Vulnerability Database & Alerts LIVE
CVE
Affected Version
Vulnerability
Severity
View & Download
Uploader
Date
| Klever Node | 13. This showed /log is a live WebSocket endpoint. Before attack, the validator emitted periodic slot logs. Example logs included SLOT 14 BEGINS and SLOT 15 BEGINS. The PoC connected to ws://127.0.0.1:18080/log without authentication. The PoC sent {"LogLevelPatterns":":NONE","WithCorrelation":false,"WithLoggerName":false}. The validator printed websocket log profile received profile = [pattern=:NONE, with correlation=false, with logger name=false]. The node accepted the unauthenticated profile. The node stopped emitting normal slot logs while the WebSocket remained open. Expected slot logs for the :NONE interval did not appear. The profile was restored only after the attacker disconnected. The validator printed reverted log profile profile = [pattern=:INFO, with correlation=false, with logger name=false]. The attacker can also send :TRACE to increase verbosity and force noisy logging. The attacker can toggle correlation and logger-name settings process-wide. This affects confidentiality and operational integrity. Logs may contain operational details, peer information, error traces, and occasionally secrets or credentials. Suppressing or distorting logs degrades detection, incident response, and operator visibility. This is distinct from GHSA-jc6w-wmfc-fh33, GHSA-87m7-qffr-542v, and GHSA-74m6-4hjp-7226. Those are VM/P2P-path flaws. This is an unauthenticated management-plane flaw in the WebSocket logging endpoint. DailyCVE Form: Platform: Klever Node Version: 9640d63265e910e166dfa694c8e5ddeb53018ffd | Unauthenticated Log Mutation | notstated | View or Download | UNDERCODE | 2026-05-30 |
|---|---|---|---|---|---|---|
| Hono | <4.12.4 | Cookie Injection | medium | View or Download | UNDERCODE | 2026-03-06 |
| D-Link DIR-513 | v1.10 | Stack buffer overflow | critical | View or Download | UNDERCODE | 2026-03-06 |
| D-Link DIR-513 | 1.10 | Path Traversal | critical | View or Download | UNDERCODE | 2026-03-06 |
| D-Link DIR-513 | critical98 | View or Download | UNDERCODE | 2026-03-06 | ||
| FreePBX GUI | 86high | View or Download | UNDERCODE | 2026-05-03 | ||
| D-Link DIR-513 | critical | View or Download | UNDERCODE | 2026-03-06 | ||
| D-Link DIR-513 | 1.10 only | Stack Buffer Overflow | critical98 | View or Download | UNDERCODE | 2026-03-06 |
| CoreDNS | 77high | View or Download | UNDERCODE | 2026-03-06 | ||
| Traefik | moderatecvss44 | View or Download | UNDERCODE | 2026-03-05 | ||
| Traefik | 2.11.9-2.11.37, 3.1.3-3.6.8 | Case-sensitivity bypass | highcvss31avnaclprnuinsucnihan | View or Download | UNDERCODE | 2026-03-05 |
| Traefik | high | View or Download | UNDERCODE | 2026-03-05 | ||
| Gogs | <0.14.2 | Option injection | medium | View or Download | UNDERCODE | 2026-03-05 |
| Gogs | < 0.14.2 | Stored XSS | medium | View or Download | UNDERCODE | 2026-03-05 |
| Gogs | high | View or Download | UNDERCODE | 2026-03-05 | ||
| OpenClaw (npm) | critical | View or Download | UNDERCODE | 2026-03-03 | ||
| Geth | <1.16.9 | ECIES Key Extraction | high | View or Download | UNDERCODE | 2026-02-19 |
| go-ethereum | Prior to 1.14.13 | Denial of Service | moderate | View or Download | UNDERCODE | 2026-02-19 |
| LangChain Redis Checkpointer | < 1.0.2 | Query Injection Bypass | critical | View or Download | UNDERCODE | 2026-02-19 |
| filippo.io/edwards25519 | Prior to v1.2.0 | MultiScalarMult initialization failure | low | View or Download | UNDERCODE | 2026-02-19 |
| TensorFlow/Keras | 2.20.0/3.11.3 | Information Disclosure | medium | View or Download | UNDERCODE | 2025-10-19 |
| LibreNMS | before 24.4.0 | time-based blind SQLi | high71-88 | View or Download | UNDERCODE | 2024-04-22 |
| Windows | <5.27.14 | Command Injection | high81 | View or Download | UNDERCODE | 2025-12-16 |
| PHP Application | Not specified | SQL Injection IPv6 | critical | View or Download | UNDERCODE | 2025-02-18 |
| OpenClaw | <=2026.2.14 | Token Leak | moderate | View or Download | UNDERCODE | 2026-02-18 |
🌐 UNDERCODENEWS LIVE
Active
0
⚡
Live Attacks
Getting Updates…
🕒
24h
0
📅
Today
0
🌐
Total
0
--:--:--
🖱️
Click to interact with map
scroll, zoom & pan
Active Exploit
Dormant
Trajectory
Target Sector
🛡️ UNDERCODENEWS THREAT INTEL · SYSTEM v2.0
Threat Level
CRITICAL
🔒 SECURE CONNECTION
