U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog
ID: be514d83-31d9-52b0-b0f8-1efc668f4150
STIX ID: report--be514d83-31d9-52b0-b0f8-1efc668f4150
Feed Name: Security Affairs
Threat Score
CISA added multiple high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog — a DD-WRT UPnP buffer overflow, a critical Langflow RCE via untrusted functionality loading, and two WordPress Core flaws (a REST API route confusion and an SQL injection) that can be chained for pre-auth remote code execution; public PoCs exist for the WordPress issues and federal agencies have mandated patch deadlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
