Hidden Backdoors in npm Packages Let Attackers Wipe Entire Systems

Malicious npm packages found with hidden endpoints that wipe systems on command. Devs warned to check dependencies for express-api-sync,...Read More ...

Continue Reading
CVE-2024-47081 Requests vulnerable to .netrc credentials leak via malicious URLs

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to ve ...

Continue Reading
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter

Summary An authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS saveOutline endpoint allows a low-privileged user to read arbitrary files on the server by manipulating the location fie ...

Continue Reading
Hax CMS Stored Cross-Site Scripting vulnerability

Summary The application does not sufficiently sanitize user input, allowing for the execution of arbitrary JavaScript code. The 'saveNode' and 'saveManifest' endpoints take user in ...

Continue Reading
CVE-2024-47081

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to ve ...

Continue Reading
CVE-2024-47081 Requests vulnerable to .netrc credentials leak via malicious URLs

Requests is a HTTP library. Due to a URL parsing issue, Requests releases prior to 2.32.4 may leak .netrc credentials to third parties for specific maliciously-crafted URLs. Users should upgrade to ve ...

Continue Reading
CVE-2025-5873

creation_timestamp| type| source ---|---|--- 2025-06-09 15:13:54+00:00| seen|...Read More ...

Continue Reading
GHSA-F3PF-R3G7-G895

creation_timestamp| type| source ---|---|--- 2025-06-09 14:53:22+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: