Vulnerability Database & Alerts LIVE

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
CVE
Affected Version
Vulnerability
Severity
View & Download
Uploader
Date
Klever Node13. This showed /log is a live WebSocket endpoint. Before attack, the validator emitted periodic slot logs. Example logs included SLOT 14 BEGINS and SLOT 15 BEGINS. The PoC connected to ws://127.0.0.1:18080/log without authentication. The PoC sent {"LogLevelPatterns":":NONE","WithCorrelation":false,"WithLoggerName":false}. The validator printed websocket log profile received profile = [pattern=:NONE, with correlation=false, with logger name=false]. The node accepted the unauthenticated profile. The node stopped emitting normal slot logs while the WebSocket remained open. Expected slot logs for the :NONE interval did not appear. The profile was restored only after the attacker disconnected. The validator printed reverted log profile profile = [pattern=:INFO, with correlation=false, with logger name=false]. The attacker can also send :TRACE to increase verbosity and force noisy logging. The attacker can toggle correlation and logger-name settings process-wide. This affects confidentiality and operational integrity. Logs may contain operational details, peer information, error traces, and occasionally secrets or credentials. Suppressing or distorting logs degrades detection, incident response, and operator visibility. This is distinct from GHSA-jc6w-wmfc-fh33, GHSA-87m7-qffr-542v, and GHSA-74m6-4hjp-7226. Those are VM/P2P-path flaws. This is an unauthenticated management-plane flaw in the WebSocket logging endpoint. DailyCVE Form: Platform: Klever Node Version: 9640d63265e910e166dfa694c8e5ddeb53018ffdUnauthenticated Log MutationnotstatedView or DownloadUNDERCODE2026-05-30
Hono<4.12.4Cookie InjectionmediumView or DownloadUNDERCODE2026-03-06
D-Link DIR-513v1.10Stack buffer overflowcriticalView or DownloadUNDERCODE2026-03-06
D-Link DIR-5131.10Path TraversalcriticalView or DownloadUNDERCODE2026-03-06
D-Link DIR-513critical98View or DownloadUNDERCODE2026-03-06
FreePBX GUI86highView or DownloadUNDERCODE2026-05-03
D-Link DIR-513criticalView or DownloadUNDERCODE2026-03-06
D-Link DIR-5131.10 onlyStack Buffer Overflowcritical98View or DownloadUNDERCODE2026-03-06
CoreDNS77highView or DownloadUNDERCODE2026-03-06
Traefikmoderatecvss44View or DownloadUNDERCODE2026-03-05
Traefik2.11.9-2.11.37, 3.1.3-3.6.8Case-sensitivity bypasshighcvss31avnaclprnuinsucnihanView or DownloadUNDERCODE2026-03-05
TraefikhighView or DownloadUNDERCODE2026-03-05
Gogs<0.14.2Option injectionmediumView or DownloadUNDERCODE2026-03-05
Gogs< 0.14.2Stored XSSmediumView or DownloadUNDERCODE2026-03-05
GogshighView or DownloadUNDERCODE2026-03-05
OpenClaw (npm)criticalView or DownloadUNDERCODE2026-03-03
Geth<1.16.9ECIES Key ExtractionhighView or DownloadUNDERCODE2026-02-19
go-ethereumPrior to 1.14.13Denial of ServicemoderateView or DownloadUNDERCODE2026-02-19
LangChain Redis Checkpointer< 1.0.2Query Injection BypasscriticalView or DownloadUNDERCODE2026-02-19
filippo.io/edwards25519Prior to v1.2.0MultiScalarMult initialization failurelowView or DownloadUNDERCODE2026-02-19
TensorFlow/Keras2.20.0/3.11.3Information DisclosuremediumView or DownloadUNDERCODE2025-10-19
LibreNMSbefore 24.4.0time-based blind SQLihigh71-88View or DownloadUNDERCODE2024-04-22
Windows<5.27.14Command Injectionhigh81View or DownloadUNDERCODE2025-12-16
PHP ApplicationNot specifiedSQL Injection IPv6criticalView or DownloadUNDERCODE2025-02-18
OpenClaw<=2026.2.14Token LeakmoderateView or DownloadUNDERCODE2026-02-18

🌐 UNDERCODENEWS LIVE

Active 0
Live Attacks Getting Updates…
🕒 24h 0
📅 Today 0
🌐 Total 0
--:--:--
🖱️ Click to interact with map scroll, zoom & pan
Active Exploit
Dormant
Trajectory
Target Sector
Scroll to Top