π¨ NESTJS GET MIDDLEWARE BYPASS [CVE-2026-33011]
π Score: 8.7
π Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a N..
π Details: https://t.co/WCkJ2EofyY
#CVE#WatchStack#CyberSecurity
π¨ UNAUTHENTICATED REMOTE CODE EXECUTION IN LANGFLOW [CVE-2026-33017]
π Score: 9.3
π Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the..
π Details: https://t.co/rWRTagn3t1
#CVE#WatchStack#CyberSecurity
π¨ SQL INJECTION IN AVIDEO [CVE-2026-33025]
π Score: 8.6
π AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlF..
π Details: https://t.co/rv2mhHnj55
#CVE#WatchStack#CyberSecurity
π¨ New Critical CVE [CVE-2019-25560]
π Score: 8.7
π Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the applicat..
π Details: https://t.co/4qycTjBgXz
#CVE#WatchStack#CyberSecurity
π¨ WWBN AVIDEO SSRF VIA REDIRECT IN LIVELINKS PROXY [CVE-2026-33039]
π Score: 8.6
π WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpo..
π Details: https://t.co/N5kZF1gsFa
#CVE#WatchStack#CyberSecurity
π¨ New Critical CVE [CVE-2026-33186]
π Score: 9.1
π gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resul..
π Details: https://t.co/vyIlPWI5nb
#CVE#WatchStack#CyberSecurity
π¨ New Critical CVE [CVE-2026-3334]
π Score: 8.8
π The CMS Commander plugin for WordPress is vulnerable to SQL Injection via the 'or_blogname', 'or_blogdescripti..
π Details: https://t.co/ijeuTezTmt
#CVE#WatchStack#CyberSecurity
π¨ New Critical CVE [CVE-2026-2941]
π Score: 8.8
π The Linksy Search and Replace plugin for WordPress is vulnerable to unauthorized modification of data due to a..
π Details: https://t.co/SeD3StqJEP
#CVE#WatchStack#CyberSecurity
π¨ PATH TRAVERSAL IN ALLURE REPORT GENERATOR [CVE-2026-33166]
π Score: 8.6
π Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. The Allure report g..
π Details: https://t.co/Mb42XhIxqF
#CVE#WatchStack#CyberSecurity
π¨ MEMORY EXHAUSTION VIA CRAFTED https://t.co/UlAYLaRPCM PACKET [CVE-2026-33151]
π Score: 8.7
π https://t.co/MfSs1MkPIs is an open source, real-time, bidirectional, event-based, communication framework. Prior to versions..
π Details: https://t.co/nVMCBGwyCM
#CVE#WatchStack
π¨ New Critical CVE [CVE-2026-33136]
π Score: 9.3
π WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scrip..
π Details: https://t.co/7942d0IBkw
#CVE#WatchStack#CyberSecurity
π¨ New Critical CVE [CVE-2026-32710]
π Score: 8.5
π MariaDB server is a community developed fork of MySQL server. An authenticated user can crash MariaDB versions..
π Details: https://t.co/37NoKQCoEA
#CVE#WatchStack#CyberSecurity