Skip to content
Threat Feed

Tag

Vulnerability

2647 briefs RSS
high advisory

Arbitrary Shortcode Execution in ProfilePress Plugin

The ProfilePress WordPress plugin is vulnerable to arbitrary shortcode execution in versions up to 4.17.2, allowing authenticated users with subscriber-level access to execute arbitrary shortcodes.

Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content wordpress vulnerability rce
2t 1c
critical advisory

Arbitrary Shortcode Execution in Forminator WordPress Plugin

The Forminator plugin for WordPress contains an arbitrary shortcode execution vulnerability (CVE-2026-92229) allowing unauthenticated attackers to execute arbitrary shortcodes by leveraging improper input validation.

Forminator wordpress vulnerability web-application
1t 1c
high advisory

Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway

A critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.

Secure Mail Gateway vulnerability remote-code-execution network-appliance
2t 1c
critical advisory

Unauthenticated SSRF and DoS in OpenShift Console

An unauthenticated vulnerability in the OpenShift console /api/devfile/ endpoints allows remote attackers to perform Server-Side Request Forgery (SSRF) and cause Denial of Service (DoS) via memory exhaustion.

OpenShift vulnerability cloud web-application
1t 1c
high advisory

Insecure Deserialization in Cotonti Comments Plugin

Cotonti version 1.0.0 contains an insecure deserialization vulnerability in the comments plugin allowing authenticated users to trigger object injection and potential remote code execution.

Cotonti web-application deserialization vulnerability
1t 1c
high advisory

Integer Overflow Vulnerability in IBM MQ Request Processing (CVE-2026-11725)

An integer overflow vulnerability in IBM MQ's processing of MQINQ requests allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability remote-code-execution ibm-mq
1c
critical advisory

Unauthenticated Remote Code Execution in IBM Guardium Data Protection

IBM Guardium Data Protection version 12.2 is vulnerable to a critical deserialization flaw allowing remote, unauthenticated attackers to execute arbitrary code (CVE-2026-81657).

Guardium Data Protection cve rce vulnerability enterprise-security authentication-bypass cve-2026-82967 web-application privilege-escalation +4
4t 1c
high advisory

SSRF Vulnerability in Obot via Remote MCP Server URLs

Obot versions 0.22.1 and earlier are vulnerable to server-side request forgery (SSRF) allowing authenticated privileged users to probe internal network resources and cloud instance metadata services.

Obot +1 ssrf cloud-security vulnerability oauth authentication-bypass token-theft mcp
5t
critical advisory

AnyIO TLS Certificate Spoofing via IDNA 2003 Encoding

AnyIO versions prior to 4.14.2 are vulnerable to TLS certificate spoofing when using IDNA 2003 encoded internationalized domain names, allowing an attacker who redirects traffic to present a domain-validated certificate that the client incorrectly trusts.

AnyIO +1 privilege-escalation vulnerability python linux
1t updated
high advisory

Microsoft Dataverse Privilege Escalation Vulnerability

A vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.

Dataverse privilege-escalation cloud-security vulnerability high-confidence-source
1t 1c
medium advisory

Remote Denial of Service Vulnerability in Moxa TN-4500B Series

A critical out-of-bounds write vulnerability (CVE-2026-15579) in Moxa TN-4500B Series switches allows remote, unauthenticated attackers to cause a denial-of-service condition.

TN-4500B Series vulnerability industrial-control-systems denial-of-service network-device
1t 1c
low advisory

CVE-2026-91149: Denial of Service via Resource Exhaustion in Cockpit

An unauthenticated remote attacker can exploit CVE-2026-91149 in Cockpit by exhausting system resources through numerous simultaneous connections to the cockpit-tls service.

cockpit denial-of-service vulnerability
1t 1c
high advisory

Stack-based Buffer Overflow in PLANET IGS-5225-8P2T4S Managed Switches

A stack-based buffer overflow vulnerability in the web server of PLANET IGS-5225-8P2T4S industrial managed switches allows authenticated remote attackers to achieve denial of service or remote code execution via CVE-2026-81944.

IGS-5225-8P2T4S vulnerability industrial-control-systems network-security cve-2026-81944
1t 1c
high advisory

IBM MQ Improper Validation Vulnerability (CVE-2026-11381)

IBM MQ contains a vulnerability in the validation of message distribution list structures that allows an authenticated attacker to trigger a denial of service or potentially execute arbitrary code.

MQ vulnerability cve middleware
1c
high threat

Stack Buffer Overflow in IBM MQ XA Transaction Processing

IBM MQ is vulnerable to a stack buffer overflow triggered by malicious XA transaction identifiers, allowing an authenticated attacker to cause a denial of service or achieve arbitrary code execution.

exploited MQ vulnerability remote-code-execution denial-of-service
1c
high advisory

Path Traversal Vulnerability in IBM Cloud Pak for Data

IBM Cloud Pak for Data 5.1.2 is vulnerable to a path traversal vulnerability via crafted URL requests that allow unauthenticated remote attackers to access arbitrary files on the system.

Cloud Pak for Data vulnerability webserver path-traversal
1t 1c
high advisory

Improper Translation of HTTP/1 CONNECT to HTTP/2 Headers

A vulnerability exists where HTTP/1 authority-form CONNECT requests are incorrectly translated into malformed HTTP/2 CONNECT requests, allowing for attacker control over the :authority header and potential request smuggling.

cve-2026-93567 request-smuggling proxy vulnerability
1c
critical threat

Heap Buffer Underflow in IBM MQ for HPE NonStop

IBM MQ for HPE NonStop versions 8.1.0 through 8.1.0.40 contain a heap buffer underflow vulnerability in multi-segment message processing that allows authenticated attackers to execute arbitrary code or trigger denial of service.

exploited IBM MQ for HPE NonStop vulnerability remote-code-execution ibm-mq critical
1t 1c
medium advisory

CSRF Vulnerability in IBM Common Licensing Agent and ART

IBM Common Licensing Agent and ART versions 9.0 through 9.0.0.2 contain a cross-site request forgery (CSRF) vulnerability that enables unauthenticated attackers to perform unauthorized actions on behalf of an authenticated user.

Common Licensing Agent +1 vulnerability web-security cve
1c
high advisory

Privilege Escalation in uutils coreutils via Incorrect File Ownership Handling

uutils coreutils versions before 0.10.0 are vulnerable to local privilege escalation due to an race condition in the install utility that preserves setuid/setgid bits when ownership changes fail.

coreutils vulnerability privilege-escalation linux
1t 1c
high advisory

DNSSEC Validation Bypass in hickory-resolver

A vulnerability in hickory-resolver versions prior to 0.26.2 causes the library to ignore bogus DNSSEC proof states, allowing attackers to inject forged DNS records as validated data.

hickory-resolver dnssec vulnerability network-security
1t 1c
high advisory

SSRF Vulnerability in ArcadeDB via IPv6 Transition Addressing

Authenticated attackers can exploit a validation flaw in ArcadeDB's SSRF guard to reach internal services or cloud metadata endpoints by using specifically crafted IPv6 transition addresses.

ArcadeDB ssrf vulnerability database access-control
2t 1c
medium advisory

Local Arbitrary Code Execution and Denial of Service Vulnerability in Red Hat CloudForms

Red Hat CloudForms contains a local vulnerability that allows an attacker to execute arbitrary code with user-level privileges or trigger a denial-of-service condition.

CloudForms vulnerability local-access red-hat
1t
medium advisory

Denial of Service Vulnerability in libxml2

A vulnerability in the libxml2 library allows a remote, unauthenticated attacker to trigger a denial of service condition through the submission of malformed XML data.

libxml2 denial-of-service vulnerability
1t 1c
high advisory

Denial of Service Vulnerability in Netty StompSubframeDecoder

A memory leak vulnerability in the Netty StompSubframeDecoder component (CVE-2026-93494) allows remote attackers to cause a Denial of Service by sending malformed STOMP frames.

Netty +1 denial-of-service vulnerability cve-2026-93565 rtsp input-validation
1t 1c
high advisory

Pi-hole SSRF to RCE Vulnerability via CVE-2024-34361

Pi-hole versions 5.18.2 and earlier are vulnerable to an authenticated SSRF attack via improper URL validation, which can be chained with the Gopherus protocol to achieve remote code execution on the host system.

Pi-hole vulnerability rce ssrf
1r 2t 1c
high advisory

Authorization Bypass in Master Addons for Elementor

An authorization bypass vulnerability in the Master Addons for Elementor WordPress plugin allows authenticated contributors to modify or delete arbitrary posts.

Master Addons for Elementor wordpress vulnerability authorization-bypass
1t 1c
high advisory

Authorization Bypass in TECHIN2B Application

An authorization bypass vulnerability in TECHIN2B Application allows unauthenticated or low-privileged users to perform privilege abuse via user-controlled keys.

TECHIN2B Application vulnerability privilege-escalation
1t 1c
critical advisory

Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic

Synology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.

DiskStation Manager +7 vulnerability critical remote-code-execution file-read-write dsm file-access synology cve +4
1t 6c
high advisory

Chromium V8 Engine Out-of-Bounds Memory Access Vulnerability

CVE-2026-0899 is an out-of-bounds memory access vulnerability in the Chromium V8 JavaScript engine that may result in memory corruption, process crashes, or arbitrary code execution.

Chromium vulnerability browser-security
1c
high advisory

CVE-2026-17086 PHP Object Injection in ShortPixel Image Optimizer

Authenticated attackers can exploit insecure deserialization in ShortPixel Image Optimizer versions 6.5.5 and below to execute arbitrary code if a POP chain is available via other plugins or themes.

ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF wordpress vulnerability php-injection deserialization
1t 1c
high advisory

Command Injection in marcopiovanello yt-dlp-web-ui

An unauthenticated remote command injection vulnerability in yt-dlp-web-ui version 4 and earlier allows remote attackers to execute arbitrary system commands via the params argument.

yt-dlp-web-ui remote-code-execution command-injection vulnerability
2t 1c
high advisory

Jupyter Server Authentication Token Leak in Error Logs

Jupyter Server versions prior to 2.21.0 inadvertently expose authentication tokens in plain-text 500 error logs due to improper logging of the Referer header.

jupyter_server credential-exposure logging vulnerability
1t 1c
low advisory

Unbounded DEFLATE Decompression Vulnerability in HAPI FHIR

The HAPI FHIR SHCParser component contains an unbounded DEFLATE decompression flaw (CVE-2026-81875) allowing attackers to trigger memory exhaustion and denial-of-service.

HAPI FHIR +1 denial-of-service vulnerability cve-2026-81875
1t 1c
low advisory

Denial of Service via Malformed HTTP Chunked Encoding in react/http

A malformed HTTP chunked body triggers an infinite loop in the react/http ChunkedDecoder, causing 100% CPU usage and service disruption in both server and client implementations.

react/http denial-of-service php vulnerability
1t 1c
high advisory

CoreDNS DoH/DoQ/gRPC RFC 2136 UPDATE Bypass

CoreDNS versions up to 1.14.6 fail to validate DNS UPDATE opcodes over DoH, DoH3, DoQ, and gRPC, allowing attackers to relay unauthorized updates to upstream servers.

CoreDNS dns vulnerability rfc-2136 denial-of-service cve-2026-82399 networking
1r 3t 1c
high advisory

Grav Privilege Escalation via Group Blueprint ACL Bypass

A missing 'security@' guard in Grav's group blueprint allows an 'admin.users' operator to escalate privileges to 'admin.super' by modifying group access configurations.

Grav +2 privilege-escalation cms vulnerability web-application-vulnerability path-traversal cve-2026-74907 twig security-misconfiguration
1r 3t 1c
critical advisory

SQL Injection Vulnerability in CakePHP FunctionsBuilder

Multiple methods in the CakePHP FunctionsBuilder component are vulnerable to SQL injection when user-supplied input is passed to specific functional parameters.

cakephp/database +1 sql-injection vulnerability web-application
1t 1c
low advisory

Denial of Service Vulnerability in redis-parser via RESP Recursion

The redis-parser library up to version 3.0.0 is vulnerable to a denial of service attack where crafted RESP byte streams trigger unbounded recursion, exhausting the V8 call stack and crashing the host Node.js process.

redis-parser denial-of-service vulnerability supply-chain
1c
high advisory

Keycloak Stateless Mode Replay Vulnerability (CVE-2026-90997)

A row-count mismatch in Keycloak when using MySQL or MariaDB in stateless mode allows attackers to bypass replay protection for single-use security artifacts like JWT client assertions, DPoP proofs, or TOTP codes.

Keycloak identity-management authentication-bypass vulnerability
1t 1c
high advisory

Out-of-Bounds Read Vulnerability in Redis Cluster Bus

A vulnerability in the Redis cluster bus packet parser allows remote attackers to trigger an out-of-bounds read via crafted PING, PONG, or MEET packets, resulting in potential information disclosure or denial of service.

Redis vulnerability memory-safety denial-of-service
1c
medium advisory

RabbitMQ Java Client Out-of-Memory Vulnerability via Frame Negotiation

A logic error in the RabbitMQ Java client's frame size negotiation allows a malicious server to trigger a massive memory allocation and service crash by exploiting an integer comparison flaw in frame handling.

amqp-client vulnerability denial-of-service java rabbitmq
1t 1c
low advisory

ExifReader Denial of Service via Crafted HEIC/AVIF Files

ExifReader version 4.41.0 is susceptible to a heap exhaustion denial-of-service vulnerability due to an unbounded object allocation loop when parsing malicious ISO-BMFF iloc box structures.

exifreader denial-of-service vulnerability memory-exhaustion
1t 1c
medium advisory

Resource Exhaustion in RabbitMQ amqp091-go via Unsafe Integer Casting

The RabbitMQ amqp091-go library contains a vulnerability in its Qos configuration method where signed integer inputs are implicitly cast to unsigned integers, allowing attackers to trigger message flooding and OOM crashes via integer wrap-around.

amqp091-go denial-of-service vulnerability cve
1t 1c
high advisory

Unauthenticated SSRF in Kestra OSS via Pebble http() Function

An unauthenticated SSRF vulnerability in the Kestra OSS Pebble template engine allows remote attackers to perform arbitrary requests to internal network services and cloud metadata endpoints.

Kestra OSS ssrf vulnerability kestra
1r 3t 1c 1i
medium threat

AsyncHttpClient Unbounded Decompression Denial of Service

AsyncHttpClient is vulnerable to a decompression bomb denial of service attack due to unbounded automatic HTTP/1.1 response decompression, potentially leading to heap exhaustion.

exploited async-http-client +1 denial-of-service vulnerability java
1c
medium advisory

Fulgur HTML-to-PDF Denial of Service via Resource Exhaustion

Fulgur versions prior to 0.26.0 are vulnerable to a denial-of-service attack where an attacker-supplied HTML payload causes CPU and memory exhaustion by forcing the rendering of thousands of blank PDF pages.

fulgur +1 denial-of-service vulnerability rust
1t
critical advisory

Protocol Desynchronization and Frame Injection in RabbitMQ amqp091-go

A critical integer overflow vulnerability in the amqp091-go parser causes protocol desynchronization, allowing remote attackers to inject arbitrary AMQP frames into the network stream.

amqp091-go data-integrity serialization-vulnerability protocol-corruption denial-of-service memory-exhaustion amqp vulnerability credential-exposure +2
5t 1c
critical threat

Critical Vulnerabilities in Cisco Identity Services Engine and ISE-PIC

Multiple vulnerabilities, including one actively exploited in the wild (CVE-2026-76460), allow unauthenticated attackers to bypass authentication and gain administrative control over Cisco ISE and ISE-PIC deployments.

exploited Identity Services Engine +1 vulnerability cisco identity-management authentication-bypass
3t 2c
high advisory

Unauthenticated Remote Code Execution in SolarWinds Access Rights Manager

CVE-2026-28326 is a critical remote code execution vulnerability in SolarWinds Access Rights Manager resulting from the use of a hardcoded static key, allowing unauthenticated attackers to execute arbitrary code.

Access Rights Manager vulnerability rce windows
1t 1c
high advisory

CVE-2026-89036 Argument Injection in Appwrite

Authenticated users can achieve remote code execution in Appwrite versions before 2.0.0 by exploiting an argument injection vulnerability via the providerRootDirectory parameter in GNU tar commands.

Appwrite vulnerability rce argument-injection
2t 1c
medium advisory

Unauthenticated Routing Table Poisoning in SGLang

SGLang versions up to 0.5.19 in disaggregation mode expose an unauthenticated PUT /route endpoint allowing remote attackers to poison KV transfer tables and redirect sensitive data.

SGLang routing-poisoning cve-2026-92972 denial-of-service vulnerability
1r 2t 1c updated
high advisory

Multiple Vulnerabilities in Schneider Electric NetBotz 5 750/755

Schneider Electric NetBotz 5 750 and 755 devices are affected by OS command injection and Hibernate SQL injection vulnerabilities, enabling unauthorized code execution and database manipulation.

NetBotz 5 750 +1 vulnerability ics ot cve-2026-13336 cve-2026-13337
2t 2c
critical advisory

Multiple Critical Vulnerabilities in Hitachi Energy FACTS Control Platform

Hitachi Energy FACTS Control Platform (FCP) units equipped with the GWS component are affected by multiple critical vulnerabilities, including path traversal and authentication bypass, potentially leading to unauthorized system access or modification.

FACTS Control Platform ics energy ot vulnerability
2t 5c
medium advisory

Mitsubishi Electric CC-Link IE TSN Communication Protocol Vulnerability

A vulnerability in the Mitsubishi Electric CC-Link IE TSN Communication Protocol (CVE-2026-13584) allows network-adjacent attackers to disrupt control functions or tamper with data via specially crafted packets.

MELSEC MX Controller +27 ics ot vulnerability cve-2026-13584
1t 1c
high advisory

Remote Code Execution in SiYuan via Malicious Bookmark Labels

SiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.

SiYuan +2 vulnerability rce electron xss web-application-vulnerability sql-injection data-exfiltration web-vulnerability +1
1r 5t 1c updated
high advisory

Path Traversal Vulnerability in HUBzero CMS

Authenticated users can exploit a path traversal vulnerability in HUBzero CMS project file upload handlers to achieve arbitrary file writes, potentially leading to remote code execution.

HUBzero CMS vulnerability cve-2026-92970 path-traversal web-application session-fixation authentication
2t 1c
critical advisory

Sandbox Escape in vm2 via NodeVM Configuration Misvalidation

An improper validation of the 'require' configuration in the vm2 Node.js sandbox allows attackers to bypass nesting restrictions and achieve arbitrary code execution by spawning an inner NodeVM with elevated privileges.

vm2 +10 sandbox-escape nodejs code-execution vulnerability rce javascript cve privilege-escalation
6t 1c updated
critical threat

Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard

Cisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.

exploited Secure Firewall Management Center +4 vulnerability cisco network-security patch-management
2t 3c
high advisory

Multiple Vulnerabilities in Znuny

Znuny is affected by multiple security vulnerabilities that allow a remote, unauthenticated attacker to conduct SQL injection and perform unauthorized privilege escalation.

Znuny vulnerability web-application sql-injection privilege-escalation
1t
low advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Components

Multiple vulnerabilities in corosync, libevent, and libsoup within Red Hat Enterprise Linux could allow attackers to execute arbitrary code, bypass security controls, disclose data, or cause denial-of-service.

Enterprise Linux +1 vulnerability rhel linux
1t 1c updated
medium advisory

Information Disclosure Vulnerability in Graylog

An authenticated remote attacker can exploit a vulnerability in Graylog to gain unauthorized access to sensitive information within the application.

Graylog vulnerability information-disclosure log-management
1t
medium advisory

Multiple Denial of Service Vulnerabilities in Dovecot

Dovecot is affected by multiple vulnerabilities that can be exploited by a remote attacker to cause a denial-of-service condition on the affected service.

Dovecot denial-of-service vulnerability
1t
low advisory

Information Disclosure and Spoofing Vulnerability in Eclipse Jetty

A vulnerability in Eclipse Jetty, identified as CVE-2024-8184, allows a remote unauthenticated attacker to manipulate displayed information and gain unauthorized access to sensitive data.

Jetty vulnerability webserver cve-2024-8184
1c
low advisory

Remote Code Execution Vulnerability in Nextcloud

A critical vulnerability in Nextcloud Hub, tracked as CVE-2024-28112, allows remote attackers to execute arbitrary code on the underlying application server.

Nextcloud Hub web-application vulnerability rce
2t 1c
medium advisory

Varnish HTTP Cache Denial of Service Vulnerability

A vulnerability in Varnish HTTP Cache allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially causing service instability or resource exhaustion.

Varnish HTTP Cache vulnerability dos webserver
1c
high advisory

Remote Code Execution Vulnerability in Check Point Management Products

A critical remote code execution vulnerability (CVE-2026-91843) affects multiple Check Point security management servers, allowing unauthenticated attackers to execute arbitrary code.

Log Server +5 vulnerability rce network-security
1c updated
high advisory

Memory Corruption in Linux Kernel I2C Subsystem (CVE-2026-25278)

A race condition vulnerability in the Linux kernel I2C subsystem allows local attackers to trigger memory corruption, potentially leading to system crashes or privilege escalation.

Linux Kernel linux kernel vulnerability privilege-escalation
1t 1c
high advisory

Privilege Escalation Vulnerability in Acronis Backup for cPanel and Plesk

Acronis Backup for cPanel and WHM and the extension for Plesk contain an incorrect default permissions vulnerability (CVE-2026-87886) that enables privilege escalation.

Backup +1 vulnerability privilege-escalation server-security
1t
high advisory

Supply Chain Vulnerability in quay-builder-qemu via Mutable GitHub Action

A supply chain vulnerability in quay-builder-qemu allows for remote code execution and credential theft due to the use of a mutable GitHub Action dependency.

quay-builder-qemu supply-chain ci-cd vulnerability
2t 1c
high advisory

Manticore Search Multi-Statement Authorization Bypass

Manticore Search versions 27.0.0 through 28.4.3 contain an authorization vulnerability that allows authenticated read-only users to execute unauthorized SQL statements by appending malicious queries to multi-statement requests.

Manticore Search vulnerability sql-injection manticore
1t 1c
high advisory

Authorization Bypass in cc-connect via Interactive Card Callbacks

The cc-connect application through version 1.5.0 contains an authorization bypass vulnerability in the onCardAction handler, allowing unprivileged users to execute unauthorized agent commands.

cc-connect vulnerability authorization-bypass cloud
2t 1c
high advisory

Path Traversal in Uber Kraken

Uber Kraken versions 0.1.29 and earlier contain a path traversal vulnerability in the /tags/{tag} endpoint, allowing unauthenticated attackers to read arbitrary files from the filesystem.

Kraken path-traversal vulnerability webserver
1r 1t 1c
high advisory

Authorization Bypass in Chroma via Tenant Isolation Failure

Chroma versions 1.5.9 and earlier are vulnerable to an authorization bypass allowing authenticated users to access, modify, and delete cross-tenant data by manipulating collection identifiers.

Chroma vulnerability authorization-bypass
1t 1c
high advisory

Prototype Pollution in Builder.io Gen2 SDKs

Builder.io Gen2 SDKs are vulnerable to prototype pollution in the deep-set helper function, allowing attackers to manipulate Object.prototype via unvalidated content block bindings.

Gen2 SDKs +1 vulnerability web-application javascript
1c
high advisory

Path Traversal in BC Security Empire Upload Endpoint

BC Security Empire versions prior to 6.7.1 are vulnerable to path traversal via the multipart filename parameter, allowing an authenticated operator to achieve arbitrary file write and potential code execution.

Empire vulnerability c2 path-traversal
1t
high advisory

Authorization Bypass in SigNoz Trace-Funnel Analytics

SigNoz versions 0.88.0 through 0.141.0 contain an authorization bypass vulnerability allowing unauthenticated remote attackers to query sensitive trace analytics via the trace-funnel endpoint.

SigNoz +2 authorization-bypass api-security observability sql-injection vulnerability web-application webserver injection
2r 1t 1c updated
high advisory

SSRF Vulnerability in Quickwit SQS File Source

Quickwit versions through 0.9.0 contain a Server-Side Request Forgery vulnerability allowing unauthenticated attackers to perform internal network scanning and service fingerprinting via the create-source API.

Quickwit ssrf vulnerability web-application
1t 1c
high advisory

IDOR Vulnerability in SIMAC MyPHR

SIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.

MyPHR idor web-vulnerability vulnerability cve-2026-47094
2t 1c
critical advisory

Multi-tenant Isolation Bypass in djust via WebSocket/SSE

A vulnerability in djust caused multi-tenant isolation to fail open on WebSocket and SSE paths, allowing unauthorized cross-tenant data disclosure due to improper tenant context propagation.

djust +1 web-application mass-assignment cve-2026-61598 remote-code-execution information-disclosure cve-2026-61590 idor broken-access-control +5
6t 1c updated
medium advisory

Cross-Site Request Forgery Vulnerability in djust SSE Transport

The djust library before version 1.0.7 is vulnerable to CSRF via its SSE transport, allowing cross-origin requests to execute state-changing event handlers as an authenticated victim.

djust web-application-security csrf sse vulnerability
1r 1c
low advisory

Authenticated Blind SQL Injection in ScadaLTS

ScadaLTS 2.8.1-rc is vulnerable to an authenticated blind SQL injection via the sortBy parameter in the /api/events/search endpoint, allowing low-privileged users to exfiltrate database contents.

ScadaLTS sqli vulnerability web-application
1r 2t 1c
high advisory

Improper Authentication Vulnerability in ChangeWeDer CRM

An unauthenticated remote code execution vulnerability in the LoginUserUtil.releaseUserIdFromCookie function of ChangeWeDer CRM allows attackers to bypass authentication through cookie manipulation.

crm web-application authentication-bypass vulnerability
1t 1c
high threat

Active Exploitation of Google Pixel Improper Authorization Vulnerability

CISA has added CVE-2026-58704, an improper authorization vulnerability in Google Pixel devices, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation.

exploited Pixel vulnerability cisa-kev mobile-security
1c
low advisory

Denial of Service Vulnerability in Keycloak Theme Localization

An unauthenticated denial-of-service vulnerability in Keycloak (CVE-2026-79651) allows attackers to exhaust server memory by injecting arbitrary locale tags into an unbounded cache.

Keycloak denial-of-service vulnerability identity-management
1r 1t 1c
low advisory

BIND 9 Denial of Service via Malformed DNS64 Response

A vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.

BIND +5 denial-of-service network-infrastructure vulnerability dns infrastructure
1t 1c
low advisory

CVE-2026-18212 Keycloak Denial of Service via SAML Redirect Binding

An unauthenticated attacker can trigger a denial of service in Keycloak by sending repeated malformed SAML requests that cause native memory exhaustion due to improper zlib memory management.

Keycloak denial-of-service vulnerability
1t 1c
high advisory

Authorization Bypass in zlt2000 microservices-platform

A default configuration vulnerability in zlt2000 microservices-platform through 6.0.0 disables URL permission checks, allowing authenticated users to perform unauthorized administrative actions.

microservices-platform vulnerability privilege-escalation web-application
1t 1c
medium advisory

Octopus Deploy File Path Manipulation and Potential RCE

A vulnerability in Octopus Deploy allows remote attackers to perform unauthorized file manipulation and potentially execute arbitrary code due to improper path validation.

Octopus Deploy vulnerability rce ci-cd
1t 1c
high advisory

Remote Code Execution Vulnerability in Netgate pfSense

An authenticated remote attacker can exploit a vulnerability in Netgate pfSense to bypass security controls and execute arbitrary PHP code and shell commands.

pfSense vulnerability rce network-security
1t
high advisory

Multiple Vulnerabilities in Oracle GraalVM

Oracle GraalVM contains multiple vulnerabilities including CVE-2024-21226, CVE-2024-21227, and CVE-2024-21228, which allow remote unauthenticated attackers to compromise system confidentiality, integrity, and availability.

GraalVM vulnerability java oracle
low advisory

Multiple Vulnerabilities in Oracle Hyperion

Oracle Hyperion is affected by multiple security vulnerabilities (CVE-2024-21054, CVE-2024-21055) that allow remote attackers to compromise system confidentiality, integrity, and availability.

Hyperion vulnerability enterprise-application
2c
high advisory

Multiple Vulnerabilities in Aruba EdgeConnect

Multiple vulnerabilities in Aruba EdgeConnect allow for privilege escalation, denial of service, information disclosure, file manipulation, cross-site scripting, security bypass, and arbitrary code execution.

Aruba EdgeConnect vulnerability network-infrastructure remote-code-execution
5c
high advisory

Multiple Vulnerabilities in Microsoft Edge

Multiple vulnerabilities in Microsoft Edge allow remote attackers to achieve arbitrary code execution and escalate privileges on the host system.

Edge browser vulnerability remote-code-execution
2t 1c updated
high advisory

Multiple Vulnerabilities in Apache Airflow Providers

Multiple vulnerabilities in Apache Airflow and its providers (FAB, Keycloak, Kafka, Akeyless) could allow unauthenticated or authenticated attackers to perform remote code execution, privilege escalation, or unauthorized data access.

Airflow vulnerability apache-airflow product-news
2t
medium advisory

Vulnerability in F5 NGINX

A vulnerability in F5 NGINX, tracked as CVE-2026-90439, allows remote attackers to trigger a denial of service and potentially compromise data integrity.

NGINX Open Source +1 vulnerability webserver dos
1c
high advisory

Multiple Vulnerabilities in Docker Sandboxes

Multiple vulnerabilities, including CVE-2026-77179 and CVE-2026-79994, in Docker Sandboxes versions prior to 0.42.0 could allow remote code execution, data confidentiality breaches, and integrity loss.

Docker Sandboxes vulnerability remote-code-execution docker
2c
high advisory

Command Injection in /api/datastorage/data Endpoint (CVE-2026-27563)

An authenticated high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint to execute arbitrary code with root privileges.

/api/datastorage/data cve-2026-27563 command-injection webserver vulnerability
1r 1t 1c
medium advisory

Improper Authorization in Device Upload Endpoint (CVE-2026-27552)

An improper authorization vulnerability in the /index.php/attached_devices_tab/do_upload endpoint allows low-privileged remote attackers to upload arbitrary files, potentially leading to unauthorized device behavior or denial-of-service.

attached_devices_tab vulnerability web-application cve-2026-27552
1r 1t 1c
high advisory

Command Injection in Field_Shadow_Password

CVE-2026-27550 is a command injection vulnerability allowing low-privileged attackers with operator credentials to execute arbitrary commands with root privileges.

Field_Shadow_Password vulnerability command-injection cve-2026-27550
1t 1c
high advisory

Arbitrary File Overwrite in Contest Gallery WordPress Plugin

The Contest Gallery WordPress plugin is vulnerable to unauthenticated arbitrary file overwrite via the 'baseUrlForFacebook' parameter, allowing authenticated attackers to achieve remote code execution.

Contest Gallery wordpress vulnerability rce
2t 1c
critical advisory

Authorization Bypass in TrueBooker WordPress Plugin

The TrueBooker Appointment Booking and Scheduler System plugin for WordPress contains an authorization bypass vulnerability allowing unauthenticated attackers to modify arbitrary user email addresses and facilitate account takeover.

TrueBooker – Appointment Booking and Scheduler System wordpress vulnerability authorization-bypass
2t 1c
critical advisory

HTTP Request Smuggling Vulnerability in http4s Ember

The http4s Ember HTTP/1.1 parser fails to reject messages containing both 'Transfer-Encoding' and 'Content-Length' headers, enabling CL.TE request smuggling attacks.

http4s-ember-core +5 request-smuggling cve-2026-69204 http-vulnerability denial-of-service vulnerability http2 http4s cve-2026-69202
3t 1c
critical advisory

SSRF Vulnerability in mcp-gitlab Enables GitLab Credential Theft

The mcp-gitlab server is vulnerable to Server-Side Request Forgery (SSRF) when ENABLE_DYNAMIC_API_URL is enabled, allowing attackers to force the server to forward victim GitLab tokens to an arbitrary host.

mcp-gitlab +2 dns-rebinding mcp gitlab cve-2026-61568 vulnerability rce exfiltration
1r 6t 1c updated
high advisory

XML External Entity Injection in IBM MQ Classes for Java

An XML external entity injection vulnerability (CVE-2026-12666) in IBM MQ Classes for Java allows authenticated attackers to perform denial-of-service attacks or disclose sensitive host information by manipulating MQRFH2 headers.

IBM MQ +1 vulnerability java middleware cve-2026-12666 rce dos
1t 1c updated
high advisory

Authorization Bypass in Flowise openai-realtime Endpoints

Flowise versions prior to 3.1.4 contain an authorization flaw in the openai-realtime endpoint, enabling authenticated users to access and execute tools in unauthorized workspaces via cross-workspace ID manipulation.

Flowise vulnerability auth-bypass api-security
1c
high advisory

Flowise Cross-Tenant Authorization Vulnerability

Flowise versions before 3.1.4 contain authorization gaps in Enterprise endpoints that allow authenticated users to perform cross-tenant operations including unauthorized workspace deletion and SSO credential access.

Flowise Enterprise +1 path-traversal arbitrary-file-write rce xss vulnerability nosql-injection web-application ssrf +3
4t 1c
high advisory

SQL Injection Vulnerability in WuzhiCMS

WuzhiCMS versions up to 4.1.0 contain a SQL injection vulnerability in the article::getDataOfJson function, allowing remote attackers to execute arbitrary SQL commands via the title or master_table parameters.

WuzhiCMS sql-injection vulnerability web-application ssrf web-vulnerability
2r 1t 1c updated
high advisory

HTTP Request Smuggling Vulnerability in Tornado

Tornado versions prior to 6.4.1 are vulnerable to HTTP request smuggling via the improper processing of duplicate 'Transfer-Encoding: chunked' headers when deployed behind a proxy.

Tornado +1 web-application http-request-smuggling vulnerability request-smuggling
3t 1c updated
high advisory

FreeRDP Protocol Negotiation Bypass via CVE-2026-91949

An unauthenticated protocol negotiation vulnerability in FreeRDP servers allows attackers to bypass RDSTLS transport security policies.

FreeRDP memory-corruption rdp vulnerability denial-of-service cve-2026-91955
2t 1c
medium advisory

Insufficiently Protected Credentials Vulnerability in Schneider Electric SCADAPack x70

Schneider Electric SCADAPack x70 series RTUs contain a vulnerability (CVE-2026-81861) in the legacy 'Secure Lock' functionality that could lead to unauthorized exposure of authentication information.

SCADAPack 47x +6 vulnerability industrial-control-systems critical-infrastructure
1t 1c
high threat

Authentication and Authorization Vulnerabilities in mySCADA myPRO Manager

Multiple vulnerabilities in mySCADA myPRO Manager versions 2.1 and earlier allow unauthenticated attackers to execute arbitrary management commands or send unauthorized SMS messages.

exploited mySCADA myPRO Manager ics scada vulnerability cve
2t
high advisory

Unauthenticated Information Disclosure in lamp-cloud via CVE-2026-91996

An authentication bypass vulnerability in lamp-cloud versions 5.10.0 and earlier allows unauthenticated attackers to exfiltrate sensitive JVM system properties via insecurely whitelisted API endpoints.

lamp-cloud vulnerability authentication-bypass information-disclosure
1r 1t 1c
high advisory

Remote Code Execution Vulnerability in WebKitGTK

A memory corruption vulnerability in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service condition by processing maliciously crafted web content.

WebKitGTK vulnerability rce linux
1t 1c
high advisory

Arbitrary Code Execution Vulnerability in Octopus Deploy Server

A vulnerability in Octopus Deploy Server allows a remote attacker to execute arbitrary code, potentially leading to full system compromise of the application instance.

Octopus Deploy Server vulnerability rce cicd
2t 1c
high advisory

Multiple Vulnerabilities in Langflow

Langflow contains multiple vulnerabilities that enable remote attackers to achieve remote code execution with administrative privileges and bypass existing security controls.

Langflow vulnerability rce
2t
medium advisory

Multiple Vulnerabilities in GNU Binutils

The GNU binutils package contains multiple vulnerabilities that allow a local attacker to cause a Denial of Service condition or disclose sensitive information by processing malformed object files.

binutils vulnerability local-exploitation
1t
high advisory

Multiple Vulnerabilities in IBM MQ

IBM MQ is affected by multiple vulnerabilities, including CVE-2024-49033, CVE-2024-49034, and CVE-2024-49035, which could allow a remote attacker to execute arbitrary code, cause a denial of service, disclose sensitive information, or manipulate data.

MQ vulnerability messaging-middleware remote-code-execution
2c
high advisory

Authorization Bypass in pgweb API Connect Endpoint

An authorization bypass vulnerability in pgweb versions up to 0.17.0 allows unauthenticated attackers to supply arbitrary connection strings via the /api/connect endpoint.

pgweb vulnerability web-application authentication-bypass
1r 1t 1c
high advisory

Privilege Escalation in leapp-upgrade-el9toel10

A privilege escalation vulnerability (CVE-2026-75092) in the leapp-upgrade-el9toel10 package allows an attacker with mysql OS identity access to execute arbitrary code as root during RHEL upgrade workflows.

leapp-upgrade-el9toel10 vulnerability privilege-escalation linux rhel
1t 1c
high advisory

Use-After-Free Vulnerability in GPAC Compositor

A use-after-free vulnerability in the GPAC compositor component (CVE-2026-91087) allows remote attackers to trigger memory corruption via malicious media files.

GPAC +2 vulnerability memory-corruption remote-code-execution cve
1c updated
critical advisory

Remote Buffer Overflow Vulnerability in D-Link DI-8300

A critical stack-based buffer overflow vulnerability in the D-Link DI-8300 CGI service enables remote code execution via a manipulated URL parameter.

DI-8300 vulnerability cve network-infrastructure
1t 1c
critical threat

Active Exploitation of SQL Injection in Cisco Secure Email Gateway

Cisco has confirmed active exploitation of a SQL injection vulnerability (CVE-2026-76461) affecting multiple versions of Cisco Secure Email Gateway and Secure Email and Web Manager products.

exploited Cisco AsyncOS for Cisco Secure Email Gateway +2 vulnerability cve network active-exploitation
1c
high advisory

Path Traversal in Weights & Biases wandb

The Weights & Biases wandb library before version 0.29.0 is vulnerable to path traversal via the File.download function, allowing an attacker-controlled backend to write files to arbitrary locations.

wandb vulnerability path-traversal python
2t 1c
high advisory

SQL Injection in SourceCodester College Notes Gallery Management System

SourceCodester College Notes Gallery Management System version 1.0 contains a SQL injection vulnerability in the login.php file, allowing unauthenticated remote attackers to execute arbitrary database queries.

College Notes Gallery Management System sqli vulnerability web-application
1r 2t 1c
high advisory

Authentication Bypass in PHPGurukul Blood Donor Management System

PHPGurukul Blood Donor Management System 1.0 is vulnerable to an authentication bypass in the admin dashboard, allowing remote attackers to gain unauthorized administrative access.

Blood Donor Management System web-application authentication-bypass vulnerability
2t 1c
high advisory

CVE-2026-91145 Expression Injection in Activiti

Activiti through 7.1.0.M6 contains an expression injection vulnerability in process variables that allows unauthenticated method invocation on application beans during mail task execution.

Activiti expression-injection vulnerability
1t 1c
high advisory

Information Disclosure Vulnerability in IBM Sterling File Gateway

IBM Sterling File Gateway contains an improper access control vulnerability (CVE-2026-19290) that allows remote attackers to obtain sensitive information.

Sterling File Gateway vulnerability information-disclosure ibm
1t 1c
high advisory

SQL Injection in Magistrala HTTP API

Magistrala versions prior to 1.0.0 contain a SQL injection vulnerability in the timescale-reader and postgres-reader services allowing authenticated users to achieve remote code execution via arbitrary SQL execution.

Magistrala sql-injection vulnerability rce
2t 1c
high advisory

Command Injection Vulnerability in IBM App Connect Enterprise

IBM App Connect Enterprise versions 13.0.x and 12.0.x contain a command injection vulnerability (CVE-2026-17133) that allows local attackers to execute arbitrary OS commands.

App Connect Enterprise vulnerability command-injection cve
1t 1c
critical threat

Active Exploitation of Cisco Secure Email Gateway SQL Injection

CISA has added CVE-2026-76461 to the Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation of a SQL injection vulnerability in Cisco Secure Email Gateway.

exploited Secure Email Gateway vulnerability cve sql-injection cisa-kev
1c
high advisory

Remote Argument Injection in HKUDS nanobot

HKUDS nanobot versions up to 0.2.1 contain an argument injection vulnerability in the ExecTool component that allows remote attackers to execute arbitrary commands.

nanobot +1 vulnerability rce command-injection ssrf cloud-security
3t 1c updated
high threat

Path Traversal Vulnerability in PyMuPDF Font Processing

PyMuPDF versions through 1.28.2 contain a path traversal vulnerability in the extract_objects() function, allowing attackers to perform arbitrary file writes via crafted document font metadata.

exploited PyMuPDF vulnerability path-traversal software-library
1t
high advisory

SSRF Vulnerability in Huly Platform Print Service

Huly Platform versions up to 0.7.426 contain a server-side request forgery vulnerability that allows authenticated users to access internal metadata services via the print service.

Huly Platform web-application ssrf vulnerability
1t
medium advisory

Multiple Critical Vulnerabilities in MongoDB Drivers and Core Server

Multiple vulnerabilities across MongoDB drivers and the Core Server identified on September 10-11, 2026, pose risks of remote denial-of-service, unauthorized data access, and integrity compromise.

C Driver +10 vulnerability database patch-management
3c
medium advisory

Multiple Vulnerabilities in Squid Proxy

Multiple security vulnerabilities identified in Squid versions prior to 7.7 allow remote attackers to cause denial-of-service, manipulate data, and bypass security policy restrictions.

Squid vulnerability proxy cve-2026-61642
high advisory

Heap-Based Buffer Overflow in GIMP PSP File Loader

A heap-based buffer overflow in GIMP's PSP file loader, tracked as CVE-2026-90949, allows attackers to trigger crashes or arbitrary code execution via crafted image files.

GIMP +1 vulnerability memory-corruption
1t 1c updated
high advisory

Unauthenticated Remote Access and Plugin Injection in LangBot langbot_plugin

The LangBot langbot_plugin (<= 0.4.17) exposes an unauthenticated debug WebSocket server on port 5401, allowing remote attackers to intercept chat traffic, inject malicious LLM tools, and trigger persistent denial-of-service via plugin registration conflicts.

langbot_plugin vulnerability rce web-application cve-2026-90938
1t 1c
high advisory

Improper Authorization in File Browser Direct-Upload Endpoint

File Browser versions 2.5.0 through 2.63.23 are vulnerable to an improper authorization flaw allowing authenticated users to trigger recursive directory deletion via the direct-upload endpoint.

File Browser cve-2026-90929 improper-authorization file-browser impact vulnerability
1r 1t 1c
medium advisory

Security Bypass Vulnerability in TYPO3 Femanager Extension

A vulnerability in the TYPO3 Femanager extension (CVE-2024-42023) allows remote, unauthenticated attackers to bypass security mechanisms, potentially leading to unauthorized access within the CMS environment.

Femanager web-application cms vulnerability
1t 1c
high advisory

Multiple Vulnerabilities in TYPO3 Extensions

Multiple security flaws in various TYPO3 extensions enable remote authenticated or anonymous attackers to bypass security controls, perform information disclosure, and execute arbitrary code.

TYPO3 Extensions web-application vulnerability
2t
medium advisory

Remote Code Execution Vulnerability in Puppet Enterprise

A vulnerability in Puppet Enterprise allows an authenticated remote attacker to execute arbitrary code with administrator privileges, leading to full system compromise.

Puppet Enterprise vulnerability rce server-application
2t
high advisory

Remote Use-After-Free Vulnerability in Open5GS

A use-after-free vulnerability in the Open5GS AMF component allows remote attackers to trigger memory corruption via manipulated discovery options, potentially leading to service disruption or code execution.

Open5GS vulnerability cve
1c
high advisory

SQL Injection Vulnerability in Thinking Software Technology EFence

Thinking Software Technology EFence contains a SQL injection vulnerability that enables unauthenticated remote attackers to execute arbitrary database queries and potentially exfiltrate sensitive data.

EFence sql-injection vulnerability web-application
1t 1c
high advisory

SQL Injection in online-clinic-management-system

An unauthenticated SQL injection vulnerability (CVE-2026-90701) in the online-clinic-management-system allows remote attackers to manipulate database queries via the listdoctor.php searchtext parameter.

online-clinic-management-system web-application sql-injection vulnerability
2r 1t 1c updated
medium threat

NULL Pointer Dereference Vulnerability in S2OPC

CVE-2026-90782 is a NULL pointer dereference vulnerability in S2OPC 1.7.3 and earlier, allowing an attacker to trigger a denial-of-service crash via manipulated allocation sequences.

exploited S2OPC industrial-control-systems denial-of-service vulnerability
1t 1c
high advisory

Remote Command Injection in 0x4m4 HexStrike AI

A command injection vulnerability in HexStrike AI allows remote unauthenticated attackers to execute arbitrary OS commands via the Execute Endpoint.

HexStrike AI +1 remote-code-execution vulnerability command-injection api-security
1r 3t 1c
high advisory

Unrestricted File Upload Vulnerability in Anil-matcha Open-Generative-AI

Anil-matcha Open-Generative-AI is vulnerable to unrestricted file uploads via the /api/upload-binary endpoint, allowing remote attackers to manipulate the x-proxy-target-url argument to upload arbitrary files.

Open-Generative-AI vulnerability remote-code-execution web-application-security
1r 1c
high advisory

Integer Overflow in embedded-graphics Library

An integer overflow vulnerability in the embedded-graphics library (up to version 0.8.2) allows remote attackers to trigger memory corruption via a manipulated width argument in ImageRaw::draw_sub_image.

embedded-graphics vulnerability memory-corruption
1c
high advisory

Authentication Bypass in Cheshire Cat AI via Custom Auth Handler

An unauthenticated remote code execution vulnerability in Cheshire Cat AI version 1.9.2 and earlier stems from improper validation of the user_id argument within the custom authentication handler.

Cheshire Cat AI vulnerability authentication-bypass webserver
1t 1c
critical advisory

Exploitation of CVE-2021-38647 (OMIGOD) in Open Management Infrastructure

Publicly available proof-of-concept exploits for CVE-2021-38647 allow unauthenticated remote command execution via the OMI framework by omitting the Authorization header.

Open Management Infrastructure +4 vulnerability remote-code-execution cloud omi omigod
1r 2t 1c
low advisory

Buffer Overflow Vulnerability in SIPp get_peer_tag()

SIPp versions 3.7.7 and earlier contain a buffer overflow vulnerability in the get_peer_tag() function that allows remote attackers to cause a denial of service.

SIPp vulnerability denial-of-service network-protocol
1t 1c
high advisory

Path Traversal Vulnerability in rustypaste

rustypaste versions prior to 0.18.1 contain a path traversal vulnerability that allows attackers to write files to arbitrary locations by manipulating the custom filename HTTP header.

rustypaste path-traversal vulnerability remote-code-execution
2t 1c
high advisory

SSRF Vulnerability in Open Notebook /api/sources Endpoint

Open Notebook versions prior to 1.11.0 contain a Server-Side Request Forgery vulnerability allowing authenticated users to probe internal network services and cloud metadata endpoints.

Open Notebook ssrf web-application vulnerability
1r 1t 1c
high advisory

Hard-coded Cryptographic Key Vulnerability in Orion-visor

Orion-visor versions 2.5.7 and earlier contain a hard-coded cryptographic key within the HostKeyServiceImpl.encryptKey function, enabling potential remote compromise of encrypted host keys.

orion-visor vulnerability credential-exposure webserver
1t 1c
medium threat

Default Credential Vulnerability in lenve vhr

The lenve vhr 1.0-SNAPSHOT application contains a vulnerability in vhr.sql involving the use of default credentials, enabling remote exploitation via publicly available exploit code.

exploited vhr vulnerability credential-exposure cve
1t 1c
high advisory

Remote SQL Injection in Feng Office Legacy API

Feng Office versions up to 3.11.13.11 are susceptible to remote SQL injection via the 'auth' parameter in the Legacy API component.

Feng Office sqli web-application vulnerability
1r 1t 1c
critical advisory

Stack-based Buffer Overflow in sngrep SIP Parsing

sngrep versions up to 1.8.4 are vulnerable to a stack-based buffer overflow in SIP header formatting routines, allowing attackers to trigger crashes or achieve remote code execution via malformed SIP packets.

sngrep vulnerability rce sip networking
1t 1c
high advisory

Remote Code Execution in vLLM LlavaOnevision2 Processor Loader

A vulnerability in vLLM versions prior to 0.28.0 allows remote code execution by bypassing the trust_remote_code parameter during the loading of malicious LlavaOnevision2 processor classes.

vLLM +2 remote-code-execution model-inference supply-chain denial-of-service vulnerability
1r 2t 1c updated
high advisory

Privilege Escalation in MemberPress Corporate Accounts WordPress Plugin

The MemberPress Corporate Accounts plugin for WordPress contains a mass assignment vulnerability that allows authenticated users with corporate sub-account privileges to escalate to administrator by injecting unauthorized fields during user creation.

MemberPress Corporate Accounts wordpress privilege-escalation vulnerability
1t 1c
high advisory

Local File Inclusion Vulnerability in GEO my WP WordPress Plugin

The GEO my WP plugin for WordPress is vulnerable to unauthenticated local file inclusion (LFI) via the gmw_posts_locator_ajax_info_window_loader function, which can be escalated to remote code execution in specific PEAR-enabled environments.

GEO my WP wordpress lfi vulnerability rce
1r 1t 1c
high advisory

PHP Object Injection in Tutor LMS Plugin for WordPress

Tutor LMS plugin versions up to 4.0.7 are vulnerable to remote code execution via PHP object injection in the tutor_save_withdraw_account AJAX handler, allowing attackers to leverage POP chains.

Tutor LMS wordpress rce php-injection vulnerability
1r 1t 1c
critical advisory

Remote Code Execution in The Events Calendar WordPress Plugin

The Events Calendar plugin for WordPress is vulnerable to unauthenticated remote code execution via a flaw in the parse_array function that allows attackers to bypass security checks through crafted widget block comments.

The Events Calendar wordpress cve rce vulnerability
2t 1c
high advisory

Unauthenticated Admin API Exposure in Mockoon

Mockoon versions before 9.7.0 expose an unauthenticated, CORS-misconfigured admin API by default, allowing attackers to exfiltrate environment variables, hijack mock responses, and perform cross-origin secret theft.

commons-server +1 webserver vulnerability cve
3t 1c
critical advisory

Unauthenticated SQL Execution and RCE in MySQL MCP Server via SSE Transport

The mysql_mcp_server package (v < 0.4.2) fails to implement security protections in SSE transport mode, enabling unauthenticated attackers to perform arbitrary SQL execution, data exfiltration, and potential remote code execution.

mysql_mcp_server vulnerability rce sql-injection mcp
2t
critical advisory

Remote Code Execution in SPIP via editer_objet Action

SPIP versions before 4.4.18 are vulnerable to remote code execution due to improper validation of the arg parameter in the editer_objet action, allowing attackers to inject malicious serialized data into the job queue.

SPIP rce vulnerability web-application sql-injection cve
1r 2t 1c
high advisory

Multiple Vulnerabilities in GitLab CE and EE

GitLab has released security patches addressing a large set of vulnerabilities across Community and Enterprise editions, including flaws leading to remote code execution and data confidentiality compromises.

PoC GitLab Community Edition +7 vulnerability remote-code-execution gitlab
1c updated
high advisory

OS Command Injection in Pardus Software (CVE-2026-7863)

CVE-2026-7863 is an OS command injection vulnerability in TUBITAK BILGEM Pardus Software versions prior to 1.0.5, allowing unauthenticated attackers to execute arbitrary system commands.

Pardus Software vulnerability cve command-injection
2t 1c
high advisory

Privilege Escalation Vulnerability in Pardus-software

CVE-2026-8303 is an incorrect privilege assignment vulnerability in Pardus-software versions prior to 1.0.5 that allows local attackers to perform privilege escalation.

Pardus-software vulnerability privilege-escalation linux
1t 1c
high advisory

CVE-2026-57842: Kernel Use-After-Free in NetBSD COMPAT_NETBSD32 Layer

A use-after-free and double-free vulnerability in the NetBSD kernel's COMPAT_NETBSD32 layer allows local users to trigger memory corruption or kernel panics via crafted recvmsg system calls.

NetBSD kernel vulnerability privilege-escalation
1t 1c
low advisory

Net-SNMP Denial of Service via SMUX Module

An unauthenticated denial of service vulnerability in Net-SNMP versions up to 5.9.5.2 allows remote attackers to hang the snmpd process by initiating idle connections to the SMUX module.

Net-SNMP +1 denial-of-service network-infrastructure vulnerability
1t 1c updated
low advisory

Denial of Service Vulnerability in libp2p-rendezvous

A vulnerability in libp2p-rendezvous through version 0.17.1 allows malicious rendezvous servers to crash client nodes by providing an unbounded registration TTL value.

libp2p-rendezvous denial-of-service vulnerability libp2p
1c
high advisory

Arbitrary File System Access via Hugo Build Process

Hugo versions 0.43 through 0.164.0 include TailwindCSS in the default allowed execution list, enabling Node-based tools to bypass sandbox restrictions and perform unauthorized file read/write operations.

Hugo vulnerability supply-chain static-site-generator
1t 1c
high advisory

Multiple Vulnerabilities in Angular Framework

Multiple vulnerabilities in the Angular framework allow remote, anonymous attackers to perform cross-site scripting (XSS), bypass security controls, and manipulate or disclose sensitive data.

Angular web-security framework vulnerability
1t 3c
high advisory

Stored Cross-Site Scripting in Kirki WordPress Plugin

The Kirki plugin for WordPress version 6.2.0 and below is susceptible to unauthenticated Stored Cross-Site Scripting (XSS) via the 'comment' parameter, potentially leading to unauthorized script execution in administrative or user sessions.

Kirki – Freeform Page Builder, Website Builder & Customizer wordpress xss vulnerability
2t 1c
high advisory

Unauthenticated Endpoint Spoofing in WeenyGenius

WeenyGenius by Howyar Technologies contains a missing authentication vulnerability allowing unauthenticated network-adjacent attackers to spoof teacher or student roles and achieve remote control of student workstations.

WeenyGenius vulnerability authentication-bypass lab-management
3t 1c
high advisory

Information Disclosure Vulnerability in multicluster-observability-addon

A configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.

multicluster-observability-addon vulnerability cloud-native kubernetes
1t 1c
critical threat

Active Exploitation of JFrog Artifactory Vulnerabilities

Attackers are actively exploiting a chain of three critical vulnerabilities (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329) in JFrog Artifactory to bypass authentication and achieve full administrative control.

exploited Artifactory supply-chain vulnerability authentication-bypass
3t 3c
high advisory

Stored XSS in Simple Ajax Chat WordPress Plugin via CVE-2026-81825

The Simple Ajax Chat plugin for WordPress contains a stored cross-site scripting vulnerability in versions <= 20260811, allowing unauthenticated attackers to inject malicious scripts due to exposed nonces and insufficient input sanitization.

Simple Ajax Chat – Add a Fast, Secure Chat Box xss web-security wordpress vulnerability
2t 1c
high advisory

Path Traversal Vulnerability in AcyMailing WordPress Plugin

The AcyMailing WordPress plugin is vulnerable to unauthenticated directory traversal, allowing attackers to read arbitrary files on the server when the Embed images feature is enabled.

AcyMailing web-application vulnerability directory-traversal
1r 1t 1c
high advisory

Remote Code Execution Vulnerability in SAP Extended Passport Processing

A critical unauthenticated remote code execution vulnerability in the SAP Extended Passport (EPP) kernel component allows attackers to execute arbitrary system commands via RFC or HTTP communication layers.

SAP Kernel sap rce kernel vulnerability
2t
high advisory

Cross-Site Scripting in Angular Platform Server SSR

An XSS vulnerability in Angular's server-side rendering serializer fails to escape closing tags within <template> content nested inside fallback raw-content elements, allowing arbitrary script execution.

Angular platform-server +6 ssrf angular vulnerability
3t 1c
critical advisory

SigV4 Authentication Bypass in rclone serve s3

A critical authentication bypass vulnerability in rclone's S3 serving mode allows unauthenticated attackers to spoof identity via forged SigV4 signatures when '--auth-proxy' is used without '--auth-key'.

rclone +3 authentication-bypass s3 cve-2026-88018 vulnerability ftp session-hijacking authentication cve-2026-88017 +2
4t 1c
critical advisory

Traefik HTTP/3 Backend Authentication Bypass via Connection Reuse

Traefik fails to isolate connection-bound NTLM and Negotiate authentication on HTTP/3 routes, allowing unrelated clients to inherit victim-authenticated backend connections.

Traefik +3 vulnerability auth-bypass webserver proxy request-smuggling authorization-bypass
1r 2t 1c
high advisory

Stack-Based Buffer Overflow in IBM Db2 DRDA Client Implementation

IBM Db2 versions 11.5.0-11.5.9 and 12.1.0-12.1.5 are vulnerable to a stack-based buffer overflow via malicious DRDA server responses, potentially leading to arbitrary command execution on clients.

Db2 vulnerability cve remote-code-execution denial-of-service database-security
2t 1c
high advisory

Remote Code Execution in IBM DataStage

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to an OS command injection flaw allowing remote authenticated attackers to execute arbitrary code.

Cloud Pak for Data vulnerability rce cloud cve ssrf cloud-security ibm
3t 1c
high advisory

Authentication Bypass in Lenovo Software Fix

CVE-2026-63427 is an authentication bypass vulnerability in Lenovo Software Fix that allows a local authenticated user to escalate privileges and execute arbitrary code.

Software Fix vulnerability privilege-escalation
1t 1c
high advisory

Command Injection Vulnerability in Tianxi AI Agent PC Application

A command injection vulnerability (CVE-2026-19136) in the Tianxi AI Agent PC Application allows unauthenticated local attackers to execute arbitrary system commands via specially crafted links.

AI Agent PC Application vulnerability command-injection cve
2t 1c
high advisory

Improper Authorization Vulnerability in Lenovo File Manager Android App

A local improper authorization vulnerability in the Lenovo File Manager Android app allows authenticated local users to read or modify protected application files.

File Manager vulnerability android privilege-escalation
1t 1c
high advisory

Privilege Escalation in Lenovo Filez Client

Lenovo Filez Client contains an improper permissions vulnerability (CVE-2026-11813) that allows local authenticated users to escalate privileges.

Filez Client vulnerability privilege-escalation
1t 1c
high advisory

Prototype Pollution in isomorphic-git getRemoteInfo

A prototype pollution vulnerability in isomorphic-git before 1.42.0 allows malicious Git server operators to manipulate proxy configurations and intercept credentials via crafted ref advertisements.

isomorphic-git vulnerability prototype-pollution supply-chain
1c
critical advisory

Path Traversal Vulnerability in IBM DataStage on Cloud Pak for Data

IBM DataStage on Cloud Pak for Data version 5.4.0.0 is vulnerable to a path traversal flaw that allows a remote authenticated attacker to trigger a denial of service condition.

DataStage on Cloud Pak for Data vulnerability denial-of-service cloud-pak-for-data
1t 1c
critical advisory

Path Traversal Vulnerability in IBM DataStage

IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal during archive extraction, allowing an authenticated remote attacker to create arbitrary files on the host system.

DataStage +1 vulnerability path-traversal cloud-security idor
2t 1c
critical advisory

Authentication Bypass in passport-saml-encrypted via Unsigned SAML Assertions

The passport-saml-encrypted library versions up to 0.1.13 contain a critical vulnerability where SAML signature verification is skipped if a specific configuration is omitted, allowing attackers to forge and inject arbitrary authentication assertions.

passport-saml-encrypted authentication-bypass saml supply-chain vulnerability cve-2026-89043
2t 1c
high advisory

Security Advisories for cPanel WHM and ConfigServer Security & Firewall

WebPros has released patches for multiple critical vulnerabilities in cPanel & WebHost Manager and ConfigServer Security & Firewall, including an SQL injection flaw in the EmailTrack component.

PoC cPanel & WebHost Manager +1 vulnerability web-application cpanel sql-injection
3c updated
high advisory

Open WebUI Same-Origin XSS via Terminal Port Preview

An insecure sandbox configuration in the Open WebUI terminal port preview feature allows authenticated users to execute arbitrary JavaScript in the application's origin, leading to session token theft and account takeover.

Open WebUI +5 web-vulnerability xss session-theft web-application ssrf cve-2026-87996 vulnerability denial-of-service +5
3r 5t 1c updated
high advisory

Domain-Restriction Bypass in n8n OpenAI Chat Model Node

An unauthenticated credential access vulnerability in n8n allows users to bypass domain restrictions in the OpenAI Chat Model node via the model-search endpoint, leading to unauthorized credential exposure.

n8n +5 vulnerability webserver credential-theft cve-2026-86082 denial-of-service web-vulnerability cve-2026-86076 javascript +1
3t 2c updated
low advisory

Denial of Service in ION-DTN via Zero-Length Payload

ION-DTN versions prior to 4.2.1-a.1 are vulnerable to a remote denial-of-service attack, allowing unauthenticated attackers to terminate the process by sending a malformed BPv7 bundle.

ION-DTN denial-of-service vulnerability
1t 1c
high advisory

Multiple Vulnerabilities in AVEVA Pipeline Integrity Monitor

AVEVA Pipeline Integrity Monitor versions through 2025_SP1_P1_build_7.1.9580.8513 contain multiple vulnerabilities including hard-coded keys and improper authorization, facilitating information disclosure, credential brute-forcing, and XSS-based code execution.

Pipeline Integrity Monitor industrial-control-systems vulnerability critical-infrastructure
4c
high advisory

Critical Vulnerabilities in NextGen Healthcare Mirth Connect

NextGen Healthcare Mirth Connect versions 4.7.1 and earlier contain three critical vulnerabilities including SQL injection and XML External Entity (XXE) injection flaws that allow for unauthorized data access and denial-of-service.

Mirth Connect medical-devices vulnerability cisa ics
1t
high advisory

Heap Out-of-Bounds Write Vulnerability in Orthanc DICOM Server

An integer overflow vulnerability (CVE-2026-87020) in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to cause a denial-of-service via a crafted PNG or JPEG image.

Orthanc DICOM Server vulnerability ics-medical dos
high advisory

CyberPanel Authentication Bypass via API

CyberPanel versions prior to 3.0.5 contain an authentication bypass vulnerability where two-factor authentication is not enforced on API endpoints, allowing credential-derived token misuse.

CyberPanel vulnerability authentication-bypass cve-2026-88895
1t 1c
high advisory

Credential Disclosure in Renovate via Malicious Pagination Links

Renovate improperly validates HTTP 'Link' headers during GitHub API interactions, allowing a compromised GitHub server to exfiltrate configured credentials by redirecting pagination requests to an attacker-controlled host.

Renovate +5 credential-access supply-chain vulnerability supply-chain-security credential-theft nuget dependency-management
1t 1c
high advisory

Improper Link Header Validation in Renovate

Renovate versions prior to 44.11.3 fail to validate Link header destinations during GitLab server pagination, enabling attackers to exfiltrate credentials via malicious redirects.

Renovate +1 supply-chain vulnerability gitlab
1t 1c
high advisory

Weak Password Recovery Mechanism in LIBRID/LIBREF

Ankaref Innovation and Technology LIBRID/LIBREF versions 2.01.0.2183 through 10092026 contain a weak password recovery vulnerability that allows attackers to potentially gain unauthorized account access.

LIBRID/LIBREF credential-access vulnerability web-application
1t 1c
high advisory

Multiple Vulnerabilities in Arista EOS

Multiple vulnerabilities in Arista EOS allow an attacker to achieve privilege escalation, arbitrary code execution, security bypass, and denial-of-service.

EOS network-security vulnerability arista
3t
low advisory

Multiple Denial of Service Vulnerabilities in Dell Intel NPU Driver

Multiple vulnerabilities in the Dell Intel NPU driver allow a local attacker to cause a denial of service condition through insufficient input validation.

Intel NPU Driver denial-of-service vulnerability hardware-driver
1c
high advisory

Multiple Vulnerabilities in Joplin

Joplin is affected by multiple vulnerabilities that allow a remote attacker to execute arbitrary code, escalate privileges, bypass security controls, perform cross-site scripting (XSS), or manipulate sensitive data, potentially leading to a full account takeover.

Joplin vulnerability code-execution privilege-escalation xss
2t
medium advisory

Information Disclosure Vulnerability in Fortra GoAnywhere MFT

A vulnerability in Fortra GoAnywhere MFT allows a remote, authenticated attacker to disclose sensitive information due to insufficient access control.

GoAnywhere MFT vulnerability information-disclosure managed-file-transfer
1t 1c
critical advisory

SQL Injection in Armiya Information Technologies Access Control System

CVE-2026-7188 is a critical SQL injection vulnerability in the Armiya Information Technologies Access Control System versions prior to 2, allowing unauthenticated remote command execution against the backend database.

Access Control System sql-injection vulnerability cve
2t 1c
high threat

Critical Remote Code Execution Vulnerabilities in Adobe Illustrator

Three vulnerabilities in Adobe Illustrator allow for remote code execution when a user opens a maliciously crafted file, potentially granting an attacker full control over the host system.

exploited Illustrator vulnerability code-execution adobe graphical-editing
2t
high advisory

Critical Vulnerabilities in Check Point Security Appliances

Check Point has disclosed critical vulnerabilities, including CVE-2026-85102 and CVE-2026-85103, affecting various Security Gateway, Management Server, and Spark Firewall deployments.

Security Gateway +2 vulnerability network-security rce high-confidence-source
2t 2c
high advisory

Privilege Escalation Vulnerability in Bulk Password Reset WordPress Plugin

The Bulk Password Reset WordPress plugin, versions 1.3.3 and earlier, contains a privilege escalation vulnerability allowing authenticated users to perform unauthorized account takeovers.

Bulk Password Reset wordpress vulnerability privilege-escalation
2t 1c
critical advisory

Unauthenticated Remote Code Execution in Drag and Drop File Upload for Elementor Forms

An arbitrary file upload vulnerability in the Drag and Drop File Upload for Elementor Forms WordPress plugin allows unauthenticated attackers to execute arbitrary code via MIME type validation bypass.

PoC Drag and Drop File Upload for Elementor Forms vulnerability rce wordpress web-application
1r 2t 1c updated
critical advisory

Critical RCE Vulnerability in Fortinet Products via AuthHash Cookie (CVE-2025-32756)

A critical unauthenticated stack-based buffer overflow vulnerability, tracked as CVE-2025-32756, affects multiple Fortinet products and can be triggered via a crafted 'enc' parameter in the 'AuthHash' cookie.

FortiMail +4 remote-code-execution buffer-overflow vulnerability
1r 1t 1c
high advisory

Arbitrary Code Execution in Joker Linter via Malicious Project-Local Configuration

Joker versions before 1.8.2 are vulnerable to arbitrary code execution because the linter automatically traverses directory structures to execute project-local 'linter.*' files, allowing execution of attacker-supplied code within untrusted repositories.

Joker remote-code-execution vulnerability development-tools
1t
high advisory

Local File Inclusion in MaxSite CMS via Ajax Dispatchers

MaxSite CMS versions up to 109.6 contain a local file inclusion vulnerability in its ajax and require-maxsite dispatchers allowing unauthenticated attackers to execute arbitrary privileged handlers.

MaxSite CMS web-application lfi vulnerability
1r 1t 1c
medium threat

Cortex XDR Broker VM Privilege Escalation Vulnerability

A privilege escalation vulnerability (CVE-2026-0304) in Palo Alto Networks Cortex XDR Broker VM allows an authenticated, low-privileged attacker with man-in-the-middle positioning to execute arbitrary code as root.

exploited Cortex XDR Broker VM vulnerability privilege-escalation cortex-xdr
1t
medium threat

Information Disclosure Vulnerability in Prisma Access Agent for Linux

An information disclosure vulnerability in the Prisma Access Agent for Linux allows local, low-privileged users to access sensitive configuration data and stored credentials (CVE-2026-0305).

exploited Prisma Access Agent +1 vulnerability information-disclosure linux dlp-bypass endpoint-security
2t
high threat

CVE-2026-0308 Stored XSS in PAN-OS Web Interface

A stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows an authenticated administrator to execute arbitrary JavaScript within the context of the management interface.

PAN-OS +12 xss web-vulnerability cve rce network-security vulnerability panos
4t
medium threat

GlobalProtect App Local Privilege Escalation Vulnerabilities

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect application allow a local user to gain administrative privileges (SYSTEM/root) due to an untrusted search path issue.

exploited GlobalProtect App +3 vulnerability privilege-escalation endpoint
1t updated
low advisory

OS Command Injection in Checkov by Prisma Cloud

CVE-2026-0302 allows local users with low privileges to achieve OS command injection by influencing input consumed during Checkov scanning processes.

Checkov by Prisma Cloud +1 vulnerability command-injection prisma-cloud rce checkov supply-chain
1t
high advisory

Multiple Vulnerabilities in Microsoft Development Tools

Multiple vulnerabilities in Microsoft development tools allow remote, anonymous attackers to perform privilege escalation, bypass security mechanisms, and perform unauthorized information manipulation or disclosure.

Visual Studio +1 vulnerability development-tools privilege-escalation
1t
high advisory

Privilege Escalation Vulnerability in ESET AV Remover

A privilege escalation vulnerability, CVE-2026-12858, in ESET AV Remover allows local attackers to gain elevated privileges on affected host systems.

AV Remover privilege-escalation vulnerability security-update
1t 1c
high advisory

Heap-based Buffer Overflow in VLC Media Player via Malformed PNG

A 32-bit integer overflow in VLC media player's picture buffer calculation allows remote attackers to trigger a heap-based buffer overflow via crafted PNG files.

VLC media player vulnerability remote-code-execution media-player
1t 1c
high advisory

Multiple Vulnerabilities in ImageMagick

ImageMagick contains multiple vulnerabilities that could allow an attacker to trigger information disclosure, denial-of-service, or remote code execution by processing specially crafted image files.

ImageMagick vulnerability application-security
1t
high advisory

Multiple Privilege Escalation Vulnerabilities in Microsoft Authenticator and Xbox Gaming Services

Local attackers can exploit multiple vulnerabilities in Microsoft Authenticator and Xbox Gaming Services to achieve elevated privileges on Windows systems.

Microsoft Authenticator +1 privilege-escalation windows vulnerability
1t 2c
high advisory

Multiple Vulnerabilities in Adobe Experience Manager

Authenticated remote attackers can exploit multiple vulnerabilities in Adobe Experience Manager to achieve arbitrary code execution, privilege escalation, cross-site scripting, or security bypass.

Experience Manager vulnerability adobe aem
2t
high advisory

Multiple Vulnerabilities in Adobe ColdFusion

Adobe ColdFusion contains multiple vulnerabilities that enable attackers to achieve arbitrary code execution, privilege escalation, data manipulation, XSS, and denial-of-service.

ColdFusion vulnerability web-server
3t
low advisory

Fortinet FortiSIEM Open Redirect Vulnerability

A vulnerability in Fortinet FortiSIEM allows a remote, unauthenticated attacker to perform an open redirect, enabling the redirection of users to malicious or untrusted websites.

FortiSIEM vulnerability webserver informational
1c
medium advisory

Apache ActiveMQ Denial of Service and Data Manipulation Vulnerability

A vulnerability in Apache ActiveMQ allows a remote, authenticated attacker to perform a denial-of-service attack and manipulate data.

ActiveMQ denial-of-service vulnerability messaging
1t 1c updated
high advisory

Apache Airflow Privilege Escalation Vulnerability

A vulnerability in Apache Airflow allows a remote, unauthenticated attacker to escalate privileges and gain unauthorized user access within the workflow orchestration environment.

Airflow privilege-escalation vulnerability cloud
1c
high advisory

Multiple Vulnerabilities in Microsoft Azure, Entra, and Azure CLI

Multiple vulnerabilities across Microsoft Azure, Entra, and Azure CLI allow for identity impersonation, unauthorized data access, privilege escalation to SYSTEM level, and arbitrary code execution.

Azure +2 entra cloud-security vulnerability identity-security
3t
high advisory

Multiple Remote Code Execution Vulnerabilities in Ivanti Neurons for ITSM

Multiple vulnerabilities in Ivanti Neurons for ITSM (CVE-2024-7569, CVE-2024-7570, CVE-2024-7571) allow a remote unauthenticated attacker to achieve remote code execution.

Neurons for ITSM vulnerability remote-code-execution ivanti
3c
high advisory

Multiple Vulnerabilities in Dell OpenManage Server Administrator

Dell OpenManage Server Administrator contains multiple critical vulnerabilities allowing remote attackers to perform SSRF, escalate privileges, and execute arbitrary code.

OpenManage Server Administrator vulnerability server-management hardware-security
2t
high advisory

Out-of-Bounds Memory Read in zstd-jni

The zstd-jni library versions prior to 1.5.7-14 are vulnerable to an out-of-bounds memory read in the ZstdDictCompress constructor, allowing local or remote attackers to read native heap memory into a compression dictionary.

zstd-jni vulnerability memory-safety java
1t 1c updated
high advisory

Argument Injection in bestzip nativeZip Function

The bestzip package version 2.2.6 and 3.0.2 is vulnerable to argument injection in the nativeZip function, allowing unauthenticated attackers to execute arbitrary commands via malicious input.

bestzip vulnerability remote-code-execution nodejs software-supply-chain
1t 1c
high advisory

Authentication Bypass in Next-Cart Store to WooCommerce Migration Plugin

An authentication bypass vulnerability (CVE-2026-76009) in the Next-Cart Store to WooCommerce Migration WordPress plugin allows unauthenticated attackers to execute arbitrary SQL and delete files, leading to potential site takeover.

Store to WooCommerce Migration web-application wordpress vulnerability cve
1r 3t 1c
high advisory

Local File Inclusion in Eventin WordPress Plugin

The Eventin WordPress plugin contains a local file inclusion vulnerability in the event_layout parameter, allowing authenticated contributors to execute arbitrary PHP code.

PoC Eventin lfi vulnerability wordpress webserver
1r 1t 1c updated
high advisory

Attribute Injection in @xmldom/xmldom via Element.setAttribute

The @xmldom/xmldom library fails to validate attribute names during the use of Element.setAttribute, allowing attackers to inject malicious attributes into serialized XML output leading to potential XSS.

@xmldom/xmldom +1 xss injection vulnerability web-application
1t 1c
medium advisory

OpenVPN Reliability Layer Vulnerability CVE-2026-84732

OpenVPN versions 2.6.22 and 2.7.6 and earlier contain a vulnerability in the reliability layer that can be triggered by unbounded TLS timeouts and acknowledgments for non-outstanding packets, potentially leading to denial-of-service.

OpenVPN +1 vulnerability denial-of-service network-security
1c
high advisory

Critical Security Updates for Ivanti Endpoint Manager Mobile, Neurons for ITSM, and Sentry

Ivanti released security patches for multiple products, including Endpoint Manager Mobile, Neurons for ITSM, and Sentry, addressing vulnerabilities identified as CVE-2026-18851 and CVE-2026-83527.

Endpoint Manager Mobile +4 vulnerability patch-management security-advisory
2c updated
high advisory

Remote Code Execution in Windows Presentation Foundation

A high-severity remote code execution vulnerability (CVE-2026-50646) in .NET WPF allows arbitrary code execution via maliciously crafted XAML input.

Microsoft.WindowsDesktop.App.Runtime.win-arm64 +8 remote-code-execution vulnerability dotnet wpf
1t 1c
high advisory

Plaintext WebSocket Exposure in HTTPX2 and httpcore2 via SOCKS5 Proxy

A transport flaw in httpcore2 and httpx2 fails to establish TLS for wss:// connections routed through SOCKS5 proxies, exposing authentication headers, cookies, and message payloads in plaintext to proxy intermediaries.

httpcore2 +1 vulnerability transport-security proxy
2t 1c
low advisory

HTTPX2 Decompression Amplification Vulnerability (CVE-2026-84382)

The HTTPX2 library, prior to version 2.12.0, is vulnerable to a decompression amplification attack where malicious compressed HTTP responses can trigger large, unbonded memory allocations, leading to denial-of-service via memory exhaustion.

httpx2 denial-of-service vulnerability memory-exhaustion
1c
medium advisory

Unauthenticated Denial of Service in xmldom via Quadratic Complexity

The xmldom XML parser contains multiple O(n²) complexity flaws in its error-recovery path and DOM normalization logic, allowing an unauthenticated attacker to stall the Node.js event loop using crafted XML payloads.

xmldom +1 denial-of-service vulnerability web-application
1c
medium advisory

Denial of Service via Quadratic Memory Consumption in xmldom

The xmldom parser suffers from a quadratic memory complexity flaw during namespace processing, allowing unauthenticated attackers to trigger process OOM crashes using small, crafted XML payloads.

xmldom +2 denial-of-service vulnerability xml
1t 1c
high advisory

XML Injection Vulnerability in @xmldom/xmldom via Processing Instruction Targets

The @xmldom/xmldom library fails to validate the target parameter in createProcessingInstruction, enabling attackers to break out of XML processing instructions and inject arbitrary content when serializing with the requireWellFormed flag.

@xmldom/xmldom +2 injection xss xxe vulnerability
1t 1c
low advisory

Denial of Service Vulnerability in js-yaml via Empty Merge Source Exhaustion

The js-yaml library fails to correctly account for empty mappings when enforcing maxTotalMergeKeys, allowing attackers to trigger excessive CPU consumption through specially crafted YAML documents.

js-yaml +1 vulnerability denial-of-service supply-chain
1c
high advisory

Critical Remote Code Execution Vulnerabilities in libheif Affecting Sharp

Multiple critical vulnerabilities in the libheif library, including CVE-2026-84383, enable potential remote code execution via malicious AVIF image processing in applications using the sharp npm package.

libheif +1 vulnerability rce image-processing library-vulnerability
1t
critical advisory

Unauthenticated Remote Code Execution in Next.js Image Optimization API

A critical vulnerability in the libheif dependency used by Next.js allows unauthenticated attackers to achieve remote code execution via malicious AVIF image uploads.

Next.js +1 rce vulnerability web-application nextjs
1t
high advisory

Elevation of Privilege in Spring Cloud Azure

CVE-2026-69854 is an elevation of privilege vulnerability in Spring Cloud Azure caused by improper authentication, allowing an unauthenticated remote attacker to gain elevated access over a network.

Spring Cloud Azure vulnerability cloud authentication
1t 1c
critical advisory

Heap-Based Buffer Overflow in Telnet Client (CVE-2026-69431)

CVE-2026-69431 is a critical heap-based buffer overflow vulnerability in the Telnet Client that allows an unauthenticated, remote attacker to achieve arbitrary code execution over a network connection.

Telnet Client vulnerability cve remote-code-execution
1t 1c
low advisory

Denial of Service Vulnerability in libtpms

A vulnerability in libtpms (CVE-2024-0230) allows an attacker on an adjacent network to trigger a denial of service condition, potentially leading to service instability.

libtpms denial-of-service vulnerability virtualization
1t 1c
critical advisory

Apache Tomcat Remote Code Execution Vulnerability (CVE-2025-24813)

A critical remote code execution vulnerability (CVE-2025-24813) in Apache Tomcat with a CVSS score of 10.0 is now being targeted by publicly available proof-of-concept exploit tools.

Tomcat vulnerability rce webserver
1c
high advisory

Arbitrary Command Execution in Snipe-IT Backup Restoration

Snipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.

Snipe-IT +1 remote-code-execution cve vulnerability web-vulnerability css-injection account-takeover cve-2026-86751 ssrf +8
1r 14t 1c updated
high advisory

Unrestricted File Upload Vulnerability in iWebShop

CVE-2026-86666 allows remote, unauthenticated attackers to perform arbitrary file uploads via the uploadFile function in iWebShop-5 versions up to 5.15.

iWebShop-5 web-application file-upload vulnerability
1r 1t 1c
high advisory

Improper Input Validation in PayTR Virtual POS iFrame API WHMCS Module

The PayTR Virtual Pos iFrame API (v9x) WHMCS Module, versions 9.0.0 through 9.0.2, is vulnerable to input data manipulation due to improper quantity validation, allowing potential unauthorized modification of transaction parameters.

PayTR Virtual Pos iFrame API +1 vulnerability webserver payment-infrastructure
1c
high advisory

XenForo OAuth2 Authorization Code Reuse Vulnerability

XenForo versions prior to 2.3.13 contain an OAuth2 authorization code reuse vulnerability (CVE-2026-73311) that allows attackers to obtain unauthorized token pairs by submitting previously used codes.

XenForo web-application vulnerability authentication-bypass cve-2026-73309 web-application-vulnerability
3r 3t 1c
low advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package

Multiple vulnerabilities in the python-cryptography package for Red Hat Enterprise Linux, including CVE-2024-26130, may allow a remote, unauthenticated attacker to bypass security controls or cause a denial-of-service condition.

Enterprise Linux +1 vulnerability linux cryptography low-severity
1t 1c updated
high advisory

Multiple Vulnerabilities in Samsung Android Implementations

Multiple vulnerabilities in Samsung's Android implementation allow remote or local attackers to achieve arbitrary code execution with root privileges, escalate permissions, and cause denial-of-service.

Android mobile vulnerability security-advisory informational
2t
critical advisory

Remote Code Execution Vulnerability in Adobe Magento Open Source

A remote, unauthenticated attacker can exploit a vulnerability in Adobe Magento Open Source to achieve arbitrary code execution with administrator privileges.

Magento Open Source vulnerability rce web-application
2t
high advisory

Multiple Vulnerabilities in strongSwan

Multiple vulnerabilities, including remote code execution and security policy bypass, have been disclosed in strongSwan versions prior to 6.1.0.

strongSwan +1 vulnerability network-security patch-management
critical advisory

CVE-2026-86542 Path Traversal in knowns Application

An unauthenticated path traversal vulnerability in knowns versions prior to 0.30.0 allows attackers to overwrite arbitrary files on the server by supplying malicious traversal sequences in the import route name parameter.

knowns +1 remote-code-execution cve vulnerability path-traversal mcp
2r 6t 1c updated
medium threat

Arbitrary File Read in Ghost CMS via CVE-2023-40028

Ghost CMS versions prior to 5.59.1 are vulnerable to an authenticated arbitrary file read, exploitable through malicious symbolic link uploads via the administrative API.

exploited Ghost CMS ghost-cms arbitrary-file-read web-application cve-2023-40028 vulnerability
1r 1t 1c
high advisory

Multiple Vulnerabilities in SmarterTools SmarterMail

Authenticated remote attackers can exploit vulnerabilities in SmarterTools SmarterMail to bypass path restrictions, access unauthorized files, and compromise administrative API functions or cached credentials.

SmarterMail vulnerability webserver path-traversal
1t
critical advisory

Unauthenticated Remote Code Injection in Next4Biz CSM

CVE-2026-7861 is a critical deserialization of untrusted data vulnerability in Next4Biz CSM that permits unauthenticated remote code execution via malicious object injection.

CSM +1 vulnerability remote-code-execution cve
2t 1c
low advisory

Denial of Service Vulnerability in CommonMark AttributesExtension

CommonMark versions 1.5.0 through 2.09.0 are susceptible to a CPU-exhaustion denial-of-service attack due to inefficient attribute processing within the AttributesExtension.

commonmark denial-of-service vulnerability web-application
1c
high advisory

Argument Injection in LibreNMS graph_title Parameter

Authenticated attackers can exploit CVE-2026-86427 in LibreNMS before version 26.8.0 to inject arbitrary rrdtool arguments, bypassing authorization controls to read unauthorized RRD files or execute commands.

LibreNMS vulnerability web-application command-injection
1r 1t 1c
high advisory

Out-of-Bounds Read Vulnerability in 92181 markdown Library

An out-of-bounds read vulnerability in the 'lds' function of the 92181 markdown library allows remote attackers to trigger memory access errors via crafted inputs.

markdown vulnerability cve-2026-86303 memory-safety
1c
critical advisory

Unauthenticated Administrative Compromise in FreeIPA via OTP ACI Flaw

An unauthenticated remote attacker can exploit a flaw in FreeIPA's self-managed OTP token access control instructions to create arbitrary Kerberos principals and grant them administrator group membership.

FreeIPA +2 identity-management authentication-bypass privilege-escalation ldap vulnerability cve linux
3t 3c updated
medium advisory

Multiple Vulnerabilities in libxml2 Library

Multiple vulnerabilities within the libxml2 library could allow remote attackers to bypass security restrictions, manipulate data, disclose sensitive information, or trigger a denial-of-service condition.

libxml2 vulnerability gnome
1t
medium advisory

CoreDNS DNS Record Manipulation Vulnerability

A vulnerability in CoreDNS allows a remote, unauthenticated attacker to manipulate DNS records, potentially enabling traffic redirection or DNS cache poisoning.

CoreDNS dns vulnerability
1c
medium advisory

PackageKit Security Restriction Bypass Vulnerability

A local privilege escalation vulnerability in the PackageKit service, tracked as CVE-2024-1615, allows local attackers to bypass authorization checks and perform unauthorized package operations.

PackageKit privilege-escalation linux vulnerability
1t
critical threat

Critical RCE Vulnerability in N-able N-central

A critical unauthenticated remote code execution vulnerability (CVE-2026-86218) in N-able N-central is under active exploitation, allowing attackers to gain full system control.

N-central +2 vulnerability rce critical remote-management
1t updated
high advisory

CVE-2026-86404 Arbitrary Deserialization in Red Hat JBoss EAP

Red Hat JBoss Enterprise Application Platform (EAP) contains a vulnerability in its Artemis component where default deserialization configurations permit arbitrary object deserialization, potentially leading to remote code execution.

JBoss Enterprise Application Platform vulnerability deserialization rce
2t 1c
critical threat

OS Command Injection in Linksys RE7000 Range Extender

An OS command injection vulnerability (CVE-2026-86299) in the Linksys RE7000 version 2.0.15 allows unauthenticated remote code execution via the PingTest Handler component.

exploited RE7000 vulnerability rce network-security
1r 1t 1c
high advisory

Multiple Vulnerabilities in Netgate pfSense Plus and CE

Multiple vulnerabilities in Netgate pfSense Plus and CE allow remote attackers to execute arbitrary code or conduct cross-site scripting attacks, posing a high risk to network perimeter security.

pfSense Plus +1 vulnerability network-security firewall
2t
critical advisory

Critical Command Injection Vulnerability in Advantech WISE-6610 Gateways (CVE-2026-79697)

Advantech WISE-6610 series gateways are vulnerable to unauthenticated remote command injection via the Basic Station Certificate-Deletion Handler, potentially leading to full system compromise.

WISE-6610-NB +12 iot vulnerability cve network-security
2t 1c
high advisory

Unauthenticated SSRF Vulnerability in OpenMAIC

OpenMAIC versions prior to 1.0.1 contain a vulnerability in non-production builds that allows unauthenticated attackers to perform SSRF by manipulating request headers or parameters to access cloud metadata services.

OpenMAIC vulnerability ssrf cloud-security
1t 1c
high advisory

SQL Injection Vulnerability in Mstfakts College-Management-System

A remote SQL injection vulnerability in Mstfakts College-Management-System allows unauthenticated attackers to execute arbitrary database commands via the book search handler.

College-Management-System vulnerability web-application authentication-bypass
1r 2t 1c
low advisory

Denial of Service Vulnerability in h3 Library

The h3 library is vulnerable to a denial of service attack due to improper input validation of cookie chunk counts, allowing an attacker to trigger an O(n²) cleanup loop that hangs the server process.

h3 denial-of-service vulnerability web-application
1t 1c
low advisory

Denial of Service Vulnerability in PocketMine-MP

PocketMine-MP versions prior to 4.7.2 are vulnerable to a denial-of-service attack due to improper exception handling when parsing skin geometry data.

PocketMine-MP +3 denial-of-service vulnerability game-server
2t 1c updated
high advisory

SQL Injection in Inventory Management System

A SQL injection vulnerability in the login component of inventory-management-system 1.0.0 allows remote attackers to execute arbitrary database queries via the username and password parameters.

inventory-management-system sqli web-vulnerability vulnerability
1r 1t 1c
critical advisory

Unauthenticated Arbitrary File Upload in Drag and Drop Multiple File Upload for WooCommerce

The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress versions 1.1.6 and below contains an unauthenticated arbitrary file upload vulnerability, allowing attackers to achieve remote code execution.

Drag and Drop Multiple File Upload for WooCommerce wordpress file-upload rce vulnerability
1r 1t 1c
high advisory

Unauthenticated Blind SQL Injection in WP Fastest Cache

WP Fastest Cache versions 1.2.2 and earlier contain a blind SQL injection vulnerability allowing unauthenticated attackers to exfiltrate sensitive user data via the wordpress_logged_in cookie.

WP Fastest Cache sqli vulnerability wordpress plugin
1r 2t 1c
high advisory

Bilibili Desktop TLS Verification Bypass and Remote JavaScript Injection

Bilibili Desktop versions 1.18.0 and earlier are vulnerable to remote command execution and credential theft due to disabled TLS certificate verification and the execution of unsigned remote JavaScript configurations.

Bilibili Desktop vulnerability rce credential-theft mitm
2t 1c
high advisory

Unauthenticated SSRF Vulnerability in Webstudio

Webstudio versions through 0.296.0 are vulnerable to unauthenticated SSRF via proxy endpoints, allowing attackers to access internal cloud metadata and services.

Webstudio ssrf vulnerability cloud-security
1r 2t 1c
critical advisory

Authentication Bypass in Lara Dashboard

Lara Dashboard versions prior to 1.3.0 are vulnerable to an authentication bypass in the screenshot-login route that permits unauthenticated access to any user account when APP_ENV is not set to production.

Lara Dashboard +2 vulnerability authorization-bypass remote-code-execution web-application ssrf cve-2026-87821
2r 3t 1c updated
high advisory

Unauthenticated SSRF Vulnerability in MindsDB Crawler

MindsDB versions 26.1.0 and earlier are vulnerable to unauthenticated server-side request forgery (SSRF) in the web crawler handler, enabling unauthorized access to internal resources and cloud metadata.

MindsDB web-application ssrf vulnerability
1t 1c
high advisory

Unauthenticated SQL Injection and Database Access in SQL Chat

CVE-2026-86123 allows unauthenticated attackers to supply arbitrary database connection parameters, enabling unauthorized SQL execution against internal infrastructure.

SQL Chat cve-2026-86123 sql-injection web-application vulnerability
1t 1c
critical advisory

Unauthenticated Remote Code Execution in AutoAgent TCP Server

AutoAgent contains an unauthenticated remote code execution vulnerability in its TCP server that allows attackers to execute arbitrary bash commands as root.

AutoAgent vulnerability rce container-security
3t 1c
critical advisory

CVE-2026-83627: Unauthenticated RCE in Hummingbird WordPress Plugin

An unauthenticated remote code execution vulnerability in the Hummingbird WordPress plugin allows attackers to inject and execute arbitrary PHP code via unsanitized cookie headers in the debug log.

Hummingbird wordpress rce vulnerability
1r 1t 1c
high advisory

Critical Use-After-Free Vulnerability in Tinyproxy

A use-after-free vulnerability in Tinyproxy versions 1.10.0 and 1.11.1 permits unauthenticated remote attackers to trigger denial of service or potential remote code execution via malformed HTTP headers.

Tinyproxy vulnerability cve-2023-49606 use-after-free proxy
1c
critical advisory

Authentication Bypass and RCE in VMware vRealize Log Insight (CVE-2023-34051)

CVE-2023-34051 is an authentication bypass in VMware vRealize Log Insight that allows unauthenticated arbitrary file write and remote code execution via chained exploitation of Thrift RPC endpoints.

vRealize Log Insight +1 vulnerability remote-code-execution cve
3t 4c
high advisory

CVE-2022-22978 Authorization Bypass in Spring Security

An authorization bypass vulnerability in Spring Security allows unauthenticated attackers to access restricted endpoints by injecting URL-encoded newline or carriage return characters into request paths protected by RegexRequestMatcher.

Spring Security vulnerability web-application authentication-bypass
1r 1t 1c
high advisory

Heap Buffer Overflow in ntop nDPI

Versions of ntop nDPI before 6.0 are vulnerable to a heap-based buffer overflow in the ndpi_json_string_escape function, allowing attackers to trigger memory corruption via crafted network traffic.

nDPI vulnerability remote-code-execution network-security
1t 1c
high advisory

Authorization Bypass in ntopng REST v2 Handlers

An authorization bypass vulnerability in ntopng prior to version 6.7.260717 allows authenticated non-administrator users to delete notification endpoints and recipients, disrupting alerting services.

ntopng web-application authentication-bypass denial-of-service vulnerability authorization-bypass
2r 2t 1c
high advisory

Authorization Bypass Vulnerability in jofpin trape

An authorization bypass vulnerability in jofpin trape 2.0, triggered by manipulating the vId or id arguments, allows remote attackers to gain unauthorized access.

trape vulnerability web-application access-control
1t 1c
high advisory

Authentication Bypass in Nango Runner tRPC Server

Nango versions prior to 0.71.6 contain an authentication bypass vulnerability allowing unauthenticated attackers to achieve remote code execution via the tRPC runner server.

Nango vulnerability remote-code-execution
2t 1c
low advisory

Denial of Service Vulnerability in Chroma 1.5.9 via HNSW Index Parameters

Chroma 1.5.9 is vulnerable to an unauthenticated denial-of-service attack due to insufficient bounds validation on HNSW index parameters during collection creation, allowing memory exhaustion.

Chroma denial-of-service vulnerability cve
1t 1c
low advisory

Checkmk Agent Receiver Denial of Service Vulnerability

A vulnerability in the Checkmk Agent Receiver allows a remote, authenticated attacker to trigger a Denial of Service condition on the affected monitoring infrastructure.

Checkmk Agent Receiver denial-of-service vulnerability cve
1t 1c
high advisory

Critical Remote Code Execution Vulnerabilities in VMware Fusion and Workstation

VMware has released security updates for Fusion and Workstation to address multiple vulnerabilities, including CVE-2026-59346 and CVE-2026-59347, which could allow a remote attacker to execute arbitrary code.

Fusion +1 vulnerability virtualization rce
high advisory

Multiple Vulnerabilities in SonicWall Network Security Manager

SonicWall Network Security Manager (NSM) versions prior to 4.3.1-R4 contain multiple vulnerabilities, including CVE-2026-78327, CVE-2026-78328, and CVE-2026-81939, that allow for remote code execution, privilege escalation, and security policy bypass.

Network Security Manager On-Prem vulnerability remote-code-execution privilege-escalation patch-management
critical threat

Active Exploitation of Google Chromium V8 Type Confusion Vulnerability

A type confusion vulnerability in the Google Chromium V8 engine is being actively exploited in the wild, allowing remote attackers to achieve arbitrary code execution within the sandbox environment via crafted HTML pages.

exploited Chromium V8 +8 vulnerability chromium browser-security
1t 2c updated
high advisory

Authorization Bypass in IBM i DDM Target Dispatcher

A vulnerability in the IBM i DDM target dispatcher allows remote attackers to manipulate database transactions due to improper authorization handling.

IBM i vulnerability database-security
1c
high advisory

Information Disclosure Vulnerability in IBM Instana Agent Operator

IBM Instana Agent Operator versions 1.0.303 through 1.0.323 contain a vulnerability involving missing namespace validation that allows an authenticated attacker to copy sensitive etcd mTLS credentials to an attacker-controlled namespace.

Observability with Instana +1 vulnerability kubernetes openshift credential-access
1t 1c
high advisory

Information Disclosure via DNS Rebinding in IBM ContextForge MCP Gateway

IBM ContextForge MCP Gateway versions 1.0.6 and earlier contain a DNS rebinding vulnerability that allows remote authenticated attackers to access sensitive information during tool invocation.

mcp-contextforge-gateway vulnerability information-disclosure cve-2026-18905
1t 1c
high advisory

Path Traversal Vulnerability in Plandex

Plandex version 2.2.1 contains a path traversal vulnerability in the ApplyFiles function allowing arbitrary file writes via manipulated model outputs, potentially leading to remote code execution.

Plandex vulnerability path-traversal code-execution
3t 1c
high advisory

Unauthenticated Arbitrary File Read in surya Screenshot Server

The surya screenshot server version 0.22.1 is vulnerable to an unauthenticated arbitrary file read vulnerability via the /info, /page, and /process routes, allowing attackers to access sensitive local files.

surya webserver vulnerability file-read cve-2026-85687
1r 1t 1c
high advisory

Arbitrary Command Execution in aider via Malicious Configuration Files

The aider CLI tool is vulnerable to arbitrary command execution because it automatically executes shell commands defined in a .aider.conf.yml file located in the root of a Git repository upon startup.

aider vulnerability remote-code-execution cli-tool
1r 1t 1c
high advisory

Unauthenticated Arbitrary File Read in Xinference

Xinference versions 3.x and commit 4a94832 contain an unauthenticated arbitrary file read vulnerability via the model_path parameter in the auto-register endpoint.

Xinference vulnerability file-read webserver
1r 1t 1c
high advisory

Command Allowlist Bypass in cli-mcp-server

The cli-mcp-server package version 0.2.5 contains a vulnerability in the _validate_command_with_operators function allowing attackers to bypass command allowlists via shell substitution.

cli-mcp-server vulnerability command-injection execution
1t 1c
high advisory

Arbitrary Code Execution in sift.js via Prototype Pollution and $where Operator

The sift.js library version 17.1.3 is vulnerable to arbitrary code execution when processing untrusted input that leverages prototype pollution or malicious $where operator strings to invoke the new Function constructor.

sift vulnerability code-execution prototype-pollution javascript cve-2026-85625
1t 1c
high advisory

Remote Code Execution in Goose 1.37.0 via Malicious Recipes

The goose utility version 1.37.0 contains a vulnerability where insecure handling of recipe stdio extensions and retry.checks permits unvalidated arbitrary shell command execution.

goose remote-code-execution vulnerability supply-chain
1t 1c
high advisory

Authorization Bypass in AppFlowy-Cloud

AppFlowy-Cloud version 0.9.64 is susceptible to an insecure direct object reference (IDOR) vulnerability that allows unauthorized cross-workspace data access and modification.

AppFlowy-Cloud vulnerability web-application
1t 1c
high advisory

XML External Entity Vulnerability in IBM App Connect Enterprise and Integration Bus

IBM App Connect Enterprise and IBM Integration Bus for z/OS SAP Adapter components are susceptible to an XML External Entity (XXE) vulnerability, potentially allowing unauthenticated information disclosure or denial of service.

App Connect Enterprise +1 vulnerability xxe ibm integration
1t 1c
critical advisory

Authentication Bypass and SSRF in FastChat /register_worker Endpoint

An authentication bypass vulnerability in FastChat allows unauthenticated attackers to register arbitrary workers, enabling server-side request forgery and the interception of model prompts and responses.

FastChat vulnerability ssrf authentication-bypass
1r 2t 1c
critical advisory

Unauthenticated Arbitrary File Read and Write in TEN Framework

TEN Framework version 0.11.71 contains unauthenticated file read and write vulnerabilities in its API endpoints, enabling remote code execution via file system manipulation.

TEN Framework vulnerability rce webserver
1r 2t 1c
critical advisory

CVE-2026-85672 OS Command Injection in zerox

The zerox library version 1.1.20 is susceptible to OS command injection via maliciously crafted URLs that interpolate unsanitized file extensions into shell-executed poppler utility commands.

zerox cve-2026-85672 command-injection rce vulnerability
1t 1c
critical advisory

Unauthenticated RCE and SSRF in xiaobei via Webhook Injection

The xiaobei product through version 5.5.2 lacks authentication on webhook endpoints, enabling unauthenticated remote code execution via pipeline message injection and server-side request forgery (SSRF) via malicious media URL fetching.

xiaobei webserver vulnerability cve
1r 1t 1c
critical advisory

Authentication Bypass in Aim Remote Tracking Server

The Aim remote tracking server version 3.29.1 contains an authentication bypass vulnerability allowing unauthenticated attackers to execute arbitrary methods and perform unauthorized data access or deletion.

Aim vulnerability authentication-bypass cve-2026-85663
2t 1c
high advisory

SQL Injection in Vehicle Management System

Vehicle Management System version 1.0 contains an SQL injection vulnerability in the busid parameter of /busprofile.php, allowing unauthenticated remote attackers to execute arbitrary SQL queries.

Vehicle Management System web-vulnerability sqli vulnerability
1r 1t 1c
high advisory

Unauthenticated SSRF in Openpanel Site Checker

Openpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.

Openpanel +2 web-vulnerability ssrf reconnaissance remote-code-execution injection privilege-escalation web-application cve-2026-88891 +3
1r 8t 1c updated
high advisory

Plaintext Password Storage Vulnerability in Menulux Portal

Menulux Portal versions before 20260903211448 contain a vulnerability that stores passwords in plaintext, potentially allowing unauthorized retrieval of sensitive credentials.

Menulux Portal reconnaissance vulnerability web-application
1t 1c
high advisory

CVE-2026-6471 PostGREShell PostgreSQL Replication Vulnerability

CVE-2026-6471, dubbed PostGREShell, allows attackers with Replication privileges to achieve remote code execution and escalate to superuser by abusing the logical decoding plugin loader.

PostgreSQL vulnerability remote-code-execution privilege-escalation database
3t 1c
high advisory

Authorization Bypass in SourceCodester Class and Exam Timetabling System

SourceCodester Class and Exam Timetabling System version 1.0 is vulnerable to a remote authorization bypass via the ID argument in /admin/session.php, enabling unauthenticated access to administrative functions.

Class and Exam Timetabling System sql-injection vulnerability web-application
2r 1t 1c updated
high advisory

Heap-Based Buffer Overflow in Corosync Totem Process Group

A heap-based buffer overflow in the Corosync Totem Process Group component allows a network-adjacent attacker to crash the cluster or potentially execute arbitrary code via crafted multicast messages.

Corosync vulnerability heap-overflow dos
1t 1c
high advisory

Heap Use-After-Free in libsoup HTTP/2 Implementation

A heap use-after-free vulnerability in the libsoup HTTP/2 client allows malicious servers or MITM attackers to trigger memory corruption via specifically timed GOAWAY frames during file uploads.

libsoup vulnerability memory-corruption
1t 1c
high threat

Exploitation of CVE-2024-30043 XXE in Microsoft SharePoint Server

A publicly available exploit for CVE-2024-30043 allows unauthenticated remote attackers to perform XML External Entity (XXE) injection against Microsoft SharePoint Server via URL parsing confusion, potentially leading to sensitive data disclosure.

exploited SharePoint Server vulnerability xxe sharepoint cve-2024-30043
1t 1c
high advisory

SQL Injection Vulnerability in Hospital Information System 1.0

An unauthenticated SQL injection vulnerability in the Hospital Information System 1.0 allows remote attackers to execute unauthorized database queries via the Search parameter in addReq.php.

Hospital Information System web-application-vulnerability sql-injection cve-2026-85397 vulnerability web
2r 1t 1c
critical advisory

Hard-coded Credentials in SmartIT Desktop Manager

SmartIT Desktop Manager contains a hard-coded credentials vulnerability that allows unauthenticated remote attackers to retrieve SSH service account credentials for the SmartIT Agent via application source code.

SmartIT Desktop Manager vulnerability credential-exposure remote-access
1t 1c
high advisory

Second-Order SSTI in SiYuan via Attribute-View Template Columns

SiYuan kernel is vulnerable to a second-order SSTI via the queryBlocks template function, allowing attackers to achieve arbitrary SQL execution upon rendering imported malicious content.

kernel vulnerability ssti sql-injection rce
2t 1c
high advisory

Information Disclosure in SiYuan Kernel Enabling Offline Password Cracking

An information disclosure vulnerability in SiYuan's API allows unauthorized remote readers to retrieve cryptographic material necessary for offline, unthrottled GPU-based cracking of encrypted notebook master passwords.

SiYuan Kernel +5 info-disclosure cve cryptanalysis authentication-bypass webserver vulnerability session-forgery credential-disclosure +3
4r 8t 1c updated
high advisory

Buffer Overflow Vulnerability in MOOS ui-moos

The ui-moos component is vulnerable to a buffer overflow in ScopeTabPane.cpp and ScopeGrid.cpp, potentially allowing arbitrary code execution when processing crafted MOOS identifiers.

ui-moos vulnerability remote-code-execution buffer-overflow
1t 1c
low advisory

Memory Exhaustion Vulnerability in MOOS-IvP pMarineViewer

An unauthenticated memory exhaustion vulnerability in MOOS-IvP pMarineViewer (<= 24.8.1) allows attackers to stall the operator display by flooding the application with unbounded NODE_REPORT messages.

pMarineViewer vulnerability denial-of-service marine-systems
1t 1c
high advisory

Remote Code Execution in MOOS essential-moos pAntler

The pAntler component in essential-moos versions 10.0.1 and earlier allows unauthenticated attackers to achieve remote code execution by publishing a crafted MISSION_FILE message to the MOOSDB.

essential-moos remote-code-execution vulnerability cve network-security
4t 1c
critical advisory

CVE-2026-85440: Heap Overflow in MOOS core-moos

A pre-authentication heap overflow vulnerability in the MOOSCommPkt packet handling of MOOS core-moos versions up to 10.4.0 allows remote unauthenticated attackers to perform arbitrary memory writes via crafted packets.

core-moos cve authentication-bypass middleware denial-of-service network-vulnerability vulnerability network-security remote-access
5t 1c
critical advisory

Buffer Overflow Vulnerabilities in MOOS-IvP

Multiple buffer overflow vulnerabilities in MOOS-IvP versions up to 24.8.1 allow for remote code execution via malformed IvP function strings.

MOOS-IvP +1 vulnerability cve rce memory-corruption buffer-overflow research-robotics cve-2026-85438 remote-code-execution +4
4t 1c
critical advisory

Unauthenticated Bridge Redirection in MOOS-IvP uFldShoreBroker

MOOS-IvP uFldShoreBroker through version 24.8.1 is vulnerable to unauthorized route manipulation via forged node ping messages, enabling attackers to redirect data to arbitrary network locations.

uFldShoreBroker denial-of-service vulnerability robotics
1t 1c
critical advisory

Authentication Bypass and Message Injection in MOOS pShare

The pShare component in MOOS essential-moos versions up to 10.0.1 is vulnerable to unauthenticated UDP message injection and denial-of-service.

essential-moos vulnerability remote-code-execution network-security cve authorization-bypass robotics
2t 1c
high advisory

Hardcoded Credentials in IBM Netezza Software

IBM Netezza Software versions 11.3.0.3 through 11.3.0.3 Interim Fix 002 contain hardcoded credentials, allowing unauthorized access to internal container registries.

Netezza Software vulnerability cve-2026-8862 ibm
1t 1c
low advisory

Denial of Service in parsedmarc via Unbounded Attachment Decompression

The parsedmarc library before version 11.0.1 is vulnerable to remote denial-of-service exploitation via crafted email attachments that trigger memory exhaustion through unbounded decompression.

parsedmarc denial-of-service vulnerability email-security
1c
medium advisory

Denial of Service Vulnerability in LiquidJS strip_html Filter

An infinite loop vulnerability in the LiquidJS strip_html filter, tracked as CVE-2026-61556, allows attackers to trigger a process-wide denial of service by providing specific malformed HTML strings.

liquidjs +1 denial-of-service vulnerability web-application
1t 1c updated
low advisory

ffuf Denial of Service via Decompression Bomb

An attacker-controlled server can trigger an out-of-memory denial of service in ffuf (<= 2.1.0) by serving a decompression bomb that bypasses existing size constraints.

ffuf vulnerability denial-of-service web-fuzzer
1c
high advisory

Authorization Bypass in Label Studio Storage URI Resolution

Label Studio contains an authorization bypass vulnerability in its proxy_api.py module that allows attackers to access and exfiltrate cloud storage objects belonging to other organizations.

Label Studio vulnerability authorization-bypass cloud data-exfiltration
1t 1c
high advisory

Ollama Arbitrary Redirect Vulnerability (CVE-2026-85180)

Ollama versions fail to validate redirect destinations during model pulls, allowing unauthenticated attackers to perform Server-Side Request Forgery (SSRF) against internal resources and cloud metadata services.

Ollama vulnerability ssrf cloud-security
1t 1c
high advisory

Authentication Bypass in Mendix SAML Module

An authentication bypass vulnerability (CVE-2026-80465) in multiple Mendix SAML module versions allows unauthenticated attackers to hijack user sessions via improper SAML response signature validation.

Mendix SAML +2 vulnerability authentication-bypass sso mendix
1c updated
critical advisory

Buffer Overflow in TOTOLINK CP450

A critical buffer overflow vulnerability (CVE-2026-85031) in the TOTOLINK CP450 web interface allows remote, unauthenticated attackers to execute arbitrary code via the 'topicurl' argument.

CP450 vulnerability remote-code-execution cve-2026-85031
1t 1c
high threat

Cisco Releases Patches for Critical Infrastructure Vulnerabilities

Cisco has issued security advisories for unpatched S/MIME vulnerabilities in Secure Email and critical RCE and authentication bypass flaws across its IOS XR, Nexus, and VoIP phone product lines.

exploited Secure Email +6 vulnerability network-security patch-management informational
2t 5c
medium threat

Unauthenticated Information Disclosure in LearnDash LMS

LearnDash LMS versions prior to 4.10.3 are vulnerable to unauthenticated REST API access (CVE-2024-1208, CVE-2024-1210), allowing unauthorized remote actors to exfiltrate quiz and examination content.

exploited LearnDash LMS vulnerability web-application wordpress
1r 1t 2c
critical advisory

Unauthenticated RCE in Ivanti Connect Secure via CVE-2025-0282

A critical unauthenticated stack buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access (version 22.7) allows remote attackers to execute arbitrary code and create unauthorized administrative accounts.

Connect Secure +2 vulnerability remote-code-execution ivanti
2t 1c
high advisory

Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX

Progress Software has patched two vulnerabilities, including path traversal (CVE-2026-18672) and input tampering (CVE-2026-19219), in Telerik UI for ASP.NET AJAX versions prior to 2026.3.812.

Telerik UI for ASP.NET AJAX vulnerability web-application patch-management
2c
high advisory

SSRF Vulnerability via IPv6 Normalization in fast-uri

The fast-uri library incorrectly normalizes malformed IPv6 bracketed literals, allowing attackers to bypass host-based security checks via SSRF.

fast-uri +5 vulnerability web-application supply-chain
1c
high advisory

Scrapy S3DownloadHandler Vulnerable to Credential Exposure via Plaintext HTTP

The Scrapy S3DownloadHandler defaults to sending signed AWS S3 requests over plaintext HTTP, potentially exposing AWS authorization headers and security tokens to network-based attackers.

Scrapy vulnerability cloud web-scraping
1t 1c
high advisory

Authenticated OS Command Injection in OpenChoreo Workflow Plane

Authenticated users can trigger OS command injection in OpenChoreo workflow templates by supplying crafted parameters that are insecurely interpolated into shell execution scripts.

openchoreo vulnerability remote-code-execution kubernetes podman
1t 1c
high advisory

Omnigent Shared Agent Bundle Overwrite Leads to Runner RCE

An improper access control vulnerability in Omnigent allows authenticated users to overwrite shared agent bundles, enabling arbitrary command execution on runner infrastructure via malicious MCP server configuration.

Omnigent rce vulnerability webserver
2r 6t 1c
high advisory

Improper Client-Side Security Enforcement in tsi-dpdp-cms

The tsi-dpdp-cms software contains a vulnerability in versions 0.5.0 and earlier that improperly relies on client-side enforcement for security controls, allowing for remote exploitation via publicly available exploit code.

tsi-dpdp-cms vulnerability remote-access web-security
1c
high advisory

Arbitrary Code Execution in Faker.js helpers.fake

The Faker.js library contains an arbitrary code execution vulnerability in the helpers.fake method, allowing attackers to access the global constructor and execute unauthorized JavaScript.

faker vulnerability rce javascript
1t 1c
low advisory

Denial of Service in Tornado via Unbounded Form Field Parsing

Tornado fails to restrict the number of fields parsed in application/x-www-form-urlencoded request bodies, allowing an unauthenticated attacker to cause a denial-of-service by stalling the event loop.

Tornado denial-of-service web-application vulnerability
1t 1c
high advisory

Orval OpenAPI $ref Resolver SSRF and File Inclusion

Orval versions prior to 8.22.0 contain a vulnerability in the OpenAPI $ref resolver allowing build-time SSRF, remote file inclusion, and local file inclusion via crafted specification files.

Orval vulnerability ssrf file-inclusion supply-chain
1c
low advisory

Mistune Denial of Service via Markdown Recursion

Mistune versions 3.3.0 through 3.3.2 are susceptible to a denial of service attack via uncontrolled recursion during the rendering of deeply nested emphasis markers.

mistune denial-of-service markdown python vulnerability
1t 1c
high advisory

Multiple Vulnerabilities in Curl

Multiple vulnerabilities were discovered in the Curl library (versions 7.44.0 through 8.21.x), potentially allowing attackers to compromise data integrity, confidentiality, or bypass security policies.

Curl vulnerability library patch-management
high advisory

Multiple Critical Vulnerabilities in HPE Aruba Networking Products

HPE has disclosed a wide range of vulnerabilities across AOS-CX and Fabric Composer, including RCE, privilege escalation, and DoS flaws, impacting numerous versions of the network operating system.

AOS-CX +5 vulnerability networking infrastructure
3t
critical advisory

Critical SSRF Vulnerability in SonicWall SMA1000 Appliances

SonicWall SMA1000 appliances are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw, enabling remote attackers to access sensitive internal functionality and perform unauthorized operations.

SMA1000 Appliances vulnerability ssrf network-appliance
1t 2c
critical advisory

SQL Injection Vulnerability in Sangoma Switchvox

Sangoma Switchvox is vulnerable to an unauthenticated SQL injection flaw that allows remote attackers to execute arbitrary SQL commands on the backend PostgreSQL database, potentially leading to remote code execution.

Switchvox +1 webserver sql-injection vulnerability cisa-kev
2t 1c updated
critical advisory

Unauthenticated OS Command Injection in Kestra OSS (CVE-2026-49869)

Kestra OSS contains an OS command injection vulnerability allowing unauthenticated remote attackers to create and execute arbitrary workflows, posing a risk of full system compromise.

Kestra OSS vulnerability rce command-injection
2t 1c
high advisory

Command Injection Vulnerability in rpmuncompress

A command injection vulnerability in rpmuncompress allows local attackers to execute arbitrary code by supplying specially crafted archive filenames containing shell metacharacters.

rpmuncompress vulnerability command-injection linux
1t 1c
high advisory

Command Injection Vulnerability in rpm rpmbuild

A command injection vulnerability (CVE-2026-84837) in the rpmbuild -t* functionality allows attackers to execute arbitrary commands by supplying malicious tarball filenames or paths in build workflows.

rpm vulnerability ci-cd
1t 1c
high advisory

Out-of-Bounds Write in NGINX JavaScript (njs) XML Module

CVE-2026-78689 allows remote unauthenticated attackers to trigger an out-of-bounds heap write in the NGINX JavaScript (njs) and QuickJS (qjs) XML module via crafted namespace prefix lists.

njs +2 vulnerability denial-of-service cve-2026-78689
1c
medium advisory

CVE-2026-66362: Injection Vulnerability in NGINX Gateway Fabric

An injection vulnerability in the NGINX Gateway Fabric configuration generator allows authenticated users to inject arbitrary NGINX directives into the configuration when using NGINX Plus as the data plane.

NGINX Gateway Fabric vulnerability kubernetes ingress injection
1t 1c
high advisory

Integer Overflow Vulnerability in EVerest SDP Parsing

An integer overflow vulnerability (CVE-2025-68137) in EVerest everest-core versions prior to 2025.10.0 allows unauthenticated attackers to cause a Denial of Service or potential code execution.

everest-core dos vulnerability cve-2025-68137
1t 1c
high advisory

Remote Code Execution in Marimo 0.20.4

A Remote Code Execution vulnerability in Marimo version 0.20.4 allows attackers to achieve arbitrary command execution via a publicly available exploit.

Marimo webapps rce vulnerability
2t
medium advisory

Stored XSS Vulnerability in PodcastGenerator 3.2.9

PodcastGenerator version 3.2.9 contains a stored Cross-Site Scripting (XSS) vulnerability allowing unauthenticated attackers to inject malicious scripts into the application.

PodcastGenerator webapps xss vulnerability
1t
high advisory

Authorization Bypass in Craft CMS assets/move-asset Endpoint

Craft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.

Craft CMS +3 cms web-vulnerability authorization-bypass web-application vulnerability privilege-escalation web-application-vulnerability rce +1
2r 4t 1c updated
critical threat

Authentication Bypass in GNU Inetutils Telnet Daemon (CVE-2026-24061)

An authentication bypass vulnerability in GNU Inetutils telnetd (CVE-2026-24061) allows unauthenticated remote attackers to gain root access via a malicious USER parameter.

Inetutils vulnerability cve telnet privilege-escalation remote-code-execution
1r 2t 1c
medium advisory

Filebeat Denial of Service Vulnerability

A vulnerability in Filebeat allows a remote, authenticated attacker to trigger a denial of service condition.

Filebeat denial-of-service vulnerability
1t
medium advisory

Information Disclosure Vulnerability in MailPit

A vulnerability in MailPit allows a remote, unauthenticated attacker to exploit the application and perform unauthorized information disclosure.

MailPit vulnerability information-disclosure
1t
medium threat

Information Disclosure Vulnerability in IBM QRadar SIEM

A vulnerability in IBM QRadar SIEM allows a remote, authenticated attacker to gain unauthorized access to sensitive information.

exploited QRadar SIEM vulnerability information-disclosure ibm-qradar
1t 1c
high advisory

Unauthorized Remote Code Execution in DevKit Pro Plugin for WordPress

The DevKit Pro plugin for WordPress versions 2.3.0 and earlier contains an authorization vulnerability that allows authenticated attackers to perform remote code execution via arbitrary theme installation.

DevKit Pro wordpress vulnerability rce webserver
1r 2t 1c
critical advisory

Arbitrary File Deletion Vulnerability in SigmaForms Pro

The SigmaForms Pro WordPress plugin is vulnerable to arbitrary file deletion via path traversal in the delete_submission_files function, allowing unauthenticated attackers to delete critical server files and potentially achieve remote code execution.

SigmaForms Pro – AI Generated Forms wordpress vulnerability arbitrary-file-deletion
2t 1c
high advisory

Authorization Bypass in FeatherPanel SubuserController

Authenticated subusers can exploit a permission validation failure in FeatherPanel versions before 1.3.7.10 to escalate privileges to full server control.

FeatherPanel vulnerability privilege-escalation web-application
1t 1c
high advisory

Apache Solr UNC Path Validation Vulnerability (CVE-2026-22444)

A vulnerability in the Apache Solr create core API allows unauthenticated or low-privileged attackers to perform UNC path injection, potentially leading to NTLM hash exposure or remote code execution.

Solr vulnerability rce apache-solr
1r 1t 1c
high advisory

Command Injection Vulnerability in Coolify

Coolify versions before 4.2.0 are vulnerable to command injection via environment variable keys, allowing authenticated attackers to execute arbitrary commands on the underlying host server.

Coolify +2 vulnerability remote-code-execution cloud authentication-bypass web-application
4t 1c updated
high advisory

Environment Secret Exfiltration via pnpm-workspace.yaml Proxy Settings

A vulnerability in pnpm allows local environment variable exfiltration when a user executes 'pnpm install' in a malicious repository containing a crafted 'pnpm-workspace.yaml' file.

pnpm +3 supply-chain exfiltration vulnerability path-traversal
5t updated
high advisory

Integer Overflow Vulnerability in nanoid Leads to Deterministic Token Generation

An integer overflow in the nanoid library allows unauthenticated attackers to permanently corrupt the process-wide CSPRNG pool, forcing all subsequent ID generation to output a deterministic string and enabling mass authentication bypass.

nanoid +1 supply-chain vulnerability remote-code-execution
1t 1c
medium advisory

Broken Access Control in TYPO3 CMS Backend and Install Tool

TYPO3 CMS versions 13.0.0 through 13.4.33 and 14.0.0 through 14.3.5 contain a broken access control vulnerability (CVE-2026-19418) that allows attackers to perform unauthorized actions by abusing ineffective referrer enforcement.

TYPO3 CMS +1 web-application cms vulnerability cve-2026-19418
2t
critical advisory

Authentication Bypass in Proxmox Virtual Environment

CVE-2023-54391 allows unauthenticated remote attackers to bypass authentication in Proxmox VE 7.0-8.0 by providing a crafted tfa-challenge parameter to the API login endpoint.

Proxmox Virtual Environment vulnerability authentication-bypass critical
1r 1t 1c
high advisory

Privilege Escalation in Konga via Insecure Library Loading

Konga versions before 2.1.0 are vulnerable to privilege escalation on Windows via an insecure library loading path that allows low-privileged local users to execute arbitrary code.

Konga vulnerability privilege-escalation windows
2t 1c
high advisory

MySQL2 Auth Plugin Downgrade Vulnerability

The mysql2 Node.js database driver is vulnerable to credential theft because it does not enforce TLS before executing a requested authentication switch to the mysql_clear_password plugin.

mysql2 credential-access vulnerability nodejs
1t
low advisory

Browserslist Unbounded Memory Growth via Cache Exhaustion

The Browserslist package is vulnerable to a volumetric denial-of-service attack due to a missing cache eviction policy in its internal query result storage, leading to unbounded heap growth and potential OOM crashes in long-running processes.

browserslist denial-of-service memory-exhaustion javascript nodejs vulnerability prototype-pollution supply-chain
1t 1c
medium threat

Security Policy Bypass in Kaspersky Endpoint Security for Windows

A security policy bypass vulnerability exists in Kaspersky Endpoint Security for Windows, affecting versions 14.0 and 14.1, which allows attackers to circumvent configured security enforcement.

exploited Endpoint Security Windows vulnerability security-policy-bypass
1t
medium advisory

Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic

Multiple vulnerabilities in Rockwell Automation RSLinx Classic allow an unauthenticated remote attacker to cause a denial-of-service condition via specially crafted CIP packets.

RSLinx Classic ics ot denial-of-service vulnerability
1t 4c
high threat

Heap-Based Buffer Overflow in gvfs SFTP Backend

The gvfsd-sftp process contains a heap-based buffer overflow vulnerability that allows a malicious SFTP server to corrupt memory via crafted file read responses.

exploited gvfs vulnerability memory-corruption linux
1c
high advisory

Memos Refresh Token Revocation Failure

Memos versions 0.26.0 through 0.30.0 fail to invalidate refresh tokens after a password change, enabling persistent unauthorized access via the RefreshToken RPC.

Memos session-management vulnerability mssql-bypass
1t 1c
high advisory

Arbitrary Code Execution in ModelScope via Insecure PyYAML Parsing

ModelScope insecurely utilizes the unsafe yaml.Loader to parse model configuration files, allowing an attacker to achieve arbitrary code execution by supplying a poisoned repository containing malicious Python object construction tags.

ModelScope remote-code-execution vulnerability supply-chain
2t 1c
high advisory

Arbitrary File Write in appium-mcp-server via Path Traversal

The appium-mcp-server package up to version 0.1.61 contains a path traversal vulnerability in file writing tools, allowing unauthenticated attackers to overwrite sensitive system files.

appium-mcp-server vulnerability path-traversal appium cve-2026-84201
2t 1c
critical advisory

Hard-coded Credentials in Talassoft Industrial Management Software

Talassoft Industrial Management Software versions 4 through 16 contain a hard-coded credentials vulnerability, enabling unauthorized attackers to retrieve sensitive embedded data.

Talassoft Industrial Management Software vulnerability industrial-control-systems
1c
high advisory

Multiple Vulnerabilities in WatchGuard Fireware OS

Multiple vulnerabilities in WatchGuard Fireware OS, including the Mobile Security component, allow unauthenticated remote attackers to execute arbitrary code via specially crafted network traffic.

Fireware OS vulnerability network-security remote-code-execution watchguard
2t
high advisory

Jolokia JSR-160 Proxy JNDI Injection Vulnerability

Jolokia JSR-160 proxy contains an insufficient validation flaw, identified as CVE-2026-84218, which allows attackers to bypass denylists and trigger JNDI lookups leading to SSRF or remote code execution.

Jolokia vulnerability java jmx jndi ssrf
2t 2c
high advisory

Arbitrary File Upload Vulnerability in Gravity Forms

An arbitrary file upload vulnerability in the Gravity Forms WordPress plugin (<= 3.0.2) allows unauthenticated attackers to write arbitrary files to the temporary upload directory, potentially leading to remote code execution or stored XSS.

Gravity Forms +1 wordpress vulnerability rce xss application-security
1r 3t 1c updated
critical advisory

Code Injection Vulnerability in Klemsan KIO

Klemsan KIO versions prior to 1.9 contain a code injection vulnerability allowing unauthenticated attackers to execute arbitrary code due to improper input validation during code generation.

KIO vulnerability code-injection industrial-control-systems
2t 1c
critical advisory

SQL Injection Vulnerability in Teracity E-OSB

Teracity E-OSB versions prior to V02.26.07.08.01 contain an SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL commands against the backend database.

E-OSB sql-injection vulnerability web-application
1c
high threat

Blind SQL Injection Vulnerability in Payload CMS

Payload CMS versions prior to 3.73.0 are vulnerable to Blind SQL Injection via maliciously crafted JSON filter inputs processed by the Drizzle database adapter.

exploited Payload CMS webapps sqli vulnerability
1r 1t 1c
critical advisory

CVE-2026-18550 Privilege Escalation in Nokri Job Board WordPress Theme

The Nokri Job Board WordPress theme is vulnerable to unauthenticated account takeover due to improper password reset token validation, allowing attackers to reset passwords for arbitrary user accounts.

Nokri - Job Board WordPress Theme wordpress vulnerability privilege-escalation
1t 1c
critical advisory

Critical Vulnerability in VMware Aria Operations for Networks (CVE-2023-34039)

VMware Aria Operations for Networks versions 6.0 to 6.10 contain a vulnerability involving static SSH keys that allow unauthorized remote access and root-level privilege escalation.

Aria Operations for Networks vulnerability remote-code-execution network-infrastructure
1r 2t 1c
medium advisory

Samba Denial of Service Vulnerability

A vulnerability in Samba tracked as CVE-2024-4323 allows a remote, authenticated attacker to trigger a Denial of Service condition through specific request handling.

Samba +1 denial-of-service vulnerability linux network-security
1t 1c
medium advisory

GnuTLS Denial of Service Vulnerability

A vulnerability in the GnuTLS library allows remote, unauthenticated attackers to trigger a denial of service condition in applications leveraging the library via CVE-2024-0553.

GnuTLS +1 denial-of-service vulnerability transport-security
1t 1c
medium advisory

Apache Commons Configuration Denial of Service Vulnerability

A vulnerability in Apache Commons Configuration allows a remote, unauthenticated attacker to trigger a denial of service condition through improper variable interpolation handling.

Commons Configuration vulnerability denial-of-service java
1t 1c
low advisory

Security Constraint Bypass in VMware Tanzu Spring Framework

A vulnerability in VMware Tanzu Spring Framework identified as CVE-2024-38816 allows a remote, unauthenticated attacker to bypass security restrictions.

Spring Framework vulnerability web-framework patch-management
1c
high advisory

VMware Tanzu Spring Security Authentication Bypass Vulnerability

A vulnerability in VMware Tanzu Spring Security allows a remote, unauthenticated attacker to bypass security restrictions, potentially leading to unauthorized access to sensitive information.

Tanzu Spring Security vulnerability security-bypass authentication-bypass
1c
high advisory

Unauthenticated Remote Access Vulnerability in ES File Explorer

CVE-2019-6447 allows unauthenticated attackers on a local Wi-Fi network to execute arbitrary commands and exfiltrate files from Android devices running vulnerable versions of ES File Explorer.

ES File Explorer File Manager android vulnerability mobile cve-2019-6447
3t 1c
high advisory

Devtron Authorization Bypass in Webhook API

Devtron versions 2.2.0 and earlier contain an authorization flaw in the orchestrator webhook endpoint that allows authenticated users to retrieve plaintext super-admin API tokens.

Devtron vulnerability privilege-escalation credential-access
1r 1t 1c
critical advisory

Unauthenticated Remote Command Injection in QVidium Opera11

QVidium Opera11 version 3.3.2a26-Ax4x-opera11 is vulnerable to unauthenticated remote command injection via the ipaddr parameter in the /cgi-bin/net_tr.cgi script, which lacks security updates due to the vendor ceasing operations.

Opera11 vulnerability remote-code-execution cgi-injection legacy-software
1r 2t 1c
high advisory

Authentication Bypass in cu silicon

An unauthenticated remote code execution vulnerability (CVE-2026-82919) exists in the cu silicon library versions 0.1.5 and earlier due to missing authentication controls in the create_app function.

silicon cve-2026-82919 authentication-bypass vulnerability
1c
high advisory

Authentication Bypass Vulnerability in Pangolin

Pangolin versions prior to 1.22.0 are vulnerable to an authentication bypass in the share-link endpoint, allowing unauthenticated access to arbitrary resources.

Pangolin authentication-bypass cve-2026-72001 vulnerability
1t 1c
high advisory

RESTEasy XML External Entity Vulnerability in SourceProvider

An XML External Entity (XXE) vulnerability in RESTEasy's SourceProvider allows unauthenticated attackers to perform arbitrary remote file reads via malicious XML input.

RESTEasy web-application xxe vulnerability
1t 1c
high advisory

Information Exposure in Keep Backup Daily WordPress Plugin

The Keep Backup Daily plugin for WordPress before 2.1.4 contains a vulnerability allowing unauthenticated attackers to trigger database backups and retrieve them via predictable filenames.

Keep Backup Daily wordpress vulnerability web-application data-exfiltration
1r 2t 1c
high advisory

SQL Injection Vulnerability in Online Shopping System

The Online Shopping System 1.0 contains an unauthenticated SQL injection vulnerability in the search functionality of /action.php, allowing remote attackers to execute arbitrary database queries.

Online Shopping System sqli vulnerability web-application
1r 1t 1c
low advisory

Denial of Service Vulnerability in SmallRye GraphQL

An unauthenticated remote attacker can cause a denial of service in SmallRye GraphQL by exploiting improper BigInteger scalar coercion to trigger resource exhaustion.

GraphQL denial-of-service vulnerability
1t 1c
high advisory

Remote Code Execution in Quarkus via Qute Template Engine

The Qute template engine in Quarkus fails to properly restrict access to sensitive Java internals, allowing an attacker to achieve remote code execution via template injection.

Quarkus vulnerability rce java
2t 1c
critical advisory

Authentication Bypass in Tenda AC1206 Web UI

Tenda AC1206 firmware version 15.03.06.23 contains an authentication bypass vulnerability in the /goform/telnet handler, allowing remote attackers to gain unauthorized access.

AC1206 vulnerability network-security web-application
1r 1t 1c
critical threat

Remote Command Injection in D-Link NAS Devices

A critical command injection vulnerability in D-Link DNS-327L and DNS-340L devices allows unauthenticated remote code execution via manipulation of the f_dev parameter.

exploited DNS-327L +1 vulnerability rce network-storage
1r 1t 1c
high advisory

Remote Out-of-Bounds Write Vulnerability in D-Link DSM-G600

A critical out-of-bounds write vulnerability in the D-Link DSM-G600 multipart handler allows remote attackers to compromise the device via the /load_file.cgi endpoint, with public exploit code currently available.

DSM-G600 vulnerability remote-code-execution network-appliance
1t 1c
critical advisory

OS Command Injection in D-Link Virtual Volume Handler

D-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.

DNS-340L +4 webserver vulnerability remote-code-execution cve-2026-82692 storage-device cve-2026-85222 command-injection nas +1
3r 3t 1c updated
low advisory

Multiple Vulnerabilities in GIMP Lead to DoS and Information Disclosure

Multiple vulnerabilities in GIMP (CVE-2024-10332, CVE-2024-10333) allow a local attacker to cause a denial-of-service condition or perform information disclosure via malicious input files.

GIMP vulnerability dos information-disclosure
1c
medium advisory

Multiple Vulnerabilities in MariaDB Connectors

Multiple vulnerabilities in MariaDB Connector libraries enable remote, unauthenticated attackers to perform SQL injection, bypass security controls, and manipulate sensitive database content.

MariaDB Connectors vulnerability database injection
1t 3c
high advisory

Security Policy Bypass in @hulumi/policies via Parent Spoofing

The @hulumi/policies package before version 1.3.2 is vulnerable to a parent spoofing attack that allows unauthorized actors to bypass security policy enforcement during bucket configuration validation.

policies supply-chain vulnerability cloud-security iam
2t 1c
high advisory

Nodemailer SSRF and Arbitrary File Read Vulnerability

Nodemailer versions before 9.0.1 fail to enforce security flags when processing message-level raw options, allowing authenticated attackers to perform SSRF and read arbitrary files.

nodemailer +1 vulnerability ssrf file-access smtp-injection
3t 1c
critical advisory

ToolJet Multi-Tenancy Broken Access Control

ToolJet versions prior to 3.16.208 are vulnerable to broken access control, allowing authenticated builder-role users to perform unauthorized database operations across tenant boundaries.

ToolJet webserver broken-access-control vulnerability web-application-vulnerability authorization-bypass privilege-escalation web-application authentication-bypass +1
4t 1c
critical advisory

Privilege Escalation in hulumi via IAM Policy Misconfiguration

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that permits unauthorized role lifecycle operations on af-e2e-* roles.

hulumi privilege-escalation cloud-security identity-access-management iac vulnerability rce execution
3t 1c
high advisory

Local Privilege Escalation in Colorful iGameCenter WinRing0x64.sys

Colorful iGameCenter 2.0.0.81 is vulnerable to local privilege escalation due to improper input validation within the WinRing0x64.sys IOCTL dispatch handler.

iGameCenter vulnerability local-privilege-escalation windows
1t 1c
high advisory

Authorization Bypass in Soarkey StudentManagement

A vulnerability in the Administrative Servlet of Soarkey StudentManagement and 学生信息管理系统 allows remote attackers to bypass authorization via manipulation of the action argument in AdminDao.doGet.

StudentManagement +1 web-application vulnerability authentication-bypass
1r 1c
high advisory

SQL Injection in Online Medicine Delivery System

Online Medicine Delivery System 1.0 contains a SQL injection vulnerability in the login interface, allowing remote unauthenticated attackers to bypass authentication or access database contents.

Online Medicine Delivery System sql-injection web-vulnerability web-application vulnerability
3r 1t 1c
critical advisory

WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding

WWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.

AVideo +7 credential-access web-application authentication-bypass web-application-vulnerability path-traversal reconnaissance web-vulnerability csrf +13
7r 15t 1c updated
critical advisory

Critical RCE Vulnerability in Valvepress Automatic Plugin

CVE-2024-27956 is a critical vulnerability in the Valvepress Automatic WordPress plugin (versions 3.92.0 and earlier) that allows unauthenticated remote code execution via a publicly available exploit.

Automatic wordpress vulnerability rce web-application
1t 1c
high advisory

Remote Buffer Overflow in NASA Trick JSONVariableServer

CVE-2026-82478 is a stack-based buffer overflow in the NASA Trick simulation environment (version 19.6.0) that enables remote attackers to trigger memory corruption via the TCP Socket Handler.

Trick cve vulnerability remote-code-execution nasa-trick
1t 1c
critical advisory

Authentication Bypass in MyHome Core Plugin for WordPress

The MyHome Core plugin for WordPress is vulnerable to authentication bypass via insecure AJAX handlers, allowing unauthenticated attackers to hijack arbitrary user accounts.

MyHome Core plugin wordpress authentication-bypass vulnerability
1r 1t 1c
high advisory

VMware vCenter Server Backup API Flag Injection Vulnerability (CVE-2024-22274)

A newly released PoC exploit for CVE-2024-22274 enables authenticated attackers to perform flag injection within VMware vCenter Server backup API components, resulting in remote code execution as root.

VMware Cloud Foundation +1 vmware rce vulnerability cve-2024-22274
2t 1c
high advisory

Exploitation of CVE-2018-14847 in MikroTik RouterOS

An unauthenticated remote file read vulnerability in MikroTik RouterOS (CVE-2018-14847) allows attackers to extract and decrypt administrative credentials, leading to full system compromise.

RouterOS +1 vulnerability credential-access network-infrastructure
1r 2t 1c
critical advisory

Critical RCE via Server-Side Template Injection in OpenSAGRES XDocReport

OpenSAGRES XDocReport is vulnerable to a critical server-side template injection (SSTI) flaw via the Apache Velocity engine, allowing unauthenticated remote code execution through malicious .docx uploads.

XDocReport +1 vulnerability rce ssti webserver
2t 1c
high advisory

Authentication Bypass in KubeEdge CloudCore Node Task Reporting

KubeEdge CloudCore versions through 1.23.1 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to manipulate node upgrade status reports via port 10002.

KubeEdge CloudCore vulnerability cloud-native kubernetes
1c
high advisory

Authentication Bypass in pac4j-oidc via Token Forgery

An authorization bypass vulnerability in pac4j-oidc versions prior to 6.5.6 allows attackers to forge OIDC access tokens by exploiting the library's failure to validate token signatures, issuers, audiences, and expiration.

pac4j-oidc vulnerability authentication-bypass oidc identity-security
1t 1c
critical advisory

Unauthenticated Remote Access in argocd-mcp via CVE-2026-82456

The argocd-mcp component version 0.8.0 insecurely binds its HTTP transport to all network interfaces and lacks authentication for MCP sessions when an API token is present, allowing remote attackers to perform unauthorized Argo CD resource modifications.

argocd-mcp vulnerability remote-code-execution cloud-native cicd
2t 1c
high advisory

CVE-2026-82457 Privilege Escalation in su-exec

The su-exec utility up to version 0.3 suffers from integer truncation during user identifier parsing, allowing attackers to escalate privileges to root.

su-exec privilege-escalation vulnerability linux
1t 1c
high advisory

Skyvern TextPromptBlock Sandbox Escape

A sandbox escape vulnerability in Skyvern prior to version 1.0.45 allows unauthenticated attackers to achieve remote code execution by injecting malicious Jinja2 templates into prompt inputs.

Skyvern cve-2026-82447 sandbox-escape rce vulnerability
1t 1c
critical advisory

Hardcoded Connection Key Vulnerability in Shinobi Child Node

Shinobi versions prior to commit 5a76c74f contain a hardcoded connection key in the child node service, allowing unauthenticated attackers to execute arbitrary SQL queries.

Shinobi cve-2026-82448 sql-injection vulnerability
1t 1c
high advisory

Graylog Syslog Parser Vulnerability Enabling Log Evasion

A vulnerability in the Graylog syslog parser allows unauthenticated attackers to overwrite or discard logs from devices using key-value formats, such as Fortigate, facilitating log evasion.

Graylog Server vulnerability logging defense-evasion
1t 1c
high advisory

XXE Vulnerability in MapFish Print

MapFish Print is susceptible to an XML External Entity (XXE) injection vulnerability via the GML layer processing feature, allowing attackers to perform arbitrary file reads or Server-Side Request Forgery (SSRF).

print-lib +1 xxe cve-2026-55848 vulnerability webserver
2t 1c
high advisory

Information Disclosure Vulnerability in IBM Administration Runtime Expert for i

IBM Administration Runtime Expert for i 1R1M0 contains an improper authentication enforcement vulnerability allowing a remote authenticated attacker to access sensitive information.

Administration Runtime Expert for i vulnerability authentication-bypass cve-2026-17203
1t 1c
critical advisory

Remote Code Execution in IBM Langflow OSS via A2A Endpoint

IBM Langflow OSS versions 1.0.0 through 1.11.1 contain an unauthenticated remote code execution vulnerability in the A2A public endpoint.

Langflow OSS +4 remote-code-execution vulnerability webserver web-application security-scanner-bypass cve-2026-76059 rce cloud-security +2
1r 8t 1c updated
high advisory

Improper Hostname Validation in Gitingest

Gitingest versions 0.3.1 and earlier contain a hostname validation vulnerability allowing attackers to force outbound connections and exfiltrate GitHub personal access tokens.

Gitingest vulnerability credential-theft data-exfiltration
2t 1c
high threat

Credential Disclosure in Stable Diffusion WebUI via /sdapi/v1/cmd-flags

Stable Diffusion WebUI versions 1.10.1 and earlier contain a credential disclosure vulnerability allowing unauthenticated remote attackers to retrieve cleartext authentication credentials.

exploited Stable Diffusion WebUI vulnerability credential-disclosure web-api
1r 2t 1c
high advisory

SSRF Vulnerability in Qwen-Agent Document Parsing

Qwen-Agent version 0.0.34 and earlier contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to force the server to perform arbitrary internal HTTP requests and exfiltrate metadata service content.

Qwen-Agent ssrf vulnerability cloud path-traversal arbitrary-file-read web-application-vulnerability
2t 1c
high advisory

Hermes Agent Supply Chain Vulnerability via Mutable MCP Catalog References

Hermes Agent versions prior to 0.19.0 contain a supply chain vulnerability where the bundled MCP catalog uses mutable branch references, enabling remote code execution if an upstream repository is compromised.

Hermes Agent supply-chain rce vulnerability
1t 1c
high advisory

Command Injection in Synk Sweater Comb

Synk Sweater Comb before version 3.8.8 contains a command injection vulnerability in the expectGitBranch() function, allowing arbitrary OS command execution via crafted .vervet.yaml configuration files.

Sweater Comb vulnerability remote-code-execution ci-cd-security
1t 1c
high advisory

SpringBlade Privilege Escalation via Hardcoded JWT Key and Unprotected Endpoint

SpringBlade versions 2.7.3 through 3.5.0 allow authenticated attackers to forge administrative tokens using a hardcoded JWT signing key and escalate privileges via an unprotected internal endpoint.

SpringBlade vulnerability privilege-escalation authentication-bypass
2t 1c
critical advisory

Unauthenticated Mutating Operations in Argo Rollouts Dashboard

Argo Rollouts dashboard versions 1.10.0 and earlier expose sensitive, mutating operations without authentication, authorization, or CSRF protection when bound to all network interfaces.

Argo Rollouts vulnerability cloud-native kubernetes
1t 1c
critical advisory

CVE-2026-82266: Unauthenticated Redpanda Admin API Access

Redpanda versions 26.2.2 and earlier insecurely expose the Admin API on port 9644 by default without authentication enabled, allowing remote attackers to perform superuser actions.

Redpanda vulnerability remote-code-execution api-security
1r 1t 1c
high advisory

Remote Code Execution in Spinnaker rosco-manifests via Kustomize

The Spinnaker rosco-manifests package is vulnerable to remote code execution (RCE) via improper YAML processing during Kustomize bake operations, allowing attackers to execute arbitrary code on rosco pods.

rosco-manifests vulnerability rce ci-cd spinnaker
1t 1c
high advisory

MariaDB Node.js Connector Credential Disclosure via MitM

The MariaDB connector for Node.js (CVE-2026-55215) inadvertently sends database credentials during the handshake process before server identity is validated, enabling cleartext credential theft by an active man-in-the-middle.

mariadb +3 credential-theft vulnerability npm nodejs
1t 1c
high advisory

Pimcore Studio API Privilege Escalation via Class Definition Endpoint

An insufficient permission check in the Pimcore studio-backend-bundle allows authenticated users with standard object-editing privileges to create class definitions, leading to unauthorized schema modification and server-side file creation.

studio-backend-bundle +3 privilege-escalation cms vulnerability account-takeover cve-2026-55207 web-application-vulnerability
3r 4t 1c
low advisory

Unauthenticated Remote Denial of Service in alos-http

An unauthenticated remote denial-of-service vulnerability in alos-http allows attackers to crash the server process by sending a single malformed HTTP request starting with a '?' character.

alos-http dos vulnerability webserver
1r 1t 1c
high advisory

Wazuh Cluster Mode Insecure Deserialization Vulnerability (CVE-2026-25769)

An insecure deserialization vulnerability in Wazuh cluster communication allows a compromised worker node to achieve remote code execution as root on the master node.

Wazuh vulnerability rce
1c
high advisory

Stored Cross-Site Scripting Vulnerability in WP Rocket

WP Rocket versions up to and including 3.21.0.1 are vulnerable to unauthenticated Stored Cross-Site Scripting via the rocket_beacon AJAX endpoint.

WP Rocket web-application xss wordpress vulnerability
1r 1t 1c
high advisory

Path Traversal and Trust Inheritance Vulnerability in gitoxide

A path traversal and trust inheritance vulnerability in the gitoxide Rust crates allows attackers to access arbitrary git configurations by crafting malicious .gitmodules files.

gix +1 vulnerability supply-chain gitoxide rust
1t 1c
critical advisory

SSRF Vulnerability in SiYuan via DNS Rebinding

SiYuan versions prior to 3.8.1 are vulnerable to server-side request forgery through a DNS rebinding attack, enabling unauthorized access to cloud metadata services and internal network resources.

SiYuan +5 ssrf vulnerability cloud-security web-vulnerability xss information-disclosure credential-access cve-2026-85174 +8
2r 6t 1c updated
medium advisory

Multiple Denial of Service Vulnerabilities in FFmpeg

Multiple vulnerabilities in the FFmpeg multimedia framework can be exploited by a remote, anonymous attacker to trigger a Denial of Service condition, leading to service disruption.

FFmpeg vulnerability denial-of-service media-processing
1t
high advisory

Critical Vulnerability in n8n Allows Remote File Manipulation and Data Disclosure

A vulnerability in n8n allows a remote, unauthenticated attacker to manipulate files and disclose sensitive information on the platform, identified as CVE-2024-51746.

n8n vulnerability remote-code-execution security-advisory
1t 1c updated
high advisory

Multiple Vulnerabilities in Composer Dependency Manager

Composer contains multiple vulnerabilities that allow a remote attacker to bypass security restrictions and execute arbitrary code on systems using the dependency manager.

Composer vulnerability dependency-management rce
1t
high advisory

Multiple Vulnerabilities in SUSE Rancher

SUSE Rancher contains multiple vulnerabilities that enable unauthenticated attackers to trigger denial of service, perform unauthorized information disclosure, and bypass security controls.

Rancher vulnerability cloud-native suse
2t
high advisory

Remote Code Execution via Malicious Plugin Upload in Budibase

Authenticated administrators can exploit an insecure plugin handling mechanism in Budibase versions prior to 3.41.3 to achieve remote code execution via malicious JavaScript tarball uploads.

Budibase +1 vulnerability rce
1r 6t 1c
high advisory

Stored XSS via Authentication Bypass in Amelia WordPress Plugin

An unauthenticated stored Cross-Site Scripting (XSS) vulnerability in the Amelia WordPress plugin allows attackers to inject malicious scripts into appointment bookings, which execute in an administrator's browser context.

Amelia web-application xss wordpress vulnerability
2t 1c
high advisory

Multiple Vulnerabilities in ServiceNow Now Platform and AI Platform

ServiceNow Now Platform and AI Platform are vulnerable to multiple flaws enabling arbitrary code execution, privilege escalation, and SQL injection, risking full environment compromise.

Now Platform +1 vulnerability service-now cloud-security informational
3t
critical threat

Unauthenticated OS Command Injection in NUMail

NUMail contains an unauthenticated OS command injection vulnerability allowing remote attackers to execute arbitrary system-level commands on affected servers.

exploited NUMail remote-code-execution vulnerability web-application
2t 1c
high advisory

Unitree G1 EDU Firmware BLE Authentication Bypass and RCE

Unitree G1 EDU firmware versions 1.5.2 and earlier contain a chained vulnerability in the BLE GATT server and WiFi provisioning stack, allowing unauthenticated proximate attackers to achieve root-level remote code execution.

G1 EDU firmware iot rce vulnerability bluetooth
2t 1c
low advisory

CVE-2026-66384 - Improper Path Limitation in JFrog Artifactory

JFrog Artifactory suffers from a path traversal vulnerability that allows an authenticated user to write files to unauthorized locations on the server by manipulating remote-repository configurations.

Artifactory vulnerability path-traversal cisa-kev jfrog
1t 1c
critical advisory

Denial of Service Vulnerability in nltk PorterStemmer

An algorithmic complexity vulnerability in the nltk PorterStemmer module allows unauthenticated attackers to cause high CPU usage via specially crafted inputs.

nltk +3 vulnerability rce python java sandbox-bypass path-traversal library-vulnerability sandbox-escape +1
4t 1c updated
high advisory

SSRF Vulnerability in get-html-skeleton MCP Tool

The get-html-skeleton tool contains an SSRF vulnerability via insufficient URL validation, allowing remote callers to exfiltrate cloud instance metadata or internal credentials.

get-html-skeleton ssrf vulnerability cloud-security
2t 1c
critical threat

CVE-2026-81702 Key Substitution in openssl_encrypt

The openssl_encrypt library before 1.4.9 is vulnerable to key substitution attacks due to improper fingerprint validation when loading identities from local identity.json files.

exploited openssl_encrypt +2 cryptographic-vulnerability credential-theft cve-2026-81689 vulnerability cryptography denial-of-service cve-2026-81699
1t 1c
medium advisory

Security Vulnerabilities in Plesk Management Interface and Extensions

WebPros has released security updates for Plesk and its Migrator and Site Import extensions to address critical vulnerabilities CVE-2026-65642 and CVE-2026-65647.

Plesk +2 vulnerability patch-management web-hosting
2c
medium advisory

Remote Denial of Service Vulnerability in CPython

A remote denial of service vulnerability identified as CVE-2026-15310 exists in CPython, potentially allowing unauthenticated attackers to crash the interpreter via resource exhaustion.

CPython denial-of-service vulnerability
1c
high advisory

Critical Vulnerabilities in Adobe Campaign Classic

Adobe Campaign Classic is affected by three critical vulnerabilities, including SSRF and OS Command Injection, which allow unauthenticated remote attackers to achieve full system compromise.

Campaign Classic vulnerability remote-code-execution adobe ssrf
3c
high advisory

Critical Vulnerabilities in Ubiquiti UniFi Product Suite

Multiple high-severity vulnerabilities, including CVE-2026-77533 and CVE-2026-77537, affect Ubiquiti UniFi products, potentially allowing for system compromise.

UniFi Protect +2 vulnerability network-security
2c
medium advisory

Multiple Vulnerabilities in GNU Screen

GNU screen contains multiple vulnerabilities that enable a local attacker to perform privilege escalation, data manipulation, or unauthorized information disclosure.

screen vulnerability privilege-escalation linux
1t
high threat

Multiple Vulnerabilities in TeamViewer Client

TeamViewer clients are affected by multiple vulnerabilities that allow an unauthenticated or local attacker to execute arbitrary code with the privileges of the logged-in user.

exploited TeamViewer Client vulnerability remote-access code-execution
1t
medium advisory

Multiple Information Disclosure Vulnerabilities in Broadcom Brocade SANnav

Broadcom Brocade SANnav contains multiple vulnerabilities that could allow an unauthenticated or remote attacker to perform information disclosure, potentially exposing sensitive system or network data.

Brocade SANnav vulnerability information-disclosure storage-security
1t
high advisory

Multiple Vulnerabilities in CKAN

CKAN is affected by multiple vulnerabilities that allow remote attackers to conduct cross-site scripting (XSS) attacks, bypass security controls, and disclose sensitive information.

CKAN web-application vulnerability
1t
critical advisory

Multiple Vulnerabilities in Google Chrome and Microsoft Edge

Multiple vulnerabilities in Google Chrome and Microsoft Edge allow remote, unauthenticated attackers to achieve arbitrary code execution, bypass sandbox protections, and perform information disclosure.

Chrome +9 vulnerability browser-security patch-management
1t 2c updated
high threat

Path Traversal Vulnerability in with-context-mcp

A publicly disclosed path traversal vulnerability (CVE-2026-81491) in boxpositron with-context-mcp versions 3.0.7 and earlier allows remote attackers to manipulate file paths via specific ingested note functions.

exploited with-context-mcp path-traversal vulnerability remote-code-execution
1t 1c
high advisory

CVE-2026-15990 Directory Traversal in Formidable Charts Plugin

The Formidable Charts WordPress plugin is vulnerable to an unauthenticated directory traversal attack via the 'frm_graph' parameter, enabling arbitrary file read on the underlying server.

Formidable Charts vulnerability wordpress web-application
1r 2t 1c
high advisory

Multiple Vulnerabilities in Wibu-Systems CodeMeter Runtime

Multiple vulnerabilities in Wibu-Systems CodeMeter Runtime allow attackers to bypass security, disclose sensitive data, manipulate information, escalate privileges, or induce denial-of-service conditions.

CodeMeter Runtime vulnerability privilege-escalation dos
2t
high advisory

Veeam ONE Security Bypass Vulnerability

A vulnerability in Veeam ONE allows a remote, unauthenticated attacker to bypass security protections, potentially leading to unauthorized access to monitoring functions.

PoC Veeam ONE vulnerability remote-access monitoring
1t 1c updated
medium advisory

Information Disclosure Vulnerability in Veeam Backup & Replication

A local information disclosure vulnerability in Veeam Backup & Replication, identified as CVE-2024-40713, allows authenticated local attackers to gain unauthorized access to sensitive data.

Backup & Replication vulnerability information-disclosure
1t 1c
medium advisory

PolicyKit Local Denial of Service Vulnerability

A local, unprivileged attacker can exploit CVE-2024-41611 in PolicyKit to trigger a denial of service condition, potentially leading to system instability.

PolicyKit vulnerability denial-of-service linux
1c
high advisory

Multiple Vulnerabilities in GitLab

GitLab is affected by multiple vulnerabilities that allow remote code execution, denial of service, data manipulation, and security control bypass.

GitLab vulnerability application-security
2t
high advisory

Multiple Vulnerabilities in DNN Platform

DNN is affected by multiple high-severity vulnerabilities allowing attackers to achieve remote code execution, escalate privileges, and conduct SSRF or cross-site scripting attacks.

DNN vulnerability web-application cms
3t
critical threat

Active Exploitation of Windows IKE Extension RCE

CVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.

exploited Windows vulnerability remote-code-execution
2t 1c
high advisory

Unauthenticated Path Traversal in geyang/ml-logger

An unauthenticated path traversal vulnerability (CVE-2025-10951) in the geyang/ml-logger library enables attackers to perform arbitrary file access via the log_handler and stream_handler components.

ml-logger vulnerability path-traversal web-application
1t 1c
critical advisory

Unauthenticated Remote Code Execution in DB-GPT via Path Traversal

An unauthenticated path traversal vulnerability in DB-GPT allows remote attackers to write arbitrary files and achieve remote code execution by uploading malicious Python modules to the application server.

DB-GPT vulnerability rce path-traversal webserver
1r 2t 1c
high advisory

Authorization Bypass and SSRF in Dradis Community Edition

An authorization bypass vulnerability in Dradis Community Edition allows authenticated users to execute SSRF attacks by injecting malicious AI provider configurations.

Dradis Community Edition web-application ssrf vulnerability authorization-bypass
2t 1c
high advisory

Remote Code Execution via SSTI in mcp-contextforge-gateway

An authenticated Server-Side Template Injection (SSTI) vulnerability in mcp-contextforge-gateway version 0.9.0 and earlier allows attackers to achieve Remote Code Execution via unsandboxed Jinja2 template rendering.

mcp-contextforge-gateway ssti rce vulnerability
1r 1t
critical advisory

Vulnerabilities in Nokogiri Vendored libxml2 and libxslt Libraries

Nokogiri versions prior to 1.13.2 bundle vulnerable libxml2 2.9.12 and libxslt 1.1.34 libraries, exposing applications to denial of service, memory disclosure, and potential code execution.

Nokogiri +2 vulnerability memory-corruption libxslt
3c
high advisory

Public Exploit Released for Android Zygote CVE-2024-31317

A public proof-of-concept deployment script for CVE-2024-31317 enables local privilege escalation and arbitrary code execution on Android 9 through 13 by exploiting Zygote process command injection via the global settings API.

Android vulnerability privilege-escalation zygote
2t 1c
critical advisory

Unauthenticated Remote Code Execution in TRtek Software Repository Management

An unrestricted file upload vulnerability (CVE-2026-16286) in TRtek Software Repository Management enables unauthenticated attackers to upload web shells, leading to complete remote system compromise.

Software Repository Management vulnerability rce webserver
1r 2t 1c
high advisory

Arbitrary File Write Vulnerability in PraisonAI Agents

The FileMemory component in praisonaiagents versions 1.6.52 and earlier fails to sanitize user-supplied identifiers, enabling path traversal attacks that result in arbitrary JSON file creation or overwriting.

praisonaiagents vulnerability path-traversal python ssrf cloud-security authentication-bypass insecure-design api-security
5t 1c
high advisory

mcp-shell Insecure Configuration and Allowlist Bypass

mcp-shell versions prior to 0.6.0 suffer from default-disabled security settings and insecure allowlists, enabling unauthenticated arbitrary command execution via connected LLM agents.

PoC mcp-shell vulnerability rce mcp llm-security
2t
high advisory

Multiple Vulnerabilities in SEPPmail Secure E-Mail Gateway

SEPPmail Secure E-Mail Gateway contains multiple vulnerabilities that an attacker can exploit to bypass security controls and achieve remote code execution on the appliance.

Secure E-Mail Gateway vulnerability email-security remote-code-execution
1t
high advisory

Multiple Vulnerabilities in Contao CMS

Contao is affected by multiple vulnerabilities that may allow an unauthenticated or low-privileged attacker to bypass security controls, elevate privileges to administrator level, perform cross-site scripting (XSS) attacks, disclose sensitive information, and manipulate data.

Contao web-application cms vulnerability
3t
high advisory

Stored Cross-Site Scripting in NotificationX Pro WordPress Plugin

The NotificationX Pro plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping in versions up to and including 3.1.4.

NotificationX Pro web-application xss wordpress vulnerability
2t 1c
high advisory

Local File Inclusion Vulnerability in Verdure Core WordPress Plugin

An unauthenticated Local File Inclusion vulnerability in Verdure Core versions 1.2 and earlier allows remote attackers to execute arbitrary PHP code on affected WordPress sites.

Verdure Core lfi wordpress vulnerability web-application
1r 1c
low advisory

Arbitrary Code Execution Vulnerability in RPM Package Manager

A local vulnerability in the RPM package management utility allows an attacker to execute arbitrary code with the privileges of the user executing the command.

RPM vulnerability linux code-execution
1t 1c
low advisory

Data Manipulation Vulnerability in Devolutions Remote Desktop Manager

A vulnerability in Devolutions Remote Desktop Manager allows a remote, unauthenticated attacker to manipulate data, leading to unauthorized modification risks.

Remote Desktop Manager vulnerability remote-access
1c
high advisory

Arbitrary Code Execution Vulnerability in WebKitGTK

A memory corruption vulnerability (CVE-2025-23714) in WebKitGTK allows a remote, unauthenticated attacker to execute arbitrary code or trigger a denial-of-service via specially crafted web content.

WebKitGTK vulnerability memory-corruption linux
1t 1c
high advisory

CVE-2026-78637 Argument Injection in Fdawgs node-poppler

An argument injection vulnerability in the node-poppler package allows remote attackers to inject malicious command-line arguments via the file_path parameter.

node-poppler supply-chain vulnerability argument-injection
1t 1c
high advisory

CVE-2026-72700: Timing Vulnerability in Grav Login Plugin

The Grav login plugin for Composer is vulnerable to token-recovery via timing attacks due to non-constant-time string comparisons and a lack of rate limiting on password reset endpoints.

grav-plugin-login credential-access vulnerability web-application
1t 1c
high advisory

Remote Code Execution in GitPython via Git Config Injection

GitPython versions before 3.1.59 contain a vulnerability where improper sanitization of multi-line configuration values allows attackers to inject arbitrary git directives, leading to remote code execution.

GitPython +2 vulnerability path-traversal supply-chain info-disclosure local-file-inclusion
4t 1c updated
critical advisory

Remote Code Execution in Adminer via PDO DSN Injection

Adminer versions prior to 5.4.3 are vulnerable to unauthenticated remote code execution via DSN injection, allowing attackers to write arbitrary PHP files to the web root.

PoC Adminer +1 web-vulnerability rce cve-2026-56705 vulnerability web-application cve-2026-34968
3r 2t 4c updated
high advisory

Autodesk 3ds Max Out-of-Bounds Write Vulnerability (CVE-2026-16783)

Autodesk 3ds Max contains an out-of-bounds write vulnerability triggered by parsing maliciously crafted Alembic (.abc) files, potentially allowing arbitrary code execution upon user interaction.

3ds Max +1 vulnerability autodesk remote-code-execution
1t 1c
high advisory

NetworkManager Local Privilege Escalation and Credential Theft via CA Path Manipulation

An improper authorization vulnerability in NetworkManager allows unprivileged local users to bypass 802.1X server certificate validation, facilitating credential theft through rogue access points.

NetworkManager +7 credential-access local-privilege-escalation linux networking 802.1x vulnerability
1t 2c
high advisory

Dolibarr Members REST API Improper Authorization Vulnerability

An improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.

Dolibarr +2 vulnerability rest-api privilege-escalation cve-2026-71504 sqli web-vulnerability cve-2026-81730 path-traversal +1
2r 2t 1c updated
high advisory

CVE-2026-76836 - Improper Access Control in AzuraCast Leads to RCE

An improper access control vulnerability in AzuraCast allows low-privileged users to inject arbitrary commands into Liquidsoap configurations, leading to remote code execution upon backend restart.

AzuraCast web-application rce access-control vulnerability
2t 1c
high advisory

Command Injection Vulnerability in DrayTek VigorSwitch

Authenticated attackers can exploit a command injection flaw in the DrayTek VigorSwitch commandTable function to achieve root-level remote code execution.

VigorSwitch vulnerability remote-code-execution network-infrastructure
2t 1c
critical advisory

Critical OS Command Injection in DrayTek VigorSwitch

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.

VigorSwitch G2540xs +10 vulnerability remote-code-execution network-infrastructure cve network-security network hardware
1r 3t 1c
critical advisory

Authentication Bypass and Privilege Escalation in rConfig

rConfig versions 8.0.0 through 8.2.12 contain a logic flaw in route configuration that enables unauthenticated registration of administrator-privileged accounts, facilitating full system compromise.

rConfig vulnerability web-application authentication-bypass privilege-escalation
1r 1t
high advisory

Macro Injection Vulnerability in rpmbuild (CVE-2026-78367)

A macro injection vulnerability in rpmbuild allows remote attackers to achieve arbitrary code execution by convincing a user to process a specially crafted tarball.

Red Hat Enterprise Linux 7 +4 vulnerability rce rpmbuild rhel
1t 1c
high advisory

Remote Code Execution in Xinference via Unsafe Model Loading

Xinference versions prior to 2.12.0 are vulnerable to remote code execution because they unconditionally enable 'trust_remote_code=True' when loading models, allowing attackers to execute arbitrary Python code via crafted model configurations.

Xinference remote-code-execution vulnerability ai-security
1t 1c
high threat

SQL Injection Vulnerability in XBROTHER Dynamic Environment Monitoring System

An unauthenticated SQL injection vulnerability in the PlanController.getImmediatePlans function of the Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System allows remote attackers to execute arbitrary SQL commands.

exploited XBROTHER Dynamic Environment Monitoring System sql-injection vulnerability webserver
1r 1t 1c
critical advisory

OS Command Injection in 4MOSAn GCB Doctor

An unauthenticated OS command injection vulnerability in 4MOSAn GCB Doctor allows remote attackers to execute arbitrary system commands via an unremoved ADOdb test page.

GCB Doctor cve-2026-78211 command-injection vulnerability
1r 2t 1c
high advisory

Remote Code Execution via Out-of-Bounds Write in libwebsockets LECP Component

An out-of-bounds write vulnerability in the libwebsockets LECP CBOR recording function (CVE-2026-78161) allows remote attackers to trigger memory corruption via crafted CBOR data.

libwebsockets vulnerability remote-code-execution cbor
1t 1c
high advisory

Prototype Pollution Vulnerability in exceljs-hardened

The exceljs-hardened library before version 5.0.0 is vulnerable to prototype pollution, allowing unauthenticated remote attackers to inject malicious properties into Object.prototype via crafted cell note data.

exceljs-hardened +1 path-traversal vulnerability npm information-disclosure
4t 1c
high advisory

PHP Object Injection in PPWP Password Protect Pages Plugin

The PPWP WordPress plugin contains a PHP Object Injection vulnerability in the post_protection_roles parameter, allowing authenticated attackers to achieve remote code execution if a compatible POP chain exists in the environment.

PPWP wordpress php vulnerability deserialization webserver
1r 2t 1c
high advisory

Insufficient Access Control in docker-socket-proxy

An access control vulnerability in docker-socket-proxy (CVE-2026-78122) allows unauthenticated adjacent attackers to bypass restrictions and exfiltrate container filesystems via unauthorized API requests.

PoC docker-socket-proxy vulnerability container-security api-security
1r 1t 1c
high advisory

Authentication Bypass in AVideo via Parameter Manipulation

An authentication bypass vulnerability in AVideo (CVE-2026-59808) allows attackers with upload access to hijack administrative sessions via improper video ownership verification.

AVideo +6 authentication-bypass privilege-escalation web-application ssrf vulnerability credential-theft web-vulnerability path-traversal +4
7r 13t 1c updated
high advisory

Privilege Escalation in WPeMatico RSS Feed Fetcher Plugin for WordPress

An unauthenticated or low-privilege authenticated user can leverage a missing capability check in the wpematico_import_settings function to modify site options, enabling unauthorized privilege escalation.

WPeMatico RSS Feed Fetcher wordpress privilege-escalation vulnerability
1t 1c
medium advisory

Uncontrolled Resource Consumption in kin-openapi deepObject Decoder

An unauthenticated remote attacker can cause a denial-of-service via memory exhaustion by supplying a large integer index in a 'deepObject' style query parameter.

kin-openapi +1 denial-of-service memory-exhaustion vulnerability golang
1t
critical advisory

Unauthenticated SQL Injection in GeoTools PostGIS DataStore

A critical unauthenticated SQL injection vulnerability (CVE-2026-76904) in the GeoTools library allows remote attackers to execute arbitrary SQL via the jsonArrayContains filter function.

PoC GeoTools sql-injection vulnerability application-security
1t 1c updated
high advisory

Integer Overflow in GNU Emacs PBM/PPM/PGM Image Loader (CVE-2026-77219)

GNU Emacs versions prior to 31.0.91 are susceptible to an integer overflow vulnerability in the PBM/PPM/PGM image loader, potentially leading to heap memory disclosure.

Emacs +1 vulnerability command-injection local-exploitation
1t 1c updated
high advisory

Command Injection in Unix-like Artifacts Collector

Unix-like Artifacts Collector (UAC) versions prior to 3.3.0 are vulnerable to command injection via the _command_collector function, allowing arbitrary command execution through malicious filenames or artifact definitions.

Unix-like Artifacts Collector vulnerability command-injection forensic-tooling
1t 1c
critical advisory

Authentication Bypass in Headroom LLM Proxy via Header Spoofing

The Headroom LLM proxy improperly derives memory ownership from the unauthenticated 'x-headroom-user-id' request header, allowing attackers to perform unauthorized read and write operations on arbitrary user LLM memory.

LLM proxy identity-spoofing cve web-application-vulnerability web-application ssrf vulnerability
2r 2t 1c
high advisory

Multiple Vulnerabilities in VMware Tanzu Spring Security

Multiple vulnerabilities in VMware Tanzu Spring Security, tracked as CVE-2024-22259 and CVE-2024-22262, allow remote attackers to perform file manipulation, information disclosure, cross-site scripting (XSS), and security control bypass.

Tanzu Spring Security vulnerability web-security
2c
high advisory

Authorization Bypass in Reconmap Report Preview Endpoint

An improper [AllowAnonymous] attribute in Reconmap's ReportsController allows unauthenticated remote attackers to perform enumeration of sensitive penetration testing engagement data by walking sequential project IDs.

Reconmap vulnerability authentication-bypass cve-2026-77767
1t 1c
high advisory

Authentication Bypass in ArchitectPanel Web Admin Panel

An Execution After Redirect (EAR) vulnerability in ArchitectPanel Web Admin Panel allows unauthenticated attackers to bypass authentication and gain unauthorized access.

ArchitectPanel Web Admin Panel vulnerability authentication-bypass web-application
1t 1c
high advisory

NLTK TweetTokenizer Regular Expression Denial of Service

The NLTK library's TweetTokenizer is vulnerable to a ReDoS attack due to an unbounded regular expression, allowing unauthenticated attackers to trigger CPU exhaustion.

NLTK +1 vulnerability file-system python
2t 1c updated
high advisory

Information Disclosure in Red Hat Advanced Cluster Management via HelmRelease Manipulation

An authenticated user with HelmRelease creation permissions can exploit CVE-2026-73137 to exfiltrate sensitive credentials from arbitrary Kubernetes namespaces in Red Hat Advanced Cluster Management.

Advanced Cluster Management exfiltration vulnerability cloud kubernetes
1t 1c
high advisory

OTRS Community Edition Authenticated OS Command Injection

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands.

OTRS Community Edition vulnerability remote-code-execution
1t 1c
high advisory

Red Hat Advanced Cluster Management Lighthouse Component DNS Hijacking

A vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to perform Man-in-the-Middle attacks via malicious EndpointSlice advertisements.

Advanced Cluster Management for Kubernetes kubernetes vulnerability cloud-native cve
2t 1c
high advisory

Credential Guessing Vulnerability via WildFly Elytron Unicode Normalization

A vulnerability in WildFly Elytron's password normalization logic allows attackers to bypass intended password character entropy, facilitating unauthorized access through dictionary-based credential guessing.

Red Hat build of Apache Camel 4 for Quarkus 3 +5 credential-access vulnerability middleware
1t 1c
high advisory

Laravel Backpack CRUD Mass Assignment Vulnerability

An authenticated mass-assignment vulnerability in Laravel Backpack CRUD allows an attacker with a session to update arbitrary user model attributes, leading to password reset, email hijacking, or privilege escalation.

CRUD vulnerability web-application php laravel
2t
medium advisory

Unauthenticated CPU Exhaustion DoS in netty-incubator-codec-bhttp

An infinite loop vulnerability in the BinaryHttpParser of netty-incubator-codec-bhttp allows unauthenticated attackers to exhaust event-loop threads and induce a persistent denial of service via specially crafted BHTTP requests.

netty-incubator-codec-bhttp +1 denial-of-service vulnerability netty
1t
high advisory

Memory Corruption Vulnerability in liftoff-sr CIPster

A remote memory corruption vulnerability in the Generic Attribute Logic component of liftoff-sr CIPster allows for unauthenticated exploitation via the GetAttrData and SetAttrData functions.

CIPster vulnerability cve-2026-76987 memory-corruption
1c
low advisory

Denial of Service Vulnerability in FreeIPA Migration Handler

An unauthenticated remote denial-of-service vulnerability in FreeIPA, tracked as CVE-2026-73197, allows attackers to exhaust system memory by sending oversized form POST requests to the migration endpoint.

FreeIPA +4 denial-of-service vulnerability cve-2026-73197
1r 1t 1c
medium advisory

Information Disclosure Vulnerability in Octopus Deploy Server

An authenticated remote attacker can exploit a vulnerability in Octopus Deploy Server to perform unauthorized information disclosure.

Octopus Deploy Server vulnerability information-disclosure
1t 1c
medium advisory

Multiple Vulnerabilities in Cisco Industrial Ethernet 1000 Series Switches

Cisco Industrial Ethernet 1000 Series Switches contain multiple vulnerabilities, including CVE-2024-20412, CVE-2024-20413, and CVE-2024-20414, which allow unauthenticated attackers to cause a denial-of-service or perform cross-site scripting attacks.

Industrial Ethernet 1000 Series Switches vulnerability industrial-control-systems network-security
1t 3c
high advisory

Multiple Vulnerabilities in Cisco Secure Workload

Cisco Secure Workload is affected by multiple vulnerabilities allowing unauthenticated remote attackers to execute arbitrary code, escalate privileges, and cause service disruptions.

Secure Workload vulnerability cisco network-security
2t
medium advisory

SQL Injection Vulnerability in Cisco Unified Intelligence Center

A vulnerability in the Cisco Unified Intelligence Center allows a remote, authenticated attacker to perform a SQL injection attack due to insufficient input validation.

Unified Intelligence Center sqli vulnerability cisco
1t
high advisory

Multiple Vulnerabilities in n8n Workflow Automation

Multiple vulnerabilities in n8n allow a remote, authenticated attacker to achieve remote code execution, bypass security controls, perform SSRF, and manipulate sensitive data.

n8n +3 vulnerability workflow-automation
2t updated
low advisory

Security Control Bypass in MLflow

A vulnerability in the MLflow machine learning lifecycle platform allows unauthenticated remote attackers to bypass security controls, resulting in potential data disclosure or unauthorized data manipulation.

MLflow vulnerability data-integrity security-bypass
1t 1c
high advisory

Integer Overflow Vulnerability in libvirt NodeGetFreePages RPC Handler

An integer overflow vulnerability (CVE-2026-18917) in the libvirt NodeGetFreePages RPC handler allows an unprivileged local user to trigger a heap buffer overflow and achieve potential local privilege escalation.

libvirt +5 vulnerability local-privilege-escalation linux
1t 1c
critical advisory

Insufficient Session Expiration in Frauscher Sensortechnik FDS 102

CVE-2026-14950 is an insufficient session expiration vulnerability in Frauscher Sensortechnik FDS 102 that allows an attacker with a valid session identifier to maintain access beyond the intended expiration time.

FDS 102 +3 cve vulnerability rce industrial-control-system path-traversal cve-2026-14948 session-hijacking information-disclosure +4
3r 7t 1c
high advisory

Stack-Based Buffer Overflow in Binutils (CVE-2026-19582)

A stack-based buffer overflow vulnerability in binutils versions 2.46.1 and prior allows attackers to achieve arbitrary code execution by enticing a victim to process a maliciously crafted Portable Executable (PE) file.

binutils +3 vulnerability cve memory-corruption
1t 1c
high advisory

Remote Code Injection in chenhg5 cc-connect

An unauthenticated remote code injection vulnerability in the Authenticate function of chenhg5 cc-connect (up to 1.4.1) allows attackers to execute arbitrary code via the exec parameter.

cc-connect vulnerability remote-code-execution injection web-application
1r 2t 1c
high advisory

Privilege Escalation in Splunk AI Toolkit via Agent Run History

A privilege escalation vulnerability in Splunk AI Toolkit versions prior to 6.0.0 allows non-privileged users to execute searches with system-level permissions by exploiting an insecure session token replacement mechanism in the Agent Run History handler.

AI Toolkit +1 vulnerability remote-code-execution
2t 1c
high advisory

Privilege Escalation in Splunk Enterprise Security via UEBA Search Macros

Splunk Enterprise Security versions below 8.6.1 contain a privilege escalation vulnerability where users with the ess_analyst role can modify UEBA search macros, allowing for unauthorized execution of administrative queries.

Enterprise Security privilege-escalation splunk vulnerability
1t 1c
high advisory

Arbitrary Code Execution in Splunk SOAR via Path Traversal

Splunk SOAR versions prior to 8.6.0 are vulnerable to authenticated remote code execution due to improper path validation and insufficient role-based access control on the REST API.

SOAR +1 vulnerability rce splunk
1t 1c updated
high advisory

Remote Command Injection in TRENDnet TEW-821DAP

TRENDnet TEW-821DAP firmware version 2.2.01b05 is vulnerable to remote command injection via the /cgi-bin/ping.cgi endpoint, allowing authenticated attackers to execute arbitrary system commands.

TEW-821DAP command-injection network-device vulnerability
1r 1t 1c
high advisory

IBM Portieris Image Policy Enforcement Bypass

IBM Portieris versions 0.5.0 through 0.14.2 contain a missing authorization vulnerability that allows authenticated attackers to bypass image policy enforcement by manipulating pod owner references.

Portieris vulnerability kubernetes ibm security-policy
1t 1c
critical threat

Stack-based Buffer Overflow in TRENDnet TEW-755AP Access Points

A critical stack-based buffer overflow vulnerability in the /sbin/mycli binary of TRENDnet TEW-755AP access points allows remote unauthenticated attackers to execute arbitrary code via the 'ssid' argument.

exploited TEW-755AP remote-code-execution buffer-overflow iot networking vulnerability network-security cve-2026-76590 cve-2026-76591 +2
2r 3t 1c
high advisory

Arbitrary Local File Read and Write in claude-faf-mcp

The claude-faf-mcp MCP server exposes arbitrary file read and write primitives through unconfined path parameters, allowing LLM-based prompt injection to access sensitive local files or modify system files.

claude-faf-mcp vulnerability mcp path-traversal arbitrary-file-read arbitrary-file-write
2t
high advisory

Copier Trust-Prefix Bypass via Path Traversal

Copier versions 9.5.0 through 9.15.1 contain an authorization bypass vulnerability in the 'trust' configuration where insufficient path normalization allows attackers to execute arbitrary tasks by traversing out of trusted template prefixes.

copier vulnerability rce supply-chain
2t
high advisory

GeoServer Server-Side Template Injection Vulnerability

An authenticated administrator can exploit a server-side template injection (SSTI) vulnerability in GeoServer's FreeMarker engine to execute arbitrary OS commands and perform unauthorized file operations.

gs-main +2 vulnerability rce geoserver
1t
critical advisory

Critical RCE Vulnerability in IBM Power Systems Firmware ASMI

IBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.

Power Systems Firmware vulnerability remote-code-execution firmware hardware
2t 1c
high advisory

Stack-Based Buffer Overflow in IBM Power Firmware

A stack-based buffer overflow in the firmware boot image validation process of specific IBM Power Firmware versions allows attackers with service processor access to execute arbitrary code on the host system.

Power Firmware vulnerability firmware ibm cve-2026-19234
2t 1c
high advisory

Heap-based Buffer Overflow in FFmpeg hvcC Box Writer

FFmpeg versions prior to commit acf5d7c contain a heap-based buffer overflow in the hvcC box writer that can be triggered during HEVC file muxing, potentially leading to arbitrary code execution.

FFmpeg +2 vulnerability memory-corruption memory-safety
1t 1c
high advisory

Exposure of Certificate Authority Private Keys in IBM AIX and PowerVM VIOS

IBM AIX 7.2, 7.3, and PowerVM VIOS 4.1 contain intermediate CA private keys within publicly available update files, potentially allowing remote attackers to bypass security restrictions.

AIX +5 vulnerability cve-2026-15065 ibm security-bypass denial-of-service privilege-escalation kernel-vulnerability powervm
3t 1c updated
high advisory

Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

Citrix has released patches for critical vulnerabilities including CVE-2026-19490, an authentication bypass, and CVE-2026-19489, a memory overflow vulnerability affecting NetScaler ADC and Gateway appliances.

PoC NetScaler ADC +3 vulnerability network-infrastructure authentication-bypass
2c updated
low advisory

Cryptographic Implementation Vulnerabilities in libcrux

Multiple cryptographic implementation vulnerabilities in the libcrux library (CVE-2026-76234) allow for denial of service and improper cryptographic validation.

libcrux-ecdh +2 vulnerability cryptographic-flaw library-vulnerability
1c
high advisory

Vim Netrw Plugin Arbitrary Code Execution

A vulnerability in the Vim netrw plugin allows for arbitrary Vimscript execution through crafted filenames, enabling attackers to execute system commands with user privileges.

Vim code-injection vulnerability rce
1r 1t 1c
medium advisory

Information Disclosure Vulnerability in Insyde UEFI Firmware

A local attacker can exploit a vulnerability in Insyde UEFI firmware to gain unauthorized access to sensitive information during the system boot or runtime.

UEFI Firmware firmware vulnerability information-disclosure
1t
high advisory

Cross-Site Scripting Vulnerability in IBM App Connect Enterprise

IBM App Connect Enterprise contains a vulnerability, identified as CVE-2024-44280, that allows a remote, anonymous attacker to execute Cross-Site Scripting (XSS) attacks within the context of the affected application.

App Connect Enterprise xss web-vulnerability vulnerability remote-code-execution ibm security-advisory
1t 1c updated
high advisory

Remote Code Execution Vulnerability in Red Hat OpenShift Container Platform

A critical remote code execution vulnerability, tracked as CVE-2024-8979, allows unauthenticated remote attackers to execute arbitrary code within the Red Hat OpenShift Container Platform environment.

OpenShift Container Platform vulnerability cloud-security rce
1c
low advisory

Multiple Vulnerabilities in Oracle Hyperion

Oracle has disclosed a series of 25 vulnerabilities affecting Hyperion, enabling remote, anonymous, or authenticated attackers to compromise system confidentiality, integrity, and availability.

Hyperion vulnerability enterprise-software patch-management
2c
critical advisory

Stack-Based Buffer Overflow in UTT HiPER 1250GW

A critical stack-based buffer overflow vulnerability in the UTT HiPER 1250GW HTTP handler allows remote authenticated attackers to execute arbitrary code via a crafted 'pvid' parameter.

HiPER 1250GW vulnerability cve network-security
2r 1t 1c updated
critical advisory

Remote Stack-based Buffer Overflow in TRENDnet TV-IP751WIC

A critical stack-based buffer overflow vulnerability (CVE-2026-75877) in the TRENDnet TV-IP751WIC alphapd component allows remote attackers to execute arbitrary code via multiple affected functions.

TV-IP751WIC vulnerability cve iot rce
2r 3t updated
high advisory

Authorization Bypass in Lemur Leading to Unauthorized Certificate Revocation

An authorization bypass vulnerability in Lemur allows authenticated users to revoke arbitrary certificates by creating duplicate certificate records and bypassing ownership and endpoint-attached safeguards.

lemur +2 certificate-management authorization-bypass cve-2026-71417 cloud ssrf vulnerability cve-2026-70666
1r 5t 1c
high advisory

Multiple Vulnerabilities in CISA Malcolm Network Analysis Suite

Multiple vulnerabilities in CISA Malcolm, including RCE, path traversal, and resource exhaustion, allow authenticated attackers to execute arbitrary code or cause denial-of-service.

CISA Malcolm vulnerability cisa rce dos
1r 2t 3c
high advisory

SSRF Bypass in CodeWhale via DNS Pinning TOCTOU

CodeWhale versions before 0.8.64 contain a time-of-check-time-of-use vulnerability in DNS pinning logic, allowing attackers to bypass SSRF mitigations and access internal resources.

CodeWhale +2 vulnerability argument-injection code-execution remote-code-execution credential-theft
5t 1c
high advisory

SSRF Vulnerability in RAGFlow Agent Workflow

RAGFlow before 0.26.3 contains a server-side request forgery (SSRF) vulnerability in the 'Invoke' component that allows attackers to access sensitive internal network resources and cloud metadata.

PoC RAGFlow ssrf vulnerability cloud-security
2t 1c updated
low advisory

Expat Denial of Service Vulnerability (CVE-2026-66046)

The Expat library through version 2.8.3 contains an algorithmic complexity vulnerability in its XML attribute parsing logic that allows unauthenticated attackers to cause CPU exhaustion and denial of service.

Expat denial-of-service vulnerability cve-2026-66046
1c
high advisory

Argument Injection Vulnerability in CodeWhale git_show Tool

An argument injection vulnerability (CVE-2026-75913) in the CodeWhale git_show tool allows attackers to perform arbitrary file writes under the user's privilege level by manipulating the 'rev' parameter.

PoC codewhale +6 remote-code-execution configuration-vulnerability developer-tools vulnerability code-execution authorization-bypass path-traversal data-exfiltration +5
1r 5t 3c updated
high advisory

Credential Exfiltration via AAP Controller Vault Plugin

A vulnerability in the Red Hat Ansible Automation Platform controller allows authenticated attackers to exfiltrate Kubernetes service account tokens via the HashiCorp Vault credential plugin.

Ansible Automation Platform credential-access exfiltration vulnerability
1t 1c
high advisory

SQL Injection Vulnerability in SuiteCRM

An authenticated remote attacker can exploit a SQL injection vulnerability in SuiteCRM to potentially gain unauthorized database access or manipulate backend data.

SuiteCRM web-application sqli vulnerability
1t
medium advisory

Grafana Improper Access Control Information Disclosure Vulnerability

An authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.

Grafana informational product-news directory-traversal vulnerability web-application xss security-advisory denial-of-service
3t 1c updated
medium advisory

Multiple Vulnerabilities in Icinga Web

Remote attackers can exploit multiple vulnerabilities in Icinga Web to conduct Denial of Service attacks or disclose sensitive information due to improper request handling.

Icinga Web vulnerability webserver
1t 2c
critical advisory

Critical SQL Injection Vulnerability in GeoServer

A critical vulnerability in GeoServer allows remote, unauthenticated attackers to perform SQL injection attacks, potentially leading to remote code execution.

GeoServer sql-injection vulnerability gis
1t
medium threat

Denial of Service Vulnerability in NanaZip UFS Codec

NanaZip 6.5 and earlier are vulnerable to a denial-of-service attack due to an unbounded memory allocation in the UFS codec handler triggered by a malicious fs_bsize value in a UFS image file.

NanaZip Jorge González Milla dos vulnerability file-processing
2t 1c
high advisory

Missing Authorization Vulnerability in ArcadeDB DELETE FUNCTION Statement

ArcadeDB versions 26.7.3 and earlier are vulnerable to a missing authorization flaw allowing any authenticated database user to delete server-side functions via the command API.

ArcadeDB +2 vulnerability privilege-escalation database-security remote-code-execution
1r 3t 1c updated
high advisory

Path Traversal Vulnerability in AKINSOFT Wolvox9 ERP

A path traversal vulnerability (CVE-2026-15585) in AKINSOFT Wolvox9 ERP KontrolPanel.exe versions s26.02.17 through s26.02.21 allows unauthenticated remote attackers to read arbitrary files from the host filesystem.

AKINSOFT Wolvox9 ERP vulnerability path-traversal erp
1t 1c
critical advisory

Authentication Bypass and Privilege Escalation in ArcadeDB

ArcadeDB versions before 26.8.1 contain a vulnerability in the gRPC transaction executor that allows authenticated readers to execute arbitrary JavaScript, leading to server-wide privilege escalation.

ArcadeDB privilege-escalation database-security cve-2026-75843 vulnerability authentication-bypass arbitrary-file-read sandbox-bypass cve-2026-75840 +3
1r 5t 1c
critical advisory

Authentication Bypass in Bastillion via Path Prefix Misrouting

An authentication bypass vulnerability (CVE-2026-75627) in Bastillion versions 5.1.0 and earlier allows unauthenticated attackers to access administrative controllers via path prefix manipulation, enabling full control over managed SSH infrastructure.

Bastillion vulnerability authentication-bypass ssh-gateway
1r 2t 1c
low advisory

Denial of Service Vulnerability in libpng

A vulnerability in libpng allows a remote, anonymous attacker to trigger a Denial of Service (DoS) condition via specially crafted image input, leading to potential application instability.

libpng vulnerability denial-of-service
1t 1c
high advisory

Authorization Bypass Vulnerability in WPAdverts Classifieds Plugin

The WPAdverts - Classifieds Plugin for WordPress up to version 2.3.2 is vulnerable to an authorization bypass allowing unauthenticated attackers to exfiltrate internal configuration data via the REST API.

WPAdverts - Classifieds Plugin wordpress vulnerability information-disclosure
1r 1t 1c
critical advisory

Command Injection Vulnerability in COMFAST CF-N1-S

A critical command injection vulnerability (CVE-2026-75094) in the COMFAST CF-N1-S CGI interface allows remote, authenticated attackers to execute arbitrary OS commands via the 'ssid' parameter.

CF-N1-S vulnerability rce network-infrastructure
3r 2t 1c updated
high advisory

Unbounded Gzip Decompression Denial of Service in http4k

The http4k library fails to limit the size of decompressed gzip data, allowing unauthenticated remote attackers to trigger JVM heap exhaustion via small, highly compressed payloads.

http4k-core denial-of-service vulnerability web-server
1t
high advisory

Missing Authorization in Determined API Endpoints (CVE-2026-75109)

Determined AI's Determined platform fails to authorize API requests for generic task management, allowing authenticated attackers to disrupt workloads by terminating or pausing tasks owned by other users.

Determined vulnerability access-control cloud
1c
high advisory

Out-of-Bounds Read in TIER IV Nebula

TIER IV Nebula through 1.2.0 is vulnerable to an out-of-bounds read in the Vlp32Decoder::unpack function, allowing remote attackers to inject fabricated point cloud data via malformed UDP packets.

Nebula vulnerability iot robotics
1t 1c
high advisory

Incomplete Fix for Glances Configuration Command Execution Bypass

Glances versions up to 4.5.5 contain a vulnerability where the --disable-config-exec flag fails to sanitize shell operators in on-alert action commands, allowing arbitrary command execution or file redirection.

Glances +1 vulnerability remote-code-execution security-bypass command-injection local-privilege-escalation
2t 2c
medium advisory

SQLParse CPU Denial of Service via Algorithmic Complexity

A complexity vulnerability in sqlparse <= 0.5.5 allows attackers to trigger CPU exhaustion through deeply nested SQL structures, achieving significant amplification and causing denial of service in downstream applications.

sqlparse dos algorithmic-complexity cve-2026-54284 denial-of-service vulnerability
1t 1c
critical threat

Unauthenticated Remote Code Execution in D-Link NAS Devices

Multiple D-Link NAS devices are vulnerable to unauthenticated OS command injection via the account_mgr.cgi script, allowing remote attackers to execute arbitrary commands with root privileges.

exploited DNS-320 +3 remote-code-execution nas hardware vulnerability
1r 1t 1c
high threat

phpSysInfo IP Allowlist Bypass

A vulnerability in phpSysInfo 3.4.5 and earlier allows unauthenticated attackers to bypass IP-based access controls by spoofing HTTP headers, potentially exposing sensitive system information via xml.php.

exploited phpSysInfo web-application vulnerability cve-2026-55584
1r 1t
high advisory

Insufficiently Protected Credentials in Logsign SIEM

Logsign SIEM versions 6.4.97 through 6.4.113 are vulnerable to an insufficiently protected credentials flaw, allowing privileged users to retrieve embedded sensitive data (CVE-2026-14564).

Logsign SIEM vulnerability credential-theft logsign
1c
critical advisory

Arbitrary Code Execution in openssl_encrypt Library

The openssl_encrypt library before version 1.4.0 contains a vulnerability in its Whirlpool hash implementation that allows arbitrary code execution via untrusted shared object loading.

openssl_encrypt +1 vulnerability rce python supply-chain library-vulnerability cryptography cve-2026-74876 authentication-bypass +6
1r 8t 1c
medium advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux glib2

Multiple vulnerabilities in the glib2 library for Red Hat Enterprise Linux, identified as CVE-2024-52532 and CVE-2024-52533, allow remote attackers to perform denial-of-service attacks or achieve information disclosure.

Enterprise Linux vulnerability linux rhel glib2 privilege-escalation
1t 2c updated
high advisory

Authorization Bypass in GL.iNet WebDAV Service

Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.

A1300 +16 cve-2026-19980 remote-code-execution network-security firmware-vulnerability vulnerability rce network-infrastructure
1r 2t 1c
critical advisory

Stack-based Buffer Overflow in Edimax EW-7478APC

Edimax EW-7478APC version 1.04 is vulnerable to a stack-based buffer overflow in the formWanTcpipSetup function, allowing for remote code execution via the pppUserName parameter.

EW-7478APC remote-code-execution buffer-overflow router cve-2026-19961 vulnerability network-device cve
3r 2t 1c
high advisory

Denial of Service via SVG ViewBox Exploitation in stoatchat

stoatchat versions prior to 0.15.0 contain an uncontrolled resource consumption vulnerability in its proxy endpoint that allows unauthenticated attackers to cause memory exhaustion through malicious SVG files.

stoatchat denial-of-service cve vulnerability authorization-bypass cve-2026-74869 privacy
2t 1c updated
critical advisory

Access-Modifier Bypass in Scriban

Scriban versions prior to 7.2.2 contain an access-modifier bypass in TypedObjectAccessor that allows unauthorized modification of private, internal, or init-only CLR object properties via template injection.

Scriban +3 vulnerability dot-net template-injection access-control sandbox-bypass cve-2026-74790 .net denial-of-service +1
3t 1c
high advisory

Arbitrary File Deletion in ProSolution WP Client Plugin

An unauthenticated arbitrary file deletion vulnerability in the ProSolution WP Client plugin allows attackers to remove critical WordPress configuration files, potentially facilitating remote code execution.

WP Client wordpress arbitrary-file-deletion vulnerability
1r 2t 1c
critical advisory

Authentication Bypass in Tenda AC10 Router

An improper authentication vulnerability in the Tenda AC10 router's httpd component allows remote, unauthenticated attackers to gain unauthorized access to the device.

AC10 vulnerability authentication-bypass cve-2026-19924
1t 1c
high advisory

SQL Injection Vulnerability in Jinher OA 1.0

Jinher OA 1.0 is vulnerable to remote SQL injection via the 'httpOID' parameter in a specific attendance approval module, allowing attackers to execute arbitrary database queries.

OA sql-injection vulnerability web-application
1r 1t 1c
high advisory

Chromium Use-After-Free in Extensions

A use-after-free vulnerability in the Chromium Extensions component allows for potential arbitrary code execution or application instability across affected browsers.

Chrome +1 vulnerability browser web-security
1c
high advisory

ZeroBrew Arbitrary Code Execution via Missing Integrity Verification

ZeroBrew version 0.3.1 and prior fails to validate checksums for formula resources, allowing attackers to perform supply chain attacks via intercepted network traffic during the build process.

ZeroBrew supply-chain rce vulnerability
1t 1c
high advisory

SQL Injection in SourceCodester Simple Client Management System

An unauthenticated remote SQL injection vulnerability exists in the SourceCodester Simple Client Management System 1.0 that allows attackers to manipulate database queries via the ID parameter.

Simple Client Management System sqli vulnerability web-application
1r 1t 1c
high advisory

Remote Stack-Based Buffer Overflow in Tenda W20E

A stack-based buffer overflow vulnerability in Tenda W20E firmware allows authenticated remote attackers to achieve potential code execution via the QoS Edit component.

W20E cve-2026-19822 vulnerability remote-code-execution cve-2026-19823 buffer-overflow rce network-infrastructure
2r 3t 1c
critical advisory

Critical Remote Code Execution Vulnerability in Exim MTA

Exim is affected by a critical vulnerability (CVE-2024-39929) that allows a remote, unauthenticated attacker to execute arbitrary code via a logic error in header field processing.

PoC Exim vulnerability remote-code-execution mail-server
1t 1c updated
high advisory

Privilege Escalation Vulnerability in Sophos Endpoint Products for macOS

A local privilege escalation vulnerability, tracked as CVE-2026-18367, affects multiple Sophos endpoint security products on macOS, potentially allowing authenticated local users to gain elevated system privileges.

Intercept X Endpoint +1 vulnerability privilege-escalation macos
1t 1c
high advisory

Multiple Vulnerabilities in PostgreSQL

PostgreSQL has released patches for multiple high-severity vulnerabilities across several versions that could allow remote attackers to achieve arbitrary code execution, perform SQL injection, or conduct denial-of-service attacks.

PoC PostgreSQL 14 +5 vulnerability database security-patch
5c updated
low advisory

Remote Denial of Service Vulnerability in OpenSSL

A vulnerability (CVE-2026-14456) in OpenSSL versions 3.5.x, 3.6.x, and 4.0.x allows remote attackers to trigger a denial of service condition.

OpenSSL 3.5 +2 denial-of-service vulnerability openssl
1c
high threat

Remote Stack-based Buffer Overflow in TOTOLINK A800R

An authenticated remote attacker can trigger a stack-based buffer overflow in the TOTOLINK A800R router via the setIpQosRules function, potentially leading to arbitrary code execution.

exploited A800R +1 remote-code-execution cve-2026-19811 router-vulnerability cve-2026-19812 buffer-overflow router rce vulnerability +1
2r 2t 1c
high advisory

Stack-Based Buffer Overflow in Tenda AC1206 Web Interface

A stack-based buffer overflow in the Tenda AC1206 firmware version 15.03.06.23_multi_TD01 allows remote attackers to trigger memory corruption via the httpd web management interface.

AC1206 vulnerability remote-code-execution network-security buffer-overflow
1r 1t 1c
high advisory

Path Traversal Vulnerability in DTStack Taier

DTStack Taier 1.4.0 is susceptible to a remote path traversal vulnerability (CVE-2026-19762) in the Chunk-Check endpoint, allowing unauthenticated attackers to manipulate file paths.

Taier vulnerability path-traversal
1r 1t 1c
high advisory

Prototype Pollution in Trigger.dev Run Metadata API

An unauthenticated-accessible prototype pollution vulnerability in the Trigger.dev metadata API allows low-privileged attackers to corrupt the global object, leading to cross-tenant denial of service and process crashes via CVE-2026-73654.

trigger.dev prototype-pollution rce vulnerability webserver
1r 1t 1c
high advisory

Hardcoded Authentication Token in IBM Storage Scale GUI

IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 contain a hardcoded token used for inter-node communication and REST API authentication, allowing potential unauthenticated access to the GUI.

Storage Scale 5.2.3.0 through 5.2.3.8 +2 vulnerability authentication-bypass cve-2026-13460
2t 1c
critical advisory

Remote Code Execution in IBM Documentation Offline

IBM Documentation Offline versions 1.0.0 through 1.4.1 are vulnerable to remote code execution due to improper control of file paths (CVE-2026-17482), allowing unauthenticated attackers to compromise affected systems.

Documentation Offline vulnerability rce cve
2t 1c
high threat

Unauthenticated SQL Injection and Authentication Bypass in Hongjing e-HR

Hongjing e-HR contains an unauthenticated SQL injection and path traversal vulnerability (CVE-2024-58374) allowing attackers to bypass authentication and exfiltrate database contents via the getSdutyTree servlet.

exploited e-HR vulnerability sql-injection web-application cve-2024-58374
1r 2t 1c
critical advisory

Red Hat Multicluster Engine Confused Deputy Vulnerability

An authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.

Multicluster Engine for Kubernetes cve-2026-73266 kubernetes privilege-escalation multitenancy cloud-native vulnerability cve-2026-66794 supply-chain
4t 1c updated
high advisory

Out-of-Bounds Read Vulnerability in PostGIS FlatGeobuf Decoder

PostGIS versions prior to 3.7.0beta2 are vulnerable to an out-of-bounds read in the FlatGeobuf property metadata decoder, allowing authenticated attackers to trigger a denial of service or perform memory disclosure via malformed input.

PostGIS vulnerability memory-corruption
1t 1c
high advisory

Arbitrary Code Execution in Siemens Simcenter Femap

Siemens Simcenter Femap is susceptible to arbitrary code execution via two out-of-bounds read vulnerabilities when parsing specially crafted BMP files.

Simcenter Femap +1 vulnerability industrial-control-systems ics cve-2026-59086 stack-overflow rce
2t 1c updated
high advisory

Multiple Vulnerabilities in ANDRITZ HIPASE-250 and 250 SCALA

ANDRITZ HIPASE-250 and 250 SCALA devices (versions <=7.20) contain multiple high-severity vulnerabilities, including hard-coded credentials, missing authentication on critical functions, and insecure password storage, enabling potential remote exploitation.

HIPASE-250 +1 ics energy ot vulnerability cve-2026-65309 cve-2026-65310 cve-2026-65311 cve-2026-65313
4t 3c
high advisory

Command Injection Vulnerability in Siemens Siveillance Video

A critical OS command injection vulnerability (CVE-2026-3014) in Siemens Siveillance Video allows authenticated users with administrative permissions to achieve remote code execution in the context of the Management Server service.

Siveillance Video vulnerability cve ics industrial-control-systems
1t 1c
high advisory

Out-of-Bounds Read Vulnerability in Siemens Parasolid

Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.

Parasolid vulnerability industrial-control-systems ics cve-2026-64629
1t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Dock Manager

Lenovo Dock Manager versions prior to 1.6.5.3 contain a local privilege escalation vulnerability due to an improperly protected key, allowing authenticated local users to gain elevated access.

Dock Manager vulnerability privilege-escalation lenovo
1t 1c
high advisory

Multiple Command and Argument Injection Vulnerabilities in rsync

Versions of rsync prior to 3.5.0 contain multiple command and argument injection flaws that allow attackers to execute arbitrary code via malicious hostnames, environment variables, and shell command injections.

rsync +1 vulnerability command-injection file-transfer cve-2026-53793 denial-of-service network
5t 1c
high advisory

Privilege Escalation Vulnerability in Lenovo Vantage

Lenovo Vantage and Commercial Vantage contain an improper link following vulnerability (CVE-2026-15994) that allows local authenticated users to achieve privilege escalation through file system manipulation.

Vantage +1 vulnerability privilege-escalation lenovo
1t 1c
high advisory

CVE-2026-53791 - IP Address Spoofing in rsync Daemon

The rsync daemon before version 3.5.0 contains a vulnerability where unauthenticated attackers can inject a forged PROXY protocol header to bypass IP-based access control restrictions.

rsync +3 vulnerability cve-2026-53791 spoofing access-control-bypass file-read
4t 1c
high advisory

Security Bypass in Network-AI ClaudeHookBridge via Input Truncation

CVE-2026-73614 in ClaudeHookBridge allows attackers to bypass security deny-lists by appending malicious command strings beyond a 500-character truncation threshold, resulting in potential arbitrary code execution.

ClaudeHookBridge vulnerability command-injection code-execution
1t 1c
critical advisory

Authorization Bypass in File Browser via Recursive Operations

File Browser versions prior to 2.63.22 contain an authorization bypass vulnerability allowing authenticated users to manipulate restricted files via recursive copy, rename, and delete operations.

File Browser +2 vulnerability access-control-bypass cve file-deletion path-traversal
1r 2t 1c updated
medium advisory

Denial of Service Vulnerabilities in Absolute Secure Access

Multiple vulnerabilities in Absolute Secure Access allow a remote, authenticated attacker to trigger a Denial of Service condition, impacting system availability.

Secure Access denial-of-service vulnerability
1t
medium advisory

X.Org X11 Denial of Service Vulnerability

A vulnerability in X.Org X11 (CVE-2023-6478) allows a remote, authenticated attacker to trigger a Denial of Service condition through resource exhaustion.

X.Org X11 vulnerability denial-of-service
1t 1c
high advisory

Multiple Vulnerabilities in MongoDB

Multiple vulnerabilities in MongoDB allow remote attackers to achieve arbitrary code execution, bypass security controls, manipulate data, disclose sensitive information, or trigger a denial-of-service.

