Skip to content
Threat Feed

Tag

Remote Code Execution

405 briefs RSS
high advisory

Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway

A critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.

Secure Mail Gateway vulnerability remote-code-execution network-appliance
2t 1c
high advisory

Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)

An integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability remote-code-execution ibm-mq
1c
critical advisory

Remote Code Execution in jsonpath-plus via CVE-2025-1302

CVE-2025-1302 is a critical remote code execution vulnerability in the jsonpath-plus library, exploitable via malicious JSONPath expressions injected through query parameters.

jsonpath-plus remote-code-execution injection web-application library-vulnerability
1r 2t 1c
high threat

Stack Buffer Overflow in IBM MQ XA Transaction Processing

IBM MQ is vulnerable to a stack buffer overflow triggered by malicious XA transaction identifiers, allowing an authenticated attacker to cause a denial of service or achieve arbitrary code execution.

exploited MQ vulnerability remote-code-execution denial-of-service
1c
critical threat

Heap Buffer Underflow in IBM MQ for HPE NonStop

IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.

exploited IBM MQ for HPE NonStop vulnerability remote-code-execution ibm-mq critical
1t 1c
high advisory

Remote Code Execution in ClipBucket via Unrestricted File Upload

Authenticated users can exploit a file upload vulnerability in ClipBucket v5 before 5.5.3-#182 to achieve remote code execution by bypassing MIME validation.

ClipBucket cve-2026-77929 remote-code-execution file-upload
1r 1t 1c
critical advisory

Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic

Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.

DiskStation Manager +7 vulnerability critical remote-code-execution file-read-write dsm file-access synology cve +4
1t 6c
high advisory

Command Injection in marcopiovanello yt-dlp-web-ui

An unauthenticated remote command injection vulnerability in yt-dlp-web-ui version 4 and earlier allows remote attackers to execute arbitrary system commands via the params argument.

yt-dlp-web-ui remote-code-execution command-injection vulnerability
2t 1c
critical advisory

Chamilo LMS CStudio Unauthenticated Remote Code Execution

An unauthenticated remote code execution vulnerability in the Chamilo LMS CStudio upload flow allows attackers to gain server-level access by exploiting improper file handling (CVE-2026-45140).

PoC Chamilo LMS remote-code-execution web-application critical-vulnerability
1r 2t 1c updated
high advisory

Remote Code Execution in SiYuan via Malicious Bookmark Labels

SiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.

SiYuan +2 vulnerability rce electron xss web-application-vulnerability sql-injection data-exfiltration web-vulnerability +1
1r 5t 1c updated
high advisory

Arbitrary File Upload Vulnerability in Paid Downloads WordPress Plugin

An unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (<= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.

Paid Downloads web-vulnerability wordpress remote-code-execution
1r 1t 1c
critical advisory

Multi-tenant Isolation Bypass in djust via WebSocket/SSE

A vulnerability in djust caused multi-tenant isolation to fail open on WebSocket and SSE paths, allowing unauthorized cross-tenant data disclosure due to improper tenant context propagation.

djust +1 web-application mass-assignment cve-2026-61598 remote-code-execution information-disclosure cve-2026-61590 idor broken-access-control +5
6t 1c updated
critical advisory

Remote Command Injection in Ruijie RG-EW3000GX

A critical remote OS command injection vulnerability in the Ruijie RG-EW3000GX router allows unauthenticated attackers to execute arbitrary commands via the configChange component.

RG-EW3000GX remote-code-execution cve-2026-92398 command-injection
1r 2t 1c
high advisory

Multiple Vulnerabilities in Aruba EdgeConnect

Multiple vulnerabilities in Aruba EdgeConnect allow for privilege escalation, denial of service, information disclosure, file manipulation, cross-site scripting, security bypass, and arbitrary code execution.

Aruba EdgeConnect vulnerability network-infrastructure remote-code-execution
5c
high advisory

Multiple Vulnerabilities in Microsoft Edge

Multiple vulnerabilities in Microsoft Edge allow remote attackers to achieve arbitrary code execution and escalate privileges on the host system.

Edge browser vulnerability remote-code-execution
2t 1c updated
high advisory

Multiple Vulnerabilities in Docker Sandboxes

Multiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.

Docker Sandboxes vulnerability remote-code-execution docker
2c
high advisory

Command Injection in /index.php/ajax/parameterManage Endpoint

A low-privileged remote attacker can exploit a command injection vulnerability at the /index.php/ajax/parameterManage endpoint using valid credentials to gain root-level code execution.

web-vulnerability remote-code-execution command-injection cve-2026-27551
1r 1t 1c
high advisory

Remote Command Injection in TOTOLINK X5000R

A remote OS command injection vulnerability in the TOTOLINK X5000R router allows unauthenticated attackers to execute arbitrary commands via the exportOvpn function.

X5000R remote-code-execution cve-2026-91853 network-security
1r 1t 1c
critical threat

Hard-Coded JWT Key in Issabel Framework Enabling RCE

A hard-coded HS256 signing key in the Issabel Framework allows unauthenticated attackers to forge JWTs and execute arbitrary commands via the Asterisk manager originate endpoint.

PoC Issabel Framework +2 remote-code-execution pbx cve-2026-89026
2t 1c updated
critical threat

Unauthenticated SQL Injection in Yonyou U8 CRM (CVE-2024-58385)

An unauthenticated SQL injection vulnerability in Yonyou U8 CRM allows attackers to execute arbitrary SQL commands via the fillbacksettingedit.php endpoint, potentially leading to remote code execution on MS SQL Server instances.

exploited U8 CRM web-application sql-injection remote-code-execution cve-2024-58385
1r 2t 1c
critical advisory

Critical Vulnerabilities in Digital Watchdog VMAX DVR and NVR Products

Multiple high-severity vulnerabilities in Digital Watchdog VMAX series devices allow unauthenticated remote attackers to bypass authentication, gain root access via hard-coded credentials, and execute arbitrary system commands.

VMAX A1 G4 DVRs +4 critical-infrastructure ics authentication-bypass remote-code-execution
2t
high advisory

Multiple Vulnerabilities in IBM MQ

IBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.

MQ vulnerability messaging-middleware remote-code-execution
2c
high advisory

Remote Code Execution in Polyaxon via Unsandboxed Jinja2 Injection

Authenticated users can execute arbitrary commands on the Polyaxon scheduler process by injecting malicious Jinja2 payloads into operation specification fields.

Polyaxon remote-code-execution jinja2 template-injection
1t 1c
high advisory

Use-After-Free Vulnerability in GPAC Compositor

A use-after-free vulnerability in the GPAC compositor component (CVE-2026-91087) allows remote attackers to trigger memory corruption via malicious media files.

GPAC +2 vulnerability memory-corruption remote-code-execution cve
1c updated
critical advisory

Remote Code Execution in EFM ipTIME C200E via Command Injection

An unauthenticated remote command injection vulnerability in EFM ipTIME C200E firmware version 1.094 allows remote attackers to execute arbitrary operating system commands via the iux_set.cgi script.

ipTIME C200E remote-code-execution cve-2026-90847 networking command-injection
2t 1c
critical advisory

Hard-coded JWT Secret in Crawlab Vulnerability

Crawlab versions 0.6.3 and earlier utilize a hard-coded HMAC-SHA256 secret for JWT signing, enabling unauthenticated attackers to forge administrative tokens and achieve remote code execution.

Crawlab web-application authentication-bypass remote-code-execution
2t 1c
high advisory

Remote Command Injection in 0x4m4 HexStrike AI

A command injection vulnerability in HexStrike AI allows remote unauthenticated attackers to execute arbitrary OS commands via the Execute Endpoint.

HexStrike AI +1 remote-code-execution vulnerability command-injection api-security
1r 3t 1c
high advisory

Remote Command Injection in GH05TCREW PentestAgent

A critical remote command injection vulnerability (CVE-2026-90617) exists in the MCP HTTP Server component of GH05TCREW PentestAgent, allowing unauthenticated attackers to execute arbitrary OS commands via the run_task function.

PentestAgent +1 remote-code-execution cve pentest-tool cve-2026-90618 command-injection rce
2t 1c
high advisory

Unrestricted File Upload Vulnerability in Anil-matcha Open-Generative-AI

Anil-matcha Open-Generative-AI is vulnerable to unrestricted file uploads via the /api/upload-binary endpoint, allowing remote attackers to manipulate the x-proxy-target-url argument to upload arbitrary files.

Open-Generative-AI vulnerability remote-code-execution web-application-security
1r 1c
critical advisory

Exploitation of CVE-2021-38647 (OMIGOD) in Open Management Infrastructure

Publicly available proof-of-concept exploits for CVE-2021-38647 allow unauthenticated remote command execution via the OMI framework by omitting the Authorization header.

Open Management Infrastructure +4 vulnerability remote-code-execution cloud omi omigod
1r 2t 1c
high advisory

Path Traversal Vulnerability in rustypaste

rustypaste versions prior to 0.18.1 contain a path traversal vulnerability that allows attackers to write files to arbitrary locations by manipulating the custom filename HTTP header.

rustypaste path-traversal vulnerability remote-code-execution
2t 1c
critical advisory

Remote Code Execution in Dell iDRAC7 and iDRAC8

CVE-2018-1207 allows unauthenticated attackers to achieve root-level remote code execution on Dell iDRAC7 and iDRAC8 firmware versions 2.52.52.52 and below via dynamic linker injection.

iDRAC7 +1 cve-2018-1207 rce idrac remote-code-execution firmware-vulnerability
1r 3t 1c
high advisory

Remote Code Execution in vLLM LlavaOnevision2 Processor Loader

A vulnerability in vLLM versions prior to 0.28.0 allows remote code execution by bypassing the trust_remote_code parameter during the loading of malicious LlavaOnevision2 processor classes.

vLLM +2 remote-code-execution model-inference supply-chain denial-of-service vulnerability
1r 2t 1c updated
high advisory

Prototype Pollution in yayson Store and LegacyStore

The yayson library (<= 4.2.0) is vulnerable to prototype pollution when deserializing malicious JSON:API documents, allowing unauthenticated attackers to corrupt the global Object.prototype and potentially achieve RCE via gadget chains.

yayson prototype-pollution deserialization remote-code-execution nodejs
1t
high advisory

Multiple Vulnerabilities in GitLab CE and EE

GitLab has released security patches addressing a large set of vulnerabilities across Community and Enterprise editions, including flaws leading to remote code execution and data confidentiality compromises.

PoC GitLab Community Edition +7 vulnerability remote-code-execution gitlab
1c updated
critical advisory

Unauthenticated Arbitrary File Write in WAVLINK Routers

WAVLINK WN535M1 and WN535M3 routers are vulnerable to unauthenticated arbitrary file writes via the sync_server daemon, enabling attackers to gain root-level persistence.

WN535M1 +1 network-security remote-code-execution cve-2026-89009
2t 1c
high advisory

Stack-Based Buffer Overflow in IBM Db2 DRDA Client Implementation

IBM Db2 versions 11.5.0-11.5.9 and 12.1.0-12.1.5 are vulnerable to a stack-based buffer overflow via malicious DRDA server responses, potentially leading to arbitrary command execution on clients.

Db2 vulnerability cve remote-code-execution denial-of-service database-security
2t 1c
critical advisory

Critical RCE Vulnerability in Fortinet Products via AuthHash Cookie (CVE-2025-32756)

A critical unauthenticated stack-based buffer overflow vulnerability, tracked as CVE-2025-32756, affects multiple Fortinet products and can be triggered via a crafted 'enc' parameter in the 'AuthHash' cookie.

FortiMail +4 remote-code-execution buffer-overflow vulnerability
1r 1t 1c
high advisory

Unauthenticated Remote Task Execution in @yeger/turbo-graph

The @yeger/turbo-graph package exposes an unauthenticated HTTP endpoint (/api/run) that binds to all network interfaces, allowing adjacent attackers to execute arbitrary Turborepo tasks defined in the victim repository.

turbo-graph remote-code-execution nodejs insecure-api
2t
high advisory

Arbitrary Code Execution in Joker Linter via Malicious Project-Local Configuration

Joker versions before 1.8.2 are vulnerable to arbitrary code execution because the linter automatically traverses directory structures to execute project-local 'linter.*' files, allowing execution of attacker-supplied code within untrusted repositories.

Joker remote-code-execution vulnerability development-tools
1t
high advisory

Remote Code Execution in functype-mcp-server via Unsanitized MCP Tool Input

The set_functype_version MCP tool in functype-mcp-server allows unauthenticated attackers to execute arbitrary code by passing a malicious package alias to pnpm, which the server subsequently executes via dynamic import.

functype-mcp-server remote-code-execution mcp nodejs
1r 1t
high advisory

Unauthenticated Access to ESPHome Dashboard via Ingress Interface Misconfiguration

An auth bypass in the ESPHome Home Assistant add-on allows unauthenticated LAN access to the dashboard due to improper interface binding, enabling remote code execution on the host.

esphome-device-builder auth-bypass remote-code-execution home-assistant esphome
2t
high advisory

Arbitrary File Upload in Rara One Click Demo Import WordPress Plugin

An authenticated administrator can exploit CVE-2026-26212 in the Rara One Click Demo Import plugin to achieve remote code execution by bypassing file type validation during the upload process.

Rara One Click Demo Import wordpress arbitrary-file-upload remote-code-execution plugin-vulnerability
1r 2t 1c
high advisory

Heap-based Buffer Overflow in VLC Media Player via Malformed PNG

A 32-bit integer overflow in VLC media player's picture buffer calculation allows remote attackers to trigger a heap-based buffer overflow via crafted PNG files.

VLC media player vulnerability remote-code-execution media-player
1t 1c
high advisory

Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM

Multiple vulnerabilities in Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570, CVE-2024-7571) allow a remote unauthenticated attacker to achieve remote code execution.

Neurons for ITSM vulnerability remote-code-execution ivanti
3c
high advisory

Argument Injection in bestzip nativeZip Function

The bestzip package version 2.2.6 and 3.0.2 is vulnerable to argument injection in the nativeZip function, allowing unauthenticated attackers to execute arbitrary commands via malicious input.

bestzip vulnerability remote-code-execution nodejs software-supply-chain
1t 1c
high advisory

Remote Code Execution in Windows Presentation Foundation

A high-severity remote code execution vulnerability (CVE-2026-50646) in .NET WPF allows arbitrary code execution via maliciously crafted XAML input.

Microsoft.WindowsDesktop.App.Runtime.win-arm64 +8 remote-code-execution vulnerability dotnet wpf
1t 1c
high advisory

Remote Code Execution via CORS Misconfiguration in winml-cli

An unauthenticated RCE vulnerability in winml-cli (CVE-2026-84452) allows remote attackers to execute arbitrary code via a malicious website sending cross-origin requests to the local API server.

winml-cli remote-code-execution web-application cors
2t 1c
critical advisory

OS Command Injection in Semaphore UI via Repository Configuration

An authenticated user with Manager or Owner privileges can achieve remote code execution on the Semaphore server by injecting malicious arguments into the git_url field.

Semaphore remote-code-execution command-injection cve-2026-73294
1t 1c
critical advisory

Heap-Based Buffer Overflow in Telnet Client (CVE-2026-69431)

CVE-2026-69431 is a critical heap-based buffer overflow vulnerability in the Telnet Client that allows an unauthenticated, remote attacker to achieve arbitrary code execution over a network connection.

Telnet Client vulnerability cve remote-code-execution
1t 1c
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
critical advisory

CVE-2026-86542 Path Traversal in knowns Application

An unauthenticated path traversal vulnerability in knowns versions prior to 0.30.0 allows attackers to overwrite arbitrary files on the server by supplying malicious traversal sequences in the import route name parameter.

knowns +1 remote-code-execution cve vulnerability path-traversal mcp
2r 6t 1c updated
critical advisory

Unauthenticated Remote Code Injection in Next4Biz CSM

CVE-2026-7861 is a critical deserialization of untrusted data vulnerability in Next4Biz CSM that permits unauthenticated remote code execution via malicious object injection.

CSM +1 vulnerability remote-code-execution cve
2t 1c
high advisory

Unrestricted File Upload Vulnerability in U+Smart Enjoyment WebSite

An unrestricted file upload vulnerability in U+Smart Enjoyment WebSite version 18.6001.1096.1000 allows unauthenticated remote attackers to execute arbitrary code via the /Report/Upload/UploadFormImg.ashx endpoint.

U+Smart Enjoyment WebSite web-application remote-code-execution cve-2026-86272
1r 2t 1c
critical advisory

MediaWiki Remote Code Execution via PHP Deserialization

MediaWiki is vulnerable to remote code execution (CVE-2026-58025) via insecure PHP deserialization within the LogEntryBase::extractParams method, allowing authenticated sysop users to execute arbitrary code through malicious XML imports.

MediaWiki remote-code-execution deserialization
1r 2t 2c
high advisory

Remote Code Execution in Microsoft Web Deploy via CVE-2025-53772

An unauthenticated or low-privilege attacker can achieve remote code execution in Microsoft Web Deploy versions prior to 10.0.2001 by exploiting insecure deserialization of the 'MSDeploy.SyncOptions' HTTP header.

Web Deploy remote-code-execution deserialization cve-2025-53772 iis web-deploy
1r 2t 1c
critical advisory

Remote Command Injection Vulnerability in Tenda CP3

An unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.

CP3 remote-code-execution firmware-vulnerability iot network-appliance command-injection iot-vulnerability cve-2026-86152
2t 1c
critical advisory

Authentication Bypass in Lara Dashboard

Lara Dashboard versions prior to 1.3.0 are vulnerable to an authentication bypass in the screenshot-login route that permits unauthenticated access to any user account when APP_ENV is not set to production.

Lara Dashboard +2 vulnerability authorization-bypass remote-code-execution web-application ssrf cve-2026-87821
2r 3t 1c updated
high advisory

Remote Code Execution in Axolotl via trust_remote_code Bypass

Axolotl versions through 0.18.0 contain a remote code execution vulnerability where an insecure default configuration allows attackers to bypass security guards and execute arbitrary Python code.

Axolotl remote-code-execution machine-learning supply-chain
1t 1c
critical advisory

Authentication Bypass in Cua computer-server via Environment Variable Misconfiguration

Cua computer-server versions prior to 0.3.42 contain an authentication bypass vulnerability triggered when the CONTAINER_NAME environment variable is unset, allowing unauthenticated remote command execution on TCP port 8000.

computer-server authentication-bypass remote-code-execution cve-2026-86121
1r 2t 1c
critical advisory

Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051)

CVE-2023-34051 is an authentication bypass in VMware vRealize Log Insight that allows unauthenticated arbitrary file write and remote code execution via chained exploitation of Thrift RPC endpoints.

vRealize Log Insight +1 vulnerability remote-code-execution cve
3t 4c
high advisory

Heap Buffer Overflow in ntop nDPI

Versions of ntop nDPI before 6.0 are vulnerable to a heap-based buffer overflow in the ndpi_json_string_escape function, allowing attackers to trigger memory corruption via crafted network traffic.

nDPI vulnerability remote-code-execution network-security
1t 1c
high advisory

Authentication Bypass in Nango Runner tRPC Server

Nango versions prior to 0.71.6 contain an authentication bypass vulnerability allowing unauthenticated attackers to achieve remote code execution via the tRPC runner server.

Nango vulnerability remote-code-execution
2t 1c
high advisory

Multiple Vulnerabilities in SonicWall Network Security Manager

SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.

Network Security Manager On-Prem vulnerability remote-code-execution privilege-escalation patch-management
high advisory

Remote Code Execution in LaVague via Indirect Prompt Injection

LaVague version 0.2.35 contains a remote code execution vulnerability in the PythonFromMarkdownExtractor.extract_as_object function, allowing attackers to execute arbitrary code via indirect prompt injection.

LaVague remote-code-execution injection ai-security supply-chain
1t 1c
high advisory

Arbitrary Command Execution in aider via Malicious Configuration Files

The aider CLI tool is vulnerable to arbitrary command execution because it automatically executes shell commands defined in a .aider.conf.yml file located in the root of a Git repository upon startup.

aider vulnerability remote-code-execution cli-tool
1r 1t 1c
high advisory

Remote Code Execution in Goose 1.37.0 via Malicious Recipes

The goose utility version 1.37.0 contains a vulnerability where insecure handling of recipe stdio extensions and retry.checks permits unvalidated arbitrary shell command execution.

goose remote-code-execution vulnerability supply-chain
1t 1c
high advisory

Unauthenticated SSRF in Openpanel Site Checker

Openpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.

Openpanel +2 web-vulnerability ssrf reconnaissance remote-code-execution injection privilege-escalation web-application cve-2026-88891 +3
1r 8t 1c updated
high advisory

Remote Code Execution in Grav via Twig sort filter

Grav versions 2.0.17 and earlier contain a remote code execution vulnerability in the Twig sort filter that allows authenticated users with page-write permissions to execute arbitrary PHP code.

Grav remote-code-execution web-application php
1t 1c
high advisory

CVE-2026-6471 PostGREShell PostgreSQL Replication Vulnerability

CVE-2026-6471, dubbed PostGREShell, allows attackers with Replication privileges to achieve remote code execution and escalate to superuser by abusing the logical decoding plugin loader.

PostgreSQL vulnerability remote-code-execution privilege-escalation database
3t 1c
high advisory

Unauthenticated Remote Code Execution in Claude Code Studio

An unauthenticated OS command injection vulnerability in the Claude Code Studio HTTP server allows remote attackers to execute arbitrary code via drive-by web requests or local network access.

claude-code-templates remote-code-execution injection express nodejs
1r 2t 1c
high advisory

Buffer Overflow Vulnerability in MOOS ui-moos

The ui-moos component is vulnerable to a buffer overflow in ScopeTabPane.cpp and ScopeGrid.cpp, potentially allowing arbitrary code execution when processing crafted MOOS identifiers.

ui-moos vulnerability remote-code-execution buffer-overflow
1t 1c
high advisory

Remote Code Execution in MOOS essential-moos pAntler

The pAntler component in essential-moos versions 10.0.1 and earlier allows unauthenticated attackers to achieve remote code execution by publishing a crafted MISSION_FILE message to the MOOSDB.

essential-moos remote-code-execution vulnerability cve network-security
4t 1c
critical advisory

Buffer Overflow Vulnerabilities in MOOS-IvP

Multiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.

MOOS-IvP +1 vulnerability cve rce memory-corruption buffer-overflow research-robotics cve-2026-85438 remote-code-execution +4
4t 1c
critical advisory

Authentication Bypass and Message Injection in MOOS pShare

The pShare component in MOOS essential-moos versions up to 10.0.1 is vulnerable to unauthenticated UDP message injection and denial-of-service.

essential-moos vulnerability remote-code-execution network-security cve authorization-bypass robotics
2t 1c
critical advisory

Buffer Overflow in TOTOLINK CP450

A critical buffer overflow vulnerability (CVE-2026-85031) in the TOTOLINK CP450 web interface allows remote, unauthenticated attackers to execute arbitrary code via the 'topicurl' argument.

CP450 vulnerability remote-code-execution cve-2026-85031
1t 1c
critical advisory

Unauthenticated RCE in Ivanti Connect Secure via CVE-2025-0282

A critical unauthenticated stack buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access (version 22.7) allows remote attackers to execute arbitrary code and create unauthorized administrative accounts.

Connect Secure +2 vulnerability remote-code-execution ivanti
2t 1c
high advisory

Authenticated OS Command Injection in OpenChoreo Workflow Plane

Authenticated users can trigger OS command injection in OpenChoreo workflow templates by supplying crafted parameters that are insecurely interpolated into shell execution scripts.

openchoreo vulnerability remote-code-execution kubernetes podman
1t 1c
critical advisory

Remote Code Execution in Submariner via CRD Injection

Submariner in cert-auth mode is vulnerable to command injection via improper input validation in the CableName field, allowing unauthenticated remote code execution as root.

Submariner remote-code-execution kubernetes cve cloud
2t 1c
critical threat

Authentication Bypass in GNU Inetutils Telnet Daemon (CVE-2026-24061)

An authentication bypass vulnerability in GNU Inetutils telnetd (CVE-2026-24061) allows unauthenticated remote attackers to gain root access via a malicious USER parameter.

Inetutils vulnerability cve telnet privilege-escalation remote-code-execution
1r 2t 1c
high advisory

Command Injection Vulnerability in Coolify

Coolify versions before 4.2.0 are vulnerable to command injection via environment variable keys, allowing authenticated attackers to execute arbitrary commands on the underlying host server.

Coolify +2 vulnerability remote-code-execution cloud authentication-bypass web-application
4t 1c updated
high advisory

Integer Overflow Vulnerability in nanoid Leads to Deterministic Token Generation

An integer overflow in the nanoid library allows unauthenticated attackers to permanently corrupt the process-wide CSPRNG pool, forcing all subsequent ID generation to output a deterministic string and enabling mass authentication bypass.

nanoid +1 supply-chain vulnerability remote-code-execution
1t 1c
high advisory

Arbitrary Code Execution in ModelScope via Insecure PyYAML Parsing

ModelScope insecurely utilizes the unsafe yaml.Loader to parse model configuration files, allowing an attacker to achieve arbitrary code execution by supplying a poisoned repository containing malicious Python object construction tags.

ModelScope remote-code-execution vulnerability supply-chain
2t 1c
high advisory

Multiple Vulnerabilities in WatchGuard Fireware OS

Multiple vulnerabilities in WatchGuard Fireware OS, including the Mobile Security component, allow unauthenticated remote attackers to execute arbitrary code via specially crafted network traffic.

Fireware OS vulnerability network-security remote-code-execution watchguard
2t
high advisory

Command Injection Vulnerability in ICP DAS UA-2200 and UA-5200

An unauthenticated remote command injection vulnerability in the ArmAngstromInstructionSet function of ICP DAS UA-2200 and UA-5200 devices allows remote attackers to execute arbitrary code via the ParameterArray argument.

UA-2200 +1 cve command-injection industrial-control-system iiot remote-code-execution
1r 2t 1c
critical advisory

Critical Vulnerability in VMware Aria Operations for Networks (CVE-2023-34039)

VMware Aria Operations for Networks versions 6.0 to 6.10 contain a vulnerability involving static SSH keys that allow unauthorized remote access and root-level privilege escalation.

Aria Operations for Networks vulnerability remote-code-execution network-infrastructure
1r 2t 1c
high advisory

Arbitrary File Deletion in Frontend Admin Plugin for WordPress

An unauthenticated arbitrary file deletion vulnerability in the Frontend Admin plugin for WordPress allows attackers to delete critical server files, potentially leading to remote code execution.

Frontend Admin wordpress arbitrary-file-deletion remote-code-execution cve-2026-19952
1t 1c
critical advisory

Command Injection in Cobham SATCOM VSAT7090 Maritime Satellite Router

An unauthenticated remote command injection vulnerability in the mail-report.sh script of Cobham SATCOM VSAT7090 devices allows attackers to execute arbitrary system commands via crafted JSON input.

VSAT7090 Maritime Satellite Router network-security remote-code-execution cve-2026-83772
1r 2t 1c
critical advisory

Unauthenticated Remote Code Execution in WPLP Cookie Consent Plugin

The WPLP Cookie Consent WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to improper authorization and missing file type validation, enabling remote code execution.

WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode wordpress remote-code-execution cve-2026-75865
2t 1c
high advisory

Unrestricted File Upload Vulnerability in ShopEx ECShop

ShopEx ECShop versions up to 2.5.1 contain an unrestricted file upload vulnerability in the check_img_type function that allows unauthenticated remote attackers to upload malicious files via the pack_img argument.

ECShop web-application-vulnerability remote-code-execution file-upload web-vulnerability sql-injection cve-2026-82922
2r 2t 1c
critical advisory

Unauthenticated Remote Command Injection in QVidium Opera11

QVidium Opera11 version 3.3.2a26-Ax4x-opera11 is vulnerable to unauthenticated remote command injection via the ipaddr parameter in the /cgi-bin/net_tr.cgi script, which lacks security updates due to the vendor ceasing operations.

Opera11 vulnerability remote-code-execution cgi-injection legacy-software
1r 2t 1c
high advisory

Remote Out-of-Bounds Write Vulnerability in D-Link DSM-G600

A critical out-of-bounds write vulnerability in the D-Link DSM-G600 multipart handler allows remote attackers to compromise the device via the /load_file.cgi endpoint, with public exploit code currently available.

DSM-G600 vulnerability remote-code-execution network-appliance
1t 1c
critical advisory

OS Command Injection in D-Link Virtual Volume Handler

D-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.

DNS-340L +4 webserver vulnerability remote-code-execution cve-2026-82692 storage-device cve-2026-85222 command-injection nas +1
3r 3t 1c updated
high advisory

Remote Command Injection in TOTOLINK NR1800X

The TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.

NR1800X remote-code-execution command-injection network-infrastructure
1r 1t 1c
critical advisory

Remote Stack-Based Buffer Overflow in D-Link DIR-825M

A critical stack-based buffer overflow vulnerability in D-Link DIR-825M firmware allows unauthenticated remote attackers to achieve code execution via the /boafrm/formDiskFormat endpoint.

PoC DIR-825M remote-code-execution buffer-overflow network-security
1r 2t 2c updated
high advisory

Remote Buffer Overflow in NASA Trick JSONVariableServer

CVE-2026-82478 is a stack-based buffer overflow in the NASA Trick simulation environment (version 19.6.0) that enables remote attackers to trigger memory corruption via the TCP Socket Handler.

Trick cve vulnerability remote-code-execution nasa-trick
1t 1c
critical advisory

Unauthenticated Remote Access in argocd-mcp via CVE-2026-82456

The argocd-mcp component version 0.8.0 insecurely binds its HTTP transport to all network interfaces and lacks authentication for MCP sessions when an API token is present, allowing remote attackers to perform unauthorized Argo CD resource modifications.

argocd-mcp vulnerability remote-code-execution cloud-native cicd
2t 1c
critical advisory

Remote Code Execution in IBM Langflow OSS via A2A Endpoint

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.

Langflow OSS +4 remote-code-execution vulnerability webserver web-application security-scanner-bypass cve-2026-76059 rce cloud-security +2
1r 8t 1c updated
high advisory

Command Injection in Synk Sweater Comb

Synk Sweater Comb before version 3.8.8 contains a command injection vulnerability in the expectGitBranch() function, allowing arbitrary OS command execution via crafted .vervet.yaml configuration files.

Sweater Comb vulnerability remote-code-execution ci-cd-security
1t 1c
critical advisory

CVE-2026-82266: Unauthenticated Redpanda Admin API Access

Redpanda versions 26.2.2 and earlier insecurely expose the Admin API on port 9644 by default without authentication enabled, allowing remote attackers to perform superuser actions.

Redpanda vulnerability remote-code-execution api-security
1r 1t 1c
high advisory

Critical Vulnerability in n8n Allows Remote File Manipulation and Data Disclosure

A vulnerability in n8n allows a remote, unauthenticated attacker to manipulate files and disclose sensitive information on the platform, identified as CVE-2024-51746.

n8n vulnerability remote-code-execution security-advisory
1t 1c updated
critical threat

Unauthenticated OS Command Injection in NUMail

NUMail contains an unauthenticated OS command injection vulnerability allowing remote attackers to execute arbitrary system-level commands on affected servers.

exploited NUMail remote-code-execution vulnerability web-application
2t 1c
high threat

Remote Code Execution in GLPI Fields Plugin (CVE-2026-23489)

CVE-2026-23489 is a blind remote code execution vulnerability in the GLPI Fields plugin (<= 1.23.2) that allows authenticated attackers to execute arbitrary PHP code via the dropdown-generation feature.

exploited Fields Plugin remote-code-execution web-application-vulnerability
1r 2t 1c
high advisory

Critical Vulnerabilities in Adobe Campaign Classic

Adobe Campaign Classic is affected by three critical vulnerabilities, including SSRF and OS Command Injection, which allow unauthenticated remote attackers to achieve full system compromise.

Campaign Classic vulnerability remote-code-execution adobe ssrf
3c
high threat

Path Traversal Vulnerability in with-context-mcp

A publicly disclosed path traversal vulnerability (CVE-2026-81491) in boxpositron with-context-mcp versions 3.0.7 and earlier allows remote attackers to manipulate file paths via specific ingested note functions.

exploited with-context-mcp path-traversal vulnerability remote-code-execution
1t 1c
critical advisory

Unauthenticated Remote Code Execution in senaite.core

An unauthenticated remote code execution vulnerability in senaite.core allows attackers to execute arbitrary Python code via a two-request chain leveraging missing authorization and unsafe eval() usage in the JSON API.

senaite.core remote-code-execution injection web-application senaite
1r 1t
critical threat

Active Exploitation of Windows IKE Extension RCE

CVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.

exploited Windows vulnerability remote-code-execution
2t 1c
critical threat

OS Command Injection in ClipBucket V5 Installer

ClipBucket V5 versions 5.5.1 through 5.5.3-#153 contain an OS command injection vulnerability in the web installer, allowing unauthenticated remote code execution via the php_cli_filepath parameter.

exploited clipbucket-v5 remote-code-execution web-application-vulnerability
1r 2t 1c
high advisory

Authenticated Remote Code Execution in qwed via Unsafe SymPy Parsing

The qwed package (version 5.1.1) fails to sanitize input in math verification endpoints, allowing authenticated attackers to achieve remote code execution via unsafe SymPy expression evaluation.

qwed remote-code-execution input-validation python
1r 1t
high advisory

DNS Rebinding Vulnerability in GenieACS MCP Streamable HTTP Transport

The genieacs-mcp package fails to validate Host and Origin headers on loopback listeners, allowing unauthorized web pages to perform DNS rebinding and invoke administrative GenieACS tools via an unauthenticated MCP interface.

genieacs-mcp dns-rebinding mcp genieacs remote-code-execution
1t 1c
critical advisory

Remote Code Execution in qwed-mcp via Unsafe SymPy Input

The qwed-mcp library v0.2.0 is vulnerable to arbitrary remote code execution because it passes unsanitized input to SymPy's parse_expr function, allowing attackers to execute arbitrary system commands via Python code injection.

qwed-mcp remote-code-execution python injection supply-chain
1r 1t
high advisory

Multiple Vulnerabilities in SEPPmail Secure E-Mail Gateway

SEPPmail Secure E-Mail Gateway contains multiple vulnerabilities that an attacker can exploit to bypass security controls and achieve remote code execution on the appliance.

Secure E-Mail Gateway vulnerability email-security remote-code-execution
1t
high advisory

Arbitrary File Upload in CM Map Locations WordPress Plugin

The CM Map Locations WordPress plugin is vulnerable to remote code execution due to insufficient file validation in the uploadMedia function, allowing subscriber-level authenticated users to upload arbitrary executable files.

CM Map Locations wordpress arbitrary-file-upload remote-code-execution plugin-vulnerability
2t 1c
high advisory

Autodesk 3ds Max Out-of-Bounds Write Vulnerability (CVE-2026-16783)

Autodesk 3ds Max contains an out-of-bounds write vulnerability triggered by parsing maliciously crafted Alembic (.abc) files, potentially allowing arbitrary code execution upon user interaction.

3ds Max +1 vulnerability autodesk remote-code-execution
1t 1c
high advisory

Command Injection Vulnerability in DrayTek VigorSwitch

Authenticated attackers can exploit a command injection flaw in the DrayTek VigorSwitch commandTable function to achieve root-level remote code execution.

VigorSwitch vulnerability remote-code-execution network-infrastructure
2t 1c
critical advisory

Critical OS Command Injection in DrayTek VigorSwitch

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.

VigorSwitch G2540xs +10 vulnerability remote-code-execution network-infrastructure cve network-security network hardware
1r 3t 1c
high advisory

SSRF and Credential Leakage in AWX Notification Backends

CVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.

