All CosmicBytez Labs articles tagged #Pre-Auth, across news, security advisories, how-to guides, and projects.
vBulletin has patched a critical unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary PHP code through template rendering. A public exploit was available before the patch was released, putting thousands of forum installations at immediate risk.
A critical unauthenticated remote code execution vulnerability in Fujitsu Software openFT allows attackers to execute arbitrary code on Linux and Solaris...
A critical SQL injection vulnerability in LiteLLM's proxy server allows unauthenticated attackers to manipulate database queries during API key...
A critical pre-authorization remote code execution vulnerability in Marimo, the open-source reactive Python notebook, allows unauthenticated attackers to...
Two newly disclosed vulnerabilities in Progress ShareFile can be chained together to enable unauthenticated remote code execution and file exfiltration,...
A critical pre-authentication OS command injection vulnerability in BeyondTrust Remote Support and Privileged Remote Access with CVSS 9.9 is being...