MongoDB database vulnerability
3t
medium advisory

Multiple Vulnerabilities in etcd

Multiple vulnerabilities have been identified in etcd that could allow a remote attacker to bypass security controls or trigger a denial of service condition.

etcd vulnerability denial-of-service
1t
high advisory

Local Privilege Escalation in IBM Informix Dynamic Server

A local privilege escalation vulnerability in the oninit setuid-root utility of IBM Informix Dynamic Server 14.10 and 15.0 allows local authenticated users to gain elevated system privileges.

Informix Dynamic Server +1 vulnerability privilege-escalation local-access
1t 1c
high advisory

Arbitrary Code Execution in IBM i Access Client Solutions

IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 contain a local arbitrary code execution vulnerability on Windows due to insecure file permissions on a configuration file.

i Access Client Solutions +1 vulnerability local-privilege-escalation windows
3t 1c
critical advisory

Remote Code Execution via Search Custom Resource in Red Hat Advanced Cluster Management

An administrative user on the Red Hat Advanced Cluster Management hub can exploit a flaw in the Collector.ImageOverride field to deploy arbitrary container images and achieve remote code execution across managed clusters.

acm-search-v2-rhel9 vulnerability command-injection sql-injection kubernetes
1t 1c updated
high threat

Remote Code Execution Vulnerability in Zoom Clients

A critical buffer overflow vulnerability (CVE-2026-53413) in the Zoom annotator function allows for unauthenticated remote code execution on participant devices.

exploited Zoom Workplace +3 vulnerability rce zoom cve-2026-53413
1t 1c
critical advisory

Authentication Bypass in SiYuan Publish API

SiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.

SiYuan +3 access-control web-vulnerability authentication-bypass information-disclosure api-security remote-code-execution vulnerability pdf-processing +9
7r 19t 5c updated
high advisory

Remote Code Execution in IBM Informix via sq_sgkprepare

A critical buffer-related vulnerability (CVE-2026-13361) in IBM Informix allows remote, unauthenticated attackers to achieve code execution via the SQL interface by exploiting an unchecked length field in the oninit process.

Informix remote-code-execution vulnerability database-security
2t 1c
high advisory

Nagios Core and XI CSRF Protection Bypass

Nagios Core and XI contain a CSRF protection bypass vulnerability (CVE-2026-48551) that allows unauthenticated attackers to execute commands as an authorized user via manipulated double-submit cookies.

Nagios Core +1 vulnerability rce monitoring
2t 2c updated
critical advisory

Remote Command Injection in IBM Db2 Mirror for i

IBM Db2 Mirror for i versions 7.4 through 7.6 contain a critical command injection vulnerability allowing remote unauthenticated attackers to execute arbitrary system commands.

Db2 Mirror for i remote-code-execution vulnerability ibm-i
2t 1c
critical advisory

Uncontrolled Search Path Vulnerability in IBM i

IBM i versions 7.3 through 7.6 contain an uncontrolled search path element vulnerability that allows a remote authenticated attacker to execute arbitrary code with elevated privileges.

IBM i +6 vulnerability remote-code-execution ibm-i privilege-escalation cve-2026-16856
3t 5c updated
high advisory

Arbitrary File Write Vulnerability in SSH.NET ScpClient

A path traversal vulnerability in the SSH.NET ScpClient allows a malicious SCP server to write or overwrite arbitrary files on a client machine during a recursive directory download.

SSH.NET vulnerability path-traversal dotnet
1t
low threat

Information Disclosure Vulnerability in PAN-OS URL Filtering

An information disclosure vulnerability (CVE-2026-0301) in Palo Alto Networks PAN-OS URL Filtering allows unauthenticated attackers to access sensitive memory data if custom response pages are enabled.

exploited PAN-OS +2 vulnerability information-disclosure palo-alto
1t
medium threat

Local Privilege Escalation in Palo Alto Networks GlobalProtect

A local privilege escalation vulnerability (CVE-2026-0299) in the Palo Alto Networks GlobalProtect app allows authenticated local users to escalate to SYSTEM or root privileges via untrusted search path exploitation.

exploited GlobalProtect App 6.3 +3 privilege-escalation vulnerability endpoint-security
2t 2c updated
low threat

CVE-2026-0292: Prisma Access Agent Local Security Inspection Bypass

A local authentication bypass vulnerability in the Palo Alto Networks Prisma Access Agent for Windows enables an administrative user to disable security inspections and manipulate network traffic.

exploited Prisma Access Agent vulnerability windows network-security
1t
high advisory

Remote Code Execution Vulnerability in CUPS

A vulnerability in the cups-browsed service allows a local attacker to achieve arbitrary code execution via malicious print queue discovery packets.

PoC CUPS vulnerability rce linux
1t 1c updated
high advisory

Multiple Vulnerabilities in NGINX-UI

NGINX-UI is affected by multiple security vulnerabilities enabling remote attackers to achieve arbitrary code execution with root privileges, privilege escalation, data exfiltration, and denial-of-service.

NGINX-UI web-application vulnerability remote-code-execution privilege-escalation
3t
high advisory

Multiple Vulnerabilities in Fleet

Fleet is affected by multiple security vulnerabilities that allow unauthenticated or authenticated attackers to perform SQL injection, arbitrary code execution, and unauthorized data manipulation.

Fleet vulnerability web-application product-news
2t
high advisory

Multiple Vulnerabilities in Microsoft Exchange Server

Microsoft Exchange Server contains multiple vulnerabilities that can be exploited by an authenticated remote attacker to achieve privilege escalation, arbitrary code execution, security control bypass, data manipulation, and denial-of-service.

PoC Exchange Server vulnerability microsoft-exchange privilege-escalation remote-code-execution
3t 1c updated
medium advisory

Privilege Escalation Vulnerability in Microsoft Windows Package Manager

A local privilege escalation vulnerability in the Microsoft Windows Package Manager allows an authenticated local attacker to gain elevated privileges on the host system.

Windows Package Manager privilege-escalation windows vulnerability
1c
medium advisory

Denial of Service Vulnerability in Nmap

A vulnerability in the Nmap network scanning tool allows a remote, anonymous attacker to trigger a Denial of Service condition by sending specially crafted packets.

PoC nmap denial-of-service vulnerability network-scanning
1t 1c updated
high advisory

Multiple Vulnerabilities in Adobe ColdFusion

Adobe ColdFusion is susceptible to multiple vulnerabilities allowing remote code execution, privilege escalation, denial of service, information disclosure, and cross-site scripting.

ColdFusion vulnerability web-server adobe
3t
high advisory

Multiple Vulnerabilities in Commvault Backup & Recovery

Commvault Backup & Recovery is affected by multiple vulnerabilities that allow a remote, unauthenticated attacker to bypass security controls, execute arbitrary code, and perform server-side request forgery (SSRF), enabling potential full compromise of the backup infrastructure.

Backup & Recovery vulnerability backup-security
2t
high advisory

Multiple Vulnerabilities in Microsoft Office Products

Microsoft Office products contain multiple vulnerabilities that allow a remote attacker to achieve arbitrary code execution, privilege escalation, information disclosure, file manipulation, and perform cross-site scripting (XSS) attacks.

Office vulnerability
1t
high advisory

Multiple Vulnerabilities in SonicWall GMS

SonicWall GMS contains multiple vulnerabilities allowing remote code execution with root privileges, privilege escalation, security bypass, and information disclosure.

GMS vulnerability network-security sonicwall
3t
high advisory

Unauthenticated Access Vulnerability in FitSoft POS System

FitSoft POS System contains a missing authentication vulnerability that allows unauthenticated remote attackers to gain unauthorized access and control over the platform.

POS System vulnerability remote-access pos
1t 1c
low advisory

Unauthenticated Denial-of-Service Vulnerability in PLCnext Engineer

An unauthenticated remote denial-of-service vulnerability in the Phoenix Contact PLCnext Engineer communication interface allows attackers to crash the service, requiring manual intervention.

PLCnext Engineer dos industrial-control-system vulnerability
1t 1c
medium advisory

Denial of Service Vulnerability in Apache Kafka

A vulnerability in Apache Kafka allows a remote, unauthenticated attacker to trigger a Denial of Service condition by exploiting CVE-2024-27309.

Kafka vulnerability denial-of-service apache-kafka
1t 1c
high advisory

Multiple Vulnerabilities in IBM QRadar SIEM

IBM QRadar SIEM contains multiple vulnerabilities that enable a remote authenticated attacker to escalate privileges, execute arbitrary code, disclose information, and bypass security controls.

QRadar SIEM vulnerability security-management ibm-qradar
3t
critical threat

Active Exploitation of SonicWall SMA 1000 Series Appliances by Ransomware Actors

CISA has added CVE-2024-40766 to its Known Exploited Vulnerabilities catalog after reports that ransomware actors are leveraging the flaw in SonicWall SMA 1000 series appliances to gain initial access to enterprise networks.

exploited SMA 1000 ransomware vulnerability cve-2024-40766
1t 1c
high advisory

CVE-2026-73122: Unauthorized Information Disclosure in Red Hat Advanced Cluster Management

A vulnerability in the multicloud-operators-channel component of Red Hat Advanced Cluster Management allows compromised agents to perform unauthorized reads of Secrets and ConfigMaps within hub Channel namespaces, risking credential exposure.

Advanced Cluster Management vulnerability cloud-security rhacm cve-2026-73122
1t 1c
medium advisory

TPM 2.0 RSA OAEP Timing Side-Channel Information Disclosure

CVE-2026-6727 is an information disclosure vulnerability in the TPM 2.0 reference implementation caused by an RSA OAEP timing side-channel that potentially allows for sensitive key material recovery.

Windows +1 vulnerability information-disclosure hardware-security
1t 1c
medium advisory

Security Advisory for Grafana MCP Server and mcp-grafana

Grafana Labs has addressed a security vulnerability identified as CVE-2026-19516 affecting the Grafana MCP Server and mcp-grafana components in versions 1.0.0 and earlier.

Grafana MCP Server +1 vulnerability observability product-news
1c
high advisory

Authenticated Identity Spoofing Vulnerability in Velociraptor

Rapid7 Velociraptor versions prior to 0.77.2 are affected by an authenticated identity-spoofing vulnerability, CVE-2026-18972, that may allow unauthorized access or impersonation within the platform.

Velociraptor vulnerability identity-management
1c
high advisory

Code Injection Vulnerability in Perl DBI

An incomplete patch for CVE-2026-14380 introduced a code injection vulnerability (CWE-94) in the perl-DBI package for Red Hat Enterprise Linux 9 and 10, potentially allowing authenticated attackers to execute arbitrary code.

Red Hat Enterprise Linux 9 +2 vulnerability rce rhel
1t 1c
medium advisory

Information Disclosure Vulnerability in AMD Zen Processors

An information disclosure vulnerability in AMD Zen processors allows an authorized local attacker to access sensitive information.

Zen vulnerability hardware information-disclosure
1t
critical advisory

Multiple Vulnerabilities in Mira Hormone Monitor and Android App

Multiple critical vulnerabilities in Quanovate Tech Inc. Mira Hormone Monitor firmware and Android application enable unauthenticated remote access, health data tampering, and credential theft via BLE and cloud-based attack vectors.

Mira Hormone Monitor +1 medical-device vulnerability ics health-data
2t
high advisory

Multiple Vulnerabilities in OpenSSH Including Remote Code Execution

OpenSSH is susceptible to multiple security flaws, most notably a signal handler race condition in the sshd server known as regreSSHion, which can enable remote code execution with root privileges.

OpenSSH vulnerability rce
1t 1c
medium advisory

Denial of Service Vulnerability in GNU C Library

A local attacker can exploit a vulnerability in the GNU C Library (glibc) to cause application crashes or service instability, resulting in a Denial of Service.

PoC GNU C Library +2 denial-of-service linux vulnerability
1t 1c updated
high advisory

Multiple Vulnerabilities in HCL BigFix Mobile

HCL BigFix Mobile is affected by multiple security flaws, including cross-site scripting (XSS), information disclosure, and security restriction bypasses, enabling attackers to compromise user sessions and access unauthorized data.

BigFix Mobile vulnerability web-application security-bypass
2t
medium advisory

CVE-2026-68160: Out-of-Bounds Read in Ceph ceph_handle_caps

A vulnerability in the Ceph ceph_handle_caps function allows for an out-of-bounds read during the pre-authentication phase, potentially leading to denial-of-service or memory disclosure.

Ceph vulnerability memory-safety
1c
medium advisory

Multiple Vulnerabilities in Apache Airflow Providers

Apache Airflow is affected by multiple vulnerabilities, specifically CVE-2024-48792 and CVE-2024-48793, which allow a remote, authenticated attacker to perform unauthorized information disclosure.

Airflow vulnerability apache-airflow information-disclosure
1t 2c
high advisory

Pega Platform Security Control Bypass Vulnerability

A vulnerability in Pega Platform allows a remote, authenticated attacker to bypass security controls, potentially leading to unauthorized access or actions within the platform environment.

Pega Platform vulnerability security-bypass web-application
1t
medium advisory

Microchip WILC1000 Wi-Fi Driver Vulnerability

CVE-2026-68196 is a memory corruption vulnerability in the Microchip WILC1000 Linux kernel driver caused by insufficient validation of the association response length prior to header subtraction.

WILC1000 vulnerability linux kernel
1c
medium advisory

Memory Corruption Vulnerability in Cedrus Media Driver

CVE-2026-68229 is a vulnerability in the Cedrus H.264 video decoding driver that improperly handles invalid reference list entries, potentially resulting in memory corruption or system instability.

Cedrus vulnerability cve-2026-68229 media-driver linux
1c
medium threat

Vulnerability in Linux Kernel fscrypt Subsystem

CVE-2026-68147 addresses a memory management vulnerability in the Linux kernel fscrypt subsystem within the fscrypt_get_devices function, where improper dynamic allocation could lead to memory corruption or exhaustion.

exploited fscrypt vulnerability kernel linux informational
1c
medium advisory

Intel i915 Driver Speculation Barrier Vulnerability

CVE-2026-68269 describes a missing speculation barrier in the Intel i915 graphics driver that could enable transient execution side-channel attacks by allowing unauthorized speculative memory access.

i915 Graphics Driver vulnerability kernel linux
1c
medium advisory

Out-of-bounds Vulnerability in NXP i.MX 8 Image Signal Processor Driver

A potential out-of-bounds memory vulnerability in the NXP i.MX 8 Image Signal Processor (ISI) driver could lead to system instability or memory corruption if triggered by an attacker with driver-level access.

i.MX 8 ISI vulnerability kernel hardware informational
1c
low advisory

MediaTek mt76 Wireless Driver Memory Access Vulnerability

CVE-2026-68310 in the MediaTek mt76 wireless driver for mt7915 chipsets allows for potential memory access issues due to inadequate validation during HE capability lookups.

mt7915 vulnerability networking informational
1c
medium advisory

NULL Pointer Dereference Vulnerability in MediaTek mt76 Wi-Fi Driver

A NULL pointer dereference vulnerability exists in the MediaTek mt76 driver within the mt76_connac_mcu_uni_bss_he_tlv function, potentially leading to kernel panic or denial-of-service conditions.

mt76 vulnerability denial-of-service kernel firmware informational product-news linux
1c
medium advisory

Integer Overflow in AMD KFD Driver

A 32-bit integer overflow vulnerability in the AMD KFD kernel driver allows for potential memory corruption during CWSR size calculations.

Linux kernel vulnerability linux-kernel amd denial-of-service kernel-vulnerability product-news
1c
low advisory

Vulnerability in brcmfmac Wi-Fi Driver release_scratchbuffers

CVE-2026-68192 describes a flaw in the brcmfmac Wi-Fi driver related to non-idempotent buffer release routines, potentially leading to memory management issues.

brcmfmac vulnerability kernel-security driver-security
1c
medium advisory

Open vSwitch GSO Userspace Truncation Underflow Vulnerability

CVE-2026-68123 is a vulnerability in Open vSwitch related to GSO userspace truncation that may cause an underflow condition during packet processing, potentially impacting memory or system stability.

Open vSwitch vulnerability network-infrastructure product-news
1c
medium advisory

Missing Superblock Check in fscrypt find_or_insert_direct_key

A vulnerability in the Linux kernel fscrypt subsystem exists due to a missing superblock check in the find_or_insert_direct_key function, potentially impacting filesystem integrity.

fscrypt vulnerability linux kernel informational
1c
medium advisory

NULL Pointer Dereference in Linux ath11k Wi-Fi Driver

CVE-2026-68362 describes a NULL pointer dereference vulnerability in the Linux kernel ath11k driver that may lead to denial-of-service or potential code execution via crafted interactions.

ath11k linux kernel-vulnerability denial-of-service vulnerability linux-kernel networking cve-2026-68355
1t 1c
high advisory

Path Resolution Vulnerability in Linux ksmbd Kernel Module

CVE-2026-68083 describes a path resolution vulnerability in the ksmbd_vfs_kern_path_create function within the Linux kernel ksmbd module that may allow unauthorized file system operations.

ksmbd vulnerability kernel smb linux
1c
low threat

Memory Reference Leak in Linux Kernel AMD Display Driver

CVE-2026-68256 describes a memory reference leak in the Linux kernel drm/amd/display driver occurring during specific DP alt mode timeout conditions.

exploited drm/amd/display informational product-news vulnerability
1c
medium advisory

Vulnerability in AMD Display Driver for Linux Kernel

A memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.

amdgpu vulnerability linux kernel informational product-news linux-kernel kernel-security kernel-vulnerability +1
1t 1c
low threat

Linux Kernel cfg80211 Wireless Subsystem Vulnerability

CVE-2026-68412 identifies an error handling flaw in the cfg80211_wext_siwscan function of the Linux kernel wireless subsystem, potentially leading to instability during wireless scanning operations.

exploited cfg80211 vulnerability linux kernel
1c
medium advisory

GitHub CLI Partial Authentication Token Disclosure

GitHub CLI contains an information exposure vulnerability in the gh auth status command that results in the partial disclosure of authentication tokens.

GitHub CLI vulnerability cli github
1c
low advisory

Memory Leak and List Corruption in Intel Stratix 10 Firmware

Intel has patched memory leaks and list corruption vulnerabilities in the stratix10-svc firmware component that could lead to system instability.

Stratix 10 firmware vulnerability informational product-news
medium advisory

Linux Kernel binfmt_misc Privilege Escalation Vulnerability

CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.

Linux Kernel +1 linux kernel vulnerability privilege-escalation mac802154 cve linux-kernel networking +2
high advisory

Unauthenticated Remote Code Execution in Red Hat JBoss EAP via openjdk-orb

CVE-2026-15560 allows unauthenticated remote code execution in Red Hat JBoss EAP environments configured with the -secmgr flag due to insecure object unmarshalling.

JBoss Enterprise Application Platform remote-code-execution vulnerability jboss denial-of-service web-server enterprise-application java jndi
5t 4c updated
high advisory

Undertow AJP Authentication Bypass via CVE-2026-15554

The Undertow AJP listener incorrectly trusts ssl_cert and is_ssl attributes within the AJP protocol without validating a shared secret, allowing unauthenticated attackers to bypass CLIENT-CERT authentication.

Undertow vulnerability authentication-bypass network-security
2t 1c
critical advisory

PicketLink Federation SAML Authentication Bypass via Forged Assertions

A vulnerability in the PicketLink Federation SAML unsolicited response handler allows unauthenticated attackers to forge assertions, resulting in full authentication bypass as any principal.

PicketLink Federation authentication-bypass saml picketlink vulnerability
1t 1c
high advisory

Path Traversal Vulnerability in Hugging Face Accelerate

Hugging Face Accelerate versions 1.14.0 and earlier contain a path traversal vulnerability in checkpoint loading functions that allows arbitrary file reads or denial of service via named pipes.

Accelerate vulnerability path-traversal python
1c
high advisory

Improper Configuration in Red Hat OpenShift AI MaaS Gateway

A configuration vulnerability in the Red Hat OpenShift AI (RHOAI) MaaS Gateway enables low-privileged users to intercept and manipulate model-serving traffic, resulting in the unauthorized disclosure of access keys and AI prompts.

OpenShift AI vulnerability cloud-security information-disclosure
2t 1c
high advisory

Path Traversal Vulnerability in unearth Library

The unearth library version 0.18.2 and earlier contains a path traversal vulnerability in the is_within_directory function that permits arbitrary file writes via malicious archives.

unearth path-traversal vulnerability supply-chain
1t 1c
high advisory

Unauthenticated RCE and Data Access in Feast via Default Configuration

Feast and feast-operator contain a vulnerability due to a default 'no_auth' configuration, allowing unauthenticated attackers to achieve RCE via malicious User-Defined Functions and perform unauthorized cross-tenant data access.

Feast SDK +1 vulnerability rce authentication-bypass
3t 1c
high advisory

Blind SQL Injection Vulnerability in Plesk Obsidian

Plesk Obsidian versions prior to 18.0.80.1 and 18.0.79.5 are vulnerable to a blind SQL injection (CVE-2026-64636) which allows unauthenticated or low-privileged attackers to execute unauthorized database queries.

Plesk Obsidian vulnerability sql-injection web-application
1t 1c
critical advisory

OS Command Injection Vulnerability in Zyxel WAH7601

An OS command injection vulnerability in Zyxel WAH7601 devices (CVE-2026-13206) allows unauthenticated remote attackers to execute arbitrary system commands.

WAH7601 cve-2026-13206 command-injection zyxel network-device rce credential-access vulnerability networking +1
3t 1c
medium advisory

Multiple Vulnerabilities in GNU Emacs

GNU Emacs is impacted by multiple vulnerabilities that can be leveraged by an attacker to facilitate information disclosure, arbitrary code execution, and denial-of-service.

Emacs vulnerability software-update
1t
high advisory

Heap Out-of-Bounds Write in GStreamer adpcmdec Element

A heap out-of-bounds write vulnerability in the GStreamer gst-plugins-bad adpcmdec element allows attackers to trigger memory corruption or arbitrary code execution via crafted WAV files.

gst-plugins-bad vulnerability memory-corruption
1c
medium advisory

Memory Corruption in libkcapi via Uncanceled AIO Requests

CVE-2026-71226 involves a memory corruption vulnerability in libkcapi due to improper handling of canceled asynchronous I/O (AIO) requests within the one-shot path.

libkcapi denial-of-service vulnerability linux
1t 1c updated
medium threat

Memory Safety Vulnerability in libceph decode_lockers()

CVE-2026-68082 describes two unsafe bare decode operations within the libceph decode_lockers() function that could lead to memory corruption during network data deserialization.

exploited libceph memory-corruption vulnerability storage memory-safety linux ceph
1c updated
medium advisory

KVM Shadow VMCS Memory Handling Vulnerability

A vulnerability in the Linux kernel KVM module allows a guest user to trigger memory corruption via improper shadow VMCS handling after a VMCLEAR operation.

Kernel vulnerability virtualization linux denial-of-service kernel-security
1t 1c updated
medium advisory

Vulnerability in Linux KVM MMU Page Management

CVE-2026-64561 identifies a flaw in the Linux KVM hypervisor where incorrect validation of MMU pages could lead to memory management inconsistencies.

KVM vulnerability linux virtualization informational privilege-escalation kernel kernel-vulnerability arm64
1t 1c updated
high advisory

Linux Kernel MPLS NULL Pointer Dereference Vulnerability

A NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.

Linux Kernel vulnerability linux kernel informational stability cve filesystem product-news +13
2t 1c updated
medium advisory

Quadratic Complexity Vulnerability in Python xml.etree.ElementPath

A vulnerability in the xml.etree.ElementPath module allows for denial-of-service via quadratic time complexity when processing maliciously crafted XML index predicates.

Python denial-of-service vulnerability
1c
high advisory

Double-free Vulnerability in open-iscsi iSNS Attribute Decoder

A double-free vulnerability exists in the iSNS attribute decoder of the open-iscsi package, which may lead to memory corruption or application instability.

open-iscsi vulnerability linux privilege-escalation
1t 1c
high advisory

Remote Command Injection in INQUIRELAB mcp-bridge-api

A command injection vulnerability in the mcp-bridge.js component of mcp-bridge-api allows remote attackers to execute arbitrary system commands via manipulation of the command/args argument.

mcp-bridge-api vulnerability remote-code-execution webserver
2t 1c
critical advisory

Critical Stack Overflow in Tenda W6-S wifiSSIDset Endpoint

A critical stack-based buffer overflow in the Tenda W6-S web management interface allows unauthenticated remote attackers to cause a denial of service or potentially execute arbitrary code.

W6-S vulnerability iot rce dos
1r 2t 1c 1i
critical threat

Unauthenticated Remote Code Execution in Weaver E-cology 9.0

Weaver E-cology 9.0 versions prior to 10.52 are vulnerable to unauthenticated arbitrary file upload via the /workrelate/plan/util/uploaderOperate.jsp endpoint, allowing remote code execution.

exploited E-cology 9.0 vulnerability rce file-upload webserver
1r 1t 1c
high advisory

Multiple Critical Vulnerabilities in Progress Telerik UI for ASP.NET AJAX

Progress Telerik UI for ASP.NET AJAX is affected by a suite of thirteen critical vulnerabilities, including insecure deserialization, path traversal, XXE, and SSRF, which collectively enable remote code execution and data theft.

Telerik UI for ASP.NET AJAX vulnerability web-application rce srf
2t 5c
medium advisory

Local Arbitrary Code Execution Vulnerability in RHEL gpsd

A local arbitrary code execution vulnerability in the gpsd component of Red Hat Enterprise Linux allows a local attacker to execute arbitrary code.

Enterprise Linux +1 vulnerability rhel linux
1t
high advisory

Heap Buffer Overflow in FFmpeg DVB Subtitle Parser

FFmpeg versions 0.5 through 8.9 are vulnerable to a signed integer overflow in the DVB subtitle parser that can be triggered via a crafted WTV file to achieve remote code execution.

FFmpeg +2 vulnerability memory-corruption
1t 2c updated
high advisory

Arbitrary Code Execution in Autodesk Revit via Malicious PDF

Autodesk Revit contains an out-of-bounds read vulnerability in its PDF parsing engine that can be exploited for arbitrary code execution or information disclosure.

Revit 2026 +6 vulnerability cve office-application
1t 4c
medium advisory

Algorithmic Complexity Denial of Service in league/commonmark

A quadratic time complexity vulnerability in the UniqueSlugNormalizer component of league/commonmark 2.x allows attackers to trigger CPU exhaustion via specially crafted Markdown documents.

commonmark +1 denial-of-service algorithmic-complexity vulnerability
1c
high advisory

Remote Code Execution in ngx-extended-pdf-viewer via CVE-2026-16633

The ngx-extended-pdf-viewer library bundles a vulnerable version of pdf.js, allowing attackers to achieve arbitrary JavaScript execution in the context of the host application when processing malicious PDF files with XFA rich text enabled.

ngx-extended-pdf-viewer supply-chain vulnerability web-application javascript
1t
high advisory

Critical Security Vulnerabilities in Progress MarkLogic Server

Progress Software has released a security bulletin addressing ten critical vulnerabilities, including CVE-2026-7326 through CVE-2026-9203, affecting MarkLogic Server versions prior to 11.3.6 and 12.0.3.

MarkLogic Server vulnerability security-advisory patch-management
5c 2i
medium advisory

Hardcoded Credentials in Johnson Controls TL280

Johnson Controls TL280 devices running firmware versions below 5.63 contain hardcoded credentials and utilize insecure cryptographic algorithms, potentially allowing unauthorized access.

TL280 vulnerability ics iot
critical advisory

Unauthenticated Denial of Service in Ground Station

Ground Station versions prior to 0.6.0 are susceptible to an unauthenticated denial-of-service vulnerability in the Socket.IO service_control event handler, allowing remote attackers to terminate critical satellite-tracking processes via a restart_service command.

Ground Station vulnerability remote-code-execution sql-injection ground-station ssrf remote-execution webserver
5t 1c updated
high advisory

Memory Management Vulnerability in llama.cpp Android JNI Wrapper

A memory management mismatch in the llama.cpp Android JNI wrapper leads to heap metadata corruption, enabling potential denial of service or arbitrary code execution.

PoC llama.cpp +2 vulnerability integer-overflow llama-cpp
1t 3c 1i updated
medium advisory

Denial of Service Vulnerability in M-Files Server

A vulnerability in M-Files Server allows a remote, authenticated attacker to trigger a Denial of Service condition on the affected platform.

M-Files Server denial-of-service vulnerability
1t
high advisory

Multiple Vulnerabilities in Cisco IOS XE

Cisco IOS XE contains multiple vulnerabilities that can be exploited by an attacker to achieve remote code execution, bypass security controls, perform unauthorized data disclosure or manipulation, or cause a denial-of-service condition.

IOS XE vulnerability cisco networking dos
1t
high advisory

Multiple Vulnerabilities in Cisco Integrated Management Controller

Multiple vulnerabilities in the Cisco Integrated Management Controller allow remote, authenticated attackers to perform Cross-Site Scripting or execute arbitrary code with root privileges.

Integrated Management Controller vulnerability cisco hardware watchlist_match
2t
high advisory

Security Policy Bypass in SonicWall SonicOS

A security policy bypass vulnerability (CVE-2026-0516) in SonicWall SonicOS affects multiple hardware generations and virtual appliances, potentially allowing unauthorized access or configuration subversion.

SonicOS +3 vulnerability network-security firewall
1c
medium advisory

Multiple Vulnerabilities in Nextcloud Products

Multiple vulnerabilities, including CVE-2026-61527 and CVE-2026-61545, affect Nextcloud Server and Mail components, posing risks to data confidentiality and security policy enforcement.

Nextcloud Server 32 +4 vulnerability nextcloud patch-management
medium advisory

Multiple Security Vulnerabilities in Wallix Access Manager and Bastion

Multiple vulnerabilities in Wallix Access Manager and Bastion products allow for unauthorized privilege escalation and security policy bypass.

Access Manager +1 vulnerability privilege-escalation authentication-bypass informational
1t
high advisory

Electron Sandboxed Iframe Popup Restriction Bypass

A vulnerability in Electron, identified as CVE-2026-70608, allows sandboxed iframes to bypass 'allow-popups' restrictions and open new windows via the OpenURL navigation path.

Electron +4 vulnerability remote-code-execution javascript
2t 1c
high advisory

SSRF Vulnerability in IBM Application Gateway Operator

IBM Application Gateway Operator versions 22.2 through 26.06 contain a Server-Side Request Forgery vulnerability due to improper URL validation in custom resources, potentially allowing unauthorized access to internal resources.

Application Gateway Operator +20 vulnerability ssrf kubernetes
1t 1c updated
high advisory

IBM WebSphere Application Server ORB Unsafe Reflection Vulnerability

A vulnerability in the Object Request Broker (ORB) component of IBM SDK for Java allows an unauthenticated attacker to trigger remote code execution via arbitrary class instantiation.

WebSphere Application Server +2 vulnerability remote-code-execution java
1t 1c
high advisory

XXE Injection Vulnerability in IBM QRadar

IBM QRadar contains an XML External Entity (XXE) injection vulnerability in the event processing pipeline that allows unauthenticated attackers to read arbitrary files from the system.

QRadar vulnerability cve-2026-10025 xxe siem
1t 1c
high advisory

Multiple Vulnerabilities in Veeam ONE

Veeam ONE is affected by multiple security vulnerabilities that may allow a remote attacker to achieve arbitrary code execution, perform SQL injection, disclose sensitive information, or escalate privileges.

Veeam ONE vulnerability veeam-one
2t
medium advisory

Arbitrary Code Execution in Red Hat Ansible Automation Platform

A vulnerability in Red Hat ansible-core allows local attackers to achieve arbitrary code execution through improper input handling.

Ansible Automation Platform +1 vulnerability rce automation
1t 1c
critical advisory

Privilege Escalation in Red Hat Advanced Cluster Management

An insecure configuration in the Red Hat Advanced Cluster Management Application Subscription controller allows users with namespace-scoped edit privileges to escalate to cluster-admin by deploying unauthorized cluster-scoped resources via Helm charts.

Advanced Cluster Management for Kubernetes +1 privilege-escalation kubernetes cve vulnerability cloud credential-access
2t 2c updated
high advisory

Unauthenticated Authorization Bypass in Material Dashboard WordPress Plugin

The Material Dashboard plugin for WordPress contains a missing authorization vulnerability (CVE-2026-6079) allowing unauthenticated attackers to enumerate, execute, or delete scheduled tasks.

Material Dashboard wordpress vulnerability cve
1r 1t 1c
high advisory

Authorization Bypass Vulnerability in Odysseus Embedding Configuration

Authenticated non-admin users in Odysseus versions prior to commit bf325f6 can exploit a missing authorization vulnerability to modify server-wide embedding backend settings and intercept sensitive data.

Odysseus privilege-escalation vulnerability authentication-bypass
1t 1c
critical advisory

Unauthenticated Remote Code Execution in MaxSite CMS via Config Injection

MaxSite CMS is vulnerable to remote code execution due to improper input sanitization of the db_dbprefix parameter, allowing unauthenticated attackers to inject persistent PHP code into the database configuration file.

PoC MaxSite CMS +2 web-application cms vulnerability
1r 1t 3c 1i updated
high advisory

SSRF Vulnerability in Open WebUI via NAT64-encoded URLs

Authenticated users can bypass SSRF protection in Open WebUI by wrapping internal IPv4 addresses in NAT64 IPv6 transition prefixes, allowing unauthorized access to cloud metadata and internal network services.

PoC Open WebUI +5 ssrf vulnerability cloud-security web-application cve-2026-70479 web-vulnerability authorization-bypass cve-2026-70494 +2
2r 6t 1c updated
medium advisory

Vulnerabilities in MISP cti-transmute

The MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.

cti-transmute vulnerability misp patch-management
3i
critical threat

Improper Access Control in Atlas-Livre Admin Controllers

An unauthenticated access control flaw in Atlas-Livre allows attackers to bypass authentication and execute privileged database operations due to a failure to terminate script execution following HTTP redirects.

exploited Atlas-Livre vulnerability web-application cve-2026-69703
1r 2t 1c
high advisory

Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100

A hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.

KARR BT +1 ics transportation-security bluetooth vulnerability
1t
high advisory

Unauthenticated Remote Code Execution in Perspective 5.0.0

Perspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.

Perspective remote-code-execution cve-2026-67195 denial-of-service vulnerability CVE-2026-67198
3t 3c
high advisory

Missing Authorization Vulnerability in HAVELSAN Liman MYS

A missing authorization vulnerability (CVE-2026-18650) in HAVELSAN Liman MYS versions 2.2.3 through 2.3.0 allows authenticated users to escalate privileges.

Liman MYS vulnerability privilege-escalation havelsan
1c
high advisory

Stack-based Buffer Overflow in Autodesk FBX SDK

A stack-based buffer overflow vulnerability (CVE-2026-10709) in the Autodesk FBX SDK allows arbitrary code execution via maliciously crafted FBX files.

FBX SDK +1 vulnerability rce sdk code-execution 3d-rendering
2t 2c updated
medium advisory

Remote Code Execution Vulnerability in Zyxel Firewalls

A vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.

Zyxel Firewall vulnerability remote-code-execution firewall
1t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Perl Modules

Multiple vulnerabilities in Red Hat Enterprise Linux within DBI and perl-GD components allow local or remote attackers to execute arbitrary code, manipulate data, or trigger denial-of-service conditions.

Enterprise Linux +1 linux vulnerability perl rhel
1t
medium advisory

Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus

Multiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.

Tivoli Netcool/OMNIbus denial-of-service vulnerability enterprise-monitoring
1t
high advisory

Multiple Vulnerabilities in LibreNMS

LibreNMS versions prior to 26.5.0 are affected by multiple vulnerabilities including RCE, SSRF, and XSS, posing a significant risk for unauthorized system access and network reconnaissance.

LibreNMS web-application vulnerability rce ssrf xss
1t
critical advisory

Critical Vulnerabilities in HUMANIST Digital Human Resources

Multiple critical vulnerabilities in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources version 26.0 allow unauthorized access, web shell upload, session hijacking, and remote code execution. Upgrade to version 26.1 immediately.

HUMANIST Digital Human Resources sql-injection vulnerability webserver remote-code-execution web-application cve-2026-14175 session-hijacking credential-access
1r 3t 4c
high advisory

Heap-based Buffer Overflows in GIMP APNG and DDS Loaders

GIMP contains multiple heap-buffer-overflow vulnerabilities in its APNG and DDS file format loaders, which can lead to arbitrary code execution when a victim opens a specially crafted image file.

GIMP vulnerability remote-code-execution desktop-app code-execution
1t 5c updated
high threat

Guzzle Hostname Validation Bypass via Transport Discrepancy

Guzzle versions before 7.15.2 and 8.0.1 are vulnerable to a host-based security check bypass where transport handlers interpret non-canonical URI hostnames differently than application-level validation, potentially enabling SSRF.

exploited Guzzle +1 ssrf php vulnerability web-security
1t 1c
high advisory

DLL Hijacking in FirmaCheck for Windows via Unvalidated OpenSSL Configuration

FirmaCheck for Windows versions prior to 1.3.16 are susceptible to local privilege escalation and arbitrary code execution due to an unvalidated OpenSSL configuration file path.

FirmaCheck vulnerability dll-hijacking local-privilege-escalation
1r 2t 1c
high advisory

OS Command Injection in ClearOS Log Viewer

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands as the webconfig user, with subsequent escalation to root.

ClearOS vulnerability remote-code-execution privilege-escalation webserver
1r 2t 1c
high advisory

Emlog Pro TLS Certificate Validation Bypass

Emlog Pro versions up to 2.6.23 contain a vulnerability in the AI service component that disables TLS certificate verification, allowing attackers to perform man-in-the-middle interception of LLM API keys and manipulate AI responses.

PoC Emlog Pro +1 vulnerability mitm ai-security
2t 1c 1i updated
low advisory

Memory Exhaustion in Socket.IO Parser

A memory exhaustion vulnerability in socket.io-parser (CVE-2026-69185) allows remote attackers to trigger denial-of-service by sending specially crafted packets containing a large number of binary attachments.

socket.io-parser +2 denial-of-service vulnerability javascript npm supply-chain
1t 1c
high advisory

Information Disclosure and Denial of Service in Undici Cache Interceptor

The undici library is susceptible to cache poisoning leading to information disclosure and application crashes due to improper handling of malformed Cache-Control directives in the cache interceptor.

undici +1 vulnerability npm nodejs webserver
1c
high advisory

Blind SQL Injection in Krayin CRM leads DataGrid

Krayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid, allowing authenticated attackers to exfiltrate database contents via the rotten_lead[in] query parameter.

Krayin CRM sqli vulnerability web-application
1r 1t 1c
high advisory

Remote Stack-Based Buffer Overflow in Wavlink Networking Devices

Multiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.

WN572 +10 vulnerability rce network-infrastructure
1t 1c 1i
high advisory

Privilege Escalation in Razer RzUpdateService

A local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.

RzUpdateService privilege-escalation windows vulnerability
1t 1c
critical advisory

Krayin CRM Installer Authentication Bypass Vulnerability

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.

Krayin CRM vulnerability crm authentication-bypass
1r 1t 1c
high advisory

Remote Code Execution in OpenEMR Document Category Tree

OpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.

OpenEMR +1 web-application-vulnerability remote-code-execution healthcare cve-2026-39931 sql-injection web-application vulnerability authentication-bypass +1
8t 1c
critical threat

SQL Injection in SiYuan via /api/search/searchEmbedBlock

SiYuan versions 3.7.2 and earlier contain a critical SQL injection vulnerability in the /api/search/searchEmbedBlock endpoint, allowing unauthenticated or low-privileged users to execute stacked SQL queries and modify database content.

exploited PoC SiYuan +1 sqli vulnerability web-application
1r 2t 2c 1i updated
critical advisory

Critical Pre-Authentication RCE in Gitea and Forgejo

CVE-2026-60004 is a critical pre-authentication RCE vulnerability in Gitea and Forgejo platforms caused by an unsafe bare clone design in the diffpatch API endpoint, enabling arbitrary command execution via injected Git hooks.

Gitea +2 remote-code-execution git vulnerability forgejo
1r 3t 1c updated
high advisory

Linux Kernel posix-cpu-timers Use-After-Free Vulnerability

A use-after-free vulnerability in the Linux kernel posix-cpu-timers subsystem, identified as CVE-2026-64560, allows attackers to trigger kernel memory corruption via a race condition during non-leader thread exec() calls.

Linux Kernel +1 vulnerability linux-kernel cve uaf
1t 2c 1i updated
critical threat

Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes

A vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.

exploited multicluster engine for Kubernetes denial-of-service kubernetes cloud-native vulnerability privilege-escalation cloud-security cve
2t updated
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.

Ansible Automation Platform vulnerability remote-code-execution enterprise-automation
2t
high advisory

Multiple Vulnerabilities in cPanel/WHM

Multiple vulnerabilities in cPanel/WHM allow remote attackers to manipulate files and escalate privileges, potentially leading to arbitrary code execution with administrative rights.

cPanel/WHM vulnerability cpanel web-hosting
2t
high advisory

Critical RCE and Information Disclosure Vulnerability in Gitea

Gitea contains a critical vulnerability allowing remote, unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive information.

Gitea +1 vulnerability remote-code-execution web-application
1t 1c updated
critical advisory

Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin

A critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.

WPL Real Estate +1 wordpress rce vulnerability
1r 2t 1c 1i
critical advisory

Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client

A heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.

FreeRDP vulnerability remote-access windows rdp
1c
high advisory

Arbitrary File Read Vulnerability in CubeWP Framework

An unauthenticated directory traversal vulnerability in the CubeWP Framework plugin allows attackers to read arbitrary files by leveraging exposed AJAX nonces.

CubeWP Framework web-application wordpress vulnerability
2t 1c
high advisory

Command Injection Vulnerability in GitPython

GitPython versions prior to 3.1.51 are vulnerable to command injection because the library's security blocklist fails to account for Git command-line option abbreviation, allowing attackers to execute arbitrary commands.

GitPython vulnerability command-injection python
1t 1c
high advisory

Heap Out-of-Bounds Read in FreeRDP Glyph Caching

FreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.

FreeRDP vulnerability memory-safety remote-access tls man-in-the-middle
1t 1c
high advisory

FreeRDP Denial of Service via Smartcard Cache Request

A null pointer dereference vulnerability in FreeRDP prior to 3.29.0 allows remote attackers to trigger a crash in the client process via crafted smartcard cache requests.

FreeRDP +1 denial-of-service vulnerability remote-execution
2t 6c
high advisory

Remote Code Execution in Savon::Model via WSDL Injection

The Savon Ruby library is vulnerable to remote code execution (CVE-2026-53510) due to insecure use of module_eval when processing untrusted WSDL operation names.

Savon ruby remote-code-execution vulnerability cve-2026-53510
1t
low advisory

Pterodactyl Wings SFTP Service Denial of Service

An unauthenticated remote attacker can trigger a panic and crash the Pterodactyl Wings service by sending a maliciously crafted packet during the SFTP handshake.

wings denial-of-service pterodactyl go vulnerability
1t 1c
high advisory

NLTK pathsec DNS Rebinding SSRF Filter Bypass

A DNS rebinding vulnerability in the NLTK pathsec module allows attackers to bypass SSRF filters and access restricted internal resources by manipulating hostname resolution during the validation and connection phases.

NLTK ssrf dns-rebinding vulnerability path-traversal arbitrary-file-read library-vulnerability
1t
high advisory

Apache Cassandra JavaScript User-Defined Function Execution

Adversaries can exploit the creation of JavaScript-based user-defined functions in Apache Cassandra to escape the Nashorn sandbox and achieve remote code execution, particularly when vulnerable to CVE-2021-44521.

Cassandra vulnerability execution cql sandbox-escape
1r 1t 1c
medium advisory

Redis Authenticated Remote Code Execution Vulnerability

A vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.

Redis vulnerability rce database
1t
high advisory

Multiple Vulnerabilities in Progress MOVEit Transfer

Multiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.

MOVEit Transfer vulnerability web-application moveit
1t 4c
critical advisory

Unauthenticated Remote Code Injection in Logsign SIEM

Logsign SIEM versions prior to 6.4.108 are vulnerable to a critical code injection flaw (CVE-2026-17561) that enables unauthenticated remote attackers to achieve arbitrary code execution.

Logsign SIEM code-injection rce siem vulnerability
1c
critical advisory

Remote Code Execution via Exposed H2 Database in Juggle Through

An unauthenticated remote code execution vulnerability in Juggle Through 1.6.0 allows attackers to leverage default credentials on the H2 database console to execute system-level commands.

Juggle Through remote-code-execution vulnerability cve-2026-67208
2t 1c
critical advisory

Critical OS Command Injection in IBM Hardware Management Console

A critical unauthenticated command injection vulnerability (CVE-2026-12943) in IBM HMC and Novalink allows remote attackers to execute arbitrary commands with elevated privileges.

HMC V10.3 +2 vulnerability rce ibm-power critical
1c
high advisory

IBM PowerVM Hypervisor Memory Integrity Vulnerability

A buffer overflow vulnerability in IBM PowerVM Hypervisor allows a local attacker with low privileges to trigger system crashes or compromise OS memory integrity via crafted hypervisor calls.

PowerVM Hypervisor +2 vulnerability hypervisor buffer-overflow
1c
critical advisory

Unauthenticated Remote Code Execution in IBM Langflow OSS

IBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.

Langflow OSS remote-code-execution cve-2026-12940 ibm langflow code-injection vulnerability rce
3t 1c
critical advisory

SolarWinds Web Help Desk SAML Authentication Bypass

SolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.

Web Help Desk authentication-bypass saml vulnerability cve-2026-28323
1t 1c
high advisory

Denial of Service Vulnerability in IBM WebSphere Application Server - Liberty

A remote unauthenticated denial-of-service vulnerability in IBM WebSphere Application Server - Liberty allows attackers to cause excessive memory consumption via crafted requests.

WebSphere Application Server - Liberty denial-of-service vulnerability web-server web-application csrf ssrf privilege-escalation
1c
high advisory

Critical Vulnerabilities in Spring Tools IDE Extensions

Multiple vulnerabilities in Spring Tools for Eclipse and VSCode/Cursor/Theia allow for remote code execution, unauthorized service access, credential exposure, and cross-site scripting.

PoC Spring Tools for Eclipse +3 vulnerability ide rce spring-framework
5c updated
high advisory

Blind SQL Injection Vulnerability in Plesk XML-RPC API

A blind SQL injection vulnerability, tracked as CVE-2026-58046, affects the Plesk XML-RPC API, potentially allowing unauthenticated attackers to execute arbitrary database queries.

Plesk web-application sql-injection vulnerability
1r 1t 1c
high advisory

Credential Exfiltration via Unrestricted Base URL in Flyto-core

Flyto-core versions prior to 2.26.7 allow unauthenticated callers to exfiltrate API provider keys by supplying a malicious 'base_url' parameter, which forces the library to append operator-configured secrets to requests sent to attacker-controlled infrastructure.

flyto-core credential-theft vulnerability cloud-security cve-2026-67425 cve-2026-67427 exfiltration flyto variable-interpolation
2t 1c
critical threat

Unauthenticated SSRF and Secret Exfiltration in Flyto Core

An unauthenticated SSRF vulnerability in the Flyto Core /run endpoint allows attackers to exfiltrate the internal FLYTO_RUNNER_SECRET and perform unauthorized requests against internal infrastructure.

Flyto Core ssrf credential-theft vulnerability cve-2026-67426 path-traversal arbitrary-file-write rce framework
1r 4t 1c
low advisory

Multiple Vulnerabilities in GitLab

Multiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.

GitLab Community Edition +1 vulnerability gitlab patch-management
5c
high advisory

CVE-2026-54366 CentreStack XXE Injection

CentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.

CentreStack xxe vulnerability web-application
1r 2t 1c
high advisory

Unauthenticated Deserialization Vulnerability in CentreStack

An unauthenticated deserialization vulnerability in CentreStack allows remote attackers to create unauthorized local user accounts by sending crafted XML payloads to specific API endpoints.

CentreStack vulnerability deserialization remote-code-execution
2t
medium advisory

IBM WebSphere Application Server Security Bypass Vulnerability

IBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.

WebSphere Application Server +1 vulnerability websphere middleware
1t
low advisory

Denial of Service Vulnerabilities in RHEL perl-Archive-Tar and httplib2

Multiple vulnerabilities in Red Hat Enterprise Linux packages perl-Archive-Tar and httplib2 can be exploited by a remote, anonymous attacker to cause a Denial of Service condition.

Enterprise Linux +2 vulnerability denial-of-service linux
1t 2c
critical advisory

Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker

A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.

CHARX SEC-3150 +7 industrial-control-systems mqtt cve-2026-44091 ics cve injection authentication-bypass cve-2026-44100 +14
2r 5t 12c
high advisory

Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module

A file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.

Performance Co-Pilot +8 privilege-escalation linux cve-2026-16526 remote-code-execution cve-2026-16527 monitoring-tool denial-of-service vulnerability +1
1r 1t 1c
high advisory

Command Injection in PCP linux_sockets PMDA

A command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.

pcp +5 vulnerability command-injection linux
1t 1c
high advisory

SSRF Bypass Vulnerability in V Library

The V library (versions 0.5.2 and below) contains a server-side request forgery (SSRF) bypass vulnerability allowing attackers to circumvent host-based allowlists via URL parsing differentials.

V ssrf vulnerability web-security
1t 1c
critical advisory

SSRF Vulnerability in IBM WebSphere Application Server

IBM WebSphere Application Server and Liberty are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) when the SIP container feature is enabled, allowing attackers to perform unauthorized requests to internal services.

WebSphere Application Server +2 ssrf webserver vulnerability
1c
critical threat

Critical Unauthenticated RCE in JetBrains TeamCity

A critical insecure deserialization vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated remote attackers to execute arbitrary system commands via the agent polling protocol.

exploited TeamCity On-Premises vulnerability rce cicd jetbrains
2t 1c
high advisory

Arbitrary Host File Write via Symlink Escape in proot-distro

The proot-distro utility contains a symlink traversal vulnerability (CVE-2026-54574) that allows malicious tar archives to overwrite arbitrary files on the host filesystem during the installation or reset process.

proot-distro +1 vulnerability path-traversal arbitrary-file-write termux
2t 1i
medium advisory

Req Library Unbounded Archive/Compression Extraction Denial-of-Service

The Elixir library 'Req' (versions >= 0.1.0, < 0.6.1) is susceptible to a denial-of-service vulnerability (CVE-2026-49755) caused by unbounded archive and compression extraction, which an attacker can leverage by providing a malicious HTTP response with a crafted 'content-type' or 'content-encoding' header, leading to memory exhaustion and application crashes.

Req denial-of-service elixir vulnerability memory-exhaustion
1t 1c
high advisory

veraPDF Validation Module XML External Entity Injection Vulnerability (CVE-2026-54079)

A critical XML External Entity Injection (XXE) vulnerability, CVE-2026-54079, in veraPDF's validation-model module allows a remote attacker to read arbitrary files on the server file system or perform Server-Side Request Forgery (SSRF) by submitting a crafted PDF containing a malicious XFA stream, due to insecure XML parsing defaults.

veraPDF validation-model +3 xxe xml-external-entity pdf server-side-request-forgery vulnerability
4t
low advisory

Denial of Service Vulnerability in cJSON Library (CVE-2026-67215)

CVE-2026-67215 describes a denial-of-service vulnerability in cJSON through version 1.7.19, where an attacker can trigger uncontrolled recursion and stack exhaustion by supplying a crafted RFC 6902 JSON Patch to cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(), leading to process crash.

cJSON <= 1.7.19 denial-of-service vulnerability cJSON
1t 1c
medium advisory

Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)

A critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).

Apache Tomcat +2 denial-of-service vulnerability apache-tomcat
1t 1c 4i
high advisory

Multiple Vulnerabilities in Xen Hypervisor

Multiple vulnerabilities have been discovered in Xen, allowing an attacker to achieve privilege escalation, remote denial of service, and compromise data confidentiality across all unpatched Xen versions, necessitating immediate patching.

Xen virtualization hypervisor vulnerability privilege-escalation denial-of-service data-confidentiality
7c 31i
medium advisory

Apache Tomcat Vulnerability Allows Denial of Service

A vulnerability in Apache Tomcat allows a remote, anonymous attacker to perform a Denial of Service attack, potentially disrupting service availability for applications hosted on the affected server.

Apache Tomcat denial-of-service vulnerability apache
1t
high threat

BlackBerry UEM Management Console Multiple Vulnerabilities

An attacker can exploit multiple vulnerabilities in BlackBerry UEM Management Console to perform cross-site scripting attacks, cause a denial of service, and disclose information.

exploited BlackBerry UEM Management Console vulnerability xss denial-of-service information-disclosure blackberry
2t
high threat

IBM WebSphere Application Server and Liberty Multiple Vulnerabilities

Multiple vulnerabilities exist in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty that an attacker can exploit to execute arbitrary code, escalate privileges, perform denial of service attacks, disclose sensitive information, manipulate files, conduct cross-site scripting attacks, and bypass security measures.

exploited WebSphere Application Server +1 vulnerability web-application code-execution
5t
medium advisory

Broadcom Brocade SANnav Vulnerabilities Allow Information Disclosure, SQL Injection, and Data Manipulation

Multiple vulnerabilities in Broadcom Brocade SANnav can be exploited by an attacker from an adjacent network to achieve information disclosure, execute SQL injection attacks, and manipulate data within the system.

SANnav vulnerability sql-injection data-manipulation information-disclosure network-attack
3t
high advisory

CVE-2026-18220: Out-of-Bounds Write in GNU Binutils BFD Library Leading to Arbitrary Code Execution

An out-of-bounds write vulnerability, CVE-2026-18220, exists in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils, allowing attackers to achieve arbitrary code execution via a specially crafted ELF/DLX object file processed by BFD-consuming tools.

binutils vulnerability code-execution linux
1t 1c
high advisory

Fluent Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability (CVE-2026-16655)

An unauthenticated attacker can exploit a Stored Cross-Site Scripting vulnerability (CVE-2026-16655) in the Fluent Forms WordPress plugin, versions up to and including 6.2.7, via insufficient input sanitization of the Name Field Nested `password` Member, allowing injection of arbitrary web scripts that execute in a user's browser upon page access.

Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder wordpress plugin xss vulnerability webserver
2t 1c
high threat

Red Hat Enterprise Linux librest and pipewire Vulnerabilities Allow Code Execution

An attacker can exploit multiple vulnerabilities found in Red Hat Enterprise Linux, specifically within the librest and pipewire components, to bypass security measures and achieve arbitrary code execution on affected systems, posing a significant risk to the integrity and confidentiality of the system.

exploited Red Hat Enterprise Linux linux vulnerability redhat code-execution defense-evasion
2t
low advisory

PackageKit: Vulnerability Allows Bypassing Security Measures

A remote, authenticated attacker can exploit a vulnerability in PackageKit to bypass security mechanisms.

PackageKit vulnerability defense-evasion linux
1t
high threat

Gitea Remote Code Execution Vulnerability

A vulnerability in Gitea allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full compromise of the affected Gitea instance and potentially the underlying server.

exploited Gitea vulnerability rce
1t
medium advisory

Tanium Endpoint Management Vulnerability Allows Authenticated SQL Injection

A remote, authenticated attacker can exploit a SQL injection vulnerability in Tanium Endpoint Management, enabling the execution of arbitrary SQL commands and potentially leading to data manipulation or unauthorized access.

Tanium Endpoint Management sql-injection vulnerability endpoint-management
2t
medium threat

IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service

Multiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.

exploited WebSphere Application Server Liberty denial-of-service vulnerability ibm websphere
1t
critical advisory

Unauthenticated Credential Disclosure in Vacron VIN-DS783E-E6 via Hidden Functionality (CVE-2026-18191)

CVE-2026-18191 describes a critical Hidden Functionality vulnerability in Vacron VIN-DS783E-E6 devices that allows unauthenticated remote attackers to exploit a specific hidden function to obtain administrator credentials, leading to full device compromise.

VIN-DS783E-E6 vulnerability credential-access unauthenticated network-device CVE-2026-18191
2t 1c
high advisory

Path Traversal Vulnerability in openhole-server (CVE-2026-54650)

An unauthenticated path traversal vulnerability (CVE-2026-54650) in openhole-server and openhole CLI versions 0.1.1 and earlier allows remote attackers to read arbitrary files outside the web root on tunneled local services by exploiting URL-decoded percent-encoded dot-segments and slashes, enabling arbitrary file disclosure and potential bypass of access controls.

openhole-server +1 vulnerability path-traversal webserver
1r 2t
critical advisory

SQL Injection Vulnerability in @hypequery/clickhouse Allows Arbitrary SQL Execution

A SQL injection vulnerability exists in the `escapeValue()` function of the `@hypequery/clickhouse` library, affecting versions prior to 2.0.2, allowing attackers to leverage a trailing backslash in user-controlled query parameters to bypass escaping mechanisms, leading to arbitrary SQL execution against ClickHouse databases.

@hypequery/clickhouse sql-injection vulnerability npm clickhouse supply-chain
2t
high advisory

td Library Denial of Service via Unbounded Memory Allocation

A denial-of-service vulnerability exists in the `go/github.com/gotd/td` library versions prior to 0.145.1. A remote, unauthenticated attacker can exploit this by sending a crafted unencrypted MTProto packet during the handshake. This packet declares a large `dataLen` value, forcing the application to allocate an excessive amount of memory, potentially leading to out-of-memory (OOM) termination and denial of service due to unbounded memory allocation before length validation.

go/github.com/gotd/td denial-of-service vulnerability go-lang
1t
critical advisory

Goshs WebDAV MOVE Method Bypasses No-Delete Flag

A critical vulnerability (CVE-2026-64863) in the goshs WebDAV server, affecting versions up to 2.1.3, allows an attacker to bypass the `--no-delete` security flag using the `MOVE` HTTP method, leading to unauthorized deletion of source files or overwriting of existing destination files, impacting data integrity.

goshs <= 2.1.3 +1 webdav vulnerability file-deletion data-destruction server golang
1r 1t
high advisory

Goshs File-Based ACL Authorization Bypass via Bulk Zip Download

An unauthenticated attacker can exploit CVE-2026-54719 in goshs versions up to 1.1.4 and goshs/v2 up to 2.1.0 to bypass file-based Access Control Lists (ACLs) and read any file under the webroot using the `?bulk` zip-download route, leading to unauthorized information disclosure.

goshs +1 authorization-bypass webserver vulnerability cve information-disclosure
1r 3t
high advisory

datamodel-code-generator Arbitrary Local File Read Vulnerability

The `datamodel-code-generator` library (versions <= 0.61.0) is vulnerable to an unauthenticated path traversal and arbitrary local file read (CVE-2026-55389), allowing an attacker to supply a crafted JSON-Schema with `$ref` fields pointing to local files using `file://` URIs or `../` path traversal sequences, bypassing the `--no-allow-remote-refs` security control, which leads to information disclosure of sensitive data and enables filesystem mapping.

datamodel-code-generator <= 0.61.0 vulnerability path-traversal information-disclosure python
2t 1i
high advisory

datamodel-code-generator Vulnerable to Code Injection via Unescaped Carriage Return

The `datamodel-code-generator` Python package is vulnerable to code injection (CVE-2026-54654) when a developer uses the `--extra-template-data` option with a file whose `comment` value contains an unescaped carriage return, leading to arbitrary Python code execution during the import process of the generated code.

datamodel-code-generator code-injection supply-chain rce python vulnerability
1t
medium advisory

datamodel-code-generator Vulnerable to SSRF Protection Bypass via DNS Rebinding

The `datamodel-code-generator` tool is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass, identified as CVE-2026-55391, due to a time-of-check/time-of-use (TOCTOU) race condition through DNS rebinding, allowing attackers to access internal services like cloud instance metadata endpoints when processing attacker-influenced URLs.

datamodel-code-generator ssrf dns-rebinding vulnerability supply-chain python
4t 1i
high advisory

datamodel-code-generator Vulnerable to Arbitrary Local File Read via XSD Path Traversal

datamodel-code-generator versions 0.59.0 through 0.61.0 are vulnerable to an unauthenticated path traversal and information disclosure issue, allowing an attacker to read arbitrary local files on the system where the code generator is executed by crafting a malicious XML Schema (XSD) `schemaLocation` attribute, with the contents of the files then incorporated into the generated output.

datamodel-code-generator path-traversal information-disclosure supply-chain vulnerability
1t
high advisory

Datamodel Code Generator Vulnerable to SSRF via URL Parameter

The `datamodel-code-generator` tool, specifically versions from `0.9.1` up to `0.60.2`, is vulnerable to Server-Side Request Forgery (SSRF) when using the `--url` argument with the `[http]` extra installed, allowing attackers to access internal network resources and exfiltrate sensitive data into generated Python files.

datamodel-code-generator ssrf supply-chain code-generation python vulnerability
1r 3t 3i
high advisory

IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)

A path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.

WebSphere Application Server - Liberty 17.0.0.3 +45 vulnerability path-segment-injection information-disclosure websphere ibm
1c
high threat

CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability

CVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.

exploited Aspera Faspex 5 +1 vulnerability session-management IBM cve
1t 1c
high advisory

IBM WebSphere Application Server Unsafe Deserialization Vulnerability

A critical unsafe deserialization vulnerability, CVE-2026-14974, in IBM WebSphere Application Server versions 8.5 and 9.0 traditional, allows a remote attacker to execute arbitrary code by processing specially crafted untrusted data, potentially leading to full system compromise.

WebSphere Application Server 8.5 +1 vulnerability deserialization rce websphere cve
2t 1c
high advisory

IBM Instana Node.js Tracer Vulnerable to Prototype Pollution (CVE-2026-14893)

A high-severity prototype pollution vulnerability, CVE-2026-14893, exists in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) affecting IBM Observability with Instana Agent builds 1.0.303 through 1.0.320, allowing an attacker to modify critical application behavior through the configuration normalization API.

IBM Observability with Instana +1 vulnerability prototype-pollution nodejs instana
1c 2i
critical advisory

IBM Aspera Desktop App Path Traversal Vulnerability (CVE-2026-14973)

The IBM Aspera Desktop App (versions 1.0.5 through 1.0.19) is affected by a path traversal vulnerability (CWE-22) which allows files to be written outside of the user's selected download destination, leading to high integrity and confidentiality impacts through arbitrary file write operations, and requires user interaction to exploit.

Aspera Desktop App +1 vulnerability path-traversal ibm aspera cve critical-vulnerability
1t 1c
critical advisory

CVE-2026-14959: IBM Aspera Faspex 5 Remote Code Execution via Shell Command Injection

A critical vulnerability, CVE-2026-14959, in IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) allows a remote authenticated attacker to execute arbitrary code due to a shell command injection flaw, potentially leading to full system compromise and significant data loss or service disruption.

Aspera Faspex 5 vulnerability command-injection rce remote-code-execution ibm
2t 1c
critical advisory

IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)

A critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.

Aspera Faspex 5 remote-code-execution vulnerability os-command-injection web-application
1r 2t 1c
medium advisory

IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)

A denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.

WebSphere Application Server - Liberty +1 denial-of-service vulnerability websphere
2c
critical advisory

IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)

A remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.

WebSphere Application Server 9.0 +8 vulnerability authentication-bypass websphere broken-access-control privilege-escalation deserialization RCE server-side-request-forgery +6
5t 7c 5i
high advisory

Fission Zip Slip Vulnerability in pkg/utils/zip.go Unarchive Function

The Unarchive function in Fission's pkg/utils/zip.go was vulnerable to a Zip Slip path traversal. An attacker controlling a malicious zip archive's URL could leverage this to write files outside the intended destination directory, potentially leading to overwriting sensitive files, accessing secrets from mounted volumes, or tampering with the fetcher's own binaries, impacting other tenants in a multi-tenant containerized environment. This vulnerability affects Fission versions up to and including v1.24.0 and was fixed in v1.25.0.

Fission <= 1.24.0 zip-slip path-traversal vulnerability cloud linux
3t 1c
high advisory

SQL Injection Vulnerability in IBM Sterling B2B Integrator and File Gateway (CVE-2026-7769)

A remote attacker can exploit CVE-2026-7769, an SQL injection vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway, to send specially crafted SQL statements, allowing them to view, add, modify, or delete information in the backend database.

Sterling B2B Integrator +5 sql-injection vulnerability data-manipulation enterprise-software
3t 1c
high advisory

Artica Proxy Session Fixation Vulnerability CVE-2026-66745

A session fixation vulnerability, CVE-2026-66745, in Artica Proxy before version 4.50.000000 Service Pack 7 allows unauthenticated attackers to hijack administrative sessions by pre-setting a PHPSESSID on a victim's browser, leading to full administrative control upon victim authentication.

Artica Proxy vulnerability session-fixation web-application proxy
1t 1c 1i
high threat

Adobe Bridge Untrusted Search Path Vulnerability Allows Arbitrary Code Execution (CVE-2026-48395)

An Untrusted Search Path vulnerability (CVE-2026-48395) in Adobe Bridge, affecting versions up to 16.0.5 and 15.1.6, can be exploited by an attacker to achieve arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file.

exploited Adobe Bridge +1 vulnerability code-execution user-interaction adobe
2t 1c 1i
medium advisory

Progress Software Security Advisory Addresses Multiple Vulnerabilities

Progress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.

ECS Connection Manager < 7.2.63.3 +4 vulnerability cve security-advisory patch-management
5c
high advisory

TinyWeb Path Traversal Vulnerability (CVE-2026-67185)

A path traversal vulnerability, tracked as CVE-2026-67185, exists in TinyWeb through version 0.0.8, allowing unauthenticated attackers to read arbitrary files by submitting '..' sequences in the URL path, bypassing security checks and potentially exposing sensitive data like credential stores or private keys when the server runs with root privileges.

TinyWeb <= 0.0.8 path-traversal webserver vulnerability cve
1r 2t 1c
high advisory

Rouille HTTP Request Smuggling Vulnerability (CVE-2026-67182)

An HTTP request smuggling vulnerability, identified as CVE-2026-67182, in Rouille versions 0.3.3 through 3.6.2 allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values, causing upstream backends to misinterpret subsequent data as a separate, attacker-controlled HTTP request.

Rouille 0.3.3 +1 vulnerability http-request-smuggling access-control-bypass web-application defense-evasion
1t 1c
high advisory

CVE-2026-16313: sg3_utils Vulnerability Allows Root Command Execution via Crafted SCSI Device

A vulnerability, CVE-2026-16313, exists in the `sg_inq` command of `sg3_utils` on Red Hat Enterprise Linux systems, allowing an attacker who can present a specially crafted SCSI device to inject arbitrary properties into the `udev` device database by embedding a newline character in the device's name string, leading to arbitrary command execution as root when the device is disconnected.

sg3_utils linux vulnerability privilege-escalation arbitrary-command-execution
2t 1c 3i
medium advisory

SIPSorcery: Malformed UDP Packet Can Remotely Terminate Media Sessions (DoS)

A denial-of-service vulnerability (CVE-2026-54632) exists in the SIPSorcery NuGet package versions <= 10.0.8, allowing an unauthenticated attacker to remotely terminate an active RTP or WebRTC media session by sending a single malformed inbound UDP packet to the RTP/ICE socket, which exploits insufficient length checks and an exception handling flaw.

SIPSorcery denial-of-service vulnerability nuget
2t
medium advisory

QTINeon NeonRelay Unauthenticated Denial-of-Service Amplification Vulnerability

An unauthenticated attacker can exploit an unbounded RECONNECT_REQUEST forwarding vulnerability in QTINeon's NeonRelay component to amplify denial-of-service attacks against a connected host. By sending spoofed RECONNECT_REQUEST packets, the relay forwards each one to the host without proper deduplication or rate limiting, consuming host resources. Additionally, excessive spoofed IPs can reset legitimate rate limiting, further impacting service availability. This vulnerability affects Java, Python, and TypeScript implementations of NeonRelay.

qti-neon = 1.0.0 denial-of-service amplification network vulnerability
3t
high advisory

OAuth2::Client Redirection Vulnerability Leaks Bearer Tokens

The `OAuth2::Client` in the `oauth2` Ruby gem is vulnerable to credential disclosure and Server-Side Request Forgery (SSRF) due to improper handling of protocol-relative redirect URLs, allowing an attacker to steal bearer tokens and access internal network resources.

oauth2 ruby vulnerability credential-disclosure ssrf redirect ghsa
3t 3i
medium advisory

Cross-origin OAuth token-request redirects can expose signed request metadata

The 'oauth' Ruby gem versions 0.5.5 through 1.1.5 are vulnerable to a critical issue (CVE-2026-54605) where the 'OAuth::Consumer#token_request' method improperly handles HTTP 3xx redirects during OAuth 1.0 token exchanges, enabling an attacker to redirect the request to a malicious host, exposing sensitive OAuth 1.0 metadata, and facilitating Server-Side Request Forgery (SSRF) and confused-deputy behavior.

oauth vulnerability ssrf ruby gem web-application
3t
low advisory

Rouille Web Server Vulnerability CVE-2026-66754 Allows Remote DoS

A reachable assertion vulnerability exists in the `Request::remove_prefix` function of the Rouille web server framework, affecting versions 0.1.6 through 3.6.2, allowing remote, unauthenticated attackers to crash the server and cause a denial of service by sending a crafted percent-encoded URL.

Rouille 0.1.6-3.6.2 rouille web-server dos vulnerability cve rust
1t 1c
high advisory

HTTP Request Smuggling Vulnerability in tiny-http CVE-2026-66752

A critical HTTP request smuggling vulnerability (CVE-2026-66752) exists in tiny-http versions up to and including 0.12.0, allowing remote attackers to desynchronize request framing by sending a Transfer-Encoding header with arbitrary values, causing the library to incorrectly apply chunk-decoding and ignore Content-Length, which enables request smuggling attacks and can lead to denial of service by tying up connections and consuming worker threads.

tiny-http <= 0.12.0 http-request-smuggling vulnerability denial-of-service webserver
1c
high advisory

Authenticated Remote Code Execution in Camaleon CMS

Camaleon CMS versions 2.1.1 through 2.9.1 are vulnerable to authenticated remote code execution where an attacker with `custom_fields manage` permission can execute arbitrary Ruby code by injecting a malicious expression into the `select_eval` custom field type's options command parameter, which is then evaluated via `instance_eval` within an ERB view when a post edit page is rendered, leading to server-side code execution with web server process privileges.

Camaleon CMS remote-code-execution cms vulnerability
1t 1c
high threat

Pterodactyl Wings Privilege Escalation via Improper JWT Scoping (CVE-2026-54593)

A privilege escalation vulnerability, CVE-2026-54593, exists in Pterodactyl's Wings component that allows authenticated subusers to upload arbitrary files to a server without explicit file creation permissions, due to insufficient validation of panel-signed JSON Web Tokens (JWTs.

Pterodactyl Panel +1 Unauthorized Subuser privilege-escalation vulnerability JWT Pterodactyl web-server
1r 1t
high advisory

CVE-2026-8164: ArkSigner Desktop Client Vulnerable to Search Order Hijacking

An Uncontrolled Search Path Element vulnerability, CVE-2026-8164, in ArkSigner Desktop Client versions from v2.2.16.10 through 17062026 allows a local attacker to perform Search Order Hijacking, potentially leading to arbitrary code execution or privilege escalation with the application's privileges.

ArkSigner Desktop Client vulnerability cve search-order-hijacking dll-sideloading privilege-escalation local-exploitation
2t 1c
high advisory

Improper Privilege Escalation in Anchore Enterprise User Management API

An improper privilege escalation vulnerability (CVE-2026-63727) exists in Anchore Enterprise versions 5.11.0 to 5.27.1 and 6.0.0, specifically within the user management API, allowing an authenticated attacker to issue a crafted API call to modify user permissions and gain elevated access to resources and operations, such as granting write access to a read-only user, with fixes available in versions 5.27.2 and 6.0.1.

Anchore Enterprise +1 privilege-escalation api-security vulnerability anchore
1t 1c
medium advisory

Pterodactyl Panel Global Rate-Limit Vulnerability Enables Unauthenticated DoS (CVE-2026-61609)

An unauthenticated attacker can exploit CVE-2026-61609, a global rate-limit vulnerability in Pterodactyl Panel versions up to and including 1.12.4, by sending approximately 10 requests per minute to authentication endpoints, leading to a panel-wide denial of service for all legitimate users and administrators attempting to log in or complete 2FA.

Panel denial-of-service vulnerability web-application pterodactyl
1r 2t
medium advisory

GitHub MCP Server Nil Pointer Dereference DoS in completion/complete Handler (CVE-2026-47427)

A nil pointer dereference vulnerability, tracked as CVE-2026-47427, in the GitHub MCP Server's `completion/complete` handler allows an unauthenticated attacker to cause a complete denial of service by sending a malformed JSON-RPC request with missing or empty parameters for the `ref` field, leading to an immediate server crash.

github-mcp-server denial-of-service vulnerability github
1t
high threat

Multiple Vulnerabilities Identified in Apache Thrift

Multiple vulnerabilities, including decompression bombs (CVE-2026-48586, CVE-2026-49158), an integer overflow (CVE-2026-55969), and a heap out-of-bounds read (CVE-2026-58023), affect Apache Thrift prior to version 0.24.0, potentially leading to denial of service, memory corruption, or arbitrary code execution, and require immediate patching.

exploited Apache Thrift +1 vulnerability apache library deserialization denial-of-service
4c updated
high threat

WordPress Coding Standards Contains an Arbitrary Code Execution Vulnerability

WordPress Coding Standards (WordPressCS) versions before 3.4.1 are vulnerable to arbitrary code execution due to a flaw in the `WordPress.WP.EnqueuedResourceParameters` sniff, allowing an attacker to execute arbitrary commands on the scanning host by crafting a malicious `$ver` argument, posing a risk for users running PHPCS with specific rulesets in CI pipelines or developer environments.

exploited WordPress Coding Standards wordpress code-execution vulnerability php ci/cd
1t
high advisory

Appium Java Client Allows Network Pivot via Unvalidated directConnect Redirect (CVE-2026-43910)

A vulnerability, CVE-2026-43910, in Appium's java-client allows a malicious Appium server to redirect all subsequent session traffic to an arbitrary internal endpoint by injecting unvalidated `directConnectHost` and `directConnectPort` parameters when `directConnect(true)` is enabled, potentially leading to session traffic interception, network pivoting, and cloud credential theft.

java-client supply-chain vulnerability network-pivot credential-theft java CI/CD
3t 1i
critical advisory

Vulnerability in VeloCloud Orchestrator On-Prem Allows Remote Code Execution

A critical vulnerability has been identified in VeloCloud Orchestrator (VCO) On-Prem that allows for remote code execution, enabling a remote attacker to gain privileged access, execute arbitrary commands on the VCO host, and potentially install programs, modify or delete data, or create new user accounts with administrative rights, with impact severity depending on the service account privileges.

VeloCloud Orchestrator On-Prem rce vulnerability network sd-wan sase
3t
medium advisory

Multiple Vulnerabilities in Samba

Multiple vulnerabilities have been discovered in Samba, a network file sharing service, which could allow a remote attacker to trigger a denial of service, compromise data confidentiality, and bypass security policies.

Samba +2 vulnerability denial-of-service data-breach security-bypass
3t 1c
high advisory

CVE-2026-7187: Missing Authentication Vulnerability in Universal Software Inc. UKBS

A missing authentication for critical function vulnerability, tracked as CVE-2026-7187, in Universal Software Inc.'s UKBS product allows attackers to bypass authentication and access functionality not properly constrained by Access Control Lists (ACLs), leading to unauthorized operations.

UKBS vulnerability missing-authentication CVE-2026-7187
1t 1c
high advisory

CVE-2026-49332: OpenShift OAuth Proxy Header Smuggling Vulnerability

A flaw in Red Hat OpenShift's oauth-proxy, tracked as CVE-2026-49332, allows an authenticated low-privilege user to smuggle a forged identity header by exploiting differences in how dash and underscore variants of 'X-Forwarded-User' are handled, potentially leading to privilege escalation in upstream applications.

Red Hat OpenShift Container Platform 4 +1 cloud vulnerability privilege-escalation header-smuggling openshift red-hat cve
1t 1c
medium advisory

Multiple Vulnerabilities in Apache Wicket Allow XSS and Security Bypass

An anonymous, remote attacker can exploit multiple vulnerabilities in Apache Wicket to perform Cross-Site Scripting (XSS) attacks and bypass existing security measures, potentially leading to unauthorized client-side script execution and further compromise of user sessions or data.

Wicket vulnerability web-application xss security-bypass
2t
medium advisory

binutils: Vulnerability Enables Denial of Service and Data Disclosure

A local attacker can exploit a vulnerability in binutils to cause a Denial of Service condition and disclose sensitive data.

binutils linux macos denial-of-service data-disclosure vulnerability
2t
high advisory

Multiple Vulnerabilities in GIMP Plugins Allow Local Exploitation

A local attacker can exploit multiple vulnerabilities found in GIMP plugins to perform a Denial of Service attack, execute arbitrary code, or disclose confidential information on affected systems.

GIMP vulnerability local-privilege-escalation denial-of-service code-execution information-disclosure
2t
critical advisory

CVE-2026-16462: SQL Injection Vulnerability in PROCON-WEB SCADA

CVE-2026-16462 describes a critical SQL Injection vulnerability in Weidmueller Interface's PROCON-WEB SCADA, where a remote unauthenticated attacker can execute arbitrary SQL commands via the 'GetGridData' endpoint due to improper input sanitization, potentially leading to full system compromise.

PROCON-WEB SCADA <= 6.11.2 sql-injection vulnerability scada critical-vulnerability
1r 2t 1c
medium advisory

Netty: Vulnerability Enables Denial of Service

A denial of service vulnerability exists in Netty, which an unauthenticated, remote attacker can exploit, allowing the attacker to disrupt the availability of affected systems or services.

Netty denial-of-service vulnerability
1t
critical advisory

Erlang/OTP: Multiple Vulnerabilities

Multiple vulnerabilities in Erlang/OTP allow a remote, anonymous attacker to perform a Denial of Service attack, execute arbitrary code, bypass security measures, and manipulate or disclose data.

Erlang/OTP vulnerability erlang otp rce dos data-exfiltration defense-evasion
2t
high advisory

WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)

An unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.

Question Answer plugin <= 1.2.73 wordpress sql-injection vulnerability web-application
1r 2t 1c
high advisory

CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection

Unauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.

Bookly plugin for WordPress <= 27.5 web sql-injection wordpress plugin vulnerability cve exfiltration
1r 2t 1c
medium advisory

CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout

A low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.

DVG-IRF1401 +5 vulnerability denial-of-service industrial-control-systems network-device
1t 1c
high advisory

CVE-2026-14167: ads-tec Industrial IT DVG-IRF Series Privilege Escalation Vulnerability

A low-privileged remote attacker can exploit CVE-2026-14167, an incorrect authorization vulnerability in multiple ads-tec Industrial IT DVG-IRF series products, to perform privileged configuration changes, including permission management, leading to privilege escalation.

DVG-IRF1401 +5 vulnerability privilege-escalation authorization-bypass ICS OT
1t 1c
high advisory

CVE-2026-66759: Out-of-Bounds Read in GIMP file-icns Plugin

A critical out-of-bounds read vulnerability (CVE-2026-66759) has been identified in the GIMP file-icns plugin, where processing a crafted ICNS file with a truncated mask resource can lead to information disclosure of heap contents via leaked alpha channel pixel values or a denial of service due to an application crash.

GIMP vulnerability out-of-bounds-read information-disclosure denial-of-service image-processing
1c
high advisory

CVE-2026-12383: Event-Driven Ansible Server Authentication Bypass

A flaw in the Event-Driven Ansible (EDA) server's ExternalEventStreamViewSet allows an unauthenticated attacker to bypass mTLS authentication by spoofing the Subject HTTP header, enabling injection of arbitrary events into mTLS-protected streams and triggering downstream automation actions, while also leaking the expected certificate Distinguished Name in 403 error responses.

Event-Driven Ansible vulnerability network ansible
1r 2t 1c
high threat

Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass

A remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.

exploited PoC FortiOS +7 fortinet vulnerability cve exposure persistence
1t 3c 4i updated
low advisory

CVE-2026-66730 Denial of Service in facil.io Multipart Body Parser

A denial-of-service vulnerability exists in facil.io versions 0.6.0 through 0.7.6, specifically in its multipart body parser, allowing an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a malformed multipart/form-data request with a partial closing boundary, effectively disabling the server until manual restart.

facil.io 0.6.0 through 0.7.6 denial-of-service vulnerability web-server
1t 1c
low advisory

CVE-2026-66729: facil.io Integer Underflow Vulnerability Leading to Server Crash

An integer underflow vulnerability in facil.io through version 0.7.6 allows unauthenticated remote attackers to crash the server process via a crafted Content-Disposition header with an empty field name, leading to a Denial of Service.

facil.io denial-of-service vulnerability web-server
1t 1c
high advisory

CVE-2026-66394: SiYuan XSS Vulnerabilities in SVG Sanitization

Authenticated attackers can exploit stored and reflected cross-site scripting (XSS) vulnerabilities, identified as CVE-2026-66394, in SiYuan versions prior to v3.7.3 by bypassing the application's SVG sanitization to execute arbitrary scripts within the application's origin, potentially leading to session hijacking and data exfiltration.

SiYuan xss web-application vulnerability svg-sanitization
2t 1c
high advisory

Path Traversal Vulnerability in NitroShare Desktop (CVE-2026-66050)

NitroShare Desktop versions up to and including 0.3.4 are vulnerable to a path traversal flaw in their LAN file transfer server, allowing unauthenticated attackers on the same network to craft malicious filenames containing directory traversal sequences within the JSON item header. Exploiting this, attackers can write arbitrary files outside the intended transfer root to any location the current user has write access, including the Windows Startup folder, leading to persistent code execution upon user login.

NitroShare Desktop <= 0.3.4 path-traversal persistence code-execution vulnerability
1r 1t 1c
high advisory

Multiple Vulnerabilities in GLPI

Multiple vulnerabilities have been discovered in GLPI, including SQL injection, cross-site scripting (XSS), and privilege escalation, which could allow an attacker to compromise data integrity, bypass security policies, and elevate their privileges within the system.

PoC GLPI +2 vulnerability web-application sql-injection xss privilege-escalation
3t 1c 9i updated
critical advisory

Zabbix Cross-Site Scripting Vulnerability

A critical cross-site scripting (XSS) vulnerability has been identified in Zabbix, which a remote, unauthenticated attacker can exploit to execute malicious scripts within a user's browser session, potentially leading to unauthorized actions or data theft.

Zabbix cross-site-scripting xss web-application vulnerability
1r 1t
high threat

FFmpeg: Multiple Vulnerabilities

Multiple vulnerabilities in ffmpeg allow a remote, anonymous attacker to cause memory corruption, execute arbitrary code, trigger a denial-of-service condition, or disclose confidential information. The attacker does not require authentication to exploit these flaws.

exploited ffmpeg vulnerability rce denial-of-service information-disclosure memory-corruption
2t
high advisory

OpenCTI Security Bypass and Information Disclosure Vulnerability

A remote, anonymous attacker can exploit a vulnerability in OpenCTI to bypass security measures and disclose sensitive information, potentially leading to unauthorized access to critical threat intelligence data and circumvention of protective controls within the platform.

OpenCTI vulnerability information-disclosure security-bypass
2t
high threat

Multiple Vulnerabilities in libssh2 Library Discovered

Multiple vulnerabilities in the libssh2 library allow a remote, unauthenticated attacker to potentially disclose sensitive information, cause a denial-of-service condition, or execute arbitrary code.

exploited libssh2 vulnerability library remote-code-execution denial-of-service information-disclosure
2t
high advisory

Improper Signature Verification in Lenze Products (CVE-2026-14837)

A low-privileged local attacker can exploit CVE-2026-14837, an improper signature verification vulnerability, in multiple Lenze products including models c430, c520, c550, i950 GenA, and i950 GenB to bypass the verification of the SSH enable file signature, subsequently enabling SSH access on the affected device, resulting in unauthorized administrative access and complete system compromise.

c430 +4 vulnerability ics ot industrial-control-system ssh signature-bypass
2t 1c
high advisory

Code Injection Vulnerability in datamodel-code-generator (CVE-2026-63720)

CVE-2026-63720 details a code injection vulnerability in datamodel-code-generator versions prior to 0.70.0, allowing attackers to achieve remote code execution by providing a malicious `customBasePath` value within input schemas that is unsafely embedded into a Python import statement.

datamodel-code-generator < 0.70.0 code-injection rce vulnerability
1t 1c
critical advisory

SiYuan Missing Authorization Vulnerability in /mcp Endpoint (CVE-2026-66012)

A critical missing authorization vulnerability, CVE-2026-66012, in SiYuan before version 3.7.2 allows a remote unauthenticated attacker to exploit the POST /mcp kernel endpoint when the Publish server is in anonymous mode, leading to arbitrary file writes, sensitive credential exposure, malicious plugin execution, and ultimately administrator takeover on affected systems.

SiYuan < v3.7.2 vulnerability rce authorization-bypass siyuan cve-2026-66012
5t 2i updated
low advisory

AWS Smithy-RS HTTP Server Vulnerable to Unauthenticated Slowloris Denial of Service

An unauthenticated Slowloris denial of service vulnerability exists in the default `serve()` path of AWS's `aws-smithy-http-server` framework (versions <= 0.66.4), allowing remote attackers to exhaust server resources by initiating numerous incomplete connections.

aws-smithy-http-server denial-of-service vulnerability webserver rust aws
1t 1c
high advisory

AWS Bedrock AgentCore Python SDK Arbitrary Command Execution Vulnerability

An improper neutralization of argument delimiters vulnerability (CVE-2026-16796) in the AWS Bedrock AgentCore Python SDK's `install_packages()` method allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox by crafting malicious package name arguments.

bedrock-agentcore cloud vulnerability rce aws
1t 1c
high advisory

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure (CVE-2026-16584)

The AWS API MCP Server has a high-severity vulnerability, CVE-2026-16584, where a failure to initialize security policy data at server startup leads to a silent bypass of all per-request policy checks, allowing AWS API operations to execute without the intended restrictions, though underlying IAM permissions remain enforced.

AWS API MCP Server vulnerability cloud aws security-bypass
1c
medium advisory

py-libp2p yamux Connection DoS via Oversized Data Frame

A denial-of-service vulnerability in py-libp2p versions up to 0.6.0 allows an authenticated attacker to send a specially crafted 12-byte DATA or SYN frame with an oversized length field, causing the victim's yamux read loop to block indefinitely and freezing all streams on the affected connection.

py-libp2p denial-of-service vulnerability network python libp2p
1t
high advisory

Multiple HTTP/1.1 Request Smuggling Primitives in Blaze Java Parser

Five independent HTTP/1.1 conformance laxities in Blaze's Java parser cause request-boundary disagreement with a stricter intermediary proxy, enabling front-end ACL/authentication bypass, response-queue poisoning on pooled backend connections, and cache poisoning in affected `http4s-blaze-server` and `blaze-http` components.

http4s-blaze-server_2.13 +2 request-smuggling http/1.1 java vulnerability
2t
low advisory

Denial of Service via Unbounded Expansion Length in Node.js brace-expansion Library (CVE-2026-14257)

An attacker can exploit CVE-2026-14257, a denial of service vulnerability in the `brace-expansion` Node.js library, by crafting an input with deeply chained brace groups that causes the expanded string length to grow without bound, leading to an uncatchable out-of-memory process crash in any application processing untrusted input via `expand()` directly or through dependencies like `minimatch` or `glob`.

brace-expansion denial-of-service vulnerability node.js software-supply-chain
1t 1c
high advisory

Poweradmin OIDC `sub` Collation Bypass Leads to Account Takeover

A collation vulnerability in Poweradmin's OIDC integration allows an unauthenticated attacker to take over victim accounts by exploiting the case and accent-insensitive MySQL collation (`utf8mb4_unicode_ci`) used for OIDC subject (`sub`) identifiers, causing the attacker's colliding `sub` to resolve to the victim's `user_id` during authentication.

Poweradmin >= 4.1.0, < 4.2.5 +1 account-takeover oidc vulnerability web-application poweradmin
1t
medium advisory

Poweradmin: Broken Access Control (IDOR) Allows DNS Record Modification

A low-privilege authenticated user in Poweradmin (a web front-end for PowerDNS) can exploit an Insecure Direct Object Reference (IDOR) vulnerability, allowing them to modify any DNS record on the server, even those they do not own, by manipulating POST request parameters to bypass access control checks and achieve DNS record repointing, disabling, or hijacking, leading to data integrity and availability issues, and potentially cross-tenant DNS takeover.

Poweradmin +2 idor dns-takeover web-application vulnerability access-control
3t 5i
high advisory

frp: Unauthenticated Remote Denial of Service in SSH Tunnel Gateway via Integer Overflow

An unauthenticated remote denial-of-service vulnerability exists in the frp server's optional SSH Tunnel Gateway (frps) that allows an attacker to crash the entire frps process by sending a specially crafted five-byte message containing an integer overflow value in an SSH `exec` channel request, leading to a sustained service outage.

frp +2 denial-of-service vulnerability integer-overflow
1t
high advisory

Vantage6 Algorithm Developer Can Edit Other Developers' Pending Algorithms

An algorithm developer in the vantage6 system can modify another developer's algorithm metadata or Docker image tag, even when that algorithm is pending review, allowing an attacker with low privileges to replace an approved algorithm with an unapproved or malicious image.

vantage6 vulnerability supply-chain authorization application-security
1t
high advisory

GitPython Environment Variable Exfiltration via Remote URL Processing

A vulnerability in GitPython allows environment variables to be exfiltrated when using `Repo.create_remote()` or `Remote.add()`, where attacker-supplied URLs are processed by `Git.polish_url()` expanding sensitive environment variables into the URL, which is then stored in `.git/config` and transmitted to an attacker-controlled host.

GitPython supply-chain vulnerability exfiltration data-theft
2t 2i
high advisory

Budibase MongoDB Datasource Vulnerability Allows Server Filesystem Existence/Read Oracle

A vulnerability in Budibase's MongoDB datasource configuration allows authenticated attackers to specify arbitrary absolute server-side file paths for `tlsCertificateKeyFile` and `tlsCAFile`, enabling the `/api/datasources/verify` endpoint to act as an arbitrary-path existence/read oracle on the underlying multi-tenant server, distinguishing between existing and non-existing files and potentially exfiltrating certificate content.

npm/@budibase/server <= 3.38.1 +1 budibase vulnerability file-read information-disclosure cloud mongodb api web-vulnerability +1
2r 6t 2i
critical advisory

SQL Injection Vulnerability in Budibase MySQL Integration

A critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.

Budibase Server +1 sql-injection web-application vulnerability nosql-injection data-exfiltration data-destruction application-vulnerability csrft +4
1r 7t
critical advisory

Budibase OIDC SSO Account Takeover via Unverified Email Claim

A critical vulnerability in Budibase versions up to 3.38.1 allows full account takeover of any existing user, including global administrators, by exploiting a flaw in its OIDC SSO implementation that links incoming identities by email address alone without validating the `email_verified` claim, enabling an attacker to log in as a victim if they can coerce a trusted Identity Provider to assert the victim's email as unverified.

Budibase <= 3.38.1 oidc sso account-takeover budibase vulnerability
1t
low advisory

Denial of Service Vulnerability in React Server Components

A denial of service vulnerability (CVE-2026-44907) affects multiple versions of the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages, allowing threat actors to trigger out-of-memory exceptions or excessive CPU usage by sending specially crafted HTTP requests to server function endpoints.

react-server-dom-webpack +2 react denial-of-service web vulnerability
1t 1c
high advisory

Budibase Privilege Escalation via Role Assignment API

An app-scoped builder in Budibase can exploit a missing authorization flaw in the public role assignment API (`POST /api/public/v1/roles/assign`) to escalate privileges, granting themselves builder access to any other application within the tenant, read/modify data, exfiltrate datasource credentials, and execute arbitrary code via automation steps, compromising the entire tenant's app and data plane in Budibase versions up to and including 3.39.19 and npm/@budibase/server up to 3.38.1.

Budibase +1 privilege-escalation API-abuse authorization-bypass vulnerability
4t
critical advisory

Critical Unauthenticated Remote Code Execution in OpenAM WebAuthn due to Deserialization Vulnerability (CVE-2026-62263)

A critical remote code execution (RCE) vulnerability, CVE-2026-62263, exists in OpenAM's WebAuthn authenticator deserialization, allowing an unauthenticated attacker to bypass an `ObjectInputFilter` and execute arbitrary code by crafting a malicious serialized stream before authentication.

openam-auth-webauthn deserialization rce webauthn java openam vulnerability
2t
high advisory

Open WebUI Terminal Proxy Path Traversal Bypass via 9x Encoding (CVE-2026-59221)

An incomplete fix for a path traversal vulnerability in Open WebUI's terminal proxy allows authenticated attackers to bypass security checks by sending a 9x percent-encoded path, leading to requests being forwarded with terminal credentials and user identification headers to unintended arbitrary paths outside the intended proxy scope.

Open WebUI path-traversal web-application vulnerability open-webui defense-evasion
1r 1t 1c
high advisory

yt-dlp Shortcut Command Injection Vulnerability

A high-severity command injection vulnerability, CVE-2026-55404, in yt-dlp versions prior to 2026.7.4 allows remote attackers to achieve arbitrary code execution by crafting malicious metadata that is improperly sanitized when generating Windows `.url` or Linux `.desktop` shortcut files, leading to remote executable execution or shell command injection upon user interaction.

yt-dlp command-injection rce client-side vulnerability code-execution
1r 3t 1c
high advisory

FFmpeg Heap Out-of-Bounds Write Vulnerability (CVE-2026-66041)

A heap out-of-bounds write vulnerability exists in the vf_quirc filter of FFmpeg versions 7.0 through 8.1.2, allowing an attacker to corrupt heap memory and potentially achieve arbitrary code execution by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions.

FFmpeg 7.0 +1 ffmpeg vulnerability heap-overflow rce
1c
high advisory

CVE-2026-66040: FFmpeg Heap Out-of-Bounds Write in PNG/APNG Encoders

A heap out-of-bounds write vulnerability, CVE-2026-66040, exists in the native PNG and APNG encoders of FFmpeg through version 8.1.2, allowing remote attackers to corrupt heap memory and achieve potential arbitrary code execution by supplying a crafted PNG image with a malicious eXIf chunk.

FFmpeg cve vulnerability heap-overflow rce
1t 1c
high advisory

FFmpeg Heap Out-of-Bounds Write Vulnerability (CVE-2026-66036)

A heap out-of-bounds write vulnerability exists in FFmpeg through version 8.1.2, specifically within the vf_hqdn3d filter, allowing attackers to corrupt heap memory by providing a crafted video input where frame resolution increases between frames while filtergraph reinitialization is disabled, leading to undersized buffers and a write beyond allocation boundaries.

FFmpeg vulnerability heap-corruption code-execution dos
1c
high advisory

Red Hat Advanced Cluster Management Vulnerability Allows Cluster-Admin Privilege Escalation

A flaw exists in the cluster-proxy service-proxy component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE), allowing an authenticated hub principal to inject an Impersonate-Group header into proxied requests, bypassing validation, and leveraging the spoke ServiceAccount's unrestricted impersonation permissions to escalate privileges to cluster-admin on all managed clusters.

Red Hat Advanced Cluster Management for Kubernetes +1 privilege-escalation vulnerability kubernetes cloud red-hat
1t 1c
high advisory

CVE-2026-66032 - libssh2 SFTP Double-Free Vulnerability

A double-free vulnerability, CVE-2026-66032, in libssh2 versions through 1.11.1 allows a malicious SSH server to corrupt the heap of an authenticated client opening an SFTP session, potentially leading to arbitrary code execution.

libssh2 <= 1.11.1 ssh sftp double-free vulnerability libssh2 memory-corruption rce DoS +2
4t 4c
high advisory

CVE-2026-65709 - sysPass JSON-RPC API Missing Object-Level Authorization

sysPass versions up to 3.2.11 are affected by a missing object-level authorization vulnerability in the JSON-RPC API. Attackers holding an API token can exploit this flaw by invoking AccountController methods (e.g., viewAction, editAction, deleteAction, editPassAction) without proper AccountFilterUser checks, allowing them to enumerate account metadata, overwrite passwords, and delete user accounts across the entire vault, bypassing per-account access control defined by their token permissions.

sysPass +1 vulnerability authorization-bypass api-exploitation cve missing-authorization credential-disclosure web-application
5t 3c
high advisory

Open WebUI Cross-Channel Message Overwrite Vulnerability

An authenticated user can overwrite messages in any channel, including private and DM channels, by exploiting the CVE-2026-59714 authorization bypass vulnerability in Open WebUI's chat completion API, leading to message integrity destruction and impersonation.

Open WebUI vulnerability web-application api-abuse authorization-bypass ghsa data-manipulation
3t 1i
high advisory

Open WebUI: Cross-User Code-Interpreter and Tool Execution via Unvalidated Socket.IO Session ID

An authenticated low-privilege user can exploit CVE-2026-59216 in Open WebUI versions prior to 0.10.0 to execute arbitrary Python code or tools within another user's authenticated session by supplying an unvalidated `session_id`, which, if targeting an administrator, leads to remote code execution on the server as the root process.

Open WebUI web-vulnerability rce session-hijacking open-webui python vulnerability web-application identity-spoofing +1
1r 3t 1c
high advisory

Open WebUI: Realtime Endpoints Fail to Revoke JWTs

Open WebUI versions from 0.9.0 to before 0.10.0, when configured with Redis, fail to correctly enforce JWT revocation for realtime authentication endpoints such as Socket.IO and terminal websockets, allowing attackers to maintain access to real-time features with stolen, revoked JWTs.

Open WebUI vulnerability jwt authentication webui realtime bypass
1t 1c
medium advisory

Netty XmlFrameDecoder CPU Exhaustion Denial of Service

An unauthenticated remote attacker can cause a Denial of Service (DoS) in Netty servers utilizing XmlFrameDecoder by sending a specially crafted XML payload containing repeated '</' characters, leading to CPU exhaustion of the server's EventLoop thread and unresponsiveness.

netty-codec-xml +1 denial-of-service cpu-exhaustion network-attack vulnerability
1t
high advisory

Open WebUI: Stored Web Worker XSS via Pyodide Leading to Server-Side RCE

A stored web worker XSS vulnerability, CVE-2026-59214, in Open WebUI versions prior to 0.10.0 allows a low-privileged user to inject malicious Python code into chat messages that, when executed by an administrator or privileged user via a 'Run' click, triggers authenticated same-origin requests to create server-side functions with arbitrary commands, leading to remote code execution on the Open WebUI server.

Open WebUI < 0.10.0 xss rce pyodide web-application vulnerability
4t 1c
medium advisory

React Router RSC Mode CSRF Bypass

A high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.

react-router react router csrf web-application vulnerability
1t 1c
medium advisory

js-yaml Denial of Service via Exponential Parsing Time in Flow Collections

A denial of service vulnerability exists in the js-yaml library (versions 5.0.0 through 5.2.1) due to an exponential parsing time bug in flow collections, allowing attackers to craft a small YAML document which, when processed by `load()` or `loadAll()` functions, consumes significant CPU resources and blocks the Node.js event loop.

js-yaml denial-of-service yaml javascript vulnerability
1t
high advisory

GitPython Incomplete Denylist Allows Arbitrary Command Execution via Git Clone Hooks

A critical vulnerability in GitPython versions up to 3.1.53 allows attackers to achieve arbitrary command execution by influencing `git clone` options to include a malicious `--template` directory, which causes Git hooks to be copied and executed during cloning, even in default configurations.

GitPython <= 3.1.53 git python vulnerability rce
1r 3t
critical advisory

Velocity.js Remote Code Execution via Function Constructor Bypass

Velocity.js versions up to 2.1.6 are vulnerable to Remote Code Execution (RCE) through an incomplete fix for a previous prototype pollution vulnerability, enabling attackers to craft malicious Velocity templates to leverage unfiltered property-read expressions and execute arbitrary JavaScript code on the server, leading to full server compromise.

velocityjs <= 2.1.6 velocityjs rce nodejs vulnerability server-side
1r 2t 1i
critical advisory

Server-Side Template Injection to Remote Code Execution in @prompty/core Nunjucks Renderer

A critical server-side template injection vulnerability exists in the @prompty/core Nunjucks renderer, affecting versions <= 0.1.4 and >= 2.0.0-alpha.1 up to <= 2.0.0-beta.4. This flaw allows an attacker to execute arbitrary JavaScript code within the host Node.js process by crafting malicious `.prompty` template bodies. The renderer's unrestricted JavaScript member access permits traversal of constructor and prototype properties, leading to remote code execution when rendering untrusted, community-supplied, cloned, or LLM-generated `.prompty` files.

@prompty/core +1 server-side-template-injection remote-code-execution nodejs npm vulnerability
1t
high advisory

Suna Broken Access Control Vulnerability (CVE-2026-66027)

A broken access control vulnerability in Suna's message queue API allows authenticated attackers to gain unauthorized access to and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. This exploit enables attackers to read all users' pending prompt queues, read or delete individual sessions, and inject arbitrary prompts into another user's session, which causes the background drainer to forward malicious messages to the victim's AI agent using their credentials and permissions, leading to potential data manipulation, unauthorized actions, or further compromise.

Suna < 0.9.102 broken-access-control vulnerability suna ai message-queue
4t 1c
medium advisory

Account Takeover via Pre-Account Hijacking in Better Auth Library

An attacker can perform a pre-account hijacking attack against the `better-auth` library if it uses magic-link or email-OTP plugins alongside open email and password registration and allows unverified accounts. The attacker first registers an account using the victim's email with a password they control. When the legitimate victim later uses a passwordless flow to verify their account, the attacker's pre-set password remains active, granting them persistent, unauthorized access to the victim's account and data, potentially leading to account takeover and user lockout.

better-auth < 1.6.22 +1 account-takeover vulnerability web-application pre-account-hijacking
3t
medium advisory

Account Takeover and Stale Access via SCIM Provider-ID Collision in @better-auth/scim

The `@better-auth/scim` package is affected by multiple vulnerabilities, including a critical provider-ID collision flaw that allows authenticated users to craft SCIM tokens impersonating existing account providers, leading to unauthorized account access, profile modification, and user deletion, while additional issues include failed user deactivation and email update vulnerabilities bypassing uniqueness checks in versions `1.4.0-beta.27` through `1.6.21` and `1.7.0-beta.0` through `1.7.0-beta.9`.

@better-auth/scim vulnerability web-application account-takeover sso
5t
high advisory

CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability

The Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.

Easy Appointments plugin wordpress plugin vulnerability data-modification
1r 1t 1c
low advisory

httplib2 Decompression Bomb Denial of Service via Unbounded Gzip/Deflate Handling

A high-severity vulnerability in the `httplib2` Python client library allows a remote attacker to trigger a denial-of-service condition by sending a crafted HTTP response with a small, highly compressed payload that expands excessively upon decompression, causing memory exhaustion or OOM-kill in the client process.

httplib2 +2 denial-of-service vulnerability python client-side
1t 1c
medium advisory

LiquidJS pop Filter Bypasses Memory Limit Accounting

A vulnerability (CVE-2026-55575) in the LiquidJS templating library's `pop` filter, affecting versions up to and including 10.27.0, allows an attacker to bypass the `memoryLimit` accounting, leading to uncontrolled memory allocation and potential denial of service when processing untrusted, large arrays in templates.

LiquidJS denial-of-service vulnerability memory-exhaustion nodejs
1t 1c
high advisory

electron-updater Vulnerability Leaks Credentials on Cross-Origin Redirects

A vulnerability, CVE-2026-54673, in `electron-builder`'s `builder-util-runtime` package, specifically in its HTTP redirect handler, allows credential headers like `PRIVATE-TOKEN` (GitLab personal access tokens) and mixed-case `Authorization` tokens to be improperly forwarded to attacker-controlled cross-origin redirect destinations, resulting in credential disclosure and enabling unauthorized access to private GitLab resources.

builder-util-runtime < 9.7.0 +2 credential-access exfiltration vulnerability electron software-supply-chain gitlab
2t 1c
medium threat

Multiple Vulnerabilities in MongoDB Core Server and Compass

Numerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.

exploited Compass +4 vulnerability database mongodb
2t 5c 52i
high advisory

Multiple Privilege Escalation Vulnerabilities in ESET macOS Products

Multiple vulnerabilities discovered in ESET Cyber Security and Endpoint Security for macOS allow an attacker to achieve privilege escalation on affected systems, posing a significant risk to macOS users.

Cyber Security for macOS +3 privilege-escalation vulnerability macos
1t 2c 4i
high threat

Multiple Vulnerabilities in Progress Software MOVEit Transfer

Multiple vulnerabilities in Progress Software MOVEit Transfer allow attackers to bypass security measures, achieve elevated privileges, and manipulate or disclose sensitive data, including the ability to perform Cross-Site-Scripting (XSS) attacks.

exploited MOVEit Transfer vulnerability moveit file-transfer data-exfiltration privilege-escalation web-application
4t
medium advisory

FFmpeg: Multiple Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in FFmpeg allow an attacker to achieve arbitrary code execution or cause a denial-of-service condition.

ffmpeg vulnerability code-execution dos execution impact
2t
medium advisory

Multiple Netty Vulnerabilities Enable Denial of Service Attacks

Multiple vulnerabilities in Netty can be exploited by an attacker to conduct Denial of Service (DoS) attacks, impacting the availability of services utilizing the Netty framework.

Netty denial-of-service vulnerability framework
1t
high advisory

JetBrains WebStorm Multiple Vulnerabilities Allow Code Execution

Multiple vulnerabilities in JetBrains WebStorm allow a local attacker to execute arbitrary program code, enabling attackers to compromise the integrity and confidentiality of the affected system.

WebStorm arbitrary-code-execution vulnerability development-environment
1t
high advisory

JetBrains IntelliJ IDEA: Multiple Vulnerabilities

Multiple vulnerabilities have been identified in JetBrains IntelliJ IDEA, which a remote, unauthenticated attacker can exploit to disclose sensitive information, execute arbitrary code on affected systems, and bypass existing security measures.

IntelliJ IDEA vulnerability rce information-disclosure defense-evasion development-tools
4t
medium advisory

Red Hat Quay Vulnerability Allows Authenticated Remote Attacker to Bypass Security

An authenticated remote attacker can exploit a vulnerability in Red Hat Quay to bypass security measures, circumventing established security controls within the container registry.

Red Hat Quay red-hat quay vulnerability security-bypass container-registry
1t
medium advisory

QT Vulnerability Enables File Manipulation

A remote, anonymous attacker can exploit a vulnerability in QT to manipulate files, potentially affecting data integrity or system functionality.

QT vulnerability file-manipulation
1t
medium advisory

Apache Tomcat mod_jk Connector: Vulnerability Enables Security Bypass or Information Disclosure

A vulnerability in the Apache Tomcat mod_jk Connector allows a remote, unauthenticated attacker to bypass security measures or disclose sensitive information, which could enable an adversary to gain unauthorized access or collect confidential data.

Tomcat mod_jk Connector defense-evasion network vulnerability
2t
high advisory

CVE-2026-57106 Microsoft Data Quality Elevation of Privilege Vulnerability

CVE-2026-57106 describes a server-side request forgery (SSRF) vulnerability in Microsoft Data Quality that allows an unauthorized attacker to elevate privileges over a network.

Data Quality cve vulnerability ssrf elevation-of-privilege
1t
high advisory

CVE-2026-63313 - Server-Side Request Forgery in 9Router

9Router versions prior to 0.4.72 contain a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint, allowing an authenticated or locally-connected user to bypass URL validation to fetch arbitrary internal URLs, potentially exposing cloud metadata credentials, accessing internal services, and bypassing authentication on localhost endpoints.

9Router < 0.4.72 ssrf vulnerability web-application router
1r 4t 1c
critical advisory

9router Critical Vulnerability Chain Allows Remote Code Execution via Default Password and Plugin Exploitation

A critical vulnerability chain, CVE-2026-63732, in 9router version 0.4.59 allows a remote, unauthenticated attacker to achieve arbitrary code execution on the host operating system by leveraging a hardcoded default password for initial access, bypassing a local-only network restriction via Host header spoofing, and exploiting unvalidated arguments during MCP plugin registration to execute malicious code when a plugin's SSE endpoint is triggered.

9router 0.4.59 vulnerability remote-code-execution hardcoded-credentials webserver nodejs
2r 3t 1c 1i
critical advisory

Repository Takeover Vulnerability in cal.com GitHub Actions (CVE-2024-58354)

A critical repository takeover vulnerability (CVE-2024-58354) exists in the cal.com (calcom/cal.diy) GitHub Actions workflows, allowing an attacker to submit a malicious pull request that executes arbitrary commands with write permissions to the repository, leading to full compromise.

cal.com +1 github-actions repository-takeover vulnerability cloud-security
1t 1c
high advisory

Critical Out-of-Bounds Write Vulnerability in FFmpeg (CVE-2026-65706)

A critical out-of-bounds write vulnerability (CVE-2026-65706) exists in FFmpeg versions 3.0 through 8.1.2 within the vf_swaprect video filter, allowing attackers to corrupt heap memory and achieve potential remote code execution by providing a specially crafted NV12 video frame with odd width dimensions.

FFmpeg versions 3.0 through 8.1.2 vulnerability RCE out-of-bounds-write video-processing FFmpeg
1t 1c
high advisory

Out-of-Bounds Write Vulnerability in FFmpeg vf_floodfill Filter (CVE-2026-65705)

A critical out-of-bounds write vulnerability exists in FFmpeg versions 3.4 through 8.1.2 within the vf_floodfill video filter, which attackers can exploit by providing a specially crafted, dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0, leading to heap corruption, a process crash, and potentially remote code execution.

FFmpeg versions 3.4 through 8.1.2 cve vulnerability out-of-bounds-write ffmpeg video-processing
1c
high advisory

FFmpeg TDSC Video Decoder Out-of-Bounds Write Vulnerability

An out-of-bounds write vulnerability (CVE-2026-65703) exists in the TDSC video decoder within FFmpeg versions 2.7 through 8.1.2, allowing remote attackers to cause heap corruption and potential code execution by supplying a specially crafted AVI file with changing frame dimensions across TDSF frames.

FFmpeg 2.7 +1 vulnerability media-processing code-execution
1t 1c
high advisory

CVE-2026-15212: WordPress WPO365 Login Plugin Cross-Site Request Forgery Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability in the WPO365 | Login plugin for WordPress, affecting versions up to and including 43.2, allows unauthenticated attackers to overwrite arbitrary plugin options. This is due to a misconfiguration where the nonce check is effectively disabled. By tricking a site administrator into clicking a malicious link, an attacker can manipulate settings such as enabling the SCIM REST endpoint, planting a SCIM secret token, and setting the default user role for new registrations to 'administrator', potentially leading to full site compromise and unauthorized administrative access.

WPO365 | Login plugin wordpress plugin csrf vulnerability web
1r 4t 1c
medium advisory

Denial of Service Vulnerability in find-my-way Node.js Router

A remotely triggerable Denial of Service (DoS) vulnerability exists in the 'find-my-way' router when used with Node.js HTTP/2 servers. Malicious HTTP/2 method values, such as 'constructor' or '__proto__', can be passed to the 'lookup()' function, which then indexes these values against internal data structures. This leads to a crash when the code attempts to access properties of these unexpected values, such as 'currentNode.prefix.length', causing the server to become unavailable. Users are advised to upgrade to version 9.7.0 or validate HTTP methods before processing.

find-my-way denial-of-service nodejs http2 vulnerability
1r 2t
high advisory

CVE-2026-63765: Chatwoot Authentication Bypass Vulnerability in Direct Uploads Controller

Chatwoot before version 4.16.0 contains an authentication bypass vulnerability in its direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account by exploiting missing authentication checks, leading to data manipulation.

Chatwoot < 4.16.0 authentication-bypass web-application vulnerability cve
1r 2t 1c
high advisory

Vanna FileSystemConversationStore Path Traversal Vulnerability (CVE-2026-65702)

Vanna versions up to and including 2.0.2 contain a path traversal vulnerability in its FileSystemConversationStore persistence integration, allowing unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary server filesystem locations and read conversation metadata or other files from outside the intended base directory by supplying path traversal sequences within the 'conversation_id' parameter to unauthenticated chat API endpoints.

Vanna <= 2.0.2 path-traversal file-write file-read vulnerability web-application cve
1r 3t 1c
low advisory

pypdf: Possible infinite loop for not terminated inline images

An attacker can exploit a vulnerability in the pypdf library by crafting a PDF containing a malformed, not terminated inline image. When this malicious PDF is processed by pypdf, such as during text extraction, it triggers an infinite loop, leading to a denial of service. The issue is resolved in pypdf version 6.14.1.

pypdf denial-of-service vulnerability python library
1c
critical advisory

CyberPanel Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-65917)

An Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-65917, exists in CyberPanel versions through 1.9.1, specifically within the IncBackups application's incremental-backup handlers, allowing authenticated panel users to exploit attacker-controlled IncJob integer IDs to access, read metadata from, delete, or trigger unauthorized restoration of other tenants' backup resources, potentially leading to operations with root privileges.

CyberPanel vulnerability idor web-panel privilege-escalation data-manipulation
3t 1c
medium advisory

PHPSpreadsheet Denial of Service via Malformed XLS/OLE Sector Chain

PhpSpreadsheet's OLE reader contains a denial-of-service vulnerability where it fails to detect cycles in attacker-controlled XLS/OLE sector chains, leading to infinite loops and memory exhaustion when parsing specially crafted, small malformed XLS/OLE files, which can cause PHP workers to crash and deny service to web applications processing untrusted spreadsheet uploads.

PhpSpreadsheet +4 denial-of-service vulnerability php xls ole
1t
high advisory

PostCSS: Arbitrary File Read and Information Disclosure via sourceMappingURL

A high-severity vulnerability (CVE-2026-45623) in PostCSS's `PreviousMap` component allows attackers to perform arbitrary file reads and information disclosure from the local filesystem by injecting malicious `sourceMappingURL` comments into untrusted CSS input, leading to sensitive data leakage and denial of service.

postcss file-read information-disclosure supply-chain nodejs web-application vulnerability cve-2026-45623
3t
medium advisory

PhpSpreadsheet Gnumeric Reader Unbounded Gzip Expansion Leads to Denial of Service

The PhpOffice PhpSpreadsheet library is vulnerable to a denial of service (DoS) attack, identified as CVE-2026-59932, where its Gnumeric reader processes attacker-supplied `.gnumeric` files containing gzipped content without enforcing a decompressed-size limit, causing memory exhaustion and application crashes.

PhpSpreadsheet +4 denial-of-service vulnerability php ghsa software-supply-chain
1t
medium advisory

Auth.js getToken() Vulnerability Leads to Denial of Service

A vulnerability in the Auth.js `getToken()` helper function (next-auth and @auth/core) allows unauthenticated attackers to trigger an uncaught exception via a malformed `Authorization: Bearer` header, leading to a per-request denial of service in affected applications.

@auth/core +1 denial-of-service vulnerability web-application javascript input-validation
1t
high advisory

Bold Reports Standalone Report Designer Path Traversal to RCE Vulnerability

A missing filepath validation vulnerability (CVE-2026-65690) in Bold Reports Standalone Report Designer before version 14.1.12 allows authenticated attackers to perform path traversal via crafted filenames during file upload, leading to arbitrary command execution with high privileges.

Standalone Report Designer vulnerability path-traversal rce web-application
1r 1t 1c 2i
critical advisory

CVE-2026-65689: Bold Reports Standalone Report Designer Path Traversal Vulnerability

A missing filepath validation vulnerability (CVE-2026-65689) in Bold Reports Standalone Report Designer before version 14.1.12 allows unauthenticated attackers to perform path traversal by sending a crafted request to the database download feature, enabling them to read arbitrary sensitive server files, including authentication credentials, and potentially gain full unauthorized access to the application.

Standalone Report Designer path-traversal vulnerability web-application arbitrary-file-read cve
1r 1t 1c
high advisory

Grav API Plugin Privilege Escalation via Invitation Group Manipulation (CVE-2026-65897)

An authenticated attacker can exploit CVE-2026-65897 in Grav API Plugin versions prior to 1.0.10 by manipulating the 'groups' field during invitation creation, allowing invited accounts to gain super-admin API access, leading to privilege escalation.

Grav API Plugin privilege-escalation vulnerability
1t 1c 4i
high advisory

Grav API Plugin Path Traversal Vulnerability (CVE-2026-65896)

An authenticated API caller with 'api.pages.write' permission in Grav API Plugin (Composer package getgrav/grav-plugin-api) before version 1.0.10 can exploit a path traversal vulnerability (CVE-2026-65896). The 'POST /pages/{route}/move' endpoint's 'slug' field is not properly sanitized, allowing attackers to use path traversal sequences (e.g., '01.home/../../../pwned'). This enables them to move an entire page directory, including content and media, to an arbitrary writable location outside the intended 'user/pages/' directory, potentially leading to unauthorized file manipulation or system compromise.

Grav API Plugin path-traversal web-application vulnerability
3t 1c
high advisory

Grav API Plugin Missing Authorization Allows Security Settings Modification

Grav API Plugin versions prior to 1.0.10 contain a missing authorization vulnerability (CVE-2026-65895) allowing authenticated users with the 'api.config.write' privilege to modify critical security settings, including disabling site-wide rate limiting to enable credential brute-forcing attacks and reconfiguring CORS policies to include attacker-controlled origins with credentials enabled, potentially leading to unauthorized data access.

Grav API Plugin grav-cms api-plugin vulnerability access-control cwe-862
1t 1c
critical advisory

CVE-2026-65606 - SiYuan XSS to RCE Vulnerability

A critical cross-site scripting (XSS) vulnerability, CVE-2026-65606, exists in SiYuan desktop application versions prior to 3.7.2's `siyuan://` protocol handler, allowing an attacker to inject an unescaped `<img>` element into the tab header, leading to arbitrary JavaScript execution and ultimately operating system command execution due to `nodeIntegration:true`.

SiYuan xss rce desktop-application vulnerability cve
2t 1c
medium advisory

Exim: Multiple Vulnerabilities Allow Local Command Execution and Privilege Escalation

Multiple vulnerabilities in Exim allow a local attacker to execute arbitrary commands and escalate privileges on the affected system, enabling a local adversary to gain higher control over the mail transfer agent and potentially the underlying operating system.

Exim vulnerability privilege-escalation command-execution
2t
high advisory

Multiple Vulnerabilities in Mitel Products Allow Remote Code Execution and XSS

Multiple vulnerabilities have been discovered in Mitel MiCollab and Openscape UC products, enabling a remote attacker to achieve arbitrary code execution and conduct indirect remote code injection (XSS), posing significant risks to affected organizations.

MiCollab versions 10.2.x antérieures à 10.2 SP1 FP2 +4 vulnerability rce xss mitel
3t 2i
low advisory

CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement

A high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.

libcupsfilters +5 vulnerability denial-of-service linux printer-vulnerability
1t 1c
high threat

Multiple Vulnerabilities in n8n Workflow Automation Platform

An attacker can exploit multiple vulnerabilities in the n8n workflow automation platform to bypass security measures, perform a Denial of Service attack, disclose sensitive information, manipulate files, conduct SQL injection, and execute arbitrary code.

n8n vulnerability rce sql-injection denial-of-service data-exfiltration defense-evasion
5t
critical advisory

Mitel MiCollab Vulnerability Allows Remote Code Execution

A critical vulnerability in Mitel MiCollab allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full system compromise or further network penetration.

MiCollab vulnerability rce network
1t
high threat

Multiple Vulnerabilities Affect MongoDB

Multiple vulnerabilities in MongoDB allow an attacker to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, cause memory corruption, or trigger a denial-of-service condition.

exploited MongoDB vulnerability code-execution data-exfiltration denial-of-service data-manipulation
5t
high threat

Mitel OpenScape Cross-Site Scripting Vulnerability

A remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Mitel OpenScape, allowing the execution of malicious scripts in the victim's browser, potentially leading to session hijacking, data theft, or redirection to malicious websites.

OpenScape Authenticated Attacker cross-site-scripting vulnerability web-application
1r 1t
high advisory

Budibase: Multiple Vulnerabilities

Multiple vulnerabilities in Budibase allow an attacker to gain elevated privileges, perform SQL injection, bypass security measures, take over user accounts, manipulate or disclose data, and trigger a denial-of-service condition, enabling various malicious activities impacting data integrity, confidentiality, and system availability.

Budibase +3 vulnerability sql-injection privilege-escalation defense-evasion data-exfiltration denial-of-service
5t 1c 9i updated
medium advisory

Internet Systems Consortium BIND: Multiple Vulnerabilities

Multiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.

BIND dns vulnerability denial-of-service data-manipulation information-disclosure network-infrastructure
3t
medium threat

Intel Ethernet Products: Multiple Vulnerabilities

Multiple vulnerabilities exist in various Intel Ethernet products, which an attacker can exploit to trigger a denial-of-service condition and expose confidential information.

exploited Intel Ethernet Products vulnerability intel network-device dos information-disclosure
2t
high threat

OS Command Injection Vulnerability in Pardus-Update (CVE-2026-16287)

A high-severity OS command injection vulnerability, tracked as CVE-2026-16287, has been identified in the TUBITAK BILGEM Software Technologies Research Institute's pardus-update software, affecting versions from 0.6.6 before 0.7.0, enabling attackers to execute arbitrary operating system commands due to improper neutralization of special elements.

exploited pardus-update os-command-injection vulnerability linux
1t 1c 1i
high advisory

ARforms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via 'password' Field (CVE-2026-12421)

An insufficient input sanitization and output escaping vulnerability (CVE-2026-12421) in the ARforms plugin for WordPress, affecting versions up to and including 7.2.1, allows unauthenticated attackers to inject arbitrary web scripts via the 'password' field, leading to Stored Cross-Site Scripting (XSS) when a user accesses an injected page.

ARforms wordpress xss plugin web-application vulnerability
2t 1c
medium advisory

Excon Redirection Vulnerability (CVE-2026-54171)

A vulnerability, CVE-2026-54171, has been identified in the Excon library concerning the redaction of sensitive or risky headers when following redirects, which could potentially expose confidential information if not properly addressed.

Excon vulnerability information-disclosure library
1c
medium advisory

HAProxy Denial of Service Vulnerability (CVE-2026-26080)

A denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.

HAProxy Community Edition +3 denial-of-service vulnerability haproxy load-balancer
1c
low advisory

Libunbound Denial of Service via unwanted-reply-threshold

CVE-2026-44621 describes a vulnerability in Libunbound applications where, when configured with the 'unwanted-reply-threshold' option, they can be abruptly terminated, leading to a denial of service.

Libunbound denial-of-service vulnerability
1t 1c
high threat

Improper Input Validation in boazsegev facil.io WebSocket Frame Parser (CVE-2026-16632)

A high-severity improper input validation vulnerability, CVE-2026-16632, exists in the `websocket_on_protocol_error` function of the `boazsegev facil.io` WebSocket Frame Parser, allowing a remote unauthenticated attacker to manipulate the `on_message` argument with a publicly available exploit, potentially leading to denial of service or information disclosure.

exploited facil.io 0.7.4 +4 vulnerability web-application input-validation remote-code-execution
1t 1c
high advisory

JupyterLab Cross-site Scripting via Crafted Settings File

A cross-site scripting (XSS) vulnerability exists in JupyterLab versions 3.3.0 through 4.5.9 and 4.6.0 through 4.6.1, allowing arbitrary code execution because notebook display settings in the `overrides.json` file are not properly validated, enabling an attacker to craft a malicious file which, when imported by a user or automatically applied on a multi-tenant file system, can execute hidden instructions and compromise user data.

JupyterLab +1 xss code-execution vulnerability cloud
6t
high advisory

JupyterLab Image Viewer XSS Vulnerability Leading to RCE

A cross-site scripting (XSS) vulnerability exists in JupyterLab's image viewer, allowing an attacker to achieve remote code execution (RCE) on the JupyterLab server if a specially crafted image file is opened in the image viewer and then opened in a new browser tab; affected versions include JupyterLab prior to 4.5.10 and versions from 4.6.0 up to, but not including, 4.6.2, with patches available in versions 4.5.10 and 4.6.2.

JupyterLab +1 xss rce vulnerability web
2t
low advisory

Eclipse Jetty Denial of Service Vulnerability via 100-Continue Requests (CVE-2024-7708)

A memory leak vulnerability, CVE-2024-7708, in Eclipse Jetty's server handling of HTTP 100-Continue requests can be exploited by an attacker to trigger an OutOfMemory error, leading to a Denial of Service state for affected servers.

Jetty 10 +1 denial-of-service vulnerability webserver memory-leak
1t 1c
high advisory

n8n Edit Image Node Format Injection Allows Arbitrary File Write

An authenticated user can exploit a format injection vulnerability in the n8n Edit Image node to write arbitrary files outside the node's working directory within the n8n instance, potentially leading to remote code execution or other significant impact.

n8n +2 arbitrary-file-write vulnerability rce
2t
high advisory

n8n Git Node Operations Bypass Sandbox Path Restriction

An authenticated n8n user can exploit a path restriction bypass vulnerability within the Git node's fetch, pull, or push-tags operations to access arbitrary local Git repositories and their contents, potentially leading to sensitive data exposure.

n8n +2 vulnerability sandbox-bypass data-exfiltration workflow-automation
3t
high advisory

Authenticated Code Execution Vulnerability in n8n Git Node

An authenticated n8n user with workflow creation and execution rights can achieve arbitrary code execution on the n8n host by staging a crafted local Git repository within the Git node, causing Git to run malicious hooks as the n8n process user.

n8n +2 code-execution vulnerability authenticated-rce prototype-pollution denial-of-service credential-access
5t
high advisory

n8n Account Takeover via Unverified Email Claim in Token Exchange Embed Login

A high-severity vulnerability in n8n's embed login feature (CVE-2026-XXXX) allows attackers to achieve full account takeover by leveraging unverified email claims in incoming tokens, enabling authentication as any existing user if the instance has embed login enabled and a trusted key source configured that emits unverified email addresses.

n8n +2 vulnerability authentication-bypass account-takeover embed-login credential-access exfiltration rce sandbox-escape +1
2r 7t
high advisory

n8n Privilege Escalation and Code Execution via Flawed JWT Scope Assignment (CVE-2026-65595)

A critical vulnerability, CVE-2026-65595, in n8n's Token Exchange module allows low-privileged users to achieve privilege escalation and potential code execution by exploiting incorrect Public API key scope assignments to JWTs, enabling administrative operations.

n8n >= 2.30.0, < 2.30.1 +1 privilege-escalation code-execution vulnerability jwt-exploitation
2t 1c
low advisory

n8n AI Agents Module Restriction Bypass via MCP Connector (CVE-2026-59207)

The n8n AI Agents module in versions prior to 2.27.4 and between 2.28.0 and 2.28.1 failed to enforce configured 'Allowed HTTP Request Domains' restrictions, allowing an authenticated member-level user with 'use-only' access to a shared credential to bypass these domain restrictions and exfiltrate sensitive secrets to an attacker-controlled server.

n8n +1 vulnerability restriction-bypass data-exfiltration ai-agents
1t 1c
high advisory

n8n Shared Credential Leakage via HTTP Request Pagination Vulnerability

An authenticated n8n user with 'use-only editor access' can exploit CVE-2026-59209 in shared workflows when `N8N_EXPRESSION_ENGINE=vm` is enabled, allowing them to read sensitive HTTP Header Auth credentials from the `$request.headers` object within a paginated HTTP Request node's expression and exfiltrate them, bypassing credential domain restrictions.

n8n +2 vulnerability credential-access data-exfiltration application-security prototype-pollution authentication-bypass data-enumeration
5t 1c
medium advisory

Netty Bzip2Decoder Infinite Loop Vulnerability Leads to Event-Loop Thread Hang (CVE-2026-59901)

A denial-of-service vulnerability exists in the `Bzip2Decoder` handler within Netty's `netty-codec-compression` and `netty-codec` libraries, allowing a remote attacker to exploit CVE-2026-59901 by providing a specially crafted bzip2 stream, which causes an infinite loop in the run-length encoding state machine, leading to the permanent hang of an event-loop thread and application denial of service.

netty-codec-compression +1 denial-of-service vulnerability netty
1t
high advisory

Netty XML Injection Vulnerability (CVE-2026-56817)

A misconfiguration vulnerability (CVE-2026-56817) in Netty's XmlDecoder component allows attackers to send XML with DOCTYPE declarations to an unconfigured XML factory, potentially leading to XML External Entity (XXE) injection if the underlying Aalto XML parser resolves external entities, impacting Netty applications using `netty-codec-xml` versions 4.1.0.Final through 4.1.135.Final and 4.2.0.Final through 4.2.15.Final.

netty-codec-xml +1 netty xml xxe vulnerability java server-side web-application
1r 1t 1c
high advisory

Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

A critical vulnerability (CVE-2026-56820) in Netty's `OcspClient` allows a bad actor to bypass certificate revocation checks by replaying a valid OCSP 'GOOD' status response from an unrelated certificate, enabling a certificate validation bypass for any certificate issued by the same Certificate Authority.

netty-handler-ssl-ocsp +3 netty certificate-validation ocsp vulnerability replay-attack cve tls TOCTOU +1
1c
low advisory

Netty HTTP/3 Codec Vulnerability Leads to Denial of Service via Memory Exhaustion

A vulnerability in Netty's HTTP/3 `Http3FrameCodec`, tracked as CVE-2026-56816, allows an unauthenticated remote attacker to cause a denial of service by sending crafted reserved HTTP/3 frames with an excessively large, unvalidated payload length, leading to server memory exhaustion.

netty-codec-http3 denial-of-service vulnerability java netty http3
1t 1c
medium advisory

Netty HAProxyMessageDecoder Vulnerability Leads to Unbounded Memory Exhaustion

A vulnerability, CVE-2026-55851, in Netty's `HAProxyMessageDecoder` can lead to unbounded memory exhaustion when an attacker sends a specific PROXY protocol v2 binary prefix followed by a version byte of `0xFF`, causing a signed-byte sentinel collision that traps the decoder in a version-detection loop and ultimately exhausts the JVM's direct memory allocation, resulting in a denial of service.

netty-codec-haproxy +1 denial-of-service memory-exhaustion vulnerability proxy-protocol
1c
medium advisory

Netty SPDY SETTINGS Frame Denial of Service Vulnerability

A high-severity vulnerability, CVE-2026-55831, in Netty's SPDY SETTINGS decoder allows a remote unauthenticated attacker to trigger a denial of service by sending a crafted SPDY/3.1 SETTINGS frame that leads to excessive heap growth and CPU consumption due to unbounded map entries in `DefaultSpdySettingsFrame`.

netty-codec-http +3 denial-of-service vulnerability netty spdy java memory-leak DoS
3t 1c 1i
medium advisory

Question2Answer Session Invalidation Vulnerability

Attackers can exploit CVE-2026-64829, a session invalidation vulnerability in Question2Answer through version 1.8.8, where the forgot-password reset flow fails to clear the sessioncode field, allowing an attacker with a previously obtained remember-me cookie to retain authenticated access even after the account's password has been reset.

Question2Answer <= 1.8.8 question2answer vulnerability session-management web-application cve
2t 1c
high threat

Critical Access Bypass Vulnerability in Drupal Internationalization Single Sign-On Module

A critical access bypass vulnerability (SA-CONTRIB-2026-081) exists in the Internationalization Single Sign-On module for Drupal, affecting versions prior to 1.8.0, allowing an attacker to bypass authentication mechanisms and potentially gain unauthorized access or elevate privileges within the application.

exploited Internationalization Single Sign-On drupal cms vulnerability access-bypass web-application
1t
low advisory

FFmpeg RTP/ASF Demuxer Infinite Loop Vulnerability (CVE-2026-64834)

FFmpeg versions 0.6.3 through 8.1.2 are vulnerable to a remote denial of service (DoS) via CVE-2026-64834, allowing an attacker to trigger an infinite loop in the `rtp_asf_fix_header` function by sending a crafted RTP/ASF stream, leading to CPU exhaustion and service unavailability.

FFmpeg denial-of-service vulnerability media
1t 1c
critical threat

Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Actively Exploited

Check Point released a critical security advisory to address CVE-2026-16232, an authentication bypass vulnerability in SmartConsole, which is actively being exploited in the wild and affects Security Management, Multi-Domain Management, Firewall, and Multi-Domain Log Server products.

exploited PoC SmartConsole +9 cve vulnerability authentication-bypass checkpoint
1t 4c 6i updated
high advisory

FFmpeg ADX Audio Decoder Out-of-Bounds Memory Access Vulnerability

A high-severity out-of-bounds memory access vulnerability, tracked as CVE-2026-64835, exists in FFmpeg versions 4.4 through 8.1.2 within the ADX audio decoder, allowing attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change, potentially leading to denial of service, information disclosure, or arbitrary code execution.

FFmpeg vulnerability audio-codec memory-corruption denial-of-service remote-code-execution
1c
high advisory

FFmpeg Out-of-Bounds Read Vulnerability in S/PDIF Muxer (CVE-2026-64833)

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer, allowing attackers to exploit a missing bounds check in the `spdif_header_dts4` function by supplying a crafted DTS stream with an oversized `core_size` value during S/PDIF re-muxing, leading to unauthorized memory reads beyond the packet buffer and potential information disclosure or denial of service.

FFmpeg vulnerability out-of-bounds-read
1t 1c
high advisory

FFmpeg NVIDIA NVDEC Double-Free Vulnerability (CVE-2026-64832)

FFmpeg versions 4.4 through 8.1.2 are vulnerable to a double-free condition within the NVIDIA NVDEC hardware decoder component (libavcodec/nvdec.c), allowing attackers to trigger memory corruption by providing a specially crafted video file, which occurs when an error path frees memory via `nvdec_fdd_priv_free` due to no decoder surfaces remaining, and a subsequent layer attempts to free the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware acceleration.

FFmpeg 4.4 +7 vulnerability memory-corruption ffmpeg nvdec cve
1c
high advisory

n8n Authenticated Code Execution Vulnerability

A security advisory from CCCS highlights an authenticated code execution vulnerability (GHSA-rcv6-pvrj-4xcg) within the n8n Git node, affecting multiple versions prior to 1.123.67, 2.32.1, and 2.31.5, which could allow an authenticated attacker to execute arbitrary code on the host system.

n8n versions prior to 1.123.67 +5 authenticated-rce workflow-automation vulnerability
1t
high advisory

n8n AI Agents Privilege Escalation via run_node_tool

A privilege escalation vulnerability (CVE-2026-65015) exists in n8n's AI Agents feature, allowing users with the read-only Project Viewer role to execute arbitrary tool nodes and access unauthorized credential secrets, potentially leading to arbitrary command execution on the n8n host.

n8n +1 privilege-escalation vulnerability ai-agents web-application
1r 1t 1c
high advisory

n8n DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview

A DOM-Based Cross-Site Scripting (XSS) vulnerability in n8n allows an attacker to inject scripts into the HTML preview through an unsandboxed iframe srcdoc, enabling the injected script to run with the same origin as the editor; if a victim opens this compromised preview, the script can call authenticated APIs using their session, allowing an account with 'global:member' privileges to exploit this to gain unauthorized access or perform actions.

n8n +2 xss vulnerability web-application
2t 1c
high advisory

n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`

A stored DOM XSS vulnerability in n8n's Resource Locator feature allows attackers to inject malicious JavaScript into the cachedResultUrl parameter. When a victim opens a specially crafted workflow and interacts with external links, the JavaScript payload executes in their browser, due to a lack of scheme validation for `cachedResultUrl` passed to `window.open()`.

n8n +4 xss vulnerability privilege-escalation authenticated-rce sanitizer-bypass
2t 1c
high advisory

FFmpeg Vulkan HEVC Stack Buffer Overflow (CVE-2026-64831)

A stack buffer overflow vulnerability exists in the Vulkan HEVC hardware decoder within FFmpeg versions 8.0 through 8.1.2, allowing remote attackers to achieve arbitrary code execution by crafting a malicious HEVC/H.265 bitstream with an oversized vps_num_hrd_parameters value that overwrites return addresses and adjacent stack frames in the vk_hevc_end_frame function.

FFmpeg vulnerability buffer-overflow media-processing arbitrary-code-execution
1t 1c
high advisory

FFmpeg VobSub Heap Buffer Overflow Vulnerability (CVE-2026-64830)

FFmpeg versions 2.1 through 8.1.2 contain a heap buffer overflow vulnerability (CVE-2026-64830) in the VobSub subtitle demuxer, allowing attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file, potentially leading to arbitrary code execution in applications using FFmpeg's VobSub demuxer.

FFmpeg 2.1 +1 vulnerability heap-overflow ffmpeg arbitrary-code-execution media
1t 1c
high advisory

CVE-2026-13321 BIND Resolver Origin Validation Error

CVE-2026-13321 describes a vulnerability in the BIND resolver where it incorrectly accepts validly-signed NSEC records that contain a 'Next Domain Name' field pointing outside the signer's zone, impacting integrity with a CVSSv3.1 score of 8.6 and requiring immediate updates to affected BIND 9 installations.

BIND 9 +4 vulnerability dns bind
1c
low advisory

CVE-2026-13204: BIND 9 Denial-of-Service Vulnerability

A critical vulnerability (CVE-2026-13204) in Internet Systems Consortium (ISC) BIND 9 can lead to a denial-of-service condition where the server exits unexpectedly due to an assertion failure during DNSSEC validation of specific NSEC/NSEC3 record configurations. This allows an unauthenticated attacker to cause a BIND 9 DNS resolver to crash, disrupting DNS resolution services.

BIND 9 +4 dns dos vulnerability bind cve
1t 1c
low advisory

CVE-2026-12617: BIND 9 Denial of Service via Malicious DNS Responses

This vulnerability affects BIND 9 resolver (`named`) and can lead to unexpected program termination (denial of service). The issue occurs when the resolver receives specific, delayed, or out-of-order responses to queries for CNAME or DNAME and A records. Specifically, if an authoritative server delays a DNAME or self-referential CNAME response while providing an A record, the `named` process may crash.

BIND 9 +3 denial-of-service vulnerability dns bind linux
1c
high advisory

CVE-2026-11622: BIND 9 DNSSEC Resolver Memory Exhaustion Vulnerability

A DNSSEC validating resolver, specifically BIND 9 versions within the ranges 9.11.0-9.18.50, 9.20.0-9.20.24, 9.21.0-9.21.23, and their S1 variants, is vulnerable to a denial-of-service attack where an attacker can launch a random subdomain attack against a DNSSEC-signed zone by sending queries faster than the resolver can perform validation, leading to runaway memory usage and potentially exceeding configured limits by orders of magnitude.

BIND 9 +4 dns denial-of-service vulnerability isc bind cache-poisoning network
1t 1c
low advisory

Resource Exhaustion Vulnerability in BIND 9 DNSSEC Validation (CVE-2026-11605)

A resource exhaustion vulnerability, CVE-2026-11605, affects specific versions of ISC BIND 9, where DNSSEC validation disproportionately consumes CPU resources when processing superfluous RRSIG records, potentially leading to a denial of service.

BIND 9 +2 dns dnssec vulnerability denial-of-service resource-exhaustion
1t 1c
medium advisory

CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability

An attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.

BIND 9 +4 vulnerability denial-of-service dns bind networking
1c
critical advisory

CVE-2026-2395: Critical SQL Injection in Xpoda No Code Platform

Xpoda Türkiye Informatics Technology Inc.'s No Code Platform, specifically versions 4.3.1.0 through 20260722, is critically vulnerable to an SQL injection (CVE-2026-2395) that allows unauthenticated remote attackers to achieve high impact on the confidentiality, integrity, and availability of the system.

No Code Platform sql-injection web-application vulnerability
1r 3t 1c 1i
medium advisory

Multiple Vulnerabilities in Elastic Products

CERT-FR has issued an advisory detailing multiple vulnerabilities in Elastic products, including CVE-2026-42397 and CVE-2026-49092, which could allow an attacker to cause remote denial of service, compromise data confidentiality and integrity, and perform Server-Side Request Forgery (SSRF).

Elasticsearch 8.x +5 vulnerability elastic elasticsearch kibana data-integrity data-confidentiality denial-of-service ssrf
5c
medium advisory

Multiple Vulnerabilities in GLPI

Multiple vulnerabilities have been discovered in GLPI, specifically affecting versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26, which allow an attacker to compromise data confidentiality and integrity, and bypass security policies.

GLPI < 10.0.26 +1 vulnerability web-application glpi data-breach data-integrity security-policy-bypass
3t
high advisory

CVE-2026-4773: Authentication Bypass Vulnerability in Magarsus Consulting IDM-MFA

CVE-2026-4773 is an improper input validation vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA, allowing authentication bypass in versions from 2025.11.27 before 2026.03.10.

IDM-MFA cve authentication-bypass web-application vulnerability
1t 1c
high advisory

Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)

A command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.

Ansible Lightspeed Visual Studio Code extension +1 command-injection vscode-extension remote-code-execution vulnerability
1t 1c
high threat

Aruba AOS-CX: Multiple Vulnerabilities

Multiple vulnerabilities in Aruba AOS-CX can be exploited by an attacker to bypass security measures, execute arbitrary code, and manipulate files, which could lead to compromise of the network device.

exploited AOS-CX network vulnerability rce file-manipulation aruba
1t
high advisory

Ubuntu Desktop Vulnerability Allows Local Root Access via snap-confine

A high-severity vulnerability, CVE-2026-8933, in Ubuntu's snap-confine component of the snapd service allows an unprivileged local user to gain root access on affected Ubuntu Desktop systems by exploiting race conditions during temporary file creation, enabling full administrative control.

snapd +1 privilege-escalation vulnerability linux ubuntu local-access
1t 1c updated
high advisory

SolarWinds Serv-U: Multiple Critical Vulnerabilities

A remote, highly privileged attacker can exploit multiple vulnerabilities in SolarWinds Serv-U to execute arbitrary code as Root, gain administrator privileges, take over accounts, disclose confidential information, or perform Cross-Site Scripting attacks.

Serv-U vulnerability rce xss data-exfiltration
7t
medium advisory

Veeam Backup & Replication: Vulnerability Enables Privilege Escalation

A vulnerability in Veeam Backup & Replication allows a local attacker to escalate privileges on the affected system.

Veeam Backup & Replication privilege-escalation vulnerability veeam backup
1t
medium advisory

Ansible: Local Code Execution Vulnerability

A local attacker can exploit a vulnerability within Ansible software to execute arbitrary code on the affected system, potentially leading to further compromise or unauthorized actions on the host where Ansible is running.

Ansible vulnerability code-execution red-hat
1t
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities exist in Red Hat Ansible Automation Platform, stemming from issues in components such as node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, and DOMPurify. A remote, unauthenticated attacker can exploit these flaws to bypass security measures, perform Cross-Site Scripting (XSS) attacks, manipulate data, trigger Denial-of-Service (DoS) conditions, or execute arbitrary code on the affected system.

Ansible Automation Platform remote-code-execution xss denial-of-service data-manipulation vulnerability ansible red-hat
5t
medium advisory

Avahi Vulnerability Allows Local Denial of Service

A vulnerability in the avahi service allows a local attacker to perform a Denial of Service (DoS) attack, potentially leading to the unavailability of services or the system itself.

avahi denial-of-service vulnerability linux
1t
medium advisory

Libarchive Vulnerability Enables Remote Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in libarchive to initiate a Denial of Service attack, disrupting the availability of services or systems utilizing the affected library.

libarchive denial-of-service vulnerability library-vulnerability
1t
low advisory

Information Published for CVE-2026-64191

Information has been published regarding CVE-2026-64191, which addresses an issue in the i2c stub related to rejecting I2C block transfers with invalid lengths.

vulnerability patch-management informational
1c
high advisory

Oracle Java SE and GraalVM Vulnerability CVE-2026-47063 Allows Unauthenticated Data Integrity Compromise

An easily exploitable vulnerability, CVE-2026-47063, in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows unauthenticated attackers with network access to achieve unauthorized creation, deletion, or modification of critical data via API exploitation, impacting data integrity.

Java SE 8u491 +9 vulnerability java oracle graalvm integrity data-manipulation
2t 1c
high advisory

Multiple High-Severity Vulnerabilities in sharp and libvips Image Processing Libraries

Multiple high-severity vulnerabilities, including CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591, have been identified and patched in the libvips dependency used by the sharp image processing library, affecting users processing untrusted input with sharp versions prior to 0.35.0 or globally installed libvips prior to 8.18.3.

npm/sharp +1 vulnerability supply-chain image-processing npm libvips
4c
high advisory

Gitea OAuth Callback Re-enables Administrator-Disabled Accounts

An improper authorization vulnerability in Gitea's OAuth2 sign-in callback mechanism (CVE-2026-58422) allows users with linked external identity providers to unilaterally re-enable their administrator-disabled accounts, regaining full access and bypassing security controls.

Gitea improper-authorization oauth account-takeover persistence vulnerability
2t 1c
high advisory

Server-Side Request Forgery in mcp-webresearch (CVE-2026-65056)

A server-side request forgery (SSRF) vulnerability in mcp-webresearch version 0.1.7 allows attackers to bypass URL protocol validation by supplying private IP addresses, enabling them to leverage prompt injection to steer an LLM-controlled URL, forcing the server's Playwright browser to access internal network services and cloud instance metadata, which leads to the exfiltration of sensitive internal content, including credentials, into the model's context.

mcp-webresearch 0.1.7 ssrf vulnerability cloud data-exfiltration cve-2026-65056 llm-security
4t 1c
critical advisory

CVE-2026-65057 Server-Side Request Forgery in Keep Healthcheck Endpoint

An unauthenticated server-side request forgery (SSRF) vulnerability in Keep (commit 91c75e0) allows attackers to exploit an unprotected healthcheck endpoint by supplying crafted JSON payloads with malicious host values, forcing the backend to issue arbitrary HTTP requests to internal services or cloud metadata endpoints for internal network reconnaissance and theft of cloud credentials.

Keep SSRF vulnerability cloud web-vulnerability credential-theft
1r 2t 1c
critical advisory

CVE-2026-63764: Server-Side Request Forgery in lmdeploy OpenAI-Compatible API Server

An unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-63764, exists in lmdeploy's OpenAI-compatible API server, allowing attackers to access internal services and cloud metadata by submitting a crafted image_url that redirects to internal targets.

lmdeploy's OpenAI-compatible API server server-side-request-forgery ssrf vulnerability api cloud-security
1r 1t 1c
high advisory

Gitea OAuth2 Sign-in Flaw Reactivates Administrator-Deactivated Accounts

A vulnerability (CVE-2026-55987) in Gitea's OAuth2 sign-in allows administrator-deactivated user accounts to be reactivated upon re-authentication through specific authentication sources (like GitHub or OIDC/OAuth2 without refresh tokens), enabling users to regain full access, potentially including administrator privileges, by bypassing the intended deactivation.

go/code.gitea.io/gitea gitea vulnerability authentication account-takeover privilege-escalation
3t
high advisory

Gitea LFS Authentication Bypass via Malformed SSH Sub-Verb

A high-severity authentication bypass vulnerability (CVE-2026-58423) in Gitea's SSH Git LFS handling allows any authenticated SSH user to obtain valid LFS credentials for any private repository, enabling unauthorized download of all LFS objects from instances running Gitea versions 1.23.0 through 1.26.2.

Gitea lfs ssh authentication-bypass information-disclosure vulnerability
1r 4t 1c
critical advisory

Gitea Incomplete SSRF Protection in Webhook and Migration Allow-list

An incomplete Server-Side Request Forgery (SSRF) protection in Gitea versions prior to 1.26.3 allows authenticated users to bypass the allow-list in webhook delivery and repository migrations, enabling internal network probing and data exfiltration from sensitive services like cloud metadata endpoints.

Gitea ssrf web-application data-exfiltration vulnerability github authorization-bypass information-disclosure api +5
4t 1c 1i
critical advisory

Gitea Branch Protection Bypass via Pull Request Retargeting

An attacker with write access to a Gitea repository can bypass branch protection rules by exploiting a logic flaw, obtaining an 'official' approval on a pull request (PR) targeting an unprotected branch, then retargeting the PR to a protected branch, preserving the stale approval and leading to unauthorized code merges and privilege escalation.

Gitea branch-protection-bypass code-repository privilege-escalation persistence web-application vulnerability defense-evasion network +7
1r 7t
critical advisory

@vitest/browser File Access Bypass Vulnerability (GHSA-p63j-vcc4-9vmv)

A critical vulnerability in `@vitest/browser`'s Browser Mode allows arbitrary file system access due to a bypass of the `allowWrite` permission gate and lack of path confinement, enabling an attacker to read, create, overwrite, or delete files on the local filesystem where the Vitest process is running.

@vitest/browser +2 supply-chain vulnerability file-access RCE web-dev
5t
critical advisory

Sigstore/OCI Credential Confusion Vulnerability (CVE-2026-59891)

A critical credential exposure vulnerability (CVE-2026-59891) exists in `@sigstore/oci` versions prior to 0.7.1. The `getRegistryCredentials()` function, used to read credentials from `~/.docker/config.json`, employs a substring match instead of an exact host match when selecting credentials. This flaw allows credentials for a legitimate registry (e.g., `ghcr.io`) to be inadvertently transmitted to an attacker-controlled registry if its hostname is a substring of the legitimate one (e.g., `cr.io`). This impacts consumers of `@sigstore/oci` and related GitHub Actions (`actions/attest`, `actions/attest-build-provenance`, `actions/attest-sbom`) when pushing artifacts to untrusted or attacker-influenced destination registries, potentially leading to the leakage of long-lived registry tokens. The vulnerability is fixed in `@sigstore/oci@0.7.1` by enforcing exact host matching.

PoC @sigstore/oci < 0.7.1 +3 credential-exposure vulnerability github-actions docker supply-chain
1t 1c 1i updated
critical advisory

Unauthenticated SQL Injection Vulnerability in Linknat VOS3000 and VOS2009

An unauthenticated SQL injection vulnerability (CVE-2016-20096) exists in Linknat VOS3000 and VOS2009 through version 2.1.2.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'name' parameter in a POST request to the login endpoint, which leads to the extraction of plaintext credentials and other database content with DBA-level privileges.

VOS3000 <= 2.1.2.0 +1 sql-injection vulnerability web-application
1r 3t 1c
high advisory

Gitea Repository Migration SSRF and Internal Git Repository Exfiltration

A critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.

Gitea +1 server-side-request-forgery ssrf vulnerability code-exfiltration data-exfiltration information-disclosure api-vulnerability web-vulnerability +5
2r 9t 1c
low advisory

pyasn1 Uncontrolled Resource Consumption (CVE-2026-59886)

The pyasn1 library is vulnerable to uncontrolled resource consumption (excessive CPU and memory) when converting BER/CER/DER-encoded REAL values to Python floats, which can lead to a denial of service (DoS) in applications that decode untrusted ASN.1 data and then perform operations like printing, logging, comparing, or arithmetic on the decoded `univ.Real` objects.

pyasn1 <= 0.6.3 denial-of-service vulnerability python library
1t 1c
low advisory

CVE-2026-59892: OpenTelemetry JaegerPropagator Denial of Service

A critical denial of service vulnerability, CVE-2026-59892, exists in `@opentelemetry/propagator-jaeger` versions prior to 2.9.0, allowing an unauthenticated remote attacker to terminate Node.js applications configured with `JaegerPropagator` by sending a malformed percent-encoded value in `uber-trace-id` or `uberctx-*` HTTP headers, leading to an uncaught `URIError`.

@opentelemetry/propagator-jaeger denial-of-service vulnerability javascript nodejs opentelemetry
1t 1c
high advisory

OS Command Injection in AWS CDK NodejsFunction Docker Bundling (CVE-2026-13760)

An OS command injection vulnerability, CVE-2026-13760, in AWS CDK's `aws-cdk-lib` package before version 2.260.0 allows an attacker to execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into dependency version strings within a project's `package.json` file when using Docker-based NodejsFunction bundling.

aws-cdk-lib command-injection supply-chain cloud-native aws-cdk vulnerability
1t 1c
low advisory

Linkify-it Denial of Service via Mailto Validator Quadratic Complexity

The JavaScript library linkify-it is vulnerable to a quadratic-complexity Denial of Service (DoS) (CVE-2026-59887) due to an inefficient regular expression in its `mailto:` schema validator, which allows an unauthenticated attacker to block application event loops by supplying specially crafted input with repeated 'mailto:' strings.

linkify-it <= 5.0.1 +1 denial-of-service nodejs web-application vulnerability redos
1t 1c
low advisory

Immutable.js Map/Set Hash Collision Denial of Service Vulnerability

A high-severity algorithmic complexity vulnerability (CVE-2026-59880) in the Immutable.js library's `Immutable.Map` and `Immutable.Set` allows an attacker to craft object keys that cause hash collisions, degrading performance from O(1) to O(N²) and leading to a CPU-bound denial of service in applications, particularly those running on single-threaded Node.js environments that ingest untrusted input as object keys.

Immutable.js +1 denial-of-service algorithmic-complexity immutable-js nodejs vulnerability
2t 1c
low advisory

Immutable.js List 32-bit Trie Overflow Leads to Denial of Service

A vulnerability in Immutable.js List methods (`#set`, `#setSize`, `#setIn`, `#updateIn`) allows a remote, unauthenticated attacker to trigger an infinite loop or heap exhaustion by providing a crafted numeric string index in the range `[2 ** 30, 2 ** 31)`. This leads to an unrecoverable Denial of Service (DoS) by causing a tight CPU spin or process abortion, with an additional silent data corruption issue in `setSize`. This vulnerability impacts application availability but not confidentiality or integrity, and can be triggered by a single small HTTP request.

Immutable.js < 4.3.9 +1 denial-of-service vulnerability javascript npm immutable-js
1t 1c 2i
medium advisory

Denial of Service in websocket-driver-ruby via Malformed Host Header (CVE-2026-61666)

A denial of service vulnerability (CVE-2026-61666) exists in the websocket-driver-ruby library when used to implement a WebSocket server via `WebSocket::Driver.server()`, allowing a remote attacker to send a malformed `Host` header causing a `URI::InvalidURIError` exception and subsequent server process crash if unhandled.

websocket-driver denial-of-service vulnerability ruby webserver
1r 1t
critical advisory

Home Assistant Core Path Traversal Vulnerability (CVE-2026-64825)

A critical path traversal vulnerability, CVE-2026-64825, in Home Assistant Core versions before 2026.6.0 allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window, potentially leading to full system compromise with root privileges.

Home Assistant Core < 2026.6.0 vulnerability path-traversal home-assistant rce unauthenticated initial-access
2t 2c
critical advisory

SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28310)

CVE-2026-28310 describes a critical privilege escalation vulnerability (CVSS 9.1) affecting SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing a domain administrator to elevate their user type to that of a system administrator, with lower impact noted in Windows deployments.

Serv-U 15.5.4 HF1 and below privilege-escalation server-software vulnerability
1t 1c 2i
critical advisory

Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)

A critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.

Serv-U +1 remote-code-execution privilege-escalation vulnerability-exploitation vulnerability cve improper-access-control server software-update +5
5t 8c 3i
critical advisory

SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability Allows Privilege Escalation and RCE

A critical insecure direct object reference (IDOR) vulnerability, CVE-2026-28302, in SolarWinds Serv-U allows authenticated group administrators to achieve privilege escalation and remote code execution as root.

Serv-U +2 idor privilege-escalation rce file-transfer vulnerability solarwinds
3t 4c
high threat

CVE-2026-59851: Libssh GSSAPIKeyExchange Authorization Bypass

A vulnerability in libssh, tracked as CVE-2026-59851, allows an authenticated Kerberos principal to bypass authorization checks on servers with GSSAPIKeyExchange enabled, enabling arbitrary local user login and potential privilege escalation.

exploited libssh +2 vulnerability authorization-bypass privilege-escalation
1t 5c 22i
critical advisory

Critical SQL Injection Vulnerability in Turkhotspot 5651 Loglama (CVE-2026-1617)

A critical SQL injection vulnerability (CVE-2026-1617) exists in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama software, affecting versions from 5.1.2 before 5.1.3. This flaw, rated with a CVSS v3.1 Base Score of 9.8, allows attackers to execute arbitrary SQL commands due to improper neutralization of special elements in an SQL query.

Turkhotspot 5651 Loglama sql-injection vulnerability web-application
1r 1t 1c
high advisory

Multiple Vulnerabilities in Synacor Zimbra

An attacker can exploit multiple vulnerabilities in Synacor Zimbra to execute arbitrary code, perform cross-site scripting attacks, bypass security measures, disclose confidential information, and carry out unauthorized actions.

Zimbra vulnerability rce xss data-exfiltration defense-evasion
5t
medium threat

OPNsense: Multiple Vulnerabilities

An attacker can exploit multiple vulnerabilities in OPNsense to bypass security controls, disclose information, perform Cross-Site Scripting (XSS) attacks, and execute Denial of Service (DoS) attacks.

exploited OPNsense vulnerability firewall network-device
4t
high advisory

ProFTPD: Multiple Vulnerabilities Leading to RCE and Information Disclosure

A remote, authenticated attacker can exploit multiple vulnerabilities in ProFTPD to achieve arbitrary code execution and disclose confidential information, leading to system compromise and data theft.

ProFTPD vulnerability rce information-disclosure linux
3t
medium advisory

CUPS (libcupsfilters, cups-filters) Denial of Service Vulnerability

A vulnerability in CUPS, specifically affecting libcupsfilters and cups-filters, allows a remote, unauthenticated attacker to exploit the system, leading to a denial-of-service condition that disrupts the availability of the printing system.

CUPS +2 denial-of-service vulnerability linux
1t
high advisory

rsyslog Vulnerability Allows Denial of Service and Potential Code Execution

A remote, unauthenticated attacker can exploit a vulnerability in rsyslog to perform a Denial of Service attack and potentially execute arbitrary code.

rsyslog vulnerability denial-of-service code-execution linux
2t
high threat

Red Hat Enterprise Linux Vulnerabilities Allow Privilege Escalation and DoS

Multiple vulnerabilities in Red Hat Enterprise Linux, affecting components such as sssd, glib, and c-ares, can be exploited by an attacker to gain administrator privileges, bypass security measures, manipulate data, and trigger a denial-of-service condition.

exploited Red Hat Enterprise Linux red-hat linux vulnerability privilege-escalation defense-evasion denial-of-service
4t
low advisory

BusyBox AWK Vulnerability Leads to Denial of Service

A stack overflow vulnerability, identified as CVE-2026-38752, exists in the evaluate() function within the AWK editor (editors/awk.c) of BusyBox commit 371fe9, which allows attackers to trigger a Denial of Service (DoS) condition by providing a specially crafted AWK script.

BusyBox denial-of-service vulnerability linux
1t 1c
medium advisory

ethtool RSS Resource Leak on get_rxfh Failure

A vulnerability, CVE-2026-63999, has been identified in the `ethtool` utility on Linux systems, involving a resource leak of `indir_table` and `hkey` when the `get_rxfh` function related to Receive Side Scaling (RSS) functionality fails, which could lead to system instability or resource exhaustion.

ethtool linux vulnerability resource-leak
1c
high threat

Linux Kernel USB Type-C Wcove Driver Buffer Overflow Vulnerability

A buffer overflow vulnerability, identified as CVE-2026-63960, exists in the `wcove_read_rx_buffer()` function within the USB Type-C `wcove` driver in the Linux kernel, potentially leading to memory corruption or system instability upon exploitation.

exploited Linux Kernel linux kernel vulnerability buffer-overflow cve
1c
medium threat

CVE-2026-64117 Vulnerability in Linux Kernel mac80211 Wi-Fi Subsystem

A vulnerability, CVE-2026-64117, has been disclosed in the Linux kernel's mac80211 Wi-Fi subsystem, potentially leading to unexpected behavior or information exposure due to incorrect handling of fast-RX rates and `skb->cb` buffer reuse in mesh networking contexts.

exploited mac80211 linux vulnerability kernel wifi
1c
medium threat

CVE-2026-64097: AMD Display Module Vulnerability in Linux Kernel

A vulnerability, CVE-2026-64097, affects the `drm/amd/display` module in the Linux kernel due to insufficient validation of GPIO pin LUT table size, potentially leading to system instability or other security impacts on Linux systems utilizing AMD display drivers.

exploited Linux Kernel vulnerability linux kernel amd denial-of-service
1c
critical advisory

Qemu-kvm HyperV Syndbg Out-of-Bounds Write Vulnerability

A critical vulnerability, CVE-2026-3842, exists in the `hyperv/syndbg` component of Qemu-kvm, allowing an attacker to perform out-of-bounds writes on the host system due to a missing mapped-length guard after a `cpu_physical_memory_map` operation.

Qemu-kvm virtualization hypervisor vulnerability guest-to-host-escape
1c
high advisory

CVE-2026-38754: Busybox Heap Overflow Leads to Denial of Service

A heap overflow vulnerability (CVE-2026-38754) exists in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0. This flaw allows attackers to trigger a Denial of Service (DoS) by providing a specially crafted input, leading to application instability or unavailability.

Busybox v1.38.0 vulnerability denial-of-service heap-overflow linux
1t 3c
critical threat

Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.

exploited PoC Active Directory Federation Services +23 patch-tuesday zero-day vulnerability microsoft windows sharepoint active-directory-federation-services bitlocker +2
8t 4c 8i updated
high advisory

Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)

A post-authentication command injection vulnerability (CVE-2026-6952) in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.

AX7501-B1 firmware command-injection vulnerability router network-device
1t 1c
high advisory

CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability

A high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.

DNS-320 1.0.2 web-vulnerability remote-code-execution file-upload d-link unrestricted-file-upload nas vulnerability unrestricted-upload +2
4r 4t 2i updated
low advisory

Pillow Decompression Bomb DoS via PdfParser.PdfStream.decode()

A denial-of-service vulnerability (CVE-2026-59200) exists in Pillow's `PdfParser.PdfStream.decode()` function across versions 5.1.0 to 12.2.x, allowing an unauthenticated attacker to craft a malicious PDF file that, when processed by a vulnerable application, triggers excessive memory allocation (e.g., a ~950 KB file expanding to 1 GB), leading to server Out-of-Memory termination or severe service degradation.

PoC Pillow +1 denial-of-service vulnerability python library pdf
1t 2c 2i updated
high advisory

FileBrowser Username Normalization Collision Leads to Authorization Bypass

A critical authorization bypass vulnerability, CVE-2026-62685, in FileBrowser versions <= 2.63.16 enables an attacker to gain full read and write access to other users' files by exploiting a username normalization collision during self-registration, thus bypassing per-user isolation and allowing data tampering or exfiltration.

FileBrowser <= 2.63.16 authorization-bypass web-application filebrowser vulnerability
4t 1c
low advisory

Engine.IO Polling Transport Connection Exhaustion Vulnerability (CVE-2026-59725)

An unauthenticated remote attacker can cause a denial of service in `engine.io` by sending invalid binary POST requests with `Content-Type: application/octet-stream` to Engine.IO protocol v4 polling transports, leading to exhaustion of server-side resources such as HTTP connections, sockets, and file descriptors due to improper connection closure.

engine.io +1 denial-of-service vulnerability web-application
1r 1t 1c
medium advisory

File Browser Symlink Following Vulnerability Allows Out-of-Scope File Deletion (CVE-2026-55667)

A File Browser user with only `Create` permission can exploit CVE-2026-55667, an incomplete fix for CVE-2026-54094, to delete arbitrary files and directories outside their authorized scope by abusing the `ScopedFs.RemoveAll` function's symlink-following behavior during failed upload cleanup, leading to data loss, cross-tenant data deletion, or denial of service.

filebrowser vulnerability file-browser symlink-attack data-loss denial-of-service
2t 2c
high advisory

Cloudreve OAuth Access Token Scope Bypass Vulnerability

Cloudreve's OAuth implementation contains a vulnerability, CVE-2026-54560, where OAuth access tokens bypass intended scope enforcement due to a missing `client_id` claim, allowing an attacker with a low-scope token to access sensitive APIs requiring higher privileges, effectively leading to privilege escalation.

Cloudreve oauth vulnerability privilege-escalation web-application
1t 1c
low advisory

Pillow FontFile.compile() Vulnerability Bypasses Decompression Checks Leading to DoS (CVE-2026-54060)

A vulnerability, CVE-2026-54060, in the Pillow library's `FontFile.compile()` method allows attackers to craft malicious BDF or PCF font files that bypass standard decompression bomb checks, causing an unchecked, massive memory allocation when processed, which can lead to a Denial of Service (DoS) via an Out-Of-Memory (OOM) crash in vulnerable applications.

Pillow vulnerability denial-of-service python software-supply-chain
1t 1c
high advisory

Pillow BdfFontFile Decompression Bomb Bypass Vulnerability

A vulnerability (CVE-2026-55379) in Pillow's BdfFontFile component allows attackers to craft a malicious BDF font file with oversized BBX dimensions and an empty BITMAP section, bypassing documented decompression bomb protection and causing the Image.new() function to silently allocate large amounts of memory in the C-heap, leading to resource exhaustion and denial-of-service for applications processing untrusted BDF fonts.

pillow vulnerability denial-of-service python heap-overflow integer-overflow image-processing python-library cve-2026-59199 +2
4t 1c
high advisory

@better-auth/sso Authorization Bypass Allows Unauthorized SSO Provider Registration

A high-severity authorization bypass vulnerability (CVE-2026-53515) in `@better-auth/sso` versions `>= 1.2.10, < 1.6.11` allows regular organization members to register new SSO providers for an organization, potentially leading to unauthorized user creation and, under specific configurations, unauthorized administrative access within the target organization.

@better-auth/sso web vulnerability authorization-bypass sso
2t 1c
high advisory

Pillow Out-of-Bounds Read Vulnerability in McIdas AREA Plugin (CVE-2026-54058)

The Pillow library contains an out-of-bounds read vulnerability in its McIdas AREA plugin when processing specially crafted image files opened from a filename, allowing an attacker to manipulate header words to define a 'stride' value smaller than the actual row width, leading to information disclosure through adjacent process memory leakage or denial of service due to a process crash (SIGBUS).

Pillow < 12.3.0 pillow oob-read image-processing vulnerability information-disclosure denial-of-service python
2t 1c
critical advisory

Critical Unauthenticated RCE in ktransformers (CVE-2026-63767)

A critical unauthenticated pickle deserialization vulnerability (CVE-2026-63767) in ktransformers versions up to 0.6.3 allows remote attackers to execute arbitrary commands by sending specially crafted pickle payloads containing malicious `__reduce__` methods to the SchedulerServer ZMQ ROUTER socket, leading to complete server compromise.

ktransformers <= 0.6.3 deserialization remote-code-execution python zmq vulnerability
2r 2t 1c
high advisory

CVE-2026-64619: FileCodeBox Rate Limit Bypass Vulnerability

Unauthenticated attackers can bypass rate limits in FileCodeBox versions before 2.4 due to a vulnerability in the IPRateLimit class, allowing them to enumerate share codes and retrieve other users' files without authentication by spoofing X-Real-IP and X-Forwarded-For headers without proper verification.

FileCodeBox rate-limit-bypass vulnerability web-application file-sharing data-exfiltration cve
2t 1c 4i
high advisory

CVE-2026-63770: Glance IP Address Spoofing Vulnerability Bypasses Brute-Force Lockout

A vulnerability in Glance through version 0.8.5 allows unauthenticated attackers to bypass brute-force lockout protections by manipulating the X-Forwarded-For HTTP header with arbitrary values, making each login attempt appear to originate from a distinct IP address when the server's proxied option is enabled, thereby enabling unlimited credential guessing against the authentication endpoint.

Glance credential-access defense-evasion vulnerability web-application proxy brute-force
1r 2t 1c
high advisory

Server-Side Request Forgery in HyperDX via ClickHouse Proxy Test Endpoint

An authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-63731, in HyperDX before version 2.31.0 by manipulating the `host` parameter of the ClickHouse proxy test endpoint, leading to disclosure of internal service response bodies and potential access to internal APIs, container services, and cloud provider metadata.

HyperDX ssrf vulnerability webserver
1r 2t 1c
high advisory

LimeSurvey Server-Side Request Forgery Vulnerability (CVE-2026-63107)

An authenticated attacker can exploit CVE-2026-63107, a server-side request forgery vulnerability in LimeSurvey versions through 6.17.10 and 7.0.4, by manipulating the HTTP Host header in the REST API survey template endpoint, allowing the server to issue arbitrary HTTP requests to internal networks and cloud metadata services, potentially leading to the extraction of sensitive credentials like IAM tokens.

LimeSurvey through 6.17.10 +1 ssrf web-application vulnerability credential-access data-exfiltration
1r 1t 1c
high advisory

Composer: Arbitrary File Write via Malicious Transitive Package Name

A critical vulnerability, CVE-2026-59948, in Composer allows for arbitrary file write outside the project's vendor directory when processing a maliciously crafted package from an untrusted third-party repository during `install` or `update` operations, enabling code execution.

Composer +1 php supply-chain arbitrary-file-write code-execution vulnerability
3t 1c
low advisory

CVE-2026-64612 - libcupsfilters and cups-filters Denial of Service

A high-severity denial-of-service vulnerability (CVE-2026-64612) exists in libcupsfilters and cups-filters, allowing an unauthenticated attacker to cause the CUPS image filter process to abort by submitting a specially crafted PNG print job, leading to service disruption.

libcupsfilters +1 vulnerability denial-of-service cups linux unix
1t 1c
high advisory

Public Exploit for Apache Camel CVE-2026-49098 Improper Input Validation

A public exploit has been released for CVE-2026-49098, an improper input validation vulnerability in Apache Camel's 'camel-kafka' component, which allows an attacker to perform message-header injection by supplying 'kafka.OVERRIDE_TOPIC' in HTTP headers, enabling cross-topic message injection and integrity compromise of sensitive Kafka topics.

Apache Camel +2 apache-camel vulnerability kafka injection
1t 1c
high advisory

ProFTPD mod_sftp Heap Buffer Overflow Leads to Arbitrary Code Execution

A heap-based buffer overflow vulnerability exists in the mod_sftp module of ProFTPD versions prior to 1.3.9c and 1.3.10rc3, allowing authenticated low-privilege attackers to achieve arbitrary code execution by sending specially crafted SFTP packet fragments exceeding 16 KB, corrupting memory and redirecting function calls.

ProFTPD before 1.3.9c +1 vulnerability heap-overflow rce sftp
1t 1c
critical advisory

Path Traversal Vulnerability in Pulpcore (CVE-2026-12701)

An authenticated administrator can exploit a path traversal vulnerability in the 'relative_path_validator' function within 'pulpcore'. During 'FilesystemExport' operations, specially crafted 'relative_path' values containing directory traversal sequences (e.g., "../") can bypass validation, leading to arbitrary file writes. This allows an attacker to write files to any location writable by the Pulp service user, such as '/etc/shadow', potentially leading to service compromise, privilege escalation, or further system exploitation.

pulpcore path-traversal vulnerability linux
3t 1c
high advisory

QEMU Guest Agent Vulnerability Allows Local Privilege Escalation (CVE-2026-12080)

A local unprivileged user within a QEMU guest can exploit CVE-2026-12080, a vulnerability in the QEMU Guest Agent's 'guest-ssh-add-authorized-keys' command handler, by manipulating symbolic links through a directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race to gain ownership of arbitrary root-owned files or directories, leading to root access within the guest OS.

QEMU Guest Agent +1 privilege-escalation vulnerability qemu guest-agent
2t 1c updated
high advisory

Potential CVE-2025-41244 vmtoolsd Local Privilege Escalation Attempt

Attackers can exploit CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools' `vmtoolsd` service and its `get-versions.sh` script on Linux, by manipulating the `PATH` environment variable to execute malicious binaries with elevated privileges when the service attempts to retrieve version information, potentially leading to a root shell.

VMware Tools +1 privilege-escalation vmware linux vulnerability
1r 3t 1c
high advisory

Sudo Chroot Privilege Escalation via NSSwitch File Manipulation (CVE-2025-32463)

Attackers can exploit CVE-2025-32463, a privilege escalation vulnerability in `sudo` when used with `chroot`, by creating a malicious `nsswitch.conf` file and associated Name Service Switch (NSS) modules within a controlled chroot environment to trick `sudo` into loading attacker-controlled code, leading to root privileges on Linux systems.

PoC sudo +1 privilege-escalation linux cve vulnerability nsswitch
1r 2t 1c updated
high advisory

CVE-2026-64623: Jovancoding Network-AI Signature Verification Bypass Leading to Remote Code Execution

Jovancoding Network-AI versions before 5.13.4 are vulnerable to an improper cryptographic signature verification flaw (CVE-2026-64623) in the APSAdapter component, allowing unauthenticated attackers to bypass signature validation by submitting forged APS delegation payloads with arbitrary scopes to obtain signed permission tokens for sensitive resources, including SHELL_EXEC capabilities.

Network-AI < 5.13.4 vulnerability rce signature-bypass network-ai
4t 1c
high advisory

Authorization Bypass in Network-AI npm Package CVE-2026-64622

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 are vulnerable to an authorization bypass (CVE-2026-64622) that allows unauthenticated actors to access sensitive approval request details via specific GET read routes like /approvals/. This vulnerability discloses critical information such as shell-command strings, file paths, justifications, and risk levels. Additionally, a hardcoded 'Access-Control-Allow-Origin: *' header in responses facilitates cross-origin data disclosure, enabling potential exfiltration from malicious websites an operator might visit.

Network-AI vulnerability authorization-bypass information-disclosure npm
1r 2t 1c
high advisory

FreeRDP Double-Free Vulnerability (CVE-2026-64621)

A double-free vulnerability exists in FreeRDP versions 3.x through 3.27.1 within the freerdp_client_rdp_file_apply_to_settings() function, specifically when parsing the selectedmonitors field of a .rdp connection file. An attacker can exploit this by convincing a victim to open a crafted .rdp file containing oversized monitor tokens, leading to a size-controlled double-free in FreeRDP CLI clients like xfreerdp, sdl-freerdp, or wlfreerdp. This vulnerability can result in denial of service or potentially lead to arbitrary code execution.

FreeRDP vulnerability double-free linux
2t 1c
high threat

CVE-2026-63757: SurrealDB Session Hijacking Vulnerability

SurrealDB versions prior to 3.1.0 are vulnerable to a session hijacking flaw (CVE-2026-63757) where unauthenticated attackers can enumerate session UUIDs via the HTTP /rpc sessions method and impersonate authenticated sessions to read, write, and delete data, leading to privilege escalation.

SurrealDB vulnerability session-hijacking privilege-escalation data-exfiltration denial-of-service webserver json-parsing
5t 1c
high advisory

SurrealDB RPC Endpoint Race Condition Allows Privilege Escalation (CVE-2026-63756)

SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use (TOCTOU) race condition in the HTTP /rpc endpoint that allows unauthenticated attackers to hijack authenticated session state and execute operations with elevated user privileges, leading to privilege escalation.

SurrealDB race-condition privilege-escalation web-application vulnerability
2t 1c
low advisory

SurrealDB Denial of Service Vulnerability (CVE-2026-63747)

SurrealDB versions prior to 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when the 'db' parameter is set without a corresponding namespace, allowing unauthenticated attackers to crash the server by sending a malformed WebSocket message to the /rpc endpoint.

SurrealDB < 3.1.0 denial-of-service vulnerability web-application database
1t 1c
high advisory

SurrealDB Arbitrary File Read Vulnerability CVE-2026-63739

SurrealDB versions prior to 3.1.5 contain an arbitrary file read vulnerability (CVE-2026-63739) within the DEFINE ANALYZER mapper filter that allows authenticated database users with EDITOR or OWNER roles to read arbitrary files from the server filesystem by injecting file paths into query error messages, especially when the SURREAL_FILE_ALLOWLIST is unconfigured.

SurrealDB vulnerability arbitrary-file-read database cve
3t 1c
high advisory

CVE-2026-63735: SurrealDB Scope Validation Bypass in Custom API Routes

A vulnerability, CVE-2026-63735, in SurrealDB versions prior to 3.2.0 allows authenticated users to bypass namespace and database scope validation in custom API routes by manipulating the URL path, potentially leading to unauthorized data reading or triggering unintended operations across different tenants.

SurrealDB vulnerability database api-bypass data-exfiltration privilege-escalation
2t 1c 2i
high advisory

CVE-2026-14448: Authenticated OS Command Injection in MB connect line and Helmholz Products

CVE-2026-14448 describes an authenticated OS command injection vulnerability in the system_certificates view of MB connect line's mbCONNECT24 and mymbCONNECT24 products, as well as Helmholz's myREX24V2 and myREX24V2.virtual products, all versions up to and including 2.20.0, allowing a high-privileged remote attacker to execute arbitrary commands leading to a total loss of confidentiality, availability, and integrity.

mbCONNECT24 +3 os-command-injection vulnerability rce industrial-control-system
1r 2t 1c
critical advisory

CVE-2026-64620 - FreeRDP Heap-based Buffer Overflow

FreeRDP before version 3.28.0 contains a heap-based buffer overflow in the `crypto_rsa_common()` function, exploitable pre-authentication by an unauthenticated attacker crafting a malicious ciphertext to cause a denial of service on the server when a client uses RDP Standard Security.

FreeRDP vulnerability buffer-overflow denial-of-service cve network
2t 1c
low advisory

PHP File Creation in WordPress Plugin Directory

Attackers commonly establish persistence on compromised Linux WordPress web servers by creating malicious PHP files, often web shells, within the WordPress plugin directory, enabling remote access and command execution following initial compromise of a public-facing application.

WordPress persistence initial-access execution web-shell linux endpoint threat-detection vulnerability
1r 3t 1c 1i updated
medium threat

Multiple Vulnerabilities in Proxmox Virtual Environment

An attacker can exploit multiple vulnerabilities in Proxmox Virtual Environment to conduct Cross-Site Scripting attacks, bypass security measures, and disclose confidential information, potentially leading to unauthorized data access or session hijacking.

exploited Proxmox Virtual Environment vulnerability web-application xss information-disclosure proxmox
1t
high advisory

IBM DB2: Multiple Vulnerabilities

Multiple vulnerabilities in IBM DB2 allow an attacker to perform a Denial of Service (DoS) attack and execute arbitrary code, which could lead to system disruption or full compromise.

DB2 vulnerability rce dos database ibm
2t
high advisory

Multiple Vulnerabilities in Extreme Networks ExtremeXOS Allow Privilege Escalation and Data Manipulation

Multiple vulnerabilities in Extreme Networks ExtremeXOS can be exploited by a remote, authenticated attacker to achieve privilege escalation, bypass security controls, and manipulate data on affected network devices.

ExtremeXOS vulnerability network privilege-escalation defense-evasion
3t
high threat

FreeRDP: Vulnerability Enables Remote Code Execution

A high-severity vulnerability in the FreeRDP software allows a remote, unauthenticated attacker to execute arbitrary code on systems running FreeRDP, enabling system compromise without prior authentication.

FreeRDP Anonymous Attacker vulnerability remote-code-execution bsi
2t
high advisory

Multiple Vulnerabilities in IBM Langflow Desktop OSS

An attacker can exploit multiple vulnerabilities in IBM Langflow Desktop OSS to gain administrator privileges, execute arbitrary code, bypass security measures, manipulate and disclose data, or cause a denial-of-service condition, leading to full system compromise and data integrity/confidentiality breaches.

Langflow Desktop OSS vulnerability remote-code-execution privilege-escalation data-exfiltration denial-of-service desktop-application
6t
medium advisory

ProFTPD: Vulnerability Enables Denial of Service

An authenticated remote attacker can exploit a vulnerability within ProFTPD to initiate a denial-of-service attack, leading to the unavailability of the FTP service. This flaw could be triggered by legitimate users or adversaries with valid credentials, causing operational disruption.

ProFTPD denial-of-service vulnerability ftp linux
1t
critical advisory

CVE-2026-16242: Konnectivity Proxy-Server Authentication Bypass

A critical authentication bypass vulnerability, CVE-2026-16242, exists in the Konnectivity proxy-server configuration for hosted control planes, allowing a remote unauthenticated attacker to connect as an agent and potentially proxy, inspect, modify, or drop control-plane-to-node traffic due to improper client certificate validation.

Logging Subsystem for Red Hat OpenShift +2 kubernetes cloud vulnerability authentication-bypass redhat
4t 1c
high advisory

Linux Kernel fbdev Use-After-Free Vulnerability (CVE-2026-53401)

A high-severity use-after-free vulnerability, CVE-2026-53401, has been identified in the Linux kernel's fbdev subsystem affecting omap2 processors, potentially allowing for privilege escalation or denial of service.

Linux kernel linux vulnerability kernel use-after-free
1c
medium threat

CVE-2026-63825: gcov Utility Concurrent Access Crash Vulnerability

A vulnerability, CVE-2026-63825, has been disclosed for the 'gcov' utility, which is part of the GNU Compiler Collection, involving concurrent access crashes fixed by using atomic counter updates to ensure thread-safe operations, potentially leading to system instability or denial of service due to race conditions during data access.

exploited gcov vulnerability denial-of-service cve
1c
medium threat

Potential Out-of-Bounds Write in rust-openssl AES-KW-PAD Cipher Operations

A potential out-of-bounds write vulnerability, CVE-2026-45784, has been identified in the `rust-openssl` library's `CipherCtxRef::cipher_update_inplace` function when processing AES-KW-PAD ciphers, which could lead to unexpected behavior or potential exploitation by corrupting memory.

exploited rust-openssl vulnerability library out-of-bounds
1c
high threat

Linux Kernel ip_gre Module Vulnerability CVE-2026-63829

A vulnerability identified as CVE-2026-63829 affects the `ip_gre` module in the Linux kernel, involving a security fix to ensure that the `changelink` operation properly requires `CAP_NET_ADMIN` capabilities within the device's network namespace, addressing a potential privilege escalation or security bypass scenario.

exploited Linux Kernel linux vulnerability kernel privilege-escalation nfs information-disclosure linux-kernel oob-read
1c
high advisory

CVE-2026-63833: Linux Kernel ntfs3 Privilege Escalation Vulnerability

The Microsoft Security Response Center has published information concerning CVE-2026-63833, a privilege escalation vulnerability in the Linux kernel's `ntfs3` module that allows direct userspace writes to reserved `$LX*` extended attributes.

Linux Kernel linux kernel vulnerability privilege-escalation
1c
high advisory

CVE-2026-16227: SourceCodester Class and Exam Timetabling System SQL Injection

A high-severity SQL injection vulnerability (CVE-2026-16227) in SourceCodester Class and Exam Timetabling System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/edit_subject.php' file, with the exploit publicly disclosed.

Class and Exam Timetabling System 1.0 sql-injection web-application vulnerability CVE sourcecodester
1r 1t 2c
high advisory

Unauthenticated Access in Newpanjing simpleui via AjaxAdmin Endpoint (CVE-2026-16210)

A high-severity authentication bypass vulnerability, CVE-2026-16210, exists in newpanjing simpleui version 2026.01.13, specifically within the `self.get_action` function of the `AjaxAdmin AJAX Endpoint` component, allowing remote attackers to perform unauthorized manipulations due to missing authentication, with a public exploit available.

simpleui 2026.01.13 vulnerability authentication-bypass web-application CVE-2026-16210
1t 2c 6i
high advisory

CVE-2026-16200: Remote Authorization Bypass in zevorn rt-claw

A high-severity remote authorization bypass vulnerability (CVE-2026-16200) has been identified in zevorn rt-claw versions up to 0.2.0, specifically within the RPC Handler's claw_tool_invoke function, allowing remote exploitation with a public exploit.

rt-claw vulnerability authorization-bypass
1t 1c
high advisory

ProFTPD mod_sftp Heap Overflow Allows Authenticated Denial of Service (CVE-2026-53994)

An authenticated SFTP user can trigger a heap-based buffer overflow in ProFTPD's mod_sftp module (CVE-2026-53994) by sending a malformed SFTP packet, leading to an integer underflow, an undersized buffer allocation, and subsequent heap corruption, which results in a reliable remote denial of service.

ProFTPD mod_sftp vulnerability denial-of-service sftp linux-server
1t 1c
high advisory

Server-Side Request Forgery in zevorn rt-claw (CVE-2026-16128)

A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16128, exists in zevorn rt-claw versions up to and including 0.2.0. The flaw is located within the `receiver_thread` function of the `http_request` component in `claw/services/swarm/swarm.c`. This critical vulnerability allows remote attackers to perform server-side request forgery, and a public exploit is available, increasing the urgency for detection and mitigation efforts.

rt-claw 0.1 +1 ssrf vulnerability webserver remote-code-execution information-disclosure
3t 1c 5i
high advisory

CVE-2026-16125: Server-Side Request Forgery in zevorn rt-claw

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16125, affects zevorn rt-claw versions up to and including 0.2.0, residing in the claw_net_get/claw_net_post functions within the http_request component, allowing remote attackers to manipulate the URL argument and access internal resources or perform port scanning.

rt-claw <= 0.2.0 server-side-request-forgery vulnerability web-application ssrf exploitation
1r 3t 2c 10i
high advisory

SurrealDB Default Permissions Vulnerability

SurrealDB versions prior to 1.0.1 are vulnerable due to default table permissions being set to FULL instead of NONE, allowing attackers with existing database access or unauthenticated users on publicly exposed instances to perform unrestricted SELECT, CREATE, UPDATE, and DELETE operations on tables that lack explicit permission settings, leading to unauthorized data access, modification, or deletion.

SurrealDB misconfiguration database vulnerability data-exfiltration
3t 1c
high advisory

Arbitrary Code Execution in uproot via Crafted ROOT Files (CVE-2026-9147)

A vulnerability, CVE-2026-9147, in the uproot library allows arbitrary Python code execution when processing crafted ROOT files due to improper handling of streamer metadata fields during dynamic code generation, impacting applications that open or process untrusted ROOT files.

uproot vulnerability rce python code-execution
1t 1c
high advisory

Shibby Tomato Router Firmware Out-of-Bounds Write Vulnerability (CVE-2026-16095)

A remote out-of-bounds write vulnerability, CVE-2026-16095, affects Shibby Tomato firmware version 1.28 RT-N5x MIPSR2 Build 124, where manipulating the `ct_tcp_timeout` argument in the `setup_conntrack` function of `/sbin/rc` can lead to memory corruption, potentially allowing arbitrary code execution or denial of service.

Tomato 1.28 RT-N5x MIPSR2 Build 124 vulnerability router firmware out-of-bounds-write CVE-2026-16095
3t 2c
high advisory

Remote Server-Side Request Forgery in Sipeed PicoClaw (CVE-2026-16084)

A server-side request forgery (SSRF) vulnerability, CVE-2026-16084, has been identified in Sipeed PicoClaw versions up to 0.2.9, allowing remote exploitation due to a weakness in the `web_fetch` function of `pkg/tools/integration/web.go`, with a public exploit available.

PicoClaw ssrf vulnerability remote-exploitation sipeed
1r 3t 1c 9i
low advisory

CoreDNS Rewrite Plugin Vulnerability Allows Remote Denial of Service

A remote denial-of-service vulnerability (CVE-2026-62299) has been discovered in the CoreDNS rewrite-plugin that can lead to a nil-pointer panic when a downstream plugin returns an EDNS0 response without an OPT record, potentially causing service disruption.

CoreDNS +1 denial-of-service dns vulnerability kubernetes
1t 1c
high advisory

CVE-2026-48373: Adobe Acrobat Reader Heap-based Buffer Overflow

A heap-based buffer overflow vulnerability, CVE-2026-48373, in Adobe Acrobat Reader could allow an attacker to achieve arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file.

Acrobat Reader +1 cve vulnerability adobe acrobat-reader arbitrary-code-execution heap-buffer-overflow
2t 1c
high advisory

CVE-2026-16118: Heap-Based Buffer Overflow in xdgmime

A heap-based buffer overflow vulnerability exists in the `xdgmime` library, specifically within the `_xdg_mime_magic_parse_magic_line()` function, which can be triggered on little-endian systems when an application parses an attacker-controlled MIME magic file in a user-writable XDG data location, leading to an application crash or memory corruption.

xdgmime vulnerability buffer-overflow linux desktop-environment
2t 1c
high advisory

IBM Engineering AI Hub Information Disclosure via URL Session Tokens (CVE-2026-15322)

A remote attacker can exploit CVE-2026-15322 in IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 to obtain sensitive session tokens exposed in URLs, potentially leading to unauthorized access and information disclosure.

Engineering AI Hub 1.0.0 +2 vulnerability information-disclosure session-token ibm cve
1t 1c
high advisory

IBM Langflow OSS Command Injection Vulnerability

An authenticated attacker can exploit CVE-2026-14499 in IBM Langflow OSS versions 1.0.0 through 1.10.1 due to improper validation of user input in the Python Interpreter component, leading to arbitrary command execution with elevated privileges.

Langflow OSS command-injection rce web-application vulnerability python
1r 2t 1c
high threat

IBM Storage Protect Client Heap Buffer Overflow Allows Remote Code Execution

IBM Storage Protect Client versions 8.1.0.0 through 8.1.27.1 and 8.2.0.0 through 8.2.1.0 are vulnerable to CVE-2026-13473, a heap-based buffer overflow caused by improper bounds checking, allowing a remote attacker to execute arbitrary code or crash the server.

exploited IBM Storage Protect Client < 8.1.27.2 +1 heap-overflow buffer-overflow rce denial-of-service vulnerability client-side
2t 1c
critical advisory

IBM Langflow OSS Remote Code Execution via Deserialization

IBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.

Langflow OSS 1.0.0 +13 remote-code-execution deserialization python langflow web-vulnerability rce authentication-bypass critical-vulnerability +7
1r 5t 7c 1i
high advisory

Arbitrary Code Execution via JavaScript Frontmatter in Prompty TypeScript Loader

A high-severity vulnerability, CVE-2026-53597, in the Prompty TypeScript loader (`@prompty/core`) versions `>= 2.0.0-alpha.1 < 2.0.0-beta.3` allows arbitrary JavaScript code execution in the host Node.js process when parsing untrusted `.prompty` files due to improper handling of `gray-matter`'s executable frontmatter engines.

@prompty/core arbitrary-code-execution supply-chain vulnerability nodejs typescript
1t 1c
low advisory

IBM PowerVM Novalink Vulnerable to Denial of Service via Specially-Crafted Request

IBM PowerVM Novalink is vulnerable to CVE-2026-9171, a denial-of-service attack where a remote unauthenticated attacker can send a specially-crafted request to cause the server to consume excessive memory resources, leading to system unavailability.

PowerVM Novalink 2.2.02.2.12.2.1.1 +1 denial-of-service vulnerability IBM PowerVM Novalink
1t 1c 1i
critical advisory

IBM Langflow OSS Code Injection Vulnerability in ToolGuard (CVE-2026-9135)

An authenticated attacker can exploit CVE-2026-9135, a code injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.2, to bypass security controls and achieve arbitrary Python code execution on the backend through unvalidated dynamic CodeInput fields in the ToolGuard integration, potentially escalating privileges via cross-tenant flow manipulation.

Langflow OSS code-injection vulnerability rce langflow hard-coded-credentials ibm
3t 1c
critical advisory

IBM Langflow OSS Improper Authentication Vulnerability

A remote attacker can gain full administrative access to IBM Langflow OSS versions 1.0.0 through 1.10.0 by exploiting an improper authentication vulnerability. The /api/v1/login/auto_login endpoint, when the default AUTO_LOGIN configuration is enabled, issues long-lived superuser bearer tokens without requiring authentication. This allows an unauthenticated network attacker to obtain these tokens and achieve superuser privileges. Additionally, permissive Cross-Origin Resource Sharing (CORS) settings could expose these tokens to unintended origins, exacerbating the risk.

Langflow OSS vulnerability web-application api-exploitation improper-authentication cve privilege-escalation code-injection critical-vulnerability +4
2r 5t 3c
high advisory

Unauthenticated Server-Side Request Forgery in meta-ads-mcp via image_url

An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in `meta-ads-mcp` v1.0.113, specifically within the `upload_ad_image` function, by providing a malicious `image_url` parameter that causes the server to make arbitrary outbound HTTP requests to internal services, RFC 1918 addresses, or cloud metadata endpoints, leading to information disclosure and potential internal network compromise.

meta-ads-mcp 1.0.113 ssrf vulnerability web python unauthenticated
3t 2i
high advisory

Incomplete Privilege Drop in 'sh' Package Allows Privilege Escalation

A vulnerability in the 'sh' package, affecting Linux/Unix-like systems, allows for an incomplete privilege drop when the `_uid` option is used. When a process with elevated privileges launches a child process with `_uid=<unprivileged user>`, the child process changes its UID and primary GID but fails to reset its supplementary groups. This flaw enables the child process to retain potentially privileged supplementary groups (e.g., root, docker), bypassing intended privilege boundaries and granting access to resources beyond its expected permissions.

sh privilege-escalation vulnerability linux
1t
high advisory

Privilege Escalation in AWS Advanced JDBC Wrapper for Aurora PostgreSQL

A privilege escalation vulnerability (CVE-2026-11400) exists in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL, affecting versions 3.0.0 through 4.0.0. A low-privileged authenticated user can craft a function to execute with rds_superuser permissions.

AWS Advanced JDBC Wrapper +1 privilege-escalation vulnerability cloud aws postgresql
1c
high advisory

IBM Db2 Remote Code Execution via JDBC URL Vulnerability (CVE-2026-9762)

A critical remote code execution vulnerability, identified as CVE-2026-9762, exists in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4, allowing attackers to execute arbitrary code if a JDBC URL is under user control, categorized as an improper control of code generation.

Db2 +1 vulnerability rce code-injection database
2t 1c
high advisory

Authentication Bypass Vulnerability in Vimesoft Enterprise Video Platform (CVE-2026-12691)

CVE-2026-12691 describes a critical authentication bypass vulnerability in Vimesoft Inc.'s Enterprise Video Platform versions from 3.11.0.0 before 3.25.0, allowing unauthenticated attackers to bypass security mechanisms for critical functions and potentially gain unauthorized access to sensitive information, with a CVSS v3.1 base score of 7.5.

Enterprise Video Platform authentication-bypass vulnerability web-application
1t 1c
critical advisory

CVE-2026-8297: Critical SQL Injection in GisLab Laboratory Management System

CVE-2026-8297 is a critical SQL injection vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.'s GisLab Laboratory Management System, affecting versions 1.4.03 through 08072026, which allows unauthenticated remote attackers to execute arbitrary SQL commands and achieve high impact on confidentiality, integrity, and availability of sensitive data.

GisLab Laboratory Management System sql-injection vulnerability web-application cve
1r 1t 1c
critical advisory

CVE-2026-12693 Authorization Bypass in Vimesoft Enterprise Video Platform

A critical authorization bypass vulnerability, identified as CVE-2026-12693, exists in Vimesoft Inc.'s Enterprise Video Platform, affecting versions from 3.11.0.0 before 3.25.0, allowing an unauthenticated, remote attacker to gain unauthorized access to functionality not properly constrained by Access Control Lists (ACLs) via a user-controlled key, leading to high confidentiality and integrity impacts.

Enterprise Video Platform authorization-bypass vulnerability web-application
2t 1c
critical advisory

CVE-2026-12692: Unverified Password Change Vulnerability in Vimesoft Enterprise Video Platform

An unverified password change vulnerability (CVE-2026-12692) exists in Vimesoft Inc.'s Enterprise Video Platform, affecting versions from 3.11.0.0 up to, but not including, 3.25.0, which allows an attacker to bypass authentication mechanisms, potentially leading to unauthorized access to the platform by changing user passwords without proper verification.

Enterprise Video Platform +1 vulnerability authentication-bypass web-application cve critical-vulnerability
1t 2c 1i
high advisory

SigNoz Open Redirect Vulnerability Allows Session Token Theft (CVE-2026-63094)

An open redirect vulnerability exists in SigNoz through version 0.133.0 within its SSO authentication flow, affecting instances configured with Google OAuth, SAML, or OIDC. Unauthenticated attackers can exploit this by crafting a login URL with a malicious `ref` parameter pointing to an attacker-controlled host. By delivering this crafted URL to a victim, attackers can steal the victim's access and refresh tokens upon successful SSO authentication, leading to session compromise.

SigNoz <= 0.133.0 open-redirect sso vulnerability web-application credential-theft
3t 1c
high advisory

CVE-2026-63093: Binary Planting Vulnerability in Cursor for Windows

CVE-2026-63093 describes a binary planting vulnerability in Cursor for Windows version 3.2.16 that allows a remote attacker to achieve arbitrary code execution by placing a malicious `git.exe` file in a crafted repository's root, which the Cursor IDE automatically executes during startup or on a recurring cadence when a developer opens the repository, running the malicious binary under the privileges of the current user.

Cursor for Windows 3.2.16 binary-planting ide vulnerability execution windows
1r 3t 1c
high advisory

CVE-2026-7488 IKAS E-Commerce Sensitive Information Disclosure Vulnerability

A sensitive information insertion vulnerability (CVE-2026-7488) in IKAS Technology Inc. E-Commerce software allows an unauthenticated attacker to retrieve embedded sensitive data by crafting specific requests, leading to potential data exposure.

E-Commerce vulnerability data-exposure cve
1t 1c
high advisory

Improper Restriction of XML External Entity Reference in Netcad Software NetGIS (CVE-2026-8396)

A critical XML External Entity (XXE) vulnerability, CVE-2026-8396, in Netcad Software Inc.'s NetGIS allows unauthenticated remote attackers to perform serialized data external linking, potentially leading to sensitive information disclosure or server-side request forgery.

NetGIS xxe vulnerability web-application information-disclosure cwe-611
2t 1c
high advisory

Proliz OBS Vulnerability Allows Sensitive Information Insertion Leading to ACL Bypass (CVE-2026-7189)

A high-severity vulnerability, CVE-2026-7189, in Proliz Software Ltd. Co.'s Proliz OBS before version 3.6.0 allows for the insertion of sensitive information into sent data, enabling attackers to access functionality not properly constrained by Access Control Lists (ACLs).

Proliz's OBS vulnerability sensitive-data-exposure access-control-bypass
1c
high advisory

Multiple Vulnerabilities in Ubuntu Pro Client

Multiple vulnerabilities exist in the ubuntu-pro-client within Ubuntu Linux, allowing an attacker to execute arbitrary program code with administrator privileges and disclose confidential information.

ubuntu-pro-client linux vulnerability rce information-disclosure
3t
high advisory

nginx-ui: Multiple Vulnerabilities

Multiple vulnerabilities in nginx-ui allow an attacker to execute arbitrary code, including with root privileges, gain elevated privileges, perform account takeover, bypass security measures, and disclose or manipulate data.

nginx-ui vulnerability rce privilege-escalation data-exfiltration
4t
low advisory

pyasn1: Quadratic Complexity in OBJECT IDENTIFIER and RELATIVE-OID Processing Allows Denial of Service

A denial of service vulnerability, identified as CVE-2026-59885, exists in the pyasn1 library caused by quadratic complexity in the processing of OBJECT IDENTIFIER and RELATIVE-OID, which can lead to a denial of service.

pyasn1 denial-of-service vulnerability library
1c
medium advisory

CVE-2026-15392: DBD::File Module Symlink Vulnerability

CVE-2026-15392 is a medium-severity vulnerability affecting versions of the Perl module DBD::File prior to 1.651, where the module fails to prevent symlinks to untrusted locations, potentially allowing local attackers to achieve information disclosure or local privilege escalation through symlink following.

DBD::File < 1.651 vulnerability symlink perl
1c
low advisory

libsoup Websocket Unbounded Decompression Denial of Service Vulnerability

A remote denial of service vulnerability, CVE-2026-15709, exists in the libsoup library's websocket permessage-deflate extension, allowing an attacker to trigger a denial of service through unbounded decompression.

libsoup denial-of-service vulnerability
1c
low advisory

Libsoup WebSocket Remote Denial of Service Vulnerability

A remote denial of service vulnerability, CVE-2026-15711, exists in the libsoup library's WebSocket connection handling due to an oversized control frame protocol violation, allowing an attacker to cause service disruption.

libsoup denial-of-service vulnerability websocket
1c
low threat

Vulnerability in Perl DBI Module Before 1.651 (CVE-2026-60082)

A vulnerability, identified as CVE-2026-60082, exists in the DBI module for Perl, specifically in versions before 1.651, related to the module not enforcing statement handle consistency with the row.

exploited DBI < 1.651 vulnerability perl data-integrity
1c
medium threat

Libsoup Vulnerability CVE-2026-15714 Allows Out-of-Bounds Read

A vulnerability identified as CVE-2026-15714 in the Libsoup library's soupmultipartinputstream component allows an out-of-bounds read when processing an oversized multipart boundary string, potentially leading to information disclosure or application instability.

exploited Libsoup vulnerability out-of-bounds-read gnome
1c
high threat

Libsoup HTTP/2 Frame Window Exhaustion Remote Denial of Service

A remote denial of service vulnerability, CVE-2026-15713, exists in the soupcache component of the Libsoup library due to a memory leak that leads to HTTP/2 frame window exhaustion, potentially causing application crashes or unresponsiveness.

exploited Libsoup denial-of-service vulnerability http/2 memory-leak
1c
medium advisory

CoreDNS: Multiple Vulnerabilities Enable Denial of Service

Multiple vulnerabilities exist in CoreDNS that allow a remote, unauthenticated attacker to execute a Denial of Service (DoS) attack against the service, potentially leading to service disruption and unavailability for affected systems utilizing CoreDNS.

CoreDNS +1 dns denial-of-service vulnerability network
1t 1c updated
high advisory

Sensitive Information Exposure in LearnPress WordPress Plugin (CVE-2026-13765)

An unauthenticated sensitive information exposure vulnerability (CVE-2026-13765) in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses, versions up to 4.4.1, allows attackers to extract quiz answers, options, explanations, and question content, including for paid courses.

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses <= 4.4.1 wordpress plugin vulnerability information-exposure web
1r 2t 1c
high advisory

Arbitrary File Upload Vulnerability in ProfilePress WordPress Plugin (CVE-2026-13352)

An arbitrary file upload vulnerability, CVE-2026-13352, affects the ProfilePress plugin for WordPress up to version 4.16.18, allowing authenticated attackers with author-level privileges or higher to upload executable files, which can lead to remote code execution.