AWX web-vulnerability ssrf credential-leakage path-traversal arbitrary-file-write remote-code-execution cve-2026-71364
3t 1c
critical advisory

Remote Code Execution in Netis NC63 Firmware via Buffer Overflow

A stack-based buffer overflow in the Netis NC63 login handler allows unauthenticated remote attackers to achieve root-level code execution.

NC63 remote-code-execution network-device buffer-overflow
1t
high advisory

Remote Code Execution in Xinference via Unsafe Model Loading

Xinference versions prior to 2.12.0 are vulnerable to remote code execution because they unconditionally enable 'trust_remote_code=True' when loading models, allowing attackers to execute arbitrary Python code via crafted model configurations.

Xinference remote-code-execution vulnerability ai-security
1t 1c
high advisory

Unrestricted File Upload Vulnerability in itsourcecode Online Pharmacy System

An unauthenticated remote code execution vulnerability (CVE-2026-78245) exists in itsourcecode Online Pharmacy System 1.0 due to improper file validation within the user registration process.

Online Pharmacy System web-vulnerability remote-code-execution cve-2026-78245
1r 2t 1c
high advisory

SQL Injection in Real Estate Management System

The itsourcecode Real Estate Management System 1.0 contains an SQL injection vulnerability in search.php that allows unauthenticated remote attackers to execute arbitrary database queries.

Real Estate Management System web-vulnerability sqli remote-code-execution
1r 2t 1c
high advisory

Remote Code Execution via Out-of-Bounds Write in libwebsockets LECP Component

An out-of-bounds write vulnerability in the libwebsockets LECP CBOR recording function (CVE-2026-78161) allows remote attackers to trigger memory corruption via crafted CBOR data.

libwebsockets vulnerability remote-code-execution cbor
1t 1c
high advisory

Remote Command Injection in Tenda CH22 Firmware

Tenda CH22 router firmware version 1.0.0.1 is vulnerable to unauthenticated remote command injection via the /goform/editFileName endpoint, allowing potential full system compromise.

CH22 +1 remote-code-execution command-injection network-device
2r 3t 1c updated
critical advisory

Arbitrary Code Execution in JSONata

The JSONata library contains a critical vulnerability (CVE-2026-77415) allowing unauthenticated attackers to achieve arbitrary code execution via maliciously crafted JSONata expressions.

jsonata +2 remote-code-execution cve-2026-77415 software-vulnerability nodejs
1t 1c
high advisory

OTRS Community Edition Authenticated OS Command Injection

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands.

OTRS Community Edition vulnerability remote-code-execution
1t 1c
high advisory

NocoBase Authenticated Remote Code Execution via File Write and LFI Chain

An authenticated admin can achieve remote code execution in NocoBase prior to v2.1.5 by chaining arbitrary file uploads via storage root manipulation with a local file inclusion vulnerability in the plugin manager.

@nocobase/server remote-code-execution lfi nocobase authentication-bypass
1r 2t
high advisory

Unauthenticated Remote Code Execution in Elementor Pro

Elementor Pro versions 4.2.1 and below contain a critical file upload vulnerability (CVE-2026-32475) that allows unauthenticated attackers to achieve remote code execution by bypassing extension validation.

Elementor Pro +1 web-vulnerability wordpress remote-code-execution cve-2026-32475
1r 2t updated
high advisory

Remote Code Injection in chenhg5 cc-connect

An unauthenticated remote code injection vulnerability in the Authenticate function of chenhg5 cc-connect (up to 1.4.1) allows attackers to execute arbitrary code via the exec parameter.

cc-connect vulnerability remote-code-execution injection web-application
1r 2t 1c
high advisory

Privilege Escalation in Splunk AI Toolkit via Agent Run History

A privilege escalation vulnerability in Splunk AI Toolkit versions prior to 6.0.0 allows non-privileged users to execute searches with system-level permissions by exploiting an insecure session token replacement mechanism in the Agent Run History handler.

AI Toolkit +1 vulnerability remote-code-execution
2t 1c
critical threat

Stack-based Buffer Overflow in TRENDnet TEW-755AP Access Points

A critical stack-based buffer overflow vulnerability in the /sbin/mycli binary of TRENDnet TEW-755AP access points allows remote unauthenticated attackers to execute arbitrary code via the 'ssid' argument.

exploited TEW-755AP remote-code-execution buffer-overflow iot networking vulnerability network-security cve-2026-76590 cve-2026-76591 +2
2r 3t 1c
critical advisory

Critical RCE Vulnerability in IBM Power Systems Firmware ASMI

IBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.

Power Systems Firmware vulnerability remote-code-execution firmware hardware
2t 1c
high advisory

Cross-Site Scripting Vulnerability in IBM App Connect Enterprise

IBM App Connect Enterprise contains a vulnerability, identified as CVE-2024-44280, that allows a remote, anonymous attacker to execute Cross-Site Scripting (XSS) attacks within the context of the affected application.

App Connect Enterprise xss web-vulnerability vulnerability remote-code-execution ibm security-advisory
1t 1c updated
critical advisory

Remote Stack-Based Buffer Overflow in UTT HiPER 1200GW

A stack-based buffer overflow vulnerability in the UTT HiPER 1200GW router allows remote attackers to trigger memory corruption via a malicious 'timestart' parameter, with proof-of-concept exploits publicly available.

HiPER 1200GW remote-code-execution buffer-overflow network-security
1r 1t 1c
critical advisory

Remote Code Execution in jmespath.php via CompilerRuntime

The mtdowling/jmespath.php library contains a critical code injection vulnerability, CVE-2026-54133, allowing attackers to execute arbitrary PHP code when untrusted JMESPath expressions are processed by the CompilerRuntime.

jmespath.php remote-code-execution php code-injection
1t 1c
high advisory

Oracle Database SQL Injection Leads to OS-Level RCE and khunt Toolkit Deployment

A threat actor exploited SQL injection in a public-facing application to achieve OS-level remote code execution by abusing Oracle Java Source to deploy the custom 'khunt' post-exploitation toolkit.

Oracle Database sqli remote-code-execution khunt oracle credential-theft
3t 1i
high advisory

SSRF Bypass in CodeWhale via DNS Pinning TOCTOU

CodeWhale versions before 0.8.64 contain a time-of-check-time-of-use vulnerability in DNS pinning logic, allowing attackers to bypass SSRF mitigations and access internal resources.

CodeWhale +2 vulnerability argument-injection code-execution remote-code-execution credential-theft
5t 1c
high advisory

Argument Injection Vulnerability in CodeWhale git_show Tool

An argument injection vulnerability (CVE-2026-75913) in the CodeWhale git_show tool allows attackers to perform arbitrary file writes under the user's privilege level by manipulating the 'rev' parameter.

PoC codewhale +6 remote-code-execution configuration-vulnerability developer-tools vulnerability code-execution authorization-bypass path-traversal data-exfiltration +5
1r 5t 3c updated
critical advisory

Critical Stack-Based Buffer Overflow in TRENDnet TEW-WLC100

A critical stack-based buffer overflow in the TRENDnet TEW-WLC100 HTTP Header Handler allows remote attackers to achieve arbitrary code execution via a malformed 'Server' header.

TEW-WLC100 cve-2026-75784 buffer-overflow remote-code-execution network-security
1r 1t 1c
high advisory

Missing Authorization Vulnerability in ArcadeDB DELETE FUNCTION Statement

ArcadeDB versions 26.7.3 and earlier are vulnerable to a missing authorization flaw allowing any authenticated database user to delete server-side functions via the command API.

ArcadeDB +2 vulnerability privilege-escalation database-security remote-code-execution
1r 3t 1c updated
high advisory

Stack Buffer Overflow in COVESA Open1722

COVESA Open1722 versions through 0.9.2 are vulnerable to a stack-based buffer overflow in the avtp_to_can function that allows unauthenticated remote attackers to achieve arbitrary code execution via crafted UDP datagrams.

Open1722 +1 remote-code-execution buffer-overflow automotive cve-2026-73522
2t 1c
high advisory

Incomplete Fix for Glances Configuration Command Execution Bypass

Glances versions up to 4.5.5 contain a vulnerability where the --disable-config-exec flag fails to sanitize shell operators in on-alert action commands, allowing arbitrary command execution or file redirection.

Glances +1 vulnerability remote-code-execution security-bypass command-injection local-privilege-escalation
2t 2c
critical threat

Unauthenticated Remote Code Execution in D-Link NAS Devices

Multiple D-Link NAS devices are vulnerable to unauthenticated OS command injection via the account_mgr.cgi script, allowing remote attackers to execute arbitrary commands with root privileges.

exploited DNS-320 +3 remote-code-execution nas hardware vulnerability
1r 1t 1c
high threat

Remote Code Execution in ipTIME A3004T EAD Service

The ipTIME A3004T router (firmware 14.19.0) is vulnerable to pre-authentication remote code execution via a flaw in the EAD service, allowing root command injection.

A3004T Paccaron remote-code-execution router-vulnerability command-injection
1r 1t
high advisory

Unauthenticated Arbitrary File Upload in WooCommerce 1.5.0

WooCommerce 1.5.0 contains an unauthenticated arbitrary file upload vulnerability allowing remote attackers to upload malicious files, potentially resulting in remote code execution.

WooCommerce webapps file-upload remote-code-execution
1t
high advisory

Remote Command Injection in GL.iNet Router Firewall RPC

An OS command injection vulnerability in the Firewall-management RPC component of GL.iNet BE9300 and MT6000 routers allows remote, unauthenticated attackers to execute arbitrary system commands via crafted network parameters.

BE9300 +1 remote-code-execution firewall networking cve
2t 1c
high advisory

Authorization Bypass in GL.iNet WebDAV Service

Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.

A1300 +16 cve-2026-19980 remote-code-execution network-security firmware-vulnerability vulnerability rce network-infrastructure
1r 2t 1c
critical advisory

Stack-based Buffer Overflow in Edimax EW-7478APC

Edimax EW-7478APC version 1.04 is vulnerable to a stack-based buffer overflow in the formWanTcpipSetup function, allowing for remote code execution via the pppUserName parameter.

EW-7478APC remote-code-execution buffer-overflow router cve-2026-19961 vulnerability network-device cve
3r 2t 1c
high advisory

Command Injection in Cockpit CMS FFmpeg Integration

Cockpit CMS versions 2.14.0 and prior are vulnerable to authenticated command injection via malicious filenames processed by the FFmpeg integration.

Cockpit CMS web-application-vulnerability remote-code-execution injection cockpit-cms
1r 1t 1c
high advisory

Remote Code Execution in Grav CMS Flex Objects Plugin

Authenticated users can achieve remote code execution in Grav CMS versions prior to 2.0.13 by exploiting improper input validation in the Flex Objects plugin to upload and execute arbitrary PHP files.

Grav CMS +2 web-application-vulnerability rce ssti cms privilege-escalation web-application remote-code-execution cve-2026-75827
2r 6t 1c updated
high advisory

Remote Stack-Based Buffer Overflow in Tenda W20E

A stack-based buffer overflow vulnerability in Tenda W20E firmware allows authenticated remote attackers to achieve potential code execution via the QoS Edit component.

W20E cve-2026-19822 vulnerability remote-code-execution cve-2026-19823 buffer-overflow rce network-infrastructure
2r 3t 1c
critical advisory

Remote Code Execution in Grav API Plugin via Privilege Escalation

The Grav API plugin before version 1.0.13 fails to enforce API key scope restrictions in ConfigController, enabling remote code execution via injected scheduler commands.

Grav API plugin remote-code-execution privilege-escalation web-application-vulnerability
1r 3t 1c updated
critical advisory

Critical Remote Code Execution Vulnerability in Exim MTA

Exim is affected by a critical vulnerability (CVE-2024-39929) that allows a remote, unauthenticated attacker to execute arbitrary code via a logic error in header field processing.

PoC Exim vulnerability remote-code-execution mail-server
1t 1c updated
high threat

Remote Stack-based Buffer Overflow in TOTOLINK A800R

An authenticated remote attacker can trigger a stack-based buffer overflow in the TOTOLINK A800R router via the setIpQosRules function, potentially leading to arbitrary code execution.

exploited A800R +1 remote-code-execution cve-2026-19811 router-vulnerability cve-2026-19812 buffer-overflow router rce vulnerability +1
2r 2t 1c
high threat

Remote Buffer Overflow Vulnerability in Tenda G0

Tenda G0 devices contain a remote buffer overflow vulnerability in the httpd management interface that allows for potential arbitrary code execution or denial of service.

exploited G0 remote-code-execution buffer-overflow router cve-2026-19792
1r 1t 1c
high advisory

Stack-Based Buffer Overflow in Tenda AC1206 Web Interface

A stack-based buffer overflow in the Tenda AC1206 firmware version 15.03.06.23_multi_TD01 allows remote attackers to trigger memory corruption via the httpd web management interface.

AC1206 vulnerability remote-code-execution network-security buffer-overflow
1r 1t 1c
critical advisory

Path Traversal Vulnerability in Budibase

Budibase versions before 3.40.0 are vulnerable to path traversal via maliciously crafted S3 object keys, allowing authenticated builders to perform arbitrary file writes during workspace export.

server webserver path-traversal cve-2026-72850 web-vulnerability sqli remote-code-execution
1r 4t 1c
critical advisory

Path Traversal in luci-app-openvpn via instance_name2 Parameter

An authenticated path traversal vulnerability in the luci-app-openvpn component of OpenWrt allows remote attackers to write arbitrary files to the filesystem and achieve persistent root-level code execution.

luci-app-openvpn path-traversal remote-code-execution openwrt network-security
2t 1c
critical advisory

Authentication Bypass in SiYuan Publish API

SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.

SiYuan +3 access-control web-vulnerability authentication-bypass information-disclosure api-security remote-code-execution vulnerability pdf-processing +9
7r 19t 5c updated
high advisory

Remote Code Execution in IBM Informix via sq_sgkprepare

A critical buffer-related vulnerability (CVE-2026-13361) in IBM Informix allows remote, unauthenticated attackers to achieve code execution via the SQL interface by exploiting an unchecked length field in the oninit process.

Informix remote-code-execution vulnerability database-security
2t 1c
high advisory

Path Traversal Vulnerability in Joomla com_joomlaupdate

Joomla version 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension allowing a Super User to be manipulated into extracting malicious ZIP files, leading to arbitrary file write and remote code execution.

Joomla +1 web-vulnerability path-traversal remote-code-execution
1t 1c updated
critical advisory

Remote Command Injection in IBM Db2 Mirror for i

IBM Db2 Mirror for i versions 7.4 through 7.6 contain a critical command injection vulnerability allowing remote unauthenticated attackers to execute arbitrary system commands.

Db2 Mirror for i remote-code-execution vulnerability ibm-i
2t 1c
critical advisory

Uncontrolled Search Path Vulnerability in IBM i

IBM i versions 7.3 through 7.6 contain an uncontrolled search path element vulnerability that allows a remote authenticated attacker to execute arbitrary code with elevated privileges.

IBM i +6 vulnerability remote-code-execution ibm-i privilege-escalation cve-2026-16856
3t 5c updated
high advisory

Multiple Vulnerabilities in NGINX-UI

NGINX-UI is affected by multiple security vulnerabilities enabling remote attackers to achieve arbitrary code execution with root privileges, privilege escalation, data exfiltration, and denial-of-service.

NGINX-UI web-application vulnerability remote-code-execution privilege-escalation
3t
high advisory

Unauthenticated Remote Code Execution in Voltronic Power SNMP Web Pro

Voltronic Power SNMP Web Pro version 1.1 contains an unauthenticated RCE vulnerability allowing attackers to upload and execute malicious CGI scripts as root by bypassing session validation.

SNMP Web Pro remote-code-execution cve-2026-44402 firmware-vulnerability
1r 2t
high advisory

Multiple Vulnerabilities in Microsoft Exchange Server

Microsoft Exchange Server contains multiple vulnerabilities that can be exploited by an authenticated remote attacker to achieve privilege escalation, arbitrary code execution, security control bypass, data manipulation, and denial-of-service.

PoC Exchange Server vulnerability microsoft-exchange privilege-escalation remote-code-execution
3t 1c updated
high advisory

Exploitation of N-able N-central via CVE-2024-27429

Threat actors are exploiting a remote code execution vulnerability (CVE-2024-27429) in N-able N-central to gain unauthorized access and deploy RMM payloads on managed systems.

N-central remote-code-execution rmm supply-chain
3t 1c
high advisory

OS Command Injection in FileRun Thumbnail Generation

FileRun versions up to 2026.2.0 contain a command injection vulnerability in the thumbnail generation component allowing authenticated attackers to execute arbitrary code.

FileRun remote-code-execution command-injection file-upload
1r 1t 1c
high advisory

Unauthenticated Remote Code Execution in Red Hat JBoss EAP via openjdk-orb

CVE-2026-15560 allows unauthenticated remote code execution in Red Hat JBoss EAP environments configured with the -secmgr flag due to insecure object unmarshalling.

JBoss Enterprise Application Platform remote-code-execution vulnerability jboss denial-of-service web-server enterprise-application java jndi
5t 4c updated
high advisory

Remote Command Injection in INQUIRELAB mcp-bridge-api

A command injection vulnerability in the mcp-bridge.js component of mcp-bridge-api allows remote attackers to execute arbitrary system commands via manipulation of the command/args argument.

mcp-bridge-api vulnerability remote-code-execution webserver
2t 1c
high advisory

Path Traversal in GitPython via Malicious Submodule Names

GitPython fails to validate submodule names defined in .gitmodules files, allowing attackers to perform path traversal and create arbitrary Git repositories outside the intended working tree during submodule initialization.

GitPython +1 remote-code-execution input-validation python
1t 1c
high advisory

GitPython Command Injection via Unsafe Git Option Guard Bypass

A bypass of the GitPython safety guard allows arbitrary OS command execution via token smuggling when using single-character keyword arguments with split_single_char_options=False.

GitPython +1 execution library-vulnerability command-injection remote-code-execution injection supply-chain
2t 1c updated
high advisory

Remote Code Execution in ZenML CloudpickleMaterializer

ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows arbitrary command execution via malicious pickle file injection.

ZenML remote-code-execution deserialization
1t
critical advisory

Unauthenticated Denial of Service in Ground Station

Ground Station versions prior to 0.6.0 are susceptible to an unauthenticated denial-of-service vulnerability in the Socket.IO service_control event handler, allowing remote attackers to terminate critical satellite-tracking processes via a restart_service command.

Ground Station vulnerability remote-code-execution sql-injection ground-station ssrf remote-execution webserver
5t 1c updated
critical advisory

Unauthenticated Remote Code Execution in OpenChamber

OpenChamber 1.11.7 contains a critical unauthenticated RCE vulnerability in the /api/fs/exec endpoint due to improper command input validation and flawed authentication middleware.

OpenChamber remote-code-execution web-vulnerability cve-2026-53975
2r 4t 3c
high advisory

Arbitrary File Deletion Vulnerability in WordPress File Manager Plugin

The WordPress File Manager plugin (versions 6.0-6.9) contains an arbitrary file deletion vulnerability allowing authenticated attackers to delete critical server files and achieve remote code execution.

File Manager web-application-vulnerability wordpress remote-code-execution arbitrary-file-deletion
1r 2t 1c
high advisory

Electron Sandboxed Iframe Popup Restriction Bypass

A vulnerability in Electron, identified as CVE-2026-70608, allows sandboxed iframes to bypass 'allow-popups' restrictions and open new windows via the OpenURL navigation path.

Electron +4 vulnerability remote-code-execution javascript
2t 1c
high advisory

Nuxt 4.x Runtime Payload Cache Disclosure

A vulnerability in Nuxt 4.4.0 through 4.5.0 causes sensitive SSR data in the payload cache to be disclosed to unauthorized users due to an insufficient cache key implementation.

Nuxt +4 remote-code-execution template-injection cve-2026-71320
2r 3t updated
high advisory

IBM WebSphere Application Server ORB Unsafe Reflection Vulnerability

A vulnerability in the Object Request Broker (ORB) component of IBM SDK for Java allows an unauthenticated attacker to trigger remote code execution via arbitrary class instantiation.

WebSphere Application Server +2 vulnerability remote-code-execution java
1t 1c
critical advisory

Authentication Bypass and RCE Vulnerabilities in Milvus

Milvus vector database versions prior to 2.5.27 and 2.6.10 are vulnerable to multiple authentication bypass flaws and arbitrary expression execution, allowing attackers to gain full administrative access.

Milvus +2 authentication-bypass remote-code-execution cve-2025-64513 cve-2026-26190
2t updated
high threat

SQL Injection in ESAFENET CDG

A publicly exploitable SQL injection vulnerability in ESAFENET CDG allows unauthenticated remote attackers to execute arbitrary database queries via the keyid parameter.

exploited CDG web-application-vulnerability sqli remote-code-execution
1r 2t 1c
high advisory

Unauthenticated Remote Code Execution in Perspective 5.0.0

Perspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.

Perspective remote-code-execution cve-2026-67195 denial-of-service vulnerability CVE-2026-67198
3t 3c
medium advisory

Remote Code Execution Vulnerability in Zyxel Firewalls

A vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.

Zyxel Firewall vulnerability remote-code-execution firewall
1t
critical advisory

Critical Vulnerabilities in HUMANIST Digital Human Resources

Multiple critical vulnerabilities in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources version 26.0 allow unauthorized access, web shell upload, session hijacking, and remote code execution. Upgrade to version 26.1 immediately.

HUMANIST Digital Human Resources sql-injection vulnerability webserver remote-code-execution web-application cve-2026-14175 session-hijacking credential-access
1r 3t 4c
high advisory

Heap-based Buffer Overflows in GIMP APNG and DDS Loaders

GIMP contains multiple heap-buffer-overflow vulnerabilities in its APNG and DDS file format loaders, which can lead to arbitrary code execution when a victim opens a specially crafted image file.

GIMP vulnerability remote-code-execution desktop-app code-execution
1t 5c updated
high advisory

OS Command Injection in ClearOS Log Viewer

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands as the webconfig user, with subsequent escalation to root.

ClearOS vulnerability remote-code-execution privilege-escalation webserver
1r 2t 1c
high advisory

Remote Command Injection in Sangfor Operation and Maintenance Security Management System

An unauthenticated remote OS command injection vulnerability in the Sangfor Operation and Maintenance Security Management System allows attackers to execute arbitrary system commands via the /fort/portal_login endpoint.

Operation and Maintenance Security Management System cve-2026-18641 remote-code-execution command-injection sangfor
1r 2t 1c
high advisory

Remote Code Execution in OpenEMR Document Category Tree

OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.

OpenEMR +1 web-application-vulnerability remote-code-execution healthcare cve-2026-39931 sql-injection web-application vulnerability authentication-bypass +1
8t 1c
critical advisory

Critical Pre-Authentication RCE in Gitea and Forgejo

CVE-2026-60004 is a critical pre-authentication RCE vulnerability in Gitea and Forgejo platforms caused by an unsafe bare clone design in the diffpatch API endpoint, enabling arbitrary command execution via injected Git hooks.

Gitea +2 remote-code-execution git vulnerability forgejo
1r 3t 1c updated
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.

Ansible Automation Platform vulnerability remote-code-execution enterprise-automation
2t
high advisory

Critical RCE and Information Disclosure Vulnerability in Gitea

Gitea contains a critical vulnerability allowing remote, unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive information.

Gitea +1 vulnerability remote-code-execution web-application
1t 1c updated
critical advisory

Unauthenticated Remote Code Execution in ComfyUI via Unsafe Deserialization

ComfyUI version 0.23.0 is vulnerable to unauthenticated remote code execution via unsafe deserialization of malicious pickle files.

ComfyUI remote-code-execution deserialization cve-2026-68771
1r 2t 1c
high advisory

Remote Code Execution in Savon::Model via WSDL Injection

The Savon Ruby library is vulnerable to remote code execution (CVE-2026-53510) due to insecure use of module_eval when processing untrusted WSDL operation names.

Savon ruby remote-code-execution vulnerability cve-2026-53510
1t
high advisory

Authenticated Remote Code Execution in Wolf CMS

Wolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.

PoC Wolf CMS remote-code-execution web-application-vulnerability
1r 3t 2c updated
critical advisory

Remote Code Execution via Exposed H2 Database in Juggle Through

An unauthenticated remote code execution vulnerability in Juggle Through 1.6.0 allows attackers to leverage default credentials on the H2 database console to execute system-level commands.

Juggle Through remote-code-execution vulnerability cve-2026-67208
2t 1c
critical advisory

Critical Deserialization Vulnerability in IBM webMethods Integration

IBM webMethods Integration (on-premises) versions 10.11 and 10.15 contain a critical deserialization vulnerability (CVE-2026-12118) that enables unauthenticated remote code execution.

webMethods Integration remote-code-execution deserialization ibm cve-2026-12118
1t 1c
critical advisory

Unauthenticated Remote Code Execution in IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.

Langflow OSS remote-code-execution cve-2026-12940 ibm langflow code-injection vulnerability rce
3t 1c
high advisory

Unauthenticated Deserialization Vulnerability in CentreStack

An unauthenticated deserialization vulnerability in CentreStack allows remote attackers to create unauthorized local user accounts by sending crafted XML payloads to specific API endpoints.

CentreStack vulnerability deserialization remote-code-execution
2t
critical advisory

Authentication Bypass and RCE in CentreStack via Hardcoded Cryptographic Key

CentreStack versions prior to 17.5 contain a hardcoded cryptographic key vulnerability, allowing unauthenticated attackers to forge authentication tokens and execute arbitrary code.

CentreStack authentication-bypass remote-code-execution hardcoded-key
1t 1c
high advisory

Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module

A file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.

Performance Co-Pilot +8 privilege-escalation linux cve-2026-16526 remote-code-execution cve-2026-16527 monitoring-tool denial-of-service vulnerability +1
1r 1t 1c
critical advisory

Logging Operator Configuration Injection Leading to RCE

The Logging operator is vulnerable to remote code execution due to improper input sanitization in Fluentd configuration rendering, allowing authenticated users to inject arbitrary configuration blocks via CRDs.

logging-operator remote-code-execution kubernetes configuration-injection cve-2026-54680
1t
high advisory

Pre-Authentication Remote Code Execution in Xlight FTP Server

Xlight FTP Server versions prior to 3.9.5 contain a pre-authentication stack buffer overflow vulnerability triggered by malformed SSH packets, potentially leading to remote code execution.

Xlight FTP Server +1 remote-code-execution buffer-overflow ftp
1t 2c
critical advisory

Apache Axis2: Vulnerability Allows Code Execution

An anonymous, remote attacker can exploit a vulnerability in Apache Axis2 to execute arbitrary program code. This flaw allows for critical remote code execution without authentication, posing a significant risk to systems running the affected software.

Axis2 remote-code-execution vulnerability-exploitation apache
2t
critical advisory

CVE-2026-14959: IBM Aspera Faspex 5 Remote Code Execution via Shell Command Injection

A critical vulnerability, CVE-2026-14959, in IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) allows a remote authenticated attacker to execute arbitrary code due to a shell command injection flaw, potentially leading to full system compromise and significant data loss or service disruption.

Aspera Faspex 5 vulnerability command-injection rce remote-code-execution ibm
2t 1c
critical advisory

IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)

A critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.

Aspera Faspex 5 remote-code-execution vulnerability os-command-injection web-application
1r 2t 1c
high advisory

Authenticated Remote Code Execution in Camaleon CMS

Camaleon CMS versions 2.1.1 through 2.9.1 are vulnerable to authenticated remote code execution where an attacker with `custom_fields manage` permission can execute arbitrary Ruby code by injecting a malicious expression into the `select_eval` custom field type's options command parameter, which is then evaluated via `instance_eval` within an ERB view when a post edit page is rendered, leading to server-side code execution with web server process privileges.

Camaleon CMS remote-code-execution cms vulnerability
1t 1c
critical advisory

SiYuan Stored XSS Leads to Remote Code Execution (CVE-2026-66396)

SiYuan before v3.7.2 is vulnerable to stored cross-site scripting (XSS) due to improper escaping of the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing attackers with editor permissions to inject malicious onload handlers that execute arbitrary code in the Electron renderer with full Node.js access, leading to remote code execution.

SiYuan xss remote-code-execution client-side-exploitation electron
2t 1c
critical advisory

Critical Eval Injection Vulnerability in vBulletin Allows Remote Code Execution (CVE-2026-61511)

An eval injection vulnerability, identified as CVE-2026-61511, exists in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, specifically within the vB5_Template_Runtime::runMaths() method, allowing unauthenticated remote attackers to achieve arbitrary PHP code execution by manipulating the pagenav[pagenumber] parameter through the unauthenticated ajax/render template route with phpfuck-style encoding.

PoC vBulletin 5.x through 5.7.5 +4 web-vulnerability remote-code-execution eval-injection php unauthenticated
1r 2t 3c 4i
high threat

Multiple Vulnerabilities in libssh2 Library Discovered

Multiple vulnerabilities in the libssh2 library allow a remote, unauthenticated attacker to potentially disclose sensitive information, cause a denial-of-service condition, or execute arbitrary code.

exploited libssh2 vulnerability library remote-code-execution denial-of-service information-disclosure
2t
high advisory

CVE-2025-71408 NLTK Eval Injection Vulnerability

An eval injection vulnerability exists in the nltk.collocations module of NLTK (Natural Language Toolkit) versions prior to 3.9.3, allowing an attacker to exploit this by controlling command-line arguments passed to collocations.py, which are then unsafely passed to eval() enabling remote code execution on the affected system.

NLTK eval-injection remote-code-execution python
1t 1c
critical advisory

Server-Side Template Injection to Remote Code Execution in @prompty/core Nunjucks Renderer

A critical server-side template injection vulnerability exists in the @prompty/core Nunjucks renderer, affecting versions <= 0.1.4 and >= 2.0.0-alpha.1 up to <= 2.0.0-beta.4. This flaw allows an attacker to execute arbitrary JavaScript code within the host Node.js process by crafting malicious `.prompty` template bodies. The renderer's unrestricted JavaScript member access permits traversal of constructor and prototype properties, leading to remote code execution when rendering untrusted, community-supplied, cloned, or LLM-generated `.prompty` files.

@prompty/core +1 server-side-template-injection remote-code-execution nodejs npm vulnerability
1t
critical advisory

9router Critical Vulnerability Chain Allows Remote Code Execution via Default Password and Plugin Exploitation

A critical vulnerability chain, CVE-2026-63732, in 9router version 0.4.59 allows a remote, unauthenticated attacker to achieve arbitrary code execution on the host operating system by leveraging a hardcoded default password for initial access, bypassing a local-only network restriction via Host header spoofing, and exploiting unvalidated arguments during MCP plugin registration to execute malicious code when a plugin's SSE endpoint is triggered.

9router 0.4.59 vulnerability remote-code-execution hardcoded-credentials webserver nodejs
2r 3t 1c 1i
critical advisory

GoDAM WordPress Plugin Arbitrary File Upload Vulnerability (CVE-2026-14282)

An arbitrary file upload vulnerability exists in the GoDAM WordPress plugin versions up to and including 1.12.2 due to insufficient file type validation in the `save_video_file()` function, allowing unauthenticated attackers to upload arbitrary files to the server and potentially achieve remote code execution.

PoC GoDAM - Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Vid... <= 1.12.2 wordpress arbitrary-file-upload remote-code-execution web-exploitation
1r 2t 1c updated
high threat

Improper Input Validation in boazsegev facil.io WebSocket Frame Parser (CVE-2026-16632)

A high-severity improper input validation vulnerability, CVE-2026-16632, exists in the `websocket_on_protocol_error` function of the `boazsegev facil.io` WebSocket Frame Parser, allowing a remote unauthenticated attacker to manipulate the `on_message` argument with a publicly available exploit, potentially leading to denial of service or information disclosure.

exploited facil.io 0.7.4 +4 vulnerability web-application input-validation remote-code-execution
1t 1c
high advisory

FFmpeg ADX Audio Decoder Out-of-Bounds Memory Access Vulnerability

A high-severity out-of-bounds memory access vulnerability, tracked as CVE-2026-64835, exists in FFmpeg versions 4.4 through 8.1.2 within the ADX audio decoder, allowing attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change, potentially leading to denial of service, information disclosure, or arbitrary code execution.

FFmpeg vulnerability audio-codec memory-corruption denial-of-service remote-code-execution
1c
high advisory

Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)

A command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.

Ansible Lightspeed Visual Studio Code extension +1 command-injection vscode-extension remote-code-execution vulnerability
1t 1c
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities exist in Red Hat Ansible Automation Platform, stemming from issues in components such as node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, and DOMPurify. A remote, unauthenticated attacker can exploit these flaws to bypass security measures, perform Cross-Site Scripting (XSS) attacks, manipulate data, trigger Denial-of-Service (DoS) conditions, or execute arbitrary code on the affected system.

Ansible Automation Platform remote-code-execution xss denial-of-service data-manipulation vulnerability ansible red-hat
5t
critical advisory

Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)

A critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.

Serv-U +1 remote-code-execution privilege-escalation vulnerability-exploitation vulnerability cve improper-access-control server software-update +5
5t 8c 3i
high advisory

CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability

A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.

DNS-320 1.0.2 web-vulnerability remote-code-execution file-upload d-link unrestricted-file-upload nas vulnerability unrestricted-upload +2
4r 4t 2i updated
critical advisory

Critical Unauthenticated RCE in ktransformers (CVE-2026-63767)

A critical unauthenticated pickle deserialization vulnerability (CVE-2026-63767) in ktransformers versions up to 0.6.3 allows remote attackers to execute arbitrary commands by sending specially crafted pickle payloads containing malicious `__reduce__` methods to the SchedulerServer ZMQ ROUTER socket, leading to complete server compromise.

ktransformers <= 0.6.3 deserialization remote-code-execution python zmq vulnerability
2r 2t 1c
low advisory

Web Server Local File Inclusion Activity

This brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.

Nginx +4 local-file-inclusion web-vulnerability information-disclosure remote-code-execution discovery
1r 4t 1i updated
high threat

FreeRDP: Vulnerability Enables Remote Code Execution

A high-severity vulnerability in the FreeRDP software allows a remote, unauthenticated attacker to execute arbitrary code on systems running FreeRDP, enabling system compromise without prior authentication.

FreeRDP Anonymous Attacker vulnerability remote-code-execution bsi
2t
high advisory

Multiple Vulnerabilities in IBM Langflow Desktop OSS

An attacker can exploit multiple vulnerabilities in IBM Langflow Desktop OSS to gain administrator privileges, execute arbitrary code, bypass security measures, manipulate and disclose data, or cause a denial-of-service condition, leading to full system compromise and data integrity/confidentiality breaches.

Langflow Desktop OSS vulnerability remote-code-execution privilege-escalation data-exfiltration denial-of-service desktop-application
6t
high advisory

Server-Side Request Forgery in zevorn rt-claw (CVE-2026-16128)

A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16128, exists in zevorn rt-claw versions up to and including 0.2.0. The flaw is located within the `receiver_thread` function of the `http_request` component in `claw/services/swarm/swarm.c`. This critical vulnerability allows remote attackers to perform server-side request forgery, and a public exploit is available, increasing the urgency for detection and mitigation efforts.

rt-claw 0.1 +1 ssrf vulnerability webserver remote-code-execution information-disclosure
3t 1c 5i
high advisory

CVE-2024-58366 - SurrealDB Format String Vulnerability Leading to RCE

A high-severity format string vulnerability, CVE-2024-58366, exists in SurrealDB versions before 1.1.1 within the `rquickjs Exception::throw_type` function, allowing attackers with scripting privileges to achieve arbitrary memory reading or remote code execution with SurrealDB process privileges by injecting malicious format string sequences into error inputs.

SurrealDB < 1.1.1 format-string remote-code-execution privilege-escalation database
2t 1c
high advisory

SurrealDB RPC API Arbitrary Object Execution Vulnerability

An unauthenticated remote code execution vulnerability exists in SurrealDB's RPC API, affecting versions prior to 1.5.5 and 2.0.0-beta prior to 2.0.0-beta.3, allowing attackers to inject a specially crafted binary object containing a subquery during signin or signup operations, leading to execution with editor-level privileges and manipulation of non-IAM database resources.

SurrealDB +1 database-vulnerability remote-code-execution unauthenticated-access data-manipulation
3t 1c
critical advisory

IBM Langflow OSS Remote Code Execution via Deserialization

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.

Langflow OSS 1.0.0 +13 remote-code-execution deserialization python langflow web-vulnerability rce authentication-bypass critical-vulnerability +7
1r 5t 7c 1i
critical advisory

IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)

Unauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.

Langflow OSS +10 remote-code-execution api-exploitation unauthenticated-access code-injection web-vulnerability ai-llm
1r 3t 11c 2i updated
high threat

Vulnerability in poco-ai poco-claw Leads to Server-Side Request Forgery (CVE-2026-16016)

A high-severity server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16016, exists in poco-ai's poco-claw software up to version 0.5.4, allowing remote attackers to manipulate the `callback_url` argument in the `run_task` function to force the server to make arbitrary requests, with a public exploit available posing an immediate risk.

exploited poco-claw <= 0.5.4 server-side-request-forgery ssrf web-vulnerability python remote-code-execution cve
1r 2t 1c
high advisory

OpenClaw Vulnerability Allows Untrusted Workspace Plugin Loading (CVE-2026-62222)

A vulnerability, CVE-2026-62222, exists in OpenClaw versions prior to 2026.5.22, where an attacker with lower-trust caller access or control over configured input paths can exploit a flaw in the setup-mode discovery to load untrusted workspace plugins, leading to arbitrary code execution, persistence, and privilege escalation.

OpenClaw vulnerability remote-code-execution privilege-escalation persistence
3t 1c 2i
high advisory

LiteLLM Vulnerability Allows Remote Code Execution with Service Privileges

A remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code with the privileges of the service.

LiteLLM remote-code-execution rce vulnerability llm-security bsi
2t
critical threat

Unpatched Shark Vacuum Flaw Allows Region-Wide Remote Control and Data Theft

A researcher discovered an unpatched vulnerability in Shark RV2320EDUS robot vacuums that allows an attacker with physical access to extract an overly permissive AWS IoT certificate, enabling region-wide remote command execution and data theft on other Shark vacuums.

Shark RV2320EDUS +1 iot-security vulnerability cloud-security access-control remote-code-execution
6t
high advisory

Remote Code Execution Vulnerability in PyTorch Lightning via Malicious Checkpoint Files (CVE-2026-58659)

A remote code execution vulnerability, CVE-2026-58659, exists in PyTorch Lightning through version 2.6.5, allowing attackers to craft malicious checkpoint files that execute arbitrary code by exploiting a flaw in the `_load_state` function when `LightningModule.load_from_checkpoint` is called.

PyTorch Lightning remote-code-execution vulnerability python pytorch
1t 1c 1i
high advisory

Cherry Studio Remote Code Execution Vulnerability (CVE-2026-40501)

A remote code execution vulnerability, CVE-2026-40501, exists in Cherry Studio versions 1.2.2 through 1.9.12 due to improper Electron BrowserWindow configuration, allowing remote attackers to execute arbitrary code by injecting malicious JavaScript through controlled search provider content, thereby gaining full Node.js privileges and accessing system resources.

Cherry Studio 1.2.2 +1 remote-code-execution electron-vulnerability application-security
1r 1t 1c
high advisory

Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)

A Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.

Splunk Enterprise < 9.4.13 +14 splunk vulnerability csrf remote-code-execution credential-access data-exfiltration web-vulnerability
4t 3c updated
high advisory

MantisBT Remote Code Execution via Class Hoisting (CVE-2026-49273)

A high-severity remote code execution vulnerability, CVE-2026-49273, affects MantisBT versions 2.28.3 and earlier, allowing an authenticated administrator to achieve arbitrary code execution as the web server user by leveraging PHP's class hoisting during the processing of non-string configuration values in `adm_config_set.php`.

MantisBT remote-code-execution web-application php class-hoisting xss web-vulnerability
1r 1t
high advisory

Vulnerability in Tenable Nessus Agent Allows Remote Code Execution and Security Bypass

A critical vulnerability, CVE-2026-15265, has been discovered in Tenable Nessus Agent versions prior to 11.2.1 and 11.1.4, which allows an attacker to achieve remote code execution and bypass security policies on affected systems, necessitating immediate patching.

Nessus Agent +5 vulnerability remote-code-execution security-bypass
2t 1c updated
high advisory

Grav API Plugin File Upload Extension Bypass Leading to RCE

A vulnerability (CVE-2026-61457) in the Grav API plugin before version 1.0.3 allows an authenticated attacker with `api.media.write` permissions to bypass file upload extension validation using double extensions, which can lead to remote code execution on the web server.

Grav API plugin web-vulnerability remote-code-execution extension-bypass grav
1r 3t 1c
high advisory

PraisonAI Plugin Manager Remote Code Execution Vulnerability (CVE-2026-61446)

PraisonAI (praisonaiagents) versions prior to 1.6.78 are susceptible to a remote code execution vulnerability residing in the plugin manager's handling of Python files, where it loads and executes arbitrary .py files from specific plugin directories without implementing crucial security measures, allowing an attacker who can place a malicious .py file to achieve arbitrary code execution upon plugin system initialization.

praisonaiagents < 1.6.78 remote-code-execution plugin-vulnerability python supply-chain path-traversal
1t 1c
high advisory

PraisonAI web_crawl Tool Vulnerable to DNS Rebinding SSRF (CVE-2026-61430)

PraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) within its web_crawl tool, allowing attackers to bypass hostname validation using DNS rebinding and retrieve sensitive internal HTTP response bodies from private or loopback services.

PraisonAI +1 ssrf dns-rebinding vulnerability web-application code-injection remote-code-execution python cve +4
1r 3t 1c
high advisory

PraisonAI MCP HTTP-Stream Authentication Bypass (CVE-2026-61427)

PraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability, CVE-2026-61427, in the MCP HTTP-stream transport, allowing unauthenticated clients to establish sessions, enumerate tools, and invoke tools, potentially leading to remote code execution if the server is bound to a network-accessible address.

PraisonAI < 4.6.78 authentication-bypass remote-code-execution web-vulnerability ai-ml network
1r 3t 1c
low advisory

GitHub CLI `gh codespace jupyter` Command Remote Code Execution Vulnerability

A remote code execution vulnerability, CVE-2026-59831, has been identified in the GitHub CLI's `gh codespace jupyter` command, allowing attackers to execute arbitrary code on a user's system when connecting to a specially crafted malicious Codespace.

GitHub CLI +1 remote-code-execution vulnerability github cli codespaces developer-tools
1t 1c
high advisory

Red Hat Enterprise Linux Plexus-Utils Vulnerability Allows Remote Code Execution

A remote, unauthenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within the plexus-utils component, to execute arbitrary program code with user privileges, leading to system compromise.

Red Hat Enterprise Linux +2 linux vulnerability rce remote-code-execution
1t
critical advisory

FacturaScripts Path Traversal to Remote Code Execution Vulnerability

An authenticated attacker can exploit a path traversal vulnerability (GHSA-hgjx-r89m-m7v4) in FacturaScripts versions 2025 through 2026.2's file upload functionality to write arbitrary files outside intended directories, leading to remote code execution as the web-server user.

FacturaScripts web-application path-traversal remote-code-execution php
2r 5t
critical advisory

Critical Remote Code Execution in Totolink NR1800X Routers (CVE-2026-15701)

A critical stack-based buffer overflow vulnerability, CVE-2026-15701 (CVSS 9.8), in Totolink NR1800X firmware version 9.1.0u.6279_B20210910 allows remote attackers to execute arbitrary code by manipulating the 'Host' argument in the 'Form_Logout' function, with a public exploit available.

NR1800X 9.1.0u.6279_B20210910 buffer-overflow remote-code-execution firmware router vulnerability
2t 1c 5i
high threat

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.

exploited PoC SMA1000 Appliances +6 ssrf vulnerability cisa-kev remote-code-execution network-appliance
2t 2c 6i updated
medium advisory

Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)

A critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.

1715-AENTR EtherNet/IP Adapter <=3.003 ics ot vulnerability critical-infrastructure remote-code-execution
1t 1c
high threat

CVE-2026-60114 Sustainable Irrigation Platform Path Traversal Vulnerability

A path traversal vulnerability (CVE-2026-60114) in Sustainable Irrigation Platform (SIP) through version 5.2.16 allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files containing unvalidated keys, leading to potential remote code execution, persistence, and privilege escalation.

exploited Sustainable Irrigation Platform path-traversal arbitrary-file-write web-application remote-code-execution persistence privilege-escalation
3t 1c
high advisory

Tenda BE12 Pro Remote Code Execution Vulnerability (CVE-2026-15691)

A critical remote stack-based buffer overflow vulnerability (CVE-2026-15691) has been discovered in Tenda BE12 Pro firmware 16.03.66.23, affecting the `fromSafeClientFilter` function and allowing remote attackers to achieve arbitrary code execution by manipulating the `page` argument, with a public exploit available.

BE12 Pro 16.03.66.23 vulnerability remote-code-execution buffer-overflow firmware router network-device rce
2t 5c 8i
critical advisory

Critical JWT Authentication Bypass in Siemens Opcenter X (CVE-2026-56451)

A critical vulnerability, CVE-2026-56451, in Siemens Opcenter X versions prior to V2604 allows unauthenticated remote attackers to forge arbitrary JSON Web Tokens (JWTs) due to improper algorithm validation, leading to full authentication bypass, user impersonation including administrative accounts, and complete unauthorized access to the application.

Opcenter X cve authentication-bypass jwt remote-code-execution critical-vulnerability
3t 1c
critical advisory

DIRAC Vulnerable to Remote Code Execution via SQL Injection and Eval in DatasetManager

An authenticated user can achieve remote code execution in DIRAC's FileCatalog DatasetManager due to an SQL injection vulnerability (CVE-2026-61667) that allows manipulation of query results passed to an `eval` function, leading to full system compromise.

DIRAC remote-code-execution sql-injection python web-application vulnerability cve-2026-61667
6t
high threat

JetBrains IntelliJ IDEA Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit an unspecified vulnerability in JetBrains IntelliJ IDEA to achieve arbitrary code execution, enabling them to execute arbitrary program code on the affected system.

IntelliJ IDEA Anonymous Attacker remote-code-execution vulnerability development-tools windows linux macos
2t
critical advisory

CVE-2026-4769: Unauthenticated Remote Access in WAGO System I/O Field Series

A critical vulnerability, CVE-2026-4769, in certain WAGO System I/O Field series devices allows an unauthenticated remote attacker to gain full system compromise by accessing an undocumented internal diagnostic capability during the initial startup sequence.

0765-110x/0100-0000 +7 ics ot critical-vulnerability unauthenticated-access remote-code-execution firmware-vulnerability
2t 1c
critical advisory

Critical Buffer Overflow in Tenda CH22 Leads to Remote Code Execution (CVE-2026-15543)

A critical buffer overflow vulnerability, CVE-2026-15543, exists in the Tenda CH22 1.0.0.1 firmware's `formCertListInfo` function, allowing unauthenticated remote attackers to achieve arbitrary code execution by manipulating the 'Name' argument, with a public exploit available.

CH22 1.0.0.1 cve vulnerability buffer-overflow remote-code-execution network-device
1t 1c
high advisory

CVE-2026-15541: Missing Authorization in will-moss Isaiah Master Websocket Handler

A critical missing authorization vulnerability (CVE-2026-15541) exists in the `Server.Handle` function of the `Master Websocket Handler` component within `will-moss Isaiah` versions up to 1.36.9, allowing a remote attacker to bypass authorization controls by manipulating the `Agent` argument, potentially leading to unauthorized access or privilege escalation.

Isaiah vulnerability authorization-bypass remote-code-execution
2t 1c
high advisory

CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0

A remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.

Online Book Store System 1.0 web-vulnerability sql-injection authentication-bypass remote-code-execution
1t 1c
high threat

Remote SQL Injection Vulnerability in Jinher OA 1.0 (CVE-2026-15517)

A remote SQL injection vulnerability, CVE-2026-15517, has been discovered in Jinher OA 1.0, allowing unauthenticated attackers to execute arbitrary SQL commands by manipulating the `httpOID` argument in the `/C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx` file, with a public exploit available.

exploited OA 1.0 sql-injection web-application vulnerability cve remote-code-execution
1r 2t 1c 5i
high advisory

Metasoft MetaCRM SQL Injection Vulnerability (CVE-2026-15514)

A critical SQL injection vulnerability (CVE-2026-15514) in Metasoft MetaCRM up to version 6.4.0 Beta06 allows remote attackers to exploit the RPCService.query function via the phprpc_args argument in /customizemt/xkq/rpc.jsp, leading to unauthorized database access and manipulation, with a public exploit available.

MetaCRM up to 6.4.0 Beta06 sql-injection web-vulnerability crm remote-code-execution
1r 1t 1c
high advisory

CVE-2026-15489: SQL Injection in RafyMrX TOKO-ONLINE-ROTI login.php

A critical SQL injection vulnerability (CVE-2026-15489) exists in RafyMrX TOKO-ONLINE-ROTI, allowing remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument in the 'proses/login.php' file, with a public exploit available.

TOKO-ONLINE-ROTI web-vulnerability sql-injection initial-access public-exploit web-exploitation cve remote-code-execution
2r 4t 1c
high advisory

Unrestricted File Upload Vulnerability in hcr707305003 shiroiAdmin

A remote unrestricted file upload vulnerability (CVE-2026-15488) exists in hcr707305003 shiroiAdmin versions 1.1 and 1.3, allowing attackers to upload arbitrary files by manipulating the 'File' argument in FileController::upload, potentially leading to remote code execution.

shiroiAdmin < 1.4 vulnerability web file-upload remote-code-execution
1r 3t 1c
high advisory

Remote Buffer Overflow Vulnerability in TRENDnet TEW-821DAP Access Point

A critical buffer overflow vulnerability (CVE-2026-15484) exists in the `sub_41EC14` function within the `/goform/tools_nslookup` component of the TRENDnet TEW-821DAP 1.12B01 wireless access point, which can be exploited remotely due to improper handling of the ssi element, potentially leading to arbitrary code execution on an End-of-Life device.

TEW-821DAP buffer-overflow vulnerability network-device remote-code-execution
1c
high advisory

Remote Command Injection in Trendnet TEW-635BRM Routers (CVE-2026-15481)

A critical remote command injection vulnerability (CVE-2026-15481) has been discovered in Trendnet TEW-635BRM routers up to version 1.00.03, allowing attackers to execute arbitrary commands by manipulating the 'ipoa_ipaddr' argument in the 'ipoa_test' function, with public exploits available for this End-of-Life product.

TEW-635BRM command-injection remote-code-execution network-device EOL-product
1t 1c
critical advisory

CVE-2026-61447 PraisonAI Remote Code Execution Vulnerability via Prompt Injection

Attackers can exploit CVE-2026-61447, a critical remote code execution vulnerability in PraisonAI versions before 1.6.78, by using prompt injection to manipulate LLM-generated Python code, leading to arbitrary code execution and exfiltration of environment secrets on the host system.

PoC PraisonAI remote-code-execution prompt-injection llm ai vulnerability
1t 1c updated
high advisory

Incomplete Package Integrity Verification in Chainguard apko and melange Allows Data Section Substitution

A critical vulnerability, CVE-2026-54174, in Chainguard's apko and melange packages allows attackers to substitute arbitrary file contents within packages due to incomplete integrity verification, potentially leading to remote code execution.

apko +1 supply-chain package-manager integrity-bypass remote-code-execution defense-evasion
2t
high advisory

Clauster Dashboard Unauthenticated Access Vulnerability

A Clauster instance deployed on a non-loopback address can be accessed unauthenticated, even if password protection is configured, due to auth.enabled defaulting to false. This allows an attacker with network access to gain full control of the dashboard, including listing projects, spawning remote-control bridges, editing files, reading logs, and cloning repositories, ultimately leading to remote code execution in project directories.

Clauster misconfiguration remote-code-execution vulnerability web-application
2t 1i
high advisory

NotrinosERP Authenticated Arbitrary File Upload Leads to Remote Code Execution

An authenticated user with the 'SA_EMPLOYEE' permission in NotrinosERP can upload arbitrary files, including PHP web shells, through the HRM employee 'Documents' tab, leading to remote code execution due to a lack of extension, MIME, or content validation.

NotrinosERP web-application remote-code-execution file-upload php notrinos
1r 3t
critical threat

Malicious 'exploration' Rust Crate Downloads and Executes Remote Payload

A malicious Rust crate named 'exploration' was published to crates.io on 2026-06-02, containing a method that attempted to download and execute a payload from a remote site, and was removed within an hour with no evidence of actual usage.

exploited exploration supply-chain rust malicious-package remote-code-execution cwe-506
2t
high advisory

[UPDATE] Python: Schwachstelle ermöglicht Codeausführung

A high-severity vulnerability in Python allows a remote, unauthenticated attacker to execute arbitrary program code, potentially leading to full system compromise on machines running vulnerable Python installations.

Python remote-code-execution vulnerability rce
2t
high advisory

CVE-2026-15330: zhayujie CowAgent Server-Side Request Forgery

A critical server-side request forgery (SSRF) vulnerability, CVE-2026-15330, exists in zhayujie CowAgent up to version 2.1.1, allowing remote attackers to manipulate the 'image' argument in the Vision Tool component's `_build_image_content` or `_download_to_data_url` functions to access internal resources or conduct port scanning.

CowAgent web-vulnerability ssrf remote-code-execution network
1r 1t 1c
high advisory

UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)

The UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.

UsersWP plugin <= 1.2.65 +1 wordpress plugin vulnerability web file-deletion remote-code-execution
1r 3t 1c
high advisory

CVE-2026-15134: SQL Injection in CodeAstro Simple Online Leave Management System

A high-severity SQL injection vulnerability (CVE-2026-15134) in CodeAstro Simple Online Leave Management System 1.0, specifically within the '/SimpleOnlineLeave/index.php' file, allows a remote unauthenticated attacker to execute arbitrary SQL commands by manipulating the 'email' argument, leading to unauthorized database access and data compromise, with a public exploit available.

Simple Online Leave Management System 1.0 sql-injection web-application cve remote-code-execution data-exfiltration
1r 2t 1c
high advisory

Serena Agent Unauthenticated RCE via DNS Rebinding (CVE-2026-49471)

An unspecified attacker can achieve remote code execution in Serena agent versions prior to 1.5.2 by leveraging an unauthenticated Flask dashboard, DNS rebinding, and memory poisoning, enabling persistent attacker-controlled command execution.

serena-agent remote-code-execution dns-rebinding persistence command-and-control python flask agent
1r 6t 1c 1i
critical advisory

Nuclio Controller Vulnerability Leads to Persistent Kubernetes RCE (GHSA-v5px-423j-pf7p)

The Nuclio controller improperly sanitizes user-controlled input (cron trigger event headers and body) before injecting it into `curl` commands executed by Kubernetes CronJobs, allowing remote attackers to perform command injection and achieve remote code execution (RCE) by breaking quoting contexts in header keys or utilizing shell command substitution in event bodies, leading to arbitrary command execution with root privileges and potential persistence within the Kubernetes cluster.

Nuclio <= 1.15.27 remote-code-execution kubernetes cloud-native command-injection persistence critical-vulnerability ghsa
2r 3t 2i
high threat

CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Palo Alto Networks has disclosed multiple buffer overflow vulnerabilities (CVE-2026-0288) in their PAN-OS User-ID Terminal Server Agent (TSA) component, which an unauthenticated attacker with network access can exploit by sending specially crafted network traffic to cause a denial of service (DoS) or potentially achieve arbitrary code execution, affecting various versions of PAN-OS, Cloud NGFW, and Prisma Access if the TSA is exposed to untrusted networks.

exploited Cloud NGFW +6 network vulnerability cve palo-alto-networks denial-of-service remote-code-execution
3t
high advisory

CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover

A critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.

Grav API plugin grav api-plugin jwt cors remote-code-execution web-vulnerability
1r 3t 1c
high advisory

Joomla Page Builder CK Arbitrary File Upload (EDB-52626)

A public exploit has been released for an arbitrary file upload vulnerability in Joomla Page Builder CK version 3.5.10, which allows an unauthenticated attacker to upload malicious files to the server, potentially leading to remote code execution and full system compromise.

Joomla Page Builder CK 3.5.10 webapps arbitrary-file-upload joomla remote-code-execution
3t
high advisory

CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE

Authenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.

WHMCS Bridge <= 6.9 wordpress arbitrary-file-upload remote-code-execution web-vulnerability plugin-vulnerability
3t 1c
high advisory

CVE-2026-14771: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability

A critical SQL injection vulnerability (CVE-2026-14771) has been discovered in SourceCodester Class and Exam Timetabling System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in `/edit_exam1.php`, leading to arbitrary SQL command execution and potential data compromise.

Class and Exam Timetabling System 1.0 sql-injection web-application vulnerability remote-code-execution data-exfiltration
1r 1t 1c 6i
high advisory

CVE-2026-14755: Remote SQL Injection in code-projects Hotel and Tourism Reservation

A critical remote unauthenticated SQL injection vulnerability (CVE-2026-14755) in code-projects Hotel and Tourism Reservation version 1.0, specifically within the '/admin/reservations.php' file's 'delete' argument, allows attackers to manipulate backend database queries, leading to data exposure and manipulation with a publicly disclosed exploit.

Hotel and Tourism Reservation 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration
1r 2t 1c 2i
high advisory

CVE-2026-14754: SQL Injection in code-projects Hotel and Tourism Reservation

A critical SQL injection vulnerability (CVE-2026-14754) in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_room.php` file allows a remote, unauthenticated attacker to manipulate arguments such as `delete_image`, `edit`, `description`, `number`, `price`, `rooms`, or `type` to execute arbitrary SQL commands, leading to sensitive data exposure and potential database compromise.

Hotel and Tourism Reservation 1.0 sql-injection web-application cve code-projects remote-code-execution
1r 1t 1c
high advisory

CVE-2026-14750 — SQL Injection in mjperpinosa stumasy via Password Argument

A high-severity remote SQL injection vulnerability (CVE-2026-14750) exists in mjperpinosa stumasy up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, allowing unauthenticated attackers to manipulate the 'Password' argument in the `Notes_controller::accessing_dictionary_authorization` function to execute arbitrary SQL queries, leading to data exfiltration, manipulation, or potential server compromise via a publicly available exploit.

stumasy sql-injection web-application cve unauthenticated remote-code-execution data-exfiltration
1r 3t 1c
high threat

CVE-2026-14721: UTT HiPER 1250GW Remote Code Execution via Buffer Overflow

A critical stack-based buffer overflow vulnerability (CVE-2026-14721) in UTT HiPER 1250GW firmware versions up to 3.2.7-210907-180535 allows remote, unauthenticated attackers to achieve arbitrary code execution by manipulating the 'ssid' argument in the /goform/ConfigWirelessBase_5g web endpoint, with public exploit disclosure indicating active exploitation risk.

exploited HiPER 1250GW buffer-overflow remote-code-execution network-device web-application
2t 1c
high threat

CVE-2026-14722: Remote Code Injection in TidGi-Desktop Git Repository Import Component

A critical remote code injection vulnerability, CVE-2026-14722, has been identified in tiddly-gittly TidGi-Desktop versions up to 0.13.0, allowing unauthenticated attackers to execute arbitrary code by manipulating the Git Repository Import component, with public exploits available and confirmed active exploitation potential.

exploited TidGi-Desktop vulnerability code-injection remote-code-execution desktop-application
2t 1c 6i
high advisory

CVE-2026-14688: Remote SQL Injection in itsourcecode Online Hotel Management System

A high-severity SQL injection vulnerability, CVE-2026-14688, exists in itsourcecode Online Hotel Management System 1.0 within the `/admin/login.php` file via the `email` argument, allowing remote unauthenticated attackers to bypass authentication and potentially exfiltrate data, with a publicly available exploit.

Online Hotel Management System 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration webserver
1r 1t 1c 3i
high advisory

CVE-2026-14637: Critical Deserialization Vulnerability in kirilkirkov Ecommerce-CodeIgniter-Bootstrap

A high-severity deserialization vulnerability, CVE-2026-14637, exists in the `getCartItems` function of `application/libraries/ShoppingCart.php` in kirilkirkov Ecommerce-CodeIgniter-Bootstrap versions up to commit `13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7`, allowing remote attackers to achieve arbitrary code execution by manipulating the `shopping_cart` argument, with public exploit disclosure raising immediate risk.

Ecommerce-CodeIgniter-Bootstrap deserialization remote-code-execution web-vulnerability php codeigniter
2t 1c
high advisory

CVE-2025-71359: Picklescan Deserialization RCE Bypass

Picklescan versions prior to 0.0.29 are vulnerable to remote code execution (CVE-2025-71359) due to a failure in detecting malicious Python pickle payloads that utilize `lib2to3.pgen2.grammar.Grammar.loads`, allowing attackers to craft files that evade detection and execute arbitrary code during deserialization.

picklescan < 0.0.29 remote-code-execution deserialization python vulnerability supply-chain
2t 1c
high advisory

CVE-2025-71345: Picklescan Malicious Pickle File Detection Bypass Leading to RCE

CVE-2025-71345 describes a critical vulnerability in `picklescan` versions prior to 0.0.30, where attackers can embed undetected malicious code within pickle files that specifically invoke the `torch.utils.bottleneck.__main__.run_autograd_prof` function, leading to remote code execution upon deserialization by bypassing `picklescan`'s security checks.

picklescan < 0.0.30 remote-code-execution deserialization python machine-learning vulnerability
2t 1c
high advisory

CVE-2025-71343 — picklescan Detection Bypass via Malicious Pickle Files

A deserialization vulnerability, CVE-2025-71343, in picklescan before version 0.0.30 allows attackers to craft malicious pickle files that evade detection and lead to arbitrary code execution when loaded via `pickle.load()`.

picklescan < 0.0.30 deserialization remote-code-execution python vulnerability detection-bypass
2t 1c
high advisory

WatchGuard Firebox and Mobile VPN Client Vulnerabilities

WatchGuard has released security advisories to address critical vulnerabilities, including a race condition, use-after-free, and local privilege escalation, in its Fireware OS and Mobile VPN with SSL client for Windows, which could lead to remote code execution on appliances and local privilege escalation on client systems if not patched immediately.

Fireware OS 2025.1 +4 watchguard vulnerability network-device vpn privilege-escalation remote-code-execution
2t
high advisory

Non-Constant-Time HMAC Comparison in Pay Gem Paddle Billing Webhook Signature Verifier

A timing side-channel vulnerability in the `Pay` gem's Paddle Billing webhook signature verification component (`Pay::Webhooks::PaddleBillingController#valid_signature?` <= v11.6.1) allows an unauthenticated attacker to recover the HMAC signing secret by observing response time variations in `String#==` comparisons, enabling the forgery of arbitrary webhook events and leading to business logic abuses such as unauthorized feature provisioning or fraudulent refunds.

pay timing-attack vulnerability webhooks ruby-on-rails server-side logic-error remote-code-execution
3t
critical advisory

Paymenter vulnerable to Remote Code Execution via public file uploads

A critical remote code execution (RCE) vulnerability, CVE-2025-58048, in Paymenter's ticket attachments functionality allows an authenticated, low-privileged user to upload arbitrary files, leading to full compromise of the application and underlying server, enabling attackers to extract sensitive data, read credentials, and execute arbitrary system commands.

Paymenter remote-code-execution web-application php critical-vulnerability file-upload webshell
4t 1c 2i
critical advisory

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

Unauthenticated attackers can exploit a path traversal vulnerability in motionEye versions prior to 0.44.0 to read the application's configuration file, steal the admin SHA-1 password hash, and achieve full administrative access, leading to remote code execution.

motionEye path-traversal authentication-bypass remote-code-execution credential-theft web-application
1r 5t
critical advisory

Incus Argument Injection Vulnerability Leads to Arbitrary File Write and Command Execution

An argument injection vulnerability (CVE-2026-48755) exists in Incus due to improper validation of the user-provided backup compression algorithm, allowing an authenticated attacker to inject arbitrary arguments into the command line, leading to an arbitrary file write on the host and subsequent arbitrary command execution.

Incus argument-injection arbitrary-file-write remote-code-execution container-escape linux
2r 5t 2i
high advisory

Stack Buffer Overflow in Oj Ruby Gem (CVE-2026-54502)

The `Oj.dump` function in the `Oj` Ruby gem is vulnerable to a stack-based buffer overflow (CVE-2026-54502) due to improper validation of the `:indent` parameter, allowing an attacker to trigger a process crash or potentially remote code execution by providing an excessively large integer value, affecting all `Oj` gem versions prior to `3.17.2`.

oj gem overflow ruby gem denial-of-service remote-code-execution application-vulnerability
3r 4t
high advisory

PraisonAI Recipe Policy Bypass via YAML Workflow Approval

A policy bypass vulnerability in PraisonAI (CVE-NONE) allows untrusted recipes to self-approve and execute default-denied critical shell tools, such as `execute_command`, by declaring them in `workflow.yaml` instead of `TEMPLATE.yaml requires.tools`, leading to arbitrary command execution with the privileges of the PraisonAI process.

PraisonAI application-vulnerability policy-bypass remote-code-execution python
2r 2t
high threat

Multiple Vulnerabilities in Microsoft Office Products (June 2026)

CERT-FR has disclosed 31 vulnerabilities in various Microsoft Office products, including CVE-2026-44803 and CVE-2026-47635, which could allow remote code execution, privilege escalation, and data confidentiality compromise.

exploited Microsoft 365 Apps pour Enterprise pour systèmes 32 bits +21 vulnerability microsoft-office remote-code-execution privilege-escalation data-confidentiality windows macos android
3r 4t 5c
critical advisory

Multiple Critical Vulnerabilities in Fortinet Products Lead to RCE and Data Exposure

Multiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been discovered across Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox, enabling unauthenticated attackers to achieve remote arbitrary code execution and compromise data confidentiality.

FortiOS +11 remote-code-execution data-exfiltration vulnerability fortinet network-appliance
2r 4t 3c 6i
critical advisory

Vulnerability in Veeam Backup & Replication Allowing Remote Code Execution (CVE-2026-44963)

A critical remote code execution vulnerability, tracked as CVE-2026-44963, has been discovered in Veeam Backup & Replication versions prior to 12.3.2.4854, which could allow an unauthenticated attacker to execute arbitrary code on affected systems, leading to full compromise of the backup infrastructure and potential data exfiltration or destruction.

Veeam Backup & Replication < 12.3.2.4854 remote-code-execution vulnerability veeam backup-replication data-exfiltration data-destruction windows
3r 2t 1c 2i
high advisory

UTT HiPER 1200GW Stack-Based Buffer Overflow Vulnerability (CVE-2026-10292)

A stack-based buffer overflow vulnerability (CVE-2026-10292) exists in the strcpy function of /goform/formTaskEdit in UTT HiPER 1200GW up to version 2.5.3-170306, allowing for remote code execution.

HiPER 1200GW cve buffer overflow remote code execution web application
1r 1t 1c
critical threat

Totolink N300RH Stack-Based Buffer Overflow Vulnerability (CVE-2026-10187)

A stack-based buffer overflow vulnerability, CVE-2026-10187, exists in the setWiFiBasicConfig function of the wireless.so file in the Web Management Interface of Totolink N300RH version 6.1c.1353_B20190305, allowing a remote attacker to execute arbitrary code by manipulating the KeyStr argument.

N300RH 6.1c.1353_B20190305 stack-buffer-overflow remote-code-execution router
2r 1t 1c
high advisory

TRENDnet TEW-432BRP Stack-Based Buffer Overflow Vulnerability (CVE-2026-10123)

A stack-based buffer overflow vulnerability (CVE-2026-10123) exists in TRENDnet TEW-432BRP version 3.10B20 within the formSetDomainFilter function, allowing a remote attacker to execute arbitrary code by manipulating specific arguments in a request to /goform/formSetDomainFilter.

TEW-432BRP 3.10B20 cve buffer overflow remote code execution network device
2r 1t 1c
critical advisory

SIM-PKH 2.4.1 Arbitrary File Upload Vulnerability (CVE-2018-25409)

SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability (CVE-2018-25409) that allows authenticated attackers to upload malicious PHP files via the fupload parameter through the aksi_pengurus.php endpoint, leading to remote code execution.

SIM-PKH cve file-upload remote-code-execution web-application
2r 1t 1c
critical advisory

Apache CouchDB Improper Privilege Management Leads to Remote Code Execution

A public exploit demonstrates improper privilege management in Apache CouchDB (CVE-2017-12635) leading to privilege escalation, which can be combined with CVE-2017-12636 for remote code execution by modifying server configurations via the HTTP API.

CouchDB 1.6.0 privilege-escalation remote-code-execution couchdb CVE-2017-12635 CVE-2017-12636
2r 2t 2c
critical advisory

Langflow 1.3.0 Remote Code Execution Vulnerability

Langflow 1.3.0 contains a remote code execution vulnerability (CVE-2026-0770) due to untrusted input in the exec_globals parameter at the validate endpoint, allowing remote attackers to execute arbitrary code as root without authentication, as demonstrated by a public exploit.

langflow 1.3.0 +3 remote-code-execution webapps langflow
1r 1t 5i updated
high advisory

Dulwich Arbitrary File Write Vulnerability on Windows (CVE-2026-42305)

Dulwich versions before 1.2.5 are vulnerable to an arbitrary file write leading to remote code execution on Windows systems when cloning or checking out a malicious Git repository due to improper path validation, as tracked by CVE-2026-42305.

dulwich arbitrary-file-write remote-code-execution git
2r 2c
high advisory

CVE-2026-9227: GutenBee WordPress Plugin Arbitrary File Upload

The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to arbitrary file upload, allowing authenticated attackers with author-level access to achieve remote code execution by uploading executable files with double extensions.

GutenBee – Gutenberg Blocks plugin <= 2.20.1 arbitrary-file-upload remote-code-execution wordpress
2r 1c
high advisory

Pimcore Unsafe PHP Deserialization Vulnerability (CVE-2026-45162)

Pimcore v11 and earlier is vulnerable to unsafe PHP deserialization in multiple locations due to missing `allowed_classes` restrictions when calling `unserialize()` on data from database columns and filesystem files; an attacker with control over serialized data sources (e.g., via SQL injection or file write vulnerabilities) can inject PHP gadget chains, leading to remote code execution.

pimcore/pimcore +1 deserialization remote code execution php
2r 1t
critical advisory

CVE-2026-8175: IBM Aspera High-Speed Transfer Endpoint and Server Buffer Overflow

IBM Aspera High-Speed Transfer Endpoint and Server are vulnerable to a buffer overflow in the asperahttpd component, potentially leading to denial of service, authentication bypass, or remote code execution.

Aspera High-Speed Transfer Endpoint +1 cve-2026-8175 buffer-overflow remote-code-execution denial-of-service
2r 3t 1c
high threat

7-Zip Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in 7-Zip to execute arbitrary program code on Windows, Linux, and macOS systems.

7-Zip rce remote-code-execution
2r 1t
critical advisory

CVE-2025-12686 - Synology BeeStation Manager and OS AdminCenter Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in the AdminCenter component of Synology BeeStation Manager (BSM) and BeeStation OS before version 1.3.2-65648, allowing remote attackers to execute arbitrary code through unspecified vectors (CVE-2025-12686).

