LuCI: OpenWrt Web Interface
LuCI is the default web-based user interface for OpenWrt. An AI-assisted audit by Hacker House identified multiple vulnerabilities in LuCI components, including…
LuCI is the default web-based user interface for OpenWrt. An AI-assisted audit by Hacker House identified multiple vulnerabilities in LuCI components, including…
SpyPress is an obfuscated JavaScript-based malware used by TA458 in Operation RoundPress. It targets webmail platforms including Roundcube, Zimbra, Kerio, SOGo, and…
A cross-site scripting (XSS) flaw in Zimbra's Classic UI exploited by Laundry Bear to deploy the ZimReaper payload, harvesting email data from…
Zimbra has released security updates addressing nine vulnerabilities in Zimbra 10.1.20, including a critical command injection flaw in the Simple Network Management…
A cross-site scripting vulnerability in Zimbra that was exploited by threat actors. Part of a series of XSS flaws targeting Zimbra's web…
A cross-site scripting vulnerability in Zimbra that was exploited by threat actors. Part of a series of XSS flaws targeting Zimbra's web…
The Classic Web Client in Zimbra had four XSS vulnerabilities patched, including stored XSS via attachment filenames and crafted fields.
CVE-2024-42009 is a critical cross-site scripting (XSS) vulnerability in Roundcube webmail with a CVSS score of 9.3. Exploitation requires the victim to…
Exchange Server is a mail server and calendaring server developed by Microsoft. It had a stored XSS vulnerability in OWA patched in…