ProfilePress plugin for WordPress wordpress vulnerability rce file-upload cms
3t 1c
high advisory

Grav API Plugin Vulnerability Exposes JWT Access Tokens via URL Parameter

The Grav API plugin (getgrav/grav-plugin-api) before version 1.0.0-rc.16 is vulnerable to sensitive information exposure, accepting JWT access tokens via the '?token=' URL query parameter, causing these tokens to be logged in web server access logs, browser history, and potentially leaked through Referer headers, proxy, or CDN logs, which allows an attacker to gain unauthorized API access, read configuration and user data, create new admin accounts, modify system settings, and delete pages.

Grav API plugin +1 vulnerability web api jwt information-exposure grav
1r 6t 1c
high threat

CVE-2026-62234: Grav SSRF Vulnerability via Unrestricted cURL Protocols in Webhooks

An authenticated user with `api.webhooks.write` permissions can exploit CVE-2026-62234, a Server-Side Request Forgery (SSRF) vulnerability in Grav before version 2.0.4, by creating webhooks with unrestricted cURL protocols like `file://`, `dict://`, or `gopher://` to read local files, access process information, and pivot to internal services.

exploited Grav ssrf web-application cve vulnerability
5t 1c
high advisory

Grav Plugin API Privilege Escalation via Authorization Bypass (CVE-2026-62233)

A privilege escalation vulnerability (CVE-2026-62233) in grav-plugin-api before version 1.0.6 allows non-super api.users.write managers to bypass authorization checks on administrative API endpoints, enabling the creation of super-admin API keys or disabling super-admin Two-Factor Authentication (2FA), leading to full Grav instance takeover.

grav-plugin-api privilege-escalation vulnerability grav
1t 1c
high advisory

Grav Two-Factor Authentication Bypass Vulnerability (CVE-2026-62232)

A high-severity two-factor authentication bypass vulnerability (CVE-2026-62232) in Grav CMS before version 2.0.4 allows an attacker with a victim's password to overwrite their 2FA secret via the `regenerate2FASecret` task, enabling unauthorized access by generating a valid TOTP code and reducing multi-factor authentication to password-only protection.

Grav +1 2fa-bypass vulnerability web-application
1r 2t 1c
high advisory

OpenClaw SSRF Vulnerability (CVE-2026-62227) Allows Network Policy Bypass

A server-side request forgery (SSRF) vulnerability, CVE-2026-62227, in OpenClaw versions before 2026.5.26 allows attackers with lower-trust access to bypass network policy checks through browser snapshot routes, leading to unauthorized access to internal network destinations.

OpenClaw ssrf vulnerability web-application
1r 3t 1c
high threat

OpenClaw Authorization Bypass Vulnerability (CVE-2026-62226)

An authorization bypass vulnerability, CVE-2026-62226, affects OpenClaw versions 2026.3.28 through 2026.5.18, enabling attackers with lower-trust access to perform actions requiring stronger authorization due to improper validation of current-tab URL checks in the browser act route.

exploited OpenClaw < 2026.5.19 authorization-bypass web-application vulnerability
2t 1c 2i
high advisory

OpenClaw Vulnerability Allows Untrusted Workspace Plugin Loading (CVE-2026-62222)

A vulnerability, CVE-2026-62222, exists in OpenClaw versions prior to 2026.5.22, where an attacker with lower-trust caller access or control over configured input paths can exploit a flaw in the setup-mode discovery to load untrusted workspace plugins, leading to arbitrary code execution, persistence, and privilege escalation.

OpenClaw vulnerability remote-code-execution privilege-escalation persistence
3t 1c 2i
high advisory

OpenClaw Authorization Flaw in QQBot Exec Approvals (CVE-2026-62217)

An authorization flaw (CVE-2026-62217, CWE-863) in OpenClaw versions 2026.5.14-beta.1 before 2026.5.27 allows lower-trust callers or non-allowlisted senders to execute or persist unauthorized operations via the QQBot exec approvals feature, potentially leading to privilege escalation and system compromise.

OpenClaw authorization-bypass cve qqbot privilege-escalation vulnerability
2t 1c 2i
high advisory

OpenClaw Race Condition Bypasses Authorization via DNS Rebinding Timing Window (CVE-2026-62212)

A race condition exists in OpenClaw versions before 2026.5.28 within the MS Teams safeFetch DNS rebinding check, allowing a lower-trust caller to exploit a timing window between the DNS validation check and its use, potentially bypassing authorization or policy checks if the affected feature is enabled and reachable.

OpenClaw vulnerability race-condition dns-rebinding authentication-bypass cve
1c
high advisory

OpenClaw Environment Variable Filtering Vulnerability Allows Execution and Persistence

OpenClaw versions prior to 2026.6.6 contain an environment variable filtering vulnerability in its host exec component that fails to properly sanitize rustup startup variables, allowing attackers with lower-trust caller access or configured input paths to execute or persist actions beyond their intended authorization level.

OpenClaw +1 cve-2026-62203 vulnerability environment-variable code-execution persistence
2t 2c
high threat

CVE-2026-62202 - OpenClaw Privilege Escalation via Isolated Cron Jobs

OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability, CVE-2026-62202, in isolated cron jobs that allows lower-trust callers to regain denied execution tools and execute or persist actions beyond their intended authorization by leveraging misconfigured input paths.

exploited OpenClaw privilege-escalation vulnerability cve
2t 2c 2i
high advisory

OpenClaw Network Policy Bypass Vulnerability CVE-2026-62201

OpenClaw versions prior to 2026.6.6 contain a network policy bypass vulnerability, CVE-2026-62201, within its sandbox exec-server that allows lower-trust callers to send HTTP requests to internal network destinations, effectively bypassing configured security policies and leading to server-side request forgery (SSRF).

OpenClaw vulnerability ssrf network-policy-bypass
1r 2t 1c
critical advisory

Clawvet API Server Hard-Coded JWT Secret Vulnerability (CVE-2026-62241)

A critical vulnerability exists in the clawvet self-hosted API server (apps/api) before version 0.7.5 due to a hard-coded fallback JWT secret ('clawvet-dev-secret-change-me') shipped in the default .env.example, allowing an unauthenticated remote attacker to harvest user IDs, forge session cookies, and retrieve sensitive user information including email address, subscription plan, and API key via the /api/v1/auth/me endpoint.

clawvet self-hosted API server vulnerability CVE-2026-62241 JWT API hardcoded-secret
3t 1c 1i
critical advisory

Bricksforge WordPress Plugin Privilege Escalation Vulnerability (CVE-2026-14956)

The Bricksforge plugin for WordPress, in versions up to and including 3.1.8.6, contains a critical privilege escalation vulnerability, CVE-2026-14956, allowing unauthenticated attackers to register new administrator accounts by manipulating the 'fieldIds' parameter in Pro Forms registration actions, leading to full compromise of the WordPress site.

Bricksforge plugin wordpress plugin privilege-escalation vulnerability webserver
1t 1c
critical advisory

CVE-2026-63089: WireGuard Easy Weak One-Time Link Token Generation Vulnerability

Unauthenticated network attackers can exploit a cryptographically weak one-time link token generation vulnerability, CVE-2026-63089, in WireGuard Easy through version 15.3.0 by brute-forcing a limited keyspace against the unauthenticated `/cnf/:oneTimeLink` route, allowing them to recover WireGuard peer credentials (PrivateKey and PresharedKey) and impersonate legitimate peers to gain unauthorized VPN access.

WireGuard Easy vulnerability cve weak-cryptography credential-access initial-access web
1r 2t 1c
high advisory

MCP Python SDK WebSocket Server Lacks Host/Origin Validation

A high-severity vulnerability (CVE-2026-59950) in the deprecated `mcp.server.websocket.websocket_server` component of the MCP Python SDK allows malicious webpages to bypass same-origin policy and establish unauthorized WebSocket connections, enabling attackers to invoke server tools and read resources from affected local or LAN-bound MCP servers.

mcp Python SDK vulnerability server-side websocket python supply-chain
2t 1c
high advisory

ArcadeDB Trigger Script RCE via Java.lang.* Allow-list

A vulnerability in ArcadeDB's ScriptTriggerExecutor allows users with UPDATE_SCHEMA privileges to achieve OS Remote Code Execution (RCE) due to a permissive allow-list for trigger scripts, enabling direct calls to `java.lang.Runtime.exec()` when a malicious trigger script is created and fired.

arcadedb-engine ArcadeDB RCE vulnerability java database privilege-escalation SSRF DoS +2
3t
high advisory

MCP Python SDK Authentication Bypass Vulnerability (CVE-2026-52869)

A high-severity authentication bypass vulnerability, CVE-2026-52869, exists in affected versions of the MCP Python SDK's HTTP transports, allowing an attacker who obtains or guesses a session ID to send JSON-RPC messages to an existing session without verifying the authenticated principal, thereby bypassing per-client isolation and potentially injecting messages.

MCP Python SDK <= 1.27.1 vulnerability authentication-bypass python sdk web-application
1t 1c
medium advisory

MCP Python SDK Vulnerability Allows Cross-Client Task Access and Cancellation (CVE-2026-52870)

A high-severity vulnerability (CVE-2026-52870) in the MCP Python SDK's experimental task handlers, specifically in versions 1.23.0 through 1.27.1, allows any connected client to observe, read results from, and cancel tasks belonging to other clients due to a lack of session validation, potentially leading to unauthorized data access and denial of service.

mcp vulnerability server-side-request-forgery data-exfiltration denial-of-service
3t 1c
high advisory

Envoy Gateway xDS Control Plane Information Disclosure Vulnerability (CVE-2026-53714)

A vulnerability in Envoy Gateway, when operating in GatewayNamespaceMode, allows unauthenticated access to the xDS gRPC server on port 18000. This is due to a missing unary interceptor and an authentication bypass in the JWT interceptor that fails to validate specific message types (DiscoveryRequest). Any pod within the cluster can exploit this flaw using the State-of-the-World (SotW) xDS protocol to retrieve sensitive information, including TLS private keys, all xDS resources, backend endpoints, and routing rules.

Envoy Gateway +1 vulnerability information-disclosure cloud network
2t
critical advisory

Envoy Gateway Authentication Bypass via Path Traversal Leads to Secret Disclosure

A critical path traversal vulnerability (CVE-2026-53713) exists in the `to_absolute_normalized_path` function of Envoy Gateway due to improper input validation, allowing specially crafted Lua code submitted via an `EnvoyExtensionPolicy` to bypass critical-path checks and read arbitrary sensitive files from the gateway controller pod's filesystem, potentially leading to authentication bypass to the Kubernetes API Server or Gateway XDS server.

Envoy Gateway +1 envoy gateway vulnerability path-traversal file-disclosure kubernetes cloud
2t
high advisory

Grafana MCP Server SSRF and Loki DoS Vulnerabilities Addressed

Grafana has published security advisories for vulnerabilities in Grafana MCP Server (CVE-2026-15583), leading to server-side request forgery, and Grafana Loki (CVE-2026-21729), resulting in unbounded memory allocation and denial of service, impacting versions 0.17.1 and prior for MCP Server and 3.7.0 and prior for Loki, urging users to update to mitigate potential exploitation.

Grafana MCP Server 0.17.1 and prior +1 grafana ssrf dos vulnerability cve
1r 3t 2c
high advisory

CVE-2026-63088: stoatchat Server-Side Request Forgery (SSRF) via DNS Blocklist Bypass

An unauthenticated, network-accessible Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2026-63088, exists in stoatchat versions prior to 0.14.0, allowing attackers to bypass DNS-based IP blocklists by exploiting incomplete address validation, potentially leading to unauthorized access to internal network resources.

stoatchat < 0.14.0 vulnerability ssrf web-application
1t 1c
high advisory

Server-Side Request Forgery in text-generation-inference Allows Internal Access

An unauthenticated network attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2026-63086, in the OpenAI-compatible multimodal chat completions endpoint of text-generation-inference through version 3.3.7 to coerce the server into issuing arbitrary HTTP GET requests, enabling internal port scanning and credential theft from internal services and cloud instance metadata endpoints.

text-generation-inference <= 3.3.7 ssrf vulnerability data-exfiltration cloud network
1r 3t 1c
high advisory

Authorization Bypass in Axelor Open Platform (CVE-2026-63085)

An authorization bypass vulnerability, CVE-2026-63085, in Axelor Open Platform versions 8.x prior to 8.2.2 allows authenticated non-admin users to exploit unenforced field restrictions during nested relational save operations to modify sensitive user record fields like roles and groups, thereby escalating privileges to administrative levels.

Axelor Open Platform privilege-escalation vulnerability authorization-bypass
1t 1c
high advisory

Lenovo App Store Path Traversal Vulnerability (CVE-2026-13103) Leading to Arbitrary Code Execution

A critical path traversal vulnerability, identified as CVE-2026-13103, exists in the Lenovo App Store, enabling a local authenticated user to achieve arbitrary code execution on affected Windows systems within the Chinese market.

Lenovo App Store vulnerability path-traversal rce lenovo
1t 1c
critical advisory

Grafana OnCall Unauthenticated Access Vulnerability (CVE-2026-63087)

A critical unauthenticated access vulnerability, CVE-2026-63087, in Grafana OnCall through version 1.16.11 allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to an internal plugin install endpoint using hardcoded default stack_id and org_id values, enabling authentication to all internal API endpoints, creation of arbitrary administrative users, and redirection of API calls to an attacker-controlled host.

Grafana OnCall unauthenticated-access grafana oncall vulnerability rce-potential
4t 1c
medium advisory

Rockwell Automation Communication Modules Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.

1756-EN2 <=V12.001 +2 industrial-control-systems ics ot vulnerability denial-of-service rockwell-automation
1t 1c
high advisory

Multiple Vulnerabilities in AutomationDirect Productivity Suite Could Lead to Privilege Escalation and DoS

Multiple vulnerabilities, including out-of-bounds write, out-of-bounds read, and divide-by-zero, exist in AutomationDirect Productivity Suite versions up to and including v4.6.2.2, allowing an attacker with local or physical access to exploit these flaws via crafted IOCTL requests, potentially leading to kernel memory corruption, privilege escalation, information disclosure, application instability, or a denial-of-service condition.

Productivity Suite ICS SCADA industrial-control-systems out-of-bounds-write out-of-bounds-read privilege-escalation denial-of-service vulnerability
2t
high advisory

Multiple Out-of-Bounds Write Vulnerabilities in Rockwell Automation Arena

Multiple out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in Rockwell Automation Arena versions prior to V17.00.01 could allow an attacker to execute arbitrary code by convincing a user to open a malicious file.

Rockwell Automation Arena <=V17.00.00 +1 vulnerability ics ot memory-corruption out-of-bounds-write arbitrary-code-execution critical-manufacturing
1r 3t 4c updated
medium threat

NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability

A high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.

exploited NASA Core Flight System cve vulnerability denial-of-service ics space transportation
1t
high advisory

Rockwell Automation FactoryTalk DataMosaix Stored XSS Vulnerability (CVE-2026-9292)

An authenticated attacker with high privileges can exploit CVE-2026-9292, a Stored Cross-Site Scripting (XSS) vulnerability, in Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier by injecting malicious scripts into the Workflows configuration, leading to execution of malicious JavaScript in other users' browsers and potential account takeover or credential theft.

FactoryTalk DataMosaix Private Cloud xss ics ot vulnerability cve
2t 1c
medium advisory

Rockwell Automation Flex 5000 Adapter Vulnerability Leads to Denial of Service

A denial-of-service vulnerability (CVE-2026-12659), categorized as a Double Free issue (CWE-415), exists in Rockwell Automation Flex 5000 Adapter version 6.011 due to improper handling of crafted CIP packets, which could allow an unauthenticated attacker to cause a denial-of-service condition requiring a power cycle to recover.

Flex 5000 Adapter ics ot critical-manufacturing information-technology denial-of-service vulnerability
2t 1c
medium advisory

Rockwell Automation CompactLogix and ControlLogix Vulnerabilities Lead to Denial-of-Service

Multiple Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product versions are vulnerable to denial-of-service conditions through CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, which an attacker can exploit via buffer overflows by loading invalid project files or writing invalid data, causing controllers to enter a major non-recoverable fault.

CompactLogix 5370 +13 ics scada denial-of-service critical-manufacturing vulnerability
2t 3c
high advisory

Unauthenticated Server-Side Request Forgery (SSRF) Vulnerability in stoatchat CVE-2026-63306

An unauthenticated server-side request forgery vulnerability, tracked as CVE-2026-63306, exists in stoatchat versions prior to 0.13.5 in the /proxy and /embed endpoints, allowing attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints, leading to unauthorized information disclosure and potential further compromise of internal infrastructure.

stoatchat ssrf vulnerability web-application unauthenticated information-disclosure
1r 3t 1c
medium advisory

Denial-of-Service Vulnerability Affects ESET Endpoint Antivirus and Server Security Products (CVE-2026-6424)

A vulnerability, identified as CVE-2026-6424, has been discovered in various ESET Endpoint Antivirus and Server Security product versions, allowing an attacker to cause a denial of service, impacting the availability of the affected systems.

Endpoint Antivirus 12.0.x +11 vulnerability denial-of-service endpoint-security server-security
1t 1c
high advisory

Multiple Vulnerabilities Discovered in Drupal Leading to XSS and Data Confidentiality Breach

Multiple vulnerabilities have been discovered in Drupal, allowing an attacker to achieve indirect remote code injection via Cross-Site Scripting (XSS) and compromise data confidentiality across various versions.

Drupal +2 web-application vulnerability xss data-breach
3t
high advisory

Vulnerability in Traefik Allows Security Policy Bypass

A vulnerability has been discovered in Traefik versions 3.7.x prior to 3.7.8, enabling an attacker to bypass security policies, potentially leading to unauthorized access or actions.

Traefik vulnerability security-bypass webserver
1i
high advisory

FreeRDP: Multiple Vulnerabilities

Multiple vulnerabilities in FreeRDP allow an attacker to execute arbitrary code, bypass security controls, disclose sensitive information, tamper with data, or cause a denial-of-service, posing a high risk to systems using the software.

FreeRDP vulnerability remote-desktop rce denial-of-service
3t
medium advisory

X.Org X11 Server (libXfont2): Multiple Vulnerabilities Allow Arbitrary Code Execution with Administrator Rights

Multiple vulnerabilities in X.Org X11 Server and libXfont2 allow a local attacker to gain elevated privileges and execute arbitrary code with root rights, posing a significant risk for systems utilizing the X.Org display server.

X11 Server +1 privilege-escalation linux vulnerability
1t
high advisory

LiteLLM Vulnerability Allows Remote Code Execution with Service Privileges

A remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code with the privileges of the service.

LiteLLM remote-code-execution rce vulnerability llm-security bsi
2t
medium threat

Multiple Vulnerabilities in Absolute Secure Access

An attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.

exploited Absolute Secure Access vulnerability denial-of-service information-disclosure remote-access
2t
critical advisory

X-Rite MA-T6 Remote Code Execution Vulnerability (CVE-2023-49899)

An unauthenticated remote attacker can exploit CVE-2023-49899 in X-Rite MA-T6 devices (versions prior to v2.33) to achieve arbitrary command execution by bypassing origin verification, leading to full compromise of the device.

MA-T6 vulnerability RCE ICS OT critical
2t 1c
medium advisory

Drupal Core: Multiple Vulnerabilities Allowing Information Disclosure and XSS

A remote, unauthenticated attacker can exploit multiple vulnerabilities in Drupal Core to achieve information disclosure and Cross-Site Scripting (XSS) attacks, potentially compromising user data or session integrity.

Drupal Core vulnerability web-application xss information-disclosure cve-less
2t
medium advisory

Apache Ivy: Vulnerability Allows File Manipulation

A remote, authenticated attacker can exploit a vulnerability in Apache Ivy to manipulate files on the system, leading to unauthorized modification of data and potential integrity compromise.

Apache Ivy file-manipulation vulnerability
1t
medium advisory

7-Zip: Vulnerability Enables Code Execution

A remote, anonymous attacker can exploit an unspecified vulnerability in 7-Zip to execute arbitrary code, leading to potential compromise of the system running the vulnerable software.

7-Zip vulnerability rce file-compression
1t
medium advisory

F5 BIG-IP and BIG-IP Next Vulnerability Enables Denial of Service

An unauthenticated, remote attacker can exploit a vulnerability in F5 BIG-IP and BIG-IP Next to perform a Denial of Service attack, potentially disrupting services.

BIG-IP +1 denial-of-service vulnerability network
1t
critical threat

Unpatched Shark Vacuum Flaw Allows Region-Wide Remote Control and Data Theft

A researcher discovered an unpatched vulnerability in Shark RV2320EDUS robot vacuums that allows an attacker with physical access to extract an overly permissive AWS IoT certificate, enabling region-wide remote command execution and data theft on other Shark vacuums.

Shark RV2320EDUS +1 iot-security vulnerability cloud-security access-control remote-code-execution
6t
high threat

Red Hat OpenShift Container Platform Vulnerability Allows Security Bypass

A vulnerability in the Red Hat OpenShift Container Platform allows a local attacker to bypass security controls, potentially leading to unauthorized access or further compromise of the platform.

exploited OpenShift Container Platform vulnerability cloud container
1t
medium advisory

Gitea: Multiple Vulnerabilities

An anonymous, remote attacker can exploit multiple vulnerabilities in Gitea to manipulate data or trigger a denial of service.

Gitea vulnerability denial-of-service data-manipulation
2t updated
medium advisory

Argo CD: Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in Argo CD, including Cross-Site Scripting (XSS) and information disclosure flaws, which could lead to sensitive information exposure and potentially allow the attacker to gain administrator privileges.

Argo CD argo-cd vulnerability xss information-disclosure privilege-escalation cloud kubernetes
2t
high advisory

Stored Cross-Site Scripting Vulnerability in Breakdance WordPress Plugin

The Breakdance plugin for WordPress, in versions up to and including 2.7.1, is susceptible to CVE-2026-7543, a Stored Cross-Site Scripting (XSS) vulnerability via the 'fields' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute when users access affected pages, potentially leading to session hijacking, data theft, or defacement.

Breakdance plugin wordpress xss web-application vulnerability
1r 2t 1c
high advisory

Uncanny Automator WordPress Plugin Vulnerable to Arbitrary File Deletion (CVE-2026-15008)

A critical arbitrary file deletion vulnerability, CVE-2026-15008, exists in The Uncanny Automator plugin for WordPress, versions up to and including 7.3.1.4, due to insufficient file path validation in the `fr_token` function, allowing unauthenticated attackers to delete arbitrary files on the server and potentially achieve remote code execution (RCE) by targeting critical files like `wp-config.php`, provided a Forminator form is linked to an 'Everyone' configured Uncanny Automator recipe, enabling the submission of a malicious serialized payload that leverages a gadget chain within the plugin's `Action_Helpers_Email __destruct()` method.

Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin wordpress vulnerability arbitrary-file-deletion deserialization
2t 1c
low advisory

CVE-2026-48863: libsolv Stack-Based Buffer Overflow Leading to Denial of Service

A critical stack-based buffer overflow vulnerability, CVE-2026-48863, has been identified in the PGP verification component of libsolv, allowing a remote attacker to trigger a denial of service by crafting a malicious Ed25519 PGP signature with mismatched MPI lengths, impacting automated package or repository processing workflows.

libsolv +1 vulnerability denial-of-service buffer-overflow linux
1c updated
low advisory

Feast Feature Server Denial of Service via Unauthenticated WebSocket Connections (CVE-2026-23538)

A vulnerability (CVE-2026-23538) exists in the Feast Feature Server's /ws/chat endpoint, allowing remote attackers to establish numerous unauthenticated, persistent WebSocket connections. This exploit, a form of resource exhaustion (CWE-770), consumes server resources like memory, CPU, and file descriptors, leading to a complete denial of service for legitimate users. Affected versions are those prior to 0.59.0.

Feast Feature Server +1 denial-of-service vulnerability websocket resource-exhaustion feast-feature-server
1r 1t 1c
high advisory

Unauthenticated Access to @andrea9293/mcp-documentation-server Web UI/API

The `@andrea9293/mcp-documentation-server` version 1.13.0 defaults to binding its Web UI/API to all network interfaces (0.0.0.0:3080) and lacks authentication for its document-management endpoints, enabling any network-reachable attacker to perform unauthorized operations such as reading, searching, adding, and deleting documents, potentially corrupting the user's knowledge base.

@andrea9293/mcp-documentation-server vulnerability web api node.js default-misconfiguration unauthenticated-access
1r 4t
medium advisory

dd-trace-rb: Improper Parsing of W3C Baggage Headers Leads to DoS

A vulnerability (CVE-2026-50276) in Datadog tracing libraries, specifically `dd-trace-rb` versions prior to 2.32.0, allows a remote and unauthenticated attacker to perform a Denial of Service (DoS) by sending HTTP requests with malformed W3C baggage headers, leading to unbounded CPU and memory consumption.

dd-trace-rb < 2.32.0 denial-of-service vulnerability ruby web
1t
medium advisory

Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression

Pomerium proxy deployments using the stateless authentication flow (Pomerium Zero or hosted authenticate) are vulnerable to a pre-authentication memory exhaustion denial of service, allowing an unauthenticated attacker to send specially crafted HPKE-encrypted zstd payloads to the `/.pomerium/callback` endpoint, leading to excessive memory allocation and potential proxy crashes.

Pomerium +1 denial-of-service network vulnerability go
1t 1i
medium advisory

Datadog dd-trace-go Library Vulnerability May Lead to Denial of Service

A vulnerability, CVE-2026-50274, in Datadog's `dd-trace-go` library (versions <= 1.24.1 and v2 < 2.8.1) allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending HTTP requests with oversized W3C baggage headers, leading to unbounded CPU and memory consumption in instrumented services.

go/github.com/DataDog/dd-trace-go +1 denial-of-service vulnerability supply-chain go datadog
1t
medium advisory

Datadog dd-trace-dotnet Improper W3C Baggage Header Parsing Leads to DoS

A Denial of Service (DoS) vulnerability exists in Datadog tracing libraries (`dd-trace-dotnet`) due to improper parsing of W3C baggage HTTP headers, allowing remote, unauthenticated attackers to send requests with arbitrarily large baggage headers, causing unbounded CPU and memory consumption and leading to service unavailability for any HTTP service instrumented with affected library versions where baggage propagation is enabled by default. The issue, tracked as CVE-2026-50273, is resolved in version 3.43.0 and later.

Datadog.Trace +1 denial-of-service vulnerability dot-net
1t
medium advisory

Datadog dd-trace-js W3C Baggage Header Denial of Service Vulnerability

The Datadog `dd-trace-js` library, specifically versions older than 5.100.0, is vulnerable to a Denial of Service (DoS) attack where improper parsing of W3C baggage HTTP headers allows a remote, unauthenticated attacker to send requests with an arbitrarily large number of comma-separated key-value pairs, leading to unbounded CPU and memory consumption and enabling a remote DoS against any HTTP service instrumented with the affected library where baggage propagation is enabled.

dd-trace-js denial-of-service vulnerability javascript nodejs datadog
1t
medium advisory

Datadog dd-trace-py Improper Parsing of W3C Baggage Headers Leads to DoS

The Datadog dd-trace-py tracing library, versions prior to 4.8.2, is vulnerable to a Denial of Service (DoS) attack due to improper parsing of W3C baggage HTTP headers, which fails to enforce item-count or byte-size limits on the extraction path, allowing an unauthenticated attacker to send a request with an arbitrarily large baggage header causing unbounded CPU and memory consumption.

dd-trace-py < 4.8.2 denial-of-service vulnerability python supply-chain
1t
medium advisory

Datadog dd-trace-java DoS Vulnerability via W3C Baggage Headers

A denial-of-service vulnerability, CVE-2026-50270, exists in Datadog tracing libraries (dd-trace-java prior to version 1.62.0) that implement W3C baggage propagation. Remote, unauthenticated attackers can exploit this by sending HTTP requests with W3C baggage headers containing an arbitrarily large number of comma-separated key-value pairs. The tracer, when extracting these headers, fails to enforce item-count or byte-size limits, leading to unbounded CPU and memory consumption as it allocates hash-map entries for each pair, thereby causing a denial of service against the instrumented HTTP service.

dd-java-agent denial-of-service java vulnerability w3c datadog
1t
high advisory

ViewComponent HTML-Safety Bypass Leads to Cross-Site Scripting (CVE-2026-54498)

A critical HTML-safety bypass vulnerability, CVE-2026-54498, exists in ViewComponent versions prior to 4.12.0, allowing attackers to inject raw HTML via the `around_render` method, bypassing standard escaping and leading to Cross-Site Scripting (XSS) in affected Ruby on Rails applications.

ViewComponent xss web-application ruby vulnerability client-side-scripting
3t
medium advisory

Message Corruption Vulnerability in websocket-driver Library (CVE-2026-54466)

A critical vulnerability, CVE-2026-54466, in the `websocket-driver` npm library allows remote attackers to cause message corruption by sending specially crafted WebSocket frames that exploit improper handling of the protocol's length header, leading to incorrect parsing of subsequent payload data.

websocket-driver vulnerability websocket npm message-corruption
high advisory

Authenticated Path Traversal in Obsidian Local REST API

An authenticated path traversal vulnerability (GHSA-62gx-5q78-wrvx) in the Obsidian Local REST API's `/vault/{path}` endpoints allows an attacker to bypass path normalization checks using URL-encoded `%2F` sequences, enabling arbitrary file read, write, and delete operations outside the intended vault directory with the privileges of the Obsidian process.

obsidian-local-rest-api path-traversal web-application vulnerability obsidian
1r 4t
low advisory

CVE-2026-62389 - ws Library Memory Exhaustion Vulnerability

A memory exhaustion vulnerability, CVE-2026-62389, exists in the 'ws' WebSocket library versions prior to 8.21.1, allowing attackers to exhaust server memory via incomplete fragmented WebSocket messages and cause denial of service.

ws +1 network denial-of-service vulnerability websocket
1t 1c updated
high advisory

CVE-2026-59255: Missing Authorization in BloodHound Custom Node API

An authenticated attacker can exploit CVE-2026-59255, a missing authorization vulnerability in BloodHound versions through 9.4.0's custom-nodes API endpoints, to modify the global graph schema by creating, updating, or deleting custom node types, affecting all users and tenants.

BloodHound vulnerability authorization api-exploitation
4t 1c
high advisory

Remote Code Execution Vulnerability in PyTorch Lightning via Malicious Checkpoint Files (CVE-2026-58659)

A remote code execution vulnerability, CVE-2026-58659, exists in PyTorch Lightning through version 2.6.5, allowing attackers to craft malicious checkpoint files that execute arbitrary code by exploiting a flaw in the `_load_state` function when `LightningModule.load_from_checkpoint` is called.

PyTorch Lightning remote-code-execution vulnerability python pytorch
1t 1c 1i
high advisory

Unauthenticated Information Disclosure in GPUStack

An unauthenticated information disclosure vulnerability, CVE-2026-58658, in GPUStack through version 2.2.1 allows attackers to access sensitive inference logs containing prompts and completions and modify worker configurations by exploiting unprotected /serveLogs and /debug endpoints.

GPUStack <= 2.2.1 information-disclosure vulnerability web-application
1r 1t 1c
high advisory

Splunk Path Traversal Vulnerability Allows Arbitrary File Writes (CVE-2026-20297)

A path traversal vulnerability (CVE-2026-20297) in Splunk Enterprise and Splunk Cloud Platform allows an authenticated user with `edit_local_apps` and `install_apps` capabilities to write files outside the intended application directory during app installation, specifically into the `$SPLUNK_HOME/etc/` directory and its subdirectories, leading to configuration manipulation, persistence, or privilege escalation.

Splunk Enterprise +1 path-traversal vulnerability splunk rce persistence privilege-escalation
3t 1c
high advisory

Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)

A Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.

Splunk Enterprise < 9.4.13 +14 splunk vulnerability csrf remote-code-execution credential-access data-exfiltration web-vulnerability
4t 3c updated
medium advisory

Unbounded Recursion Depth in Elixir Protobuf Decoder Causes Denial of Service

An unauthenticated attacker can trigger a denial-of-service condition in services that decode untrusted protobuf messages using the `Protobuf.Decoder` (Hex package `protobuf`) versions between 0.8.0 and 0.16.1 by crafting deeply nested self-referential message types, leading to memory exhaustion and service crashes.

protobuf denial-of-service vulnerability elixir
1t
high advisory

Insecure Permission Assignment for Garmin OAuth Token Store

The `garminconnect` Python library versions 0.3.4 and earlier insecurely assigned world-readable file permissions to the `garmin_tokens.json` OAuth token store, allowing local attackers on multi-user systems to steal refresh tokens and gain persistent, unauthorized access to victims' Garmin Connect accounts.

garminconnect insecure-permissions credential-theft local-privilege-escalation vulnerability
4t
high advisory

Koel Authenticated Full-Read SSRF via Subsonic Internet Radio Stations

An authenticated user can exploit a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-54493, in Koel v9.6.0 via the Subsonic-compatible radio endpoints, which lack proper URL validation, allowing the server to fetch and return the body of internal network resources.

Koel ssrf web-application vulnerability subsonic
1r 2t
high threat

KNX Protocol Vulnerability CVE-2023-4346 Allows Device Purging and Lockout

An overly restrictive account lockout mechanism vulnerability, CVE-2023-4346, in KNX Association KNX Protocol Connection Authorization Option 1 could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device, leading to denial of service and data destruction.

exploited KNX Protocol Connection Authorization Option 1 vulnerability protocol-vulnerability ics-scada smart-building denial-of-service
2t 1c
critical advisory

MantisBT SQL Injection via history_order Configuration Value

MantisBT versions 2.28.3 and earlier are vulnerable to a SQL injection within the `history_order` configuration value in `core/history_api.php`, allowing an authenticated administrator to inject malicious SQL via the web UI or REST API, which then executes whenever any user views a bug with history entries, leading to sensitive data extraction and potential Remote Code Execution (RCE) via webshell if the MySQL FILE privilege is enabled.

MantisBT <= 2.28.3 sql-injection web-application vulnerability rce mantisbt xss web-vulnerability credential-phishing
2r 8t
low advisory

CVE-2026-59762: F5 BIG-IP HTTP/2 Profile Denial of Service Vulnerability

A denial-of-service vulnerability (CVE-2026-59762) exists in F5 BIG-IP systems when an HTTP/2 profile is configured on a virtual server, where undisclosed requests can lead to increased memory resource utilization, degrading system performance and potentially causing the TMM process to restart, allowing a remote, unauthenticated attacker to cause a denial-of-service condition affecting the data plane.

BIG-IP system denial-of-service vulnerability f5
1t 1c
medium advisory

NGINX Ingress Controller Injection Vulnerability via CRDs/Annotations (CVE-2026-55723)

An injection vulnerability exists in the NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. An authenticated attacker with write permissions to these CRDs or annotations via the Kubernetes API can craft values to inject arbitrary NGINX configuration directives. This can lead to creating or deleting files and disabling services, affecting the control plane without exposing the data plane.

NGINX Ingress Controller kubernetes vulnerability injection webserver cve
2t 1c
high advisory

CVE-2026-42533 Heap Buffer Overflow in NGINX Map Directive

A heap buffer overflow vulnerability, CVE-2026-42533, exists in NGINX Plus and NGINX Open Source when a 'map' directive uses regex matching and references its capture variables before the map's output variable or uses a non-cacheable variable under certain conditions, allowing an unauthenticated attacker to send crafted HTTP requests causing denial-of-service or remote code execution.

PoC NGINX Plus +9 vulnerability nginx webserver buffer-overflow DoS RCE
3t 2c updated
high advisory

Cornac Tar Slip Vulnerability Allows Arbitrary File Writes via Path Traversal (CVE-2026-43637)

A path traversal vulnerability, dubbed 'Tar Slip' and tracked as CVE-2026-43637, exists in Cornac versions prior to 2.6.0, allowing attackers to write arbitrary files outside the intended cache directory by supplying a specially crafted TAR archive containing path manipulation sequences, which is then processed by built-in dataset loaders.

Cornac < 2.6.0 vulnerability path-traversal tar-slip data-science python
2t 1c
high advisory

Vulnerability in ESET Inspect Connector Allowing Privilege Escalation

A vulnerability, CVE-2026-6423, in ESET Inspect Connector versions prior to 3.1.6017.0 for Windows allows an attacker to achieve privilege escalation on affected systems.

ESET Inspect Connector privilege-escalation vulnerability endpoint-security
high advisory

Vulnerability in Tenable Nessus Agent Allows Remote Code Execution and Security Bypass

A critical vulnerability, CVE-2026-15265, has been discovered in Tenable Nessus Agent versions prior to 11.2.1 and 11.1.4, which allows an attacker to achieve remote code execution and bypass security policies on affected systems, necessitating immediate patching.

Nessus Agent +5 vulnerability remote-code-execution security-bypass
2t 1c updated
medium advisory

Vulnerability in Veeam Backup & Replication Allows Privilege Escalation

A privilege escalation vulnerability has been discovered in Veeam Backup & Replication, affecting versions prior to 12.3.0.65, which allows an attacker to elevate their privileges within the system.

Backup & Replication vulnerability privilege-escalation veeam
1i
high advisory

Multiple Vulnerabilities in Citrix Products

Multiple vulnerabilities have been discovered in various Citrix products, including Endpoint Analysis Client, Secure Access Client, XenCenter SDK client, and XenCenter. These flaws allow an attacker to achieve privilege escalation, compromise data confidentiality, and bypass security policies.

Endpoint Analysis Client +3 vulnerability citrix privilege-escalation data-exfiltration defense-evasion
2c 5i
high threat

Multiple Vulnerabilities in Apache Tomcat

Multiple vulnerabilities, including CVE-2026-59083 and CVE-2026-59084, have been discovered in Apache Tomcat versions 10.1.x prior to 10.1.57, 11.0.x prior to 11.0.24, and 9.0.x prior to 9.0.120, allowing an attacker to bypass security policies and cause an unspecified security issue.

exploited Tomcat 10.1.x +2 vulnerability apache tomcat web-server
1t 2c
high advisory

Vulnerability in Schneider Electric EcoStruxure Allows Security Policy Bypass

A vulnerability, identified as CVE-2026-14354, exists in Schneider Electric EcoStruxure Cybersecurity Admin Expert versions prior to or equal to 4.2.0, allowing an attacker to bypass the product's security policy, potentially leading to unauthorized access or actions.

EcoStruxure Cybersecurity Admin Expert <= 4.2.0 industrial-control-system operational-technology vulnerability defense-evasion
2i
high advisory

CRI-O Environment Variable Injection Vulnerability (CVE-2026-15809)

A critical vulnerability, CVE-2026-15809, in CRI-O allows an attacker with the ability to set container environment variables to bypass a previous fix (CVE-2022-4318), inject a newline character into the HOME environment variable, and add arbitrary lines to /etc/passwd, potentially leading to privilege escalation or persistence within the container.

CRI-O +2 container linux vulnerability privilege-escalation persistence
1r 1t 2c
high advisory

Authentication Bypass in PraisonAI Call API via Host Header Spoofing (CVE-2026-61435)

PraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability in the Call API agent invocation endpoints when PRAISONAI_CALL_AUTH=disabled is configured, allowing an unauthenticated attacker to remotely list and invoke registered agents by sending a spoofed 'Host: 127.0.0.1' HTTP header.

PraisonAI authentication-bypass vulnerability web-application rce-potential
1r 2t 1c
high advisory

PraisonAI web_crawl Tool Vulnerable to DNS Rebinding SSRF (CVE-2026-61430)

PraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) within its web_crawl tool, allowing attackers to bypass hostname validation using DNS rebinding and retrieve sensitive internal HTTP response bodies from private or loopback services.

PraisonAI +1 ssrf dns-rebinding vulnerability web-application code-injection remote-code-execution python cve +4
1r 3t 1c
high advisory

CVE-2026-56400 open-webui Cross-Origin Resource Sharing Misconfiguration Leads to RCE

A cross-origin resource sharing (CORS) misconfiguration in open-webui versions prior to 0.3.14 allows remote attackers to achieve arbitrary code execution by crafting malicious cross-site requests that an authenticated administrator user visits.

open-webui cve vulnerability web-exploitation cors rce
3t 1c
high advisory

Information Disclosure in Capgo Supabase Integration via RPC Function

An information disclosure vulnerability in Capgo (Cap-go/capgo) before version 12.128.2 allows unauthenticated attackers to enumerate organization existence. This flaw resides within the Supabase PostgREST SECURITY DEFINER RPC function 'public.rescind_invitation', which returns distinct error messages (NO_ORG vs. NO_RIGHTS) when called with only a publishable API key. This enables attackers to discover valid organization IDs, increasing the attack surface for targeted phishing or social engineering campaigns.

Cap-go/capgo information-disclosure vulnerability supabase
2t 1c
critical advisory

Wazuh Manager Vulnerability CVE-2026-56699 Allows NDJSON Injection

Wazuh Manager versions prior to 5.0.0-beta3 are critically vulnerable to an injection flaw, CVE-2026-56699 (CWE-74), enabling enrolled agents to inject arbitrary NDJSON operations into OpenSearch bulk requests, leading to data integrity compromise and defense evasion.

Wazuh Manager vulnerability injection SIEM Wazuh
2t 1c
medium advisory

Perl Denial of Service Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Perl to cause a Denial of Service condition.

Perl denial-of-service vulnerability
1t
high advisory

Octopus Deploy: Vulnerability Allows Security Bypass

A remote, authenticated attacker can exploit a vulnerability in Octopus Deploy to bypass security measures, potentially leading to unauthorized access or actions within the affected system.

Octopus Deploy vulnerability security-bypass defense-evasion deployment-automation
1t
medium advisory

Multiple WebKitGTK Vulnerabilities

Multiple vulnerabilities exist in WebKitGTK that can be exploited by a remote, unauthenticated attacker for information disclosure, denial of service, data manipulation, and security mechanism bypass.

WebKitGTK vulnerability denial-of-service information-disclosure defense-evasion
4t
high threat

Multiple Vulnerabilities in Zoom Video Communications Rooms and Workplace

Multiple vulnerabilities have been identified in Zoom Video Communications Rooms and Zoom Video Communications Workplace, which an attacker can exploit to elevate privileges and ultimately take control of a user account.

exploited Zoom Video Communications Rooms +1 vulnerability privilege-escalation account-takeover collaboration
2t
medium advisory

Netty: Multiple Vulnerabilities

An attacker can exploit multiple vulnerabilities within the Netty framework to bypass security checks, manipulate requests or headers, circumvent certificate validations, and cause a denial of service.

Netty vulnerability network denial-of-service
1t
medium advisory

Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service

A vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.

Red Hat Enterprise Linux denial-of-service vulnerability linux red-hat
1t
critical advisory

SonicWall SMA: Multiple Vulnerabilities

Multiple vulnerabilities in SonicWall SMA allow an unauthenticated, remote attacker to bypass security mechanisms and execute arbitrary operating system commands on the affected system, leading to full compromise of the appliance.

SonicWall SMA vulnerability rce sonicwall network-appliance
3t
medium advisory

Citrix Secure Access Client for Windows Vulnerabilities Lead to Privilege Escalation and Information Disclosure

Multiple vulnerabilities in Citrix Systems Secure Access Client for Windows can be exploited by a local attacker to achieve privilege escalation and information disclosure on affected Windows systems.

Secure Access Client for Windows vulnerability privilege-escalation information-disclosure windows
2t
medium advisory

Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution

Multiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.

Studio 5000 Logix Designer ics scada ot rce vulnerability local-exploitation
1t
high advisory

Multiple Vulnerabilities in Fortinet FortiSIEM

Multiple vulnerabilities have been identified in Fortinet FortiSIEM that could allow an attacker to perform Cross-Site Scripting (XSS) attacks or achieve arbitrary code execution, enabling unauthorized script injection into web pages or direct execution of attacker-controlled code within the system.

FortiSIEM fortinet vulnerability xss rce
3t
high threat

MetaGuru HCM SQL Injection Vulnerability (CVE-2026-15804)

A SQL Injection vulnerability (CVE-2026-15804) in MetaGuru's HCM software allows authenticated remote attackers to inject SQL commands via specific parameters, compromising database confidentiality, integrity, and availability.

exploited HCM sql-injection vulnerability cve
2t 1c
medium threat

OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision

A high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.

exploited OpenShift GitOps operator +1 openshift kubernetes gitops denial-of-service vulnerability
1t 1c
high advisory

RabbitMQ Management UI UNC SSRF Vulnerability (CVE-2026-57211) on Windows

CVE-2026-57211 details a Server-Side Request Forgery (SSRF) vulnerability within the RabbitMQ management UI when deployed on Windows, enabling an attacker to coerce the server into making requests to arbitrary UNC paths, potentially leading to NTLM credential disclosure or internal network reconnaissance.

RabbitMQ management UI vulnerability ssrf rabbitmq windows msrc
1c
low advisory

RabbitMQ Topic Authorization Bypass via Cross-Tenant Routing-Key Vulnerability

CVE-2026-57217 details a vulnerability in RabbitMQ where topic authorization can be bypassed, leading to cross-tenant routing-key bypass, potentially allowing unauthorized access to or manipulation of routing keys in a multi-tenant environment.

RabbitMQ vulnerability authorization-bypass
1c
low advisory

RabbitMQ Stream Listener Vulnerability CVE-2026-57220 Allows Unauthenticated Memory Exhaustion DoS

A denial-of-service vulnerability, CVE-2026-57220, exists in the RabbitMQ stream listener that allows an unauthenticated attacker to exhaust memory resources by not properly enforcing frame-size limits during authentication, leading to service disruption.

RabbitMQ Stream listener denial-of-service vulnerability rabbitmq
1t 1c
low advisory

GitHub CLI `gh codespace jupyter` Command Remote Code Execution Vulnerability

A remote code execution vulnerability, CVE-2026-59831, has been identified in the GitHub CLI's `gh codespace jupyter` command, allowing attackers to execute arbitrary code on a user's system when connecting to a specially crafted malicious Codespace.

GitHub CLI +1 remote-code-execution vulnerability github cli codespaces developer-tools
1t 1c
medium advisory

Perl Regex Engine Vulnerability Allows Silently Incorrect Matches

A vulnerability exists in Perl versions up to and including 5.43.9 where regular expression matches can be silently incorrect when an alternation of more than 65535 fixed string branches is compiled into a trie within the Perl_study_chunk function, potentially leading to incorrect logic or data processing.

Perl vulnerability regex software-bug
1c
high advisory

RabbitMQ Unauthenticated OAuth Client Credential Disclosure via HTTP API (CVE-2026-57219)

CVE-2026-57219 describes an unauthenticated disclosure vulnerability in RabbitMQ, allowing an attacker to obtain OAuth client credentials via an HTTP API endpoint when RabbitMQ is configured with certain less common OAuth 2 configurations, potentially leading to unauthorized access to other systems or services.

RabbitMQ vulnerability credential-access broadcom
1t 1c
low advisory

Libarchive Heap Overflow and Out-of-Bounds Read via Pax Extended Header (CVE-2026-15028)

A heap overflow and out-of-bounds read vulnerability (CVE-2026-15028) has been identified in the Libarchive library, triggered by parsing a tar archive with a specially crafted pax extended header, potentially leading to denial of service or arbitrary code execution.

Libarchive vulnerability heap-overflow oob-read rce dos supply-chain
1c
high threat

CVE-2025-44904 HDF5 Heap Buffer Overflow in H5VM_memcpyvv Function

CVE-2025-44904 describes a heap buffer overflow vulnerability in HDF5 version 1.14.6 that occurs via the H5VM_memcpyvv function, which could lead to potential security risks such as denial of service or arbitrary code execution.

exploited hdf5 vulnerability heap-buffer-overflow code-execution
1c
medium advisory

Multiple Vulnerabilities in Python Lead to Denial of Service

Remote and unauthenticated attackers can exploit multiple unspecified vulnerabilities within Python to conduct Denial of Service attacks, potentially disrupting the availability of services or applications running on the language.

Python denial-of-service vulnerability
1t
high advisory

Red Hat Enterprise Linux Plexus-Utils Vulnerability Allows Remote Code Execution

A remote, unauthenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within the plexus-utils component, to execute arbitrary program code with user privileges, leading to system compromise.

Red Hat Enterprise Linux +2 linux vulnerability rce remote-code-execution
1t
high advisory

Zhinianboke Xianyu-Auto-Reply Missing Authorization Vulnerability (CVE-2026-15752)

A missing authorization vulnerability (CVE-2026-15752) exists in the /api/v1/users/ endpoint of zhinianboke xianyu-auto-reply, affecting versions up to commit dcb445ad97816ad65299a7580ee0c8c8f929da84, allowing a remote attacker to bypass authentication or authorization checks. An exploit for this vulnerability has been made public, and organizations using this product should apply the patch named 19fc3282a1bb78a05c34945c088525d20e081cbd to mitigate the risk.

xianyu-auto-reply vulnerability authorization-bypass cve web-vulnerability network
1t 1c
high advisory

Adobe Premiere Pro Out-of-Bounds Write Vulnerability (CVE-2026-48369)

An out-of-bounds write vulnerability (CVE-2026-48369) in Adobe Premiere Pro, requiring user interaction to open a malicious file, can lead to arbitrary code execution in the context of the current user.

Premiere Pro +1 vulnerability rce adobe premiere-pro client-side-exploitation
3t 1c
high threat

Adobe Bridge Integer Overflow Vulnerability (CVE-2026-48342) Leads to Arbitrary Code Execution

CVE-2026-48342 is an Integer Overflow or Wraparound vulnerability in Adobe Bridge that could enable an attacker to achieve arbitrary code execution on a victim's system if the victim opens a specially crafted malicious file, affecting versions up to 16.0.3 and 15.1.5.

exploited Adobe Bridge +1 vulnerability integer-overflow code-execution adobe
3t 1c
high advisory

Adobe Creative Cloud Desktop Vulnerability Allows Arbitrary Code Execution via Uncontrolled Search Path

An Uncontrolled Search Path Element vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop versions up to 6.9.1.1 could allow arbitrary code execution in the context of the current user, requiring no user interaction but dependent on conditions beyond the attacker's full control.

Creative Cloud Desktop arbitrary-code-execution vulnerability adobe windows macos
1t 1c
high advisory

Adobe Media Encoder Stack-based Buffer Overflow Vulnerability (CVE-2026-47971)

A critical stack-based buffer overflow vulnerability, CVE-2026-47971, in Adobe Media Encoder versions prior to 26.3 and 25.6.6 could lead to arbitrary code execution within the context of the current user when a victim opens a specially crafted malicious file.

Adobe Media Encoder +1 vulnerability buffer-overflow adobe media-encoder client-side
2t 1c
medium threat

Denial-of-Service Vulnerability in Pillow EPS Parser (CVE-2026-59203)

A denial-of-service vulnerability, CVE-2026-59203, exists in the Python imaging library Pillow, affecting versions 12.0.0 through 12.2.0, where a specially crafted EPS file with a negative byte count in the `%%BeginBinary` directive can cause an infinite loop and resource exhaustion when processed by the `Image.open()` function, leading to application unresponsiveness.

exploited Pillow 12.0.0 +2 denial-of-service vulnerability python pillow
1t 1c
high advisory

Pillow TGA RLE Encoder Out-of-Bounds Read (CVE-2026-59198)

A critical out-of-bounds read vulnerability, CVE-2026-59198, exists in Pillow versions 5.2.0 through 12.2.x, specifically within its TGA RLE encoder, allowing adjacent process heap bytes to be copied into generated TGA files, which can lead to information disclosure.

Pillow vulnerability out-of-bounds-read python
1t 1c
critical advisory

Critical Vulnerability in Podlove Podcast Publisher Plugin Allows Unauthenticated File Uploads Leading to RCE

A critical vulnerability, CVE-2026-13001, in the Podlove Podcast Publisher plugin for WordPress, impacting versions up to and including 4.5.1, allows unauthenticated attackers to upload arbitrary files due to missing file type validation, potentially leading to remote code execution on the server.

PoC Podlove Podcast Publisher <= 4.5.1 wordpress plugin vulnerability file-upload rce
1r 3t 1c 4i updated
high advisory

Anyquery Server-Side Request Forgery via Unrestricted SQLite Virtual Table Modules

Unauthenticated attackers can exploit a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-54628) in Anyquery's `server` mode (versions prior to 0.4.5) by creating SQLite virtual tables that fetch internal network resources or cloud metadata, leading to internal network mapping and exfiltration of sensitive information like cloud credentials.

Anyquery ssrf vulnerability local-file-read linux data-exfiltration
3r 4t
medium advisory

Netty StompSubframeDecoder Denial of Service Vulnerability (CVE-2026-44891)

A high-severity denial of service vulnerability, identified as CVE-2026-44891, exists in the `StompSubframeDecoder` component of Netty's `netty-codec-stomp` library, allowing an unauthenticated attacker to exhaust server memory and cause an `OutOfMemoryError` by sending a STOMP message with an excessive number of headers, leading to application crashes.

netty-codec-stomp +1 denial-of-service vulnerability netty java application-layer
1t
high advisory

Nebula-Mesh Stores Operator Session Tokens in Plaintext, Enabling Session Hijacking (CVE-2026-53603)

Operator session tokens in ForgeKeep's nebula-mesh application are stored in plaintext within the database, allowing an attacker who gains read access to the database to retrieve active session tokens and hijack operator sessions, bypassing further authentication.

nebula-mesh vulnerability session-hijacking database plaintext credential-exposure
1t
high advisory

Woodpecker Privilege Escalation via Unrestricted Kubernetes serviceAccountName

A high-severity privilege escalation vulnerability (CVE-2026-61549) in Woodpecker CI, specifically affecting instances using the Kubernetes backend, allows any user with Push permissions on a connected repository to run pipeline pods under an arbitrary ServiceAccount, potentially leading to secret exfiltration and full cluster takeover.

Woodpecker CI privilege-escalation kubernetes ci/cd vulnerability
2t
low advisory

Pillow Python Imaging Library Vulnerable to Out-of-Memory via Crafted JPEG2000

A denial-of-service vulnerability, CVE-2026-59204, exists in the Pillow Python imaging library versions 8.2.0 through 12.2.0, allowing a remote attacker to trigger an out-of-memory error and crash applications by processing a specially crafted tiled JPEG2000 image.

Pillow vulnerability denial-of-service python imaging-library
1t 1c
high advisory

EasyAdmin Bundle Stored Cross-Site Scripting via File Uploads (CVE-2026-54087)

A high-severity stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-54087, exists in EasyAdmin Bundle versions >= 5.0.0 and < 5.0.13, allowing attackers to upload malicious HTML or SVG files containing JavaScript which executes in an administrator's session when viewed in the backend, leading to session/CSRF token theft and privilege escalation.

EasyAdmin Bundle xss web-application vulnerability easyadmin
1t
low advisory

Trivy Unbounded Read Leads to Denial of Service via Helm Chart Tar Bomb

Trivy versions prior to 0.71.0 are vulnerable to CVE-2026-54448, a denial-of-service attack where a crafted Helm chart archive (.tgz) can cause unbounded memory consumption, leading to the OS OOM killer terminating the Trivy process and other services on the host or CI runner.

Trivy supply-chain vulnerability denial-of-service ci-cd
1t 1c
critical advisory

TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import

A critical remote code execution (RCE) vulnerability exists in TidGi Desktop through version 0.13.0, allowing attackers to execute arbitrary code with full Node.js access by tricking victims into importing a specially crafted TiddlyWiki Git repository, leveraging the automatic execution of 'startup' modules during the wiki boot sequence.

TidGi Desktop 0.13.0 rce vulnerability initial-access execution windows macos linux
1r 3t 4i
critical advisory

Critical Remote Code Execution in Totolink NR1800X Routers (CVE-2026-15701)

A critical stack-based buffer overflow vulnerability, CVE-2026-15701 (CVSS 9.8), in Totolink NR1800X firmware version 9.1.0u.6279_B20210910 allows remote attackers to execute arbitrary code by manipulating the 'Host' argument in the 'Form_Logout' function, with a public exploit available.

NR1800X 9.1.0u.6279_B20210910 buffer-overflow remote-code-execution firmware router vulnerability
2t 1c 5i
medium advisory

Ivanti Xtraction Vulnerabilities CVE-2026-14902 and CVE-2026-14903

Ivanti has published a security advisory (AV26-696) on July 14, 2026, to address two vulnerabilities, CVE-2026-14902 and CVE-2026-14903, affecting Ivanti Xtraction version 2026.2 and prior, urging users to apply necessary updates to mitigate potential risks.

Ivanti Xtraction vulnerability Ivanti security-advisory
2c
high threat

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.

exploited PoC SMA1000 Appliances +6 ssrf vulnerability cisa-kev remote-code-execution network-appliance
2t 2c 6i updated
high advisory

OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection Vulnerability

OpenCost contains an unauthenticated file write vulnerability, tracked as GHSA-wmj8-9953-vff5, in its `/serviceKey` endpoint that allows remote attackers to overwrite the GCP service account key file (`key.json`) without any authentication or input validation, leading to service disruption, credential theft, and potential privilege escalation within Kubernetes clusters or GCP environments.

OpenCost: All versions opencost kubernetes cloud gcp vulnerability unauthenticated-access file-write
1r 4t 2i
high advisory

Fedify SSRF Mitigation Bypass via Incomplete IPv4 Validation (CVE-2026-50131)

Fedify's `validatePublicUrl()` function, intended to mitigate Server-Side Request Forgery (SSRF), contains an incomplete IPv4 validation logic. It incorrectly treats several special-use, reserved, multicast, benchmarking, and carrier-grade NAT IPv4 ranges as valid public destinations, allowing an attacker to bypass the SSRF protection and cause the Fedify server to initiate requests to internal or non-public network ranges when processing attacker-controlled ActivityPub object, activity, document, or media URLs.

@fedify/fedify +7 ssrf incomplete-fix bypass network-access vulnerability fedify npm
1r 2t 1c
high advisory

Woodpecker CI gRPC Vulnerability Allows Cross-Tenant Agent Impersonation (CVE-2026-50141)

A high-severity vulnerability (CVE-2026-50141) in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` into gRPC metadata, leading to potential privilege escalation and unauthorized access within CI/CD pipelines.

Woodpecker CI v3 privilege-escalation vulnerability grpc ci-cd
1t 1c
critical advisory

Anyquery Arbitrary File Write (AFW) Leads to Remote Code Execution (RCE)

Anyquery in server mode is vulnerable to arbitrary file write (AFW) due to its failure to restrict native SQLite disk manipulation commands like `ATTACH DATABASE`. Unauthenticated attackers can connect to the MySQL-compatible server port and write arbitrary files (e.g., PHP webshells, malicious cronjobs) to any path writable by the Anyquery process, which can lead to remote code execution (RCE) with the privileges of the Anyquery process, significantly impacting system integrity and availability.

Anyquery arbitrary-file-write rce sqlite server-mode vulnerability
3r 4t
critical advisory

n8n-mcp Cross-Tenant Workflow Version Access Vulnerability

A critical cross-tenant access vulnerability exists in n8n-mcp versions up to 2.56.0, specifically in multi-tenant HTTP deployments. An authenticated tenant can read, delete, or destroy workflow version backups belonging to other tenants due to insufficient isolation of locally stored version history. This exposure includes sensitive data such as credential references and authorization headers embedded in node definitions, posing both a confidentiality and integrity/availability risk.

n8n-mcp <= 2.56.0 vulnerability cross-tenant n8n
2t
medium advisory

GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

A vulnerability, identified as CVE-2026-47282, in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose sensitive information over a network due to insufficiently protected credentials.

GitHub Copilot +1 information-disclosure vulnerability development-tools
low advisory

Vulnerability in ABB Advant Master Online Builder Allows Code Execution

A vulnerability (CVE-2025-13162) exists in ABB Advant Master Online Builder products, including Control Builder A and 800xA for Advant Master, enabling an attacker with necessary local access to execute unauthorized code by exploiting an uncontrolled search path element (CWE-427) to load malicious DLLs, compromising system integrity within critical manufacturing environments.

Control Builder A <= 1.4/4 +6 ics vulnerability dll-hijacking cwe-427
1t 1c
medium advisory

Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)

A critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.

1715-AENTR EtherNet/IP Adapter <=3.003 ics ot vulnerability critical-infrastructure remote-code-execution
1t 1c
critical advisory

Multiple Critical and High-Severity Vulnerabilities in ABB T-MAC Plus

CISA has issued an advisory regarding critical and high-severity vulnerabilities CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, and CVE-2025-14774 in ABB T-MAC Plus version 4.0-24, which could allow authenticated attackers to exfiltrate sensitive files, bypass authorization for administrative operations, execute arbitrary client-side code via cross-site scripting, or for unauthenticated attackers to cause a denial-of-service condition.

ABB T-MAC Plus 4.0-24 industrial-control-systems scada critical-manufacturing vulnerability web-application
4t 4c
high threat

ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)

ServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.

exploited Brazil +18 vulnerability servicenow cloud
3c updated
high advisory

CVE-2026-15692: Tenda BE12 Pro Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability, identified as CVE-2026-15692, exists in Tenda BE12 Pro firmware version 16.03.66.23's `fromSafeUrlFilter` function, allowing remote attackers to achieve arbitrary code execution by manipulating the 'page' argument via a crafted HTTP request, with a public exploit available.

BE12 Pro vulnerability buffer-overflow rce firmware router network-device
1r 2t 1c 6i
high advisory

Tenda BE12 Pro Remote Code Execution Vulnerability (CVE-2026-15691)

A critical remote stack-based buffer overflow vulnerability (CVE-2026-15691) has been discovered in Tenda BE12 Pro firmware 16.03.66.23, affecting the `fromSafeClientFilter` function and allowing remote attackers to achieve arbitrary code execution by manipulating the `page` argument, with a public exploit available.

BE12 Pro 16.03.66.23 vulnerability remote-code-execution buffer-overflow firmware router network-device rce
2t 5c 8i
medium threat

OpenSSH Vulnerability Allows Privilege Escalation

A local attacker can exploit an unspecified vulnerability in OpenSSH to elevate their privileges on the affected system.

exploited OpenSSH privilege-escalation vulnerability
1t
high advisory

Remote Code Execution Vulnerability in ServiceNow AI Platform

A remote, anonymous attacker can exploit a vulnerability in ServiceNow AI Platform to execute arbitrary program code, leading to unauthorized control over the platform's underlying systems.

ServiceNow AI Platform vulnerability rce cloud-security
2t
high advisory

Unauthenticated Remote Code Execution in Argo CD Repo-Server (CVE-2026-15416)

An unauthenticated remote code execution vulnerability (CVE-2026-15416) exists in Argo CD's repo-server, the GitOps engine used by Red Hat OpenShift GitOps, allowing an attacker with network access to achieve RCE and deploy malicious Kubernetes resources, leading to potential cluster compromise.

Argo CD +3 kubernetes gitops rce cloud vulnerability cve
3t 1c
medium advisory

Ollama: Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit an unspecified vulnerability in Ollama to execute a Denial of Service (DoS) attack, disrupting service availability.

Ollama denial-of-service vulnerability
1t
high advisory

QEMU Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in QEMU to elevate their privileges and execute arbitrary code on the host system where QEMU is running.

QEMU privilege-escalation virtualization vulnerability
2t
high advisory

Remote SQL Injection in code-projects Online Job Portal (CVE-2026-15675)

A SQL injection vulnerability (CVE-2026-15675) has been identified in code-projects Online Job Portal version 1.0, located in the `/Admin/EditUser.php` file and triggered by manipulating the `UserId` argument, allowing for remote SQL injection attacks with publicly available exploit code.

Online Job Portal 1.0 sql-injection web-application cve vulnerability rce unrestricted-upload
2r 5t 1c
high advisory

Unauthenticated Arbitrary Code Execution in SAProuter via DLL Hijacking (CVE-2026-0487)

An unauthenticated attacker can exploit CVE-2026-0487, a vulnerability in SAProuter running on Microsoft Windows, by loading malicious DLL files from an untrusted location, allowing them to execute arbitrary code on the affected system with high impact on confidentiality, integrity, and availability.

SAProuter +12 dll-hijacking code-execution vulnerability cve
1r 1t 1c 2i
medium advisory

SAP Approuter HTTP Request Smuggling Vulnerability Allows Confidentiality and Availability Impact (CVE-2026-27690)

An HTTP Request Smuggling vulnerability (CVE-2026-27690, CWE-444) in SAP Approuter allows an unauthenticated attacker to send a specially crafted HTTP request leading to request-response desynchronization, which can result in the exposure of user responses and cause a denial of service by making the system unavailable.

SAP Approuter node.js package http-request-smuggling vulnerability sap web-application denial-of-service data-exposure
3t 1c
high advisory

Kimai REST API Two-Factor Authentication Bypass Vulnerability

A critical vulnerability, CVE-2026-52827, in Kimai versions prior to 2.59.0 allows an attacker who has compromised a user's password to bypass Two-Factor Authentication (TOTP) for the REST API by intercepting and replaying the `KIMAI_SESSION` cookie obtained after password verification but before TOTP completion, granting full authenticated API access.

Kimai api 2fa-bypass vulnerability web-application
2t
critical advisory

Kimai Docker Image Default APP_SECRET Allows Account Takeover (CVE-2026-52824)

A critical vulnerability, CVE-2026-52824, in the official Kimai Docker image allows unauthenticated attackers to forge authentication tokens and achieve account takeover, including super_admin accounts, due to the image shipping with a default, publicly known APP_SECRET environment variable used by Symfony to HMAC-sign session cookies and login links.

Kimai +1 vulnerability web-application misconfiguration account-takeover docker
3t
high advisory

Cockpit CMS Missing Authorization Vulnerability in Bucket File Storage API (CVE-2026-57855)

A missing authorization vulnerability, CVE-2026-57855, in the Cockpit CMS Bucket file storage API allows any authenticated user, regardless of their assigned role, to perform all file operations on any named bucket, including those designated for administrative use, potentially leading to privilege escalation, data manipulation, or data destruction.

Cockpit CMS < 2.14.0 vulnerability web-application cms authorization-bypass privilege-escalation
4t 1c
high advisory

CrewAI Server-Side Request Forgery Vulnerability (CVE-2026-62240)

A critical server-side request forgery (SSRF) vulnerability, CVE-2026-62240, exists in the `validate_url` function of CrewAI versions prior to 1.15.1, allowing attackers to bypass security filters using URL redirects or DNS rebinding to access internal services and cloud metadata endpoints.

CrewAI ssrf vulnerability python web-application cloud
1r 3t 1c
critical advisory

CVE-2026-59801: 9Router Unauthenticated API Access Vulnerability

A critical unauthenticated access vulnerability, CVE-2026-59801, in 9Router versions up to 0.4.41 allows remote attackers to bypass authentication on provider management API endpoints, enabling them to enumerate, create, modify, or delete connections, leading to credential exposure, AI traffic redirection, or complete denial of service.

9Router vulnerability unauthenticated-access api-exploitation denial-of-service credential-theft
1r 3t 1c
high advisory

9Router Unauthenticated Information Disclosure (CVE-2026-62328)

An unauthenticated information disclosure vulnerability in 9Router through version 0.4.41 allows remote attackers to access sensitive user data by querying unprotected API endpoints like `/request-logs` and `/request-details` to enumerate paginated request logs and retrieve complete AI conversation histories, including system prompts, user messages, assistant responses, tool calls, and user email addresses, due to a lack of authentication middleware.

9Router information-disclosure vulnerability web-application
2r 2t 1c
high advisory

Spring Boot Admin Server SSRF Vulnerability (CVE-2026-62242)

An unauthenticated attacker can exploit CVE-2026-62242, a server-side request forgery vulnerability in Spring Boot Admin Server before 4.1.2, to force the server to make requests to arbitrary internal addresses and exfiltrate sensitive data, including cloud credentials.

Spring Boot Admin Server ssrf server-side-request-forgery spring-boot-admin vulnerability cloud-security
5t 1c
high advisory

OpenClaw Git Ext Transport Vulnerability Allows Unauthorized Code Execution (CVE-2026-62200)

A critical vulnerability, CVE-2026-62200, in OpenClaw versions before 2026.6.1 allows a lower-trust caller to execute or persist unauthorized actions via the Git ext transport feature, potentially leading to remote code execution due to improper host exec environment filtering.

OpenClaw vulnerability rce git
2t 1c
high advisory

OpenClaw Environment Filtering Bypass Vulnerability (CVE-2026-62199)

A critical vulnerability, CVE-2026-62199, in OpenClaw versions prior to 2026.6.6 allows a lower-trust caller to bypass host execution environment filtering by supplying crafted interpreter startup variables, leading to unauthorized code execution and persistence.

OpenClaw vulnerability rce persistence
2t 1c
high advisory

OpenClaw Policy Bypass Vulnerability in Browser CDP Discovery

OpenClaw before version 2026.6.6 contains a policy bypass vulnerability in its browser CDP discovery feature that allows attackers with lower-trust access to circumvent network blocking policies by accepting WebSocket URLs that should have been blocked, enabling them to reach otherwise restricted network destinations when the affected feature is enabled.

OpenClaw < 2026.6.6 vulnerability policy-bypass ssrf
1c
high advisory

OpenClaw Symlink Following Vulnerability (CVE-2026-62189)

A symlink following vulnerability, identified as CVE-2026-62189, in OpenClaw versions prior to 2026.6.9's mirror sync feature allows attackers with low privileges to bypass authorization boundaries by exploiting remote symlink parents, enabling unauthorized actions requiring stronger permissions.

OpenClaw vulnerability symlink-following privilege-escalation authorization-bypass cve
5t 4c 8i
high advisory

OpenClaw Feishu Tools Authorization Bypass Vulnerability (CVE-2026-62187)

OpenClaw Feishu tools (npm package @openclaw/feishu) versions up to and including 2026.6.6 contain CVE-2026-62187, an authorization bypass vulnerability that allows lower-trust callers to perform unauthorized operations by ignoring per-account disablement or policy checks, leading to potential data manipulation or information disclosure.

@openclaw/feishu <= 2026.6.6 authorization-bypass npm-package software-supply-chain vulnerability cve
1t 1c
low advisory

CVE-2026-62184 - luci-app-banip Log Parsing Vulnerability

A log parsing vulnerability in OpenWrt's luci-app-banip allows an unauthenticated remote attacker to inject arbitrary IPv4 addresses into log lines via crafted input fields, leading to the misidentification and blocking of legitimate users or services while the true attacker remains unblocked.

luci-app-banip vulnerability log-parsing ip-spoofing openwrt
1c
high advisory

CVE-2026-61458 Brute-Force Vulnerability in PasswordPusher

A brute-force vulnerability, tracked as CVE-2026-61458, exists in PasswordPusher versions prior to 2.9.2, allowing attackers with a known push token to systematically guess passphrases at high rates due to a lack of route-specific rate limiting and per-push lockout mechanisms on the POST /p/:token/access endpoint, potentially leading to the recovery of sensitive secrets within hours or days.

PasswordPusher before 2.9.2 vulnerability brute-force web-application credential-access
1r 1t 1c
critical advisory

9Router Unauthenticated API Key Disclosure Vulnerability

An unauthenticated information disclosure vulnerability, CVE-2026-62327, in 9Router through version 0.4.41 allows remote attackers to retrieve plaintext AI provider API keys via a missing authentication middleware on the Next.js API route accessible at /api/usage/stats, enabling unauthorized access to sensitive data, potential billing fraud, and quota exhaustion.

9Router <= 0.4.41 information-disclosure vulnerability web-application cve
1r 2t 1c
high advisory

Server-Side Request Forgery in Laravel-Mediable Allows Credential Exfiltration

A Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-49969, exists in Laravel-Mediable versions prior to 7.0.0, allowing remote attackers to force the server to make arbitrary HTTP requests to attacker-controlled URLs provided to `MediaUploader::fromSource()` to target internal network resources, access sensitive files, and exfiltrate cloud credentials like IAM tokens.

Laravel-Mediable ssrf vulnerability web-application credential-access data-exfiltration
4r 4t 1c
critical advisory

DIRAC Vulnerable to Remote Code Execution via SQL Injection and Eval in DatasetManager

An authenticated user can achieve remote code execution in DIRAC's FileCatalog DatasetManager due to an SQL injection vulnerability (CVE-2026-61667) that allows manipulation of query results passed to an `eval` function, leading to full system compromise.

DIRAC remote-code-execution sql-injection python web-application vulnerability cve-2026-61667
6t
high advisory

Apollo ConfigService Authentication Bypass via Raw Config File AppId Parsing

An authentication bypass vulnerability (CVE-2026-59955) in Apollo ConfigService allows unauthenticated remote attackers to read raw configuration data by exploiting an incorrect appId parsing logic for the raw config file endpoint, affecting versions prior to 2.5.2.

Apollo ConfigService authentication-bypass data-exposure vulnerability cloud
2t
high threat

Shiori Privilege Escalation via Account Update Endpoint (CVE-2026-61463)

Shiori contains a privilege escalation vulnerability in its account update endpoint that allows authenticated users to exploit this by sending a crafted PATCH request to modify the 'owner' field to 'true' without proper authorization checks, leading to administrative access and full system control.

exploited Shiori privilege-escalation vulnerability web-application
1t 1c 4i
critical advisory

DIRAC Vulnerable to Remote Code Execution via eval on Untrusted Input in RequestManager

A critical remote code execution vulnerability (CVE-2026-45579) in DIRAC's RequestManager allows any authenticated user to execute arbitrary commands or code on the DIRAC server due to the improper use of `eval()` on untrusted input, leading to full system compromise including data exfiltration and log manipulation.

DIRAC +2 RCE python web-application vulnerability sql-injection access-control
2r 6t
medium advisory

Decidim JWT Replay Vulnerability Allows Cross-Organization Data Access

A vulnerability, CVE-2026-45414, in Decidim allows an attacker to replay a JSON Web Token (JWT) issued for one organization against another organization's API, permitting an authenticated user from Org 1 to access and retrieve sensitive data, such as GraphQL `participantDetails` and `proposal.answer` mutation paths, from Org 2, effectively bypassing cross-organizational access controls.

Decidim +1 jwt-misconfiguration access-control web-application vulnerability
2t
high advisory

CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool

A privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.

OpenShift +1 privilege-escalation vulnerability red-hat kubernetes cloud-native
1t 1c
high advisory

Multiple Vulnerabilities in Netwrix Password Secure

Multiple vulnerabilities in Netwrix Password Secure allow a remote, authenticated attacker to execute arbitrary program code and disclose sensitive information, potentially leading to full system compromise and data exfiltration.

Password Secure vulnerability rce information-disclosure netwrix
2t
medium threat

Checkmk: Multiple Vulnerabilities

Multiple vulnerabilities in Checkmk allow an attacker to escalate privileges and bypass security measures, potentially leading to unauthorized access and control within the affected system.

exploited Checkmk vulnerability privilege-escalation defense-evasion
2t
medium advisory

libTIFF Vulnerability Enables Arbitrary Code Execution and Denial of Service

A local attacker can exploit a vulnerability in libTIFF to execute arbitrary code and perform a denial of service attack against the system where the library is used.

libTIFF vulnerability code-execution denial-of-service
1t
high advisory

CVE-2026-15557: Improper Authentication Vulnerability in waooAI waoowaoo

A high-severity improper authentication vulnerability, CVE-2026-15557, exists in waooAI waoowaoo up to version 0.4.1, allowing remote attackers to bypass authentication and gain unauthorized access by manipulating the 'x-internal-user-id' request argument in the Internal Task Header Handler component, with a public exploit available.

waoowaoo <= 0.4.1 vulnerability authentication-bypass web-application cve
1r 2t 1c
medium advisory

Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS

Attackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.

Grafana vulnerability web DoS XSS
2t
high threat

Multiple Vulnerabilities in JetBrains TeamCity

Multiple vulnerabilities in JetBrains TeamCity could allow an attacker to execute arbitrary code, manipulate data, or perform Cross-Site Scripting (XSS) attacks, potentially leading to system compromise or client-side attacks.

exploited TeamCity vulnerability code-execution cross-site-scripting data-manipulation jetbrains
2t
low advisory

Contao Information Disclosure Vulnerability

An authenticated remote attacker can exploit a vulnerability in Contao to disclose sensitive information, gaining unauthorized access to data within the system.

Contao information-disclosure cms vulnerability web-application
1t
high threat

JetBrains IntelliJ IDEA Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit an unspecified vulnerability in JetBrains IntelliJ IDEA to achieve arbitrary code execution, enabling them to execute arbitrary program code on the affected system.

IntelliJ IDEA Anonymous Attacker remote-code-execution vulnerability development-tools windows linux macos
2t
medium advisory

Linux Kernel Vulnerability (xfrm: iptfs) Allows Local DoS and Data Manipulation

A local attacker can exploit a vulnerability in the Linux Kernel's xfrm: iptfs component to potentially trigger a denial-of-service condition or manipulate data on affected systems.

Linux Kernel linux-kernel vulnerability dos data-manipulation kernel
2t
high advisory

Shibby Tomato Firmware Vulnerability CVE-2026-15545 Leads to Remote Out-of-Bounds Write

A critical out-of-bounds write vulnerability (CVE-2026-15545) exists in Shibby Tomato firmware up to version 1.28.0000, specifically within the `main` function of the `www/apcupsd/tomatodata.cgi` file in the `apcupsd` component, which can be exploited remotely with a publicly available exploit, posing a significant risk to affected network devices.

Tomato vulnerability firmware router out-of-bounds-write CVE
2t 1c
medium advisory

Wget Vulnerability Allows Security Bypass and Server-Side Request Forgery

A local attacker can exploit a vulnerability in wget to bypass existing security measures and perform a Server-Side Request Forgery (SSRF) attack, enabling requests to internal or restricted resources from the local system.

wget ssrf vulnerability local-privilege-escalation linux macos windows defense-evasion
1t
high advisory

GraphicsMagick PCD Decoder Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in the GraphicsMagick PCD decoder to potentially execute arbitrary code, corrupt memory, or cause a denial-of-service condition. This flaw could lead to compromise of the system running the affected software or disruption of its availability.

GraphicsMagick vulnerability rce image-processing denial-of-service
2t
critical advisory

Critical Buffer Overflow in Tenda CH22 Leads to Remote Code Execution (CVE-2026-15543)

A critical buffer overflow vulnerability, CVE-2026-15543, exists in the Tenda CH22 1.0.0.1 firmware's `formCertListInfo` function, allowing unauthenticated remote attackers to achieve arbitrary code execution by manipulating the 'Name' argument, with a public exploit available.

CH22 1.0.0.1 cve vulnerability buffer-overflow remote-code-execution network-device
1t 1c
high advisory

CVE-2026-15541: Missing Authorization in will-moss Isaiah Master Websocket Handler

A critical missing authorization vulnerability (CVE-2026-15541) exists in the `Server.Handle` function of the `Master Websocket Handler` component within `will-moss Isaiah` versions up to 1.36.9, allowing a remote attacker to bypass authorization controls by manipulating the `Agent` argument, potentially leading to unauthorized access or privilege escalation.

Isaiah vulnerability authorization-bypass remote-code-execution
2t 1c
high advisory

Public Exploit for Linux Kernel Use-After-Free Vulnerability CVE-2026-43499

A public exploit has been published for CVE-2026-43499, a Use-After-Free vulnerability in the Linux Kernel, demonstrated to achieve KASLR bypass and potential privilege escalation on Android 15 devices running Linux Kernel 5.15.149, significantly elevating risk for unpatched systems.

PoC Linux Kernel 5.15.149 +5 linux kernel vulnerability use-after-free privilege-escalation android
1t 2c 6i updated
medium advisory

Multiple Vulnerabilities in SaltStack Salt

Multiple vulnerabilities in SaltStack Salt allow an attacker to execute arbitrary program code on affected systems and bypass security measures, potentially leading to unauthorized access and control over managed infrastructure.

Salt saltstack vulnerability rce security-bypass
2t
medium threat

Django, Debian, and Ubuntu Vulnerability Allows Remote Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in Django, Debian Linux, and Ubuntu Linux to initiate a Denial of Service attack, potentially disrupting services and making them unavailable to legitimate users.

exploited Django +2 denial-of-service vulnerability linux web-application
1t
medium advisory

CPython Vulnerability Enables Remote Denial of Service

A remote, unauthenticated attacker can exploit an unspecified vulnerability within CPython to launch a Denial of Service attack, affecting the CPython interpreter across various operating systems.

CPython denial-of-service vulnerability
1t
high advisory

CVE-2026-9492 - Improper Access Control in Gigabyte Control Center MBStorage Module

An Improper Access Control vulnerability (CVE-2026-9492) in the MBStorage DRAM lighting control module of Gigabyte Control Center (GCC) allows authenticated local attackers to achieve kernel-level privileges by sending specific IOCTL commands to the `MyPortIO_x64.sys` driver, enabling arbitrary physical memory read/write.

Gigabyte Control Center +1 privilege-escalation vulnerability windows driver-vulnerability local-privilege-escalation
1t 1c
high threat

Remote SQL Injection Vulnerability in Jinher OA 1.0 (CVE-2026-15517)

A remote SQL injection vulnerability, CVE-2026-15517, has been discovered in Jinher OA 1.0, allowing unauthenticated attackers to execute arbitrary SQL commands by manipulating the `httpOID` argument in the `/C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx` file, with a public exploit available.

exploited OA 1.0 sql-injection web-application vulnerability cve remote-code-execution
1r 2t 1c 5i
high advisory

Tencent PC Manager QMUDisk Driver Uncontrolled Search Path Vulnerability (CVE-2026-15515)

A high-severity uncontrolled search path vulnerability (CVE-2026-15515) in the `qmudisk64.sys` component of Tencent PC Manager 18.1.30242.301 allows a local attacker to execute arbitrary code with elevated privileges, despite high complexity and difficult exploitability, due to public exploit disclosure.

Tencent PC Manager cve vulnerability privilege-escalation windows
1c
critical advisory

Comfast Router CVE-2026-15511: Remote OS Command Injection

A critical remote OS command injection vulnerability, CVE-2026-15511, affects Comfast CF-WR631AX V3 WiFi routers, allowing unauthenticated remote attackers to execute arbitrary operating system commands by manipulating the 'filename' argument in the FastCGI Backend's file upload function, leading to full device compromise.

CF-WR631AX V3 vulnerability command-injection rce firmware router fastcgi
1r 2t 1c
high advisory

CVE-2026-15506: SecureAge CatchPulse Local Privilege Escalation via Heap-based Buffer Overflow

A heap-based buffer overflow vulnerability, CVE-2026-15506, in the `saappctl.sys` driver of SecureAge CatchPulse versions up to 10.9.3 allows a local attacker to achieve privilege escalation, and an exploit has been publicly disclosed.

CatchPulse up to 10.9.3 vulnerability privilege-escalation driver-vulnerability heap-overflow local-access
1t 1c
high advisory

Capgo Email Change Vulnerability Bypasses Authentication (CVE-2026-56308)

A vulnerability (CVE-2026-56308) in Capgo before version 12.128.2 allows an attacker with an authenticated session to change a user's email address without re-authentication or verification of the existing email, leading to account takeover through recovery mechanisms and multi-factor authentication bypass.

Capgo vulnerability authentication-bypass account-takeover web-application
2t 1c 2i
high advisory

Crawl4AI Credential Exfiltration and Authentication Bypass Vulnerabilities

A critical vulnerability, CVE-2026-56259, in Crawl4AI versions prior to 0.8.8 allows attackers to exploit unauthenticated Docker API server endpoints by manipulating the `base_url` and `api_token` parameters, leading to credential exfiltration and authentication bypass.

Crawl4AI before 0.8.8 vulnerability credential-access defense-evasion exfiltration cloud
1r 4t 1c
high advisory

Capgo Privilege Escalation via Retained Super_Admin Privileges (CVE-2026-56241)

A privilege escalation vulnerability, CVE-2026-56241, in Capgo versions prior to 12.128.2 allows demoted super_admin users to retain access to critical RPCs, enabling them to indefinitely enumerate and bulk delete non-compliant bundles across an organization.

Capgo privilege-escalation vulnerability cloud
1t 1c
high advisory

CVE-2026-56238 - Capgo Supabase PostgREST Information Disclosure

An information disclosure vulnerability (CVE-2026-56238) in Capgo before 12.128.2's Supabase PostgREST global_stats endpoint allows unauthenticated attackers to retrieve sensitive financial and operational metrics using a public API key.

Capgo < 12.128.2 +1 information-disclosure web-application vulnerability supabase
1r 2t 1c
high advisory

SQL Injection Vulnerability in sergomanov SmartHomeAdatum Login Component (CVE-2026-15498)

A SQL injection vulnerability, identified as CVE-2026-15498, exists in the Login component of sergomanov SmartHomeAdatum, affecting versions up to commit cf495353d81b680675eb8d9aa14a318aa45ce12c. This flaw allows remote attackers to perform SQL injection by manipulating the 'Login' argument in the 'users.php' file.

SmartHomeAdatum sql-injection web-application vulnerability cve
1r 2t 1c
high advisory

SonicCloudOrg Sonic-Agent Code Injection Vulnerability (CVE-2026-15497)

A critical vulnerability (CVE-2026-15497) exists in SonicCloudOrg's sonic-agent, affecting versions up to 2.7.2. The flaw resides within an unknown function in the `ExchangeController.java` file, specifically within the JWT Authentication Filter component of the `sonic-server-controller`. This vulnerability allows for remote code injection, and public exploits are available. The vendor was notified but has not responded, and the affected products are no longer supported.

sonic-agent <= 2.7.2 vulnerability rce code-injection
1r 2t 1c
critical advisory

Crawl4AI Arbitrary File Write via Docker API Server Endpoints (CVE-2026-56260)

Crawl4AI versions prior to 0.8.7 are vulnerable to CVE-2026-56260, an arbitrary file write vulnerability in its Docker API server's /screenshot and /pdf endpoints, allowing unauthenticated attackers to supply path traversal or absolute file paths via the output_path parameter to overwrite server files, leading to denial of service or impaired defenses.

Crawl4AI < 0.8.7 vulnerability web-application path-traversal arbitrary-file-write denial-of-service
1r 3t 1c
high advisory

Unrestricted File Upload Vulnerability in hcr707305003 shiroiAdmin

A remote unrestricted file upload vulnerability (CVE-2026-15488) exists in hcr707305003 shiroiAdmin versions 1.1 and 1.3, allowing attackers to upload arbitrary files by manipulating the 'File' argument in FileController::upload, potentially leading to remote code execution.

shiroiAdmin < 1.4 vulnerability web file-upload remote-code-execution
1r 3t 1c
high advisory

Remote Buffer Overflow Vulnerability in TRENDnet TEW-821DAP Access Point

A critical buffer overflow vulnerability (CVE-2026-15484) exists in the `sub_41EC14` function within the `/goform/tools_nslookup` component of the TRENDnet TEW-821DAP 1.12B01 wireless access point, which can be exploited remotely due to improper handling of the ssi element, potentially leading to arbitrary code execution on an End-of-Life device.

TEW-821DAP buffer-overflow vulnerability network-device remote-code-execution
1c
high advisory

Trendnet TEW-635BRM Web Service Stack-based Buffer Overflow Vulnerability

CVE-2026-15480 describes a stack-based buffer overflow vulnerability in the Trendnet TEW-635BRM router firmware, specifically in the start_httpd function within the /sbin/rc component's Web Service, which can be exploited remotely by manipulating the 'device_name' argument, potentially leading to arbitrary code execution; an exploit is publicly available, but the product is End-of-Life (EOL) since 2011, and the vendor advises users to switch devices.

TEW-635BRM network vulnerability router buffer-overflow rce eol
2t 1c
high threat

H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)

A critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.

exploited NX15 V100R017 vulnerability api-exploitation password-reset network-device remote-access
2t 1c 5i
high advisory

CVE-2026-61442: PraisonAI Platform Authorization Bypass

PraisonAI Platform versions before 0.1.9 are vulnerable to an authorization bypass on PATCH routes for projects, issues, and agents, allowing an attacker with a workspace-member role to modify owner-created records, reassign the lead_id to their own user ID, and subsequently delete owner-created projects, bypassing standard permission checks and leading to unauthorized data manipulation and deletion.

PraisonAI Platform < 0.1.9 authorization-bypass vulnerability web-application cve
2t 1c
high advisory

PraisonAI Prompt Injection Defense Bypass Vulnerability (CVE-2026-61439)

A prompt injection defense misconfiguration in PraisonAI versions before 4.6.78 allows high-severity threats to bypass blocking mechanisms due to a default block threshold set to CRITICAL severity, enabling attackers to submit instruction overrides or financial manipulation for system prompt extraction and unauthorized tool invocations.

PraisonAI prompt-injection ai-security vulnerability defense-bypass
3t 1c
high advisory

PraisonAI Server-Side Request Forgery via DNS Rebinding and Redirects (CVE-2026-61429)

PraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) due to an issue in the Crawl4AI/Chromium backend, allowing attackers to bypass existing SSRF validation by employing DNS rebinding and HTTP redirects to access and exfiltrate sensitive internal responses, including canary values.

PraisonAI ssrf vulnerability dns-rebinding web-application
4t 1c
high advisory

Insecure Default Configuration in PraisonAI Allows Unauthenticated Access

An insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.

PraisonAI vulnerability web-application insecure-configuration cve
2r 3t 1c
high advisory

Capgo API Key Information Disclosure Vulnerability (CVE-2026-56303)

An information disclosure vulnerability (CVE-2026-56303) in Capgo versions before 12.128.2 allows unauthenticated attackers to retrieve sensitive API key metadata, including user ID, mode, organization scoping, and expiration details, by exploiting a misconfigured PostgreSQL function via the `/rest/v1/rpc/find_apikey_by_value` endpoint.

Capgo information-disclosure vulnerability api-security web-application
1r 1t 1c
critical advisory

CVE-2026-61447 PraisonAI Remote Code Execution Vulnerability via Prompt Injection

Attackers can exploit CVE-2026-61447, a critical remote code execution vulnerability in PraisonAI versions before 1.6.78, by using prompt injection to manipulate LLM-generated Python code, leading to arbitrary code execution and exfiltration of environment secrets on the host system.

PoC PraisonAI remote-code-execution prompt-injection llm ai vulnerability
1t 1c updated
high advisory

Vulnerability in Genolve WordPress Plugin Allows Privilege Escalation

A vulnerability in the Genolve AI image AI video generation plugin for WordPress, affecting versions up to and including 5.0.5, allows authenticated attackers with Contributor-level access to achieve privilege escalation due to a missing capability check in the `genolve_setOpt()` function, enabling them to modify arbitrary WordPress options such as enabling user registration and setting the default role to administrator.

Genolve - AI image AI video generation plugin for WordPress wordpress plugin privilege-escalation vulnerability
1r 1t 1c
medium threat

CVE-2026-59869: js-yaml Vulnerability Leading to Quadratic CPU Consumption and DoS

A vulnerability, CVE-2026-59869, in the `js-yaml` library allows attackers to craft malicious YAML merge-key chains, which can lead to quadratic CPU consumption and a Denial of Service condition in applications processing the input.

exploited js-yaml denial-of-service vulnerability yaml
2t 1c
medium advisory

CVE-2026-59928 Mistune block_parser: Quadratic-Time Parsing Leading to Denial of Service

CVE-2026-59928 identifies a vulnerability in the Mistune block_parser component where quadratic-time parsing of long lists of repeated reference-link definitions can be exploited by an attacker to cause a denial-of-service condition due to excessive resource consumption.

Mistune block_parser denial-of-service vulnerability markdown-parser
1c
critical advisory

CVE-2026-14739 DBI for Perl Heap Overflow Vulnerability

CVE-2026-14739 details a heap overflow vulnerability affecting DBI for Perl versions prior to 1.650, which arises during the preparsing of SQL statements with an excessive number of placeholders, potentially leading to arbitrary code execution or a denial of service.

DBI < 1.650 +1 vulnerability heap-overflow perl dbi cve
1c
medium threat

Out-of-Bound Read Vulnerability in mtr (CVE-2026-14461)

CVE-2026-14461 identifies an out-of-bound read vulnerability in the mtr network diagnostic tool that could lead to information disclosure or denial of service on Linux and macOS systems.

exploited mtr vulnerability linux macos network-utility
1c
high threat

NATS Server Authorization Bypass Vulnerability (CVE-2026-58252)

CVE-2026-58252 identifies an authorization bypass vulnerability in NATS Server, described as a 'Subscribe Authz Bypass via Wildcard-Overlap', which allows unauthorized access or actions by exploiting how wildcard subscriptions are handled.

exploited NATS Server authorization-bypass cve nats server vulnerability mqtt information-disclosure filter-bypass +1
2t 1c
medium advisory

Setuptools Unicode Normalization Collision Bypass on macOS

A vulnerability, CVE-2026-59890, affects the setuptools project, allowing a MANIFEST.in exclusion bypass during source distribution package creation due to Unicode normalization collisions (NFC/NFD) on macOS systems using APFS or HFS+ file systems.

setuptools python macos vulnerability supply-chain
1c
medium advisory

Mistune Markdown Parser Vulnerability CVE-2026-59930 Allows HTML ID Collision

A vulnerability, CVE-2026-59930, in the Mistune markdown parser's TableOfContents directive creates predictable HTML heading IDs, enabling an attacker to inject content with colliding IDs for client-side content manipulation.

Mistune vulnerability markdown client-side cve
1c
medium advisory

Perl DBI Out-of-Bounds Read Vulnerability CVE-2026-14740

CVE-2026-14740 describes an out-of-bounds read vulnerability in DBI versions prior to 1.650 for Perl, occurring during the preparse stage when deleting an initial SQL comment, which can lead to information disclosure or denial of service.

DBI < 1.650 vulnerability perl memory-corruption information-disclosure
1c
medium advisory

OpenSSH sshd GSSAPI Behavior Vulnerability CVE-2026-59998

CVE-2026-59998 describes an undocumented security-relevant behavior in sshd, a component of OpenSSH, specifically in versions prior to 10.4, where the GSSAPIStrictAcceptorCheck setting reportedly has no value when the server is operating within a Windows Active Directory environment.

sshd in OpenSSH < 10.4 +1 vulnerability openssh gssapi active-directory windows misconfiguration
1c
low advisory

Dahua IPC Vulnerability CVE-2026-29114 Exposes CA Root Certificate

A low-severity certificate-trust vulnerability (CVE-2026-29114) has been identified in select Dahua IPC (IP camera) models with firmware builds before April 15, 2026. A remote attacker can obtain the device's internal CA root certificate, which, if trusted by client workstations, browsers, or middleware, allows the attacker to mint fraudulent X.509 certificates, enabling person-in-the-middle (MITM) attacks against HTTPS or TLS-protected sessions, undermining confidentiality and integrity, with related CVEs for different impacts. Remediation involves upgrading firmware and removing improperly trusted device CAs from client trust stores.

Dahua IPC models vulnerability certificate-abuse dahua pki mitm
2r 3t 3c
high advisory

CVE-2026-13378 - Form Vibes WordPress Plugin Vulnerable to Stored Cross-Site Scripting

The Form Vibes - Database Manager for Forms plugin for WordPress, including all versions up to and including 1.5.2, is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when a user accesses an injected page.

Form Vibes – Database Manager for Forms wordpress plugin vulnerability xss web
1r 2t 1c 5i
high advisory

Local File Inclusion Vulnerability in LA-Studio Element Kit for Elementor Plugin for WordPress

A Local File Inclusion vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress, affecting all versions up to and including 1.6.1, which allows authenticated attackers with contributor-level access or higher to include and execute arbitrary .php files on the server due to improper path traversal handling and an easily bypassed extension check, leading to PHP code execution, access control bypass, and sensitive data exposure.

LA-Studio Element Kit for Elementor plugin for WordPress wordpress plugin vulnerability lfi web
4t 1c
critical advisory

TSDProxy Internal Authentication Token Vulnerability Leading to Management API Escalation

A critical vulnerability in TSDProxy allows its internal per-process authentication token to be unconditionally forwarded to proxied backend services when `identityHeaders` is enabled, enabling an attacker with code execution on a co-located backend to replay the token to the local TSDProxy management API (port 8080) and bypass authentication, leading to full management API control.

tsdproxy < 1.4.4-0.20260603142855-434819b4421e vulnerability privilege-escalation authentication-bypass tsdproxy go
1r 4t 1i
high advisory

Clauster Dashboard Unauthenticated Access Vulnerability

A Clauster instance deployed on a non-loopback address can be accessed unauthenticated, even if password protection is configured, due to auth.enabled defaulting to false. This allows an attacker with network access to gain full control of the dashboard, including listing projects, spawning remote-control bridges, editing files, reading logs, and cloning repositories, ultimately leading to remote code execution in project directories.

Clauster misconfiguration remote-code-execution vulnerability web-application
2t 1i
high advisory

RustDesk Authorization Bypass via Session Scope Enforcement Failure (CVE-2026-57850)

An authorization vulnerability exists in RustDesk before version 1.4.9 where the server-side fails to properly enforce connection scope for authenticated peers, allowing an attacker, having been granted a limited session type, to inject control messages typically reserved for a full Remote session and gain unauthorized observation and control over the host.

RustDesk < 1.4.9 vulnerability authorization-bypass remote-access
1t 1c
high advisory

SafeInstall CLI Guard Bypass Vulnerability Allows Unauthorized Package Execution

A vulnerability in SafeInstall CLI through version 0.10.1 allows attackers to bypass its agent guard and execute unauthorized package installation or registry-provided scaffolding commands, potentially compromising developer environments.

safeinstall-cli vulnerability supply-chain developer-tools defense-evasion
2t
critical advisory

CVE-2026-5801 - SQL Injection Leading to Command Line Execution in Semtek SEM-PMP

An SQL injection vulnerability, tracked as CVE-2026-5801, has been identified in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP versions through 23042026, allowing unauthenticated attackers to achieve command line execution on the underlying system with a critical CVSS v3.1 score of 9.8.

SEM-PMP sql-injection rce vulnerability web-application
1r 2t 1c 1i
high advisory

SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding

An incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.

siyuan kernel path-traversal vulnerability web-vulnerability arbitrary-file-read
1r 3t 2c 1i
medium advisory

Excelize Unbounded Row Index Allocation Denial-of-Service Vulnerability

An unbounded row index allocation vulnerability (CWE-770) exists in the `checkSheet()` function of the `github.com/xuri/excelize/v2` library, allowing an unauthenticated attacker to craft a malicious XLSX file with a specially crafted row index value that triggers an out-of-memory error or runtime panic, leading to a denial-of-service condition in Go applications processing untrusted spreadsheets.

excelize v2 vulnerability denial-of-service golang xlsx library cwe-770
1t
critical advisory

Authorizer Unvalidated Redirect Vulnerability Allows OAuth2 Token Theft

An unvalidated redirect vulnerability, CVE-2026-54072, in the Authorizer `/authorize` endpoint allows an unauthenticated attacker to steal OAuth2 access, ID, and refresh tokens by crafting a malicious URL with an attacker-controlled `redirect_uri` to which the application redirects a logged-in user, exposing their tokens.

authorizer oauth vulnerability redirect token-theft web ghsa
1r 2t 1i
high advisory

Authorization Bypass Vulnerability in Teracity TeraMIS (CVE-2026-6212)

A critical authorization bypass vulnerability (CVE-2026-6212) in Teracity Software Technologies Inc. TeraMIS, affecting versions V03.26.01.14 through 30.04.2026, allows an attacker to achieve Privilege Abuse by manipulating user-controlled keys.

TeraMIS authorization-bypass privilege-escalation vulnerability
1t 1c
high advisory

Krayin CRM Insecure Direct Object Reference Vulnerability (CVE-2026-61460)

An Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-61460, in Krayin CRM through version 2.2.3 allows authenticated users to modify, update, or delete records owned by other users by exploiting missing record-level ownership validation in various controllers, leading to unauthorized data manipulation.

Krayin CRM +1 idor crm web-application vulnerability
3t 1c
high advisory

HestiaCP Authenticated OS Command Injection via DNS Record Types (CVE-2025-30007)

An authenticated OS command injection vulnerability, CVE-2025-30007, in HestiaCP before version 1.9.5 allows low-privilege users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types, leading to full root code execution on the underlying host.

HestiaCP < 1.9.5 vulnerability command-injection privilege-escalation linux hestiacp
2t 1c
critical advisory

CVE-2026-61459 - Argument Injection in MCP Server Kubernetes Structured Tools Leads to Cluster Compromise

An argument injection vulnerability, CVE-2026-61459, in MCP Server Kubernetes versions prior to 3.9.0 within structured tools like kubectl_get, kubectl_describe, and kubectl_delete allows attackers to bypass the assertNoDangerousFlags security check by injecting parameters with leading dashes to redirect kubectl commands to an attacker-controlled API server, enabling the exfiltration of the operator's bearer token and leading to full Kubernetes cluster compromise.

PoC Kubernetes < 3.9.0 +1 kubernetes cloud argument-injection vulnerability cve
4t 1c updated
critical advisory

Critical SQL Injection Vulnerability in Adam Retail Automation MobilMen 20T

A critical SQL injection vulnerability, tracked as CVE-2026-2397 with a CVSS v3.1 score of 9.8, affects Adam Retail Automation Ltd.'s MobilMen 20T software, allowing remote attackers to execute arbitrary SQL commands due to improper neutralization of special elements in input, potentially leading to unauthorized data access or system compromise.

MobilMen 20T sql-injection vulnerability cve data-exfiltration
2t 1c
high advisory

CVE-2026-2398: Authorization Bypass Leads to Privilege Escalation in Adam Retail Automation MobilMen 20T

An authorization bypass vulnerability, identified as CVE-2026-2398, exists in Adam Retail Automation Ltd.'s MobilMen 20T software, affecting versions from v3 through 10072026, allowing an attacker to achieve privilege escalation by manipulating user-controlled keys.

MobilMen 20T authorization-bypass privilege-escalation vulnerability CVE
1t 1c
critical threat

CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE

A critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.

exploited Forms vulnerability web-vulnerability rce file-upload cisa-kev
1r 2t 1c
critical advisory

Arbitrary XML Schema Definition Processing in guardrails-detectors Leads to SSRF and Local File Read

A flaw in the 'file_type' content detector of 'guardrails-detectors' allows a remote attacker to provide an arbitrary XML Schema Definition (XSD) string, leading to server-side request forgery (SSRF) and local file reads, potentially exposing sensitive information such as cloud provider credentials or granting access to internal network services.

guardrails-detectors vulnerability ssrf local-file-read info-disclosure guardrails
3t 1c
high advisory

PraisonAI praisonaiagents Unsafe Dynamic Module Loading Vulnerability (CVE-2026-61437)

A critical vulnerability, CVE-2026-61437, in PraisonAI's `praisonaiagents` pip package before version 1.6.78 allows an attacker to achieve remote code execution by exploiting an unsafe dynamic module loading mechanism when a malicious workflow file and an adjacent `tools.py` are executed, bypassing sandboxing and leading to arbitrary Python code execution with workflow runner privileges.

praisonaiagents supply-chain rce vulnerability
2t 1c
high advisory

CVE-2026-61434: PraisonAI Shell Command Allowlist Bypass

PraisonAI versions prior to 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to use find's built-in -exec, -execdir, and -delete actions to execute restricted commands, read or delete files, or run non-allowlisted binaries, bypassing existing shell metacharacter filters, which can lead to arbitrary command execution and impact system integrity.

PraisonAI vulnerability rce allowlist-bypass cve
1r 3t 1c 2i
high advisory

Capgo Information Disclosure in get_orgs_v7 RPC Function (CVE-2026-56279)

Capgo versions prior to 12.128.2 are vulnerable to an information disclosure flaw in the `get_orgs_v7(userid)` RPC function, allowing unauthenticated attackers to retrieve sensitive foreign user and organization data by supplying arbitrary user UUIDs.

Capgo information-disclosure vulnerability rpc authentication-bypass account-takeover web-application
1r 4t 1c
high advisory

Capacitor Updater Vulnerability Allows Malicious Update Installation via Private Key Distribution

A vulnerability, CVE-2026-56254, in @capgo/capacitor-updater (Cap-go/capgo) before version 12.128.2 allows an attacker to create and distribute validly signed malicious application updates by leveraging the improper distribution of a private key to each client device, enabling man-in-the-middle or server compromise scenarios.

@capgo/capacitor-updater supply-chain vulnerability code-signing software-update
2t 1c
high advisory

FlaskBB Authorization Bypass Vulnerability (CVE-2026-22659)

An authorization bypass vulnerability exists in FlaskBB through version 2.2.0, allowing authenticated moderators to perform unauthorized administrative actions such as locking, unlocking, deleting, or hiding topics in forums they do not control. This is achieved by crafting batch requests that include a low-ID topic from a permitted forum, which bypasses permission checks applied only to the first item, and then executing actions on topics from unmoderated forums.

FlaskBB <= 2.2.0 authorization-bypass vulnerability web-application
2t 1c
medium advisory

CPython Denial-of-Service Vulnerability

A remote denial-of-service vulnerability, CVE-2026-15308, has been discovered in CPython, allowing an attacker to cause service disruption to affected systems not running the latest security patch.

CPython +1 denial-of-service vulnerability python
1t 1c 1i updated
high advisory

Security Risks Associated with AI Coding Tools, Including GhostApproval Vulnerability

The adoption of AI coding tools introduces significant security risks, such as the generation of vulnerable code with OWASP Top 10 flaws, the inadvertent leakage of sensitive secrets and hardcoded credentials, and supply chain compromise via 'slopsquatting,' alongside specific vulnerabilities like 'GhostApproval' which allows remote code execution on developer machines.

ai coding-tools supply-chain vulnerability rce credential-exposure
3t
critical advisory

Critical Blind SSRF Vulnerability in guardrails-detectors (CVE-2026-15378)

A critical blind Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-15378, exists in the `guardrails-detectors` component, allowing a remote attacker to exploit specially crafted XML Schema Definition (XSD) strings to gain unauthorized access to sensitive information from cloud metadata services, Kubernetes API, internal MinIO, and facilitate local file reads of service account tokens and pod secrets.

guardrails-detectors ssrf vulnerability cloud kubernetes data-exfiltration
6t 1c
high advisory

CVE-2026-59818 etcd: gRPC client listener does not enforce certificate revocation

The etcd gRPC client listener is affected by CVE-2026-59818, a vulnerability where it fails to properly enforce Certificate Revocation Lists (CRLs) when the `--client-crl-file` flag is used, potentially allowing clients with revoked certificates to bypass authentication and gain unauthorized access to etcd instances.

etcd vulnerability grpc authentication-bypass certificate-revocation
1c
high advisory

[UPDATE] Python: Schwachstelle ermöglicht Codeausführung

A high-severity vulnerability in Python allows a remote, unauthenticated attacker to execute arbitrary program code, potentially leading to full system compromise on machines running vulnerable Python installations.

Python remote-code-execution vulnerability rce
2t
high advisory

Python Privilege Escalation Vulnerability

A local attacker can exploit an unspecified vulnerability within Python to elevate their privileges on the affected system.

Python privilege-escalation vulnerability
1t
medium advisory

Multiple Python Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in Python allow an attacker to execute arbitrary code or cause a Denial of Service condition, potentially leading to system compromise or service disruption.

Python vulnerability code-execution dos
2t
medium advisory

Python: Vulnerability Enables File Manipulation

An authenticated remote attacker can exploit a vulnerability in Python to manipulate files, which could lead to unauthorized modification of data or disruption of system integrity across Windows, Linux, and macOS environments.

Python vulnerability file-manipulation
1t
high threat

Splunk Enterprise: Multiple Vulnerabilities

Attackers can exploit multiple, unspecified vulnerabilities in Splunk Enterprise to bypass security measures, disclose sensitive information, manipulate data, execute arbitrary code, and cause denial-of-service conditions, potentially leading to other unspecified impacts.

exploited Splunk Enterprise vulnerability splunk enterprise code-execution data-exfiltration
6t
high advisory

CVE-2026-15288: SureForms WordPress Plugin Payment Manipulation Vulnerability

The SureForms - Drag and Drop Form Builder for WordPress plugin (versions up to and including 2.2.1) is vulnerable to improper input validation (CVE-2026-15288), allowing unauthenticated attackers to modify payment amounts in user-controlled POST data when submitting Stripe payment forms, enabling them to purchase products or services at arbitrarily reduced prices.

SureForms - Drag and Drop Form Builder for WordPress plugin <= 2.2.1 wordpress plugin vulnerability web payment-fraud
1r 1t 1c
critical advisory

CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin

A critical SQL Injection vulnerability, identified as CVE-2026-15300, was found in the GEO my WP plugin for WordPress, affecting versions up to and including 4.5.4, allowing attackers to inject SQL payloads through the 'distance', 'lat', and 'lng' parameters, leading to potential data compromise or denial of service.

GEO my WP plugin <= 4.5.4 wordpress plugin sql-injection vulnerability webserver
1r 2t 1c
critical advisory

CVE-2026-15282: WordPress Instant Appointment Plugin Arbitrary File Upload to RCE

An unauthenticated attacker can exploit CVE-2026-15282, an arbitrary file upload vulnerability due to missing file type validation in the `insapp_upload_image_as_attachment` function of the WordPress Instant Appointment plugin up to version 1.2, to upload malicious files and achieve remote code execution on the affected server.

PoC Instant Appointment Plugin <= 1.2 wordpress plugin vulnerability rce file-upload webserver
1r 2t 1c updated
high advisory

CVE-2026-15070: WordPress Salon Booking Plugin CSRF to RCE

The Salon Booking System - Free Version plugin for WordPress (versions up to and including 10.30.32) is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability stemming from a lack of nonce validation in the setCustomText function, allowing unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file, which can lead to remote code execution (RCE) on the server if an administrator is tricked into clicking a crafted link.

Salon Booking System - Free Version plugin for WordPress <= 10.30.32 web-exploitation vulnerability wordpress rce csrf
1r 3t
high advisory

CVE-2026-15319: Remote Improper Access Control in Sipeed PicoClaw

A remote improper access control vulnerability (CVE-2026-15319) exists in the IPAllowlist function of the Launcher component in Sipeed PicoClaw versions up to and including 0.2.9, allowing unauthorized remote access due to publicly disclosed exploit.

PicoClaw <= 0.2.9 vulnerability access-control web-application
1c
high advisory

Tesla Elixir HTTP Client Header Leak via Case-Sensitive Redirect Filtering (CVE-2026-48595)

A vulnerability in the `Tesla.Middleware.FollowRedirects` component of the `tesla` Elixir HTTP client library allows `Authorization` headers to be leaked during cross-origin redirects due to a case-sensitive comparison, enabling an attacker controlling a redirect destination to receive bearer tokens or other credentials from applications using `tesla` versions 0.6.0 through 1.18.2.

tesla credential-access exfiltration vulnerability elixir http-client
2t 1c
medium advisory

Tesla HTTP Client Library Vulnerable to Atom Exhaustion Leading to Denial of Service (CVE-2026-48597)

A high-severity denial-of-service vulnerability (CVE-2026-48597) in the `Tesla.Adapter.Mint` component of the Elixir Tesla HTTP client library, affecting versions 1.3.0 through 1.18.2, allows an unauthenticated attacker to crash the underlying BEAM VM by supplying untrusted URL schemes, leading to atom exhaustion.

tesla denial-of-service elixir erlang vulnerability web-application
1t 1c
medium advisory

Mistune Markdown Parser Vulnerable to CPU Exhaustion DoS (CVE-2026-49851)

The Mistune Python Markdown parser is vulnerable to a CPU exhaustion Denial of Service (DoS) attack, identified as CVE-2026-49851, due to a superlinear (O(n²)) parsing behavior in the `parse_link_text` function when processing specially crafted input containing repeated square brackets, allowing an attacker to significantly degrade application performance with a small payload.

mistune denial-of-service python library vulnerability markdown
1t 1c
medium advisory

Mint HTTP/2 Client Vulnerable to Unbounded CONTINUATION Frame Accumulation (CVE-2026-49754)

A malicious or compromised HTTP/2 server can exploit CVE-2026-49754 in the Elixir Mint HTTP/2 client by sending an endless chain of CONTINUATION frames without an END_HEADERS flag, leading to unbounded memory accumulation, process exhaustion, and remote unauthenticated denial-of-service.

Mint http/2 denial-of-service vulnerability elixir
1t 1c
medium advisory

Mint HTTP/2 Client Unbounded Stream Map Growth Denial-of-Service (CVE-2026-48862)

A malicious or compromised HTTP/2 server can exploit CVE-2026-48862 in Mint HTTP/2 clients by flooding them with PUSH_PROMISE frames and withholding corresponding HEADERS, leading to unbounded memory consumption and denial-of-service.

Mint denial-of-service http/2 elixir client-side vulnerability
1t 1c
high advisory

CVE-2026-58143 - Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows una...

A Cross-Site Request Forgery (CSRF) vulnerability in Cotonti Siena versions 0.9.26 and earlier allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request, enabling the upload and execution of arbitrary PHP files leading to remote code execution.

Cotonti Siena <= 0.9.26 cross-site-request-forgery vulnerability webserver rce php
1r 3t 1c
medium advisory

CVE-2026-57028: Juniper Junos OS Evolved License Exhaustion via Improper Communication Channel Restriction

A vulnerability, CVE-2026-57028, in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to gain unauthorized access to internal license management processes via an exposed internal port, leading to license exhaustion and ultimately a denial-of-service condition.

Junos OS Evolved vulnerability network denial-of-service juniper
2t 1c
medium advisory

CVE-2026-57026 - Improper Validation of SIP Input in Juniper Junos OS Leads to DoS

An unauthenticated, network-based attacker can exploit CVE-2026-57026, an improper input validation vulnerability, in the SIP plugin of Juniper Networks Junos OS. If the SIP ALG is enabled on affected MX Series with SPC3 or SRX Series devices, processing a malformed SIP invite packet will cause the flow processing daemon (flowd) to crash and restart, leading to a complete denial of service until the system recovers.

Junos OS on MX Series with SPC3 +11 denial-of-service vulnerability juniper network
1t 1c
medium advisory

CVE-2026-57023: Juniper Junos OS TCP Proxy Denial of Service

An Improper Validation of Specified Quantity in Input vulnerability (CVE-2026-57023) in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS) by sending a specifically malformed TCP header packet, crashing the flow processing daemon (flowd) until automated recovery.

Junos OS on MX Series with SPC3 +1 denial-of-service vulnerability network juniper
1t 1c
high advisory

Laravel-Backup-Restore OS Command Injection (CVE-2026-53932)

A critical OS command injection vulnerability, tracked as CVE-2026-53932, exists in the wnx/laravel-backup-restore package (versions <= 1.9.3), allowing an attacker to execute arbitrary shell commands on the hosting system by crafting a malicious backup archive with shell metacharacters in a database dump filename, leading to application compromise, data tampering, and potential lateral movement.

laravel-backup-restore <= 1.9.3 os-command-injection laravel php vulnerability cve-2026-53932
2r 2t
high advisory

YesWiki Public Bazar API Unauthenticated SQL Injection (CVE-2026-52770)

An unauthenticated attacker can exploit CVE-2026-52770, an SQL injection vulnerability in YesWiki's public Bazar entry-listing APIs, by manipulating numeric `query` or `queries` GET parameters, to use the application as a boolean oracle for inferring sensitive database contents like user accounts and password hashes.

YesWiki sql-injection web-application vulnerability
1r 4t
high advisory

YesWiki Second-Order SQL Injection via Unescaped Page Tag in API Controller

A critical second-order SQL injection vulnerability (GHSA-8f2v-2qhj-gfwg) in YesWiki versions up to 4.6.5 allows a low-privilege authenticated attacker to execute arbitrary SQL commands via an unescaped page tag in the `ApiController::deletePage()` API, leading to time-based blind data exfiltration.

YesWiki 4.6.5 sql-injection web-application vulnerability yeswiki ghsa
1r 4t
critical advisory

YesWiki PHP Object Injection Vulnerability (CVE-2026-52777)

An authenticated PHP Object Injection vulnerability (CVE-2026-52777) in YesWiki's `BazarImportAction`, specifically within the `unserialize` function, allows remote code execution (RCE) on the YesWiki server when an authenticated administrator's browser is targeted via a cross-site request forgery (CSRF) attack.

composer/yeswiki/yeswiki vulnerability rce php object-injection web-application csrf
1r 4t
critical threat

Active Exploitation of CVE-2026-1207 in Django Framework

A critical vulnerability, CVE-2026-1207, affecting Django versions prior to 4.2.28, 5.2.11, and 6.0.2, is actively being exploited, posing a significant risk of web server compromise and data exfiltration to organizations using the affected framework.

exploited Django 4.2 +2 web-application vulnerability active-exploitation python django
1c
high advisory

UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)

The UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.

UsersWP plugin <= 1.2.65 +1 wordpress plugin vulnerability web file-deletion remote-code-execution
1r 3t 1c
high advisory

FreePBX API and Backup Modules Vulnerabilities Allowing Authenticated RCE and SSH Key Injection

FreePBX has released security advisories to address critical vulnerabilities in its API and Backup modules, affecting FreePBX API (versions prior to 17.0.9) and FreePBX Backup (versions prior to 17.0.11), which include authenticated command injection and arbitrary SSH key injection leading to remote code execution and unauthorized access.

FreePBX API +1 freepbx vulnerability command-injection rce ssh-key-injection voip pbx linux
2t
high advisory

CVE-2026-58459 - gpsd gpsprof Command Injection

A command injection vulnerability, CVE-2026-58459, exists in the gpsprof utility of gpsd through version 3.27.5, allowing an attacker to exploit this by controlling the GPS device subtype value and embedding backtick payloads within the gnuplot plot title, which leads to arbitrary shell command execution as the user running gnuplot when a victim renders a generated plot via the gpsprof and gnuplot workflow due to improper escaping.

gpsd command-injection vulnerability execution linux macos
2r 1t 1c
high advisory

CVE-2026-15190: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script

A critical SQL injection vulnerability (CVE-2026-15190) exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing unauthenticated remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument on the `/login.php` page, with a public exploit now available.

Simple and Nice Shopping Cart Script sql-injection web-application vulnerability cve
1r 3t 1c 3i
high advisory

CVE-2026-11404: Cesanta Mongoose TLS Out-of-Bounds Read Leading to Denial of Service

Cesanta Mongoose before version 7.22 contains an out-of-bounds read vulnerability (CVE-2026-11404) in its built-in TLS server function, `mg_tls_server_recv_hello()`, allowing a remote, unauthenticated attacker to send a specially crafted TLS ClientHello message with an oversized session ID length, leading to a service crash and denial of service for HTTPS, MQTTS, or WSS services.

Mongoose denial-of-service vulnerability tls webserver firmware
1t 1c
medium advisory

Schneider Electric Easergy MiCOM Px40 Series Information Disclosure via Hard-coded Credentials (CVE-2026-4832)

Schneider Electric Easergy MiCOM Px40 Series products are vulnerable to CVE-2026-4832, a hard-coded credentials flaw (CWE-798) that allows unauthenticated attackers to interrogate the SNMP port and expose basic device identification information from critical manufacturing, energy, and transportation systems assets globally.

Easergy MiCOM P14x +25 ics ot scada vulnerability schneider-electric snmp cve-2026-4832 information-disclosure
2t 1c
critical advisory

OpenPLC v3 Arbitrary File Write Leads to Native Code Execution (CVE-2026-14480)

An authenticated arbitrary file write vulnerability (CVE-2026-14480) in OpenPLC v3's legacy web UI program-upload workflow allows attackers to write arbitrary files, escalating to arbitrary native code execution as the OpenPLC runtime user when an operator triggers program compilation.

OpenPLC v3 ics scada vulnerability rce authenticated-rce file-write cwe-73
3t
high threat

Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown

Multiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.

exploited PowerChute Serial Shutdown ics ot vulnerability path-traversal crlf-injection dos log-tampering critical-infrastructure
5t 5c
medium advisory

CVE-2026-60109 - Zeek Kerberos Protocol Analyzer Null Pointer Dereference

A null pointer dereference vulnerability (CVE-2026-60109) exists in Zeek's Kerberos protocol analyzer before version 8.0.9, allowing unauthenticated remote attackers to crash a Zeek sensor by sending a specially crafted KRB_ERROR message with error-code 25 and specific PA-DATA elements, leading to a denial-of-service condition.

Zeek vulnerability network dos kerberos
1t 1c
medium advisory

CVE-2026-60108 - Zeek FTP Analyzer Uncontrolled Memory Consumption leading to DoS

An uncontrolled memory consumption vulnerability in the Zeek FTP analyzer, versions prior to 8.0.9, allows unauthenticated remote attackers to cause process termination and denial of service of the Zeek sensor. This occurs when a crafted FTP control session with AUTH GSSAPI and a large ADAT control line exploits the NVT_Analyzer component's lack of a maximum line length check, leading to an unbounded internal buffer during base64 decoding.

Zeek cve dos network-protocol vulnerability
1t 1c
high advisory

Multiple Vulnerabilities Discovered in GitLab CE/EE

Multiple vulnerabilities have been discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) across versions 19.0.x, 19.1.x, and 18.11.x, allowing an attacker to compromise data confidentiality, inject remote code via Cross-Site Scripting (XSS) (CVE-2026-11827), and bypass security policies (CVE-2026-13320).

GitLab Community Edition +5 web-application vulnerability gitlab xss data-leak
1t 5c
high advisory

Multiple Vulnerabilities Discovered in Wireshark Leading to DoS and Data Confidentiality Compromise

Multiple vulnerabilities (CVE-2026-15163 through CVE-2026-15174) have been discovered in Wireshark, impacting versions 4.6.x prior to 4.6.7 and versions prior to 4.4.17, which could allow a remote attacker to cause a denial of service and compromise data confidentiality.

Wireshark 4.6.x +1 vulnerability wireshark dos info-disclosure product-vulnerability
2t 5c
high advisory

Multiple Security Policy Bypass Vulnerabilities in Traefik Edge Router

Multiple vulnerabilities have been discovered in Traefik, affecting versions 3.6.x prior to 3.6.23, 3.7.x prior to 3.7.7, and versions prior to 2.11.52, which allow an attacker to bypass security policies, potentially leading to unauthorized access or actions.

Traefik < 3.6.23 +2 vulnerability policy-bypass Traefik edge-router
3i
high advisory

CVE-2026-4256 - PEAKUP PassGate LDAP Injection Vulnerability

A high-severity LDAP injection vulnerability, CVE-2026-4256, exists in PEAKUP Technology Inc.'s PassGate product through version 30042026, allowing an unauthenticated attacker to manipulate LDAP queries, potentially leading to high confidentiality impact and low integrity impact.

PassGate ldap-injection vulnerability web-application
4t 1c
medium advisory

Ruby CSS Parser Vulnerable to SSRF and Local File Disclosure via `read_remote_file`

The `css_parser` library, specifically in versions up to and including 2.2.0, is vulnerable to Server-Side Request Forgery (SSRF) and local file disclosure through improper URI validation in the `CssParser::Parser#read_remote_file` method, allowing attackers to access internal network resources or read local files when processing attacker-controlled CSS.

css_parser <= 2.2.0 ssrf lfi supply-chain ruby vulnerability web-application
4t
medium advisory

CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS

A stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.

DTLS plugin +2 denial-of-service buffer-overflow vulnerability dtls gstreamer linux high_confidence_source watchlist_match
2t 1c
high advisory

CVE-2026-59691: GStreamer rfbsrc Heap Buffer Overflow Leads to DoS

A heap buffer overflow vulnerability (CVE-2026-59691) exists in GStreamer's rfbsrc plugin, allowing a malicious RFB/VNC server to trigger an out-of-bounds heap write in connecting clients, leading to denial of service and potential memory corruption.

GStreamer rfbsrc plugin +2 vulnerability heap-overflow denial-of-service gstreamer linux red-hat cve
1t 1c
high advisory

CVE-2026-4275 - The Divi Torque Lite - Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to CSRF

The Divi Torque Lite plugin for WordPress, in versions up to 4.2.3, is vulnerable to Cross-Site Request Forgery (CVE-2026-4275), allowing an unauthenticated attacker to exploit inadequate nonce verification on the /install_plugin and /activate_plugin REST API endpoints to install arbitrary WordPress plugins, potentially leading to remote code execution or further system compromise.

Divi Torque Lite plugin for WordPress web vulnerability wordpress csrf cve
1r 1t 1c
high advisory

CVE-2026-14372 - The Bit Form WordPress Plugin Arbitrary File Deletion

The Bit Form WordPress plugin (versions up to 3.1.1) is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files like wp-config.php, potentially leading to remote code execution.

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress wordpress plugin vulnerability web rce file-deletion
3t 1c
high advisory

rclone: Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in rclone to gain unauthorized capabilities, allowing them to read and write arbitrary files on the system, disclose sensitive information, and bypass existing security mechanisms, potentially leading to data compromise or system integrity issues.

rclone vulnerability data-exfiltration impact
5t
high advisory

GitLab: Multiple Vulnerabilities

Multiple vulnerabilities in GitLab allow a remote, authenticated attacker to execute arbitrary code, perform Cross-Site Scripting (XSS), manipulate data, or disclose sensitive information.

GitLab vulnerability web-application rce xss data-exfiltration
3t
high advisory

CVE-2026-1989: Authorization Bypass in PAVO Pay through User-Controlled Key

CVE-2026-1989 describes a high-severity authorization bypass vulnerability affecting PAVO Financial Technology Solutions Inc.'s PAVO Pay, allowing attackers to exploit trusted identifiers via a user-controlled key to gain unauthorized access or escalate privileges within the system.

PAVO Pay authorization-bypass vulnerability financial-services web-application cve
3t 1c
critical advisory

CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE

The Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.

Blocksy Companion plugin +3 web vulnerability arbitrary-file-upload wordpress
2t 1c
medium threat

MailPit: Multiple Vulnerabilities Lead to Denial of Service

Multiple vulnerabilities in MailPit allow an attacker to perform a Denial of Service attack against the application, leading to disruption of service for users.

exploited MailPit denial-of-service vulnerability
1t
high advisory

Juniper JUNOS and JUNOS Evolved: Multiple Critical Vulnerabilities

Multiple vulnerabilities exist in Juniper JUNOS, JUNOS Evolved, and various Juniper network device series (EX, MX, QFX, SRX), allowing an attacker to achieve denial of service, disclose sensitive information, execute arbitrary code, or trigger undefined system behavior.

JUNOS +5 network vulnerability denial-of-service rce information-disclosure
2t
high advisory

IBM Operational Decision Manager: Multiple Vulnerabilities Reported

Multiple critical vulnerabilities in IBM Operational Decision Manager allow an attacker to achieve arbitrary code execution, elevate privileges, perform denial of service attacks, disclose information, manipulate files, and bypass security measures.

IBM Operational Decision Manager bsi vulnerability rce privilege-escalation denial-of-service data-exfiltration impact defense-evasion
4t
medium advisory

Wazuh Denial of Service Vulnerability

A vulnerability in Wazuh allows a remote, authenticated attacker to perform a denial of service attack, which could disrupt the availability of the Wazuh platform.

Wazuh denial-of-service vulnerability
1t
medium threat

Multiple Vulnerabilities in Red Hat Enterprise Linux Components libsolv and aardvark-dns

Multiple vulnerabilities in Red Hat Enterprise Linux components libsolv and aardvark-dns could allow an attacker to perform a Denial of Service attack, manipulate data, or disclose confidential information.

exploited Red Hat Enterprise Linux +2 vulnerability linux red-hat dos data-manipulation data-leak
3t
high advisory

QEMU and libvirt: Multiple Vulnerabilities

Multiple vulnerabilities exist in QEMU and libvirt, which can be exploited by a local attacker to disclose sensitive information and bypass security mechanisms, potentially leading to privilege escalation.

QEMU +1 vulnerability linux virtualization defense-evasion privilege-escalation collection
1t
medium advisory

Red Hat Enterprise Linux: Golang Component Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in Golang components within Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a Denial of Service attack, leading to service disruption.

Red Hat OpenShift +2 vulnerability denial-of-service red-hat linux
1t
high advisory

CVE-2026-8848: Popup Maker WordPress Plugin Authorization Bypass Leading to RCE

An authorization bypass vulnerability, CVE-2026-8848, exists in the Popup Maker WordPress plugin versions up to and including 1.22.0, allowing authenticated attackers with editor-level access or higher to install and activate arbitrary plugins from a controlled URL, which leads to remote code execution, provided a valid Popup Maker Pro license is active and the Pro version is not yet installed.

Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin <= 1.22.0 wordpress web-exploitation vulnerability rce authorization-bypass
1r 2t 1c
high advisory

CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader

CVE-2026-14191 describes an out-of-bounds heap write vulnerability in WinRAR and UnRAR when processing RAR5 recovery volumes (.rev), allowing an unauthenticated attacker to achieve remote code execution on a victim's system by tricking a user into opening a specially crafted archive.

WinRAR +1 cve vulnerability archive client-side windows
1c
high threat

CVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer Overflow

A heap buffer overflow vulnerability, identified as CVE-2026-55999, has been discovered in the xorg-server and xwayland components, specifically within the glamor font atlas functionality, affecting systems using these display servers and potentially leading to arbitrary code execution or denial of service.

exploited xorg-server +1 cve vulnerability heap-overflow linux xorg xwayland
1c
high threat

CVE-2026-38968: ntopng Predictable Session Identifier Vulnerability Leading to Session Hijacking

CVE-2026-38968 affects ntopng versions up to 6.6, enabling session hijacking through predictable session identifiers generated with weak time-seeded pseudo-randomness in `src/HTTPserver.cpp`, allowing attackers to gain unauthorized access to legitimate user sessions.

exploited ntopng through 6.6 session-hijacking vulnerability ntopng network-monitoring
1c
medium advisory

CVE-2026-59999: OpenSSH sshd Configuration Bypass via PermitTunnel

A logic error in OpenSSH's sshd daemon before version 10.4 allowed the PermitTunnel configuration to take precedence over DisableForwarding=yes, leading to unintended SSH tunnel establishment and potential unauthorized network access through the tunnel feature.

OpenSSH ssh vulnerability configuration-bypass linux macos
1c
medium threat

CVE-2026-59995: OpenSSH SFTP Arbitrary File Placement Vulnerability

CVE-2026-59995 describes a vulnerability in the OpenSSH sftp client, specifically versions before 10.4, that allows an attacker to control the location of downloaded files when a user executes 'sftp server:/path .' against an attacker-controlled server, potentially leading to arbitrary file placement and subsequent system compromise.

exploited OpenSSH sftp < 10.4 vulnerability client-side arbitrary-file-placement openssh sftp
1c
medium advisory

CVE-2026-59996: OpenSSH scp File Placement Vulnerability

CVE-2026-59996 details a vulnerability in OpenSSH's `scp` utility, allowing a remote attacker to cause a copied file to be placed in a parent directory of the intended destination during a remote-to-remote transfer, potentially leading to unintended file system modification.

OpenSSH before 10.4 vulnerability scp openssh linux macos
1c
medium advisory

OpenSSH internal-sftp Vulnerability (CVE-2026-59997) Allows Security Property Bypass

CVE-2026-59997 describes a vulnerability in the internal-sftp component of OpenSSH's sshd service, affecting versions before 10.4, where the service only processes the first nine command-line arguments, potentially leading to a bypass of security controls or unintended configuration.

OpenSSH sshd internal-sftp < 10.4 vulnerability openssh sshd sftp linux macos
1c
high threat

CVE-2026-53359: KVM x86 Use-After-Free in Shadow Paging

CVE-2026-53359 is a high-severity use-after-free vulnerability affecting the KVM virtualization component on x86 architectures within the Linux kernel, stemming from an unexpected role in shadow paging, which could lead to host system compromise.

exploited PoC Linux kernel +3 linux kernel kvm virtualization vulnerability use-after-free cve
1c 6i updated
medium advisory

Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification

Multiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.

Joomla cms vulnerability xss web-vulnerability data-integrity
1t
medium advisory

CVE-2026-47241: Net::IMAP Denial of Service Vulnerability

A Denial of Service vulnerability, identified as CVE-2026-47241, exists in the Net::IMAP library due to incomplete raw argument validation, potentially allowing an attacker to cause an application crash or unresponsiveness.

Net::IMAP denial-of-service vulnerability imap
1c
medium advisory

Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover

The Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.

Divi Form Builder plugin <= 5.1.8 wordpress plugin vulnerability web-application account-takeover missing-authorization
3t 1c
high threat

CVE-2026-15137: Remote SQL Injection in code-projects Interview Management System

A critical SQL injection vulnerability (CVE-2026-15137) has been identified in code-projects Interview Management System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in the '/inc/classes/View.php' file, leading to arbitrary SQL query execution and potential data compromise; a public exploit is available.

exploited Interview Management System 1.0 sql-injection webserver vulnerability cve code-projects interview-management-system
1r 2t 1c 6i
high advisory

CVE-2026-60105: Monsta FTP SSRF Vulnerability Leading to Credential Disclosure

An unauthenticated attacker can exploit CVE-2026-60105, a Server-Side Request Forgery vulnerability in Monsta FTP before 2.14.5, by leveraging an incomplete IP blocklist check with IPv4-mapped IPv6 addresses to force the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, potentially enabling retrieval of cloud instance metadata credentials.

Monsta FTP < 2.14.5 server-side-request-forgery vulnerability web-application credential-access
1r 2t 1c
critical advisory

Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE

Joro's default proxy mode (versions ≤ v1.1.0) is vulnerable to unauthenticated remote code execution (CVE-2026-53649) via a local API on `127.0.0.1:9090` that allows cross-origin JavaScript to upload a malicious native plugin and trigger a system restart, leading to RCE as the operator's user from a single page visit.

Joro rce web-exploitation vulnerability javascript cross-origin cors
2r 5t 1i
high advisory

DSpace RCE via Velocity Templates (CVE-2026-49832)

DSpace versions 8.0 through 8.3, 9.0 through 9.2, and 10.0-rc1 are vulnerable to Remote Code Execution (RCE) via Velocity Templates used for COAR Notify/LDN messages, allowing an attacker with DSpace administrator credentials to execute direct Java code using reflection, a high-impact vulnerability that can be chained with a related path traversal attack (GHSA-9qm4-rh6w-pq5x).

DSpace +7 rce web-application vulnerability
1t
high advisory

`lxml_html_clean` `javascript:` URL Bypass via `xlink:href` (CVE-2026-49825)

The `lxml_html_clean.Cleaner` Python library, and the `lxml.html.clean` module in `lxml`, fails to strip `javascript:`, `vbscript:`, and `data:` URLs from namespaced attributes like `xlink:href` when configured with `safe_attrs_only=False`. This vulnerability, identified as CVE-2026-49825, is a form of stored Cross-Site Scripting (XSS) that allows malicious JavaScript to bypass sanitization, enabling client-side code execution if an application processes and renders untrusted HTML containing such payloads.

lxml <= 6.1.0 +2 xss vulnerability python web-application html-sanitization
2t
high advisory

Zalando Skipper OPA Policy Bypass via Chunked Encoding

A critical vulnerability in `zalando/skipper`'s OpenPolicyAgent integration, tracked as GHSA-659f-rgp5-w4wf, allows attackers to bypass `opaAuthorizeRequestWithBody` policies using HTTP/1.1 `Transfer-Encoding: chunked` or HTTP/2 requests lacking a `content-length` pseudo-header, leading to unauthorized access to upstream services with uninspected payloads.

skipper vulnerability api-gateway security-bypass opa network
1r 1t
high advisory

CVE-2026-60104 - Bitwarden Server Vault Key Disclosure and Account Takeover

A low-privileged Bitwarden organization member can exploit CVE-2026-60104 in Bitwarden Server versions prior to 2026.6.0, which allows an attacker to obtain another user's vault key and access token by creating a Trusted Device Encryption authentication request bound to an attacker-controlled public key, leading to account takeover.

Bitwarden Server < 2026.6.0 vulnerability cve account-takeover credential-access data-disclosure bitwarden
7t 1c
medium advisory

CVE-2026-59803: rpcx Denial-of-Service Vulnerability

A denial-of-service vulnerability (CVE-2026-59803) in rpcx through version 1.9.3 allows an unauthenticated attacker to trigger out-of-memory conditions and service unavailability by sending a small, compressed message that expands to gigabytes of memory during decompression.

rpcx <= 1.9.3 denial-of-service vulnerability rpcx go-lang
1t 1c
high advisory

CVE-2026-59802 - PasswordPusher Data URI Scheme Vulnerability Leading to Client-Side JavaScript Execution

PasswordPusher versions prior to 2.8.1 contain a client-side vulnerability (CVE-2026-59802) due to insufficient validation of URL push payloads, allowing attackers to embed malicious data URI schemes that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.

PasswordPusher vulnerability web-application client-side javascript credential-theft phishing
3t 1c
high advisory

Progress MOVEit Transfer Critical Security Advisory (AV26-678)

Progress Software has issued a critical security advisory (AV26-678) detailing multiple vulnerabilities, including CVE-2026-10699, CVE-2026-10698, and CVE-2026-11903, affecting various versions of its MOVEit Transfer product, necessitating immediate patching to prevent potential exploitation.

MOVEit Transfer +3 vulnerability cve data-exfiltration critical-vulnerability moveit
3c
high advisory

Juniper Networks Releases Security Advisories for Multiple Vulnerabilities, Including Heap Buffer Overflow and Memory Leak

Juniper Networks has released security advisories to address multiple vulnerabilities across several products, including Juniper cRPD, CTPView, Network Director, Junos OS, Junos OS Evolved, Junos OS on MX Series with SPC3 and SRX Series, and Junos Space, with key vulnerabilities like a heap buffer overflow (CVE-2020-7450) and a memory leak (CVE-2026-33799) potentially leading to arbitrary code execution or denial of service.

Juniper cRPD +6 vulnerability network-device juniper patch-management
2t 1c
high advisory

CVE-2026-59261 - OpenClaw Credential Exposure via Workspace Dotenv Files

A critical vulnerability, CVE-2026-59261, in OpenClaw before version 2026.5.28, allows attackers with lower-trust access to configured input paths to expose sensitive provider credentials by leveraging workspace dotenv files that override legitimate configurations, leading to unauthorized access to sensitive data.

OpenClaw credential-exposure vulnerability configuration-error
1t 1c
high advisory

CVE-2026-29009 - U-Boot Buffer Overflow in nfs_readlink_reply()

A buffer overflow vulnerability exists in the nfs_readlink_reply() function of U-Boot versions up to 2026.04-rc3 when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to exploit it by sending multiple relative symlink targets, each approximately 1100 bytes long, to overflow the 2048-byte nfs_path_buff, corrupting adjacent BSS variables and potentially leading to memory corruption and control over the NFS client's state machine.

U-Boot <= 2026.04-rc3 buffer-overflow vulnerability firmware nfs u-boot
1c
high advisory

CVE-2026-29008: U-Boot Integer Underflow Leads to Bootloader Crash

An integer underflow vulnerability (CVE-2026-29008) in U-Boot's `tcp_rx_state_machine()` function allows a network-adjacent attacker to crash the bootloader by sending a crafted TCP SYN+ACK packet, potentially preventing device boot and leading to memory corruption.

U-Boot denial-of-service vulnerability bootloader network embedded-systems
1t 1c
medium threat

CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)

An XML injection vulnerability (CVE-2026-0284) in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.

exploited PAN-OS 12.1 +17 vulnerability xml-injection pan-os network-device
3t
medium threat

CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI

A command injection vulnerability, CVE-2026-0286, in the management plane of Palo Alto Networks PAN-OS software allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series) devices, potentially leading to high system compromise.

exploited PAN-OS 12.1 +6 vulnerability command-injection pan-os firewall network-device
3t
low threat

CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass

An unauthenticated attacker can exploit CVE-2026-0280, an IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS software, to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.

exploited PAN-OS +5 palo-alto-networks firewall vulnerability ipv6 policy-bypass cve
1t
medium advisory

CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface

A server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-0285, exists in the management web interface of Palo Alto Networks PAN-OS software, allowing an authenticated administrator with network access to make unauthorized requests from the firewall to internal services, potentially leading to information disclosure or further network compromise.

PAN-OS < 12.1.4-h8 +17 server-side-request-forgery ssrf vulnerability pan-os palo-alto-networks network-device
3t
low advisory

CVE-2026-0276: Palo Alto Networks Cortex XDR Broker VM Privilege Escalation

A local privilege escalation vulnerability, CVE-2026-0276, in Palo Alto Networks Cortex XDR Broker VM allows a locally authenticated low-privileged user to gain root access, potentially leading to compromise of the security solution itself.

Cortex XDR Broker VM privilege-escalation vulnerability palo-alto-networks cortex-xdr
1t
high threat

CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent

Palo Alto Networks has disclosed multiple buffer overflow vulnerabilities (CVE-2026-0288) in their PAN-OS User-ID Terminal Server Agent (TSA) component, which an unauthenticated attacker with network access can exploit by sending specially crafted network traffic to cause a denial of service (DoS) or potentially achieve arbitrary code execution, affecting various versions of PAN-OS, Cloud NGFW, and Prisma Access if the TSA is exposed to untrusted networks.

exploited Cloud NGFW +6 network vulnerability cve palo-alto-networks denial-of-service remote-code-execution
3t
low threat

CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities

Palo Alto Networks has disclosed multiple low-severity cross-site scripting (XSS) vulnerabilities, CVE-2026-0279, in PAN-OS software affecting the User-ID Authentication Portal, GlobalProtect gateway/portal features, and Clientless VPN, which could allow a malicious unauthenticated user to inject and execute JavaScript in a victim's browser.

exploited PAN-OS 12.1 +8 xss vulnerability firewall network-device web-application
2t
medium threat

CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows

CVE-2026-0278 describes multiple protection mechanism failures in the Prisma Access Agent's Data Loss Prevention (DLP) component for Windows, allowing a local user to bypass DLP policy enforcement controls and exfiltrate sensitive data on affected versions prior to 26.2.1.

exploited Prisma Access Agent < 26.2.1 cve vulnerability dlp bypass windows defense-evasion
1t
medium threat

CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS

An improper certificate validation vulnerability (CVE-2026-0277) in the Prisma Access Agent for iOS, affecting versions prior to 26.2.1, enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic, leading to potential compromise of data confidentiality and integrity.

exploited Prisma Access Agent vulnerability mitm ios vpn palo-alto-networks
1t
medium threat

CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing

Multiple denial of service vulnerabilities, tracked as CVE-2026-0287, in Palo Alto Networks PAN-OS software allow an unauthenticated attacker to cause a DoS condition by sending specially crafted network traffic, potentially forcing the firewall into maintenance mode.

exploited PAN-OS 12.1 +6 denial-of-service vulnerability network firewall palo-alto-networks
1t
low threat

CVE-2026-0282 PAN-OS: Unauthenticated File Deletion Vulnerability

An unauthenticated attacker with network access to the management web interface of Palo Alto Networks PAN-OS software can exploit CVE-2026-0282, a file deletion vulnerability, to delete files from a temporary directory, impacting PA-Series and VM-Series firewalls, and Panorama appliances.

exploited PAN-OS 12.1 +6 vulnerability pan-os network-device file-deletion
high advisory

CVE-2026-56776 - n8n Authorization Bypass via Workflow Test Run Endpoint

An authenticated user can exploit CVE-2026-56776, an authorization bypass vulnerability in n8n versions prior to 1.123.55, 2.25.7, and 2.26.2, by sending a POST request to the `/workflows/{workflowId}/test-runs/new` endpoint to trigger unauthorized workflow execution, leading to unintended outbound API calls, data mutations, and other side effects in connected downstream systems.

n8n authorization-bypass web-application vulnerability privilege-escalation
1r 3t 1c
high advisory

CVE-2026-56297 - FreeRDP Use-After-Free Vulnerability Leading to RCE/DoS

A use-after-free vulnerability (CVE-2026-56297) in the FreeRDP client before version 3.22.0 allows a malicious RDP server to achieve remote code execution or denial of service on connecting clients by triggering a race condition through concurrent DYNVC_DATA and DYNVC_CLOSE messages.

FreeRDP < 3.22.0 vulnerability RCE DoS FreeRDP client-side
2t 1c
medium advisory

CVE-2026-56250: Capgo R2 Bundle Object Deletion via Mutable r2_path

A critical vulnerability, CVE-2026-56250, in Capgo before version 12.128.2 allows an authenticated attacker with upload-scoped API keys to manipulate the app_versions.r2_path field via PostgREST, leading to arbitrary R2 bundle object deletion and denial of service.

Capgo < 12.128.2 vulnerability denial-of-service cloud web-application
2t 1c 2i
high advisory

CVE-2026-56246 - Capgo Broken Access Control in Organization Management API

Capgo versions prior to 12.128.2 contain a broken access control vulnerability (CVE-2026-56246) in their organization management API where a scoped API key inherits the full permissions of its owner-user, allowing an attacker to perform destructive operations against unauthorized organizations, bypassing intended scope and leading to privilege escalation and impact.

Capgo < 12.128.2 vulnerability privilege-escalation data-destruction impact cloud
3t 1c
high advisory

CVE-2026-56226 - Capgo Unauthenticated Data Exposure via Supabase PostgREST RPC

CVE-2026-56226 details a high-severity vulnerability in Capgo versions prior to 12.128.2 that exposes a Supabase PostgREST RPC function, `public.get_orgs_v6`, to unauthenticated attackers, allowing them to retrieve sensitive user organization membership and PII by supplying an arbitrary user UUID.

Capgo vulnerability api-exploitation data-exfiltration webserver supabase
1r 2t 1c
high advisory

CVE-2026-5356: LatePoint WordPress Plugin Improper Input Validation Leading to Arbitrary Payments

An improper input validation vulnerability (CVE-2026-5356) in the LatePoint - Calendar Booking Plugin for Appointments and Events for WordPress, versions up to and including 5.4.0, allows unauthenticated attackers to exploit its Stripe Connect payment processor by supplying a previously succeeded PaymentIntent ID, resulting in the processing of arbitrary payments.

LatePoint – Calendar Booking Plugin for Appointments and Events wordpress plugin vulnerability webserver cve
2t 1c
high advisory

CVE-2026-6230: Tainacan WordPress Plugin SQL Injection Vulnerability

An unauthenticated attacker can exploit CVE-2026-6230, a time-based blind SQL Injection vulnerability in the Tainacan plugin for WordPress (versions up to and including 1.0.3) via the 'geoquery' parameter, to append arbitrary SQL queries and exfiltrate sensitive information from the database due to insufficient input validation.

Tainacan plugin wordpress sql-injection webserver vulnerability cve
1r 1t 1c
high advisory

CVE-2026-6854 - WordPress My Calendar Plugin Time-Based Blind SQL Injection

A time-based blind SQL Injection vulnerability exists in the My Calendar - Accessible Event Manager plugin for WordPress, affecting all versions up to and including 3.7.8. This flaw, located in the 'mc_auth' parameter, stems from insufficient input sanitization and improper SQL query preparation, allowing unauthenticated attackers to inject additional SQL queries to extract sensitive information from the underlying database.

My Calendar - Accessible Event Manager plugin <= 3.7.8 wordpress sql-injection vulnerability web-application collection initial-access
1r 2t 1c
high advisory

CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference

Authenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.

WCFM Membership – WooCommerce Memberships for Multivendor Marketplace < 2.11.10 wordpress web vulnerability idor privilege-escalation
2t 1c
high advisory

Multiple Vulnerabilities in IBM Operational Decision Manager

Multiple vulnerabilities in IBM Operational Decision Manager can be exploited by a remote, unauthenticated attacker, allowing them to bypass security restrictions, achieve remote code execution, and cause a denial of service condition.

IBM Operational Decision Manager vulnerability rce dos ibm security-bypass
4t
high threat

Red Hat Enterprise Linux (389-ds-base): Multiple Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in Red Hat Enterprise Linux and the 389-ds-base component allow a remote, authenticated attacker to execute arbitrary code or cause a Denial-of-Service condition.

exploited Red Hat Enterprise Linux +1 linux vulnerability code-execution denial-of-service red-hat
2t
high advisory

X.Org X11 and Xwayland Multiple Vulnerabilities Allowing Code Execution and DoS

Multiple vulnerabilities in X.Org X11 and Xwayland allow an attacker to cause a denial of service or potentially execute arbitrary program code, posing a significant risk to systems utilizing these display server implementations, potentially leading to system instability or full compromise.

X.Org X11 +1 vulnerability linux x.org x11 xwayland denial-of-service code-execution
2t
high advisory

Multiple Vulnerabilities in ESRI ArcGIS Allow Privilege Escalation and Security Bypass

Multiple unpatched vulnerabilities in ESRI ArcGIS allow a remote, anonymous attacker to bypass security measures or gain elevated user rights, potentially leading to unauthorized access and privilege escalation within affected systems.

ArcGIS vulnerability esri privilege-escalation defense-evasion
3t
high advisory

IBM WebSphere Application Server: Authenticated Remote Action Execution Vulnerability

A vulnerability in IBM WebSphere Application Server allows a remote, authenticated attacker to execute arbitrary actions on the server, potentially leading to a compromise of the host system.

WebSphere Application Server websphere vulnerability rce ibm server authenticated-access
1t
high advisory

dpkg: Vulnerability Enables Information Disclosure

A remote, unauthenticated attacker can exploit a vulnerability in the dpkg package management system to disclose information from the affected system, potentially exposing sensitive data or system details to unauthorized parties.

dpkg information-disclosure linux package-manager vulnerability
1t
high advisory

ILIAS: Multiple Vulnerabilities Identified by BSI

An attacker can leverage several vulnerabilities within the ILIAS e-learning platform to bypass security controls, disclose sensitive information, and execute Cross-Site Scripting (XSS) attacks, potentially leading to unauthorized access, data compromise, and client-side code execution.

ILIAS web-application vulnerability xss information-disclosure
2t
low threat

GStreamer (webrtcbin): Vulnerability Allows Circumvention of Security Measures

A remote, unauthenticated attacker can exploit a low-severity vulnerability within the GStreamer webrtcbin component to bypass existing security measures, potentially allowing for the circumvention of protective mechanisms without further details on specific impact.

exploited GStreamer vulnerability security-bypass webrtc
1t
medium advisory

Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability

A remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.

JBoss Enterprise Application Platform xss web-application jboss vulnerability red-hat
1t
critical advisory

Better Auth OAuth Refresh Token Replay via Missing Client Authentication (CVE-2026-53512)

The legacy `oidcProvider` and `mcp` plugins in the `better-auth` library versions prior to 1.6.11 are vulnerable to CVE-2026-53512, an OAuth refresh-token replay attack where the plugins fail to verify the `client_secret` of confidential clients during the `refresh_token` grant, allowing an attacker who obtains a valid `refresh_token` and `client_id` to indefinitely mint new access tokens and impersonate the client for unauthorized resource access.

better-auth oauth authentication-bypass vulnerability web
1t
high advisory

CVE-2026-59708: Ghostfolio Unauthenticated Portfolio Data Exposure

An authorization bypass vulnerability (CVE-2026-59708) in Ghostfolio's GET /api/v1/public/:accessId/portfolio endpoint allows unauthenticated attackers with a private access ID to retrieve sensitive financial portfolio data, including holdings and performance metrics, due to missing `granteeUserId` filtering validation.

ghostfolio <= 3.6.0 vulnerability api authorization-bypass data-exposure webserver
3t 1c
high advisory

CVE-2026-57851 — MSI Feature Manager Kernel Driver Local Privilege Escalation

A local privilege escalation vulnerability (CVE-2026-57851) exists in the MSI Feature Manager's KernCoreLib64.sys kernel driver that allows any local user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without requiring administrator privileges, enabling manipulation of kernel objects, tampering with kernel-mode callbacks, bypassing Protected Process Light, and disabling security software.

MSI Feature Manager privilege-escalation vulnerability windows driver-vulnerability
1t 1c
high advisory

CVE-2026-13020: Weak Password Recovery in Esri Portal for ArcGIS Leading to Account Takeover

A critical vulnerability (CVE-2026-13020) exists in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes, where a weak password recovery mechanism allows a remote, unauthorized attacker to assume ownership of a user's account by exploiting this flaw.

Portal for ArcGIS <= 12.1 vulnerability web-application account-takeover esri
2t 1c
critical advisory

Critical Unauthenticated API Access in Esri Portal for ArcGIS (CVE-2026-13019)

A critical missing authentication vulnerability (CVE-2026-13019) in Esri Portal for ArcGIS versions 12.1 and earlier allows a remote, unauthenticated attacker to access unprotected critical APIs, impacting deployments on Windows, Linux, and Kubernetes environments.

Portal for ArcGIS 12.1 and earlier vulnerability esri arcgis unauthenticated-access api-security rce
1t 1c
high advisory

Hitachi Energy PROMOD V Insecure HTTP Transmission Vulnerability (CVE-2026-10763)

Hitachi Energy PROMOD V versions 1.0.10 and prior are affected by CVE-2026-10763, an insecure HTTP transmission vulnerability that allows attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access, impacting the energy sector globally.

PROMOD V <= 1.0.10 ics ot vulnerability http-insecurity data-in-transit cve
2t 1c
high threat

Multiple Vulnerabilities in Digi International PortServer TS and Digi One SP IA Devices

Multiple vulnerabilities, including CVE-2026-12352 (incorrect authorization) and CVE-2026-12948 (stored cross-site scripting), affect Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices with firmware prior to 2025, allowing unauthenticated bypass, access to restricted resources, credential acquisition, and client-side script execution in critical infrastructure environments.

exploited PortServer TS +3 ics ot network webserver vulnerability authentication-bypass xss critical-manufacturing +3
2t 2c
critical threat

Critical Vulnerabilities in Hydro-Québec Le Circuit Electrique Charging Station Backend

Multiple critical vulnerabilities, including improper access control (CVE-2026-20744), improper restriction of excessive authentication attempts (CVE-2026-42952), and insufficient session expiration (CVE-2026-44383), affect Hydro-Québec Le Circuit Electrique charging station backend versions prior to June 2026, which if exploited could lead to privilege escalation or denial-of-service impacting critical transportation infrastructure.

exploited Hydro-Québec Le Circuit Electrique charging station backend ics vulnerability denial-of-service privilege-escalation transportation
4t
high advisory

Public Exploit for MCPJam Inspector Remote Code Execution (EDB-52625)

A public exploit (EDB-52625) has been published for the web application MCPJam Inspector, demonstrating a Remote Code Execution vulnerability, significantly elevating the risk for unpatched systems and allowing attackers to execute arbitrary code.

MCPJam Inspector webapps rce exploit-db vulnerability
2t
high advisory

ProtonVPN v4.4.1 Unquoted Service Path Vulnerability with Public Exploit

A local privilege escalation vulnerability (Unquoted Service Path) in ProtonVPN v4.4.1 has a public exploit, allowing a local attacker to execute arbitrary code with 'LocalSystem' privileges by placing a malicious executable in a specific directory, which is then launched by the vulnerable 'ProtonVPN Wireguard' service upon startup or restart.

ProtonVPN v4.4.1 privilege-escalation windows vulnerability
1r 1t
high threat

Critical XSS Vulnerability in Synacor Zimbra Collaboration

A critical cross-site scripting (XSS) vulnerability, affecting Synacor Zimbra Collaboration versions prior to 10.1.19, allows an attacker to achieve remote indirect code injection, potentially leading to session hijacking, data exfiltration, or defacement.

exploited Zimbra Collaboration < 10.1.19 xss web-application vulnerability zimbra mail-server
1t
medium advisory

Multiple Vulnerabilities in Postfix Mail Server

Multiple vulnerabilities have been identified in various versions of the Postfix mail server, potentially allowing an attacker to cause a denial of service (DoS) and other unspecified security issues, requiring immediate patching across affected installations.

Postfix < 3.5.26 +6 vulnerability mail-server postfix dos patch
1t 1i
high advisory

Multiple Vulnerabilities in SPIP CMS Lead to Data Confidentiality Loss

Multiple vulnerabilities, including SQL injection and indirect remote code injection (XSS), were discovered in SPIP Content Management System versions prior to 4.4.16, allowing an attacker to compromise data confidentiality and execute malicious code in user browsers.

SPIP vulnerability web-application sqli xss cms
3t
medium advisory

Multiple Vulnerabilities in PHP (CVE-2026-12184, CVE-2026-14355)

Multiple critical vulnerabilities (CVE-2026-12184, CVE-2026-14355) have been discovered in various PHP versions, allowing an attacker to cause an unspecified security issue, as reported by CERT-FR on July 7, 2026.

PHP 8.2.x +3 vulnerability php web-application server-side
1c
high advisory

New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs

An SSRF protection bypass vulnerability, CVE-2026-33655, in the QuantumNous new-api, affecting versions prior to v0.12.0-alpha.1, allows authenticated users to send requests to internal HTTP services by configuring notification URLs with unresolved hostnames, leading to potential sensitive internal data exposure through timing, errors, or response-dependent behavior.

new-api ssrf api vulnerability bypass web-application
2t
high advisory

CVE-2026-13696: HAVELSAN Liman MYS LDAP Injection Vulnerability

A high-severity LDAP injection vulnerability, tracked as CVE-2026-13696 with a CVSS v3.1 base score of 8.8, affects HAVELSAN Inc.'s Liman MYS versions prior to release.Master.1107, allowing attackers to bypass authentication or exfiltrate sensitive data via improper neutralization of special characters in LDAP queries.

Liman MYS: before release.Master.1107 vulnerability ldap-injection web-application
1c
high threat

CVE-2026-11348: HAVELSAN Liman MYS Cryptographic Signature Bypass Vulnerability

A critical improper verification of cryptographic signature vulnerability, tracked as CVE-2026-11348, in HAVELSAN Inc.'s Liman MYS product allows an unauthenticated attacker to fake the source of data, leading to potential data integrity compromise.

exploited Liman MYS: < release.Master.1107 vulnerability cryptographic-vulnerability liman-mys
1c
high threat

Red Hat Enterprise Linux (perl-HTTP-Daemon): Remote Code Execution Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in the 'perl-HTTP-Daemon' component within Red Hat Enterprise Linux to execute arbitrary program code with the privileges of the affected service, potentially gaining control over the compromised system.

exploited Red Hat Enterprise Linux +1 redhat linux vulnerability rce perl webserver
2t
high advisory

DriveLock On-Premise and Cloud: Multiple Vulnerabilities

Multiple vulnerabilities exist in DriveLock's On-Premise and Cloud solutions, allowing an authenticated remote attacker to disclose sensitive information, execute arbitrary code, and escalate privileges, posing a significant risk to the integrity and confidentiality of systems protected by DriveLock.

DriveLock On-Premise +1 vulnerability privilege-escalation rce information-disclosure drivelock cert-bund
3t
high advisory

CVE-2026-11340 — Missing Authorization in HAVELSAN Liman MYS

A missing authorization vulnerability (CVE-2026-11340) in HAVELSAN Inc. Liman MYS versions prior to release.Master.1107 allows an attacker with low privileges to access functionality not properly constrained by ACLs, leading to high impact on integrity and availability.

Liman MYS vulnerability web-application missing-authorization cve
1t 1c
high advisory

Devolutions Server: Vulnerability Allows Multi-Factor Authentication Bypass

A remote, authenticated attacker can exploit a vulnerability in Devolutions Server to bypass its multi-factor authentication (MFA) security measures, potentially leading to unauthorized access to sensitive data and systems.

Devolutions Server defense-evasion vulnerability server
1t
high advisory

CVE-2026-14474 - SSSD LDAP sudo Provider Privilege Escalation

A vulnerability in SSSD's LDAP sudo provider, CVE-2026-14474, allows an authenticated attacker to achieve root-level privilege escalation by injecting a malicious sudoRole object into any writable LDAP subtree when the `ldap_sudo_search_base` option is not explicitly configured on SSSD-enrolled Linux hosts.

SSSD LDAP sudo provider linux privilege-escalation cve vulnerability
2t 1c
high advisory

CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS

An integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.

GIMP +1 vulnerability rce dos linux heap-overflow
2t 1c
high advisory

Synacor Zimbra Classic Web Client XSS Vulnerability

An unauthenticated remote attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the Synacor Zimbra Classic Web Client, allowing the attacker to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, data theft, or defacement.

Zimbra Classic Web Client xss vulnerability web-application zimbra
1t
medium advisory

Hashicorp Terraform: Information Disclosure Vulnerability

A vulnerability in Hashicorp Terraform allows a remote, authenticated attacker to disclose sensitive information, which could lead to the exposure of confidential data.

Terraform information-disclosure vulnerability hashicorp
1t
high advisory

CVE-2026-8377: Missing Authorization in Armiya GKS Allows Data Collection

A critical Missing Authorization vulnerability (CVE-2026-8377) in Armiya Information Technologies Ltd. Co.'s Access Control System (GKS) before Version 2 allows an unauthenticated or unauthorized attacker to collect sensitive data from common resource locations, leading to unauthorized information disclosure.

Access Control System vulnerability access-control-system missing-authorization data-collection critical-infrastructure
2t 1c
high threat

CVE-2026-5799: Authorization Bypass in Idvlabs Ontime

A high-severity authorization bypass vulnerability (CVE-2026-5799) exists in Idvlabs Software and Consulting Services Inc. Ontime versions through 04052026, allowing an unauthenticated attacker to exploit trusted identifiers by manipulating user-controlled keys, leading to unauthorized access.

exploited Ontime authorization-bypass cve web-application vulnerability
1t 1c
high advisory

CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras

A high-severity vulnerability, CVE-2026-12480, affects the `keras-team/keras` library, enabling an arbitrary HDF5 file read via a virtual dataset bypass, potentially leading to sensitive information disclosure or exfiltration from systems utilizing the library.

keras vulnerability arbitrary-file-read python machine-learning
1c
high advisory

Coder Workspace Agent API Insecure Redirect Handling Allows Cross-Agent File Access and RCE

An authenticated user can exploit insecure redirect handling in the Coder workspace agent API to redirect API requests from their modified agent to a victim's online agent, enabling unauthorized file read/write operations and potential remote command execution across workspace and tenant boundaries.

Coder < v2.34.4 +3 vulnerability rce file-manipulation coder server-side-request-forgery ghsa
2t
high threat

mkfifo: permissions of an existing file are changed after FIFO creation fails

A vulnerability (CVE-2026-35341) exists in the `uu_mkfifo` utility of `uutils coreutils`, affecting versions prior to 0.6.0. When `mkfifo()` fails because the target file already exists, the utility incorrectly proceeds to modify the permissions of the pre-existing file to `0644`. This can inadvertently relax permissions on sensitive owner-only files, such as SSH private keys, making them accessible to other users on the system and potentially enabling unauthorized access or information disclosure. The issue has been patched in PR #10376.

exploited uu_mkfifo +1 vulnerability linux coreutils permissions information-disclosure privilege-escalation
3t 1c
high advisory

9router: Login Brute-Force Protection Bypass via Spoofed X-Forwarded-For Header

The 9router dashboard login rate limiter incorrectly uses the attacker-controlled X-Forwarded-For HTTP header to identify clients, leading to a brute-force protection bypass (CVE-2026-55501) that allows attackers to circumvent the lockout mechanism and conduct unlimited password brute-force attempts to gain administrative access.

9router brute-force rate-limit-bypass x-forwarded-for vulnerability web-application
1r 2t
high advisory

CVE-2026-59713: Leantime OIDC Login CSRF leading to Session Fixation

CVE-2026-59713 identifies a high-severity OIDC login Cross-Site Request Forgery (CSRF) vulnerability in Leantime's verifyState() method, allowing attackers to craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation and log victims into an attacker's session.

Leantime csrf oidc session-fixation web-application vulnerability
3t 1c
high advisory

CVE-2026-25271: Memory Corruption in Qualcomm Snapdragon

A high-severity memory corruption vulnerability (CVE-2026-25271) exists in Qualcomm Snapdragon products due to improper handling of asynchronous input parameters, enabling a local, low-privileged attacker to achieve high impact on confidentiality, integrity, and availability without user interaction.

Snapdragon Compute +22 vulnerability memory-corruption qualcomm snapdragon cve
1c
high advisory

Coder AI Bridge Proxy TLS Certificate Verification Bypass (CVE-2026-55436)

The AI Bridge Proxy (`aibridgeproxyd`) in Coder's platform, when running in its default configuration without an upstream proxy, failed to perform TLS certificate verification for outbound HTTPS connections to the Coder server (CVE-2026-55436), allowing an on-path attacker to intercept sensitive data including Coder session tokens, user-supplied API keys, and full request/response bodies.

AI Bridge Proxy +2 vulnerability man-in-the-middle tls data-exfiltration
3t
high advisory

Coder `coder open app` Session Token Leakage Vulnerability (CVE-2026-55431)

A high-severity vulnerability, CVE-2026-55431, in the Coder CLI's `coder open app` command allows malicious workspace template authors to exfiltrate user session tokens via crafted external app URLs, leading to full account impersonation.

coder/coder/v2 +3 credential-access vulnerability cli-exploitation token-leakage coder
1t 1i
high advisory

Coder's Workspace App Vulnerability Allows Cross-Workspace Agent Rebinding

A critical authorization bypass vulnerability (CVE-2026-55429) exists in Coder's workspace application, allowing an attacker with template authorship or external provisioner access to rebind a victim's workspace app to their own agent, enabling them to proxy and compromise the victim's IDE and terminal sessions.

Coder +3 vulnerability privilege-escalation application
4t
high advisory

Coder Tailnet Vulnerability (CVE-2026-55428) Leads to Route Hijacking

A high-severity vulnerability (CVE-2026-55428) in Coder's tailnet coordinator allows a malicious workspace agent to hijack network routes by advertising arbitrary `AllowedIPs` prefixes, enabling interception and spoofing of web terminal and workspace application traffic.

Coder >= 2.34.0, < 2.34.2 +3 vulnerability cve route-hijacking network-attack supply-chain
1t
high advisory

OpenRemote Incomplete Fix for XXE in KNXProtocol Leads to Arbitrary File Read (CVE-2026-54640)

An incomplete fix for CVE-2026-40882 in OpenRemote's KNXProtocol module (specifically in versions <= 1.24.1 of the agent module) allows authenticated users to perform an XML External Entity (XXE) injection, enabling arbitrary file read from the server's filesystem, including sensitive configuration files and potentially leading to server-side request forgery (SSRF) against cloud metadata endpoints or internal services, without requiring administrator access.

OpenRemote Agent xxe arbitrary-file-read ssrf openremote iot vulnerability incomplete-fix
4t 1c 3i
high advisory

Coder OIDC email_verified Type Coercion Bypass (CVE-2026-55076)

A vulnerability, CVE-2026-55076, in Coder's OpenID Connect (OIDC) authentication callback allowed an attacker to bypass email verification due to improper Go boolean type assertion of the `email_verified` claim, leading to full account takeover for existing user accounts.

Coder < 2.29.17 +3 account-takeover oidc vulnerability web-application
3t
high advisory

Coder OIDC Account Takeover Vulnerabilities (CVE-2026-55075)

Two critical flaws in Coder's OIDC login mechanism, CVE-2026-55075, allow an attacker to achieve account takeover by exploiting email-based user matching without proper IdP subject checks and bypassing the `email_verified` claim, leading to full access to victim workspaces and resources.

Coder < 2.29.17 +3 oidc account-takeover vulnerability coder cloud
2t
high advisory

Coder SSH Config Injection Vulnerability (CVE-2026-55427)

A malicious or compromised Coder server can exploit CVE-2026-55427 to inject unsanitized SSH configuration values via `coder config-ssh` into developer workstations, enabling arbitrary code execution on client machines.

Coder +3 ssh configuration-injection rce supply-chain developer-tools vulnerability
1t
high advisory

OpenRemote Cross-Realm User Information Disclosure (CVE-2026-54641)

A high-severity vulnerability (CVE-2026-54641) in OpenRemote's `UserResourceImpl.java` allows a realm administrator in a multi-tenant deployment to perform cross-realm user enumeration and privilege-level reconnaissance by reading sensitive user information (profile, client roles, and realm roles) from any other realm, including the master realm, due to missing authorization checks in specific REST API endpoints.

openremote-manager OpenRemote Vulnerability API Information Disclosure Access Control Multi-tenant
1r 2t
high advisory

Langroid Tool Invocation Bypass via Unverified User Messages (CVE-2026-54771)

A high-severity vulnerability, CVE-2026-54771, in Langroid applications allows untrusted users to directly invoke internal tools via raw JSON payloads, even when these tools are configured not to be used by the LLM, enabling malicious actors to bypass security controls and execute sensitive operations like file read/write, database queries, or access to internal orchestration tools.

langroid vulnerability rce logic-error python
1t
critical advisory

Decompress Archive Extraction Vulnerability Allows Path Traversal and Privilege Escalation (CVE-2026-53486)

A critical vulnerability (CVE-2026-53486) in the `@xhmikosr/decompress` and unmaintained `decompress` npm packages allows attackers to craft malicious archives that, upon extraction, can write or read files outside the target directory, expose arbitrary file contents, or create setuid/setgid files leading to arbitrary file system modification, information disclosure, and potential privilege escalation.

@xhmikosr/decompress +1 vulnerability path-traversal privilege-escalation npm supply-chain
2t
high advisory

Scriban Template Engine Vulnerability: Arbitrary CLR Property Writes (Mass Assignment & Setter Bypass)

The Scriban templating engine, specifically its `TypedObjectAccessor`, allows template code to write to arbitrary CLR object properties, including those with `private set`, `internal set`, and `init` modifiers, effectively bypassing intended C# access restrictions. This mass assignment (CWE-915) and access-modifier bypass (CWE-284) vulnerability can lead to unauthorized modification of sensitive host object properties, such as changing `user.is_admin = true`, with changes persisting after template rendering, affecting Scriban versions up to and including 7.2.1, with the `init` bypass specifically impacting .NET 5+.

Scriban <= 7.2.1 templating-engine mass-assignment access-control-bypass vulnerability csharp dotnet
2t
high advisory

flyto-core SSRF Bypass via IPv6 Transition Addresses (CWE-918)

An authenticated workflow author can bypass `flyto-core`'s Server-Side Request Forgery (SSRF) protection by crafting URLs with IPv6 transition addresses that embed private IPv4s, allowing for data exfiltration from internal services like cloud instance metadata.

flyto-core ssrf vulnerability python defense-evasion
3t 3i
critical advisory

Cilium L7 Envoy Admin Socket Vulnerability (CVE-2026-49445)

When Cilium L7 functionality is enabled, a world-accessible Envoy admin socket is inadvertently created on cluster nodes. This misconfiguration (CVE-2026-49445) allows a local attacker to gain unauthorized access to Envoy's administrative endpoints, leading to sensitive information disclosure, such as the exposure of TLS secrets, and significant cluster disruption, including the interruption of traffic and the termination of Envoy processes.

Cilium v1.19 +2 vulnerability kubernetes container cilium envoy local-privilege-escalation information-disclosure denial-of-service +1
2t
high threat

CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE

A high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.

exploited GIMP +4 vulnerability memory-corruption buffer-overflow linux
1c
medium advisory

Multiples vulnérabilités dans OpenSSH

Multiple vulnerabilities in OpenSSH versions prior to 10.4 allow attackers to bypass security policies, cause denial of service, and exploit other unspecified security issues, requiring users to update to OpenSSH 10.4 or later.

OpenSSH vulnerability network
2t
high advisory

Multiple Vulnerabilities in Roundcube Webmail (CVE-2026-54432, CVE-2026-54433)

Multiple vulnerabilities, including Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), and Denial of Service (DoS), have been discovered in Roundcube Webmail versions 1.6.x prior to 1.6.17 and 1.7.x prior to 1.7.2, allowing remote attackers to impact service availability and potentially execute malicious code or access internal resources.

Roundcube Webmail < 1.6.17 +1 webmail vulnerability ssrf xss dos web-application
high advisory

Vulnerability in PostgreSQL JDBC Allows Security Policy Bypass (CVE-2026-54291)

A vulnerability, CVE-2026-54291, has been discovered in PostgreSQL JDBC versions 42.7.4 up to, but not including, 42.7.12, allowing an attacker to bypass security policies within applications utilizing the affected driver, potentially leading to unauthorized access or actions.

PostgreSQL JDBC vulnerability jdbc postgresql security-bypass cve
2i
high advisory

KeepInMind 0.8.4.2 - Stored XSS Public Exploit

A public exploit has been published for a Stored XSS vulnerability in KeepInMind version 0.8.4.2, significantly increasing the risk for unpatched installations.

KeepInMind 0.8.4.2 webapps xss vulnerability exploit-db
1t
critical advisory

Windows Defender Race Condition (EDB-52612) Leads to Local Privilege Escalation and AV Bypass

A critical local race condition (EDB-52612) exists in Microsoft Windows Defender's MsMpEng.exe, specifically between its cleanup routine (`MpCleanCallbackFunction`) and Volume Shadow Copy creation, allowing Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM and temporary disabling of antivirus protection through a use-after-free vulnerability, with a public exploit demonstrating the risk.

Windows Defender Antivirus local-privilege-escalation race-condition windows-defender exploit-db vulnerability endpoint
1t 3i
high advisory

Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability (CVE-2026-46242)

A publicly available proof-of-concept exploit for CVE-2026-46242, a race-condition use-after-free vulnerability dubbed 'Bad Epoll' in the Linux kernel's `epoll` facility, enables unprivileged processes to gain root privileges on affected Linux and Android systems.

Linux kernel +1 linux privilege-escalation vulnerability poc
1t 1c
high advisory

Multiple Vulnerabilities in Apache Camel Lead to Arbitrary Code Execution

Multiple vulnerabilities exist in Apache Camel that an attacker can exploit to bypass security controls and execute arbitrary program code, potentially leading to system compromise and unauthorized operations.

Apache Camel vulnerability apache camel code-execution security-bypass
1t
high advisory

OpenVPN: Multiple Vulnerabilities

A local attacker can exploit multiple vulnerabilities in OpenVPN to achieve arbitrary code execution, manipulate data, or cause a denial of service.

OpenVPN vulnerability rce dos
3t
medium advisory

CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service

An authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.

Red Hat Advanced Cluster Security for Kubernetes +1 kubernetes red-hat dos vulnerability graphql
1t 1c
high advisory

CVE-2026-14809: Unauthenticated SQL Injection in Prog Management System

A SQL Injection vulnerability, identified as CVE-2026-14809, exists in the Prog Management System developed by PROG MIS, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

Prog Management System sql-injection vulnerability web cve high-severity
1r 2t 1c
critical advisory

CVE-2026-14807: PROG MIS ERP App Hard-coded Credentials Vulnerability

An unauthenticated remote attacker can exploit a Use of Hard-coded Credentials vulnerability (CWE-798) in the ERP App developed by PROG MIS, allowing the attacker to log in to view application code and obtain database account and password information, leading to high impact on confidentiality, integrity, and availability.

ERP App hard-coded-credentials erp web-application vulnerability
3t 1c
high advisory

Gitea: Multiple Vulnerabilities Leading to XSS, Info Disclosure, and File Manipulation

An attacker can exploit multiple unpatched vulnerabilities in Gitea to bypass security measures, disclose sensitive information, perform Cross-Site Scripting (XSS) attacks, and manipulate files, posing a high risk to self-hosted Git instances.

Gitea web-exploitation vulnerability
4t
high advisory

CVE-2026-14802: Remote OS Command Injection in React Create React App

A high-severity OS command injection vulnerability (CVE-2026-14802) exists in `react create-react-app` up to version 5.0.1, specifically within the `startBrowserProcess` function of the `openBrowser.js` file in the `react-dev-utils` component, allowing for remote exploitation and arbitrary OS command execution on affected macOS development environments.

create-react-app <= 5.0.1 +1 vulnerability command-injection macos web-application
2t 1c 6i
high advisory

Red Hat JBoss Enterprise Application Platform: Multiple Vulnerabilities

Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform allow a remote, unauthenticated attacker to execute arbitrary code, perform cross-site scripting (XSS) attacks, disclose sensitive information, cause a denial of service, or bypass security mechanisms, posing a significant risk of system compromise and data exposure.

JBoss Enterprise Application Platform vulnerability rce xss dos information-disclosure red-hat jboss enterprise-application-platform +1
5t
high advisory

Eclipse Jetty: Multiple Vulnerabilities Including Arbitrary Code Execution

An authenticated remote attacker can exploit multiple vulnerabilities in Eclipse Jetty to achieve arbitrary code execution, bypass security measures, or perform an HTTP cache poisoning attack, necessitating immediate patching and enhanced monitoring of Jetty instances.

Jetty vulnerability webserver RCE authentication-bypass cache-poisoning eclipse-jetty
2t
high advisory

CVE-2026-14771: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability

A critical SQL injection vulnerability (CVE-2026-14771) has been discovered in SourceCodester Class and Exam Timetabling System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in `/edit_exam1.php`, leading to arbitrary SQL command execution and potential data compromise.

Class and Exam Timetabling System 1.0 sql-injection web-application vulnerability remote-code-execution data-exfiltration
1r 1t 1c 6i
high advisory

CVE-2026-14770: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability

A high-severity SQL injection vulnerability, CVE-2026-14770, exists in SourceCodester Class and Exam Timetabling System version 1.0 within the `/edit_room.php` file, allowing remote, unauthenticated attackers to manipulate the 'ID' argument with public exploits, leading to data exposure and potential database compromise.

Class and Exam Timetabling System 1.0 sql-injection vulnerability web-application cve
1r 1t 1c
high advisory

CVE-2026-9085: Incorrect Permissions Allow DNS Spoofing in Pardus-Parental-Control

An Improper Access Control and Incorrect Permission Assignment vulnerability (CVE-2026-9085) in TUBITAK BILGEM's Pardus-Parental-Control software, affecting versions up to 0.5.1 and all versions before 0.7.0, allows a local attacker to perform DNS Spoofing.

Pardus-Parental-Control dns-spoofing access-control linux vulnerability
1c
high threat

CVE-2026-6509 — Missing Authorization Vulnerability in Pardus Update Allows Privilege Escalation

A Missing Authorization vulnerability (CVE-2026-6509) in TUBITAK BILGEM Software Technologies Research Institute's Pardus Update software allows a local, low-privileged attacker to escalate privileges on affected Pardus Linux systems by bypassing authorization checks in versions up to and including 0.6.3.

exploited Pardus Update privilege-escalation linux vulnerability cve
1t 1c
high advisory

CVE-2026-12250: Pardus Domain Joiner Vulnerability Exposes Sensitive Information

A high-severity vulnerability, CVE-2026-12250, in TUBITAK BILGEM Software Technologies Research Institute's Pardus Domain Joiner (versions 0.5.2 before 0.5.4) allows local attackers to excavate sensitive information by observing process invocations that expose credentials or other confidential data.

Pardus Domain Joiner 0.5.2 +1 vulnerability linux data-exposure pardus
1c
high advisory

CVE-2026-14753: mjperpinosa stumasy Authorization Bypass

A critical authorization bypass vulnerability (CVE-2026-14753) has been identified in mjperpinosa stumasy, affecting versions up to and including commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This flaw, residing in an unknown function within the /PHP/objects/notes file of the Note Handler/Assignment Handler component, allows a remote attacker to bypass authorization by manipulating the 'assignment_item_id' argument. A public exploit is available, posing an immediate threat.

stumasy authorization-bypass web-application vulnerability cve
2t 1c 1i
high advisory

CVE-2026-14745: SQL Injection in code-projects Real State Services

A critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection cve real-estate vulnerability
1r 3t 1c
high advisory

CVE-2026-14743: Remote SQL Injection in code-projects Real State Services 1.0

A high-severity remote SQL injection vulnerability (CVE-2026-14743) in code-projects Real State Services 1.0 allows an unauthenticated attacker to manipulate the 'loc' argument in the `/normalHomeSale.php` file, leading to arbitrary SQL command execution and potential compromise of confidentiality, integrity, and availability of data, with an exploit publicly available.

Real State Services 1.0 sql-injection webserver vulnerability cve
1r 2t 1c
high advisory

CVE-2026-14737: Hanwang e-Face General Management Platform SQL Injection

A remote SQL injection vulnerability (CVE-2026-14737) affects Hanwang e-Face General Management Platform version 6.3.5.4, specifically within the `/sysAuthStr/querySysAuthStr.do` file, triggered by manipulating argument order, allowing remote attackers to potentially gain unauthorized access to or modify database contents with a publicly available exploit.

e-Face General Management Platform 6.3.5.4 sql-injection web-exploitation vulnerability cve hanwang
1r 1t 1c
high advisory

CVE-2026-14736: Ruijie RG-UAC Unrestricted Upload Vulnerability

A critical unrestricted file upload vulnerability, CVE-2026-14736, in Ruijie RG-UAC up to version 1.0-R1.8.2.p5 allows unauthenticated remote attackers to upload arbitrary files via manipulation of the `upload_image` argument in `user_auth_commit.php`, potentially leading to remote code execution.

RG-UAC firmware up to 1.0-R1.8.2.p5 vulnerability rce unrestricted-file-upload webserver cve-2026-14736
3t 1c
high threat

CVE-2026-14735: SQL Injection Vulnerability in code-projects Smart Parking System

A high-severity SQL injection vulnerability, CVE-2026-14735, exists in code-projects Smart Parking System 1.0, allowing remote attackers to manipulate the `street`, `city`, or `status` arguments in `/parkings/parkings.php` to execute arbitrary SQL queries, potentially leading to arbitrary file read and data exfiltration, with public exploit details available.

exploited Smart Parking System 1.0 sql-injection vulnerability web-application php cve
1r 2t 1c 6i
high advisory

CVE-2026-14734: SQL Injection in SourceCodester Class and Exam Timetabling System

A high-severity SQL injection vulnerability (CVE-2026-14734) exists in SourceCodester Class and Exam Timetabling System version 1.0, allowing unauthenticated remote attackers to manipulate the 'ID' argument in `/edit_product.php` to execute arbitrary SQL queries, with a publicly available exploit increasing the risk of unauthorized data access, modification, or exfiltration.

Class and Exam Timetabling System 1.0 sql-injection web-application cve vulnerability initial-access
1r 3t 1c 6i
high threat

CVE-2026-14722: Remote Code Injection in TidGi-Desktop Git Repository Import Component

A critical remote code injection vulnerability, CVE-2026-14722, has been identified in tiddly-gittly TidGi-Desktop versions up to 0.13.0, allowing unauthenticated attackers to execute arbitrary code by manipulating the Git Repository Import component, with public exploits available and confirmed active exploitation potential.

exploited TidGi-Desktop vulnerability code-injection remote-code-execution desktop-application
2t 1c 6i
high advisory

CVE-2026-14690: Improper Authorization in SourceCodester Multi-Vendor Online Grocery Management System

A high-severity improper authorization vulnerability (CVE-2026-14690) in the `save_users` function of SourceCodester Multi-Vendor Online Grocery Management System 1.0 allows remote unauthenticated attackers to manipulate user accounts, potentially leading to privilege escalation or unauthorized access, with a public exploit readily available.

Multi-Vendor Online Grocery Management System 1.0 vulnerability web-application improper-authorization cve sourcecodester
3t 1c
high threat

CVE-2026-14648: Remote SQL Injection in code-projects Online Voting System

A high-severity SQL injection vulnerability, identified as CVE-2026-14648, exists in the code-projects Online Voting System up to versions 0.x/1.0, allowing remote unauthenticated attackers to bypass authentication and execute arbitrary SQL commands by manipulating `adminUserName` or `adminPassword` parameters in the `/authentication.php` login component, with public exploit details increasing the risk of active exploitation.

exploited Online Voting System +1 sql-injection webserver vulnerability cve
1r 2t 1c
high advisory

CVE-2026-14640: CodeAstro Apartment Visitor Management System SQL Injection

A critical SQL injection vulnerability (CVE-2026-14640) in CodeAstro Apartment Visitor Management System 1.0 allows remote attackers to execute arbitrary SQL queries via manipulation of the 'Username' argument in the Login component's '/index.php' file, leading to unauthorized data access, modification, and potential system compromise.

Apartment Visitor Management System 1.0 sql-injection web-application vulnerability cve
1r 1t 1c 6i
high advisory

CVE-2025-71380: Authenticated Remote Code Execution in n8n via Execute Command Node

CVE-2025-71380 is an improper access control vulnerability (CWE-284) in n8n versions up to and including 1.114.4 that allows authenticated users to execute arbitrary commands on the underlying host system where n8n runs, potentially leading to data exfiltration, service disruption, or complete system compromise.

n8n <= 1.114.4 RCE vulnerability n8n workflow-automation command-execution improper-access-control
2r 6t 1c
high advisory

CVE-2025-71375: Picklescan Arbitrary Code Execution via _operator.methodcaller Evasion

A vulnerability in `picklescan` versions prior to 0.0.34 (CVE-2025-71375) allows attackers to craft malicious Python pickle payloads using the `_operator.methodcaller` built-in function, which evades detection by the `picklescan` library and enables arbitrary code execution when the payload is loaded by an application using `pickle.load()`.

picklescan vulnerability rce deserialization python
1t 1c
high advisory

CVE-2025-71373: Picklescan Bypass via `operator.methodcaller` Leads to Arbitrary Code Execution

Remote attackers can bypass security checks in `picklescan` versions prior to 0.0.33 by crafting malicious pickle payloads utilizing `operator.methodcaller` function calls, which upon loading by systems relying on `picklescan` for validation, results in arbitrary code execution and system compromise.

picklescan < 0.0.33 vulnerability rce picklescan python deserialization
1t 1c
high advisory

CVE-2025-71372: Picklescan Deserialization Vulnerability (Numpy Gadget)

CVE-2025-71372 describes a critical vulnerability in Picklescan versions prior to 0.0.33, where the tool fails to detect a specific numpy gadget in pickle `__reduce__` methods, allowing attackers to craft malicious pickle files that execute arbitrary Python code when loaded, bypassing safety checks and enabling supply-chain poisoning of shared model files.

Picklescan < 0.0.33 vulnerability deserialization python supply-chain numpy arbitrary-code-execution
2t 1c 2i
high advisory

CVE-2025-71369: Picklescan Malicious Pickle Detection Bypass Leading to RCE

A critical vulnerability, CVE-2025-71369, in `picklescan` versions prior to 0.0.28 allows remote attackers to bypass safety checks for malicious Python pickle files that utilize specific `torch.utils.data.datapipes` methods, enabling undetected embedded malicious code to execute during deserialization, which results in remote code execution (RCE) on the victim's system.

picklescan < 0.0.28 python deserialization rce vulnerability supply-chain machine-learning
2t 1c
high advisory

CVE-2025-71367: Picklescan Bypass Leading to Arbitrary Code Execution

Picklescan versions prior to 0.0.34 contain a deserialization vulnerability (CVE-2025-71367) that allows remote attackers to bypass security checks by crafting malicious pickle files using `_operator.attrgetter` in reduce methods, leading to arbitrary code execution when `pickle.load()` processes the file.

picklescan < 0.0.34 deserialization vulnerability python pickle rce
2t 1c
high advisory

CVE-2025-71366: Picklescan Deserialization Vulnerability Leads to RCE

A critical deserialization vulnerability (CVE-2025-71366) exists in picklescan versions prior to 0.0.28, allowing remote attackers to bypass safety checks by embedding malicious `torch.utils.bottleneck.__main__.run_cprofile` function calls in pickle files, leading to arbitrary code execution when victims load the crafted files.

picklescan < 0.0.28 cve vulnerability deserialization python picklescan
2t 1c
high advisory

CVE-2025-71362 — picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functio...

picklescan versions prior to 0.0.33 are vulnerable to unsafe deserialization via CVE-2025-71362, allowing attackers to embed malicious code in pickle files that executes due to `numpy.f2py.crackfortran` calling `eval` on arbitrary strings when loaded from untrusted sources, leading to arbitrary code execution.

picklescan cve deserialization python arbitrary-code-execution vulnerability
2t 1c
high advisory

CVE-2025-71360: Picklescan RCE via Undetected Malicious Pickle Files

A high-severity deserialization of untrusted data vulnerability (CVE-2025-71360) in picklescan versions before 0.0.29 allows attackers to embed undetected remote command execution code within malicious pickle files, leading to arbitrary code execution when loaded by victims.

picklescan < 0.0.29 deserialization rce vulnerability python
2t 1c
high advisory

CVE-2025-71359: Picklescan Deserialization RCE Bypass

Picklescan versions prior to 0.0.29 are vulnerable to remote code execution (CVE-2025-71359) due to a failure in detecting malicious Python pickle payloads that utilize `lib2to3.pgen2.grammar.Grammar.loads`, allowing attackers to craft files that evade detection and execute arbitrary code during deserialization.

picklescan < 0.0.29 remote-code-execution deserialization python vulnerability supply-chain
2t 1c
high advisory

CVE-2025-71356: picklescan Deserialization Vulnerability Leads to RCE

A critical deserialization vulnerability (CVE-2025-71356) in `picklescan` versions prior to 0.0.28 allows attackers to embed undetected malicious code within Python pickle files, leading to remote code execution when these files are loaded by victims.

picklescan < 0.0.28 deserialization python vulnerability rce machine-learning
1t 1c
high advisory

CVE-2025-71353: Picklescan Deserialization Vulnerability Leads to Remote Code Execution

Picklescan before version 0.0.28 contains a deserialization vulnerability where it fails to properly detect malicious pickle files. Attackers can craft these files with embedded code that exploits the `torch._dynamo.guards.GuardBuilder.get` function in reduce methods, leading to arbitrary command execution when loaded on a victim system.

picklescan < 0.0.28 deserialization rce python vulnerability CVE-2025-71353
1t 1c 2i
high advisory

CVE-2025-71347: Picklescan Bypass Leads to Arbitrary Code Execution via Malicious Pickle Files

A critical vulnerability (CVE-2025-71347) exists in picklescan prior to version 0.0.33, allowing remote attackers to bypass security checks by failing to detect malicious pickle files leveraging the numpy.f2py.crackfortran.param_eval function, leading to arbitrary code execution upon deserialization of untrusted data.

picklescan < 0.0.33 deserialization python arbitrary-code-execution vulnerability cve defense-evasion
2t 1c 2i
high advisory

CVE-2025-71345: Picklescan Malicious Pickle File Detection Bypass Leading to RCE

CVE-2025-71345 describes a critical vulnerability in `picklescan` versions prior to 0.0.30, where attackers can embed undetected malicious code within pickle files that specifically invoke the `torch.utils.bottleneck.__main__.run_autograd_prof` function, leading to remote code execution upon deserialization by bypassing `picklescan`'s security checks.

picklescan < 0.0.30 remote-code-execution deserialization python machine-learning vulnerability
2t 1c
high advisory

CVE-2025-71343 — picklescan Detection Bypass via Malicious Pickle Files

A deserialization vulnerability, CVE-2025-71343, in picklescan before version 0.0.30 allows attackers to craft malicious pickle files that evade detection and lead to arbitrary code execution when loaded via `pickle.load()`.

picklescan < 0.0.30 deserialization remote-code-execution python vulnerability detection-bypass
2t 1c
high advisory

CVE-2025-71342: picklescan Remote Code Execution Vulnerability

A critical vulnerability (CVE-2025-71342) exists in picklescan versions prior to 0.0.30, where it fails to detect malicious code embedded in Python pickle files by leveraging `idlelib.run.Executive.runcode` in reduce methods, allowing attackers to conceal and execute arbitrary code during `pickle.load` operations, leading to remote code execution (RCE) and potential supply chain attacks, particularly impacting PyTorch models.

picklescan < 0.0.30 vulnerability rce supply-chain python pickle pytorch
1t 1c
high advisory

CVE-2026-14606 — Stack-Based Buffer Overflow in RT-Thread CAN_Receive

A stack-based buffer overflow vulnerability (CVE-2026-14606) exists in RT-Thread versions up to 5.0.2, specifically in the `CAN_Receive` function of the SWM341 CAN Handler component, allowing for local exploitation via manipulation, with a public exploit available.

RT-Thread <= 5.0.2 vulnerability buffer-overflow RT-Thread IoT ICS embedded-systems
1c
high advisory

CVE-2026-58379: GIMP Heap Buffer Overflow in PSP Parser Allows RCE

A heap buffer overflow vulnerability (CVE-2026-58379) in GIMP's Paint Shop Pro (PSP) file format parser allows a remote attacker to achieve arbitrary code execution or cause a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file, exploiting incorrect buffer size calculations when processing low bit-depth images.

GIMP +1 heap-buffer-overflow vulnerability image-processing
3t 1c
high advisory

RPC (Remote Procedure Call) Services Exposed to the Internet

Threat actors frequently exploit internet-exposed Remote Procedure Call (RPC) services, primarily on port TCP/135, as an initial access or backdoor vector, leading to unauthorized system access, internal network compromise, and potentially data exfiltration or ransomware deployment.

network-traffic initial-access lateral-movement vulnerability misconfiguration network
1r 3t
high advisory

SMB (Windows File Sharing) Activity from the Internet

Detection rule identifies inbound Windows file sharing (SMB/CIFS) traffic originating from the Internet to internal hosts, posing a critical initial access risk due to potential exploitation of vulnerabilities like CVE-2017-0144 (EternalBlue).

SMB Server initial-access network windows smb vulnerability ms17-010
1r 4t 1c
high advisory

CVE-2026-14460: Missing Authorization and Argument Injection in TUBITAK BILGEM Pardus-Software

A Missing Authorization vulnerability, identified as CVE-2026-14460, in TUBITAK BILGEM Software Technologies Research Institute's pardus-software versions up to 1.0.4, allows for Argument Injection, posing a high severity risk to confidentiality, integrity, and availability.

pardus-software vulnerability CVE linux
1c
high advisory

CVE-2026-14459: Argument Injection Vulnerability in TUBITAK BILGEM pardus-software

A critical argument injection vulnerability (CVE-2026-14459) in TUBITAK BILGEM Software Technologies Research Institute's pardus-software versions up to 1.0.4 allows a local, low-privileged attacker to achieve unauthorized command execution, severely impacting confidentiality, integrity, and availability.

PoC pardus-software +1 vulnerability argument-injection linux cve
1t 2c 2i
high advisory

WatchGuard Firebox and Mobile VPN Client Vulnerabilities

WatchGuard has released security advisories to address critical vulnerabilities, including a race condition, use-after-free, and local privilege escalation, in its Fireware OS and Mobile VPN with SSL client for Windows, which could lead to remote code execution on appliances and local privilege escalation on client systems if not patched immediately.

Fireware OS 2025.1 +4 watchguard vulnerability network-device vpn privilege-escalation remote-code-execution
2t
high advisory

Splunk Code Injection via Custom Dashboard Leading to RCE (CVE-2022-43571)

An authenticated user can exploit CVE-2022-43571, a code injection vulnerability within Splunk Enterprise or Splunk Cloud's dashboard PDF generation component, leading to remote code execution (RCE) and potential compromise of the Splunk environment.

Splunk Enterprise +3 splunk vulnerability rce code-injection application-vulnerability
1t 1c
high advisory

Splunk XSS Privilege Escalation via Custom URLs in Dashboard (CVE-2024-36992)

A critical cross-site scripting (XSS) vulnerability, identified as CVE-2024-36992, affects Splunk Enterprise and Splunk Cloud Platform, allowing attackers to achieve privilege escalation by exploiting custom URLs within Splunk dashboards via malicious POST requests to the `splunk_internal_metrics/data/ui/views` endpoint, leading to the creation of new user accounts with elevated access permissions on the Splunk server.

Splunk Enterprise +2 xss privilege-escalation splunk cve vulnerability
2r 1t 1c
critical advisory

Splunk RCE via User XSLT Exploitation (CVE-2023-46214)

This brief identifies potential remote code execution (RCE) attempts targeting Splunk servers by exploiting CVE-2023-46214, a vulnerability related to user-supplied Extensible Stylesheet Language Transformations (XSLT) that allows attackers to execute arbitrary code leading to full system compromise.

Splunk Enterprise < 9.0.7 +3 application rce splunk vulnerability
1r 1t 1c
high advisory

Splunk Authentication Token Exposure in Debug Logs (CVE-2024-29945)

A critical vulnerability, CVE-2024-29945, allows for the exposure of authentication tokens in debug logs within Splunk Enterprise and Splunk Cloud, enabling an attacker with access to internal log files to gain unauthorized access, exfiltrate data, and potentially achieve full compromise of the Splunk infrastructure if unpatched versions (prior to 9.2.1, 9.1.4, and 9.0.9 for Enterprise) are in use.

Splunk Enterprise +3 splunk vulnerability token-exposure log-analysis application
1r 1t 1c
high advisory

FreeBSD Vulnerability CVE-2026-49424 Allows Data Confidentiality Breach

A vulnerability, identified as CVE-2026-49424, has been discovered in FreeBSD versions 14.3 (prior to 14.3-RELEASE-p16), 14.4 (prior to 14.4-RELEASE-p7), and 15.0 (prior to 15.0-RELEASE-p11) that could allow an attacker to compromise data confidentiality.

FreeBSD 14.3 +2 vulnerability freebsd cve data-confidentiality
critical advisory

CVE-2026-4321: Critical SQL Injection in Raera Destekz Product

CVE-2026-4321 describes a critical SQL Injection vulnerability with a CVSS v3.1 score of 9.8 in the Destekz product by Raera - Ankara Web Design and Digital Advertising Agency, affecting all versions through June 2nd, 2026, which remains unpatched due to the vendor discontinuing support for the product, enabling unauthenticated attackers to potentially achieve full system compromise and data exfiltration.

Destekz sql-injection cve web-application vulnerability critical unsupported-product
1t 1c
high advisory

Open Babel Heap Buffer Overflow in SMILES Parsing (CVE-2025-10996)

A heap buffer overflow vulnerability (CVE-2025-10996) in Open Babel's `OBSmilesParser::ParseSmiles` function allows attackers to achieve denial of service or arbitrary code execution by crafting and supplying a malformed SMILES input string to affected versions up to 3.1.1.

Open Babel vulnerability buffer-overflow chemistry library cve
1c
high advisory

Open Babel Heap Buffer Overflow in ChemKin Parser (CVE-2025-10997)

A heap buffer overflow vulnerability (CVE-2025-10997) in Open Babel's ChemKin parser allows an attacker to achieve memory corruption when a victim processes a specially crafted ChemKin file, potentially leading to denial of service or arbitrary code execution.

Open Babel +1 chemistry vulnerability buffer-overflow memory-corruption cve
1t 1c
high advisory

Open Babel Uninitialized Pointer Dereference Vulnerability (CVE-2022-42885)

A high-severity memory-safety vulnerability (CVE-2022-42885) in Open Babel's GRO residue parser allows an uninitialized pointer dereference when processing a specially crafted GRO input file, potentially leading to application crash or arbitrary code execution.

Open Babel <= 3.1.1 +1 vulnerability memory-safety cve open-babel
1t 1c
high advisory

Open Babel PQS coord_file parser suffers from out-of-bounds write vulnerability (CVE-2022-43467)

A high-severity memory-safety vulnerability (CVE-2022-43467) in Open Babel's PQS `coord_file` parser allows an attacker to achieve an out-of-bounds write by tricking a victim into opening a specially crafted PQS file, potentially leading to arbitrary code execution or denial of service in systems processing untrusted chemistry file formats.

Open Babel +1 open-babel vulnerability memory-corruption cve library
2t 1c
high threat

Open Babel MOL2 Parser Out-of-Bounds Write (CVE-2022-43607)

A memory-safety vulnerability, CVE-2022-43607, in Open Babel's MOL2 parser allows an out-of-bounds write when processing a crafted input file, potentially leading to denial of service or arbitrary code execution.

exploited Open Babel +1 memory-safety vulnerability library cve file-parsing chemistry denial-of-service code-execution
1r 1t 1c
high advisory

Open Babel Has Uninitialized Pointer Dereference in MSI Atom Parser

A memory-safety vulnerability (CVE-2022-44451) in Open Babel's MSI parser allows for an uninitialized pointer dereference when processing a specially crafted MSI input file, affecting versions prior to 3.2.0 and potentially leading to application instability or denial of service when a victim opens a malicious file.

Open Babel chemistry vulnerability memory-safety open-babel cve
1t 1c
high advisory

Open Babel PQS Parser Uninitialized Pointer Dereference (CVE-2022-46280)

A memory-safety vulnerability, CVE-2022-46280, in Open Babel's PQS parser (versions prior to 3.2.0) allows an uninitialized pointer dereference when processing a specially crafted input file, potentially leading to application crashes and denial of service if a victim opens a malicious PQS file.

Open Babel vulnerability memory-corruption library linux DoS
1c
high advisory

Open Babel Out-of-Bounds Write in MSI Parser (CVE-2022-46295)

An out-of-bounds write vulnerability (CVE-2022-46295) in Open Babel's MSI parser allows remote attackers to cause memory corruption, denial of service, or potentially arbitrary code execution when a victim opens a specially crafted MSI file using the `obabel` tool or any application linked to the `OBConversion` API.

Open Babel memory-corruption vulnerability library cpp ghsa
1t 1c
high advisory

auth-fetch-mcp SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

auth-fetch-mcp versions up to and including 3.0.1 contain an SSRF protection bypass vulnerability (CVE-2026-49857) where the `isPrivateV6()` function fails to correctly identify IPv4-mapped IPv6 loopback addresses after Node.js URL normalization, allowing URLs like `http://[::ffff:127.0.0.1]:PORT/` to bypass the `assertSafeUrl()` check, enabling an attacker to coerce the `auth_fetch` or `download_media` tools to make requests to internal or loopback services and compromising the confidentiality of internal service responses.

auth-fetch-mcp <= 3.0.1 ssrf vulnerability bypass node.js initial-access defense-evasion
high advisory

Wetty Client DOM XSS via Base64 Filename in File Download Escape Sequence (CVE-2026-49864)

A high-severity DOM XSS vulnerability (CVE-2026-49864) in the wetty SSH client allows an attacker to achieve keystroke injection and command execution on the victim's SSH session by embedding a crafted base64-encoded filename within a terminal file-download escape sequence, which is then unescaped and rendered as raw HTML.

wetty xss dom-xss vulnerability rce ssh-client client-side
1r 4t
high advisory

Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

A high-severity vulnerability, CVE-2026-49981, in the Twig templating engine allows for a sandbox bypass when the sandbox state changes between renders for a cached `Template` instance, enabling the execution of otherwise restricted filters, tags, and functions in sandboxed contexts.

Twig vulnerability sandbox-bypass web-application rce
2t
high advisory

Non-Constant-Time HMAC Comparison in Pay Gem Paddle Billing Webhook Signature Verifier

A timing side-channel vulnerability in the `Pay` gem's Paddle Billing webhook signature verification component (`Pay::Webhooks::PaddleBillingController#valid_signature?` <= v11.6.1) allows an unauthenticated attacker to recover the HMAC signing secret by observing response time variations in `String#==` comparisons, enabling the forgery of arbitrary webhook events and leading to business logic abuses such as unauthorized feature provisioning or fraudulent refunds.

pay timing-attack vulnerability webhooks ruby-on-rails server-side logic-error remote-code-execution
3t
high advisory

Sigstore `certificateOIDs` Verification Bypass Vulnerability (CVE-2026-48815)

A high-severity vulnerability (CVE-2026-48815) in the `npm/sigstore` library (versions <= 4.1.0) causes the `certificateOIDs` verification constraint to be silently ignored, allowing applications to accept unauthorized certificates that should have been rejected based on extension policy, which could lead to supply chain attacks by trusting malicious artifacts.

npm/sigstore vulnerability supply-chain software-security javascript npm code-signing
high advisory

SurrealDB HTTP /rpc Session Hijack Vulnerability

A critical vulnerability (versions prior to 3.1.0) in SurrealDB's HTTP /rpc endpoint allowed unauthenticated attackers to enumerate session UUIDs via the `sessions` method, enabling full session hijack of any attached and authenticated session due to a lack of ownership checks, leading to unauthorized data manipulation and privilege escalation.

SurrealDB +1 vulnerability session-hijack web-application rpc database
5t
high advisory

Rancher Fleet Unauthenticated Webhook Regex Injection (CVE-2026-44937)

An unauthenticated regex injection vulnerability exists in Rancher Fleet's webhook endpoint when it's configured without a secret, allowing attackers to forge webhook requests using unsanitized repository URL components, which leads to continuous repository re-cloning, causing network and resource exhaustion (Denial of Service) on the management cluster, and potentially service downgrades if the attacker has read access to the target Git repository.

Fleet +3 rancher vulnerability webhook regex-injection denial-of-service cloud-native kubernetes supply-chain
1t
high advisory

Oras-Go Tar Extraction Vulnerability Allows Current Working Directory Escape (CVE-2026-50163)

An attacker can craft a malicious OCI artifact with a tarball layer containing a hardlink entry that uses a relative path for its target, which, when extracted by `oras-go` (<= 2.6.1) or the `oras` CLI, allows the hardlink to resolve against the process's current working directory (CWD) instead of the intended extraction base, leading to arbitrary file read or modification in the victim's CWD via an inode-sharing vulnerability.

oras-go/v2 +1 vulnerability supply-chain go linux tar hardlink path-traversal arbitrary-file-read +1
5t 3i
high advisory

goshs WebDAV Listener Bypasses Access Restriction Flags

A vulnerability (CVE-2026-50138) in `goshs` versions up to `v2.0.9` allows an authenticated attacker to bypass intended access restriction flags like `--read-only`, `--upload-only`, and `--no-delete` when the WebDAV listener is enabled, leading to unauthorized file creation, modification, deletion, and content exfiltration on the server, compromising data integrity and confidentiality.

goshs webserver misconfiguration vulnerability cve
4t
high advisory

OpenClaw Vulnerability Allows Loading of Unscanned Payloads via Malicious Metadata

A high-severity vulnerability, CVE-2026-53810, in OpenClaw's marketplace runtime extension metadata allows an attacker to craft a malicious package that, when installed by a trusted operator, redirects runtime loading to hidden, unscanned code, potentially leading to unauthorized code execution and bypassing security checks.

npm/openclaw vulnerability supply-chain code-execution nodejs npm
3t 1c
high advisory

OpenClaw Vulnerability Allows Local Forged Identity Headers

A vulnerability (GHSA-rggc-m335-3wvj) in OpenClaw's trusted-proxy deployments allows a local attacker on the same host to forge identity headers, bypassing intended security controls and potentially leading to unauthorized access or privilege escalation if the affected feature is enabled and reachable.

OpenClaw +1 vulnerability proxy privilege-escalation defense-evasion npm server
2t
high advisory

OpenClaw Control UI Locality Spoofing Vulnerability

An authentication bypass vulnerability (CVE-2026-53817) in OpenClaw's Control UI pairing mechanism allows an attacker with existing network/authentication foothold in LAN/shared-token deployments to spoof locality information, leading to the acquisition of a durable admin-capable device token that grants persistent administrative access, even after shared gateway tokens are rotated.

openclaw authentication vulnerability admin-access persistence network
2t 1c
high advisory

OpenClaw's POSIX Node system.run Safe-Bin Widened by Shell Expansion (GHSA-mhq8-78pj-5j79)

A vulnerability in OpenClaw's `system.run` safe-bin feature on POSIX nodes could allow a lower-privilege operator flow to read local files not intended by policy, as shell expansion can alter the interpretation of an approved command, causing a seemingly safe argument to expand into additional shell words and become a file operand, potentially exposing OpenClaw configuration data or other node-local information.

npm/openclaw vulnerability policy-bypass posix data-exposure
2t
high advisory

OpenClaw Scoped Chat Route Inheritance Could Bypass Admin Command Scope Gates

A vulnerability in OpenClaw allows an attacker with `operator.write` privileges to bypass intended administrative command scope gates by delivering a scoped Gateway `chat.send` request through an inherited external route, leading to unauthorized execution of critical administrative commands.

openclaw vulnerability privilege-escalation application-security
1t
high threat

OpenClaw Matrix allowFrom Vulnerability (CVE-2026-53811)

A high-severity vulnerability (CVE-2026-53811) in OpenClaw's Matrix `allowFrom` feature allows threat actors to exploit mutable display names to match policy entries, potentially granting unauthorized agent access intended for another Matrix identity.

exploited npm/openclaw vulnerability matrix openclaw npm
1c
high advisory

OpenClaw PowerShell Encoded-Command Alias Bypass Vulnerability

A high-severity vulnerability (GHSA-j472-gf56-x589) in OpenClaw allows an attacker to bypass allowlist checks for PowerShell encoded commands by using abbreviated encoded-command flags, leading to unauthorized code execution on the underlying Windows system if a vulnerable feature is enabled and reachable.

OpenClaw vulnerability code-execution powershell bypass npm windows
1r 2t
high advisory

Langroid File Tools Path Traversal Vulnerability (CVE-2026-50181)

A path traversal vulnerability (CVE-2026-50181) exists in Langroid's `ReadFileTool` and `WriteFileTool` components (versions <= 0.63.0), allowing an attacker to read or write arbitrary files outside the configured `curr_dir` via crafted `file_path` arguments, potentially leading to sensitive information disclosure or unauthorized file modification in applications exposing these tools to user or LLM input.

langroid path-traversal python-library vulnerability llm-agent
3t
high advisory

OpenClaw Slack allowFrom Vulnerability (GHSA-c29c-2q9c-pc86)

A high-severity vulnerability (GHSA-c29c-2q9c-pc86) in OpenClaw's handling of Slack's `allowFrom` feature could allow an attacker to gain unintended agent access by manipulating their Slack display name metadata to match a policy entry, especially in configurations where the affected feature is enabled and reachable.

npm/openclaw vulnerability supply-chain cloud npm
1t
high advisory

OpenClaw Trusted-proxy Control UI Privilege Escalation (GHSA-qjpc-qf9m-xwmr)

A vulnerability in OpenClaw's trusted-proxy Control UI mode allows an unpaired or restricted trusted-proxy client to gain temporary `operator.admin` authority by declaring elevated WebSocket scopes before proper server-side authorization, enabling the execution of admin-gated Gateway RPCs until the connection is closed or revalidated.

OpenClaw vulnerability privilege-escalation websocket npm
1t
high advisory

OpenClaw Device Pairing Vulnerability Allows Unauthorized Device Enrollment

A high-severity vulnerability (affecting OpenClaw versions prior to 2026.5.4) in the bundled device-pair plugin allowed authorized non-owner chat senders to issue device-pairing bootstrap codes, enabling them to enroll devices with operator/node capabilities and gain persistent unauthorized access within the OpenClaw environment.

openclaw vulnerability application privilege-escalation persistence npm
2t
high advisory

OpenClaw Workspace .env Homebrew Executable Override Vulnerability (CVE-2026-53819)

A high-severity vulnerability (CVE-2026-53819) in OpenClaw versions prior to 2026.5.27 allows a malicious `.env` file within a repository to override the Homebrew executable selection during skill installation flows, potentially leading to arbitrary code execution on trusted operator systems running macOS or Linux.

OpenClaw vulnerability code-execution homebrew supply-chain macos linux
1t 1c
high advisory

OpenClaw Vulnerability Allows Unintended Artifact Loading (CVE-2026-53813)

A high-severity vulnerability, CVE-2026-53813, in npm/openclaw versions <= 2026.4.24 allows fake package roots to influence memory-core artifact loading, potentially leading to the selection and execution of unintended local artifacts based on attacker-controlled or lower-trust input reaching the affected path.

OpenClaw vulnerability supply-chain npm node.js
1c
high advisory

OpenClaw Vulnerability Allows Execution Revalidation Bypass (CVE-2026-53806)

A high-severity vulnerability, CVE-2026-53806, in npm/openclaw versions up to 2026.5.7, allows attackers to bypass 'exec revalidation' controls by confusing the application with combined POSIX shell options, leading to unauthorized inline shell content execution and potential remote code execution.

npm/openclaw vulnerability rce shell bypass code-execution linux macos
1c
high advisory

OpenClaw Node Forgery via Missing Provenance Check (CVE-2026-53816)

A vulnerability, CVE-2026-53816, in npm/openclaw versions prior to 2026.5.18, allows a malicious or compromised paired node to forge 'exec' lifecycle events and send them to the gateway, which, due to a missing provenance check, accepts the attacker-supplied event data as legitimate execution results, leading to unauthorized capability exposure for the compromised node.

npm/openclaw vulnerability privilege-escalation server-side npm
2t 1c
high advisory

OpenClaw Telegram Callback Authorization Bypass (GHSA-w5ww-7chg-mxcq)

A high-severity vulnerability (GHSA-w5ww-7chg-mxcq) in OpenClaw allows an unauthorized Telegram user to bypass the `commands.allowFrom` sender check via interactive callbacks, leading to unauthorized command execution on the OpenClaw Gateway.

OpenClaw authorization-bypass telegram callback vulnerability npm
3t
high advisory

OpenClaw Trusted Retry Endpoint Hostname Bypass

A vulnerability in OpenClaw allows an attacker to bypass trusted retry endpoint validation by crafting a URL with a hostname prefix that resembles a trusted host, which, if the feature is enabled and reachable by lower-trust input, could lead to sensitive authentication material being sent to an unintended external endpoint.

OpenClaw vulnerability server-side-request-forgery web-application
2t
high advisory

Craft CMS Vulnerability Allows Low-Privilege Users to Delete Peer Assets

A low-privilege user with `deleteAssets` permission in Craft CMS can bypass the `deletePeerAssets` check in the `AssetsController::actionDeleteFolder` function, allowing them to delete assets uploaded by other users (peer assets) within a shared volume, despite lacking the specific `deletePeerAssets` permission, leading to unauthorized data destruction.

Craft CMS +1 craft-cms vulnerability privilege-escalation data-deletion web-application
1t 1c
high advisory

@asymmetric-effort/specifyjs: URL Parse Failure Silently Allows Request (CVE-2026-50288)

A high-severity vulnerability, CVE-2026-50288, in the `@asymmetric-effort/specifyjs` npm package (versions prior to 0.2.136) allows for the silent bypass of HTTPS validation by mishandling URL parse errors in the `assertSecureUrl` function, which can lead to Server-Side Request Forgery (SSRF).

@asymmetric-effort/specifyjs npm supply-chain vulnerability ssrf javascript
1t
high advisory

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (CVE-2026-49852)

A critical vulnerability, CVE-2026-49852, exists in the Python `joserfc` library (versions `<= 1.6.7`) where HMAC-signed JSON Web Tokens can be forged, leading to complete authentication bypass, if the application is configured to verify tokens with an empty or `None` HMAC key.

joserfc <= 1.6.7 authentication-bypass jwt python vulnerability cve
1t
medium advisory

@conform-to/dom Vulnerable to CPU Exhaustion via Crafted Form Submissions

A CPU exhaustion vulnerability (CVE-2026-49250) exists in Conform's `parseSubmission` API when parsing `FormData` or `URLSearchParams` with many unique field names, allowing an attacker to craft a submission that causes excessive synchronous CPU work and potential denial of service by repeatedly scanning submitted entries.

npm/@conform-to/dom vulnerability web-application denial-of-service cpu-exhaustion npm
high advisory

electerm Path Traversal Vulnerability in Zmodem and Trzsz Download Handling (CVE-2026-49253)

A path traversal vulnerability exists in electerm's Zmodem and Trzsz file download handlers (CVE-2026-49253), allowing a malicious SSH server to send specially crafted filenames (e.g., `../escaped.txt`) that, when accepted by the user, can cause files to be written to arbitrary locations on the user's filesystem, potentially overwriting sensitive files or introducing malicious content.

electerm path-traversal vulnerability client-side terminal-emulator file-transfer
3t
medium advisory

Zebra Block Suppression Vulnerability (CVE-2026-52736) via P2P Body Poisoning

A remote unauthenticated attacker can exploit CVE-2026-52736 in Zebra's `zebrad` node (versions up to and including `v4.4.1`) to permanently stall a targeted blockchain node by poisoning its sent-hash cache, leading to a denial of service.

zebrad <= 4.4.1 +1 blockchain denial-of-service network vulnerability
2t
high advisory

Craft CMS Mass Assignment Vulnerability Allows Element Overwrites (CVE-2026-50281)

A high-severity mass assignment vulnerability (CVE-2026-50281) in Craft CMS versions prior to 5.9.21 allows a low-privileged authenticated attacker to overwrite arbitrary existing element data, such as entries or user profiles, by manipulating the `newAttributes` parameter during a bulk duplication action.

Craft CMS web-application vulnerability mass-assignment cve cms
1t 1c
medium advisory

JSONata $toMillis Function Vulnerability Leads to Denial of Service (CVE-2026-52746)

A high-severity vulnerability, CVE-2026-52746, in JSONata versions prior to 2.2.0 allows unauthenticated attackers to cause a denial of service by exploiting superlinear backtracking in the ISO-8601 validation regex through malicious inputs to the `$toMillis` function, leading to resource exhaustion and application unresponsiveness.

JSONata denial-of-service nodejs vulnerability CVE-2026-52746
1t
high advisory

Path Traversal Vulnerability in @asymmetric-effort/nogginlessdom Allows Arbitrary File Write

A path traversal vulnerability (GHSA-322x-v876-g883) in the `matchFileSnapshot` function of the `@asymmetric-effort/nogginlessdom` library allows an attacker to write arbitrary content to any filesystem path with write access when snapshot update mode is active, potentially leading to supply chain compromise in CI/CD environments.

nogginlessdom path-traversal supply-chain ci/cd npm vulnerability
4t
high advisory

SimpleSAMLphp HTTP-Artifact Authentication Bypass via TLS Validator Confusion (CVE-2026-49283)

A critical vulnerability (CVE-2026-49283) in SimpleSAMLphp's HTTP-Artifact receive path allows a malicious or lower-trust Identity Provider (IdP) to bypass authentication and impersonate users from a higher-trust IdP by leveraging a flaw where `SOAPClient::validateSSL()` fails to properly validate TLS public keys for unsigned SAML Responses.

SimpleSAMLphp SAML2 +3 vulnerability saml authentication-bypass identity-federation
1t
medium advisory

Zebra Node Denial-of-Service via IPv4-Mapped Mempool Misbehavior Panic (CVE-2026-52829)

A remote unauthenticated peer can exploit an address normalization mismatch in Zebra's address book when connecting via IPv4 to a dual-stack IPv6 listener on a Linux host, by then advertising an invalid mempool transaction, which triggers a deterministic assertion panic after a 30-second delay, causing the `zebrad` process to terminate, leading to persistent denial of service.

zebrad <= 4.4.1 +1 denial-of-service vulnerability linux rust
1t
medium advisory

SimpleSAMLphp Vulnerable to Denial-of-Service via Malicious XPath Transform

SimpleSAMLphp and its SAML2 library are vulnerable to CVE-2026-49289, allowing attackers to perform a Denial-of-Service attack by sending specially crafted SAML messages containing XPath transforms, leading to resource exhaustion and service unavailability.

composer/simplesamlphp/saml2 <= 4.20.2 +1 denial-of-service vulnerability saml php
1t
high advisory

Steeltoe Host Header Bypass Vulnerability (CVE-2026-50194)

An unauthenticated remote attacker can bypass port isolation in Steeltoe applications configured with `Management:Endpoints:Port` by spoofing the Host HTTP header, allowing access to all actuator endpoints (CVE-2026-50194).

Steeltoe.Management.Endpoint <= 4.1.0 +1 vulnerability web-exploitation cve dotnet bypass
1r 2t 1c
medium advisory

Steeltoe.Discovery.Eureka Deserialization Denial-of-Service (CVE-2026-50196)

The Steeltoe.Discovery.Eureka client contains a vulnerability (CVE-2026-50196) where its `DataCenterInfo.FromJson` method throws an `ArgumentException` if a `DataCenterInfo.name` value other than 'MyOwn' or 'Amazon' is encountered, specifically missing the valid 'Netflix' value from the Java Eureka specification, which causes the local service registry to become permanently empty or stale, leading to a complete service discovery outage for all connected Steeltoe Eureka clients.

Steeltoe.Discovery.Eureka +1 vulnerability service-discovery .net java denial-of-service
1c
high advisory

Steeltoe Environment Actuator Vulnerability (CVE-2026-50200) Leaks Database Passwords

A high-severity vulnerability, CVE-2026-50200, in the Steeltoe `Sanitizer` component of the Environment actuator allows for the unintended disclosure of sensitive connection string values, including embedded plaintext credentials, when the `/actuator/env` endpoint is accessed, enabling direct database connection and bypassing application-tier security.

Steeltoe.Management.Endpoint <= 4.1.0 +1 credential-access vulnerability .net steeltoe webserver actuator
1r 1t 1c
high advisory

WatchGuard Firebox: Multiple Critical Vulnerabilities

Multiple vulnerabilities in WatchGuard Firebox appliances allow a remote, unauthenticated attacker to execute arbitrary code, cause a denial of service, manipulate or disclose data, and perform Cross-Site Scripting attacks, necessitating immediate patching to mitigate critical risks.

Firebox network vulnerability execution impact
2t
high advisory

Algernon Server-Side Script Source Disclosure via NTFS Filename Manipulation (CVE-2026-52792)

Algernon, when running on a Windows host, is vulnerable to CVE-2026-52792, allowing an unauthenticated attacker to exploit its `filepath.Ext()` processing to bypass script execution and obtain the raw source code of server-side scripts by appending NTFS-equivalent suffixes (such as `::$DATA`, trailing dot, or trailing space) to the URL, thereby leaking sensitive embedded secrets like database credentials, API keys, and `SetCookieSecret` values, which can lead to authentication bypass.

Algernon webserver vulnerability code-disclosure server-side-vulnerability windows
1r 2t
high advisory

SimpleSAMLphp SP IdP Bypass Vulnerability (CVE-2026-49284)

SimpleSAMLphp's Service Provider (SP) does not properly enforce the expected Identity Provider (IdP) for an SP-initiated login when a response from a different IdP is received, allowing an attacker to exploit CVE-2026-49284 in multi-IdP deployments to bypass authentication and authorization controls by substituting a lower-trust IdP's response for a higher-trust one, potentially gaining unauthorized access or elevating privileges if application authorization relies on the specific IdP used.

simplesamlphp +1 saml vulnerability web-application authentication-bypass authorization-bypass
3t
critical advisory

XWiki Pro Macros Remote Code Execution via Excerpt-Include Macro (CVE-2026-44179)

A critical vulnerability, CVE-2026-44179, exists in XWiki Pro Macros versions before 1.14.5, allowing remote code execution for any user with page editing rights due to improper escaping of page titles and content processed by the excerpt-include macro, leading to XWiki syntax injection and full compromise of the XWiki installation.

xwiki-pro-macros xwiki rce vulnerability java web-application
1t
critical advisory

Gogs Remote Code Execution via git rebase --exec Argument Injection (GHSA-qf6p-p7ww-cwr9)

Gogs, a self-hosted Git service, is vulnerable to a Critical (CVSS 9.9) Remote Code Execution (RCE) via `git rebase --exec` argument injection (GHSA-qf6p-p7ww-cwr9) during pull request merge operations, allowing an authenticated attacker to execute arbitrary commands as the Gogs server process user and achieve full server compromise.

Gogs 0.14.2 +2 rce gogs git code-repository vulnerability argument-injection server-side-request-forgery
1r 5t
critical advisory

motionEye: LFI → Pass-the-Hash Admin → Unsafe Restore → Unauthenticated Action Execution (RCE)

An attacker can chain multiple vulnerabilities in motionEye, including an arbitrary file read (LFI), a signature bypass using password hashes, and an unsafe configuration restore, to achieve unauthenticated remote code execution (RCE) if the normal user password is unset, or authenticated RCE from a normal user account.

motionEye RCE LFI vulnerability unauthenticated privilege-escalation
1r 5t
medium advisory

dnsmasq Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in dnsmasq to initiate a Denial of Service attack, disrupting the service's availability.

dnsmasq vulnerability dos network linux
1t
high threat

Dell PowerProtect Data Domain: Multiple Vulnerabilities

Multiple vulnerabilities in Dell PowerProtect Data Domain could allow an attacker to elevate privileges, execute arbitrary code, bypass security controls, perform a Denial of Service attack, conduct Cross-Site Scripting, disclose information, and manipulate files.

exploited PowerProtect Data Domain vulnerability server dell data-protection
6t
critical advisory

OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints (CVE-2026-45052)

An improper authorization vulnerability (CVE-2026-45052) in OpenAM Community Edition through version 16.0.6 allows an unauthenticated attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry and a shared root-realm Discovery branch, due to a flaw in the Liberty Web Services SOAP receiver that permits anonymous writes with elevated internal privileges, potentially influencing service routing or security mechanisms if Liberty discovery data is consumed.

OpenAM Community Edition +1 vulnerability identity-management web-application openam
2t
critical advisory

i18next-fs-backend Prototype Pollution via Crafted Missing-Key String (CVE-2026-48713)

Untrusted input can exploit a prototype pollution vulnerability (CVE-2026-48713) in `i18next-fs-backend` versions prior to 2.6.6, particularly via `i18next-http-middleware`'s `missingKeyHandler`, by submitting crafted missing-key strings that leverage the `keySeparator` to write arbitrary properties onto `Object.prototype`, leading to crashes, configuration poisoning, or security bypasses.

i18next-fs-backend < 2.6.6 +1 prototype-pollution node.js web-application vulnerability
1r 1t 1c
critical threat

golang.org/x/crypto/ssh FIDO/U2F Physical Presence Bypass (CVE-2026-39831)

A critical vulnerability (CVE-2026-39831) in the `Verify()` method of the `golang.org/x/crypto/ssh` package (versions prior to 0.52.0) allowed the physical presence check for FIDO/U2F security key types to be bypassed, enabling unattended use of hardware security keys and potentially leading to unauthorized SSH access.

exploited golang.org/x/crypto/ssh ssh vulnerability golang fido u2f
1c
critical advisory

Critical Incus Vulnerability (CVE-2026-48752) Allows Host Arbitrary File Read/Write Leading to RCE

A critical vulnerability, CVE-2026-48752, in Incus versions prior to 7.2.0 allows an unauthenticated attacker to achieve arbitrary file read and write on the host system via specially crafted container images or instance backups containing unsanitized symlinks, potentially leading to arbitrary command execution as root.

incusd vulnerability rce symlink linux incus container
1r 6t
critical advisory

Incus S3 Multipart Upload Path Traversal Leading to RCE (CVE-2026-48753)

The Incus `incusd` daemon, specifically its S3 protocol multipart upload endpoint in versions prior to 7.1.0, is vulnerable to CVE-2026-48753, a critical path traversal flaw via the `uploadId` parameter, enabling unauthenticated attackers to write arbitrary files to any location on the host system, which can be leveraged for persistent arbitrary command execution.

incusd < 7.1.0 path-traversal rce incus s3 linux vulnerability
1r 3t
critical advisory

Deepstream Server Prototype Pollution (CVE-2026-49252) Allows Privilege Escalation

Deepstream server versions up to and including 10.0.4 are vulnerable to prototype pollution (CVE-2026-49252), a critical flaw allowing any authenticated user with write permissions to any record to potentially escalate their privileges; the vulnerability is patched in version 10.0.5.

deepstream server +1 prototype-pollution vulnerability privilege-escalation deepstream npm
1r 1t 1c
critical advisory

CVE-2026-58455: Dockwatch Unauthenticated OS Command Injection

Remote attackers can exploit an unauthenticated OS command injection vulnerability (CVE-2026-58455) in Dockwatch versions up to 0.6.567, arising from a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compose.php, to execute arbitrary shell commands leading to full host compromise, especially in deployments where the Docker socket is mounted.

PoC Dockwatch <= 0.6.567 vulnerability rce web-application linux
1r 2t 1c updated
high advisory

Multiple Vulnerabilities in Google Chrome (CVE-2026-13774 through CVE-2026-13895)

Multiple vulnerabilities, including CVE-2026-13774 through CVE-2026-13895, have been discovered in Google Chrome, allowing an attacker to cause an unspecified security problem on affected Windows, Linux, and macOS systems by exploiting these flaws.

PoC Chrome +5 vulnerability patch-management browser google-chrome cve chromium v8 rce +1
5c 5i updated
high advisory

CVE-2026-58593: NodeBB ActivityPub Forgery Vulnerability

A critical vulnerability (CVE-2026-58593) in NodeBB's ActivityPub implementation allows a remote attacker to forge posts and direct messages attributed to arbitrary local users, including administrators, by manipulating the 'attributedTo' field in inbound ActivityPub objects.

PoC NodeBB +1 activitypub federation vulnerability web-application cms forgery
1t 1c updated
critical advisory

CVE-2026-58457: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated OS Command Injection

An unauthenticated OS command injection vulnerability, CVE-2026-58457, exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02), allowing network-adjacent attackers to execute arbitrary shell commands and gain full root-level control by injecting unsanitized input into the `smacfilter_conf` handler's GET parameters within the `commuos` web backend.

M300 Wi-Fi Repeater +2 network command-injection vulnerability firmware iot
1r 2t 4i updated
high advisory

CVE-2026-57516: Ray Unsafe Deserialization Leading to RCE

An unsafe deserialization vulnerability (CVE-2026-57516) exists in the WebDataset reader of the Ray framework prior to version 2.56.0, allowing remote attackers to achieve arbitrary code execution on Ray remote workers by supplying a malicious tar archive to the `read_webdataset()` function, which then unconditionally calls `pickle.loads()` on .pkl/.pickle entries or `torch.load()` with `weights_only=False` on .pt/.pth entries, executing arbitrary code.

Ray vulnerability deserialization rce execution
1t 1c updated
medium advisory

ClamAV Vulnerabilities Lead to Denial of Service in Cisco Secure Endpoint Products

Multiple vulnerabilities (CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244) in ClamAV, as integrated into Cisco Secure Endpoint Connector, allow a remote attacker to cause a denial of service (DoS) condition by interrupting scanning operations, with a High severity impact on Windows platforms and Medium on Linux/Mac.

Cisco Secure Endpoint Connector +3 vulnerability dos clamav cisco security-software
1t 7c updated
critical advisory

CVE-2026-58138: Unauthenticated Remote Code Execution in Orkes Conductor

An unauthenticated remote code execution vulnerability (CVE-2026-58138) in Orkes Conductor allows attackers to execute arbitrary OS commands by submitting malicious JavaScript or Python expressions within inline workflow definitions to the workflow API endpoint before authentication, leveraging unsandboxed GraalVM evaluators through specific task types to invoke system commands via Java reflection or direct subprocess calls.

Conductor 3.21.21 +2 RCE vulnerability Java Conductor web-application
1r 3t 2i updated
high threat

Multiple SQL Injection Vulnerabilities in Tenable Nessus (CVE-2026-57587, CVE-2026-57588)

Multiple SQL injection vulnerabilities, CVE-2026-57587 and CVE-2026-57588, have been discovered in Tenable Nessus versions prior to 10.12.0, allowing an attacker to perform unauthorized access to or manipulation of the underlying database through specially crafted input.

PoC Nessus +1 vulnerability sqli tenable exploitation
1t 2c 10i updated
high advisory

CVE-2026-12957: Amazon Q VS Code Extension Arbitrary Code Execution

A high-severity vulnerability (CVE-2026-12957) in the Amazon Q Developer Extension for Visual Studio Code allowed attackers to achieve arbitrary code execution and cloud credential theft by automatically loading and executing malicious Model Context Protocol (MCP) server configurations from a `.amazonq/mcp.json` file in a repository without user consent, providing full access to a developer's environment and cloud credentials.

PoC Amazon Q Developer Extension for Visual Studio Code +5 vulnerability code-editor cloud rce vs-code supply-chain
1r 4t 1c 2i updated
high advisory

Multiple Vulnerabilities in Squid Proxy (CVE-2026-47729, CVE-2026-50012)

Multiple vulnerabilities, including CVE-2026-47729 and CVE-2026-50012, have been identified in Squid proxy versions prior to 7.6, allowing an attacker to compromise data confidentiality and cause other unspecified security issues.

Squid +1 vulnerability proxy data-confidentiality network-device
3t 2c updated
critical advisory

Critical Privilege Escalation in WordPress Branda Plugin (CVE-2026-11551)

An unauthenticated attacker can exploit CVE-2026-11551, a critical privilege escalation vulnerability in the WordPress Branda plugin up to version 3.4.29, by leveraging improper identity validation to change arbitrary user passwords, including administrators, leading to full account takeover and potential compromise of the WordPress site.

PoC Branda plugin wordpress plugin vulnerability privilege-escalation account-takeover web-application
2r 2t 1c updated
high advisory

CVE-2026-56073: Cap-go OTP Verification Authentication Bypass

Cap-go versions prior to 12.128.2 are susceptible to an authentication bypass vulnerability (CVE-2026-56073) in OTP verification that allows attackers to manipulate server responses to falsely mark verification successful, leading to unauthorized 2FA enablement and subsequent account takeover.

Cap-go authentication-bypass web-application vulnerability account-takeover cve network-attack
2r 2t
high advisory

Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent (CVE-2026-54896)

The `Oj.dump` function in the Ruby `oj` gem, when operating in object mode, is vulnerable to a heap buffer overflow (CVE-2026-54896) when serializing `Exception` objects with an excessively large `:indent` value, leading to memory corruption and potential denial of service or remote code execution.

oj gem ruby vulnerability heap-overflow
2r 2t
high advisory

Arbitrary Host File Read via Symlink Following in containerd CRI Checkpoint Restore (CVE-2026-53489)

A high-severity vulnerability (CVE-2026-53489) in containerd's CRI plugin allows an unprivileged attacker to read arbitrary files on the host system by crafting a malicious checkpoint with a symlink that `containerd` follows during `container.log` restoration, enabling data exfiltration via `kubectl logs`.

containerd v2.1.0-2.1.8 +2 container kubernetes vulnerability data-exfiltration linux
3r 2t
high advisory

containerd CRI Checkpoint Restore CDI Annotation Smuggling Vulnerability (CVE-2026-53492)

A high-severity vulnerability (CVE-2026-53492) in containerd's CRI implementation allows an attacker with pod creation permissions to smuggle arbitrary Container Device Interface (CDI) annotations during container restoration, bypassing Kubernetes resource allocation and enabling unauthorized device and host mount injection into the restored container.

containerd +2 kubernetes vulnerability privilege-escalation linux cloud
2r 2t
high advisory

Hugo security.http.urls Bypass via Alternate IPv4 Encodings (SSRF)

A Server-Side Request Forgery (SSRF) vulnerability exists in Hugo versions 0.162.0 through 0.163.0, where the 'security.http.urls' policy designed to deny requests to loopback, internal, and cloud-metadata IPv4 literals could be bypassed as the policy only matched dotted-decimal notation, allowing alternate IPv4 encodings (integer, hex, octal) to pass, enabling build-time server-side requests to internal services and cloud-metadata endpoints when untrusted or data-derived URLs are passed to 'resources.GetRemote'.

Hugo ssrf vulnerability build-time webserver
2r 3t
high advisory

Joomla! Component Sponsor Wall 8.0 SQL Injection (CVE-2017-20264)

An unauthenticated SQL injection vulnerability (CVE-2017-20264) in Joomla! Component Sponsor Wall version 8.0 allows attackers to execute arbitrary SQL queries by injecting malicious code into the `wallid` parameter of GET requests to `index.php`, leading to the extraction of sensitive database information such as credentials and configuration data.

Joomla! Component Sponsor Wall 8.0 sql-injection joomla web-application vulnerability cve
1r 3t
high advisory

CVE-2017-20256 - Joomla Survey Force Deluxe SQL Injection Vulnerability

CVE-2017-20256 describes an SQL injection vulnerability in Joomla Survey Force Deluxe 3.2.4 that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'invite' parameter in GET requests, enabling the extraction of sensitive database information.

Survey Force Deluxe 3.2.4 sql-injection joomla web-application vulnerability cve
2r 3t
high advisory

CVE-2016-20089: Iperius Remote Unquoted Service Path Vulnerability

An unquoted service path vulnerability, CVE-2016-20089, in Iperius Remote version 1.7.0 allows a local attacker to execute arbitrary code with SYSTEM privileges by placing a malicious executable in a specific directory when the legitimate service path contains spaces, enabling privilege escalation upon service restart or system reboot.

Iperius Remote 1.7.0 privilege-escalation windows vulnerability unquoted-service-path
2r 1t 4i
critical advisory

DotVVM AuthorizeActionFilter Critical Authorization Bypass

A critical authorization bypass vulnerability exists in the `AuthorizeActionFilter` class within the DotVVM framework, failing to perform any authorization checks and allowing attackers to bypass intended access restrictions without specific exploitation techniques, impacting all users relying on `AuthorizeActionFilter` for security. Patched versions include DotVVM 4.3.15, 4.2.11, and 5.0.0-preview09; `AuthorizeAttribute` can be used as a workaround.

DotVVM +2 authorization-bypass web-application vulnerability
2r 2t
medium advisory

undici WebSocket Client Vulnerable to Denial of Service (CVE-2026-12151)

The `undici` WebSocket client is vulnerable to CVE-2026-12151, a high-severity denial of service attack where a malicious WebSocket server can stream numerous small continuation frames that bypass `maxPayloadSize` checks, causing unbounded memory growth and exhaustion in affected client processes.

undici +2 denial-of-service vulnerability javascript npm nodejs
2r 1t
high advisory

Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server

An unauthenticated attacker can exploit CVE-2026-55882 in Tilt HUD server versions 0.19.5 through 0.37.3, when exposed on a non-loopback address, by accessing the `/debug/pprof` endpoints to read sensitive process memory, including session and API server tokens, and to degrade application performance through prolonged CPU profiling or tracing.

Tilt HUD server vulnerability rce data-exfiltration golang webserver
2r 3t
high advisory

Gitea Security Bypass Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Gitea to bypass existing security measures, potentially leading to unauthorized access, privilege escalation, or data manipulation within the application.

Gitea vulnerability web-application defense-evasion
1t
medium advisory

Vim Denial of Service Vulnerability

A vulnerability in the vim text editor allows a remote, unauthenticated attacker to perform a Denial of Service attack by exploiting a weakness to disrupt the service without requiring prior authentication.

vim denial-of-service vulnerability text-editor linux macos windows
2r 1t
medium advisory

libssh2 Vulnerability: Denial of Service and Information Disclosure

A vulnerability in the libssh2 library allows a remote, unauthenticated attacker to perform a Denial of Service (DoS) attack or disclose sensitive information, potentially leading to service disruption or unauthorized data exposure.

libssh2 ssh vulnerability dos information-disclosure library
3r 2t
medium advisory

Multiple Vulnerabilities in expat XML Parser Library

Multiple vulnerabilities have been discovered in the expat XML parser library that can be exploited by a local attacker, potentially leading to a Denial of Service condition or allowing for arbitrary code execution on the affected system.

expat vulnerability library xml denial-of-service code-execution local-exploitation
2r 2t
high advisory

Google Cloud Platform (GKE containerd): Multiple Vulnerabilities

An authenticated remote attacker can exploit multiple vulnerabilities in Google Cloud Platform, specifically within GKE containerd, to achieve arbitrary code execution, bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.

Cloud Platform +2 cloud-security container-security vulnerability rce
3r 5t
high advisory

pgAdmin: Multiple Vulnerabilities Lead to RCE, SQLi, XSS

A remote, authenticated attacker can exploit multiple vulnerabilities in pgAdmin to achieve arbitrary code execution with user or administrator privileges, bypass security measures, perform SQL Injection and Cross-Site Scripting attacks, redirect users to malicious websites, disclose sensitive information, and manipulate data. This comprehensive set of capabilities allows for significant compromise of system integrity, confidentiality, and potentially availability, posing a high risk to affected environments.

pgAdmin vulnerability web-application rce sql-injection xss
3r 6t
medium advisory

OpenBSD Information Disclosure Vulnerability

A remote, anonymous attacker can exploit a vulnerability in OpenBSD to disclose sensitive information, potentially leading to unauthorized data exposure.

OpenBSD vulnerability information-disclosure linux
3r 1t
critical advisory

CVE-2026-47647: Critical Privilege Escalation in Microsoft Dynamics 365

CVE-2026-47647 describes a critical improper access control vulnerability in Microsoft Dynamics 365 that allows an authorized attacker to elevate privileges over a network, potentially leading to full compromise of the affected system.

Microsoft Dynamics 365 privilege-escalation vulnerability microsoft dynamics365 web-application
2r 1t 1c
high advisory

PHP JWT Framework Algorithm Confusion Vulnerability (TOCTOU)

A Time-of-Check/Time-of-Use (TOCTOU) vulnerability exists in the `JWSVerifier` and `JWEDecrypter` components of the `web-token/jwt-framework` and `web-token/jwt-library` PHP packages, allowing an attacker to override the integrity-protected `alg` parameter from the unprotected header, leading to authentication bypass and unauthorized access.

jwt-framework <= 4.2.99 +3 vulnerability php jwt web authentication-bypass
2r 2t
medium advisory

spomky-labs/otphp Unbounded Digits Parameter Leads to Denial of Service

The spomky-labs/otphp library is vulnerable to a denial of service (GHSA-g7m4-839x-ch6v) where an unbounded 'digits' parameter in an otpauth provisioning URI causes a DivisionByZeroError, leading to unhandled fatal errors in applications trying to generate or verify OTPs.

otphp < 11.4.3 php denial-of-service vulnerability ghsa
2r 1t
high threat

Drupal Security Advisory AV26-615: Multiple Critical Vulnerabilities

On June 17, 2026, Drupal released critical security advisories (AV26-615) addressing multiple vulnerabilities in Drupal core and several modules including Plotly.js Graphing, Flag attendance field, and Formatter Field, which, if unpatched, could allow remote attackers to compromise affected web servers and sensitive data.

exploited Drupal core +3 web-application drupal vulnerability cccs-advisory
3r 7t
medium advisory

CVE-2026-55204: HAProxy Null Pointer Dereference Leads to Denial of Service

An unauthenticated attacker can exploit CVE-2026-55204, a null pointer dereference vulnerability in HAProxy through version 3.4.0, by triggering excessive HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash and resulting in a denial of service.

HAProxy 3.4.0 denial-of-service vulnerability HAProxy CVE-2026-55204
2r 1t
high advisory

CVE-2026-55203 HAProxy Integer Overflow in FastCGI Handling

An integer overflow vulnerability (CVE-2026-55203) in HAProxy through version 3.4.0 allows malicious FastCGI backends to desynchronize the FCGI framing parser, leading to request routing errors, response smuggling, or memory safety issues.

HAProxy vulnerability fastcgi integer-overflow webserver proxy
2r 3t
high advisory

Kirby CMS Missing Authorization Vulnerability in /api/site/find (CVE-2026-54005)

An authenticated user can exploit CVE-2026-54005, a high-severity missing authorization vulnerability in Kirby CMS versions <= 4.9.3 and from 5.0.0-alpha.1 to <= 5.4.3, via the `/api/site/find` REST API route to bypass `pages.access` permissions and retrieve sensitive content and metadata from unauthorized pages.

composer/getkirby/cms +1 cms vulnerability kirby information-disclosure api webserver
2r 3t
critical advisory

Exploitation of CVE-2026-8024 in ibaPDA and ibaDatCoordinator via Deserialization of Untrusted Data

A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability (CVE-2026-8024) in ibaPDA (versions prior to 8.14.0) or ibaDatCoordinator (versions prior to 4.0.7) to gain full access to the affected systems, potentially leading to arbitrary code execution and system compromise.

ibaPDA +1 deserialization rce ics scada vulnerability windows
2r 2t
high threat

Heimdall Proxy Forwarded Header Injection via Unsanitized Host Header

Attackers can exploit Heimdall proxy versions <= 0.17.16 operating in proxy mode by injecting malicious values into the `Host` HTTP header, leading to the construction of a manipulated `Forwarded` header that can spoof client IP addresses for upstream services, potentially bypassing IP-based access controls.

exploited Heimdall header-injection proxy access-control-bypass ip-spoofing vulnerability web
1r 1t
high threat

npm PraisonAI SandboxExecutor Network Isolation Bypass Vulnerability (GHSA-gqmf-56h7-rrpf)

The npm package `praisonai` versions 1.2.3 through 1.7.1 contain a network isolation bypass vulnerability (GHSA-gqmf-56h7-rrpf) in its `SandboxExecutor` component's `network-isolated` mode, allowing non-proxy-aware client commands to establish direct network connections, leading to potential data exfiltration and access to internal services.

praisonai vulnerability npm sandbox network-bypass ghsa
2r 3t
high advisory

npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining

A critical command injection vulnerability exists in the `npm:praisonai` package versions >= 1.2.3 and <= 1.7.1, where the `SandboxExecutor`'s `allowedCommands` policy is bypassed by allowing arbitrary shell command chaining after an allowlisted command, leading to remote code execution with the PraisonAI process privileges.

npm:praisonai command-injection npm nodejs sandbox-bypass vulnerability rce server-side
1r 1t
high advisory

undici TLS Validation Bypass via SOCKS5 ProxyAgent (CVE-2026-9697)

A vulnerability in undici's ProxyAgent, when configured with a SOCKS5 proxy, causes the `requestTls` option to be silently dropped. This bypasses user-configured TLS certificate validation settings (e.g., custom CAs), allowing HTTPS connections through the SOCKS5 tunnel to fall back to the Node.js default trust store. This flaw enables Man-in-the-Middle (MITM) attacks, where any publicly-trusted certificate for the target hostname would be accepted, compromising the intended certificate pinning and allowing attackers to read or tamper with HTTPS traffic.

undici +1 vulnerability tls-bypass node.js npm
2r
high advisory

CVE-2026-8863 UEFI Secure Boot Security Feature Bypass Vulnerability

An authorized attacker with local access can exploit CVE-2026-8863, a security feature bypass vulnerability in Windows UEFI, to circumvent Secure Boot and load unauthorized software, potentially enabling persistent rootkit installation.

PoC Windows UEFI +2 uefi secure-boot bypass windows vulnerability defense-evasion
2r 1t 1c 11i updated
critical advisory

Progress Security Advisory (AV26-552) Addressing Multiple Critical Vulnerabilities

Progress released critical security advisories between June 2 and 4, 2026, addressing multiple vulnerabilities, including CVE-2026-7312, CVE-2026-7198, CVE-2026-7195, CVE-2026-7201, CVE-2026-7313, CVE-2026-8037, and CVE-2026-33691, in Sitefinity CMS, Sitefinity Insight, and Progress Kemp LoadMaster, which could lead to various impacts if exploited, necessitating immediate patching.

PoC Sitefinity CMS +9 vulnerability web-application cms load-balancer patch-management cve
3r 1t 5c 4i updated
medium advisory

Multiple Vulnerabilities in Microsoft .Net (CVE-2026-45491, CVE-2026-45591)

Multiple vulnerabilities, CVE-2026-45491 and CVE-2026-45591, have been discovered in Microsoft .Net and ASP.NET Core versions, allowing a remote attacker to cause a denial of service and compromise data integrity across Windows, Linux, and macOS platforms.

.NET 10.0 +5 vulnerability denial-of-service data-integrity dotnet microsoft
2r 2t 2c
high advisory

Multiple Xen Hypervisor Vulnerabilities Leading to Privilege Escalation, DoS, and Data Confidentiality Compromise

Multiple vulnerabilities, including CVE-2025-10263, CVE-2026-42487, CVE-2026-42488, CVE-2026-42489, and CVE-2026-42490, have been discovered in Xen, allowing an attacker to achieve privilege escalation, trigger a remote denial of service, and compromise data confidentiality on vulnerable hypervisor instances.

Xen virtualization hypervisor vulnerability privilege-escalation denial-of-service data-exfiltration
3r 3t 1c
high threat

Multiple Vulnerabilities in Microsoft Office Products (June 2026)

CERT-FR has disclosed 31 vulnerabilities in various Microsoft Office products, including CVE-2026-44803 and CVE-2026-47635, which could allow remote code execution, privilege escalation, and data confidentiality compromise.

exploited Microsoft 365 Apps pour Enterprise pour systèmes 32 bits +21 vulnerability microsoft-office remote-code-execution privilege-escalation data-confidentiality windows macos android
3r 4t 5c
high advisory

Multiple Privilege Escalation Vulnerabilities in FreeBSD (CVE-2026-45257, CVE-2026-49413)

Multiple vulnerabilities, including CVE-2026-45257 (kernel out-of-bounds write) and CVE-2026-49413 (Linux compatibility layer memory mapping), exist in FreeBSD branches 14 and 15, allowing a local unprivileged attacker to achieve privilege escalation.

FreeBSD branch 14 versions prior to 14-n274315 +5 freebsd vulnerability privilege-escalation local-privilege-escalation
3r 4i
critical advisory

Multiple Critical Vulnerabilities in Fortinet Products Lead to RCE and Data Exposure

Multiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been discovered across Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox, enabling unauthenticated attackers to achieve remote arbitrary code execution and compromise data confidentiality.

FortiOS +11 remote-code-execution data-exfiltration vulnerability fortinet network-appliance
2r 4t 3c 6i
high threat

Multiple Critical Vulnerabilities in Siemens SCALANCE Industrial Network Products, Including Unpatched Devices

Multiple high-severity vulnerabilities, including CVE-2025-15467, affect various Siemens SCALANCE LPE, M, W, and X series industrial network devices, potentially allowing a remote attacker to achieve arbitrary code execution, provoke a denial of service, or compromise data confidentiality, with some products confirmed to receive no future patches.

SCALANCE LPE9413 +99 industrial_control_systems ics_scada vulnerability siemens network_device ot
3r 4t 1c
critical advisory

Vulnerability in Veeam Backup & Replication Allowing Remote Code Execution (CVE-2026-44963)

A critical remote code execution vulnerability, tracked as CVE-2026-44963, has been discovered in Veeam Backup & Replication versions prior to 12.3.2.4854, which could allow an unauthenticated attacker to execute arbitrary code on affected systems, leading to full compromise of the backup infrastructure and potential data exfiltration or destruction.

Veeam Backup & Replication < 12.3.2.4854 remote-code-execution vulnerability veeam backup-replication data-exfiltration data-destruction windows
3r 2t 1c 2i
high advisory

Vulnerability in Schneider Electric EcoStruxure IT Data Center Expert Leads to Data Confidentiality Compromise (CVE-2026-8045)

A critical vulnerability, CVE-2026-8045, has been identified in Schneider Electric EcoStruxure IT Data Center Expert versions prior to 9.1.2, allowing an attacker to achieve unauthorized access to sensitive data and compromise its confidentiality.

EcoStruxure IT Data Center Expert vulnerability scada ics data-confidentiality information-disclosure
2r 3t 1c
high advisory

Multiple Vulnerabilities Discovered in SAP Products Including SQLi, XSS, and Policy Bypass

Multiple high-severity vulnerabilities discovered in various SAP products, including SQL injection (SQLi), remote indirect code injection (XSS), and security policy bypasses, could allow unauthenticated attackers to compromise sensitive enterprise systems by June 2026.

Business Objects Business Intelligence Platform +86 sap vulnerability sqli xss web-application
2r 5t 5i updated
high advisory

CVE-2026-7473: Arista EOS Incomplete Comparison Vulnerability Leading to Incorrect Packet Forwarding

Arista Extensible Operating System (EOS) contains CVE-2026-7473, an incomplete comparison vulnerability that allows a switch to incorrectly decapsulate and forward unexpected tunneled packets if their destination IP matches the switch's configured decapsulation IP, potentially leading to unauthorized network access or bypass of security controls.

PoC Extensible Operating System +4 vulnerability cve network-device infrastructure
2r 3t 3c updated
critical advisory

CloudCharge Vulnerabilities Allow Charging Station Impersonation and DoS

Multiple vulnerabilities in CloudCharge cloudcharge.se allow attackers to impersonate charging stations, hijack sessions, cause denial of service, and manipulate backend data, impacting energy and transportation sectors.

cloudcharge.se cloudcharge ics vulnerability dos
2r 3t 2i
high advisory

Pixa Bank 2.0 Unauthenticated SQL Injection Vulnerability

Pixa Bank 2.0 is vulnerable to SQL injection, allowing unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter via POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads, potentially leading to the retrieval of user information such as names, email addresses, and phone numbers from the database.

Pixa Bank 2.0 sql-injection vulnerability web-application
2r 1t 1c
medium threat

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.

Elastic Defend +43 persistence initial-access vulnerability linux
2r 3t
medium advisory

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.

Elastic Defend endpoint linux persistence initial-access vulnerability
3r 2t
high advisory

Multiple Vulnerabilities in NetApp Products

Multiple vulnerabilities in NetApp products, including CVE-2023-0482, CVE-2023-20863, CVE-2024-22257, CVE-2025-23367, CVE-2025-48976, CVE-2025-53816, and CVE-2025-53817, could lead to remote denial of service, data confidentiality breaches, and data integrity breaches.

Active IQ Unified Manager +2 vulnerability netapp denial-of-service data-breach integrity
2r 5c
high advisory

Keycloak Vulnerability Allows Data Confidentiality Breach and Security Policy Bypass

A vulnerability in Keycloak versions prior to 26.2.14, 26.4.10, and 26.5.5 allows an attacker to cause a breach of data confidentiality and bypass the security policy, as tracked by CVE-2026-2092.

Keycloak +2 vulnerability data breach security policy bypass
2r 1t 1c
medium advisory

CISA ICS Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories between May 25 and 31, 2026, addressing vulnerabilities across various vendors including ABB, CP Plus, Eppendorf, Frontier, Jinan USR IOT, KMW, MacGregor, Schneider Electric, and XCharge, impacting industrial control systems and related applications.

AC500 V2 +19 ics vulnerability cisa
2r
medium threat

Dell Security Advisory Addressing Multiple Product Vulnerabilities

Dell released security advisories in May 2026 to address vulnerabilities in PowerEdge Server Chipset Driver, Data Lakehouse, Dell Enterprise SONiC Distribution, and Dell Unity/UnityVSA/Unity XT.

PowerEdge Server Chipset Driver +5 vulnerability dell patch
2r
critical advisory

Multiple Vulnerabilities in JetBrains TeamCity

Multiple vulnerabilities in JetBrains TeamCity allow an attacker to disclose information, perform a cross-site scripting attack, bypass security measures, and execute arbitrary program code.

TeamCity vulnerability code-execution xss information-disclosure
2r 3t
high advisory

Multiple Vulnerabilities in IBM Business Automation Workflow

Multiple vulnerabilities in IBM Business Automation Workflow can be exploited by an attacker to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, and conduct a cross-site scripting attack.

Business Automation Workflow vulnerability denial-of-service information-disclosure cross-site-scripting
2r 2t
high advisory

Multiple Vulnerabilities in IBM App Connect Enterprise

Multiple vulnerabilities in IBM App Connect Enterprise could allow an attacker to bypass security measures, manipulate data, disclose sensitive information, cause a denial-of-service condition, or perform other unspecified attacks.

App Connect Enterprise vulnerability denial-of-service data-manipulation
2r
high advisory

Notepad++ Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in Notepad++ to execute arbitrary program code, potentially leading to system compromise.

Notepad++ code-execution vulnerability windows
2r 1t
high threat

SQL Injection Vulnerability in student_management_system_by_php (CVE-2026-10225)

A SQL injection vulnerability exists in raisulislamg4's student_management_system_by_php up to commit 310d950e09013d5133c6b9210aff9444382d16d1, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username argument in login_check.php.

exploited student_management_system_by_php sql-injection vulnerability web-application
2r 1t 1c
high advisory

GoClaw OS Command Injection Vulnerability (CVE-2026-10219)

nextlevelbuilder GoClaw up to 3.11.3 is vulnerable to remote OS command injection via manipulation of the write_file Tool component's FsBridge.WriteFile function (CVE-2026-10219), with a public exploit available.

GoClaw <= 3.11.3 command-injection vulnerability webserver
2r 1t 1c
high threat

Open ISES Project 3.30A Unauthenticated Path Traversal Vulnerability

Open ISES Project 3.30A is vulnerable to path traversal (CVE-2018-25408), allowing unauthenticated attackers to download arbitrary files by manipulating the filename parameter in the ajax/download.php endpoint, potentially exposing configuration and system files.

Open ISES Project 3.30A path-traversal vulnerability web-application
2r 1t 1c
medium advisory

CVE-2026-41184 ServiceAccount Token Disclosure via install-cni Container Logs

CVE-2026-41184 is a ServiceAccount token disclosure vulnerability in container logs addressed by a Microsoft security update.

vulnerability token-disclosure kubernetes CVE-2026-41184
2r 1t 1c
high advisory

praisonai-platform: Cross-Workspace Label IDOR Vulnerability

Praison AI's praisonai-platform is vulnerable to an insecure direct object reference (IDOR) in the label endpoints (CVE-2026-47414), allowing cross-workspace label modification and information disclosure due to improper validation of label and issue IDs.

praisonai-platform idor vulnerability privilege-escalation collection impact cloud
2r 3t
high advisory

Ouroboros-AI Remote Code Execution via Malicious .env File

A remote code execution vulnerability exists in Ouroboros-AI versions prior to 0.39.0, enabling attackers to inject malicious scripts via CLI path variables within a cloned repository's .env file, leading to arbitrary code execution when Ouroboros commands are executed.

ouroboros-ai rce vulnerability supply_chain
2r 1t
high advisory

AgenticMail API and Core Packages Vulnerabilities

Multiple vulnerabilities, including SQL injection and SMTP header injection, have been discovered in AgenticMail API and Core packages, addressed in versions greater than 0.9.31 and 0.9.9 respectively, posing a risk of unauthorized access and control.

@agenticmail/api +1 vulnerability sqlinjection smtpheaderinjection
2r
high advisory

SQL Injection Vulnerability in ezsystems ezpublish-legacy dfscleanup

A SQL injection vulnerability exists in ezpublish-legacy, specifically in the dfscleanup.php script and the `_getFileList` function of the `eZDFSFileHandlerMySQLiBackend` class, allowing an attacker with local shell access to potentially expose sensitive data such as user credentials.

ezpublish-legacy sqli vulnerability
1r 1t
high advisory

Multiple Vulnerabilities in Elastic Kibana

Multiple vulnerabilities in Elastic Kibana allow for privilege escalation, remote denial of service, data breach, server-side request forgery (SSRF), and cross-site scripting (XSS).

Kibana +2 vulnerability privilege escalation denial of service data breach SSRF XSS
2r 3t 5c
critical threat

Multiple Vulnerabilities in OpenClaw Allow for Privilege Escalation, Code Execution, and SSRF

A remote, authenticated attacker can exploit multiple vulnerabilities in OpenClaw to bypass security mechanisms, gain elevated privileges, disclose information, manipulate configurations, execute arbitrary commands or code, and attack internal systems via SSRF.

OpenClaw vulnerability code-execution privilege-escalation ssrf
2r 4t
critical advisory

Red Hat Enterprise Linux Flatpak Multiple Vulnerabilities Allow Code Execution and File Deletion

An authenticated attacker can exploit multiple vulnerabilities in the Flatpak package of Red Hat Enterprise Linux to execute arbitrary program code and delete files.

Flatpak rhel vulnerability code_execution file_deletion
2r 1t
medium advisory

Mautic SQL Injection Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Mautic to perform a SQL injection attack, potentially leading to unauthorized data access or modification.

Mautic sql-injection vulnerability
2r 1t
high threat

Multiple Vulnerabilities in Check Point Security Gateway

Multiple vulnerabilities exist in Check Point Security Gateway that could be exploited by an attacker to perform a denial of service attack, disclose information, and perform a SQL injection attack.

Security Gateway vulnerability denial-of-service sql-injection information-disclosure checkpoint
2r 3t
medium advisory

Red Hat OpenShift Tempo Vulnerabilities Allow Remote Exploitation

Multiple vulnerabilities in Red Hat OpenShift Tempo allow an unauthenticated remote attacker to bypass security measures, disclose sensitive information, manipulate data, or cause a denial of service condition.

OpenShift Tempo openshift tempo vulnerability
1r 3t
medium advisory

CVE-2026-46834 - Oracle Database Server Net Service Denial of Service

CVE-2026-46834 is a vulnerability in the Net Service component of Oracle Database Server versions 23.4.0 to 23.26.2 that allows an unauthenticated attacker with network access via TLS to cause a denial-of-service (DoS) condition.

Database Server vulnerability dos oracle
2r 1t 1c
high advisory

CVE-2026-46826 - Oracle Payroll Vulnerability Allows Takeover

CVE-2026-46826 is a vulnerability in Oracle Payroll within Oracle E-Business Suite, where a low-privileged attacker can achieve a system takeover via network access over HTTPS.

Payroll +1 oracle e-business suite rce vulnerability
2r 2t 1c
medium advisory

CVE-2026-35266: Oracle REST Data Services Vulnerability Allows Unauthorized Data Access and Modification

A vulnerability exists in Oracle REST Data Services versions 24.2.0 to 26.1.0, where a low-privileged attacker with network access via HTTPS can, with human interaction, gain unauthorized data access, modification, and cause a partial denial of service.

REST Data Services vulnerability oracle ords
2r 1c
critical advisory

CVE-2026-46840 - Oracle REST Data Services Takeover Vulnerability

CVE-2026-46840 is a critical vulnerability in Oracle REST Data Services (ORDS) that allows an unauthenticated attacker with network access to achieve complete takeover of the service, potentially impacting additional products due to scope change.

REST Data Services oracle rds rest vulnerability cve-2026-46840 takeover
2r 1c
critical advisory

CVE-2026-46822 - Oracle iAssets Remote Code Execution Vulnerability

CVE-2026-46822 is a vulnerability in Oracle iAssets within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15, allowing a low-privileged attacker with network access via HTTP to compromise the application, potentially impacting other products within the environment.

iAssets oracle e-business-suite rce vulnerability
2r 1c
critical advisory

CVE-2026-46775 - Oracle REST Data Services Takeover via Network Access

CVE-2026-46775 is a critical vulnerability in Oracle REST Data Services (Core component) versions 24.2.0-26.1.0, allowing a low-privileged attacker with network access via HTTPS to achieve complete takeover of the service and potentially impact other products.

Oracle REST Data Services cve vulnerability rce oracle network privilege-escalation initial-access
2r 1c
medium advisory

Tanium Connect Multiple Vulnerabilities

Tanium released security advisories addressing vulnerabilities in Connect versions prior to Update 25 (v5.26.191), Update 19 (v5.29.237), and Update 9 (v5.37.140), potentially leading to unauthorized access and data compromise.

Connect +2 vulnerability tanium security advisory
3r
high advisory

OpenBao Cross-Namespace Lease Revocation via Legacy sys/revoke Path

OpenBao versions up to 2.5.3 allow cross-namespace lease revocation by exploiting legacy sys/revoke endpoints, potentially leading to unauthorized credential access and denial of service.

openbao/openbao vulnerability acl-bypass secrets-management
2r 1t
medium advisory

phpMyFAQ Unauthenticated Password Reset Vulnerability (CVE-2026-35676)

phpMyFAQ before 4.1.3 is vulnerable to an unauthenticated password reset, allowing attackers to change account passwords without token validation by sending crafted PUT requests to the /api/index.php/user/password/update endpoint.

phpMyFAQ cve vulnerability password reset unauthenticated
2r 1t 1c
medium advisory

Zimbra Security Advisory Addresses Vulnerabilities in Zimbra Daffodil

Zimbra released a security advisory on May 28, 2026, addressing unspecified vulnerabilities in Zimbra Daffodil versions prior to v10.1.17, urging users to apply necessary updates.

Zimbra Daffodil < v10.1.17 zimbra vulnerability patch
2r
critical advisory

Multiple Vulnerabilities in Veeam Products Allow Remote Code Execution

Multiple vulnerabilities in Veeam ONE and Service Provider Console allow remote code execution (CVE-2026-32998) and an unspecified security issue, potentially leading to complete system compromise.

ONE +1 veeam rce vulnerability
2r 1t 1c
medium advisory

Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass

Multiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.

GitLab Community Edition +1 gitlab vulnerability denial-of-service security-bypass CVE-2026-1402 CVE-2026-2601 CVE-2026-2710 CVE-2026-4868 +3
2r 2t 5c
high advisory

Langflow Multiple Vulnerabilities Allow Remote Code Execution and Denial of Service

Multiple vulnerabilities in Langflow allow a remote, anonymous attacker to execute arbitrary code or cause a denial of service.

Langflow vulnerability rce dos
2r 2t
medium advisory

Gitea Unauthenticated Container Registry Access (CVE-2026-27771)

A vulnerability in Gitea's built-in container registry (CVE-2026-27771) allows unauthenticated attackers to pull private container images, potentially exposing source code, secrets, and production infrastructure details, affecting over 30,000 deployments.

Gitea +2 vulnerability container registry access control cloud git
2r 1t 1c 2i updated
critical threat

Multiple Vulnerabilities in Jenkins Plugins

Multiple vulnerabilities exist in Jenkins Plugins that could allow an attacker to disclose information, manipulate files, conduct cross-site scripting attacks, execute arbitrary code, and bypass security measures.

Jenkins Plugins jenkins vulnerability xss code-execution
3r 4t
high advisory

KubeVirt virt-exportserver Path Traversal Vulnerability (CVE-2026-9804)

A path traversal vulnerability exists in KubeVirt's virt-exportserver component, where an attacker with namespace-level access can exploit this flaw by creating a symbolic link within an exported filesystem PVC to read arbitrary files from the exporter pod, leading to information disclosure.

virt-exportserver kube-virt path-traversal vulnerability cloud
2r 1t 1c
medium threat

Apache Tika Vulnerability Allows Information Disclosure or Manipulation

A remote, anonymous attacker can exploit a vulnerability in Apache Tika to read sensitive data or trigger malicious requests to internal resources or third-party servers.

Tika apache-tika vulnerability infoleak
2r 1t
medium advisory

VMware Tanzu Spring Security Vulnerability Allows File Manipulation

A local attacker can exploit a vulnerability in VMware Tanzu Spring Security to manipulate files, potentially leading to privilege escalation.

Tanzu Spring Security vulnerability file-manipulation privilege-escalation
2r 1t
medium advisory

Multiple Vulnerabilities in Vim Could Lead to Arbitrary Code Execution or Denial of Service

Multiple vulnerabilities in Vim could allow an attacker to execute arbitrary code or cause a denial of service condition.

vim vulnerability code-execution denial-of-service
2r 3t
medium advisory

CVE-2026-46072 ntfs3 Buffer Boundary Check Vulnerability

CVE-2026-46072 is a buffer boundary check vulnerability in ntfs3 affecting an unspecified Microsoft product, requiring further investigation upon patch application to understand exploitation vectors and develop detections.

vulnerability ntfs3 buffer-overflow
2r 1c
medium threat

CVE-2026-45842: Unspecified Vulnerability in Microsoft Products

CVE-2026-45842 is an unspecified vulnerability affecting Microsoft products, requiring further investigation to determine the specific attack vector, impact, and affected systems.

Unspecified Microsoft Product vulnerability microsoft
2r 1t 1c
medium threat

CVE-2026-44899 Mistune Image Directive CSS Injection Vulnerability

CVE-2026-44899 is a CSS Injection vulnerability in the Mistune Image Directive, potentially allowing for malicious CSS injection if user-supplied content is not properly sanitized.

Mistune Image Directive css-injection vulnerability mistune
2r 1c
medium threat

CVE-2025-71305 Published - Insufficient DP MST VCPI Protection

Microsoft published CVE-2025-71305, addressing a vulnerability related to insufficient protection against zero VCPI values in DisplayPort Multi-Stream Transport (MST), although specifics on exploitation and impact are not detailed in the provided source.

cve vulnerability displayport
2r 1c
medium threat

CVE-2026-45843 slip: bound decode() vulnerability

CVE-2026-45843 is a Microsoft vulnerability with unspecified details at the time of this brief.

cve vulnerability microsoft
1r 1c
medium advisory

CVE-2026-44844 eml_parser Recursion Denial-of-Service

CVE-2026-44844 is a denial-of-service vulnerability in Microsoft's eml_parser due to recursion in nested message/rfc822 attachments, potentially causing a service outage.

eml_parser dos vulnerability
2r 1t 1c
medium advisory

CVE-2026-45991 UDF Partition Descriptor Append Bookkeeping Vulnerability

CVE-2026-45991 is a security vulnerability affecting a Microsoft product, related to UDF partition descriptor append bookkeeping.

udf vulnerability msft
2r 1c
high advisory

Deno TLS Plaintext Injection Vulnerability

A vulnerability in Deno's Node.js tls compatibility layer (versions 2.0.0 to 2.7.7) allows a network attacker to intercept and tamper with plaintext application data transmitted over a supposedly TLS-protected connection when `autoSelectFamily` is enabled and the initial connection attempt fails, leading to potential information disclosure and data manipulation.

deno tls plaintext vulnerability
2r 1t
medium advisory

Google Chrome Security Update Released

Google released a security update on May 27, 2026, to address vulnerabilities in Chrome for Desktop versions prior to 0.7778.216/217 for Windows, 148.0.7778.215/216 for Mac, and 148.0.7778.215 for Linux, requiring users to apply the necessary updates to mitigate potential exploitation.

Chrome for Desktop browser vulnerability chrome patch
2r
critical advisory

Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Tools Lite contains an unspecified vulnerability (CVE-2026-8398) that has a high impact on confidentiality, integrity, and availability, requiring immediate mitigation or discontinuation of use.

Daemon Tools Lite cve-2026-8398 vulnerability
2r 1c
high advisory

Multiple Vulnerabilities in Veeam Backup & Replication

Multiple vulnerabilities in Veeam Backup & Replication prior to version 13.0.2.29 allow an attacker to cause privilege escalation and compromise data integrity.

PoC Veeam Backup & Replication +1 vulnerability privilege-escalation data-integrity
2r 1t 2c updated
high advisory

Multiple Vulnerabilities in Symfony Framework

Multiple vulnerabilities in Symfony, including SSRF, XSS, and security policy bypass, can be exploited by an attacker to compromise the application.

Symfony < 5.4.53 +3 symfony vulnerability ssrf xss security-policy-bypass
2r 1t
high advisory

Multiple Vulnerabilities in Check Point Products

Multiple vulnerabilities in Check Point Security Gateways and Spark Firewalls allow for remote denial of service, data confidentiality breaches, and data integrity compromise.

Security Gateways R81.20 +4 vulnerability denial-of-service data-breach sql-injection
2r 3t 4c
high advisory

Multiple Vulnerabilities in Joomla! Allow Privilege Escalation and Data Breaches

Multiple vulnerabilities in Joomla! versions before 5.4.6 and 6.x before 6.1.1 can allow attackers to perform privilege escalation, compromise data confidentiality, perform cross-site scripting (XSS), and conduct cross-site request forgery (CSRF) attacks.

Joomla! < 5.4.6 +1 joomla vulnerability privilege-escalation xss csrf data-breach
2r 2t 5c
medium advisory

Kaspersky Anti Targeted Attack Platform Multiple XSS Vulnerabilities

Multiple vulnerabilities have been discovered in Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7, allowing an attacker to cause a remote cross-site scripting (XSS) vulnerability, tracked as CVE-2026-28348 and CVE-2026-28350.

Anti Targeted Attack Platform xss vulnerability web-application
2r 2t 2c
critical advisory

Multiple Vulnerabilities in Apple macOS Sequoia, Sonoma, and Tahoe

A remote, anonymous attacker can exploit multiple vulnerabilities in Apple macOS to gain root privileges, execute arbitrary code, cause a denial-of-service condition, disclose confidential information, modify data, or bypass security measures.

macOS Sequoia +2 vulnerability macos privilege-escalation execution impact discovery defense-evasion
2r 5t
critical advisory

Multiple Vulnerabilities in Oracle MySQL

A remote, anonymous, or authenticated attacker can exploit multiple vulnerabilities in Oracle MySQL to compromise confidentiality, integrity, and availability.

MySQL vulnerability database exploitation
2r
medium advisory

Multiple Vulnerabilities in IBM DB2

Multiple vulnerabilities in IBM DB2 allow a remote, authenticated, or local attacker to disclose information, bypass security measures, or cause a denial of service.

DB2 vulnerability denial-of-service information-disclosure
2r 3t
high advisory

Multiple Vulnerabilities in CODESYS

Multiple vulnerabilities in CODESYS could allow an attacker to escalate privileges, manipulate data, or cause a denial of service.

CODESYS vulnerability privilege-escalation denial-of-service
3r 2t
high advisory

CVE-2026-39832: Agent Constraints Dropped When Forwarding Keys in golang.org/x/crypto/ssh/agent

CVE-2026-39832 describes a vulnerability where agent constraints are dropped when forwarding keys in golang.org/x/crypto/ssh/agent, potentially leading to unauthorized access.

cve-2026-39832 ssh key forwarding vulnerability
2r 1c
medium threat

GnuTLS Certificate Spoofing Vulnerability (CVE-2026-42012)

CVE-2026-42012 describes a vulnerability in GnuTLS where a remote attacker can spoof legitimate services or intercept sensitive information by presenting a specially crafted certificate with URI or SRV SANs, causing the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN).

GnuTLS vulnerability certificate spoofing tls
2r 1t 1c
critical advisory

Multiple Critical Vulnerabilities in Ubiquiti UniFi OS

Ubiquiti has addressed multiple critical vulnerabilities including CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, and CVE-2026-33000 in UniFi OS, which could allow remote attackers to make unauthorized system changes, access sensitive files, disclose information, or execute arbitrary commands on vulnerable systems.

PoC UniFi OS +6 vulnerability unifi command_injection path_traversal improper_access_control
2r 1t 5c 1i updated
high advisory

CVE-2026-9170: IBM WebSphere Application Server and Liberty Improper Input Validation Vulnerability

IBM WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 are vulnerable to denial of service and potential remote code execution due to improper input validation as described in CVE-2026-9170.

WebSphere Application Server +2 vulnerability websphere rce dos
2r 2t 1c
medium advisory

ABB PPT30 Operating System Vulnerability (CVE-2025-11482)

A vulnerability, CVE-2025-11482, exists in ABB's PPT30 Operating System related to handling concurrent connections in the PPT30 OPC-UA Server, affecting versions prior to 1.8.0.

PPT30 Operating System industrial control system denial of service vulnerability
1r 1t 1c
high threat

SQL Injection Vulnerability in StudentManagementSystem

A SQL injection vulnerability exists in the /success.php file of yashpokharna2555 StudentManagementSystem, allowing remote attackers to execute arbitrary SQL commands by manipulating the User argument.

StudentManagementSystem sql-injection web-application vulnerability
2r 1t 1c
high advisory

Splinterware System Scheduler Pro 5.12 Privilege Escalation via Insecure Permissions (CVE-2018-25359)

Splinterware System Scheduler Pro 5.12 is vulnerable to privilege escalation (CVE-2018-25359) due to insecure file permissions, allowing low-privilege users to replace the service executable with a malicious one, leading to arbitrary code execution as LocalSystem.

System Scheduler Pro privilege-escalation vulnerability cve
2r 1t 1c
high advisory

CVE-2026-9452 FoundDream miniclawd Remote Command Injection

A command injection vulnerability exists in FoundDream miniclawd within the ExecTool.execute function in /src/tools/exec.ts, which can be triggered remotely, allowing attackers to execute arbitrary OS commands.

miniclawd command-injection vulnerability
2r 1t 1c
critical advisory

CVE-2026-40411: Azure Virtual Network Gateway Improper Input Validation RCE

CVE-2026-40411 describes an improper input validation vulnerability in Azure Virtual Network Gateway that allows an authorized attacker to execute code over a network.

Azure Virtual Network Gateway azure rce vulnerability
2r 1t 1c
high advisory

itsourcecode Electronic Judging System SQL Injection Vulnerability (CVE-2026-9383)

CVE-2026-9383 is a SQL injection vulnerability in itsourcecode Electronic Judging System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username parameter in the /intrams/admin/login.php file.

Electronic Judging System 1.0 sql-injection vulnerability web-application
2r 1t 1c
high advisory

NousResearch hermes-agent OS Command Injection Vulnerability (CVE-2026-9367)

NousResearch hermes-agent up to version 5157f5427f19488b31c6fdebbacd15d798ce7f63 is vulnerable to OS command injection (CVE-2026-9367) in the `detect_dangerous_command` function allowing a remote attacker to execute arbitrary commands.

hermes-agent command-injection vulnerability cve
2r 1t 1c
high advisory

Online Art Gallery Shop 1.0 SQL Injection Vulnerability (CVE-2026-9364)

A SQL injection vulnerability (CVE-2026-9364) exists in projectworlds Online Art Gallery Shop version 1.0, specifically in the /admin/adminHome.php file, which can be exploited remotely by manipulating the social_linked argument, potentially leading to unauthorized data access or modification.

Online Art Gallery Shop 1.0 sql-injection vulnerability web-application
2r 2t 1c
high advisory

Joomla! Ek Rishta Component 2.10 SQL Injection Vulnerability

Joomla! Component Ek Rishta version 2.10 is vulnerable to SQL injection allowing unauthenticated attackers to manipulate database queries by injecting SQL code via the cid parameter through GET requests to the user_detail view, potentially extracting sensitive database information.

Ek Rishta 2.10 sql-injection joomla vulnerability
2r 1t 1c
medium threat

Mattermost File Access Vulnerability (CVE-2026-3473)

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, allowing an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.

Mattermost Server cve vulnerability mattermost authorization bypass
1r 1t 1c
medium advisory

Spring AI Data Integrity Vulnerability (CVE-2026-41863)

A data integrity vulnerability exists in Spring AI versions 1.1.x before 1.1.7, potentially allowing an attacker to compromise data integrity, as identified by CVE-2026-41863.

Spring AI vulnerability data-integrity spring-ai
2r
high advisory

Multiple Vulnerabilities in Roundcube Webmail

Multiple vulnerabilities in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1 could lead to remote code execution, data confidentiality breaches, data integrity breaches, SSRF, and SQL Injection.

Roundcube Webmail < 1.6.16 +1 roundcube webmail vulnerability rce ssrf sqli
2r 3t
medium advisory

CPython Unspecified Vulnerability (CVE-2026-8328)

An unspecified vulnerability in CPython, tracked as CVE-2026-8328, allows an attacker to cause an unspecified security issue.

CPython vulnerability CVE-2026-8328
2r 1c
medium advisory

Multiple Vulnerabilities in Devolutions Server

Multiple vulnerabilities in Devolutions Server could allow an attacker to bypass security measures, disclose information, and manipulate files.

Devolutions Server vulnerability data-breach file-manipulation
2r
medium advisory

Multiple Vulnerabilities in PuTTY Allow for DoS, Data Manipulation, and Spoofing

A remote, anonymous attacker can exploit multiple vulnerabilities in PuTTY to perform a denial of service attack, manipulate data, and possibly carry out spoofing attacks.

PuTTY vulnerability denial-of-service spoofing
2r 2t
critical advisory

Multiple Vulnerabilities in Roundcube Webmail

Multiple vulnerabilities in Roundcube Webmail allow an attacker to perform SQL injection attacks, bypass security measures, manipulate data, disclose confidential information, obtain extended privileges, execute arbitrary code, or perform cross-site scripting attacks.

Roundcube Webmail roundcube webmail vulnerability sqli xss code execution
2r 3t
high threat

Microsoft 365 Copilot Multiple Vulnerabilities

A remote, anonymous attacker can exploit multiple vulnerabilities in Microsoft 365 Copilot to execute arbitrary program code and disclose confidential information.

Microsoft 365 Copilot microsoft365 copilot vulnerability code_execution information_disclosure
2r 2t
high advisory

LiteLLM Multiple Vulnerabilities Allow Privilege Escalation

A remote, authenticated attacker can exploit multiple vulnerabilities in LiteLLM to escalate their privileges.

LiteLLM privilege-escalation vulnerability
2r 1t
medium advisory

CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products

CISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.

B&R Automation Runtime +10 ics scada vulnerability
2r
medium advisory

Nezha Monitoring RoleMember SSRF with Full Response Body Reflection

Nezha Monitoring is vulnerable to a server-side request forgery (SSRF) vulnerability, where a low-privilege RoleMember user can call notification routes and send HTTP requests to a user-controlled URL, with the entire response body reflected back to the caller, potentially exposing intranet resources and causing denial of service.

Nezha Monitoring ssrf nezha vulnerability
2r 3t
medium advisory

HPE Telco Universal SLA Management Multiple Vulnerabilities

HPE published a security advisory addressing multiple unspecified vulnerabilities in HPE Telco Universal SLA Management version 4.6 and prior, prompting users to apply necessary updates.

HPE Telco Universal SLA Management vulnerability hpe sla management
2r
high advisory

Debian LTS Linux Kernel Vulnerability Allows Privilege Escalation and Data Breach

A vulnerability in the Debian LTS Linux kernel allows attackers to perform privilege escalation and breach data confidentiality, specifically affecting Debian 11 bullseye versions prior to 5.10.251-5 and 6.1.172-1~deb11u1; tracked as CVE-2026-46333.

Debian 11 bullseye kernel vulnerability privilege-escalation linux debian
3r 1t
medium advisory

Multiple Vulnerabilities in Tenable Sensor Proxy

Multiple vulnerabilities in Tenable Sensor Proxy versions prior to 1.4.0 could allow a remote attacker to cause a denial of service, data confidentiality breaches, and other unspecified security impacts.

Sensor Proxy vulnerability dos dataleak
1r 1t 5c
medium advisory

SPIP Security Policy Bypass Vulnerability

A vulnerability in SPIP versions prior to 4.4.15 allows an attacker to bypass the security policy, potentially leading to unauthorized actions.

SPIP vulnerability security-bypass web-application
2r 1t
critical advisory

IBM App Connect Enterprise Multiple Vulnerabilities

A remote, anonymous attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to execute arbitrary program code, manipulate data, conduct cross-site scripting attacks, disclose confidential information, or cause a denial-of-service condition.

App Connect Enterprise vulnerability code-execution xss dos
2r 3t
medium advisory

XWiki Multiple Vulnerabilities Allow File Manipulation and Information Disclosure

An authenticated remote attacker can exploit multiple vulnerabilities in XWiki to manipulate files and disclose information.

XWiki vulnerability file-manipulation information-disclosure
2r 2t
medium advisory

AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.

AudioIgniter plugin for WordPress <= 2.0.2 idor wordpress plugin cve-2026-8679 vulnerability
2r 1t
critical advisory

Roundcube Vulnerability Allows Remote Code Execution

A remote, authenticated attacker can exploit a vulnerability in Roundcube to execute arbitrary program code, potentially leading to complete system compromise.

Roundcube code-execution vulnerability webmail
2r 1t
high advisory

Exim Vulnerability Allows SQL Injection

A vulnerability in Exim allows an attacker to perform a SQL injection attack, potentially leading to unauthorized data access or modification.

Exim sql-injection vulnerability
2r 1t
medium threat

Multiple Vulnerabilities in PHP Allow for Information Disclosure, DoS, SSRF, and Unknown Impacts

A remote attacker can exploit multiple vulnerabilities in PHP to disclose information, cause a denial-of-service condition, perform a Server-Side Request Forgery (SSRF) attack, or achieve unknown impacts.

PHP vulnerability ssrf dos information-disclosure
2r 3t
high advisory

Kemp LoadMaster and Progress Software MOVEit WAF: Multiple Vulnerabilities

Multiple vulnerabilities in Kemp LoadMaster and Progress Software MOVEit WAF could allow an attacker to execute arbitrary code or circumvent security measures.

LoadMaster +1 vulnerability code-execution security-bypass
2r 2t
medium advisory

PowerDNS Authoritative Server Multiple Vulnerabilities

Multiple vulnerabilities in PowerDNS Authoritative Server allow an attacker to disclose information, manipulate data, and cause a denial-of-service condition.

Authoritative Server vulnerability denial-of-service information-disclosure
2r 2t
high advisory

Prototype Pollution Vulnerability in @nevware21/ts-utils Library (CVE-2026-46681)

The `_copyProps` function in the `@nevware21/ts-utils` library is vulnerable to prototype pollution due to the use of `for...in` without proper `hasOwnProperty` checks, allowing attackers to modify object prototypes by injecting properties like `__proto__`.

@nevware21/ts-utils prototype-pollution javascript vulnerability cve-2026-46681
2r 2t
high advisory

@hulumi/drift Orphan Reconciler Accepts Externally Supplied Execute Plans

@hulumi/drift versions before 1.3.2 could accept externally supplied execute plans without sufficient provenance checks, allowing unsafe reconciliation input to be treated as trusted; upgrade to version 1.3.2 or later to resolve this vulnerability.

@hulumi/drift +1 supply-chain vulnerability npm
2r
high advisory

@hulumi/policies: CIS 1.16 Admin Policy Bypass Vulnerability

@hulumi/policies versions before 1.3.2 improperly inspect inline and attached IAM policies, potentially allowing admin-equivalent policy paths to bypass the administrator-policy guardrail, resulting in a CIS 1.16 admin policy bypass.

@hulumi/policies +1 vulnerability iam policy bypass privilege escalation
2r 1t
high advisory

Open ISES Tickets Hardcoded MySQL Credentials Vulnerability (CVE-2026-48241)

Open ISES Tickets before version 3.44.2 contains hardcoded MySQL database credentials in loader.php, allowing an attacker with access to the source code or the file on a deployed installation to read the username, password, and database name and use them to connect to the database (CVE-2026-48241).

Tickets < 3.44.2 cve hardcoded credentials vulnerability database
2r 1t 1c
medium advisory

ConnectWise Automate Vulnerability Addressed in Security Update

ConnectWise released a security advisory addressing a vulnerability in ConnectWise Automate versions prior to 2026.5, prompting users to apply the necessary updates.

Automate vulnerability security-update connectwise
2r
high advisory

ABB B&R PCs Vulnerable to Multiple Attacks via EDK2 Network Package

Multiple vulnerabilities in ABB B&R PCs, specifically within the EDK2 Network Package, can be exploited by a network attacker to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information (CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237).

APC4100 +9 ics vulnerability network
2r 1t 2c
medium threat

Trend Micro Security Advisory Addressing Apex One and Vision One Vulnerabilities

Trend Micro released a security advisory addressing vulnerabilities in Apex One (on-premise), Apex One as a service, and Trend Vision One Endpoint, prompting users to apply necessary updates to mitigate potential risks.

exploited Apex One +2 vulnerability patch endpoint_security
2r
high advisory

Multiple Vulnerabilities in Progress MOVEit Automation

Multiple vulnerabilities in Progress MOVEit Automation allow for remote denial of service, security policy bypass, and unspecified security issues.

MOVEit Automation +1 vulnerability dos security-bypass
2r 2t 4c
high advisory

Budibase Multiple Vulnerabilities

Multiple vulnerabilities in Budibase could be exploited by an attacker to gain administrative privileges, bypass security measures, perform cross-site scripting attacks, manipulate data, or disclose confidential information.

Budibase vulnerability privilege-escalation defense-evasion execution impact discovery cloud
2r 5t
critical threat

Actively Exploited Vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect

Multiple vulnerabilities, including a critical authentication bypass (CVE-2026-42097), affect Sparx Systems Pro Cloud Server and Enterprise Architect, potentially leading to remote code execution and data compromise; active exploitation is likely given available PoCs.

exploited Pro Cloud Server +1 vulnerability rce authentication-bypass sqli
2r 3t 5c
medium advisory

MongoDB Compass Vulnerability Allows File Manipulation and Potential Code Execution

An anonymous remote attacker can exploit a vulnerability in MongoDB Compass to manipulate files and potentially execute arbitrary code.

Compass vulnerability file-manipulation code-execution
2r 1t
critical advisory

vllm Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in vllm to achieve arbitrary code execution.

vllm remote-code-execution vulnerability
2r 1t
medium advisory

vllm Vulnerability Allows Information Disclosure and DoS

A remote, authenticated attacker can exploit a vulnerability in vllm to disclose information or cause a denial-of-service condition.

vllm vulnerability denial-of-service information-disclosure
2r 2t
critical threat

Multiple Vulnerabilities in Trend Micro Products Including TrendAI Apex One

Multiple vulnerabilities exist in Trend Micro products, including TrendAI Apex One, potentially allowing authenticated attackers to tamper with files, distribute malicious code, or escalate privileges; CVE-2026-34926 is being actively exploited.

exploited TrendAI Apex One +2 vulnerability apex-one trend-micro path-traversal
2r 1t 1i
medium advisory

Splunk Releases Security Advisory Addressing Multiple Products

Splunk released security advisories on May 20, 2026, addressing vulnerabilities in Splunk User Behavior Analytics, AppDynamics Agents, Universal Forwarder, Enterprise, Cloud Platform, and AI Toolkit, prompting users to apply necessary updates.

Splunk User Behavior Analytics +12 vulnerability splunk
2r
critical advisory

Cisco Secure Workload Unauthorized API Access Vulnerability

Cisco Secure Workload versions 3.9 and prior, versions prior to 3.10.8.3, and versions prior to 4.0.3.17 are vulnerable to unauthorized API access, requiring an urgent update.

Secure Workload cisco vulnerability api
1r
medium advisory

Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)

CVE-2026-45498 is a denial-of-service vulnerability in Microsoft Defender that could disrupt endpoint protection capabilities, requiring timely mitigation per vendor instructions.

Defender denial-of-service vulnerability microsoft-defender
2r 1t 1c
medium threat

FreePBX Security Advisories for Security-Reporting Module Vulnerabilities

FreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.

Security-Reporting cdr +3 freepbx sql_injection lfi vulnerability
2r 1t
high threat

Multiple Vulnerabilities in Mozilla Products Lead to Potential RCE and Privilege Escalation

Multiple vulnerabilities in Mozilla Firefox ESR, Firefox, Firefox for iOS, and Thunderbird products can lead to arbitrary code execution, privilege escalation, and remote denial of service.

Firefox ESR +5 vulnerability rce privilege-escalation dos
2r 3t 4c
high advisory

Multiple Vulnerabilities in Suricata Network Threat Detection Engine

Multiple vulnerabilities in Suricata versions before 8.0.5 and 7.0.16 could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

Suricata vulnerability rce dos
2r 2t
medium advisory

Multiple Vulnerabilities in Symfony Framework

Multiple vulnerabilities in Symfony, including CVE-2026-45070, CVE-2026-45077, CVE-2026-45304, CVE-2026-45305, CVE-2026-45753, CVE-2026-45754, CVE-2026-45755, CVE-2026-45756, CVE-2026-46626, and CVE-2026-47212, can lead to remote denial of service, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks.

symfony/html-sanitizer +10 symfony vulnerability dos xss csrf
3r 1t
critical advisory

Multiple Vulnerabilities in Docker Desktop Allow Remote Code Execution

Multiple vulnerabilities in Docker Desktop versions prior to 4.71.0 allow a remote attacker to execute arbitrary code.

Docker Desktop vulnerability rce docker
2r 1t
critical advisory

Squid Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in Squid to execute arbitrary program code, leading to potential system compromise.

Squid rce vulnerability
2r 1t
high advisory

Multiple Vulnerabilities in Rsync

Multiple vulnerabilities in Rsync could be exploited by an attacker to elevate privileges, disclose information, bypass security precautions, and perform a denial of service attack.

rsync vulnerability privilege-escalation information-gathering defense-evasion impact
2r 4t
high advisory

Multiple Vulnerabilities in Atlassian Products

Multiple vulnerabilities exist in Atlassian products including Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira which could lead to arbitrary code execution, denial of service, information disclosure, cross-site scripting, and security bypass.

Bamboo +5 atlassian vulnerability code-execution dos xss security-bypass
2r 4t
high threat

Multiple Vulnerabilities in Mozilla Firefox and Thunderbird

Multiple vulnerabilities in Mozilla Firefox, Firefox ESR, and Thunderbird could allow a remote attacker to execute arbitrary code, disclose information, bypass security restrictions, deceive the user, escalate privileges, or cause a denial-of-service condition.

Firefox +2 vulnerability thunderbird code-execution information-disclosure privilege-escalation denial-of-service
2r 5t
high advisory

Vaultwarden Vulnerabilities Allow Privilege Escalation and Information Disclosure

Multiple vulnerabilities in Vaultwarden allow a remote, anonymous attacker to gain user privileges and disclose sensitive information.

Vaultwarden vulnerability privilege-escalation information-disclosure
2r 3t
high advisory

Multiple Vulnerabilities in Nvidia GPU Display Drivers

Multiple vulnerabilities in Nvidia GPU Display Drivers allow a local attacker to escalate privileges, manipulate data, disclose information, cause a denial of service, or execute code.

GPU Display Treiber nvidia gpu vulnerability privilege-escalation denial-of-service
2r 3t
high advisory

Multiple Vulnerabilities in Mozilla Firefox and Thunderbird

Multiple vulnerabilities exist in Mozilla Firefox, Firefox ESR, and Thunderbird that could allow a remote attacker to execute arbitrary code, disclose sensitive information, bypass security measures, or conduct cross-site scripting or spoofing attacks.

Firefox +2 vulnerability thunderbird xss spoofing
2r 2t
critical advisory

CVE-2026-7637 - Boost Plugin for WordPress PHP Object Injection

The Boost plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7637) due to deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie, potentially leading to arbitrary code execution if a suitable property-oriented programming (POP) chain is present.

Boost plugin for WordPress php-object-injection wordpress vulnerability
2r 1t 1c
medium advisory

CVE-2026-45585: Windows BitLocker Security Feature Bypass Vulnerability ('YellowKey')

CVE-2026-45585 is a security feature bypass vulnerability in Windows BitLocker, known as 'YellowKey', for which a public proof of concept exists, prompting Microsoft to release mitigation guidance prior to a security update.

BitLocker vulnerability security feature bypass
2r
high advisory

Atlassian Security Advisory Addressing Multiple Vulnerabilities

Atlassian released a security advisory on May 19, 2026, addressing vulnerabilities in multiple products including Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira, and Jira Service Management Data Center and Server.

Bamboo Data Center and Server +5 atlassian vulnerability security-advisory
2r
high advisory

Angular platform-server SSRF via Hostname Hijacking (CVE-2026-46417)

A server-side request forgery (SSRF) vulnerability exists in `@angular/platform-server` due to improper processing of the request URL by the server-side rendering engine, allowing attackers to redirect relative HTTP requests to attacker-controlled servers, potentially exposing internal APIs or metadata services; patch CVE-2026-46417 immediately.

@angular/platform-server +4 ssrf angular vulnerability
2r 1t
medium advisory

Dell Security Advisory Addresses Vulnerabilities in Multiple Products

Dell published security advisories between May 11 and 17, 2026, addressing vulnerabilities in Dell Enterprise Sonic Distribution, Dell Live Optics Collector, Intel 800 Series Ethernet Adapters, Dell PowerEdge with AMD Graphics, and PowerScale InsightIQ, prompting users to apply necessary updates.

Dell Enterprise Sonic Distribution +4 vulnerability dell intel
2r
medium advisory

Bandit HTTP/1 Chunked Request DoS Vulnerability

Bandit's HTTP/1 chunked-body reader silently drops the request size cap, leading to excessive memory buffering. An unauthenticated attacker can crash Bandit-fronted Phoenix/Plug applications by sending a single 'Transfer-Encoding: chunked' request to any URL, causing BEAM memory exhaustion and a denial-of-service.

bandit dos vulnerability
1r 1t 1c
medium advisory

Mozilla Firefox Security Updates Released

Mozilla released security updates on May 19, 2026, addressing vulnerabilities in Firefox versions prior to 151, Firefox ESR versions prior to 115.36, and Firefox ESR versions prior to 140.11.

Firefox +2 vulnerability mozilla
1r
critical advisory

Kopia RCE via SSH ProxyCommand Injection (CVE-2026-45695)

Kopia's HTTP server, when started without `--without-password`, accepts unauthenticated requests which can lead to arbitrary command execution as the Kopia process user via `-oProxyCommand` in `sshArguments` for SFTP backends with `externalSSH: true`. An attacker-supplied storage configuration is forwarded to `blob.NewStorage`, and the `sshArguments` are split on spaces and passed directly to `exec.CommandContext("ssh")`, resulting in command injection.

kopia rce vulnerability command-injection CVE-2026-45695
2r 1t
critical advisory

Critical Vulnerability in HPE Unified OSS Console (UOC)

HPE published a security advisory (AV26-477) addressing a critical vulnerability in HPE Unified OSS Console (UOC) version 3.1.20 and prior, potentially leading to unauthorized access and control of network operations.

HPE Unified OSS Console vulnerability hpe oss network-management
1r 1t
high threat

libcrux-ml-dsa Signature Verification Bypass Vulnerability

The AVX2 implementation of ML-DSA verification in libcrux-ml-dsa mishandles an edge case in the `use_hint` function, potentially allowing an attacker to craft an invalid signature that is accepted by the verifier if the AVX2 implementation is used.

libcrux-ml-dsa signature-bypass vulnerability
2r
high advisory

ABB CoreSense HM and CoreSense M10 Path Traversal Vulnerability (CVE-2025-3465)

A path traversal vulnerability (CVE-2025-3465) in ABB CoreSense HM and CoreSense M10 allows unauthenticated local users to access restricted directories, potentially leading to system compromise and information exposure; patch to CoreSense™ HM v2.3.4 and CoreSense™ M10 v1.4.1.31.

CoreSense™ HM +1 path-traversal vulnerability abb
2r 1t 1c
medium advisory

Kieback & Peter DDC Building Controllers Cross-Site Scripting Vulnerability (CVE-2026-4293)

A cross-site scripting vulnerability, CVE-2026-4293, exists in multiple Kieback & Peter DDC Building Controllers that could allow an attacker to take control of the victim's browser.

DDC4002 +10 xss vulnerability building-automation
2r 1t
high advisory

HAXcms createSite SSRF Enables Arbitrary File Read

HAXcms is vulnerable to Server-Side Request Forgery (SSRF) via the createSite endpoint, allowing an authenticated user to supply arbitrary URLs or local file paths, which are fetched server-side without validation and written to a web-accessible directory, enabling arbitrary file read, internal network access, and cloud credential exposure; this vulnerability is tracked as CVE-2026-46393.

HAXcms ssrf cve-2026-46393 vulnerability
2r 1t 2i
high advisory

Multiple Vulnerabilities in Atlassian Jira

Multiple vulnerabilities in Atlassian Jira could allow an attacker to execute arbitrary code, manipulate and disclose data, conduct cross-site scripting attacks, or cause a denial-of-service condition.

Jira atlassian vulnerability xss dos
1r 1t
high advisory

Multiple Vulnerabilities in GLPI Allow Data Confidentiality Breach and Security Policy Bypass

Multiple vulnerabilities in GLPI versions prior to 11.0.7 and 10.0.25 allow an attacker to compromise data confidentiality and bypass security policies.

glpi vulnerability security-policy-bypass data-breach
2r 2t 1c
medium advisory

Multiple Vulnerabilities in Mattermost Products

Multiple unspecified vulnerabilities in Mattermost Desktop App and Mattermost Server allow an attacker to cause an unspecified security issue.

Mattermost Desktop App +4 mattermost vulnerability unspecified
2r
medium threat

Multiple Vulnerabilities in Docker Allow Privilege Escalation and DoS

Multiple vulnerabilities in Docker allow a local attacker to execute arbitrary code with administrator privileges, cause a denial-of-service condition, or manipulate data.

Docker vulnerability privilege-escalation denial-of-service
2r 3t
high advisory

Multiple Vulnerabilities in TYPO3 Extensions

Multiple vulnerabilities in TYPO3 extensions allow an attacker to execute arbitrary program code, conduct SQL injection attacks, disclose information, and circumvent security measures.

typo3 extensions typo3 vulnerability sqlinjection codeexecution
2r 1t
high advisory

Multiple Vulnerabilities in Apache OFBiz

Multiple vulnerabilities in Apache OFBiz could allow an attacker to execute arbitrary code, circumvent security measures, manipulate data, disclose confidential information, or conduct cross-site scripting attacks.

OFBiz vulnerability apache-ofbiz code-execution xss
2r 9t
medium advisory

Multiple Vulnerabilities in Red Hat Build of Quarkus

An authenticated or unauthenticated remote attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Quarkus to perform a denial of service attack, disclose sensitive information, or manipulate data.

Quarkus +1 vulnerability redhat denial of service information disclosure data manipulation
2r 2t
critical advisory

CUPS Multiple Vulnerabilities Allow Arbitrary Code Execution

A remote, anonymous attacker can exploit multiple vulnerabilities in CUPS to execute arbitrary program code with the privileges of the service and to disclose information.

CUPS rce vulnerability
2r 2t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux and OpenShift Grafana Component

A remote anonymous attacker can exploit multiple vulnerabilities in the Grafana component of Red Hat Enterprise Linux and OpenShift to execute arbitrary code, disclose confidential information, and cause a denial-of-service condition.

Red Hat Enterprise Linux +1 grafana rhel openshift vulnerability code execution information disclosure denial of service
2r 3t
medium advisory

Multiple Vulnerabilities in Ruby Allow for DoS and Information Disclosure

A remote, anonymous attacker can exploit multiple vulnerabilities in Ruby to cause a denial-of-service condition and disclose confidential information.

ruby vulnerability denial-of-service information-disclosure
2r 3t
critical threat

libsndfile Vulnerability Allows Remote Code Execution and Denial-of-Service

A remote attacker can exploit a vulnerability in libsndfile to execute arbitrary code or cause a denial of service, potentially leading to complete system compromise or service disruption.

libsndfile vulnerability rce dos
2r 2t
medium advisory

CVE-2026-5773: SMB Connection Reuse Vulnerability

Microsoft published information about CVE-2026-5773, a vulnerability related to the incorrect reuse of SMB connections.

smb vulnerability cve-2026-5773
2r 1c
high advisory

Claude HUD Command Injection Vulnerability via COMSPEC Manipulation (CVE-2026-47092)

Claude HUD through version 0.0.12 is vulnerable to command injection (CVE-2026-47092) allowing a local attacker to execute arbitrary commands on a Windows system by manipulating the COMSPEC environment variable; this vulnerability has been patched in commit 234d9aa.

Claude HUD command-injection vulnerability windows
2r 1t 1c
high advisory

Summarize Path Traversal Vulnerability (CVE-2026-45242)

Summarize versions prior to 0.15.1 are vulnerable to path traversal in the /v1/summarize daemon endpoint, allowing authenticated callers to write files to arbitrary directories via the slidesDir request parameter and subsequently delete files.

Summarize < 0.15.1 path-traversal vulnerability web-application
2r 1t 1c
high threat

Postgrex SQL Injection Vulnerability in Notifications.listen/3 (CVE-2026-32687)

A SQL injection vulnerability exists in Postgrex versions 0.16.0 to before 0.22.2 within the `Postgrex.Notifications.listen/3` function allowing attackers to execute arbitrary SQL commands on the notifications connection by manipulating the channel name.

postgrex sql-injection vulnerability
2r 1t 1c
high advisory

async-http-client Cookie Header Leak on Cross-Origin Redirect

The async-http-client library leaks `Cookie` headers to cross-origin redirect targets due to missing header stripping in `Redirect30xInterceptor.java`, potentially exposing sensitive information to malicious third parties.

async-http-client +1 cookie header redirect vulnerability ghsa CVE-2026-45300
2r 1t
high advisory

eduMFA Token Reusage Vulnerability due to Incorrect InnoDB Snapshot Isolation

eduMFA versions prior to 2.9.1 are vulnerable to token reusage due to incorrect InnoDB snapshot isolation in MySQL and MariaDB versions prior to 11.6.2 (or newer with innodb_snapshot_isolation=off), affecting token types such as TOTP, HOTP, and likely WebAuthN, where tokens are intended for single use, requiring racing the transaction for exploitation.

MariaDB +1 vulnerability mfa token reusage
2r
high threat

Q1 2026 Malware Trends: Ransomware and Miners

Kaspersky's Q1 2026 report highlights trends in malware targeting Windows, macOS, and IoT devices, including the exploitation of CVE-2026-20131 in Cisco Secure FMC firewalls and the rise of new ransomware variants and mining activities.

exploited Secure FMC ransomware miner vulnerability
2r 2t 1c
high advisory

Multiple Vulnerabilities in Joplin Allow for DoS, Information Disclosure, and Arbitrary File Overwrite

Multiple vulnerabilities in Joplin allow an attacker to perform a denial of service attack, disclose sensitive information, or overwrite arbitrary files, potentially leading to arbitrary code execution.

Joplin vulnerability dos information-disclosure file-overwrite
2r 1t
high advisory

GIMP Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary program code.

