Skip to main content

Threats Tagged 'cwe-138'

View all threats tagged with 'cwe-138'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-138

Threats Tagged 'cwe-138'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-55841 is a vulnerability in Graylog2-server affecting the FortiGate key-value syslog parser. It mishandles field-like text inside quoted values, allowing crafted syslog messages to manipulate or remove security-log fields. This can enable an unauthenticated network sender to obscure malicious activity by evading logging. The issue is fixed in Graylog Server versions 6.3.12, 7.0.7, 7.1.2, and Graylog Forwarder version 7.3.

Join the discussion

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Join the discussion

Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.

Join the discussion

tarteaucitron.js is a compliant and accessible cookie banner. Prior to version 1.22.0, a vulnerability was identified in tarteaucitron.js where document.currentScript was accessed without verifying that it referenced an actual <script> element. If an attacker injected an HTML element, it could clobber the document.currentScript property. This causes the script to resolve incorrectly to an element instead of the <script> tag, leading to unexpected behavior or failure to load the script path correctly. This issue arises because in some browser environments, named DOM elements become properties on the global document object. An attacker with control over the HTML could exploit this to change the CDN domain of tarteaucitron. This issue has been patched in version 1.22.0.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Tag: cwe-138
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses