Recent Advisories

Severity ID Title Vendor Product Date Type
NONE 9042DEEE-229C-

htb-myexpense-writeup_9042DEEE-229C-53AA-9DA3-C793FB7DDFA1

htb-myexpense-writeup VulnHub MyExpense — Stored XSS, Session Hijacking, SQLi...

N/A N/A GITHUBEXPLOIT
NONE 404E68B4-550F-

Exploit for CVE-2026-8206_404E68B4-550F-51C1-B107-460F8E9F767F

No description provided...

N/A N/A GITHUBEXPLOIT
NONE ECAFE318-F67E-

cve-arsenal_ECAFE318-F67E-5F49-8E24-3AAFF9AFFAE0

cve-arsenal Personal collection of exploit PoCs...

N/A N/A GITHUBEXPLOIT
NONE PACKETSTORM:222419

📄 Lightweight Music Server 3.76.0 Cross Site Scripting_PACKETSTORM:222419

Lightweight Music Server version 3.76.0 suffers from a persistent cross site scripting vulnerability. LMS stores media file metadata tags such as G...

N/A N/A PACKETSTORM
NONE PACKETSTORM:222366

📄 Espanso 2.3.0 Configuration Injection_PACKETSTORM:222366

This Python script is a configuration manipulation tool for Espanso version 2.3.0 that modifies its YAML configuration file base.yml to add new tex...

N/A N/A PACKETSTORM
NONE KREBS:F646A4A7A...

Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts_KREBS:F646A4A7AC6701E17849AA460AA338BB

The **Instagram** accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian im...

N/A N/A KREBS
NONE SCHNEIER:0737B7...

Vulnerability Disclosure in the Age of AI_SCHNEIER:0737B7D951E4C1370C0BCC5CC74FCBA8

New article: "Responsible Disclosure in the Age of AI: A Call for Urgent Action," by Melissa Hathaway. > **Abstract:** Artificial intelligence is ...

N/A N/A SCHNEIER
NONE HACKREAD:BFD957...

What One Predator Case Can Reveal About an Online Platform’s Safety Gaps_HACKREAD:BFD957787CFAF897170D256FED069C5E

When a predator contacts a child through an online platform, the details of how it happened often expose…

N/A N/A HACKREAD
NONE THN:4F197FF556F...

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm_THN:4F197FF556F916E3B86A5FBAB335549D

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOyc2NTiIl0XKOTZBsFh1bTPqNpVXfDhASWkCsYz17d-nbiWVKlxCzoq3WthMD8kMomrRPPOYLM-XRmSdtXN...

N/A N/A THN
NONE PACKETSTORM:222360

📄 dmonitor 1.0.3 Server-Side Request Forgery / Redis Enumeration_PACKETSTORM:222360

Proof of concept demonstration exploit for dmonitor version 1.0.3 that leverages an unauthenticated server-side request forgery vulnerability to de...

N/A N/A PACKETSTORM