CVE Alert: CVE-2026-27309 - Adobe - Substance3D - Stager - RedPacket Security

Substance3D - Stager versions 3.1.7 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of

RedPacket Security

CVE Alert: CVE-2026-4248 - ultimatemember - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin - https://www.redpacketsecurity.com/cve-alert-cve-2026-4248-ultimatemember-ultimate-member-user-profile-registration-login-member-directory-content-restriction-membership-plugin/

#OSINT #ThreatIntel #CyberSecurity #cve-2026-4248 #ultimatemember #ultimate-member-user-profile-registration-login-member-directory-content-restriction-and-membership-plugin

CVE Alert: CVE-2026-4248 - ultimatemember - Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin - RedPacket Security

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the

RedPacket Security
CVE Alert: CVE-2026-4975 - Tenda - AC15 - RedPacket Security

A vulnerability has been found in Tenda AC15 15.03.05.19. This affects the function formSetCfm of the file /goform/setcfm of the component POST Request

RedPacket Security
CVE Alert: CVE-2026-4974 - Tenda - AC7 - RedPacket Security

A flaw has been found in Tenda AC7 15.03.06.44. Affected by this issue is the function fromSetSysTime of the file /goform/SetSysTimeCfg of the component POST

RedPacket Security

CVE Alert: CVE-2019-25652 - Ubiquiti - UniFi Network Controller - https://www.redpacketsecurity.com/cve-alert-cve-2019-25652-ubiquiti-unifi-network-controller/

#OSINT #ThreatIntel #CyberSecurity #cve-2019-25652 #ubiquiti #unifi-network-controller

CVE Alert: CVE-2019-25652 - Ubiquiti - UniFi Network Controller - RedPacket Security

UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent

RedPacket Security

CVE Alert: CVE-2019-25651 - Ubiquiti - UniFi Network Controller - https://www.redpacketsecurity.com/cve-alert-cve-2019-25651-ubiquiti-unifi-network-controller/

#OSINT #ThreatIntel #CyberSecurity #cve-2019-25651 #ubiquiti #unifi-network-controller

CVE Alert: CVE-2019-25651 - Ubiquiti - UniFi Network Controller - RedPacket Security

Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW

RedPacket Security

🚨 EUVD-2026-16901

📊 Score: 8.0/10 (CVSS v3.1)
📦 Product: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
🏢 Vendor: ultimatemember
📅 Updated: 2026-03-27

📝 The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due t...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16901

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2026-16899

📊 Score: 5.8/10 (CVSS v3.1)
📦 Product: libjwt
🏢 Vendor: benmcollins
📅 Updated: 2026-03-27

📝 LibJWT is a C JSON Web Token Library. Starting in version 3.0.0 and prior to version 3.3.0, the JWK parsing for RSA-PSS did not protect against a NULL value when expecting to parse JSON string values. A specially crafted JWK file could exploit this behavi...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-16899

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🟠 CVE-2026-33991 - High (8.8)

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` variable into SQL queries on lines 16-17 without...

🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-33991/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

🟠 CVE-2026-4248 - High (8)

The Ultimate Member plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.11.2. This is due to the '{usermeta:password_reset_link}' template tag being processed within post content via the '[u...

🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-4248/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack