CVE-2025-55300 Komari Allows Cross-site WebSocket Hijacking

Komari is a lightweight, self-hosted server monitoring tool designed to provide a simple and efficient solution for monitoring server performance. Prior to 1.0.4-fix1, WebSocket upgrader has disabled ...

Continue Reading
GO-2025-3874 Komari vulnerable to Cross-site WebSocket Hijacking in github.com/komari-monitor/komari

Komari vulnerable to Cross-site WebSocket Hijacking in...Read More ...

Continue Reading
Linux Distros Unpatched Vulnerability : CVE-2020-15133

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available. In faye-websocket before version 0.11.0, there is a lack of cert ...

Continue Reading
PT-2025-33277 · Unknown · Runtime Event System

Name of the Vulnerable Software and Affected Versions: runtime event system (affected versions not specified) Description: A security issue in the runtime event system allows unauthenticated connectio ...

Continue Reading
CVE-2025-9036

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client l ...

Continue Reading
Security Bulletin: IBM QRadar Log Source Management app for IBM QRadar SIEM includes components with known vulnerabilities

Summary The product includes vulnerable components (e.g., framework libraries) that may be identified and exploited with automated tools. IBM QRadar Log Source Management app for IBM QRadar SIEM has a ...

Continue Reading
Rockwell Automation FactoryTalk Action Manager

1. RISK EVALUATION Successful exploitation of this vulnerability could allow a local unauthenticated attacker to listen to communications and manipulate the device. 2. RECOMMENDED PRACTICES CISA recom ...

Continue Reading
EUVD-2025-24814

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client l ...

Continue Reading

Back to Main

Subscribe for the latest news: