The WordPress CMS version was exposed in the XML file at https://hemi.xyz███. This disclosure allowed attackers to fingerprint the CMS...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
The SCIM provisioning feature in HackerOne's sandbox program was vulnerable to account takeover. An attacker could create a user with an email they controlled, import existing users, assign the v ...
Continue ReadingAugust 05, 2025
The vulnerability allowed unauthorized disclosure of private email addresses of WakaTime users through the private leaderboards feature. The email addresses were exposed to leaderboard creators and me ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
A critical vulnerability was identified in the Firefox Accounts API that allowed an authenticated attacker to permanently delete any user's account by sending a POST /v1/account/destroy request u ...
Continue ReadingAugust 05, 2025
Vulnerability description not...Read More ...
Continue ReadingAugust 05, 2025
Back to Main