Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

CERT Coordination Center

@certcc@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Report a vulnerability at https://kb.cert.org/vuls/report/

17 Followers
0 Following
23 Posts
Joined March 24, 2025
Vulnerability Notes:
kb.cert.org
Open post
CERT Coordination Center @certcc@infosec.exchange
· 4w ago
VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability https://kb.cert.org/vuls/id/943094 Overview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connections. An authenticated administrator can exploit this flaw to coerce the
kb.cert.org
1
0
1
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
Thank you @ESETresearch@infosec.exchange for working with us to responsibly disclose this UEFI vulnerability. Read the corresponding vul note at https://infosec.exchange/@certcc/116773242369763326 Interested in doing more #UEFI vulnerability discovery work? Check out the cert-uefi-parser on GitHub and PyPI.
infosec.exchange
2
0
2
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#492466: Logto Identity Platform has authentication and authorization failures in core protocol handling https://kb.cert.org/vuls/id/492466 Overview The Logto platform contains multiple vulnerabilities affecting the identity‑processing pipeline. These flaws reduce the reliability of authentication and authorization decisions and may allow attackers to bypass account‑ownership checks, skip MFA, replay externally issued SSO responses, or submit identity assertions without proper cryptographic
kb.cert.org
1
0
1
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability https://kb.cert.org/vuls/id/847406
Overview
Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:Program FilesDuplicati 2 directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this

kb.cert.org
1
0
1
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 3mo ago
VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities https://kb.cert.org/vuls/id/152953 Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. Description A vulnerability (CVE-2026-13462) exists in the PayRange Android app that causes invalid
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

RE: https://infosec.exchange/@ESETresearch/116917582564392811

Thank you @ESETresearch@infosec.exchange for working with us to responsibly disclose this UEFI vulnerability.

Read the @certcc@infosec.exchange

Interested in doing more #UEFI vulnerability discovery work? Check out the cert-uefi-parser on GitHub and PyPI.

infosec.exchange
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#725167: node-forge Signature Forgery Vulnerabilities in RSA-PKCS and ED25519 Implementations https://kb.cert.org/vuls/id/725167 Overview Two distinct cryptographic signature verification vulnerabilities exist in Digital Bazaar node-forge, a widely used JavaScript library implementing cryptographic primitives for Node.js and browser environments. These vulnerabilities allow attackers to forge RSA (PKCS#1 v1.5) and Ed25519 signatures under specific, exploitable conditions. Description Both
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys https://kb.cert.org/vuls/id/529388 Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#360868: Analog Way Picturall Quad Compact Mark II contains a local privilege escalation vulnerability https://kb.cert.org/vuls/id/360868 Overview Version 3.5.8 of Analog Way's Picturall Quad Compact Mark II server contains a local privilege escalation vulnerability, tracked as CVE-2026-14985, due to improper privilege delegation and insufficient input validation in a maintenance script. Description The Picturall Quad Compact Mark II is a compact, heavy-duty 8K media server developed by
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#141367: AT&T's Arris BGW210-700 gateway contains authentication bypass vulnerability in LAN-side management interface https://kb.cert.org/vuls/id/141367 Overview Firmware versions 2.7.7 and earlier of the Arris BGW210-700 residential gateway contain an authentication bypass vulnerability, tracked as CVE-2026-16771, that allows any unauthenticated LAN-side user to read sensitive configuration data and modify device settings through web management endpoints. Although this vulnerability was
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure https://kb.cert.org/vuls/id/305509 Overview A vulnerability has been discovered in the OPeNDAP Hyrax software solution. A remote attacker with the ability to submit crafted requests to an affected Hyrax instance could cause the application to communicate with unauthorized remote systems. Under certain conditions, the vulnerability may also result in the unintended disclosure of user authentication tokens to unauthorized
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS) https://kb.cert.org/vuls/id/293714 Overview A vulnerability in the zipx.Unzip extraction routine of Develar’s app-builder allows an attacker to overwrite arbitrary files on macOS using Apple File System (APFS). The issue arises from a combination of Unicode normalization collisions and unsafe symlink-following behavior. APFS treats certain Unicode equivalent filenames as identical
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago
VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities https://kb.cert.org/vuls/id/790363 Overview Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level authorization check, which lets a user retrieve any other customer's full profile, payment token,
kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#487613: Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations https://kb.cert.org/vuls/id/487613
Overview
A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings.
Description
Alinto SOGo is an open-source

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities https://kb.cert.org/vuls/id/243636
Overview
VPS.org's one-click deployment templates provision services with default passwords and predefined network bindings instead of generating randomized secrets or applying per-deployment hardening measures.
Description
VPS.org is a cloud and virtual private server hosting provider that offers a library of templates for quickly provisioning common applications and services.

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#281278: SGLang contains six different vulnerabilities including RCE, data exfiltration, and credential disclosure https://kb.cert.org/vuls/id/281278
Overview
Six vulnerabilities have been discovered within the SGLang project, including remote code execution (RCE), server-side request forgery (SSRF), local file read, credential leakage, and model weight exfiltration on a target server. Exploitation does not require authentication in most cases, and some vulnerabilities require only network

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#762226: Plane contains multi-tenant authorization bypass vulnerability https://kb.cert.org/vuls/id/762226
Overview
The project management tool Plane, versions 1.3.0 and earlier, contains a multi-tenant authorization bypass vulnerability in its asset-management API that allows unauthorized users to access, delete, or duplicate assets that belong to other workspaces.
Description
Plane is an open-source project management platform that provides multi-tenant workspace isolation for users to

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions https://kb.cert.org/vuls/id/885548
Overview
A denial-of-service (DoS) vulnerability exists in some HTTP/2 server implementations that fail to adequately limit resource consumption when buffering response data under stalled flow-control conditions. A remote, unauthenticated attacker can trigger memory exhaustion and service interruption by using standard flow-control parameters such as

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#326070: SGLang contains a vulnerable pickle deserialization vulnerability through the expert-parallel subsystem https://kb.cert.org/vuls/id/326070
Overview
A Pickle deserialization vulnerability has been discovered within the SGLang project, enabling an attacker to perform remote code execution (RCE) on the target vulnerable server. In order for an attacker to exploit this vulnerability, the expert-parallel backup subsystem must be enabled, and an attacker must have network access to the

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 2mo ago

VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs https://kb.cert.org/vuls/id/564823
Overview
GNU Wget, versions 1.25.0 and earlier, contains a server-side request forgery (SSRF) vulnerability in its implementation of FTP passive mode. Because Wget does not properly validate IP addresses obtained from PASV responses, an attacker-controlled FTP endpoint can redirect the client’s connection to arbitrary IPs, potentially exposing internal network host and service responses. This vuln

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 3mo ago

VU#734812: Xerte Online Toolkit contains an authentication bypass that allows for RCE https://kb.cert.org/vuls/id/734812
Overview
Two vulnerabilities have been discovered in Xerte Online Toolkits, an open-source e-learning authoring toolsuite intended for the creation of learning materials within a web browser. CVE-2026-14261 tracks the persistence of the /setup/ directory after installation, which allows an unauthenticated attacker to reconfigure the application to point to a remote database

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 3mo ago

VU#849433: Adalo Database API Enables Cross-App User Data Extraction via Over-Fetching and Missing Authorization Controls https://kb.cert.org/vuls/id/849433
Overview
Adalo’s no‑code application platform exposes complete user records through its database API for all applications built on both V1 and V2. Due to a platform-level flaw, authenticated users can retrieve full user data belonging to any Adalo application, regardless of configuration. This issue affects more than one million

kb.cert.org
0
0
0
0
Open post
CERT Coordination Center @certcc@infosec.exchange
· 4w ago
VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability https://kb.cert.org/vuls/id/859658 Overview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from the owner. Description The Skullcandy Dime 3 (Model S2DCW) wireless earbuds,
kb.cert.org
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:44:10 UTC