Firewall Pulse Patch Watch Desk
The Firewall Pulse Patch Watch Desk is the part of the Firewall Pulse newsroom that covers software flaws, vendor advisories and patches. It is a newsroom desk, not a single person. Sections: Vulnerabilities. Stories start from more than 150 monitored sources. Drafts are prepared with AI assistance and checked by software against the cited sources before they are published. It has published 15 articles so far. See the editorial policy or report an error.
11 Oct
VulnerabilitiesA critical object injection vulnerability in the Travesia WordPress theme allows untrusted data deserialization, affecting versions through 1.1.16 with a CVSS score of 9.8.
11 Oct
VulnerabilitiesUnpatched OS command injection in TOZED X300 firmware allows remote attackers to execute arbitrary commands via manipulated ping arguments.
11 Oct
VulnerabilitiesA critical flaw in the ParamAspect component allows unauthenticated users to access all HR API endpoints by omitting a specific header.
11 Oct
VulnerabilitiesRoyal Plugins SiteVault plugin allows unauthenticated remote code execution in versions up to 1.5.19, rated critical by NVD.
11 Oct
VulnerabilitiesSelect-Themes plugin allows attackers to gain administrative access without credentials, rated 9.8 CVSS.
10 Oct
VulnerabilitiesThreat actors are actively exploiting unpatched flaws in the AhsayCBS backup management platform to install webshells and cryptocurrency mining software.
10 Oct
VulnerabilitiesTwo security issues in AWS Ops Wheel allow potential exposure of sensitive cloud infrastructure configurations to unauthorized users.
10 Oct
VulnerabilitiesThe National Vulnerability Database rates CVE-2026-62046 as critical, warning that untrusted data handling in the Gutentype plugin enables object injection.
10 Oct
VulnerabilitiesDeserialization of untrusted data in the Convex plugin exposes WordPress sites to remote object injection attacks requiring immediate attention.
10 Oct
VulnerabilitiesA critical authentication bypass in the WPCOM Member plugin for WordPress allows attackers to hijack admin accounts by forging social login sessions without valid credentials.
10 Oct
VulnerabilitiesA critical vulnerability in the ThemeREX Greeny WordPress theme allows object injection through untrusted data deserialization in versions up to 2.10.0.
10 Oct
VulnerabilitiesA high-severity injection flaw in older versions of the TinaCMS CLI allows attackers to execute arbitrary code during preview builds by manipulating Git branch names.
09 Oct
VulnerabilitiesFederal agencies must mitigate the ProFTPD file copy flaw by 11 October after CISA added it to the Known Exploited Vulnerabilities catalog.
09 Oct
VulnerabilitiesA critical flaw in the Sipay OpenCart module allows attackers to bypass cryptographic signature checks and spoof transaction data.
09 Oct
VulnerabilitiesThe US government has added CVE-2015-5477 to its catalog, requiring teams to mitigate the high-severity remote DoS vulnerability within three days.