moltenbit

I look for security bugs and publish them once they are fixed.

One column per disclosure, oldest on the left.

45 disclosures 39 CVEs since 2026-03 latest 2026-08-24

  • 7 critical
  • 13 high
  • 19 moderate
  • 5 low
  • 1 no score

Writeups

all writeups

Recent disclosures

all 45
CVE-2026-10627
Events Manager WordPress Plugin

missing authorization lets unauthenticated attackers use status, private, and private_only parameters to view draft, pending, trashed, or private event and location details

CVE-2026-71540
Wazuh

pre-authentication cluster header parsing lets one source IP allocate 256 MiB of manager memory per TCP connection

CVE-2026-74046
Wazuh

zlib decompression bomb in cluster archive processing lets an authenticated peer exhaust wazuh-clusterd memory

CVE-2026-74044
Wazuh

peer-controlled cluster hello node name lets an authenticated peer delete the contents of arbitrary manager directories on disconnect

CVE-2026-48024
Wazuh

merged-file header path traversal in cluster sync allows a cluster peer to write arbitrary files under WAZUH_PATH and reach root code execution