BeeStation Manager +2 cve-2025-12686 buffer-overflow remote-code-execution synology
2r 1t 1c
high advisory

CVE-2026-8834: IBM HTTP Server Buffer Overflow Vulnerability

IBM HTTP Server 8.5 and 9.0 are vulnerable to a heap-based buffer overflow, allowing a privileged, authenticated user to execute arbitrary code or cause a denial of service.

HTTP Server 8.5 +1 buffer overflow remote code execution denial of service
2r 3t 1c
critical advisory

CVE-2026-23652 - Microsoft Power Pages Command Injection

CVE-2026-23652 is a critical command injection vulnerability in Microsoft Power Pages, allowing an unauthorized attacker to execute arbitrary code over the network by injecting commands.

Power Pages cve command injection remote code execution microsoft
2r 1t 1c
high advisory

Edimax BR-6675nD Remote Buffer Overflow Vulnerability (CVE-2026-9381)

A remote buffer overflow vulnerability (CVE-2026-9381) exists in the `formPPPoESetup` function of the Edimax BR-6675nD 1.12 router's web management interface, allowing unauthenticated attackers to potentially execute arbitrary code by manipulating the `pppUserName` argument in a POST request.

BR-6675nD 1.12 buffer overflow remote code execution cve
2r 2t 1c
high advisory

NousResearch hermes-agent Sandbox Vulnerability (CVE-2026-9368)

A vulnerability in NousResearch hermes-agent up to version 2026.4.16 allows for remote exploitation of the execute_code function, leading to a sandbox escape.

hermes-agent sandbox-escape remote-code-execution cve
2r 1t 1c
high advisory

NousResearch hermes-agent Remote Code Injection Vulnerability (CVE-2026-9353)

A remote code injection vulnerability (CVE-2026-9353) exists in NousResearch hermes-agent up to version 2026.4.23, allowing attackers to inject malicious code by manipulating the THREAT_PATTERNS argument in the Skills Guard Multi-Word Prompt Handler component.

hermes-agent cve code injection remote code execution web application
2r 1t 1c
medium advisory

LMDeploy Hardcoded trust_remote_code Enables Remote Code Execution (CVE-2026-46517)

LMDeploy <= 0.12.3 is vulnerable to remote code execution (CVE-2026-46517) because it hardcodes `trust_remote_code=True` when calling `transformers.AutoConfig.from_pretrained()`, allowing a malicious Hugging Face repository to execute arbitrary Python code when loaded without user opt-out.

transformers +1 remote code execution supply chain lmdeploy
2r 2t 1i
high advisory

Windows-MCP Unauthenticated PowerShell Control via HTTP Transports

Windows-MCP versions prior to 0.7.5 are vulnerable to unauthenticated PowerShell control via HTTP transports due to wildcard CORS and missing authentication, allowing a remote attacker to execute arbitrary PowerShell commands as the user running Windows-MCP.

windows-mcp remote-code-execution CORS
2r 1t
critical advisory

vllm Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in vllm to achieve arbitrary code execution.

vllm remote-code-execution vulnerability
2r 1t
high advisory

vllm and PyTorch Vulnerability Allows DoS and Potential Remote Code Execution

A remote, authenticated attacker can exploit a vulnerability in vllm and PyTorch to cause a denial-of-service condition or potentially achieve remote code execution.

vllm denial-of-service remote-code-execution PyTorch
2r 2t
critical advisory

Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability (CVE-2009-3459)

Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability, tracked as CVE-2009-3459, that could allow remote attackers to execute arbitrary code via a crafted PDF file.

Acrobat +1 cve-2009-3459 adobe heap overflow remote code execution
2r 1t 1c
critical advisory

CVE-2010-0249: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer is vulnerable to a use-after-free vulnerability (CVE-2010-0249) that allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object.

Internet Explorer cve use-after-free remote-code-execution
2r 1t 1c
high threat

CVE-2026-3593 Use-After-Free Vulnerability in BIND 9 DNS-over-HTTPS

A use-after-free vulnerability in the DNS-over-HTTPS implementation of BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1 could allow an attacker to cause a denial of service or potentially execute arbitrary code.

BIND 9 +2 cve dns use-after-free denial-of-service remote-code-execution
2r 2t 1c
high advisory

Penpot MCP REPL Server Unauthenticated Remote Code Execution

The Penpot MCP module's ReplServer binds to all interfaces and exposes an unauthenticated /execute endpoint, allowing remote attackers to execute arbitrary code by sending a POST request with JavaScript code, leading to potential information disclosure and command execution.

@penpot/mcp remote-code-execution unauthenticated-access
2r 1t
high threat

Shai-Hulud Campaign Returns Targeting npm Maintainer Accounts

The Shai-Hulud campaign is back and targets maintainer accounts to publish malicious code directly into the software supply chain via npm, recently hitting the Ant Design (AntV) ecosystem and potentially exposing downstream developers to credential theft and remote code execution.

npm Shai-Hulud supply-chain credential-theft remote-code-execution
1r 2t
high threat

H3C Magic B3 Buffer Overflow Vulnerability (CVE-2026-8764)

A remote buffer overflow vulnerability exists in the UpdateWanParams function of the /goform/aspForm file in H3C Magic B3 devices up to version 100R002, which can be exploited by manipulating the 'param' argument, leading to potential remote code execution.

exploited Magic B3 buffer overflow remote code execution CVE-2026-8764
2r 2t 1c
high threat

HS Brand Logo Slider 2.1 Unrestricted File Upload Vulnerability (CVE-2020-37227)

HS Brand Logo Slider version 2.1 contains an unrestricted file upload vulnerability (CVE-2020-37227) allowing authenticated users to bypass client-side validation and upload arbitrary files, leading to remote code execution by intercepting upload requests and renaming files to executable extensions.

HS Brand Logo Slider 2.1 file upload remote code execution wordpress CVE-2020-37227
2r 1t 1c
critical advisory

jsonpickle 2.0.0 Remote Code Execution via Deserialization of Malicious Payloads

jsonpickle version 2.0.0 contains a remote code execution vulnerability, allowing attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects, which invoke the eval function.

jsonpickle 2.0.0 deserialization remote code execution cve-2021-47952
2r 1t 1c
high advisory

FrankenPHP Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files

Two distinct flaws in the `splitPos()` function in `cgi.go` allows an attacker to mislead FrankenPHP into treating a non-`.php` file as a `.php` script, leading to remote code execution where the attacker can control file content.

frankenphp unicode remote code execution web server
2r 1t 1c
high threat

Remote Sunrise Helper for Windows 2026.14 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Remote Sunrise Helper for Windows version 2026.14, which can be exploited without authentication, as demonstrated by a public exploit published on Exploit-DB.

Remote Sunrise Helper for Windows remote-code-execution exploit windows
2r 2t
critical threat

Apache Camel Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in Apache Camel to execute arbitrary program code with the privileges of the service.

Camel-Coap remote-code-execution apache-camel
2r 1t
high advisory

Vvveb Unrestricted File Upload Vulnerability (CVE-2026-41937)

Vvveb before 1.0.8.3 is vulnerable to unrestricted file upload, allowing super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file containing PHP code which is then accessible via HTTP requests.

Vvveb +1 file upload remote code execution web application
2r 1t 1c
high advisory

Siemens Simcenter Femap Heap-Based Buffer Overflow RCE

A heap-based buffer overflow vulnerability in Siemens Simcenter Femap, tracked as CVE-2025-12659, can be exploited by tricking a user into opening a malicious IPT file, leading to remote code execution.

Simcenter Femap cve-2025-12659 heap overflow remote code execution siemens critical manufacturing
2r 1t 1c
high advisory

Flowise MCP Security Bypass Leads to Remote Code Execution

Flowise versions 3.1.1 and earlier are vulnerable to remote code execution (RCE) due to multiple MCP security bypasses, allowing attackers to execute arbitrary commands on the Flowise server by exploiting blocklist weaknesses in docker build, npx, and node command handling.

flowise +1 execution remote code execution
3r 1t
critical threat

CVE-2026-6271: WordPress Career Section Plugin Arbitrary File Upload Vulnerability

The Career Section plugin for WordPress is vulnerable to arbitrary file upload in versions up to 1.7 due to missing file type validation in the CV upload handler, potentially leading to remote code execution.

Career Section plugin arbitrary file upload remote code execution wordpress plugin
2r 1c
critical advisory

Mapfish Print Remote Code Injection Vulnerability in Dynamic Table (CVE-2026-44672)

An unauthenticated remote code injection vulnerability (CVE-2026-44672) exists in Mapfish Print's Dynamic table functionality, allowing attackers to execute arbitrary code on the server.

print-lib +1 remote-code-execution code-injection mapfish web-application
2r 1t
critical advisory

CVE-2026-42833: Microsoft Dynamics 365 (on-premises) Remote Code Execution

CVE-2026-42833 is a critical vulnerability in Microsoft Dynamics 365 (on-premises) allowing an authorized attacker with high privileges to execute arbitrary code over the network due to execution with unnecessary privileges.

Dynamics 365 cve remote code execution
2r 2t 1c
critical threat

CVE-2026-41096 Heap-Based Buffer Overflow in Windows DNS

CVE-2026-41096 is a critical heap-based buffer overflow vulnerability in Microsoft Windows DNS that allows an unauthenticated attacker to achieve remote code execution over a network.

Windows DNS cve-2026-41096 heap-based buffer overflow remote code execution
2r 1t 1c
high threat

Suspicious SolarWinds Web Help Desk Java Module Load or Child Process

Detects suspicious behavior related to SolarWinds Web Help Desk, specifically the loading of untrusted native modules (DLLs) or the spawning of suspicious child processes (cmd, PowerShell, rundll32) by the Java process, potentially indicating exploitation of deserialization vulnerabilities CVE-2025-40536 and CVE-2025-40551.

Web Help Desk solarwinds webhelpdesk deserialization cve-2025-40536 cve-2025-40551 remote code execution initial access
2r 1t 2c
critical advisory

Red Hat Enterprise Linux Multiple Vulnerabilities Leading to RCE/DoS

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.

Enterprise Linux vulnerability rhel remote-code-execution denial-of-service linux
2r 2t
critical advisory

CloudNativePG Metrics Exporter Privilege Escalation and RCE (CVE-2026-44477)

CVE-2026-44477 allows a low-privileged database user to escalate to PostgreSQL superuser and achieve OS command execution as the `postgres` user within the primary pod by exploiting the metrics exporter's superuser connection via custom metric queries or the default configuration.

CloudNativePG < 1.28.3 +1 privilege-escalation remote-code-execution CVE-2026-44477 CloudNativePG
2r 2t
critical advisory

CVE-2021-47933 - WordPress MStore API Arbitrary File Upload

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability, allowing unauthenticated attackers to upload malicious files via POST requests to the REST API, leading to remote code execution.

MStore API plugin for WordPress cve wordpress file upload remote code execution
2r 1t 1c
critical advisory

Snipe-IT File Upload Vulnerability Leads to Remote Code Execution (CVE-2026-37709)

Snipe-IT versions prior to 8.4.1 are vulnerable to remote code execution due to insecure permissions on file uploads, where an attacker can upload arbitrary files and execute code on the server.

snipe-it remote code execution file upload insecure permissions asset management CVE-2026-37709
2r 1t 1c
high advisory

Electerm Remote Code Execution Vulnerability via Malicious Filenames

A remote code execution vulnerability exists in Electerm versions 3.7.8 and earlier, where a malicious SSH server can inject arbitrary commands into a victim's system by crafting filenames with shell metacharacters that are executed when the user attempts to open or edit the file using the 'open with system editor' or 'edit with custom editor' feature.

electerm rce sftp remote code execution
2r 1t 1c
high threat

Totolink X5000R Buffer Overflow Vulnerability (CVE-2026-8137)

A buffer overflow vulnerability (CVE-2026-8137) exists in the Totolink X5000R router version 9.1.0u.6369_B20230113, allowing remote attackers to execute arbitrary code via manipulation of the 'submit-url' argument in the /boafrm/formDdns file.

X5000R 9.1.0u.6369_B20230113 cve buffer overflow router remote code execution
2r 1t 1c
high advisory

CVE-2026-7928 Use-After-Free Vulnerability in WebRTC

CVE-2026-7928 is a use-after-free vulnerability in the WebRTC component of Chromium, affecting Google Chrome and Microsoft Edge (Chromium-based) and potentially allowing for arbitrary code execution.

Edge +1 use-after-free webrtc chromium cve remote-code-execution
2r 4t 1c
critical advisory

AI Coding Agents Vulnerable to Supply Chain Attacks via Malicious Repositories

AI coding agents like Claude Code, Gemini CLI, Cursor CLI, and GitHub Copilot Agents can be manipulated to introduce malicious code into software supply chains by accessing attacker-controlled repositories, leading to potential remote code execution and supply chain compromises.

Claude Code +3 supply chain ai remote code execution
2r 1t
high advisory

Cisco Releases Security Advisories for Multiple Products

Cisco released security advisories on May 6, 2026, addressing vulnerabilities including remote code execution, server-side request forgery, and denial of service in Crosswork Network Controller, IoT Field Network Director, Network Services Orchestrator, SG350/SG350X Managed Switches, and Unity Connection.

Crosswork Network Controller +5 cisco vulnerability denial-of-service remote-code-execution server-side-request-forgery
3r 3t
high advisory

D-Link DI-8100 Buffer Overflow Vulnerability

A remote buffer overflow vulnerability exists in the sprintf function of the /user_group.asp file within the CGI Handler component of D-Link DI-8100 version 16.07.26A1, potentially leading to arbitrary code execution.

DI-8100 16.07.26A1 buffer-overflow cgi-handler remote-code-execution router
2r 1c
critical threat

Eclipse Equinox OSGi Remote Code Execution Vulnerability (CVE-2023-54344)

Eclipse Equinox OSGi 3.7.2 and earlier is vulnerable to remote code execution, allowing unauthenticated attackers to execute arbitrary commands by sending specially crafted payloads to the console interface, potentially leading to reverse shell creation.

Equinox OSGi rce cve-2023-54344 eclipse osgi remote-code-execution
2r 1t 1c
high advisory

Funadmin Unrestricted File Upload Vulnerability (CVE-2026-7733)

Funadmin versions up to 7.1.0-rc6 are vulnerable to unrestricted file uploads due to improper handling of the File argument in the UploadService::chunkUpload function, potentially leading to remote code execution.

funadmin <= 7.1.0-rc6 cve unrestricted file upload remote code execution
2r 1t 1c
critical advisory

Totolink WA300 Buffer Overflow Vulnerability (CVE-2026-7719)

A buffer overflow vulnerability exists in Totolink WA300 version 5.2cu.7112_B20190227 within the loginauth function of the /cgi-bin/cstecgi.cgi file, specifically affecting the POST Request Handler component, triggerable via manipulation of the http_host argument, and remotely exploitable with a publicly available exploit.

WA300 5.2cu.7112_B20190227 buffer overflow remote code execution cve-2026-7719 totolink
2r 1t 1c
critical threat

Totolink WA300 Buffer Overflow Vulnerability in UploadCustomModule

A remote buffer overflow vulnerability exists in the UploadCustomModule function of the /cgi-bin/cstecgi.cgi file in the POST Request Handler component of Totolink WA300 version 5.2cu.7112_B20190227, which can be exploited by manipulating the File argument.

WA300 5.2cu.7112_B20190227 buffer-overflow remote-code-execution router
2r 1t 1c
critical threat

Shenzhen Libituo Technology LBT-T300-HW1 Buffer Overflow Vulnerability

A buffer overflow vulnerability exists in Shenzhen Libituo Technology LBT-T300-HW1 version 1.2.8 and earlier, allowing remote attackers to execute arbitrary code by manipulating the Channel/ApCliSsid argument in the start_lan function of the /apply.cgi file.

LBT-T300-HW1 buffer overflow remote code execution web application vulnerability
2r 1t 1c
critical threat

Chromium Use-After-Free Vulnerability in GPU Component (CVE-2026-7333)

CVE-2026-7333 is a use-after-free vulnerability in the GPU component of Chromium, affecting Google Chrome and Microsoft Edge, potentially leading to arbitrary code execution.

Chrome +1 use-after-free chromium gpu cve-2026-7333 remote code execution
2r 1c
critical advisory

Chromium Use-After-Free Vulnerability in Cast (CVE-2026-7338)

CVE-2026-7338 is a use-after-free vulnerability in the Cast component of Chromium, affecting Google Chrome and Microsoft Edge, potentially leading to arbitrary code execution.

Chrome +1 use-after-free edge cve-2026-7338 remote code execution
2r 1c
critical advisory

code-projects Plugin 4.1.2cu.5137 Buffer Overflow Vulnerability

A buffer overflow vulnerability (CVE-2026-7503) exists in code-projects Plugin 4.1.2cu.5137, allowing a remote attacker to execute arbitrary code by manipulating the 'wepkey2' argument in the 'setWiFiMultipleConfig' function of the '/lib/cste_modules/wireless.so' library, posing a critical risk due to publicly available exploits.

Plugin 4.1.2cu.5137 buffer-overflow remote-code-execution cve-2026-7503
2r 2t 1c
critical advisory

UTT HiPER 1250GW Buffer Overflow Vulnerability (CVE-2026-7420)

A buffer overflow vulnerability in UTT HiPER 1250GW devices (versions up to 3.2.7-210907-180535) allows remote attackers to execute arbitrary code by manipulating the 'Profile' argument in the `strcpy` function of the `route/goform/ConfigAdvideo` file, due to insufficient bounds checking.

HiPER 1250GW buffer-overflow remote-code-execution iot
2r 1t 1c
critical advisory

UTT HiPER 1250GW Buffer Overflow Vulnerability

A remote buffer overflow vulnerability exists in the UTT HiPER 1250GW device due to improper handling of the 'Profile' argument in the NTP configuration, potentially allowing for arbitrary code execution.

