Skip to content
Threat Feed

Tag

Unauthenticated

34 briefs RSS
critical advisory

Unauthenticated Credential Disclosure in Vacron VIN-DS783E-E6 via Hidden Functionality (CVE-2026-18191)

CVE-2026-18191 describes a critical Hidden Functionality vulnerability in Vacron VIN-DS783E-E6 devices that allows unauthenticated remote attackers to exploit a specific hidden function to obtain administrator credentials, leading to full device compromise.

VIN-DS783E-E6 vulnerability credential-access unauthenticated network-device CVE-2026-18191
2t 1c
high advisory

WordPress Premium Packages Plugin SQL Injection Vulnerability (CVE-2026-12800)

The Premium Packages - Sell Digital Products Securely plugin for WordPress, in versions up to and including 6.2.0, is vulnerable to SQL Injection via the 'code' parameter of the POST /wp-json/wpdmpp/v1/cart/coupon REST API endpoint, allowing unauthenticated attackers to append additional SQL queries to extract sensitive database information.

Premium Packages – Sell Digital Products Securely wordpress sql-injection web-application unauthenticated
1r 3t 1c
critical advisory

Critical Eval Injection Vulnerability in vBulletin Allows Remote Code Execution (CVE-2026-61511)

An eval injection vulnerability, identified as CVE-2026-61511, exists in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, specifically within the vB5_Template_Runtime::runMaths() method, allowing unauthenticated remote attackers to achieve arbitrary PHP code execution by manipulating the pagenav[pagenumber] parameter through the unauthenticated ajax/render template route with phpfuck-style encoding.

PoC vBulletin 5.x through 5.7.5 +4 web-vulnerability remote-code-execution eval-injection php unauthenticated
1r 2t 3c 4i
critical advisory

OpenDJ DSMLv2 Gateway Vulnerability Allows Unauthenticated SSRF, Local File Read, and DoS

A remote, unauthenticated attacker can exploit a critical vulnerability in the DSMLv2 SOAP gateway (opendj-dsml-servlet) of OpenIdentityPlatform OpenDJ versions up to 5.1.1, allowing server-side request forgery (SSRF), local file reading via `file:` URIs, and denial-of-service (DoS) due to unbounded response reads by submitting specially crafted DSML add/modify requests.

OpenDJ <= 5.1.1 ssrf file-read denial-of-service web-application unauthenticated
4t
critical advisory

Home Assistant Core Path Traversal Vulnerability (CVE-2026-64825)

A critical path traversal vulnerability, CVE-2026-64825, in Home Assistant Core versions before 2026.6.0 allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window, potentially leading to full system compromise with root privileges.

Home Assistant Core < 2026.6.0 vulnerability path-traversal home-assistant rce unauthenticated initial-access
2t 2c
high advisory

Unauthenticated Server-Side Request Forgery in meta-ads-mcp via image_url

An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in `meta-ads-mcp` v1.0.113, specifically within the `upload_ad_image` function, by providing a malicious `image_url` parameter that causes the server to make arbitrary outbound HTTP requests to internal services, RFC 1918 addresses, or cloud metadata endpoints, leading to information disclosure and potential internal network compromise.

meta-ads-mcp 1.0.113 ssrf vulnerability web python unauthenticated
3t 2i
high advisory

Unauthenticated Server-Side Request Forgery (SSRF) Vulnerability in stoatchat CVE-2026-63306

An unauthenticated server-side request forgery vulnerability, tracked as CVE-2026-63306, exists in stoatchat versions prior to 0.13.5 in the /proxy and /embed endpoints, allowing attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints, leading to unauthorized information disclosure and potential further compromise of internal infrastructure.

stoatchat ssrf vulnerability web-application unauthenticated information-disclosure
1r 3t 1c
medium advisory

MKP Pod Log Read Vulnerability Leads to Memory Exhaustion and Denial of Service

An unauthenticated remote attacker can exploit a vulnerability in the MKP (Model Context Protocol for Kubernetes) server to exhaust its memory and cause a denial of service by sending a crafted `tools/call` request that manipulates `limitBytes` or `tailLines` parameters, leading to unbounded Kubernetes pod log reads into memory.

