HackerOne Bug Bounty Disclosure: -click-account-takeover-via-open-redirect-through-regex-bypass-in-domain-validation-farr - RedPacket Security

CompanyKhan Academy

RedPacket Security

CVE-2026-48773 - Critical RCE in Proxysql. Pre-auth heap memory corruption via oversized packet. CVSS 9.8. Patch to v3.0.9 immediately. #CVE #infosec #Proxysql

https://www.valtersit.com/cve/CVE-2026-48773/

CVE-2026-48773 | Proxysql | Valters IT Hub

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerab...

Valters IT Hub

๐Ÿšจ EUVD-2024-55642

๐Ÿ“Š Score: 9.3/10 (CVSS v3.1)
๐Ÿ“ฆ Product: Flowise
๐Ÿข Vendor: Flowise
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allo...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-55642

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-38112

๐Ÿ“Š Score: 2.3/10 (CVSS v3.1)
๐Ÿ“ฆ Product: nuxt, nuxt
๐Ÿข Vendor: nuxt
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript component that writes slot content to innerHTML without escaping. Attackers can inject malicious scripts through untrusted data in NoScript slo...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38112

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-38113

๐Ÿ“Š Score: 2.3/10 (CVSS v3.1)
๐Ÿ“ฆ Product: capgo
๐Ÿข Vendor: Capgo
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain resolver, allowing underscore characters in app_id to act as SQL wildcards. Attackers can create apps with app_ids differing by one character a...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38113

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2025-210289

๐Ÿ“Š Score: 5.1/10 (CVSS v3.1)
๐Ÿ“ฆ Product: Flowise
๐Ÿข Vendor: Flowise
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat messages and custom agent functions. An attacker can inject malicious JavaScript by sending an iframe payload (e.g., <iframe src="javasc...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-210289

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-38114

๐Ÿ“Š Score: 6.9/10 (CVSS v3.1)
๐Ÿ“ฆ Product: capgo
๐Ÿข Vendor: Capgo
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise latitude and longitude coordinates revealing user physical locatio...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38114

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-38115

๐Ÿ“Š Score: 5.3/10 (CVSS v3.1)
๐Ÿ“ฆ Product: capgo
๐Ÿข Vendor: Capgo
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend perfo...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38115

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-38116

๐Ÿ“Š Score: 6.9/10 (CVSS v3.1)
๐Ÿ“ฆ Product: capgo
๐Ÿข Vendor: Capgo
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum p...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38116

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-38117

๐Ÿ“Š Score: 6.9/10 (CVSS v3.1)
๐Ÿ“ฆ Product: capgo
๐Ÿข Vendor: Cap-go
๐Ÿ“… Updated: 2026-06-20

๐Ÿ“ Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role without enforcing org membership or permission checks. An unauth...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-38117

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database