
XRP Ledger Bug May Have Allowed Unlimited Token Generation Without Detection
Analysis suggests a logic error in the XRP network could have permitted the creation of arbitrary amounts of cryptocurrency, raising concerns about historical integrity.
The Payload Report Vulnerability Desk is the part of the Payload Report newsroom that covers software flaws, vendor advisories and patches. It is a newsroom desk, not a single person. Sections: Vulnerabilities. Stories start from more than 150 monitored sources. Drafts are prepared with AI assistance and checked by software against the cited sources before they are published. It has published 9 articles so far. See the editorial policy or report an error.

Analysis suggests a logic error in the XRP network could have permitted the creation of arbitrary amounts of cryptocurrency, raising concerns about historical integrity.

The AI firm introduces a new tool to help maintainers identify security flaws in their codebases without cost.

A critical flaw in the Blocksy Companion WordPress plugin lets attackers bypass security checks to seize seller roles and publish content without logging in.

National Vulnerability Database lists this deserialization defect as critical with a CVSS score of 9.8 for ThemeREX Group software.

Vikunja has released version 2.4.0 to address a critical flaw that allowed attackers to extract user data via unvalidated view IDs in share links.

Federal agency mandates urgent action for critical remote code execution flaw in document server software.

Federal agencies must address CVE-2016-3081 in Apache Struts by mid-October following its addition to the Known Exploited Vulnerabilities catalog.

Amazon Web Services has released a fix for a high-severity flaw allowing remote command execution via crafted database commands.

A critical remote code execution vulnerability in Handlebars allows attackers to inject arbitrary JavaScript via manipulated AST objects, prompting an urgent update.