MKP server kubernetes denial-of-service memory-exhaustion unauthenticated mcp cloud
2t
high advisory

WP CTA Plugin Vulnerable to Unauthenticated Time-Based Blind SQL Injection (CVE-2026-4661)

The WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in versions up to and including 2.2.2. This vulnerability is due to insufficient escaping of user-supplied column names and lack of preparation in database queries. Unauthenticated attackers can exploit this by injecting arbitrary SQL queries to extract sensitive information, including administrator password hashes, from the database.

WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin <= 2.2.2 wordpress plugin sql-injection time-based-blind unauthenticated web-vulnerability
1r 2t 1c
high advisory

YesWiki Unauthenticated SSRF via ActivityPub Signature.keyId (CVE-2026-52769)

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52769, exists in YesWiki's `POST /api/forms/{formId}/actor/inbox` route when ActivityPub is enabled, allowing attackers to force arbitrary outbound HTTP GET requests to internal or external hosts and potentially exfiltrate sensitive information via timing and error messages.

YesWiki ssrf web-vulnerability php unauthenticated cve
1r 3t 1i
high advisory

CVE-2026-59702: repomix Server-Side Request Forgery

An unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-59702, in repomix's POST /api/pack endpoint allows attackers to make arbitrary outbound requests, potentially leading to internal network reconnaissance, access to cloud metadata services, and local filesystem path enumeration.

repomix server-side-request-forgery ssrf cve webserver unauthenticated initial-access discovery
1r 4t 1c
high advisory

CVE-2026-14750 — SQL Injection in mjperpinosa stumasy via Password Argument

A high-severity remote SQL injection vulnerability (CVE-2026-14750) exists in mjperpinosa stumasy up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, allowing unauthenticated attackers to manipulate the 'Password' argument in the `Notes_controller::accessing_dictionary_authorization` function to execute arbitrary SQL queries, leading to data exfiltration, manipulation, or potential server compromise via a publicly available exploit.

stumasy sql-injection web-application cve unauthenticated remote-code-execution data-exfiltration
1r 3t 1c
high advisory

CVE-2026-14700: Code-Projects Internship Management System SQL Injection Vulnerability

A critical unauthenticated SQL injection vulnerability (CVE-2026-14700) in the 'employer/login.php' endpoint of code-projects Internship Management System 1.0 allows remote attackers to manipulate 'email' or 'password' arguments, potentially leading to unauthorized access and data compromise, with public exploit disclosure increasing risk.

Internship Management System 1.0 sql-injection web-application initial-access php unauthenticated
1r 1t 1c
critical advisory

motionEye: LFI → Pass-the-Hash Admin → Unsafe Restore → Unauthenticated Action Execution (RCE)

An attacker can chain multiple vulnerabilities in motionEye, including an arbitrary file read (LFI), a signature bypass using password hashes, and an unsafe configuration restore, to achieve unauthenticated remote code execution (RCE) if the normal user password is unset, or authenticated RCE from a normal user account.

motionEye RCE LFI vulnerability unauthenticated privilege-escalation
1r 5t
high advisory

Crawl4AI Unauthenticated SSRF in Docker API `crawl/stream` Endpoint

A remote, unauthenticated attacker can exploit an unpatched Server-Side Request Forgery (SSRF) vulnerability in Crawl4AI Docker API versions up to 0.8.9, specifically targeting the `/crawl/stream` endpoint, to read internal network services and cloud-metadata endpoints, potentially exposing sensitive information like IAM credentials.

crawl4ai ssrf web-application docker unauthenticated api-exploitation
2r 3t
critical advisory

CVE-2026-46817 - Oracle Payments Unauthenticated Remote Takeover via HTTP

CVE-2026-46817 is a critical vulnerability in Oracle Payments component of Oracle E-Business Suite versions 12.2.3 through 12.2.15, allowing an unauthenticated attacker with network access via HTTP to compromise the application and potentially achieve complete takeover.

