (CVSS v3.1)
                                                                                              📦 Product: Clinic, Clinic
                                                                                              🏢 Vendor: VSee
                                                                                              📅 Updated: 2026-07-20

                                                                                              📝 VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the applicatio...

                                                                                              🔗 euvd.enisa.europa.eu/vulnerabi

                                                                                                [?]TheHackerWire » 🤖 🌐
                                                                                                @thehackerwire@mastodon.social

                                                                                                🔴 CVE-2026-63766 - Critical (9.8)

                                                                                                GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attacker...

                                                                                                🔗 thehackerwire.com/vulnerabilit

                                                                                                CVE Alert: CVE-2026-63766

                                                                                                Alt...CVE Alert: CVE-2026-63766

                                                                                                  Back to top - More...