DEV Community

threataft profile picture

threataft

I run ThreatAft (threataft.com), an independent cybersecurity publication focused on CVE analysis and vulnerability intelligence. I publish daily articles covering critical CVEs, mass disclosures, and

Joined Joined on 
YesWiki 9 CVEs — CVSS 8.6 SQL Injection Can Dump Your Entire Database

YesWiki 9 CVEs — CVSS 8.6 SQL Injection Can Dump Your Entire Database

Comments
1 min read
UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket

UTMStack Cluster — 7 CVEs, Peak CVSS 9.9 Missing Auth on STOMP Command WebSocket

Comments
1 min read
WordPress Auth Bypass Cluster — 4 CVSS 9.8, Full Site Takeover via Plugin Flaws

WordPress Auth Bypass Cluster — 4 CVSS 9.8, Full Site Takeover via Plugin Flaws

Comments
1 min read
Ghost CMS Mass Disclosure — 6 CVEs Including CVSS 8.1 Staff Session Bypass

Ghost CMS Mass Disclosure — 6 CVEs Including CVSS 8.1 Staff Session Bypass

Comments
1 min read
Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

Mooncake Mass Disclosure — CVSS 9.8 Arbitrary Memory Read/Write in KV Cache Transfer Engine

Comments
1 min read
Dockhand CVE-2026-53988 — CVSS 10.0 Unauthenticated Webhook Auth Bypass

Dockhand CVE-2026-53988 — CVSS 10.0 Unauthenticated Webhook Auth Bypass

Comments
1 min read
Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows

Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows

Comments
1 min read
Cisco SD-WAN Manager CVE-2026-76504 — CVSS 9.8 Auth Bypass via URI Encoding, Actively Exploited

Cisco SD-WAN Manager CVE-2026-76504 — CVSS 9.8 Auth Bypass via URI Encoding, Actively Exploited

Comments
1 min read
Five vulnerabilities in AiSOC (the open-source SOC platform) were disclosed today.

Five vulnerabilities in AiSOC (the open-source SOC platform) were disclosed today.

Comments
1 min read
LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

LightLLM Mass Disclosure — 2 CVSS 9.8 Unauthenticated RCE in LLM Serving Framework

Comments
2 min read
CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

CTranslate2 CVE-2026-102566 & CVE-2026-102567 — Heap Overflow in AI Model Loader

Comments
2 min read
RaspAP Mass Disclosure — 3 CVEs, Privilege Escalation + RCE, No Patch

RaspAP Mass Disclosure — 3 CVEs, Privilege Escalation + RCE, No Patch

Comments
2 min read
loading...