PoC E-Business Suite +4 cve oracle ebusiness suite rce unauthenticated privilege-escalation
2r 3c 4i updated
critical advisory

CVE-2026-34311: Oracle Hospitality OPERA 5 Property Services Unauthenticated Remote Takeover

CVE-2026-34311 allows an unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services, potentially resulting in complete takeover of the application in versions 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6, and 5.6.28.

OPERA 5 Property Services cve remote_code_execution unauthenticated
2r 1c
medium advisory

phpMyFAQ Unauthenticated Password Reset Vulnerability (CVE-2026-35676)

phpMyFAQ before 4.1.3 is vulnerable to an unauthenticated password reset, allowing attackers to change account passwords without token validation by sending crafted PUT requests to the /api/index.php/user/password/update endpoint.

phpMyFAQ cve vulnerability password reset unauthenticated
2r 1t 1c
critical advisory

CVE-2026-6226 - Frontend Admin WordPress Plugin Unauthenticated Privilege Escalation

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthenticated privilege escalation in versions up to and including 3.29.2, allowing attackers to create administrator accounts by injecting a custom form configuration with a spoofed role field.

Frontend Admin by DynamiApps plugin for WordPress <= 3.29.2 cve wordpress privilege-escalation unauthenticated
2r 1t 1c
high advisory

FUXA Unauthenticated Remote Code Execution via Script Test Mode Authorization Bypass (CVE-2026-43947)

FUXA version 1.3.0 is vulnerable to unauthenticated remote code execution (CVE-2026-43947) because the /api/runscript endpoint, when in test mode, executes attacker-supplied code without proper authorization, allowing execution of arbitrary commands if a server-side script exists with permissive permissions.

fuxa-server rce unauthenticated cve-2026-43947
2r 2t
critical advisory

9router Unauthenticated Remote Code Execution via MCP Plugin Routes

9router versions 0.4.30 to 0.4.33 are vulnerable to unauthenticated remote code execution, allowing network-adjacent attackers to execute arbitrary OS commands by registering and triggering malicious plugins through unprotected API endpoints.

9router rce unauthenticated plugin
2r 1t
critical advisory

GitBucket 4.23.1 Unauthenticated Remote Code Execution Vulnerability (CVE-2018-25332)

GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability (CVE-2018-25332) allowing attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file upload functionality via a malicious JAR plugin.

GitBucket 4.23.1 cve rce gitbucket unauthenticated
2r 2t 1c
high advisory

CVE-2020-37244: Supsystic Membership 1.4.7 Unauthenticated SQL Injection Vulnerability

Supsystic Membership version 1.4.7 is vulnerable to SQL injection (CVE-2020-37244), allowing unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters, potentially extracting sensitive database information.

Membership 1.4.7 sqli cve-2020-37244 wordpress unauthenticated
2r 1t 1c
medium advisory

Goobi Viewer Unauthenticated Solr Streaming Expression Proxy Vulnerability

The Goobi viewer REST endpoint accepted an arbitrary Solr streaming expression from unauthenticated network clients, enabling attackers to read, modify, or delete the complete Solr index; this was resolved by removing the affected API endpoint.

Goobi viewer solr proxy unauthenticated CVE-2026-45083 critical
2r 1t
high advisory

Dalfox Server Mode Unauthenticated Arbitrary File Create/Append Vulnerability

Dalfox in REST API server mode is vulnerable to CVE-2026-45089, an unauthenticated arbitrary file create/append vulnerability, due to the `output`, `output-all`, and `debug` options being deserialized directly from the attacker's request body, allowing a network caller to create or append to any file writable by the dalfox process.

dalfox <= 2.12.0 xss file-write unauthenticated CVE-2026-45089
2r 3t
critical advisory

CVE-2021-47932: WordPress TheCartPress Unauthenticated Privilege Escalation

WordPress TheCartPress version 1.5.3.6 contains an unauthenticated privilege escalation vulnerability, CVE-2021-47932, allowing attackers to create administrator accounts via crafted POST requests to the AJAX handler.

TheCartPress 1.5.3.6 wordpress privilege-escalation unauthenticated CVE-2021-47932
2r 1t 1c
medium threat

free5GC SMF Unauthenticated Process-Kill Denial-of-Service via UPI Endpoint

free5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted POST request to the `/upi/v1/upNodesLinks` endpoint can trigger a `Fatalf` call, terminating the entire SMF process, effectively disrupting network services.

SMF free5GC DoS unauthenticated UPI CVE-2026-44321
2r 1t 1i
high advisory

WordPress Easy PayPal Events & Tickets Plugin Information Disclosure Vulnerability

An information disclosure vulnerability in the Easy PayPal Events & Tickets WordPress plugin (versions 1.3 and earlier) allows unauthenticated attackers to enumerate and retrieve all customer order records via the scan_qr.php endpoint.

Easy PayPal Events & Tickets plugin wordpress info-disclosure cve-2026-41471 unauthenticated enumeration
2r 1t 1c
critical advisory

Weaver E-cology Unauthenticated RCE via Dubbo API Debug Endpoint

Weaver E-cology 10.0 before 20260312 is vulnerable to unauthenticated remote code execution, allowing attackers to execute arbitrary commands by crafting a POST request to the /papi/esearch/data/devops/dubboApi/debug/method endpoint.

weaver e-cology rce unauthenticated cve-2026-22679
3r 1t 1c
critical advisory

Dell Wyse Management Suite Unauthenticated Remote Code Execution

An unauthenticated remote code execution (RCE) vulnerability exists in Dell Wyse Management Suite, allowing attackers to execute arbitrary code without authentication.

Wyse Management Suite dell wyse rce unauthenticated
2r 4t
critical advisory

WWBN AVideo Unauthenticated SQL Injection Vulnerability (CVE-2026-33485)

WWBN AVideo versions up to 26.0 are vulnerable to unauthenticated SQL injection via the RTMP `on_publish` callback, allowing attackers to extract sensitive database information.

AVideo sqli unauthenticated cve-2026-33485
2r 1t
critical advisory

Unauthenticated Remote Takeover of Nginx-UI via MCP Endpoint

Nginx-UI is vulnerable to unauthenticated remote takeover due to a missing authentication check on the `/mcp_message` endpoint, allowing attackers to invoke MCP tools without authentication, leading to arbitrary nginx configuration modification, traffic interception, service disruption, configuration exfiltration, and credential harvesting; the default empty IP whitelist allows access from any network attacker.

Nginx-UI nginx unauthenticated remote-takeover CVE-2026-33032
2r 5t 1i
critical advisory

phpMyFAQ Unauthenticated SQL Injection via User-Agent Header

Unauthenticated SQL injection vulnerability exists in phpMyFAQ <= 4.1.1 due to improper handling of the User-Agent header in BuiltinCaptcha, allowing attackers to inject malicious SQL payloads and potentially gain complete control of the datastore.

phpMyFAQ sql-injection unauthenticated web-application
2r 1t
medium advisory

Brizy WordPress Plugin Unauthenticated Stored XSS Vulnerability

The Brizy – Page Builder plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting (XSS) in versions up to and including 2.8.11, allowing unauthenticated attackers to inject arbitrary web scripts that execute when an administrator views the form Leads page due to missing nonce verification and improper handling of file upload fields.

Brizy – Page Builder plugin <= 2.8.11 wordpress xss unauthenticated
2r 1t 1c