Tag
high
advisory
Math.js Improperly Controlled Modification of Object Attributes Leads to RCE
2 rules 1 TTPA vulnerability in math.js versions before 15.2.0 allows for arbitrary JavaScript execution through the expression parser when evaluating user-supplied expressions.
mathjs
rce
expression-injection
2r
1t
critical
advisory
Thymeleaf Server-Side Template Injection Vulnerability
2 rules 1 TTPThymeleaf versions up to 3.1.3.RELEASE are vulnerable to server-side template injection (SSTI) due to improper neutralization of specific syntax patterns, allowing attackers to execute unauthorized expressions when unvalidated user input is passed directly to the template engine.
Thymeleaf +2
ssti
cve-2026-40478
server-side template injection
expression injection
2r
1t
critical
advisory
OpenRemote IoT Platform Expression Injection Vulnerability
2 rules 1 TTPThe OpenRemote IoT platform is vulnerable to expression injection, allowing remote code execution due to an unsandboxed Nashorn JavaScript engine and an inactive Groovy sandbox, leading to full server compromise.
OpenRemote IoT Platform
openremote
expression-injection
remote-code-execution
iot
2r
1t