Recent Advisories

Severity ID Title Vendor Product Date Type
NONE 5A30AF6D-A3F1-

MamaBaohe-ERP-SQLi_5A30AF6D-A3F1-5C05-9042-C5ED3EF4AAB8

MamaBaohe ERP Management Cloud Platform SQL Injection Overview | Field | Value | |-------|-------| | Product | Maternal and Child Health ERP Manage...

N/A N/A GITHUBEXPLOIT
NONE WIRED:A213F3A81...

The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials_WIRED:A213F3A81A603E96CA725AEEADB603F7

Exposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special o...

N/A N/A WIRED
NONE SCHNEIER:DF7402...

Meta Is Testing Facial Recognition for Police and Military_SCHNEIER:DF74028FA7E40C4996C0D41330A90633

We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the featu...

N/A N/A SCHNEIER
NONE PACKETSTORM:224373

📄 Penpot Server-Side Request Forgery_PACKETSTORM:224373

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin server-side request forge...

N/A N/A PACKETSTORM
NONE PACKETSTORM:224403

📄 phpSysInfo 3.4.5 IP Allowlist Bypass_PACKETSTORM:224403

phpSysInfo versions 3.4.5 and below suffer from an IP Allowlist bypass vulnerability...

N/A N/A PACKETSTORM
NONE PACKETSTORM:224409

📄 Peyara Remote Mouse 1.0.1 Unauthenticated Remote Code Execution_PACKETSTORM:224409

This Metasploit module exploits an unauthenticated remote code execution vulnerability in Peyara Remote Mouse 1.0.1. The application exposes a Sock...

N/A N/A PACKETSTORM
NONE F6F142F3-3C4F-

pocsmith_F6F142F3-3C4F-57A3-A265-A7DF88A31A6B

pocsmith pocsmith generates modular Python proof-of-concept templates from alias flags or YAML profiles. Install From GitHub with pipx: bash pipx i...

N/A N/A GITHUBEXPLOIT
NONE B6A66232-7621-

Sql-injection-scanner_B6A66232-7621-5872-A51D-EDDA3F824073

Sql-injection-scanner Developing a security scanning tool that can quickly, reliably, and automatically detect SQL Injection vulnerabilities in web...

N/A N/A GITHUBEXPLOIT
NONE THN:7A6FC6E72B7...

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign_THN:7A6FC6E72B7906A66B33E84A6B61E75E

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHsYcZgd4WIkN0k-b4_j7JxBgi0R0dzj0jSwSWVgItyIy88VoZK5z8BAiwjmYnou7YLrNuckCgQvnHXV2KYH...

N/A N/A THN
NONE H1:3823932

curl: CURLOPT_HAPROXY_CLIENT_IP lacks input validation, enabling HAProxy PROXY protocol injection_H1:3823932

Summary The CURLOPT_HAPROXY_CLIENT_IP option accepts an arbitrary string without validating that it is a valid IP address, and without stripping...

N/A N/A HACKERONE