HiPER 1250GW buffer-overflow remote-code-execution cve-2026-7418
2r 1t 1c
critical advisory

Tenda F456 Router Buffer Overflow Vulnerability (CVE-2026-7101)

A buffer overflow vulnerability in Tenda F456 version 1.0.0.5 allows remote attackers to execute arbitrary code via a crafted request to the fromWrlclientSet function in the /goform/WrlclientSet file of the httpd component.

F456 cve-2026-7101 buffer-overflow router tenda remote-code-execution
2r 1t 1c
critical advisory

Tenda F456 Router Buffer Overflow Vulnerability

A buffer overflow vulnerability in Tenda F456 router version 1.0.0.5 allows a remote attacker to execute arbitrary code by exploiting the fromSafeClientFilter function in the /goform/SafeClientFilter endpoint through manipulation of the 'menufacturer/Go' argument.

F456 1.0.0.5 buffer-overflow remote-code-execution cve-2026-7033 router
2r 1t 1c
critical advisory

Ray Data Remote Code Execution via Parquet Arrow Extension Type Deserialization

Ray Data is vulnerable to remote code execution via Parquet Arrow Extension Type Deserialization; specifically, a maliciously crafted Parquet file can trigger arbitrary code execution due to the unsafe deserialization of Arrow extension metadata, affecting Ray versions 2.49.0 through 2.54.0.

Ray Data remote-code-execution parquet deserialization cloudpickle ray
2r 1t
high advisory

OpenMage LTS Phar Deserialization RCE

A remote code execution vulnerability exists in OpenMage LTS versions prior to 20.16.1 due to Phar deserialization, where an attacker can upload a malicious phar file disguised as an image and trigger deserialization via functions like `getimagesize()`, `file_exists()`, or `is_readable()` when processing `phar://` stream wrapper paths, leading to arbitrary code execution.

phar deserialization remote code execution OpenMage LTS Magento 1.x
2r 2t
high advisory

Modelscope Agentscope Code Injection Vulnerability (CVE-2026-6603)

A code injection vulnerability exists in modelscope agentscope up to version 1.0.18, specifically affecting the execute_python_code/execute_shell_command functions, allowing for remote code execution.

code-injection remote-code-execution agentscope
2r 1t
critical threat

Microsoft April 2026 Patch Tuesday Addresses 163 Vulnerabilities

Microsoft's April 2026 Patch Tuesday addresses 163 vulnerabilities, including 8 critical ones, ranging from Tampering to Remote Code Execution and Privilege Escalation, affecting various Microsoft products; it is recommended to apply patches immediately.

exploited patch-tuesday vulnerability remote-code-execution privilege-escalation windows
2r 4t 6c
critical advisory

Openfind MailGates/MailAudit Stack-based Buffer Overflow (CVE-2026-6350)

Openfind MailGates/MailAudit is vulnerable to a stack-based buffer overflow (CVE-2026-6350) allowing unauthenticated remote attackers to execute arbitrary code by controlling the program's execution flow.

cve-2026-6350 buffer-overflow remote-code-execution
2r 1t 1c
critical advisory

CVE-2026-33824: Windows IKE Extension Double Free Vulnerability

A double free vulnerability in the Windows IKE Extension, tracked as CVE-2026-33824, allows an unauthenticated remote attacker to execute arbitrary code over the network.

cve-2026-33824 windows ike double-free remote-code-execution
2r 3t 1c
critical advisory

PraisonAI Unauthenticated Remote Session Hijacking Vulnerability (CVE-2026-40289)

PraisonAI versions before 4.5.139 and praisonaiagents versions before 1.5.140 are vulnerable to unauthenticated remote session hijacking due to missing authentication and a bypassable origin check on the /ws WebSocket endpoint, enabling unauthorized remote control and data leakage.

cve-2026-40289 websocket remote-code-execution praisonai
2r 5t 1c
critical advisory

Smart Slider 3 Pro Compromised Update Leads to Remote Code Execution

Smart Slider 3 Pro version 3.5.1.35 for WordPress and Joomla contains a multi-stage remote access toolkit injected through a compromised update system allowing unauthenticated remote code execution and system takeover.

wordpress joomla remote-code-execution plugin
3r 9t 1c
high advisory

Logstash Arbitrary File Write via Path Traversal (CVE-2026-33466)

CVE-2026-33466 describes a vulnerability in Logstash where improper validation of file paths within compressed archives allows arbitrary file writes, potentially leading to remote code execution.

path-traversal remote-code-execution logstash
2r 2t 1c
high advisory

WordPress Plugin Vulnerability: Arbitrary File Upload in Gerador de Certificados – DevApps

The Gerador de Certificados – DevApps WordPress plugin is vulnerable to arbitrary file uploads due to missing file type validation, potentially leading to remote code execution.

wordpress plugin file-upload remote-code-execution
2r 2t 1c
critical advisory

Windmill Missing Authorization Vulnerability (CVE-2026-22683)

Windmill versions 1.56.0 through 1.614.0 contain a missing authorization vulnerability (CVE-2026-22683) that allows users with the Operator role to bypass intended restrictions and perform unauthorized entity creation and modification actions via the backend API, potentially leading to privilege escalation and remote code execution.

windmill authorization-bypass privilege-escalation remote-code-execution
2r 2t 1c
critical advisory

Tenda CX12L Router Stack-Based Buffer Overflow Vulnerability (CVE-2026-5686)

A stack-based buffer overflow vulnerability (CVE-2026-5686) exists in the Tenda CX12L router version 16.03.53.12, allowing remote attackers to potentially execute arbitrary code by manipulating the 'page' argument in the `/goform/RouteStatic` endpoint.

cve-2026-5686 tenda router stack-based buffer overflow remote code execution
2r 2t 1c
critical advisory

Emlog Path Traversal Vulnerability Leads to Remote Code Execution

Emlog versions 2.6.2 and prior are vulnerable to path traversal via crafted ZIP uploads, allowing authenticated admins to write arbitrary files and achieve remote code execution.

path-traversal remote-code-execution emlog web-application
2r 3t 1c
high advisory

Cesanta Mongoose TLS 1.3 Heap-Based Buffer Overflow Vulnerability (CVE-2026-5244)

A remote heap-based buffer overflow vulnerability exists in Cesanta Mongoose versions up to 7.20 due to improper handling of the pubkey argument in the mg_tls_recv_cert function, potentially leading to code execution.

cve-2026-5244 heap-based-buffer-overflow tls-1.3 remote-code-execution
2r 1t 1c
critical advisory

Multiple Vulnerabilities in libpng Allow Remote Code Execution and Denial of Service

A remote, anonymous attacker can exploit multiple vulnerabilities in libpng to execute arbitrary program code or cause a denial of service.

libpng vulnerability remote-code-execution denial-of-service
2r 2t
critical advisory

OpenClaw Privilege Escalation Vulnerability (CVE-2026-32922)

OpenClaw before 2026.3.11 is vulnerable to privilege escalation in the device.token.rotate function, allowing attackers with limited operator.pairing scope to mint tokens with elevated operator.admin privileges, potentially leading to remote code execution.

privilege-escalation remote-code-execution cve
2r 2t
critical advisory

Crashmail 1.6 Stack-Based Buffer Overflow Vulnerability

Crashmail 1.6 is vulnerable to a stack-based buffer overflow, allowing remote attackers to execute arbitrary code via malicious input and potentially leading to denial of service.

buffer-overflow remote-code-execution cve-2018-25223
2r 5t
critical advisory

Totolink LR350 Remote Buffer Overflow Vulnerability (CVE-2026-4976)

A buffer overflow vulnerability in Totolink LR350 version 9.3.5u.6369_B20220309 allows a remote attacker to execute arbitrary code by manipulating the 'ssid' argument in the setWiFiGuestCfg function.

cve-2026-4976 buffer-overflow totolink router remote-code-execution
2r 1t
critical advisory

WP Job Portal Plugin Arbitrary File Deletion Vulnerability (CVE-2026-4758)

The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.

cve wordpress file-deletion remote-code-execution
2r 3t
high advisory

CVE-2026-4675: Google Chrome WebGL Heap Buffer Overflow Vulnerability

A heap buffer overflow vulnerability (CVE-2026-4675) exists in Google Chrome's WebGL implementation prior to version 146.0.7680.165, allowing a remote attacker to perform an out-of-bounds memory read via a specially crafted HTML page, potentially leading to information disclosure or arbitrary code execution.

cve-2026-4675 heap-buffer-overflow webgl chrome remote-code-execution
2r 2t
critical advisory

Multiple Vulnerabilities in Apache Tomcat Allow for Remote Code Execution and Data Manipulation

Multiple vulnerabilities in Apache Tomcat can be exploited by a remote, authenticated or anonymous attacker to execute arbitrary code, bypass security measures, manipulate data, and cause a denial of service.

apache-tomcat vulnerability remote-code-execution data-manipulation denial-of-service
2r 3t
high advisory

Census CSWeb 8.0.1 Arbitrary File Upload Vulnerability

A remote, authenticated attacker can exploit an arbitrary file upload vulnerability in Census CSWeb 8.0.1 (CVE-2025-60947) to upload malicious files, potentially leading to remote code execution.

file-upload remote-code-execution web-application
2r 2t
critical advisory

Tenda A15 Router Stack-Based Buffer Overflow (CVE-2026-4567)

A stack-based buffer overflow vulnerability (CVE-2026-4567) exists in the UploadCfg function of the /cgi-bin/UploadCfg file in Tenda A15 firmware version 15.13.07.13, allowing remote attackers to execute arbitrary code by manipulating the File argument.

cve-2026-4567 stack-based buffer overflow tenda router remote code execution
2r 1t
critical advisory

GStreamer Multiple Vulnerabilities Allow for Remote Code Execution and Denial of Service

Multiple vulnerabilities in GStreamer allow a remote, anonymous attacker to cause a denial-of-service condition or execute arbitrary code.

GStreamer vulnerability denial-of-service remote-code-execution
2r 2t 5c
critical advisory

ConnectWise ScreenConnect Path Traversal Vulnerability (CVE-2024-1708)

CVE-2024-1708 is a path traversal vulnerability in ConnectWise ScreenConnect that could allow an attacker to execute remote code or directly impact confidential data and critical systems.

ScreenConnect path-traversal remote-code-execution cve-2024-1708 connectwise
2r 1t 1c
medium advisory

Detection of Unauthorized GitHub Actions Runner Registration

The configuration of a GitHub Actions self-hosted runner using the Runner.Listener binary can indicate malicious activity aimed at establishing remote code execution via malicious GitHub workflows.

GitHub Actions Runner github-actions supply-chain remote-code-execution
3r 3t
critical advisory

CI4MS Unauthenticated .env Overwrite Vulnerability (CVE-2026-39393)

CI4MS versions before 0.31.4.0 are vulnerable to unauthenticated takeover due to a flawed install route guard that allows overwriting the .env file with attacker-controlled database credentials when the database is temporarily unreachable.

CI4MS CVE-2026-39393 CodeIgniter Remote Code Execution Unauthenticated Access
2r 1t 1c
high advisory

PromtEngineer localGPT Unrestricted Upload Vulnerability (CVE-2026-5001)

A remote attacker can exploit an unrestricted file upload vulnerability (CVE-2026-5001) in PromtEngineer localGPT up to version 4d41c7d1713b16b216d8e062e51a5dd88b20b054 via the do_POST function in backend/server.py.

localGPT unrestricted-upload remote-code-execution
2r 1t
critical advisory

Mozilla Firefox and Thunderbird JIT Miscompilation Vulnerability (CVE-2026-4702)

A critical JIT miscompilation vulnerability (CVE-2026-4702) in the JavaScript Engine affects Firefox and Thunderbird, potentially allowing remote code execution.

Firefox +1 cve-2026-4702 jit-miscompilation thunderbird remote-code-execution
3r 2t
critical advisory

WordPress Advanced Members for ACF Plugin Arbitrary File Deletion Vulnerability

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function, allowing authenticated attackers with Subscriber-level access or higher to delete arbitrary files, potentially leading to remote code execution.

WordPress +1 file-deletion remote-code-execution cve-2026-3243
2r 1t 1c
high advisory

gitoxide Arbitrary Command Execution via .gitmodules Bypass

A vulnerability in gitoxide's `gix_submodule::File::update()` allows arbitrary command execution via a crafted `.gitmodules` file by incorrectly validating the source of the `update` command, enabling an attacker to inject malicious commands after a submodule has been initialized.

gix code-vulnerability remote-code-execution gitoxide
2r 1t 1c
critical advisory

OpenRemote IoT Platform Expression Injection Vulnerability

The OpenRemote IoT platform is vulnerable to expression injection, allowing remote code execution due to an unsandboxed Nashorn JavaScript engine and an inactive Groovy sandbox, leading to full server compromise.

OpenRemote IoT Platform openremote expression-injection remote-code-execution iot
2r 1t
critical advisory

ChurchCRM Remote Code Execution via Backup Restore Vulnerability (CVE-2026-40484)

ChurchCRM versions before 7.2.0 are vulnerable to remote code execution (RCE) due to insufficient file extension filtering during database backup restoration, allowing an authenticated administrator to upload a crafted archive containing a PHP webshell that can be executed via HTTP requests.

ChurchCRM CVE-2026-40484 Remote Code Execution Web Shell CSRF
3r 2t 1c
high advisory

nginx-ui Race Condition Leads to Data Corruption and Potential RCE

The nginx-ui application is vulnerable to a race condition due to concurrent requests corrupting the app.ini configuration file, potentially leading to a persistent denial of service and a non-deterministic path to remote code execution.

nginx-ui race-condition denial-of-service remote-code-execution configuration-corruption
3r 2t
critical advisory

FUXA 1.2.8 Authentication Bypass and Remote Command Execution Vulnerability

FUXA 1.2.8 and earlier is vulnerable to an authentication bypass vulnerability (CVE-2025-69985) that allows remote command execution by exploiting the /api/runscript endpoint with a crafted JavaScript payload.

FUXA authentication-bypass remote-code-execution web-application scada
2r 2t 1c
critical advisory

HKUDS OpenHarness Plugin Management Vulnerability (CVE-2026-6819)

HKUDS OpenHarness before PR #156 allows remote attackers with channel layer access to manage plugin lifecycle commands, enabling unauthorized plugin installation and activation.

OpenHarness cve-2026-6819 plugin-vulnerability remote-code-execution
2r 3t 1c
critical advisory

Xerte Online Toolkits Path Traversal Vulnerability

Xerte Online Toolkits 3.15 and earlier are vulnerable to relative path traversal, allowing attackers to move files and potentially achieve remote code execution.

Xerte Online Toolkits path-traversal remote-code-execution xss
2r 2t 1c
high advisory

vm2 NodeVM require.root Bypass via Symlink Traversal

A vulnerability exists in vm2 version 3.10.5 where NodeVM's `require.root` path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the allowed root directory in host context, leading to remote code execution.

vm2 sandbox-escape remote-code-execution symlink
2r 2t
critical advisory

Paperclip Privilege Escalation via Agent API Key

A privilege escalation vulnerability in Paperclip allows an attacker with an Agent API key to execute arbitrary OS commands on the Paperclip server host by injecting commands into the `adapterConfig.workspaceStrategy.provisionCommand` field via the `/agents/:id` API endpoint, leading to remote code execution.

Paperclip privilege-escalation remote-code-execution
2r 2t
critical advisory

Microsoft Word RTF Heap Overflow Vulnerability (CVE-2023-21716)

CVE-2023-21716 is a critical heap-based buffer overflow vulnerability in Microsoft Word 2016's RTF parser, triggered by a malformed RTF file, leading to remote code execution on Windows 7.

Word 2016 cve-2023-21716 rtf heap overflow remote code execution
2r 1t 1c
critical advisory

D-Link DI-8100 Remote Buffer Overflow Vulnerability (CVE-2026-7853)

D-Link DI-8100 version 16.07.26A1 is vulnerable to a remote buffer overflow in the `sprintf` function within the `/auto_reboot.asp` file's HTTP handler component due to improper handling of the `enable/time` argument, potentially leading to arbitrary code execution.

DI-8100 buffer overflow remote code execution d-link cve-2026-7853
2r 1t 1c
critical advisory

Daptin Unauthenticated Path Traversal and Zip Slip Vulnerability

Daptin versions up to and including v0.11.3 are vulnerable to unauthenticated path traversal and zip slip attacks via the cloudstore.file.upload action, allowing arbitrary file write and potential remote code execution.

Daptin path-traversal zip-slip remote-code-execution
1r 2t
high advisory

GitPython config_writer().set_value() Newline Injection RCE

A newline injection vulnerability in GitPython's `config_writer().set_value()` function enables remote code execution by manipulating the `core.hooksPath` Git configuration.

GitPython newline injection remote code execution config poisoning
2r 1t
high advisory

CVE-2026-6315 Use-After-Free Vulnerability in Google Chrome on Android

A use-after-free vulnerability in Google Chrome on Android prior to version 147.0.7727.101 (CVE-2026-6315) allows remote attackers to execute arbitrary code by convincing a user to interact with a crafted HTML page through specific UI gestures.

Chrome use-after-free android cve-2026-6315 remote-code-execution
2r 2t 1c
critical advisory

Pipecat Remote Code Execution via Pickle Deserialization in LivekitFrameSerializer

A critical vulnerability, CVE-2025-62373, exists in Pipecat's LivekitFrameSerializer where the deserialize() method uses Python's pickle.loads() on WebSocket data without validation, allowing a malicious WebSocket client to execute arbitrary code on the Pipecat server if LivekitFrameSerializer is explicitly enabled.

pipecat-ai remote code execution deserialization pipecat
2r 1t 1c
critical advisory

Android-ImageMagick7 Improper Input Validation Vulnerability (CVE-2026-4755)

A CWE-20 improper input validation vulnerability exists in MolotovCherry Android-ImageMagick7 before version 7.1.2-11, potentially allowing for remote code execution or denial of service.

Android-ImageMagick7 cve-2026-4755 android imagemagick input-validation remote-code-execution
2r 3t