Threats Tagged 'cwe-1241'
View all threats tagged with 'cwe-1241'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-1241'
Click on any threat for detailed analysis and mitigation recommendations
0 Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining guest access to that order's details and any purchased digital downloads. Because the token is never rotated, this exposure persists indefinitely even after the underlying secret-disclosure vector is patched, unless the Joomla secret itself is also rotated. The attack complexity (`AC:H`) is high because it depends on the secret already being known through a separate vector; it is not directly exploitable by an anonymous visitor with no other foothold. Join the discussion | CVE Database V5 | 09/15/2026, 18:54:21 UTC Added: 09/15/2026, 19:02:21 UTC |
0 Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes the resulting redirect to `com_j2store`'s checkout controller to carry attacker-chosen query parameters instead of only the intended `view=checkout&task=confirmPayment&orderpayment_type=...&paction=process` set — parameter injection/smuggling into that follow-up request. This requires a victim to load the crafted link (`UI:R`/`UI:P`); it does not by itself grant an unauthenticated attacker anything they could not already obtain by requesting the target `com_j2store` URL directly with their own parameters. Join the discussion | CVE Database V5 | 09/15/2026, 18:50:47 UTC Added: 09/15/2026, 19:02:21 UTC |
0 In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumentEditingJwtSecret is generated using an insecure random number generator, resulting in insufficient entropy. An attacker who obtains a JWT signed with the generated secret may be able to recover the JWT signing secret through offline brute-force, potentially enabling JWT forgery. Join the discussion | CVE Database V5 | 08/13/2026, 18:31:38 UTC Added: 08/13/2026, 15:42:08 UTC |
0 A security update for Keylime addresses CVE-2026-6420, which involves the use of a hardcoded challenge nonce in TPM quote attestation. This vulnerability allows a security bypass in the attestation process. The update to Keylime version 7.14.2 fixes this issue. The vulnerability is rated as medium severity and affects certain versions of Keylime distributed with Red Hat Enterprise Linux 10 and related platforms. Join the discussion | GCVE Database | 06/22/2026, 14:35:18 UTC Added: 06/24/2026, 16:59:26 UTC |
The Popup Builder – Create highly converting, mobile friendly marketing popups.plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenticated attackers to unsubscribe arbitrary subscribers from mailing lists via brute-forcing the unsubscribe token, granted they know the victim's email address Join the discussion | CVE Database V5 | 02/19/2026, 03:25:14 UTC Added: 02/19/2026, 04:11:17 UTC |
0 The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is possible to reveal all 32 corresponding responses by sniffing CAN traffic or by pre-calculating the values, which allow to bypass the protection. First identified on Nissan Leaf ZE1 manufactured in 2020. Join the discussion | CVE Database V5 | 01/22/2026, 15:21:21 UTC Added: 01/22/2026, 15:35:57 UTC |
Showing 1 to 6 of 6 results