Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Apr 29
SEC Consult Vulnerability Lab Security Advisory < 20260427-0 >
=======================================================================
title: Missing TLS Certificate Validation leading to RCE
product: DeskTime Time Tracking App
vulnerable version: 1.3.671
fixed version: –
CVE number: CVE-2025-10539
impact: medium
homepage:https://desktime.com…
– Read More – Full Disclosure


![[KIS-2026-07] SocialEngine <= 7.8.0 Blind Server-Side Request Forgery Vulnerability AttackFeed by Joe Wagner | [KIS-2026-07] SocialEngine](https://attackfeed.com/wp-content/uploads/2026/04/fulldisclosure-img-t6Ehd0.webp)
