news.mlab.sh
356 results
vulnerability

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical vulnerabilities have been discovered in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could lead to complete site takeover, allowing attackers to gain administrator access and execute arbitrary code, highlighting a significant…

The Hacker News · 1d ago Critical
vulnerability

PayRange API

A critical vulnerability in the PayRange API allows unauthorized access to sensitive device information and potential denial-of-service attacks. The vulnerability stems from a lack of proper authorization on management e…

CISA Advisories · 5d ago Critical
vulnerability

Zoneminder

A critical Remote Code Execution (RCE) vulnerability exists in Zoneminder versions 1.37.48 and 1.38.3, allowing authenticated users to execute arbitrary operating system commands. The vulnerability stems from an Improper…

CISA Advisories · 5d ago Critical