Critical exposure
CVE-2024-32766 Qnap Qts Command Injection
- CVSS 10
New critical Qnap Qts Command Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
New critical Qnap Qts Command Injection (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Myqnapcloud Link privilege escalation (CVSS 9.9) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Puneethreddyhc Event Management SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
An exposure of sensitive information vulnerability has been reported to affect Media Streaming add-on.
Tenda N300 F3 router vulnerability allows users to bypass intended security policy and create weak passwords.
SQL Injection vulnerability in /event-management-master/backend/register.php in PuneethReddyHC Event Management 1.0 allows attackers to r...
An issue discovered in the DeviceIoControl component in ASUS Fan_Xpert before v.10013 allows an attacker to execute arbitrary code via cr...
An issue in Beijing Panabit Network Software Co., Ltd Panalog big data analysis platform v.
A missing authentication for critical function vulnerability has been reported to affect myQNAPcloud Link.
An OS command injection vulnerability has been reported to affect several QNAP operating system versions.
pyload is an open-source Download Manager written in pure Python.
Danswer is the AI Assistant connected to company's docs, apps, and people.
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers t...