A vulnerability, which was classified as critical, has been found in Discourse. Affected by this issue is the function ai_discover_persona. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2025-68660. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in Discourse. This affects an unknown part. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2025-68662. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
A vulnerability has been found in Discourse and classified as problematic. This vulnerability affects unknown code. Performing a manipulation results in incorrect authorization.
This vulnerability is cataloged as CVE-2025-68666. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
A vulnerability identified as problematic has been detected in Discourse. Affected by this issue is the function top_uploads of the component Admin Report. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2025-69218. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability labeled as problematic has been found in Discourse. This affects an unknown part of the component Private Message Handler. The manipulation results in incorrect authorization.
This vulnerability is known as CVE-2025-68933. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability classified as problematic was found in Discourse. This impacts an unknown function. The manipulation results in incorrect authorization.
This vulnerability was named CVE-2025-69289. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability marked as problematic has been reported in Discourse. This impacts an unknown function of the component 404 Page Search Box. The manipulation leads to information disclosure.
This vulnerability is traded as CVE-2026-23743. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability identified as problematic has been detected in Codriapp Innovation and Software HeyGarson up to 30012026. Affected is an unknown function. Performing a manipulation results in information exposure through error message.
This vulnerability is known as CVE-2025-1395. Remote exploitation of the attack is possible. No exploit is available.
Google-owned Mandiant on Friday said it identified an "expansion in threat activity" that uses tradecraft consistent with extortion-themed attacks orchestrated by a financially motivated hacking group known as ShinyHunters.
The attacks leverage advanced voice phishing (aka vishing) and bogus credential harvesting sites mimicking targeted companies to gain unauthorized access to victim
CERT Polska, the Polish computer emergency response team, revealed that coordinated cyber attacks targeted more than 30 wind and photovoltaic farms, a private company from the manufacturing sector, and a large combined heat and power plant (CHP) supplying heat to almost half a million customers in the country.
The incident took place on December 29, 2025. The agency has attributed the attacks to
A vulnerability identified as problematic has been detected in Discourse. The affected element is the function authorized_extensions. This manipulation causes escaping of output.
This vulnerability is handled as CVE-2025-66488. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in Discourse. Affected is an unknown function of the component Subscription Handler. The manipulation leads to missing authorization.
This vulnerability is referenced as CVE-2025-68479. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in Discourse. Affected by this vulnerability is an unknown functionality of the file /u//preferences/username of the component Username Preference Endpoint. The manipulation results in allocation of resources.
This vulnerability is identified as CVE-2025-68659. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability labeled as critical has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get_clip_img of the component HTTP POST Request Handler. Such manipulation of the argument frame/dirno leads to command injection.
This vulnerability is referenced as CVE-2026-1412. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A vulnerability marked as critical has been reported in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection.
This vulnerability is identified as CVE-2026-1413. The attack can be initiated remotely. Additionally, an exploit exists.