Tag
CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability
4 rules 4 TTPs 2 IOCsA high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.
CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability
1 rule 2 TTPs 1 CVEA high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.
Remote SQL Injection in code-projects Online Job Portal (CVE-2026-15675)
2 rules 5 TTPs 1 CVEA SQL injection vulnerability (CVE-2026-15675) has been identified in code-projects Online Job Portal version 1.0, located in the `/Admin/EditUser.php` file and triggered by manipulating the `UserId` argument, allowing for remote SQL injection attacks with publicly available exploit code.
Metasoft MetaCRM Unrestricted File Upload Vulnerability (CVE-2026-8758)
2 rules 1 TTP 1 CVEA vulnerability in Metasoft MetaCRM up to version 6.4.0 Beta06 allows for unrestricted file upload due to manipulation of the 'File' argument in the /common/jsp/upload3.jsp file, potentially leading to arbitrary code execution.
Langflow Unrestricted File Upload Vulnerability (CVE-2026-6596)
2 rules 2 TTPsAn unrestricted file upload vulnerability in langflow-ai langflow versions up to 1.1.0 allows remote attackers to execute arbitrary code via the create_upload_file function in the API Endpoint.
Shandong Hoteam InforCenter PLM Unrestricted Upload Vulnerability (CVE-2026-5261)
2 rules 3 TTPs 1 CVECVE-2026-5261 is an unrestricted file upload vulnerability in Shandong Hoteam InforCenter PLM up to version 8.3.8, allowing remote attackers to execute arbitrary code by uploading malicious files via the uploadFileToIIS function.
PromtEngineer localGPT Unrestricted Upload Vulnerability (CVE-2026-5001)
2 rules 1 TTPA remote attacker can exploit an unrestricted file upload vulnerability (CVE-2026-5001) in PromtEngineer localGPT up to version 4d41c7d1713b16b216d8e062e51a5dd88b20b054 via the do_POST function in backend/server.py.