Tag

#Application Security

65 published stories tagged with Application Security.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: Vvveb Cron Controller Information Disclosure Exposes Secret Cron Key

Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that can expose the application secret cron key to unauthenticated attackers.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: Vvveb Cron Controller Information Disclosure Exposes Secret Cron Key

Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that can expose the application secret cron key to unauthenticated attackers.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: Vvveb Cron Controller Information Disclosure Exposes Secret Cron Key

Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that can expose the application secret cron key to unauthenticated attackers.

criticalApplication SecurityMay 8, 2026·4 min read

Brief: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

criticalApplication SecurityMay 8, 2026·4 min read

Defender Guidance: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

criticalApplication SecurityMay 8, 2026·4 min read

Detection Notes: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

criticalApplication SecurityMay 8, 2026·4 min read

Risk Brief: LiteLLM Proxy Pre-Authentication SQL Injection Exploited Shortly After Disclosure

LiteLLM disclosed a SQL injection vulnerability in the proxy API key verification path. The project says versions v1.81.16 through v1.83.6 are affected and recommends upgrading to v1.83.10-stable.

highApplication SecurityMay 8, 2026·4 min read

Brief: electerm Arbitrary Local Code Execution Fixed in Version 3.8.15

electerm versions 3.0.6 through before 3.8.15 are vulnerable to arbitrary local code execution through deep links, CLI options, or crafted shortcuts.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: electerm Arbitrary Local Code Execution Fixed in Version 3.8.15

electerm versions 3.0.6 through before 3.8.15 are vulnerable to arbitrary local code execution through deep links, CLI options, or crafted shortcuts.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: electerm Arbitrary Local Code Execution Fixed in Version 3.8.15

electerm versions 3.0.6 through before 3.8.15 are vulnerable to arbitrary local code execution through deep links, CLI options, or crafted shortcuts.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: electerm Arbitrary Local Code Execution Fixed in Version 3.8.15

electerm versions 3.0.6 through before 3.8.15 are vulnerable to arbitrary local code execution through deep links, CLI options, or crafted shortcuts.

highApplication SecurityMay 8, 2026·4 min read

Brief: Kimai Invoice Template Vulnerability Can Expose Files Readable by PHP Worker

Kimai versions 2.32.0 to before 2.56.0 allow users with System-Admin role and upload_invoice_template permission to embed files readable by the PHP worker into rendered invoice PDFs.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: Kimai Invoice Template Vulnerability Can Expose Files Readable by PHP Worker

Kimai versions 2.32.0 to before 2.56.0 allow users with System-Admin role and upload_invoice_template permission to embed files readable by the PHP worker into rendered invoice PDFs.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: Kimai Invoice Template Vulnerability Can Expose Files Readable by PHP Worker

Kimai versions 2.32.0 to before 2.56.0 allow users with System-Admin role and upload_invoice_template permission to embed files readable by the PHP worker into rendered invoice PDFs.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: Kimai Invoice Template Vulnerability Can Expose Files Readable by PHP Worker

Kimai versions 2.32.0 to before 2.56.0 allow users with System-Admin role and upload_invoice_template permission to embed files readable by the PHP worker into rendered invoice PDFs.

criticalApplication SecurityMay 8, 2026·4 min read

Brief: TUBITAK Liderahenk Origin Validation Error Enables Improper ACL-Constrained Access

CERT Turkey reported an origin validation error vulnerability in Liderahenk that allows accessing functionality not properly constrained by ACLs.

criticalApplication SecurityMay 8, 2026·4 min read

Defender Guidance: TUBITAK Liderahenk Origin Validation Error Enables Improper ACL-Constrained Access

CERT Turkey reported an origin validation error vulnerability in Liderahenk that allows accessing functionality not properly constrained by ACLs.

criticalApplication SecurityMay 8, 2026·4 min read

Detection Notes: TUBITAK Liderahenk Origin Validation Error Enables Improper ACL-Constrained Access

CERT Turkey reported an origin validation error vulnerability in Liderahenk that allows accessing functionality not properly constrained by ACLs.

criticalApplication SecurityMay 8, 2026·4 min read

Risk Brief: TUBITAK Liderahenk Origin Validation Error Enables Improper ACL-Constrained Access

CERT Turkey reported an origin validation error vulnerability in Liderahenk that allows accessing functionality not properly constrained by ACLs.

highApplication SecurityMay 8, 2026·4 min read

Brief: PicoTronica e-Clinic Healthcare System Information Disclosure Fixed in Version 5.7.1

PicoTronica e-Clinic Healthcare System ECHS 5.7 contains an information disclosure vulnerability in the /cdemos/echs/api/v2/ response header handling component.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: PicoTronica e-Clinic Healthcare System Information Disclosure Fixed in Version 5.7.1

PicoTronica e-Clinic Healthcare System ECHS 5.7 contains an information disclosure vulnerability in the /cdemos/echs/api/v2/ response header handling component.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: PicoTronica e-Clinic Healthcare System Information Disclosure Fixed in Version 5.7.1

PicoTronica e-Clinic Healthcare System ECHS 5.7 contains an information disclosure vulnerability in the /cdemos/echs/api/v2/ response header handling component.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: PicoTronica e-Clinic Healthcare System Information Disclosure Fixed in Version 5.7.1

PicoTronica e-Clinic Healthcare System ECHS 5.7 contains an information disclosure vulnerability in the /cdemos/echs/api/v2/ response header handling component.

highApplication SecurityMay 8, 2026·4 min read

Brief: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.

mediumApplication SecurityMay 8, 2026·4 min read

Brief: GPAC Local Resource Allocation Vulnerability Fixed by Patch

NVD/VulDB reports a local resource allocation issue in GPAC up to 26.02.0 affecting sidx_box_read in src/isomedia/box_code_base.c.

mediumApplication SecurityMay 8, 2026·4 min read

Defender Guidance: GPAC Local Resource Allocation Vulnerability Fixed by Patch

NVD/VulDB reports a local resource allocation issue in GPAC up to 26.02.0 affecting sidx_box_read in src/isomedia/box_code_base.c.

mediumApplication SecurityMay 8, 2026·4 min read

Detection Notes: GPAC Local Resource Allocation Vulnerability Fixed by Patch

NVD/VulDB reports a local resource allocation issue in GPAC up to 26.02.0 affecting sidx_box_read in src/isomedia/box_code_base.c.

mediumApplication SecurityMay 8, 2026·4 min read

Risk Brief: GPAC Local Resource Allocation Vulnerability Fixed by Patch

NVD/VulDB reports a local resource allocation issue in GPAC up to 26.02.0 affecting sidx_box_read in src/isomedia/box_code_base.c.

highApplication SecurityMay 8, 2026·4 min read

Brief: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: code-projects Simple Chat System SQL Injection Disclosed in sendMessage.php

A SQL injection vulnerability was disclosed in code-projects Simple Chat System 1.0 affecting sendMessage.php.

highApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester SUP Online Shopping Wishlist SQL Injection Disclosed

A SQL injection issue was reported in SourceCodester SUP Online Shopping 1.0 affecting wishlist.php through the delwlistid argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester SUP Online Shopping Admin Message SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in SourceCodester SUP Online Shopping 1.0 affecting /admin/message.php through the seenid argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester SUP Online Shopping SQL Injection Found in Admin Reply Message Handler

NVD/VulDB reports a SQL injection issue in SourceCodester SUP Online Shopping 1.0 affecting /admin/replymsg.php through the msgid argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: CodeAstro Leave Management System Login SQL Injection Published

NVD/VulDB reports a SQL injection vulnerability in CodeAstro Leave Management System 1.0 affecting /login.php through the txt_username argument.

highApplication SecurityMay 8, 2026·4 min read

Brief: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

Defender Guidance: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

Detection Notes: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

highApplication SecurityMay 8, 2026·4 min read

Risk Brief: zyx0814 FilePress Shares Filelist API SQL Injection Disclosed

A SQL injection vulnerability was reported in zyx0814 FilePress up to 2.2.0 affecting dzz/shares/admin.php in the Shares Filelist API.

mediumApplication SecurityMay 8, 2026·4 min read

Brief: SourceCodester Pharmacy Sales and Inventory System XSS Vulnerability Published

NVD/VulDB reports a cross-site scripting vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 affecting /index.php?page=users through the Name argument.

mediumApplication SecurityMay 8, 2026·4 min read

Defender Guidance: SourceCodester Pharmacy Sales and Inventory System XSS Vulnerability Published

NVD/VulDB reports a cross-site scripting vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 affecting /index.php?page=users through the Name argument.

mediumApplication SecurityMay 8, 2026·4 min read

Detection Notes: SourceCodester Pharmacy Sales and Inventory System XSS Vulnerability Published

NVD/VulDB reports a cross-site scripting vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 affecting /index.php?page=users through the Name argument.

mediumApplication SecurityMay 8, 2026·4 min read

Risk Brief: SourceCodester Pharmacy Sales and Inventory System XSS Vulnerability Published

NVD/VulDB reports a cross-site scripting vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 affecting /index.php?page=users through the Name argument.

criticalApplication SecurityMay 8, 2026·4 min read

Brief: Critical Langflow AI vulnerability reported under active attack

Recent security coverage reported exploitation of a critical flaw in Langflow AI. The article should be treated as a prompt to validate exposure and review vendor or project adviso

criticalApplication SecurityMay 8, 2026·4 min read

Defender Guidance: Critical Langflow AI vulnerability reported under active attack

Recent security coverage reported exploitation of a critical flaw in Langflow AI. The article should be treated as a prompt to validate exposure and review vendor or project adviso

criticalApplication SecurityMay 8, 2026·4 min read

Detection Notes: Critical Langflow AI vulnerability reported under active attack

Recent security coverage reported exploitation of a critical flaw in Langflow AI. The article should be treated as a prompt to validate exposure and review vendor or project adviso

criticalApplication SecurityMay 8, 2026·4 min read

Risk Brief: Critical Langflow AI vulnerability reported under active attack

Recent security coverage reported exploitation of a critical flaw in Langflow AI. The article should be treated as a prompt to validate exposure and review vendor or project adviso

highApplication SecurityMay 8, 2026·4 min read

Kimai Invoice Template Vulnerability Can Expose Files Readable by PHP Worker

Kimai versions 2.32.0 to before 2.56.0 allow users with System-Admin role and upload_invoice_template permission to embed files readable by the PHP worker into rendered invoice PDFs.

highApplication SecurityMay 8, 2026·4 min read

CodeAstro Online Classroom SQL Injection Vulnerability Disclosed With Public Exploit

A SQL injection vulnerability in CodeAstro Online Classroom 1.0 affects the /askquery.php component through the squeryx argument, according to the NVD/VulDB record.