thehackerwire.com
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-04-22.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-04-22 2026 | Authlib Critical JWT Forgery (CVE-2026-27962)JWT | Authlib Critical JWT Forgery (CVE-2026-27962) |
| 2026-04-22 2026 | Keycloak SAML Disabled Client SSO Bypass (CVE-2026-3047)AuthN | Keycloak SAML Disabled Client SSO Bypass (CVE-2026-3047) |
| 2026-04-22 2026 | LibreChat SSRF Bypass via IPv6 Mapped Address ConfusionSSRF | LibreChat SSRF Bypass via IPv6 Mapped Address Confusion |
| 2026-04-16 2026 | Chamilo LMS IDOR Leads to Admin Privileges (CVE-2026-40291)IDOR | Chamilo LMS IDOR Leads to Admin Privileges (CVE-2026-40291) |
| 2026-04-10 2026 | FastGPT Critical SSRF via Unauthenticated HTTP Proxy EndpointSSRF | FastGPT Critical SSRF via Unauthenticated HTTP Proxy Endpoint |
| 2026-04-10 2026 | U-Office Force Critical RCE via Insecure Deserialization (CVE-2026-3422)DeserRCE | U-Office Force Critical RCE via Insecure Deserialization (CVE-2026-3422) |
| 2026-04-10 2026 | IBM Langflow Desktop RCE via Insecure DeserializationDeserRCE | IBM Langflow Desktop RCE via Insecure Deserialization |
| 2026-04-10 2026 | Wazuh RCE via Deserialization of Untrusted Data (CVE-2026-25769)RCE | Wazuh RCE via Deserialization of Untrusted Data (CVE-2026-25769) |
| 2026-04-10 2026 | Critical Pre-Auth RCE in ChurchCRM Setup WizardRCE | Critical Pre-Auth RCE in ChurchCRM Setup Wizard |
| 2026-04-10 2026 | WWBN AVideo RCE via Persistent PHP File Upload (CVE-2026-33717)RCE | WWBN AVideo RCE via Persistent PHP File Upload (CVE-2026-33717) |
| 2026-04-10 2026 | Explorance Blue RCE via Unrestricted File UploadRCE | Explorance Blue RCE via Unrestricted File Upload |
| 2026-04-10 2026 | Precurio Intranet Portal: CSRF to RCE via File UploadRCE | Precurio Intranet Portal: CSRF to RCE via File Upload |
| 2026-04-10 2026 | Tiandy Easy7 RCE via OS Command Injection (CVE-2026-4585)RCE | Tiandy Easy7 RCE via OS Command Injection (CVE-2026-4585) |
| 2026-04-10 2026 | Microsoft Bing Images OS Command Injection RCERCE | Microsoft Bing Images OS Command Injection RCE |
| 2026-04-10 2026 | AWS RES Root RCE via Crafted Session Name (CVE-2026-5707)RCE | AWS RES Root RCE via Crafted Session Name (CVE-2026-5707) |
| 2026-04-10 2026 | Group-Office Critical RCE via Insecure Deserialization (CVE-2026-34838)RCE | Group-Office Critical RCE via Insecure Deserialization (CVE-2026-34838) |
| 2026-04-10 2026 | NVIDIA APEX Deserialization RCE (CVE-2025-33244)RCE | NVIDIA APEX Deserialization RCE (CVE-2025-33244) |
| 2026-04-10 2026 | PraisonAI Critical RCE via Malicious YAML Parsing (CVE-2026-39890)RCE | PraisonAI Critical RCE via Malicious YAML Parsing (CVE-2026-39890) |
| 2026-04-10 2026 | Microsoft SharePoint Deserialization RCE (CVE-2026-26114)Deser | Microsoft SharePoint Deserialization RCE (CVE-2026-26114) |
| 2026-04-10 2026 | CI4MS Critical Stored XSS (CVE-2026-34569)XSS | CI4MS Critical Stored XSS (CVE-2026-34569) |
| 2026-04-10 2026 | CI4MS Stored DOM XSS via Menu Management (CVE-2026-34565)XSS | CI4MS Stored DOM XSS via Menu Management (CVE-2026-34565) |
| 2026-04-10 2026 | Homarr DOM-based XSS (CVE-2026-33510)XSS | Homarr DOM-based XSS (CVE-2026-33510) |
| 2026-04-09 2026 | curl_cffi SSRF via Unrestricted Redirects (CVE-2026-33752)SSRF | curl_cffi SSRF via Unrestricted Redirects (CVE-2026-33752) |
| 2026-04-09 2026 | Plunk Critical SSRF in SNS Webhook Handler (CVE-2026-32096)SSRF | Plunk Critical SSRF in SNS Webhook Handler (CVE-2026-32096) |
| 2026-04-09 2026 | Microsoft Purview SSRF Privilege Elevation (CVE-2026-26138)SSRF | Microsoft Purview SSRF Privilege Elevation (CVE-2026-26138) |
| 2026-04-06 2026 | Nginx UI IDOR Allows Cross-User Resource AccessIDOR | Nginx UI IDOR Allows Cross-User Resource Access |
| 2026-04-03 2026 | OpenOlat Velocity Template Injection Leads to RCERCE | OpenOlat Velocity Template Injection Leads to RCE |