Clawvet API Secret Flaw Risks User Data
A hard-coded JWT secret in self-hosted Clawvet API versions prior to 0.7.5 allows unauthenticated access to sensitive user information.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A hard-coded JWT secret in self-hosted Clawvet API versions prior to 0.7.5 allows unauthenticated access to sensitive user information.
Federal agencies must address a critical OS command injection vulnerability in Fortinet products by July 19, 2026.
Threat actors are weaponizing fake TrueType Font files to slip low-detection malware past traditional Windows endpoint defenses.
Compromised AsyncAPI and Jscrambler packages expose developers to credential theft via automated malicious injection.
A critical privilege escalation flaw in the Aimogen Pro WordPress plugin could permit unauthenticated administrative access.
Federal agencies must address an actively exploited OS command injection vulnerability in Fortinet products by July 19, 2026.
A critical vulnerability in the Bricksforge WordPress plugin allows unauthenticated attackers to create unauthorized administrator accounts.
A critical flaw in Grav versions before 2.0.4 permits attackers to bypass two-factor authentication by overwriting existing security secrets.
A critical vulnerability in clawvet API versions before 0.7.5 allows unauthenticated attackers to forge session cookies and access sensitive user information.
International agencies are pushing software vendors to adopt standardized vulnerability disclosure frameworks for better security.
A critical vulnerability in the illumos SCTP inbound path allows unauthenticated remote attackers to trigger kernel heap corruption and potential code execution.
A critical flaw in WireGuard Easy allows unauthenticated attackers to brute-force weak tokens and hijack VPN peer credentials.
AI tools now synthesize executive data into actionable attack profiles, rendering traditional protection programs increasingly obsolete.
A critical vulnerability in Twig versions 3.9.0 through 3.25.0 allows sandboxed templates to bypass security policy enforcement.
A critical vulnerability in Twig versions prior to 3.26.0 allows attackers to inject arbitrary PHP code via crafted template names in {% use %} tags.
A critical identity-binding bug in n8n's token exchange feature allowed unauthorized account access by ignoring multi-issuer constraints.
Researchers identify a vulnerability where agents mistake untrusted input for verified facts, bypassing current security defenses.
A critical vulnerability in Grafana OnCall allows unauthenticated remote attackers to gain full administrative access via hardcoded default identifiers.
A critical vulnerability in Envoy Gateway allows attackers to bypass path validation and access sensitive files on the gateway controller pod.
A critical deserialization vulnerability in Microsoft SharePoint is currently being exploited in the wild, requiring immediate action from federal agencies.