MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed ...
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow a...
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection hand...
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write fil...
IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass t...
CVE-2026-26030 — Semantic Kernel filter eval RCE lab A self-contained, network-isolated Docker lab reproducing CVE-2026-26030: prompt-injectable re...
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSdS_7552zEvsn5xVfDcVMG2u8ponFIE1E65j5A8Wx-qUroU49h-f6qF7FPCABA063IjNnw-JntL-L1iZjHp...
No description provided...
Log4Shell – Technical Overview & PoC Made in May 2026 by Robin Köhler and Darian Rashed as part of the lecture Secure Software Testing at Hochschul...
CVE-2026-48908 — SP Page Builder Joomla Unauthenticated RCE Proof-of-concept exploit for CVE-2026-48908, a critical CVSS 4.0 = 10.0 unauthenticated...
AI-powered asset discovery, dark web monitoring, CVE alerting, and vulnerability scanning — all in one platform.