CVE Alert: CVE-2026-108628 - jeecgboot - JeecgBoot - https://www.redpacketsecurity.com/cve-alert-cve-2026-108628-jeecgboot-jeecgboot/
RedPacket Security
CVE Alert: CVE-2026-108628 - jeecgboot - JeecgBoot - RedPacket Security
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the saveDeptRolePermission endpoint of SysDepartPermissionController that allows any
CVE Alert: CVE-2026-108549 - chenhg5 - cc-connect - https://www.redpacketsecurity.com/cve-alert-cve-2026-108549-chenhg5-cc-connect/
RedPacket Security
CVE Alert: CVE-2026-108549 - chenhg5 - cc-connect - RedPacket Security
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts
CVE Alert: CVE-2026-108550 - iflytek - skillhub - https://www.redpacketsecurity.com/cve-alert-cve-2026-108550-iflytek-skillhub/
RedPacket Security
CVE Alert: CVE-2026-108550 - iflytek - skillhub - RedPacket Security
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers
CVE Alert: CVE-2026-108623 - jeecgboot - JeecgBoot - https://www.redpacketsecurity.com/cve-alert-cve-2026-108623-jeecgboot-jeecgboot/
RedPacket Security
CVE Alert: CVE-2026-108623 - jeecgboot - JeecgBoot - RedPacket Security
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysLogController deleteBatch handler that allows any authenticated user to
CVE Alert: CVE-2026-108657 - jeecgboot - JeecgBoot - https://www.redpacketsecurity.com/cve-alert-cve-2026-108657-jeecgboot-jeecgboot/
RedPacket Security
CVE Alert: CVE-2026-108657 - jeecgboot - JeecgBoot - RedPacket Security
JeecgBoot through 3.9.5 contains a missing authorization vulnerability in the SysTenantController passApply handler that allows any authenticated user to
CVE Alert: CVE-2026-108708 - WuKongOpenSource - Wukong_HRM - https://www.redpacketsecurity.com/cve-alert-cve-2026-108708-wukongopensource-wukong-hrm/
RedPacket Security
CVE Alert: CVE-2026-108708 - WuKongOpenSource - Wukong_HRM - RedPacket Security
Wukong_HRM through commit 186115e contains a missing authorization vulnerability because EmployeeAspect assigns every caller the HR administrator role and
CVE Alert: CVE-2026-108693 - ImageMagick - ImageMagick - https://www.redpacketsecurity.com/cve-alert-cve-2026-108693-imagemagick-imagemagick/
RedPacket Security
CVE Alert: CVE-2026-108693 - ImageMagick - ImageMagick - RedPacket Security
ImageMagick on Windows through 7.1.2-33 and 6.9.13-58 contains an uncontrolled search path vulnerability in NTGhostscriptEXE() that launches gswin64c.exe by
CVE Alert: CVE-2026-108522 - Studio-Saelix - Sencho - https://www.redpacketsecurity.com/cve-alert-cve-2026-108522-studio-saelix-sencho/
RedPacket Security
CVE Alert: CVE-2026-108522 - Studio-Saelix - Sencho - RedPacket Security
A vulnerability was found in Studio-Saelix Sencho up to 0.94.1. This affects an unknown part of the file /api/auth/login of the component Login Endpoint.
CVE Alert: CVE-2026-108695 - multivendorx - MultiVendorX - https://www.redpacketsecurity.com/cve-alert-cve-2026-108695-multivendorx-multivendorx/
RedPacket Security
CVE Alert: CVE-2026-108695 - multivendorx - MultiVendorX - RedPacket Security
MultiVendorX WordPress plugin through 5.0.19 contains an incorrect authorization vulnerability that allows vendor accounts to modify marketplace-wide settings
[N0N] - Ransomware Victim: Company #4 - https://www.redpacketsecurity.com/n0n-ransomware-victim-company-4/
RedPacket Security
[N0N] - Ransomware Victim: Company #4 - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[N0N] - Ransomware Victim: Company #5 - https://www.redpacketsecurity.com/n0n-ransomware-victim-company-5/
RedPacket Security
[N0N] - Ransomware Victim: Company #5 - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: CNESTEN - https://www.redpacketsecurity.com/qilin-ransomware-victim-cnesten/
RedPacket Security
[QILIN] - Ransomware Victim: CNESTEN - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: Friendship Christian School - https://www.redpacketsecurity.com/qilin-ransomware-victim-friendship-christian-school/
RedPacket Security
[QILIN] - Ransomware Victim: Friendship Christian School - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-108718 - Rill Data - rill - https://www.redpacketsecurity.com/cve-alert-cve-2026-108718-rill-data-rill/
RedPacket Security
CVE Alert: CVE-2026-108718 - Rill Data - rill - RedPacket Security
Rill 0.77.0 through 0.90.5 contains a missing authorization vulnerability in the admin OAuth server that issues authorization codes to dynamically registered
CVE Alert: CVE-2026-108740 - arp242 - GoatCounter - https://www.redpacketsecurity.com/cve-alert-cve-2026-108740-arp242-goatcounter/
RedPacket Security
CVE Alert: CVE-2026-108740 - arp242 - GoatCounter - RedPacket Security
GoatCounter through 2.7.0 contains a mass assignment privilege escalation vulnerability in the userPrefSave handler that allows logged-in users to modify
CVE Alert: CVE-2026-108571 - Xinhu - Rainrock RockOA - https://www.redpacketsecurity.com/cve-alert-cve-2026-108571-xinhu-rainrock-rockoa/
RedPacket Security
CVE Alert: CVE-2026-108571 - Xinhu - Rainrock RockOA - RedPacket Security
A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.6. This impacts the function kqjcmdModel::returnchuli of the file
CVE Alert: CVE-2026-108714 - modelcontextprotocol - kotlin-sdk - https://www.redpacketsecurity.com/cve-alert-cve-2026-108714-modelcontextprotocol-kotlin-sdk/
RedPacket Security
CVE Alert: CVE-2026-108714 - modelcontextprotocol - kotlin-sdk - RedPacket Security
MCP Kotlin SDK through 0.15.0 contains an uncontrolled memory allocation vulnerability that allows remote clients to exhaust server memory because
CVE Alert: CVE-2026-108739 - openagents-org - OpenAgents - https://www.redpacketsecurity.com/cve-alert-cve-2026-108739-openagents-org-openagents/
RedPacket Security
CVE Alert: CVE-2026-108739 - openagents-org - OpenAgents - RedPacket Security
OpenAgents Workspace backend through launcher-v1.0.17 contains an information disclosure vulnerability that allows unauthenticated attackers to list all
CVE Alert: CVE-2026-108744 - MinaSaad1 - pbi-cli - https://www.redpacketsecurity.com/cve-alert-cve-2026-108744-minasaad1-pbi-cli/
RedPacket Security
CVE Alert: CVE-2026-108744 - MinaSaad1 - pbi-cli - RedPacket Security
pbi-cli 3.10.1 through 3.12.0 contains an OS command injection vulnerability in desktop_sync.py that passes unquoted .pbip paths to cmd /c start when
CVE Alert: CVE-2026-108746 - Vearch - vearch - https://www.redpacketsecurity.com/cve-alert-cve-2026-108746-vearch-vearch/
RedPacket Security
CVE Alert: CVE-2026-108746 - Vearch - vearch - RedPacket Security
Vearch 3.5.2 through 3.5.9 contains an incorrect authorization vulnerability in Role.HasPermissionForResources that ignores stored ReadOnly or None privilege