GIMP code-execution vulnerability
2r 1t
critical advisory

Multiple Vulnerabilities in NGINX Open Source and NGINX Plus

Multiple vulnerabilities in NGINX Open Source and NGINX Plus allow a remote, anonymous attacker to bypass security measures, execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.

nginx open source +1 nginx vulnerability webserver
2r 8t
high threat

CVE-2026-8757: adenhq hive Path Traversal Vulnerability

adenhq hive versions up to 0.11.0 are vulnerable to path traversal via manipulation of the _read_events_tail function in core/framework/server/routes_sessions.py, allowing a remote attacker to potentially access sensitive files.

hive <= 0.11.0 path traversal vulnerability web application
2r 1t 1c
high advisory

CVE-2018-25330: Joomla! EkRishta Extension Vulnerabilities

Joomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities, allowing attackers to inject malicious code through profile fields and POST parameters, potentially leading to information disclosure or arbitrary code execution.

EkRishta 2.10 cve joomla ekrishta xss sql injection web application vulnerability
2r 1t 1c
critical advisory

ACL Analytics Arbitrary Code Execution Vulnerability (CVE-2018-25320)

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability (CVE-2018-25320) that allows attackers to execute arbitrary commands by leveraging the EXECUTE function, potentially leading to remote code execution with system privileges.

ACL Analytics code execution vulnerability
2r 1t 1c
high advisory

CVE-2026-8725 - CoreWorxLab CAAL SSRF Vulnerability

A server-side request forgery (SSRF) vulnerability, identified as CVE-2026-8725, exists in CoreWorxLab CAAL up to version 1.6.0, allowing remote attackers to potentially trigger internal requests.

CAAL ssrf vulnerability
2r 1t 1c
medium advisory

CVE-2026-43490: ksmbd inherited ACE SID length validation vulnerability

Microsoft published information about CVE-2026-43490, a vulnerability in ksmbd related to the validation of inherited ACE SID length.

ksmbd ACE SID CVE-2026-43490 vulnerability
2r 1c
high advisory

phpMyFAQ SQL Injection Vulnerability in CurrentUser::setTokenData (CVE-2026-46359)

phpMyFAQ before version 4.1.2 contains a SQL injection vulnerability in CurrentUser::setTokenData, allowing authenticated attackers with crafted Azure AD accounts to execute arbitrary SQL queries by injecting malicious OAuth token claims.

phpMyFAQ sql-injection vulnerability
2r 1t 1c
critical threat

Multiple Vulnerabilities in PostgreSQL Allow for Remote Code Execution and Data Breach

Multiple vulnerabilities in PostgreSQL versions 14.x, 15.x, 16.x, 17.x and 18.x could allow for arbitrary code execution, remote denial of service, and data breach, potentially leading to complete system compromise.

PostgreSQL 14.x +4 postgresql vulnerability rce dos sqli
2r 6t 4c
critical advisory

Multiple Vulnerabilities in GitLab CE/EE Allow for Arbitrary Code Execution, Data Confidentiality Compromise, and SSRF

Multiple vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE) can allow an attacker to perform arbitrary code execution, compromise data confidentiality, perform server-side request forgery (SSRF), and other security breaches.

GitLab Community Edition +1 gitlab vulnerability rce ssrf xss csrf
2r 3c
high advisory

Multiple Vulnerabilities in Tenable Network Monitor

Multiple vulnerabilities in Tenable Network Monitor versions prior to 6.5.4 can lead to remote denial of service, security policy bypass, and unspecified security issues.

Network Monitor vulnerability dos security-bypass
2r 2t 5c
high advisory

Multiple Vulnerabilities in Strapi

Multiple vulnerabilities in Strapi could allow an attacker to cause a denial-of-service condition, gain administrator privileges, manipulate data, disclose confidential information, or bypass security measures.

Strapi vulnerability denial-of-service privilege-escalation data-manipulation information-disclosure
3r 4t
medium advisory

Shibboleth Identity Provider Vulnerabilities Leading to SMTP Injection and Denial of Service

Multiple vulnerabilities in Shibboleth Identity Provider allow an attacker to perform SMTP injection or cause a denial of service.

Identity Provider vulnerability denial-of-service smtp-injection
1r 1t
high threat

HCL BigFix Vulnerability Allows Data Manipulation and Cross-Site Scripting

A remote, anonymous attacker can exploit a vulnerability in HCL BigFix to manipulate data and conduct a cross-site scripting attack.

BigFix vulnerability xss data manipulation
2r 1t
high advisory

Multiple Vulnerabilities in MISP and MISP Modules

Multiple vulnerabilities in MISP and MISP Modules could allow an attacker to disclose information, gain admin rights, bypass security measures, manipulate data, or disclose sensitive information.

misp +1 vulnerability misp modules
2r 4t
high threat

Multiple Vulnerabilities in PostgreSQL Allow for Remote Code Execution, Denial of Service, and Information Disclosure

Multiple vulnerabilities in PostgreSQL could be exploited by an attacker to execute arbitrary code, conduct a denial of service attack, disclose information, manipulate files, conduct a SQL injection attack, and bypass security measures.

PostgreSQL vulnerability sqlinjection rce dos
2r 3t
critical threat

Multiple Vulnerabilities in Palo Alto Networks GlobalProtect App

Multiple vulnerabilities in the Palo Alto Networks GlobalProtect App could allow an attacker to gain administrator privileges, execute arbitrary code with administrator privileges, disclose sensitive information, manipulate data, and cause a denial-of-service condition.

GlobalProtect App vulnerability privilege-escalation execution credential-access impact
2r 4t
high threat

Multiple Vulnerabilities in F5 BIG-IP Products

Multiple vulnerabilities in F5 BIG-IP products could allow an attacker to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.

BIG-IP f5 vulnerability privilege-escalation execution defense-evasion impact discovery credential-access
3r 5t
medium advisory

Multiple Vulnerabilities in GStreamer

Multiple vulnerabilities in GStreamer can be exploited by a remote, anonymous attacker to disclose information, conduct a denial-of-service attack, corrupt data, or execute arbitrary code.

GStreamer vulnerability denial-of-service code-execution
2r 3t
high advisory

TeamViewer DEX Vulnerability Allows Remote Code Execution

An authenticated, remote attacker can exploit a vulnerability in TeamViewer DEX to execute arbitrary program code.

TeamViewer DEX vulnerability rce teamviewer
2r 1t
high advisory

SAP Patchday April 2026: Multiple Vulnerabilities

Multiple vulnerabilities in SAP software could allow an attacker to perform SQL injection, gain elevated privileges, execute arbitrary code, bypass security measures, perform cross-site scripting attacks, manipulate data, disclose sensitive information, or cause other unspecified impacts.

sap vulnerability sql-injection privilege-escalation xss
2r 4t
medium advisory

Multiple Vulnerabilities in GIMP

Multiple vulnerabilities in GIMP could allow an attacker to execute arbitrary code, disclose sensitive information, manipulate data, or cause a denial-of-service condition.

GIMP vulnerability code-execution information-disclosure dos
2r 3t
high advisory

Multiple Vulnerabilities in Apache Camel

Multiple vulnerabilities in Apache Camel could allow an attacker to execute arbitrary code, manipulate data, or disclose sensitive information.

Camel apache-camel vulnerability code-execution data-manipulation information-disclosure
3r 2t
medium advisory

Multiple Vulnerabilities in AMD EPYC, Athlon, and Ryzen Processors

Multiple vulnerabilities in AMD EPYC, Athlon, and Ryzen processors can be exploited by an attacker to execute arbitrary code, escalate privileges, bypass security measures, cause a denial-of-service condition, disclose sensitive information, or manipulate data.

EPYC processors +2 amd processor vulnerability privilege-escalation defense-evasion execution denial-of-service information-disclosure +1
2r 7t
critical advisory

Multiple Vulnerabilities in rclone Allow Arbitrary Code Execution

Multiple vulnerabilities in rclone could be exploited by an attacker to bypass security measures and execute arbitrary program code, potentially leading to complete system compromise.

rclone vulnerability code execution
2r 1t
high advisory

Multiple Vulnerabilities in Apache Solr

Multiple vulnerabilities in Apache Solr could be exploited by an attacker to bypass security measures, manipulate data, and disclose sensitive information.

Solr apache-solr vulnerability data-breach defense-evasion
2r 3t
high advisory

Multiple Vulnerabilities in Microsoft Windows Products

Multiple vulnerabilities exist in Microsoft Windows products, enabling attackers to execute arbitrary code, escalate privileges, perform denial-of-service attacks, disclose information, or bypass security measures.

Windows vulnerability privilege-escalation execution denial-of-service defense-evasion discovery
2r 5t
critical advisory

Electerm Local Code Execution via Single-Instance Socket (CVE-2026-45353)

Electerm versions 3.0.6 through 3.8.8 are vulnerable to local code execution (CVE-2026-45353) where a same-user process can send a JSON payload to the application's single-instance socket/pipe, leading to arbitrary tab creation and local process spawning.

electerm local code execution vulnerability
2r 1t
high advisory

Crabbox Privilege Escalation Vulnerability (CVE-2026-8629)

Crabbox versions prior to v0.12.0 contain a privilege escalation vulnerability (CVE-2026-8629) that allows users with visibility-only access to obtain elevated agent tickets and impersonate trusted lease-side bridges via unauthorized POST requests to specific ticket endpoints.

Crabbox privilege-escalation vulnerability web-application
1r 1t 1c
critical advisory

Portainer Endpoint Security Bypass via Docker Swarm Service API

Portainer is vulnerable to an endpoint security bypass via Swarm service create/update, enabling non-admin users with access to a Docker Swarm endpoint to bypass `EndpointSecuritySettings` restrictions and gain elevated privileges such as configuring services with elevated Linux capabilities, disabling syscall filtering and AppArmor confinement, setting arbitrary sysctl values, and mounting arbitrary host paths.

Portainer +3 docker swarm privilege-escalation vulnerability CVE-2026-44849
2r 1t
high advisory

Portainer Bind Mount Restriction Bypass via HostConfig.Mounts (CVE-2026-44850)

Portainer versions 2.33.0 through 2.33.7, 2.39.0 through 2.39.1, and 2.40.0 through 2.40.9 are vulnerable to CVE-2026-44850, a bind-mount restriction bypass via the `HostConfig.Mounts` array allowing regular users to mount host paths into containers and potentially compromise the host filesystem.

Portainer +2 privilege-escalation vulnerability container CVE-2026-44850
2r 1t
high advisory

Portainer Arbitrary File Read via Git Symlink Injection

Portainer is vulnerable to an arbitrary file read vulnerability due to Git symlink injection when deploying stacks from Git repositories, allowing authenticated users to read sensitive files accessible to the Portainer process.

Portainer CE +1 git symlink file-read portainer cve-2026-44881 vulnerability
2r 5t
high advisory

wger IDOR Vulnerability Exposes Private Workout Data (CVE-2026-43977)

wger 2.5 and earlier is vulnerable to CVE-2026-43977, an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to read another user's private workout session notes, exercise history, and training statistics by accessing the `/logs/` and `/stats/` actions on a public template routine they do not own.

wger idor vulnerability data-breach cloud
2r 1t
critical advisory

Cisco Catalyst SD-WAN Manager Multiple Vulnerabilities

Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow a remote attacker to gain access to sensitive information, elevate privileges, or gain unauthorized access to the application.

Catalyst SD-WAN Manager cisco sdwan vulnerability privilege-escalation initial-access
2r 2t
high advisory

Siemens Opcenter RDnL Missing Authentication Vulnerability (CVE-2026-27446)

Siemens Opcenter RDnL is vulnerable to missing authentication in critical function (CVE-2026-27446), where an unauthenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker, potentially leading to availability impacts and message injection.

Opcenter RDnL +1 cve vulnerability siemens activemq
2r 1t 1c
medium advisory

Strapi Unauthenticated Account Takeover via Relational Filtering Vulnerability (CVE-2026-27886)

Strapi versions prior to 5.37.0 are vulnerable to an unauthenticated boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field, via the 'where' query parameter on publicly accessible content-types; extracting an admin reset token via this oracle makes full administrative account takeover possible without authentication.

@strapi/strapi cve strapi account takeover vulnerability
2r 1t
critical advisory

Exim Mail Transfer Agent User-After-Free Remote Code Execution Vulnerability (CVE-2026-45185)

CVE-2026-45185, a user-after-free vulnerability in Exim versions 4.97 through 4.99.2, allows an unauthenticated remote attacker to execute arbitrary code by sending crafted SMTP traffic with BDAT chunking during TLS shutdown.

Exim rce vulnerability cve-2026-45185 user-after-free gnutls
2r 1t 1c
critical advisory

Strapi Content-Type Builder SQL Injection Vulnerability (CVE-2026-22599)

A SQL injection vulnerability, identified as CVE-2026-22599, affects Strapi's Content-Type Builder, where an authenticated administrator could inject arbitrary database statements through the `column.defaultTo` attribute, potentially leading to arbitrary file read, denial of service, or remote code execution on the database server.

@strapi/content-type-builder +1 sql-injection vulnerability strapi
2r 1t
medium advisory

HPE Security Advisory for Telco Intelligent Assurance Vulnerabilities

HPE released a security advisory addressing multiple vulnerabilities in Telco Intelligent Assurance version 4.2.14, prompting users to apply necessary updates to mitigate potential risks.

Telco Intelligent Assurance 4.2.14 hpe vulnerability telco
2r
critical advisory

Drupal Date iCal Module Vulnerability Allows Information Disclosure

A critical information disclosure vulnerability exists in the Drupal Date iCal module versions prior to 4.0.15, potentially allowing unauthorized access to sensitive information.

Date iCal < 4.0.15 drupal information-disclosure vulnerability
2r 1t
high advisory

CVE-2026-42930: F5 BIG-IP Appliance Mode Restriction Bypass

CVE-2026-42930 allows an authenticated attacker with 'Administrator' privileges to bypass Appliance mode restrictions on F5 BIG-IP systems.

BIG-IP vulnerability privilege-escalation f5
2r 1t 1c
medium advisory

CVE-2026-0239 Chronosphere Chronocollector Information Disclosure Vulnerability

CVE-2026-0239 is an information disclosure vulnerability in Chronosphere Chronocollector versions earlier than v0.116.0, allowing an unauthenticated attacker with network access to retrieve sensitive information.

Chronosphere Chronocollector < v0.116.0 information disclosure vulnerability network
1r
medium advisory

CVE-2026-0244 Prisma SD-WAN ION Improper Certificate Validation Vulnerability

CVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION that allows a man-in-the-middle (MitM) attacker to impersonate the controller.

Prisma SD-WAN ION vulnerability mitm certificate validation
2r 1t
low threat

CVE-2026-0238: Palo Alto Networks Broker VM Improper Input Validation

CVE-2026-0238 is an improper input validation vulnerability in Palo Alto Networks Broker VM that allows an authenticated administrator to inject arbitrary content into certain fields, affecting versions 30.0 prior to 30.0.24.

exploited Broker VM vulnerability input validation
2r
high advisory

Uniget Command Injection Vulnerability via Malicious Metadata

Uniget is vulnerable to command injection because the `check` field is loaded directly from untrusted JSON metadata without validation, allowing an attacker to execute arbitrary shell commands on the victim's system when performing common uniget operations.

PoC cli command-injection vulnerability linux
2r 1t 1c updated
critical threat

Exim Internet Mailer Vulnerability (Versions 4.97 to 4.99.2)

A critical vulnerability exists in Exim Internet Mailer versions 4.97 to 4.99.2, requiring users and administrators to apply necessary updates.

Exim Internet Mailer exim vulnerability rce
2r 1t
high advisory

n8n Patches Multiple Vulnerabilities Across Products

On May 13, 2026, n8n released security advisories addressing vulnerabilities in several products, including prototype pollution and OAuth endpoint issues.

n8n +4 vulnerability patch
2r
high advisory

HPE ArubaOS Multiple Vulnerabilities

HPE published security advisories addressing vulnerabilities in ArubaOS versions AOS-10.8.x.x, AOS-10.7.x.x, AOS-10.4.x.x, AOS-8.13.x.x, AOS-8.12.x.x, and AOS-8.10.x.x, as well as Aruba Networking AOS-8 Instant AP and AOS-10 AP, potentially allowing unauthorized access and control.

ArubaOS AOS-10.8.x.x +7 hpe arubaos vulnerability network
2r
high advisory

Multiple Vulnerabilities in n8n Allow for Remote Code Execution and Data Manipulation

An authenticated, remote attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, conduct SQL injection attacks, manipulate data, or disclose sensitive information.

n8n vulnerability rce sqli
2r 7t
high advisory

MongoDB Multiple Vulnerabilities

An authenticated remote attacker can exploit vulnerabilities in MongoDB to execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.

MongoDB vulnerability code execution data breach denial of service
2r 4t
high advisory

Multiple Vulnerabilities in Aruba AOS-8 and AOS-10 Allow for Arbitrary Code Execution, XSS, and DoS

Multiple vulnerabilities in ArubaOS allow an attacker to execute arbitrary code, perform cross-site scripting attacks, or cause a denial-of-service condition.

ArubaOS vulnerability code execution xss dos network
2r 2t
high advisory

Multiple Vulnerabilities in Kiali for Red Hat OpenShift Service Mesh

An anonymous remote attacker can exploit multiple vulnerabilities in Kiali for Red Hat OpenShift Service Mesh to gain extended privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.

OpenShift Service Mesh +1 kiali openshift servicemesh vulnerability privilege-escalation defense-evasion impact discovery +1
2r 4t
critical advisory

Multiple Vulnerabilities in Aruba ArubaOS

Multiple vulnerabilities in Aruba ArubaOS could allow an attacker to perform a denial of service attack, disclose information, perform a SQL injection attack, bypass security measures, and execute arbitrary code.

ArubaOS vulnerability denial-of-service sql-injection code-execution
2r 3t
medium advisory

Devolutions Server Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in Devolutions Server to manipulate files.

Devolutions Server file-manipulation vulnerability devolutions-server
2r 1t
high advisory

OX Dovecot Pro Multiple Vulnerabilities

Multiple vulnerabilities in OX Dovecot Pro could allow an attacker to perform SQL injection attacks, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.

Dovecot Pro vulnerability sql-injection dos
2r 4t
medium advisory

Multiple Vulnerabilities in Adobe Creative Cloud Applications

A local attacker can exploit multiple vulnerabilities in Adobe Creative Cloud applications to execute arbitrary program code, disclose confidential information, or cause a denial-of-service condition.

Creative Cloud adobe creative-cloud vulnerability code-execution information-disclosure denial-of-service
2r 3t
critical advisory

Fortinet FortiSandbox Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in Fortinet FortiSandbox to execute arbitrary program code, potentially leading to system compromise.

FortiSandbox fortinet rce vulnerability
2r 1t
high advisory

Multiple Vulnerabilities in Microsoft Developer Tools

Multiple vulnerabilities in Microsoft developer tools and platforms could allow an attacker to achieve arbitrary code execution, data manipulation, privilege escalation, bypassing security measures, information disclosure, and denial of service.

Visual Studio 2017 +11 vulnerability code-execution privilege-escalation denial-of-service windows cloud
3r 6t
medium advisory

Keycloak Vulnerability Allows Arbitrary Email Sending

An anonymous, remote attacker can exploit a vulnerability in Keycloak to send arbitrary emails, potentially leading to phishing or social engineering attacks.

Keycloak email vulnerability spoofing
2r 1t
high advisory

strongSwan eap-mschapv2 Plugin Vulnerability

A remote, anonymous attacker can exploit a vulnerability in strongSwan's eap-mschapv2 plugin to cause a denial of service condition or possibly execute arbitrary code.

strongSwan vulnerability denial-of-service
2r 2t
high advisory

Microsoft May 2026 Security Updates Address Remote Code Execution Vulnerabilities

Microsoft's May 2026 Security Updates address vulnerabilities that could allow remote attackers to execute arbitrary code on affected systems.

Microsoft products vulnerability patch rce
2r 1t 1i
high advisory

Adobe Acrobat Reader Vulnerability Allows Information Disclosure and Code Execution

A local attacker can exploit a vulnerability in Adobe Acrobat Reader to disclose sensitive information and execute arbitrary code, potentially leading to a complete system compromise.

Acrobat Reader vulnerability code-execution information-disclosure
2r 3t
critical threat

Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution

Multiple vulnerabilities in Fortinet's FortiAuthenticator and FortiSandbox products could lead to remote code execution, potentially allowing attackers to install programs, modify data, or create new accounts.

FortiAuthenticator +1 vulnerability rce fortinet
2r 1t
high advisory

SPIP RCE Vulnerability in Nginx Configurations (CVE-2026-8430)

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability exploitable in certain Nginx configurations, allowing attackers to execute arbitrary code within the web server's context.

SPIP +1 vulnerability rce webserver
2r 1t 1c
high advisory

Fortinet Patches Multiple Vulnerabilities in FortiAuthenticator, FortiOS, and FortiSandbox

Fortinet released security advisories on May 12, 2026, addressing critical vulnerabilities including improper access control, incorrect global authorization, and out-of-bounds access across FortiAuthenticator, FortiOS, and FortiSandbox product lines, urging users to apply necessary updates.

FortiAuthenticator +20 fortinet vulnerability patch
2r
high advisory

CVE-2026-40410 - Windows SMB Client Use-After-Free Privilege Escalation

CVE-2026-40410 is a use-after-free vulnerability in the Windows SMB Client that allows an authorized attacker to elevate privileges locally.

Windows SMB Client cve vulnerability smb privilege-escalation
2r 1t 1c
medium advisory

Intel Addresses Vulnerabilities in Multiple Software Products

Intel released security advisories addressing vulnerabilities in Display Virtualization for Windows OS driver software, Intel EMA software, AI Playground software, and Intel Vision software, requiring users to update to the latest versions.

Display Virtualization for Windows OS driver software +3 vulnerability intel software update windows
3r
high advisory

CVE-2026-41086: Windows Admin Center Privilege Escalation via Improper Access Control

CVE-2026-41086 describes an improper access control vulnerability in Windows Admin Center, allowing an authorized attacker to elevate privileges over a network.

Windows Admin Center privilege-escalation vulnerability windows
2r 1t 1c
high advisory

CVE-2026-35438: Windows Admin Center Missing Authorization Vulnerability

CVE-2026-35438 is a missing authorization vulnerability in Windows Admin Center that allows an authorized attacker to elevate privileges over a network.

Windows Admin Center privilege-escalation vulnerability network
2r 1t 1c
medium advisory

CVE-2026-35424: Windows IKE Protocol Memory Leak Denial-of-Service

CVE-2026-35424 is a denial-of-service vulnerability in the Windows Internet Key Exchange (IKE) Protocol caused by a missing release of memory after its effective lifetime, allowing an unauthenticated remote attacker to trigger a denial of service over a network.

Internet Key Exchange dos vulnerability windows ike
1r 1c
high threat

CVE-2026-35415: Windows Storage Spaces Controller Integer Overflow Privilege Escalation

CVE-2026-35415 is an integer overflow vulnerability in the Windows Storage Spaces Controller that allows a locally authorized attacker to elevate privileges.

exploited Windows Storage Spaces Controller cve vulnerability privilege-escalation windows
2r 1t 1c
medium advisory

CVE-2026-34336 - Windows DWM Core Library Buffer Over-Read Information Disclosure

CVE-2026-34336 is a buffer over-read vulnerability in the Windows DWM Core Library, allowing a local, authenticated attacker to disclose sensitive information.

DWM Core Library vulnerability information-disclosure windows
2r 2t 1c
medium advisory

Ivanti Addresses Multiple Vulnerabilities in Various Products

Ivanti released security advisories on May 12, 2026, to address vulnerabilities in Xtraction, Endpoint Manager (EPM), Virtual Traffic Manager (vTM), and Secure Access Client (Windows), urging users to apply necessary updates to mitigate potential risks from CVE-2026-8043, CVE-2026-8051, CVE-2026-7431, and CVE-2026-7432.

Xtraction +3 ivanti vulnerability patch cve
2r 4c
medium advisory

Dalfox Unauthenticated Remote DoS via Closed-Channel Write in ParameterAnalysis

Dalfox is vulnerable to an unauthenticated remote denial-of-service (DoS) vulnerability (CVE-2026-45090) due to a closed channel write in the `ParameterAnalysis` function, triggered by a crafted POST request that crashes the Dalfox server process.

dalfox dos vulnerability
2r 1t
medium advisory

Schneider Electric Security Advisory AV26-449 Addressing Multiple Vulnerabilities

Schneider Electric published advisories on May 12, 2026, addressing vulnerabilities in multiple products including Ecostruxure Machine Expert HVAC, Easergy MiCOM C264, Easergy C5, Easergy MiCOM P30, Easergy MiCOM P40, EcoStruxure Power Automation System, iPMFLS, PowerLogic, Saitel DP, EasyLogic T150, EasyLogic T150 Remote Terminal Unit and Controller, Saitel DP Remote Terminal Unit and Controller, EcoStruxure Panel Server PAS400, PAS600, PAS600V2, PAS800, PAS800V2 and Easergy MiCOM Px40 Series related to clear text storage, insufficient entropy, improper path restrictions and insecure defaults.

Ecostruxure Machine Expert HVAC +17 vulnerability scada ics ot
2r
medium advisory

Multiple Vulnerabilities in Microsoft Azure

Multiple vulnerabilities exist in Microsoft Azure, specifically affecting azl3 kernel and azl3 krb5, potentially leading to an unspecified security issue.

Azure +2 vulnerability
2r 3c
high advisory

Multiple Vulnerabilities in Microsoft Edge Allow for Privilege Escalation, Data Breach, and Security Policy Bypass

Multiple vulnerabilities in Microsoft Edge and Microsoft Edge for Android can allow an attacker to perform privilege escalation, cause a data breach, and bypass security policies.

Edge +1 vulnerability privilege-escalation data-breach security-policy-bypass
2r 1t 1c
high threat

Multiple Vulnerabilities in Centreon Products

Multiple vulnerabilities in Centreon products allow for remote code execution, SQL injection, and cross-site scripting.

Anomaly Detection +8 centreon vulnerability rce sqli xss
2r 1t 1i
high advisory

Multiple Vulnerabilities in Schneider Electric Products

Multiple vulnerabilities in Schneider Electric products can allow an attacker to perform privilege escalation, data confidentiality breaches, and data integrity breaches.

Easergy C5 +28 vulnerability industrial_control_system privilege_escalation
2r 2c
high advisory

Multiple Vulnerabilities in Apple Products Allow for Arbitrary Code Execution, Privilege Escalation, and Data Confidentiality Compromise

Multiple vulnerabilities in Apple products could allow an attacker to execute arbitrary code, escalate privileges, and compromise data confidentiality.

iOS +7 vulnerability apple code execution privilege escalation data breach
2r 3t 5c
high advisory

Multiple Vulnerabilities in Nextcloud Products

Multiple vulnerabilities in Nextcloud products can lead to data confidentiality breaches, data integrity compromise, and security policy bypass.

PoC Android Files +7 nextcloud vulnerability security-policy-bypass
2r 5c 6i updated
critical threat

Multiple Vulnerabilities in Axis Products Allow Remote Code Execution and Privilege Escalation

Multiple vulnerabilities in Axis products allow remote arbitrary code execution and privilege escalation in Axis OS versions 12.10.x prior to 12.10.37 and 12.9.x prior to 12.9.33 for Active Track.

Axis OS Active Track vulnerability rce privilege-escalation
2r 2t 4c
medium advisory

CPython Security Policy Bypass Vulnerability

A vulnerability in CPython, tracked as CVE-2026-7210, allows an attacker to bypass the security policy, requiring the latest security patch for mitigation.

CPython security-bypass vulnerability
2r 1t 1c
medium advisory

Traefik Security Policy Bypass Vulnerability

A security policy bypass vulnerability exists in Traefik versions prior to v2.11.46, v3.6.x before v3.6.17, and v3.7.x before v3.7.1, allowing attackers to potentially circumvent intended access controls.

Traefik < 2.11.46 +2 security-policy-bypass vulnerability traefik
1r 1t
medium advisory

Siemens Teamcenter Hardcoded Key Vulnerability (CVE-2026-33893)

CVE-2026-33893 describes a vulnerability in Siemens Teamcenter where hardcoded keys used for obfuscation are stored directly within the application, potentially allowing an attacker to obtain these keys and gain unauthorized access.

Teamcenter V2312 +4 cve vulnerability hardcoded-key teamcenter
2r 2t 1c
critical advisory

ROS# Path Traversal Vulnerability (CVE-2026-41551)

ROS# versions prior to V2.2.2 are vulnerable to path traversal (CVE-2026-41551) due to insufficient sanitization of user input, potentially enabling remote attackers to read arbitrary files.

ROS# path-traversal vulnerability cve
2r 1t 1c
critical advisory

Multiple Vulnerabilities in dnsmasq

Multiple vulnerabilities in dnsmasq could allow an attacker to cause a denial of service, execute arbitrary code with root privileges, disclose sensitive information, manipulate data, and redirect users to malicious domains.

Dnsmasq vulnerability denial-of-service code-execution information-disclosure
2r 9t
high advisory

KACO blueplanet Devices Vulnerable to Credential Derivation (CVE-2025-40946)

CVE-2025-40946 describes a vulnerability in KACO new energy blueplanet products where a weak CRC16-based algorithm for generating Technical Service credentials could allow an attacker to derive the credentials from the device's serial number and misuse them to gain unauthorized access.

blueplanet 100 NX3 M8 +29 credential-access vulnerability KACO
2r 1c
high advisory

Multiple Vulnerabilities in pgAdmin

Multiple vulnerabilities in pgAdmin could allow an attacker to escalate privileges, execute arbitrary code, bypass security measures, perform SQL injection and cross-site scripting attacks, manipulate data, or disclose sensitive information.

pgAdmin vulnerability sql-injection xss privilege-escalation
2r 9t
high advisory

Multiple Vulnerabilities in Apple macOS Sonoma, Sequoia, and Tahoe

Multiple vulnerabilities exist in Apple macOS Sonoma, macOS Sequoia, and macOS Tahoe that could allow an attacker to elevate privileges, conduct a denial-of-service attack, disclose information, execute arbitrary code, and bypass security measures.

macOS Sonoma +2 macos vulnerability privilege-escalation defense-evasion execution information-discovery denial-of-service
2r 6t
medium advisory

Multiple Vulnerabilities in ImageMagick Allow for DoS and Potential Data Exposure

A local attacker can exploit multiple vulnerabilities in ImageMagick to perform a denial of service attack or affect confidentiality, availability, and integrity.

ImageMagick vulnerability dos local-access
2r 2t
high advisory

Multiple Vulnerabilities in Apple macOS

Multiple vulnerabilities in Apple macOS allow an attacker to bypass security measures, conduct denial of service attacks, disclose information, manipulate files, and escalate privileges.

macOS vulnerability
2r 4t
high advisory

Poppler Vulnerability Allows Code Execution

A local attacker can exploit a vulnerability in poppler to execute arbitrary program code on a vulnerable system.

poppler vulnerability code-execution
2r 1t
medium advisory

Sonatype Nexus Repository Manager Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Sonatype Nexus Repository Manager to bypass security precautions.

Nexus Repository Manager security-bypass vulnerability nexus
2r 1t
critical advisory

Red Hat Enterprise Linux Multiple Vulnerabilities Leading to RCE/DoS

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.

Enterprise Linux vulnerability rhel remote-code-execution denial-of-service linux
2r 2t
critical advisory

Multiple Vulnerabilities in Red Hat Build of Keycloak

Multiple vulnerabilities in Red Hat Build of Keycloak could allow an attacker to bypass authentication, gain elevated privileges, disclose sensitive information, cause a denial of service condition, execute arbitrary code, or manipulate data.

Build of Keycloak keycloak vulnerability authentication-bypass
2r 5t
medium advisory

Multiple Vulnerabilities in 7-Zip Allow File Manipulation and Information Disclosure

An anonymous remote attacker can exploit multiple vulnerabilities in 7-Zip to manipulate files or disclose sensitive information on Windows systems.

7-Zip vulnerability file-manipulation information-disclosure windows
2r 2t
high advisory

CVE-2026-34259: SAP Forecasting & Replenishment OS Command Execution

CVE-2026-34259 is an OS Command Execution vulnerability in SAP Forecasting & Replenishment that allows an authenticated attacker with administrative privileges to execute arbitrary OS commands, potentially leading to complete system compromise.

Forecasting & Replenishment cve command injection sap rce vulnerability
2r 3t 1c
high advisory

SAP S/4HANA SQL Injection Vulnerability (CVE-2026-34260)

SAP S/4HANA (SAP Enterprise Search for ABAP) is vulnerable to SQL injection (CVE-2026-34260) via user-controlled input, allowing an authenticated attacker to inject malicious SQL statements, leading to unauthorized data access and potential application crashes.

S/4HANA sql-injection vulnerability sap
2r 2t 1c
medium advisory

JetBrains TeamCity Vulnerability

A security advisory released by JetBrains on May 11, 2026, addresses a vulnerability in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5, requiring users to apply updates to mitigate potential risks.

TeamCity vulnerability jetbrains
2r
high advisory

OpenClaw Arbitrary Code Execution via Malicious Plugin

OpenClaw before version 2026.4.23 is vulnerable to arbitrary code execution (CVE-2026-45004) due to insecurely loading the setup-api.js file from the current working directory, allowing attackers to execute arbitrary JavaScript under the current user account.

OpenClaw code execution vulnerability javascript
2r 1t 1c
high advisory

OpenClaw Gateway Config Mutation Guard Bypass (CVE-2026-45001)

OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints, allowing a prompt-injected model with access to the owner-only gateway tool to persist unauthorized changes to protected operator settings.

OpenClaw cve vulnerability
2r 2t 1c
medium advisory

Broadcom Patches Multiple Vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes

Broadcom published a security advisory addressing vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes versions prior to 4.3.0, 4.2.6, 4.1.11, 4.0.20 and 3.13.15, potentially allowing an attacker to compromise the affected system.

VMware Tanzu RabbitMQ on Kubernetes vulnerability patch kubernetes
2r
high advisory

Next.js i18n Pages Router Middleware Authentication Bypass (CVE-2026-44573)

Next.js applications using the Pages Router with `i18n` and middleware-based authorization are vulnerable to an authentication bypass (CVE-2026-44573), allowing unauthorized access to protected page data via locale-less `/_next/data/<buildId>/<page>.json` requests.

next +1 nextjs authentication-bypass vulnerability
2r 1t
medium advisory

Ubuntu Linux Kernel Vulnerabilities Addressed in Security Notices

Ubuntu released security notices between May 4 and 10, 2026, addressing vulnerabilities in the Linux kernel affecting Ubuntu 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10, requiring timely updates.

Ubuntu 20.04 LTS +3 linux kernel vulnerability patch
2r
high threat

Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse (CVE-2026-44473)

Ella Core is vulnerable to UE downlink redirection (CVE-2026-44473) due to missing SCTP association verification, enabling a malicious radio to forge a PDUSessionResourceSetupResponse and redirect downlink traffic.

core vulnerability 5G downlink redirection CVE-2026-44473
2r 1t
high advisory

urllib3 Sensitive Header Leak in Low-Level Redirects (CVE-2026-44431)

Sensitive headers (`Authorization`, `Cookie`, and `Proxy-Authorization`) are forwarded across origins in proxied low-level redirects when using `HTTPConnection.urlopen()` instances created via `ProxyManager.connection_from_url()` in urllib3 versions before 2.7.0, potentially exposing credentials to unintended third parties; upgrade to version 2.7.0 or later to remediate this issue.

urllib3 header-leak vulnerability
2r
medium advisory

Urllib3 Decompression Bomb Vulnerability in Streaming API (CVE-2026-44432)

Urllib3 versions before 2.7.0 are vulnerable to excessive resource consumption when using the streaming API to decompress responses, particularly when using the Brotli library or calling HTTPResponse.drain_conn() after partial decompression, leading to high CPU usage and memory allocation, potentially causing a denial-of-service condition (CVE-2026-44432).

urllib3 decompression-bomb denial-of-service vulnerability
2r 1t
high advisory

go-git Improper Parsing of Malformed Git Objects

go-git may parse malformed Git objects differently than upstream Git, leading to inconsistent interpretation and potentially allowing the signing or verification of commits with altered metadata, as described in CVE-2026-45022.

go-git/go-git/v6 +1 vulnerability git go supply chain
2r
high advisory

Open WebUI Inconsistent Authorization Controls in Memories API

Open WebUI versions before 0.6.19 have inconsistent authorization controls within the memories API, allowing standard users to view, delete, and restore other users' memories, potentially leading to sensitive data disclosure and unauthorized access as tracked by CVE-2026-44570.

open-webui authorization information-disclosure vulnerability
2r 1t
high advisory

PraisonAI Unsafe Tool Resolution Vulnerability

PraisonAI resolves tool names against module globals and `__main__` after failing to match declared tools, allowing an attacker who can influence tool-call names to invoke unintended application callables, leading to potential unauthorized state changes and command execution.

PraisonAI +1 vulnerability code-execution ai-agent
2r 1t 1c
critical advisory

Multiple Vulnerabilities in KDE Kdenlive and Okular

Multiple vulnerabilities in KDE Kdenlive and Okular allow a remote, anonymous attacker to execute arbitrary code, bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.

Kdenlive +1 vulnerability code-execution denial-of-service
2r 4t
medium advisory

jq Vulnerability Allows Security Bypass

A local attacker can exploit a vulnerability in jq to bypass security measures.

jq vulnerability security-bypass
1r
medium advisory

Multiple Vulnerabilities in Red Hat Hardened Images RPMs

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to cause a denial-of-service condition and possibly manipulate data or perform path traversal attacks.

Hardened Images RPMs vulnerability denial-of-service path-traversal
2r 1t
high advisory

Multiple Vulnerabilities in HCL BigFix

Multiple vulnerabilities in HCL BigFix could allow an attacker to disclose information, execute arbitrary code, perform a denial of service attack, and manipulate files.

BigFix vulnerability code-execution dos information-disclosure
2r 3t
medium advisory

CVE-2026-23377 Vulnerability

CVE-2026-23377 is a reported vulnerability with no further details available from the Microsoft Security Response Center.

vulnerability
1c
critical threat

Apache NiFi Multiple Vulnerabilities Allow Remote Code Execution

An authenticated, remote attacker can exploit multiple vulnerabilities in Apache NiFi to execute arbitrary code and achieve unspecified impacts.

Nifi apache-nifi rce vulnerability
2r
medium advisory

CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup

CVE-2025-37877 is a vulnerability in the iommu component requiring proper cleanup, affecting Microsoft products.

vulnerability iommu cleanup
1c
medium threat

CVE-2025-38717 KCM Race Condition Vulnerability

CVE-2025-38717 is a race condition vulnerability in the kcm_unattach() function of a Microsoft product, potentially leading to denial of service or privilege escalation.

race-condition vulnerability net kcm
2r 1c
medium advisory

CVE-2024-26756: Unspecified Vulnerability in Microsoft Products

Microsoft released details for CVE-2024-26756, an unspecified vulnerability affecting Microsoft products, but provided no further information.

vulnerability microsoft
2r 1c
medium advisory

CVE-2024-26757: Unspecified Vulnerability in Microsoft md

CVE-2024-26757 is an unspecified vulnerability in a Microsoft product, potentially allowing an attacker to perform unauthorized actions.

vulnerability microsoft
2r 1c
high advisory

SmarterTools SmarterMail Multiple Vulnerabilities

Multiple vulnerabilities in SmarterTools SmarterMail could allow an attacker to gain elevated privileges, bypass security measures, manipulate data, disclose sensitive information, cause a denial-of-service condition, or carry out other unspecified attacks.

SmarterMail vulnerability webserver denial-of-service privilege-escalation
2r 4t
critical threat

OpenCATS 0.9.4 Remote Code Execution Vulnerability (CVE-2021-47936)

OpenCATS 0.9.4 is vulnerable to remote code execution (CVE-2021-47936) allowing unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments through the careers job application endpoint, leading to potential system compromise.

OpenCATS 0.9.4 CVE-2021-47936 rce opencats vulnerability
2r 2t 1c
critical advisory

CVE-2026-41889 pgx: SQL Injection via Placeholder Confusion

CVE-2026-41889 is a critical SQL Injection vulnerability involving placeholder confusion with dollar-quoted string literals in the pgx library, potentially allowing attackers to execute arbitrary SQL queries.

sql-injection cve vulnerability
2r 1t 1c
medium advisory

free5GC NEF PATCH Handler Vulnerability Leads to Denial of Service

A nil pointer dereference vulnerability exists in free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler when UDR access fails, causing a denial-of-service condition.

nef 4.2.1 denial-of-service vulnerability free5GC NEF CVE-2026-44322
2r 1t 3i
high advisory

Atlassian Security Advisory Addresses Critical Vulnerabilities in Multiple Products

Atlassian released a security advisory addressing multiple critical vulnerabilities in Bamboo, Bitbucket, Confluence, Jira, and Jira Service Management Data Center and Server products.

Bamboo Data Center and Server +4 atlassian vulnerability rce
2r
high advisory

Velocity.js Prototype Pollution Vulnerability via #set Directive (CVE-2026-44966)

A prototype pollution vulnerability exists in Velocity.js versions 2.1.5 and earlier, allowing attackers to modify Object.prototype via crafted #set directives in Velocity templates, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE).

velocityjs <= 2.1.5 prototype-pollution vulnerability velocity.js CVE-2026-44966
2r 1t
high advisory

ex_webrtc Missing DTLS Fingerprint Validation Allows MITM

The ex_webrtc library is vulnerable to a man-in-the-middle attack due to missing DTLS peer certificate fingerprint validation in the DTLS client role, potentially allowing interception of media and data channels when chained with insecure signaling or a peer with similar validation gaps; upgrade to versions 0.15.1 or 0.16.1 to mitigate this vulnerability.

ex_webrtc +1 webrtc dtls mitm vulnerability
2r 1t
high threat

Dirty Frag Linux Kernel Local Privilege Escalation Vulnerability

The Dirty Frag vulnerability (CVE-2026-43284 and CVE-2026-43500) is a Linux kernel local privilege escalation that allows an unprivileged local user to gain root privileges by exploiting flaws in the networking subsystem to overwrite protected file contents in the page cache.

exploited Linux kernel linux privilege-escalation vulnerability dirty_frag
2r 1t
critical advisory

Spring Cloud Config Vulnerabilities Allow Secret Access and Directory Traversal

Multiple vulnerabilities in Spring Cloud Config, including CVE-2026-40981, CVE-2026-40982, and CVE-2026-41002, could allow unauthorized access to secrets and directory traversal attacks, potentially leading to data exposure and system compromise.

Spring Cloud Config spring cloud config vulnerability directory_traversal secret_access
2r 3c
medium advisory

Mozilla Firefox Multiple Vulnerabilities

Mozilla released security updates to address vulnerabilities in Firefox and Firefox ESR versions, potentially allowing for exploitation if left unpatched.

Firefox +1 vulnerability browser mozilla
2r 2t
critical advisory

Multiple Vulnerabilities in Ivanti Endpoint Manager Mobile

Multiple vulnerabilities in Ivanti Endpoint Manager Mobile allow an attacker to gain administrator privileges, execute arbitrary code with administrator privileges, bypass security measures, manipulate data, and disclose sensitive information.

Endpoint Manager Mobile vulnerability privilege-escalation execution
2r 4t
medium advisory

Ruby Multiple Vulnerabilities Lead to DoS and Information Disclosure

A remote, anonymous attacker can exploit multiple unspecified vulnerabilities in Ruby to perform a denial of service attack or disclose sensitive information.

Ruby dos information_disclosure vulnerability
2r 1t
high advisory

LiteLLM Vulnerability Allows Code Execution and Information Disclosure

A remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code and disclose sensitive information.

LiteLLM vulnerability code-execution
2r 2t
critical advisory

Red Hat Build of Debezium for Red Hat Application Foundations Vulnerabilities Allow Code Execution

Multiple vulnerabilities in Red Hat Build of Debezium for Red Hat Application Foundations could allow an attacker to execute arbitrary code.

Build of Debezium for Red Hat Application Foundations vulnerability code-execution debezium
2r 1t
high advisory

IBM WebSphere Application Server Liberty Vulnerability Allows Code Execution

An authenticated remote attacker can exploit a vulnerability in IBM WebSphere Application Server Liberty to execute arbitrary program code on the target system.

WebSphere Application Server Liberty websphere rce code_execution vulnerability
2r 1t
critical threat

LiteLLM Multiple Vulnerabilities

Multiple vulnerabilities in LiteLLM could allow an attacker to perform a SQL injection attack and gain unauthorized access or execute arbitrary code with the privileges of the service.

LiteLLM sql-injection vulnerability privilege-escalation
2r 2t
high threat

CodeAstro Leave Management System SQL Injection Vulnerability

A SQL injection vulnerability (CVE-2026-8132) exists in CodeAstro Leave Management System 1.0 via manipulation of the txt_username parameter in /login.php, enabling remote exploitation and potential database compromise.

exploited Leave Management System 1.0 sql-injection vulnerability web-application
2r 1t 1c
high advisory

SourceCodester SUP Online Shopping SQL Injection Vulnerability (CVE-2026-8130)

SourceCodester SUP Online Shopping 1.0 is vulnerable to SQL injection via the 'seenid' parameter in /admin/message.php, allowing remote attackers to execute arbitrary SQL commands; exploit code is publicly available.

SUP Online Shopping 1.0 sql-injection vulnerability web-application
2r 1t 1c
critical advisory

Zebra Consensus Divergence in Transparent Sighash Hash-Type Handling (CVE-2026-44497)

Zebra versions prior to 4.4.0 exhibit a consensus divergence vulnerability (CVE-2026-44497) due to insufficient error handling of invalid sighash types during sighash computation, potentially leading to network partitioning and double-spend attacks.

zebrad +1 consensus-failure vulnerability network-partition
2r
high threat

Broadcom Patches Multiple Vulnerabilities in Tanzu Products

Broadcom released security advisories on May 7, 2026, addressing vulnerabilities in several Tanzu products, requiring users and administrators to apply necessary updates to mitigate potential risks.

Tanzu Greenplum Command Center +7 vulnerability patch broadcom tanzu
2r 1t
critical threat

Ivanti EPMM Authenticated Remote Code Execution Vulnerability Exploited

CVE-2026-6973, an authenticated remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM), is being actively exploited, potentially leading to data breaches and system compromise.

exploited Endpoint Manager Mobile ivanti eppm rce vulnerability exploitation
2r 4t 1c
critical advisory

PAN-OS Authentication Portal Remote Code Execution Vulnerability

An unauthenticated remote code execution vulnerability exists in the PAN-OS Authentication Portal (Captive Portal) service, potentially allowing attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending crafted network packets.

PAN-OS +2 vulnerability rce network
2r 1t
high advisory

CVE-2026-7925 Use-After-Free Vulnerability in Chromium Chromoting

CVE-2026-7925 is a use-after-free vulnerability in the Chromoting component of Google Chrome, also affecting Microsoft Edge.

Chrome +1 use-after-free vulnerability chromoting
2r 1c
critical advisory

CVE-2026-33844 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

CVE-2026-33844 is a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra due to improper input validation, allowing an authorized network attacker to execute code.

Azure Managed Instance for Apache Cassandra rce vulnerability azure
2r 1t
medium advisory

CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability

CVE-2026-26164 is an information disclosure vulnerability in M365 Copilot due to improper neutralization of special elements, allowing unauthorized information disclosure over a network.

M365 Copilot information disclosure cloud vulnerability
2r 1t
critical advisory

AxonFlow Platform Multi-Tenant Isolation and Access Control Vulnerabilities

Multiple vulnerabilities in AxonFlow platform versions prior to 7.5.0, including multi-tenant isolation issues and SQL injection, could lead to unauthorized access, information disclosure, denial of service, and other security impacts; AxonFlow v7.5.0 resolves these issues.

axonflow platform +2 multi-tenancy access-control SQL injection denial of service vulnerability
2r 5t
high advisory

DivvyDrive Cross-Site Request Forgery Vulnerability (CVE-2026-5791)

DivvyDrive versions 4.8.2.9 through 4.8.3.2 are susceptible to cross-site request forgery (CSRF), allowing an attacker to execute unauthorized actions on behalf of an authenticated user.

DivvyDrive csrf web-application vulnerability
2r 1t 1c
critical advisory

wger Cross-Tenant Password Reset and Plaintext Disclosure Vulnerability

A vulnerability in wger version 2.5 and earlier allows an attacker with `gym.manage_gym` permission and `gym=None` to reset the password of any other `gym=None` user, disclosing the new password in plaintext and allowing account takeover.

wger vulnerability account-takeover web-application
2r 1t
high advisory

QuantumNous new-api SSRF Bypass via 0.0.0.0

The QuantumNous new-api is vulnerable to SSRF attacks. The SSRF protection implemented in versions v0.9.0.5 (CVE-2025-59146) and v0.9.6 (CVE-2025-62155) can be bypassed by using the address `0.0.0.0`. An attacker with a valid API token can send a request to `/v1/chat/completions`, `/v1/responses`, or `/v1/messages` with `0.0.0.0` as the image/file URL host, which bypasses the private-IP filter and allows the server to issue HTTP requests to localhost, enabling a blind SSRF and possibly a full-read SSRF in specific configurations.

new-api ssrf vulnerability quantumnous
2r 1t 2c 2i
medium advisory

Google Chrome Security Update Required

Google released a security advisory addressing vulnerabilities in Chrome for Desktop versions prior to 148.0.7778.96/97 on Windows/Mac and 148.0.7778.96 on Linux, requiring users to update to mitigate potential exploits.

Chrome +1 vulnerability browser
2r
medium advisory

Broadcom Tanzu Jammy Stemcell Vulnerability (CVE-2026-341431)

A vulnerability in Broadcom's Tanzu Jammy Stemcell versions prior to 1.1193, tracked as CVE-2026-341431, requires patching to prevent potential exploitation.

Tanzu Jammy Stemcell vmware tanzu vulnerability
2r 1t
critical threat

Cisco Unity Connection Multiple Vulnerabilities

Multiple vulnerabilities in Cisco Unity Connection allow an attacker to execute arbitrary code with administrator privileges or perform Server-Side Request Forgery (SSRF) attacks.

Unity Connection cisco vulnerability privilege-escalation execution ssrf
2r 2t
critical threat

Multiple Vulnerabilities in Oracle Java SE

A remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.

Java SE java vulnerability remote-access
2r 1t
medium advisory

CPython Multiple Vulnerabilities Allow File Manipulation and DoS

A remote, authenticated attacker can exploit multiple vulnerabilities in CPython to manipulate files or cause a denial-of-service condition.

CPython vulnerability dos file_manipulation
2r 2t
medium advisory

Erlang/OTP Information Disclosure Vulnerability

A remote, authenticated attacker can exploit an unspecified vulnerability in Erlang/OTP to disclose sensitive information.

Erlang/OTP information-disclosure vulnerability erlang
2r 1t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux

An unauthenticated or authenticated remote attacker can exploit vulnerabilities in Red Hat Enterprise Linux to perform cross-site scripting, cause denial of service, or disclose sensitive information.

Red Hat Enterprise Linux vulnerability xss dos redhat
2r 3t
medium advisory

Red Hat OpenShift Service Mesh Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.

OpenShift Service Mesh openshift servicemesh vulnerability dos
2r 4t
medium advisory

Microsoft CVE-2026-25833 Vulnerability Published

Microsoft published CVE-2026-25833, a security vulnerability for which details are currently unavailable, impacting systems and requiring further investigation upon release of additional information.

vulnerability microsoft cve-2026-25833
1c
medium advisory

Microsoft Published Information Regarding CVE-2025-66442

Microsoft has published information regarding the vulnerability CVE-2025-66442; details are currently unavailable, limiting specific analysis and detection strategies.

cve vulnerability microsoft
2r 1t 1c
medium advisory

Microsoft Published Information Regarding CVE-2026-25835

Microsoft has published information regarding the vulnerability CVE-2026-25835, but details about the vulnerability, affected products, and exploitation are currently unavailable.

cve vulnerability microsoft
2r 1c
critical advisory

Gotenberg Unauthenticated SSRF Vulnerability

Gotenberg is vulnerable to Server-Side Request Forgery (SSRF) due to bypassable default deny-lists in the `downloadFrom` and `webhook` features, where case-sensitive regex matching allows attackers to use IPv6 loopback URLs to bypass the deny-list and access internal HTTP services.

Gotenberg ssrf vulnerability
2r 3i
high advisory

Gotenberg SSRF Vulnerability in LibreOffice Conversion Endpoint

Gotenberg is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient hardening in the LibreOffice conversion endpoint, allowing attackers to make outbound HTTP requests by embedding external URLs in uploaded documents, bypassing Gotenberg's SSRF filters, affecting versions up to 8.31.0, and potentially enabling access to internal services, data exfiltration, or port scanning.

Gotenberg +1 ssrf libreoffice vulnerability
2r 1i
medium advisory

Netty DNS Codec Input Validation Bypass Vulnerability

Netty's DNS codec fails to enforce RFC 1035 domain name constraints, leading to potential DNS cache poisoning, denial-of-service, and domain validation bypass through null byte injection, overlength labels, silent truncation, and unbounded memory allocation.

Netty 4.2.12.Final netty dns vulnerability cache-poisoning
2r 1t
high advisory

rmcp Streamable HTTP Server Transport DNS Rebinding Vulnerability

The `rmcp` crate before v1.4.0 is vulnerable to DNS rebinding attacks via the Streamable HTTP server transport due to missing Host header validation, potentially allowing arbitrary code execution on a victim's machine if they visit a malicious website.

rmcp dns-rebinding vulnerability http attack
2r 1t
high advisory

PraisonAI SSRF Vulnerability via URL Parsing Discrepancy

PraisonAI versions 1.6.31 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability due to inconsistent URL parsing between the application's validation logic and the underlying requests library, allowing attackers to bypass intended security checks and access internal resources.

praisonaiagents ssrf praisonai vulnerability
2r 1t
high advisory

OpenClaw Insufficient Environment Variable Denylist Vulnerability (CVE-2026-43584)

OpenClaw before 2026.4.10 is vulnerable to an insufficient environment variable denylist, allowing attackers to manipulate interpreter startup variables to influence execution behavior or network connectivity.

OpenClaw vulnerability environment-variable code-execution
3r 3t 1c
high advisory

OpenClaw Privilege Escalation Vulnerability (CVE-2026-43578)

OpenClaw versions before 2026.4.10 are vulnerable to privilege escalation due to improper handling of background async exec completion events, potentially allowing attackers to execute code with elevated privileges by providing untrusted completion content.

OpenClaw +1 privilege-escalation vulnerability
2r 1t 1c
high advisory

OpenClaw Incomplete Navigation Guard SSRF Bypass (CVE-2026-43580)

OpenClaw before version 2026.4.10 contains an incomplete navigation guard vulnerability, allowing attackers to trigger navigation without proper SSRF policy enforcement by bypassing post-action security checks via browser interactions like pressKey and type submit flows, potentially leading to unauthorized Server-Side Request Forgery (SSRF).

OpenClaw ssrf vulnerability web application
2r 1t 1c
high advisory

Cisco Releases Security Advisories for Multiple Products

Cisco released security advisories on May 6, 2026, addressing vulnerabilities including remote code execution, server-side request forgery, and denial of service in Crosswork Network Controller, IoT Field Network Director, Network Services Orchestrator, SG350/SG350X Managed Switches, and Unity Connection.

Crosswork Network Controller +5 cisco vulnerability denial-of-service remote-code-execution server-side-request-forgery
3r 3t
critical advisory

Vvveb Hardcoded Credentials Vulnerability in phpMyAdmin Container

Vvveb versions before 1.0.8.2 contain a hardcoded credentials vulnerability in the docker-compose-apache.yaml configuration, allowing unauthenticated attackers to access the phpMyAdmin container and gain unrestricted read and write access to the Vvveb database, leading to account takeover and data manipulation.

Vvveb +1 hardcoded-credentials phpmyadmin docker vulnerability
2r 1t 1c
high advisory

Vvveb CMS XML External Entity Injection Vulnerability

Vvveb before 1.0.8.2 is vulnerable to XML external entity (XXE) injection in the admin import feature, allowing authenticated site administrators to read arbitrary files and modify database records, potentially leading to privilege escalation.

Vvveb +1 xxe vulnerability injection
2r 3t 1c
high advisory

dssrf SSRF Protection Bypass via IPv6 Addresses

A vulnerability in the dssrf npm package allows attackers to bypass SSRF protections by using specially crafted IPv6 addresses, despite documentation claiming IPv6 is disabled, which can lead to internal resource access or other malicious activities.

dssrf ssrf vulnerability ipv6 defense-evasion
2r 12i
medium advisory

Samsung Mobile Devices Multiple Vulnerabilities

Samsung released a security update to address multiple vulnerabilities in Samsung mobile devices running versions prior to SMR-MAY-2026 Release 1, potentially allowing attackers to exploit these vulnerabilities for malicious purposes.

Samsung mobile devices mobile vulnerability patch samsung
2r
medium advisory

Mistune Markdown Parser Denial-of-Service Vulnerability

A denial-of-service vulnerability exists in Mistune version 3.2.0 due to excessive parsing and CPU consumption when processing specially crafted reference links, leading to application hangs and service unavailability.

mistune dos vulnerability
2r 1t
high advisory

Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities

Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code or conduct server-side request forgery (SSRF) attacks.

Unity Connection cisco rce ssrf vulnerability
2r 1t
medium advisory

Cisco Prime Infrastructure Information Disclosure Vulnerability

Cisco Prime Infrastructure is vulnerable to an information disclosure vulnerability, allowing authenticated remote attackers to download arbitrary log files due to insufficient authorization checks.

Prime Infrastructure information-disclosure vulnerability cisco
2r 3t
high advisory

Cisco IoT Field Network Director Multiple Vulnerabilities

Multiple vulnerabilities in Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial-of-service (DoS) conditions on managed routers.

IoT Field Network Director Software cisco iot vulnerability dos command-execution file-access
3r 4t
medium advisory

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information.

Identity Services Engine cisco authentication-bypass vulnerability
2r 1t
medium advisory

Broadcom Patches Vulnerabilities in Tanzu GemFire Management Console

Broadcom released a security advisory addressing vulnerabilities in Tanzu GemFire Management Console versions prior to 1.4.4, prompting users to apply necessary updates to mitigate potential risks.

Tanzu GemFire Management Console < 1.4.4 vulnerability broadcom tanzu
2r 1t
critical advisory

Vulnerabilities in Unitree Embodied AI Systems

Commercially available Unitree robots are susceptible to multiple vulnerabilities, including hardcoded keys and command injection, allowing attackers to gain root-level access, exfiltrate data, and potentially create physical botnets.

Go1 +8 embodied-ai robot iot vulnerability data-exfiltration
3r 7t 1c 1i
high advisory

ssrfcheck vulnerable to SSRF via IPv4-mapped IPv6 bypass

ssrfcheck version 1.3.0 and earlier is vulnerable to server-side request forgery (SSRF) attacks because it fails to block private IP addresses encoded as IPv4-mapped IPv6 addresses due to WHATWG URL parsing.

ssrfcheck ssrf vulnerability node.js
2r 1t
medium advisory

Dell Security Advisories Address Multiple Vulnerabilities

Dell published security advisories addressing vulnerabilities in APEX Cloud Platform, Automation Platform, Command | Monitor, CyberSense, NativeEdge Orchestrator, SmartFabric Manager, iDRAC, Disk Library, and PowerProtect Cyber Recovery, requiring users to apply necessary updates.

APEX Cloud Platform for Red Hat OpenShift +9 vulnerability patch dell
2r
medium advisory

CISA ICS Advisories Addressing ABB and NSA Products

CISA published ICS advisories addressing vulnerabilities in multiple ABB products including AWIN Gateways, Ability OPTIMAX, Symphony Plus Engineering, Edgenius Management Portal, PCM600, System 800xA, Symphony Plus IEC 61850, and NSA GRASSMARLIN, prompting users to apply mitigations and updates.

AWIN Gateways +7 ics vulnerability abb nsa ot
2r
high advisory

awslabs/tough Delegated Roles Signature Threshold Bypass

An improper verification of cryptographic signature uniqueness vulnerability in awslabs/tough before v0.22.0 allows remote authenticated users to bypass TUF signature threshold requirements by duplicating a valid signature, leading to the acceptance of forged delegated role metadata.

tough +1 supply-chain vulnerability rust
2r 1t 1i
high advisory

Multiple Vulnerabilities in Apache Wicket

Multiple vulnerabilities in Apache Wicket could allow an attacker to bypass security measures, perform Cross-Site Scripting (XSS) attacks, disclose confidential information, or manipulate data.

Wicket apache-wicket xss vulnerability
2r 2t
medium advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Multiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to perform a denial-of-service attack or disclose sensitive information.

Velociraptor vulnerability denial-of-service information-disclosure
2r 2t
high advisory

Red Hat Hardened Images RPMs Fontconfig Vulnerability

A local attacker can exploit a vulnerability in Red Hat Hardened Images RPMs to execute arbitrary code or cause a denial of service.

Hardened Images RPMs vulnerability code-execution denial-of-service linux
2r 2t
high advisory

ProFTPD Vulnerability Allows SQL Injection

A remote, anonymous attacker can exploit a SQL injection vulnerability in ProFTPD, potentially leading to unauthorized data access or modification.

ProFTPD sql-injection vulnerability linux
2r 1t
high advisory

Multiple Vulnerabilities in Vaultwarden

Multiple vulnerabilities in Vaultwarden could be exploited by an attacker to bypass security measures, conduct a denial-of-service attack, and disclose information, potentially leading to unauthorized access and service disruption.

Vaultwarden vulnerability denial-of-service information-disclosure security-bypass
2r 3t
high advisory

Multiple Vulnerabilities in Red Hat Hardened Images RPMs

Multiple vulnerabilities in Red Hat Hardened Images RPMs can be exploited by an attacker to bypass security measures, escalate privileges, disclose sensitive information, manipulate data, or cause a denial-of-service condition.

Hardened Images RPMs vulnerability redhat rpm privilege-escalation defense-evasion information-disclosure manipulation denial-of-service
2r 5t
critical advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux and Satellite

Multiple vulnerabilities in Red Hat Enterprise Linux and Red Hat Satellite could allow a remote, anonymous attacker to disclose information or execute arbitrary code.

Red Hat Enterprise Linux +1 redhat rhel satellite vulnerability code-execution
2r 2t
high advisory

tigervnc Vulnerability Allows Information Disclosure, File Manipulation, and Denial of Service

A local attacker can exploit a vulnerability in tigervnc to disclose information, manipulate files, and perform a denial of service attack.

tigervnc vulnerability denial of service information disclosure
2r 3t
medium advisory

Multiple Vulnerabilities in OpenSSL Allow for DoS, Information Disclosure, and Ciphertext Recovery

Multiple vulnerabilities in OpenSSL can be exploited by a remote attacker to conduct a denial-of-service attack, disclose information, or recover ciphertext over a network.

OpenSSL vulnerability denial-of-service information-disclosure ciphertext-recovery
2r 2t
medium advisory

Microsoft Releases Security Update for CVE-2026-43964

Microsoft has released a security update to address the vulnerability CVE-2026-43964.

vulnerability patch
2r 1c
medium advisory

Multiple Vulnerabilities in Zabbix

Multiple vulnerabilities in Zabbix versions 6.0.x before 6.0.45, 7.0.x before 7.0.24, and 7.4.x before 7.4.8 allow for data confidentiality breaches and remote cross-site scripting (XSS) attacks.

Zabbix < 6.0.45 +2 zabbix xss vulnerability
2r 1t 3c
critical advisory

Multiple Vulnerabilities in Redis Allow Remote Code Execution

Multiple vulnerabilities in Redis could allow an attacker to execute arbitrary code remotely, potentially leading to complete system compromise.

Redis rce vulnerability
2r 1t 3c
medium advisory

Multiple Unspecified Vulnerabilities in Google Chrome

Multiple unspecified vulnerabilities in Google Chrome prior to version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac could allow an attacker to cause an unspecified security issue.

Chrome +1 vulnerability browser
2r
high advisory

JupyterHub Extension Manager API/GUI Policy Discrepancy Allows Malicious Extension Installation

JupyterLab versions prior to 4.5.7 do not correctly enforce the allow-list of extensions that can be installed from PyPI Extension Manager, allowing authenticated attackers to escalate privileges and potentially exfiltrate data, move laterally, and persistently compromise server infrastructure.

JupyterHub +2 jupyterlab privilege-escalation vulnerability extension-manager
2r 1t
critical advisory

Open-WebSearch SSRF Vulnerability in fetchWebContent Tool

Open-WebSearch has a Server-Side Request Forgery (SSRF) vulnerability in the `fetchWebContent` MCP tool due to improper validation of IPv6 literals and lack of DNS resolution, allowing attackers to fetch arbitrary private-network URLs and receive the response body.

open-webSearch ssrf vulnerability
2r 1t 1i
high advisory

ssrfcheck SSRF Bypass Vulnerability

The `ssrfcheck` npm package is vulnerable to SSRF bypass due to an incomplete denylist of IP addresses. The package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as invalid, allowing potential SSRF attacks. All versions up to and including 1.1.1 are affected. A patch has been released in version 1.2.0.

ssrfcheck ssrf vulnerability npm
2r 1t 1c
high advisory

awslabs/tough Missing Delegated Metadata Validation

The tough library before version 0.22.0 and tuftool before version 0.15.0 do not properly verify delegated target metadata, allowing an attacker with write access to serve expired or otherwise invalid targets from a TUF repository, potentially leading to the library trusting invalid targets.

tough +1 supply-chain vulnerability metadata-poisoning
2r 1t 1c 1i
high advisory

OpenClaw Gateway Configuration Mutation Vulnerability

A vulnerability in OpenClaw versions before 2026.4.23 allows a compromised model with access to the `gateway` tool to persist unsafe config changes that cross security boundaries due to an insufficient denylist.

openclaw config-mutation vulnerability
2r 1t
critical advisory

Langflow Knowledge Bases API Path Traversal Vulnerability

A path traversal vulnerability exists in the Langflow Knowledge Bases API (`DELETE /api/v1/knowledge_bases`) that allows an authenticated attacker to delete arbitrary directories on the server's filesystem, leading to data loss and potential service disruption.

langflow path-traversal vulnerability
2r 1t
medium advisory

graphql-php OverlappingFieldsCanBeMerged Quadratic Complexity Vulnerability

The `OverlappingFieldsCanBeMerged` validation rule in `webonyx/graphql-php` has an `O(n^2 x m^2)` worst-case complexity due to flattened inline fragments, leading to potential resource exhaustion.

graphql-php graphql php resource-exhaustion vulnerability
2r 1t 1c
high advisory

OpenClaw Weakened Exec Approval Binding Vulnerability

OpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution, allowing attackers to obscure which applet would run, bypass exec approval mechanisms, and weaken risk classification of unsafe applet invocations.

OpenClaw vulnerability exec-bypass
2r 2t 1c
high advisory

OpenClaw Sandbox Media Normalization Bypass via Discord Event Cover Image

OpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing, allowing attackers to bypass media normalization and inject host-local media references into channel action paths expecting normalized media.

OpenClaw vulnerability normalization bypass sandbox escape
2r 1t 1c
high advisory

OpenClaw Sender Policy Bypass Vulnerability Leading to Local File Disclosure

OpenClaw versions prior to 2026.4.10 are vulnerable to a sender policy bypass, allowing attackers with restricted read access to disclose local files by triggering host-media attachment loading, bypassing authorization boundaries.

OpenClaw vulnerability file-disclosure privilege-escalation
2r 2t 1c
high advisory

OpenClaw Shell Wrapper Detection Bypass via Environment Variable Injection

OpenClaw versions before 2026.4.12 are vulnerable to environment variable injection, allowing attackers to bypass shell wrapper detection and manipulate execution semantics by modifying shell variables.

OpenClaw cve vulnerability injection
2r 1t 1c
high advisory

Dell Computer Vulnerability Allows Local Code Execution

A local attacker can exploit a vulnerability in Dell computers to execute arbitrary code.

Dell Computer local-code-execution vulnerability dell
2r 1t
critical threat

Multiple Vulnerabilities in Apache HTTP Server

Multiple vulnerabilities in Apache HTTP Server can be exploited by an attacker to gain elevated privileges, execute arbitrary code, bypass security measures, disclose sensitive information, or cause a denial-of-service condition.

HTTP Server apache vulnerability privilege-escalation execution defense-evasion information-disclosure denial-of-service
2r 6t
critical threat

Red Hat Enterprise Linux freeipmi Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux freeipmi to cause a denial of service condition or memory corruption, potentially allowing arbitrary code execution.

Enterprise Linux rhel freeipmi vulnerability code-execution dos
2r 4t
high threat

Multiple Vulnerabilities in Prometheus Allow for DoS, Information Disclosure, and XSS

Multiple vulnerabilities in Prometheus could allow an attacker to perform a Denial of Service attack, disclose sensitive information, or execute Cross-Site Scripting attacks.

Prometheus vulnerability denial-of-service information-disclosure cross-site-scripting
2r 2t
medium advisory

Microsoft Product Vulnerability CVE-2026-37457

CVE-2026-37457 is a vulnerability affecting a Microsoft product, for which details are currently unavailable.

vulnerability microsoft
2r 1c
high advisory

Path Traversal Vulnerability in UsamaK98 python-notebook-mcp

A path traversal vulnerability exists in the create_notebook/read_notebook/edit_cell/add_cell functions of server.py in UsamaK98's python-notebook-mcp, allowing remote attackers to access arbitrary files.

python-notebook-mcp path traversal vulnerability
3r 1t 1c
high advisory

Axle-Bucamp MCP-Docusaurus Path Traversal Vulnerability

A path traversal vulnerability exists in Axle-Bucamp MCP-Docusaurus versions up to commit 404bc028e15ec304c9a045528560f4b5f27a17e0, allowing remote attackers to access sensitive files by manipulating the DOCS_DIR/path argument in specific functions.

MCP-Docusaurus path-traversal vulnerability web-application
2r 1t 1c
high advisory

Traefik Data Confidentiality Vulnerability

A vulnerability in Traefik allows an attacker to compromise the confidentiality of data, affecting versions v2.11.x prior to v2.11.44, v3.6.x prior to v3.6.15, and v3.7.0-rc.x prior to v3.7.0-rc.3.

Traefik vulnerability data-disclosure
2r 1t
high advisory

Multiple Vulnerabilities in PaperCut Allow Data Confidentiality Breach and Security Policy Bypass

Multiple vulnerabilities in PaperCut Embedded App versions prior to 2.2.0 on Ricoh devices and PaperCut NG/MF versions prior to 25.0.11 allow attackers to compromise data confidentiality and bypass security policies, potentially leading to unauthorized access and control.

PaperCut Embedded App +1 vulnerability papercut data-breach security-bypass
2r 2t 3c
critical advisory

Multiple Vulnerabilities in Apache HTTP Server Allow Remote Code Execution, Privilege Escalation, and Denial of Service

Multiple vulnerabilities in Apache HTTP Server versions prior to 2.4.67 can allow remote attackers to execute arbitrary code, escalate privileges, or cause a denial of service.

HTTP Server apache http vulnerability rce privilege-escalation dos
3r 3t 5c
critical advisory

Google Android Remote Code Execution Vulnerability

A vulnerability in Google Android allows a remote attacker to execute arbitrary code, affecting versions prior to 14, 15, 16 and 16-qpr2 before the May 4, 2026 patch.

Android rce vulnerability
2r 1t 1c
critical advisory

Arelle Unauthenticated Remote Code Execution Vulnerability

Arelle before 2.39.10 is vulnerable to unauthenticated remote code execution via the /rest/configure REST endpoint, allowing attackers to execute arbitrary Python code by supplying a malicious URL through the plugins parameter.

Arelle rce vulnerability
2r 1t 1c
high advisory

WordPress Easy PayPal Events & Tickets Plugin Authentication Bypass Vulnerability

An unauthenticated remote attacker can exploit a hardcoded authentication bypass vulnerability in the Easy PayPal Events & Tickets plugin for WordPress (versions 1.3 and earlier) by providing 'test' as the hash parameter, allowing retrieval of sensitive order details.

Easy PayPal Events & Tickets plugin wordpress authentication bypass vulnerability
2r 1t 1c 1i
critical advisory

WHM, cPanel, and WP Squared Vulnerability Allows Remote Code Execution

A vulnerability exists in WHM, cPanel, and WP Squared, Linux-based web hosting control panels, which could allow for remote code execution by bypassing authentication and gaining administrative access.

cPanel +2 vulnerability rce whm wp squared linux
2r 1t
high advisory

Norton Secure VPN Privilege Escalation Vulnerability (CVE-2025-58074)

A privilege escalation vulnerability exists in Norton Secure VPN during installation via the Microsoft Store (CVE-2025-58074), allowing a low-privilege user to replace files leading to arbitrary file deletion and potential elevation of privileges.

Norton Secure VPN privilege-escalation windows vulnerability
2r 1t 1c
critical advisory

Multiple Vulnerabilities in FreeBSD

FreeBSD published security advisories addressing multiple vulnerabilities including remote code execution, local privilege escalation, heap overflow, and stack overflow, affecting all supported versions.

FreeBSD vulnerability rce privilege-escalation
2r 2t 4c
medium advisory

libexif Vulnerability Allows Code Execution

A local attacker can exploit a vulnerability in libexif to potentially execute arbitrary code, cause a denial of service, or disclose sensitive information.

libexif vulnerability code-execution denial-of-service
2r 2t
medium advisory

Multiple Vulnerabilities in Rapid7 Velociraptor

Multiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to disclose information or cause a denial of service.

Velociraptor vulnerability denial-of-service information-disclosure
2r 3t
medium advisory

osrg GoBGP Integer Underflow Vulnerability

osrg GoBGP up to version 4.3.0 is vulnerable to an integer underflow in the parseRibEntry function, potentially allowing a remote attacker to cause a denial of service or other unspecified impacts; version 4.4.0 addresses this issue.

GoBGP cve vulnerability integer underflow bgp
2r 1t 1c
critical advisory

Multiple Vulnerabilities in Mozilla Thunderbird Allow for Remote Code Execution and Data Breach

Multiple vulnerabilities in Mozilla Thunderbird prior to versions 150.0.1 and Thunderbird ESR prior to 140.10.1 could allow a remote attacker to achieve arbitrary code execution, data confidentiality breach, and security policy bypass.

Thunderbird ESR +1 vulnerability rce databreach securitybypass
2r 4t 5c
medium advisory

Microsoft Product Vulnerability CVE-2026-37555

CVE-2026-37555 is a vulnerability affecting a Microsoft product, requiring further investigation upon patch release.

vulnerability microsoft cve-2026-37555
2r 1c
low advisory

Microsoft CVE-2026-30656 Information Published

Microsoft published information regarding CVE-2026-30656, but the details of the vulnerability are not available.

vulnerability microsoft
1c
high advisory

code-projects Online Hospital Management System SQL Injection Vulnerability

CVE-2026-7632 is a SQL injection vulnerability in code-projects Online Hospital Management System 1.0, allowing a remote attacker to execute arbitrary SQL commands by manipulating the 'delid' argument in the '/viewappointment.php' file.

Online Hospital Management System 1.0 sql-injection web-application vulnerability
2r 1t 1c
high advisory

Paid Memberships Pro Plugin Vulnerability Allows Unauthorized Stripe Webhook Modification

The Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification of Stripe webhook configurations due to missing capability checks, allowing authenticated attackers with Subscriber-level access to disrupt payment processing.

Paid Memberships Pro plugin wordpress stripe webhook vulnerability plugin
2r 3t 1c
high advisory

Zyosoft School App Insecure Direct Object Reference Vulnerability

Zyosoft's School App contains an Insecure Direct Object Reference vulnerability (CVE-2026-7491) that allows authenticated remote attackers to modify parameters and access or modify other users' data.

School App idor vulnerability web application cve-2026-7491
2r 3t 1c
high advisory

Flux159 mcp-game-asset-gen Path Traversal Vulnerability

A path traversal vulnerability exists in Flux159 mcp-game-asset-gen version 0.1.0, where manipulation of the `statusFile` argument in the `image_to_3d_async` function allows for remote exploitation.

mcp-game-asset-gen 0.1.0 path-traversal vulnerability web-application
2r 1t 1c
medium advisory

JetBrains IntelliJ IDEA Vulnerability

A vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1 and 2026.1.1, requiring users to update to the latest versions.

IntelliJ IDEA vulnerability jetbrains intellij-idea
2r
medium advisory

Microsoft Edge Stable Channel Vulnerabilities Addressed in April 2026 Update

Microsoft addressed vulnerabilities in Microsoft Edge Stable Channel versions prior to 147.0.3912.98 with a security update released on April 30, 2026, requiring users to update to the latest version.

Microsoft Edge Stable Channel vulnerability browser patch
2r
high advisory

WP Editor Plugin CSRF Vulnerability

The WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 1.2.9.2, allowing unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with malicious code by tricking a site administrator into clicking a link.

WP Editor plugin <= 1.2.9.2 csrf wordpress plugin vulnerability
2r 1t 1c
medium advisory

Microsoft Product Vulnerability CVE-2026-41526

CVE-2026-41526 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon patch release for exploitation details.

vulnerability microsoft
1c
critical advisory

Chromium Use-After-Free Vulnerability in Codecs (CVE-2026-7348)

CVE-2026-7348 is a use-after-free vulnerability in the Codecs component of Chromium, affecting Google Chrome and Microsoft Edge.

Chrome +1 use-after-free vulnerability browser
2r 1t 1c
high advisory

SourceCodester Advanced School Management System SQL Injection Vulnerability

A SQL injection vulnerability (CVE-2026-7545) exists in SourceCodester Advanced School Management System 1.0 within the checkEmail endpoint of commonController.php, allowing remote attackers to potentially execute arbitrary SQL commands.

Advanced School Management System 1.0 sqli vulnerability web-application
2r 1t 1c
critical advisory

HKUDS OpenHarness Remote Code Execution via /bridge Slash Command (CVE-2026-7551)

HKUDS OpenHarness contains a remote code execution vulnerability (CVE-2026-7551) in the /bridge slash command, allowing remote attackers to execute arbitrary operating system commands by injecting malicious commands via the /bridge spawn command, leading to unauthorized shell access and data exposure.

OpenHarness rce vulnerability injection
2r 1t 1c
critical advisory

IBM Turbonomic prometurbo Agent Privilege Escalation via Excessive Permissions (CVE-2026-6389)

IBM Turbonomic prometurbo agent versions 8.16.0 through 8.17.6 grants excessive cluster-wide permissions, including unrestricted read access to all secrets, allowing a compromised operator or service account to exfiltrate credentials, escalate privileges, and achieve full cluster compromise.

Turbonomic Application Resource Management +1 privilege-escalation credential-access kubernetes vulnerability
2r 2t 1c
medium advisory

IBM Langflow Desktop Unauthenticated Image Access via IDOR

IBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an indirect object reference (IDOR) vulnerability (CVE-2026-4503), allowing unauthenticated users to view other users' images due to a user-controlled key.

Langflow Desktop idor vulnerability privilege-escalation
2r 1t 1c
medium advisory

Sentry SAML SSO Improper Authentication Allows User Identity Linking

A critical vulnerability (CVE-2026-42354) exists in Sentry's SAML SSO implementation that allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance, affecting self-hosted users with multiple organizations configured if a malicious user has permissions to modify SSO settings, while Sentry SaaS was patched in April and self-hosted users are advised to upgrade to version 26.4.1 or higher.

sentry +1 authentication saml sso account takeover vulnerability
2r 1t
medium advisory

HPE Security Advisory for Telco Service Orchestrator and Activator

HPE released a security advisory addressing multiple vulnerabilities in HPE Telco Service Orchestrator (versions prior to v5.6.0) and HPE Telco Service Activator (versions 10.5.0 and prior), urging users to apply necessary updates.

HPE Telco Service Orchestrator +1 vulnerability hpe telco
2r
high advisory

Jupyter Notebook Authentication Token Theft via CommandLinker XSS

A stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook versions 7.0.0 through 7.5.5 and JupyterLab versions up to 4.5.6 allows attackers to steal authentication tokens by tricking users into interacting with malicious notebook files, leading to complete account takeover via the Jupyter REST API.

@jupyter-notebook/help-extension +4 xss jupyter authentication account-takeover vulnerability
2r
high advisory

Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket

This rule detects potential exploitation of CVE-2026-31431, a Copy Fail vulnerability in the Linux kernel, via AF_ALG socket abuse, by correlating non-root AF_ALG-class socket or splice events with a subsequent process execution where the effective user is root but the login user remains non-root, indicating a privilege escalation attempt.

Auditbeat +1 privilege-escalation linux vulnerability cve-2026-31431
2r 2t 1c
medium advisory

GNU InetUtils Vulnerabilities Prior to 2.8

GNU released a security advisory addressing critical vulnerabilities in GNU InetUtils versions prior to 2.8, prompting users to apply necessary updates.

InetUtils vulnerability gnu
2r
critical threat

Local Privilege Escalation Vulnerability 'Copy Fail' in Linux Kernel

A local privilege escalation vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), affects Linux kernels released since 2017, allowing an unprivileged local attacker to gain root permissions by exploiting a logic bug in the authencesn cryptographic template.

Linux kernel +4 Theori privilege-escalation linux vulnerability
2r 1t 1c
critical threat

Critical Authentication Bypass Vulnerability in cPanel & WHM (CVE-2026-41940)

CVE-2026-41940 is a critical authentication bypass vulnerability in cPanel & WHM, allowing unauthenticated remote attackers to gain administrative access by manipulating session data.

exploited cPanel & WHM authentication bypass cPanel web hosting vulnerability
2r 1t 1c
high advisory

ABB AWIN Gateway Vulnerabilities Allow Remote Reboot and Information Disclosure

Multiple vulnerabilities in ABB AWIN Gateways allow an unauthenticated attacker to remotely reboot the device (CVE-2025-13778) or disclose sensitive system configuration details (CVE-2025-13777, CVE-2025-13779).

ABB AWIN Firmware +3 ics vulnerability industrial_control_systems
3r 1t 3c
critical advisory

ABB Ability Symphony Plus Engineering Vulnerabilities Allow Remote Code Execution

Multiple vulnerabilities in ABB Ability Symphony Plus Engineering, stemming from underlying PostgreSQL flaws, could allow a remote attacker with network access to execute arbitrary code and compromise the system.

ABB Ability Symphony Plus S+ Engineering 2.2 +7 vulnerability ics postgresql
2r 3t 3c
high advisory

ABB Ability OPTIMAX Authentication Bypass Vulnerability

CVE-2025-14510 allows an attacker to bypass Azure Active Directory Single-Sign On authentication in vulnerable ABB Ability OPTIMAX versions, potentially granting unauthorized access to critical infrastructure systems.

OPTIMAX 6.1 +4 authentication bypass ics vulnerability
2r 1t 1c
high advisory

Multiple Vulnerabilities in Absolute Secure Access

Multiple vulnerabilities in Absolute Secure Access could allow an attacker to escalate privileges, conduct a denial-of-service attack, and disclose sensitive information.

Secure Access vulnerability privilege-escalation denial-of-service information-disclosure
2r 3t 1c
high threat

Multiple Vulnerabilities in SonicWall SonicOS Allow Privilege Escalation and DoS

Multiple vulnerabilities in SonicWall SonicOS allow a remote attacker to escalate privileges, bypass security measures, or cause a denial-of-service condition.

exploited SonicOS sonicwall vulnerability privilege-escalation denial-of-service
2r 3t 3c
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Fast Datapath

A remote, anonymous attacker can exploit multiple vulnerabilities in Fast Datapath for Red Hat Enterprise Linux to perform a denial-of-service attack or disclose sensitive information.

Fast Datapath redhat vulnerability denial-of-service
2r 4t
medium advisory

libsndfile Vulnerability Allows Denial of Service

A remote, unauthenticated attacker can exploit an unpatched vulnerability in libsndfile to cause a denial of service.

libsndfile denial-of-service vulnerability
2r 1t
critical advisory

Multiple Vulnerabilities in CUPS

Multiple vulnerabilities in CUPS allow an attacker to bypass security measures, execute arbitrary code, escalate privileges, manipulate data, or cause a denial-of-service condition.

CUPS vulnerability privilege-escalation execution denial-of-service
2r 4t 1c
high advisory

Multiple Vulnerabilities in Xen and Citrix Systems XenServer

Multiple vulnerabilities exist in Xen and Citrix Systems XenServer that could allow an attacker to escalate privileges, bypass security measures, modify and disclose data, or cause a denial-of-service condition.

XenServer +1 vulnerability privilege-escalation denial-of-service information-disclosure
3r 7t
critical advisory

Multiple Vulnerabilities in Wazuh Allow for Code Execution and Data Manipulation

Multiple vulnerabilities in Wazuh allow an attacker to perform a denial of service attack, execute arbitrary code, manipulate data, disclose confidential information, or bypass security measures.

Wazuh vulnerability siem xdr
2r 6t 5c
medium advisory

DNSdist Multiple Vulnerabilities Leading to Denial of Service

Multiple vulnerabilities in DNSdist can be exploited by an attacker to perform a denial of service attack, impacting the availability of DNS services.

DNSdist denial-of-service vulnerability
2r 1t 1c
info advisory

Microsoft Published Information on CVE-2026-32777

Microsoft has published information regarding CVE-2026-32777, but no further details regarding the vulnerability or its exploitation are currently available.

cve-2026-32777 vulnerability
1c
medium advisory

Microsoft Published Information on CVE-2026-32776

Microsoft published information regarding CVE-2026-32776, however, further details require JavaScript to be enabled, limiting the actionable intelligence at this time.

cve vulnerability
1c
medium advisory

Microsoft CVE-2026-32778 Vulnerability Published

Microsoft published information regarding vulnerability CVE-2026-32778, but no details regarding the vulnerability are available at this time.

cve vulnerability
2r 1c
medium advisory

1024-lab smart-admin Improper Access Control Vulnerability (CVE-2026-7468)

CVE-2026-7468 is an improper access control vulnerability in 1024-lab smart-admin up to version 3.30.0, affecting the /smart-admin-api/druid/index.html file, which can be exploited remotely.

smart-admin access-control vulnerability web-application
2r 1t 1c
high advisory

VetCoders mcp-server-semgrep OS Command Injection Vulnerability

VetCoders mcp-server-semgrep version 1.0.0 is vulnerable to remote OS command injection due to manipulation of the ID argument in several functions of the MCP Interface component.

mcp-server-semgrep 1.0.0 command-injection vulnerability mcp-server-semgrep
2r 1t 1c
medium advisory

Netgate pfSense XSS Vulnerability

A cross-site scripting (XSS) vulnerability affects Netgate pfSense CE (<= 2.8.1) and pfSense Plus (<= 26.03), potentially allowing attackers to inject malicious code.

pfSense CE +1 xss vulnerability pfSense
2r
high advisory

Multiple Vulnerabilities in Wireshark Lead to Remote Code Execution and Denial of Service

Multiple vulnerabilities in Wireshark versions 4.4.x before 4.4.15 and 4.6.x before 4.6.5 could allow remote attackers to execute arbitrary code, cause a denial of service, or compromise data confidentiality.

Wireshark 4.4.x +1 wireshark vulnerability rce dos
2r
critical advisory

Multiple Vulnerabilities in Red Hat Linux Kernel

Multiple vulnerabilities in the Red Hat Linux kernel allow for arbitrary code execution, privilege escalation, and remote denial of service.

Red Hat CodeReady Linux Builder +1 vulnerability kernel redhat execution privilege-escalation denial-of-service
2r 3t 5c
high advisory

Multiple Vulnerabilities in MISP Threat Intelligence Platform

Multiple vulnerabilities in MISP versions prior to 2.5.37 allow attackers to perform privilege escalation, SQL injection (SQLi), and security policy bypass.

MISP < 2.5.37 misp vulnerability sqli privilege-escalation security-policy-bypass
2r 1t
high advisory

Multiple Vulnerabilities in Exim Mail Transfer Agent

Multiple vulnerabilities in Exim versions prior to 4.99.2 allow an attacker to cause a remote denial of service, a breach of data confidentiality, and an unspecified security problem.

Exim vulnerability denial-of-service information-disclosure
3r 3t
critical advisory

PolarVista xcode-mcp-server OS Command Injection Vulnerability

PolarVista xcode-mcp-server 1.0.0 is vulnerable to remote OS command injection via manipulation of the Request argument in the `build_project/run_tests` function, allowing attackers to execute arbitrary commands on the server.

xcode-mcp-server 1.0.0 command-injection vulnerability xcode-mcp-server
2r 1t 1c
high advisory

n8n Python Task Runner Sandbox Escape Vulnerability

A sandbox escape vulnerability exists in n8n's Python Task Runner that allows an authenticated user with workflow creation/modification permissions to achieve arbitrary code execution on the task runner container, impacting n8n instances with the Python Task Runner enabled; upgrade to versions 1.123.32, 2.17.4, 2.18.1 or later to remediate the vulnerability.

n8n sandbox-escape code-execution vulnerability
2r 2t
high advisory

SysGauge Pro 4.6.12 Local Buffer Overflow Vulnerability (CVE-2018-25307)

SysGauge Pro 4.6.12 is vulnerable to a local buffer overflow in the Register function, allowing local attackers to overwrite the structured exception handler and execute arbitrary code by supplying a crafted unlock key during registration.

SysGauge Pro 4.6.12 vulnerability buffer_overflow privilege_escalation
2r 2t 1c
high advisory

SonicWall Firewall Vulnerabilities Addressed in Security Advisory AV26-405

SonicWall released a security advisory to address vulnerabilities in Gen6, Gen7, and Gen8 firewalls and SonicOS, urging users to update affected firmware versions to mitigate potential exploits.

Gen6 Hardware Firewalls +4 firewall vulnerability sonicwall
2r
high advisory

Path Traversal Vulnerability in mail-mcp-bridge

A path traversal vulnerability exists in fatbobman mail-mcp-bridge version 1.3.3 and earlier, allowing a remote attacker to read arbitrary files by manipulating the message_ids argument in the src/mail_mcp_server.py file.

mail-mcp-bridge path-traversal vulnerability web-application
2r 1t 1c
medium advisory

Jenkins Security Advisory Addressing Multiple Plugin Vulnerabilities

Jenkins released a security advisory on April 29, 2026, detailing vulnerabilities in Credentials Binding Plugin, GitHub Plugin, GitHub Branch Source Plugin, HTML Publisher Plugin, Matrix Authorization Strategy Plugin, Microsoft Entra ID Plugin, and Script Security Plugin, urging users to apply necessary updates.

Credentials Binding Plugin +6 jenkins vulnerability plugin
2r
high advisory

Zyxel Command Injection Vulnerabilities in CPE and Extenders

Zyxel released a security advisory on April 28, 2026, addressing command injection vulnerabilities across multiple versions of their 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and Wireless Extender products, potentially allowing attackers to execute arbitrary commands.

4G LTE/5G NR CPE +3 command injection network device vulnerability
2r 1t
medium advisory

SmarterTools SmarterMail Vulnerability Prior to Build 9610

SmarterTools released a security advisory addressing a vulnerability in SmarterMail versions prior to Build 9610, prompting users to update their software.

SmarterMail vulnerability mail-server
2r
high advisory

OpenClaw StrictInlineEval Approval Bypass Vulnerability (CVE-2026-42423)

OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that allows attackers to bypass strictInlineEval explicit-approval requirements on gateway and node exec hosts, leading to arbitrary command execution.

OpenClaw vulnerability privilege-escalation execution
2r 1t 1c
high advisory

OpenClaw Plugin Archive Integrity Vulnerability (CVE-2026-42428)

OpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives, allowing attackers to install malicious plugins and compromise the local assistant environment.

OpenClaw vulnerability plugin integrity CVE-2026-42428
2r 1t 1c
high advisory

OpenClaw Incomplete Host Environment Variable Sanitization Vulnerability (CVE-2026-41387)

OpenClaw before 2026.3.22 is vulnerable to incomplete host environment variable sanitization, allowing attackers to redirect package resolution or runtime bootstrap to attacker-controlled infrastructure and execute trojanized content.

OpenClaw vulnerability supply-chain environment-variable
2r 1t 1c
medium threat

Notepad++ Vulnerability in Version 8.9.3 and Prior

A vulnerability exists in Notepad++ version 8.9.3 and prior, prompting a security advisory and the release of version 8.9.4 to address the issue.

exploited Notepad++ 8.9.3 vulnerability notepad++ patch
2r 1t
critical advisory

Multiple Vulnerabilities in Spring Boot Allow Authorization Bypass and Potential RCE

Multiple vulnerabilities in Spring Boot, including CVE-2026-40976, CVE-2026-40973, and CVE-2026-40972, can allow attackers to bypass authorization, hijack sessions, or achieve remote code execution, potentially leading to data breaches and system compromise.

Spring Boot spring-boot vulnerability rce authentication-bypass session-hijacking
2r 3t 3c
medium advisory

Mozilla Firefox Multiple Vulnerabilities

Mozilla released a security advisory addressing vulnerabilities in Firefox and Firefox ESR versions prior to 150.0.1, 140.10.1, and 115.35.1, potentially leading to arbitrary code execution or information disclosure.

Firefox +1 vulnerability mozilla
2r 3t
medium threat

Citrix XenServer Vulnerabilities Addressed in Security Advisory AV26-400

Citrix released security advisory AV26-400 on April 28, 2026, addressing vulnerabilities in XenServer versions prior to 8.4, prompting users to apply mitigations.

XenServer virtualization vulnerability
2r 1t
medium advisory

Google Chrome Security Update Released

Google released a security advisory to address vulnerabilities in Chrome for Desktop versions prior to 147.0.7727.137/138 on Windows/Mac and 147.0.7727.137 on Linux, prompting users to apply necessary updates.

Chrome browser vulnerability update
2r
high advisory

Multiple Vulnerabilities in cURL

Multiple vulnerabilities in cURL could allow an attacker to bypass security measures, disclose confidential information, or manipulate data.

cURL vulnerability
2r 3t 4c
medium advisory

Multiple Vulnerabilities in GNU libc

A remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary program code, cause a denial-of-service condition, or disclose sensitive information.

libc vulnerability glibc denial-of-service code-execution
2r 3t 5c
high advisory

Red Hat Enterprise Linux LibRaw Multiple Vulnerabilities Allow Code Execution or DoS

Multiple vulnerabilities in Red Hat Enterprise Linux's LibRaw component allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

Enterprise Linux vulnerability code-execution denial-of-service linux
2r 2t
medium advisory

CoreDNS DoQ Server Denial-of-Service Vulnerability

CoreDNS' DNS-over-QUIC (DoQ) server can be driven into large goroutine and memory growth by a remote client that opens many QUIC streams and stalls after sending only 1 byte, leading to denial of service in versions before 1.14.3.

coredns dos denial-of-service vulnerability
2r 3t 1c
high advisory

OpenClaw Improper Authorization Vulnerability (CVE-2026-42426)

OpenClaw before 2026.4.8 contains an improper authorization vulnerability (CVE-2026-42426) allowing attackers with `operator.write` permissions to bypass node pairing approval and gain unauthorized access to `exec`-capable nodes by exploiting the `node.pair.approve` method which incorrectly accepts the `operator.write` scope instead of the narrower `operator.pairing` scope.

OpenClaw privilege-escalation vulnerability
2r 1t 1c
high advisory

Spring AI Vulnerabilities CVE-2026-40967 and CVE-2026-40978

Spring released security advisories on April 27, 2026, to address a VectorStore FilterExpression Converter injection vulnerability (CVE-2026-40967) and a SQL Injection vulnerability (CVE-2026-40978) in Spring AI versions prior to 1.0.6 and 1.1.5.

Spring AI +1 vulnerability sql-injection code-injection spring-ai
2r 1t 2c
high threat

Broadcom Addresses Critical Vulnerabilities in VMware Tanzu Products

Broadcom released a security advisory addressing critical vulnerabilities in VMware Tanzu Data Lake (versions prior to 4.0.0) and VMware Tanzu Greenplum Platform Extension Framework (versions prior to 8.0.0), requiring immediate patching to prevent potential exploitation.

exploited Tanzu Data Lake +1 vmware tanzu vulnerability
2r
critical advisory

VMware Tanzu Spring Boot Multiple Vulnerabilities

Multiple vulnerabilities in VMware Tanzu Spring Boot allow attackers to execute arbitrary code, bypass security measures, manipulate or disclose sensitive data, or hijack authenticated users.

Tanzu Spring Boot vmware spring-boot vulnerability
2r 4t
critical advisory

Multiple Vulnerabilities in Atlassian Products

Multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Jira, and Jira Service Management allow attackers to execute arbitrary code, bypass security measures, manipulate data, disclose information, or perform cross-site scripting attacks.

Bamboo +4 atlassian vulnerability code-execution xss
2r 4t 26c
high advisory

Path Traversal Vulnerability in engineer-your-data

A path traversal vulnerability (CVE-2026-7214) exists in eghuzefa's engineer-your-data up to version 0.1.3, allowing remote attackers to read or write arbitrary files by manipulating the WORKSPACE_PATH argument.

engineer-your-data path-traversal vulnerability
2r 1t 1c
high advisory

Duartium papers-mcp-server Path Traversal Vulnerability (CVE-2026-7205)

A path traversal vulnerability exists in the `search_papers` function of `src/main.py` in duartium papers-mcp-server version 9ceb3812a6458ba7922ca24a7406f8807bc55598, allowing remote attackers to read arbitrary files by manipulating the `topic` argument, with a public exploit available.

papers-mcp-server path-traversal vulnerability web-application
2r 1t 1c
high threat

dvladimirov MCP Git Search API Command Injection Vulnerability

A command injection vulnerability (CVE-2026-7211) exists in the GitSearchRequest function of dvladimirov MCP up to version 0.1.0, allowing a remote attacker to execute arbitrary commands by manipulating the repo_url or pattern argument.

exploited MCP command-injection vulnerability git-search-api
2r 1t 1c
high advisory

Moxa Security Advisory Addresses Vulnerabilities in Multiple Router Series

Moxa released a security advisory addressing CVE-2026-3867 and CVE-2026-3868, which affect TN-4900, EDR-8010, EDR-G9010, OnCell G4302-LTE4, OnCell G4308-LTE4, and EDF-G1002-BP series routers, potentially allowing for unauthorized access and control.

TN-4900 Series +5 vulnerability router industrial-control-systems
3r 2c
medium advisory

Dell Security Advisories Address Vulnerabilities in Multiple Products

Dell published security advisories addressing vulnerabilities in Dell Networking OS10, Dell Storage Monitoring and Reporting, Dell Storage Resource Manager, and Dell VxRail Appliance, urging users to apply necessary updates.

Networking OS10 +3 vulnerability dell
2r
high advisory

tufantunc ssh-mcp Command Injection Vulnerability (CVE-2026-7039)

A command injection vulnerability exists in tufantunc ssh-mcp up to version 1.5.0 via manipulation of the Description argument in the shell.write function.

ssh-mcp command-injection vulnerability
2r 1t 1c
high advisory

SQL Injection Vulnerability in code-projects Inventory Management System 1.0

A SQL injection vulnerability exists in code-projects Inventory Management System 1.0 within the Login component, specifically affecting the Username argument, where a remote attacker can manipulate the Username parameter, leading to unauthorized data access or modification.

Inventory Management System 1.0 sql-injection web-application vulnerability
2r 1t 1c
high advisory

KLiK SocialMediaWebsite SQL Injection Vulnerability (CVE-2026-7002)

KLiK SocialMediaWebsite up to version 1.0.1 is vulnerable to SQL injection via manipulation of the c_id argument in the /includes/get_message_ajax.php file, specifically affecting the Private Message Handler component, which can be exploited remotely.

SocialMediaWebsite sql-injection vulnerability web-application
2r 1t 1c
medium advisory

CVE-2026-23398 ICMP NULL Pointer Dereference

CVE-2026-23398 is a vulnerability related to a NULL pointer dereference in the ICMP protocol, potentially leading to a denial-of-service condition in affected Microsoft products.

PoC icmp denial-of-service vulnerability cve
2r 1t 1c updated
high advisory

PicoClaw Web Launcher Management Plane Command Injection Vulnerability

PicoClaw version 0.2.4 is vulnerable to command injection via the /api/gateway/restart endpoint of the Web Launcher Management Plane, allowing a remote attacker to execute arbitrary commands by manipulating input.

PicoClaw command-injection vulnerability web-application
2r 1t 1c
critical threat

Rclone Unauthenticated Remote Code Execution Vulnerabilities

Rclone versions prior to 1.73.5 are vulnerable to two critical unauthenticated remote code execution vulnerabilities (CVE-2026-41176 and CVE-2026-41179) when the remote control API is enabled without authentication, potentially allowing attackers to execute arbitrary commands and compromise the system.

exploited Rclone vulnerability rce cloud
2r 2t 2c
medium advisory

vanna-ai vanna Improper Authorization Vulnerability (CVE-2026-6977)

An improper authorization vulnerability (CVE-2026-6977) exists in vanna-ai vanna up to version 2.0.2 due to manipulation of an unknown function within the Legacy Flask API, potentially allowing remote attackers to bypass intended access restrictions.

vanna vulnerability authorization web application
2r 1t 1c
medium advisory

Microsoft Product Vulnerability CVE-2026-41080

CVE-2026-41080 is a vulnerability affecting a Microsoft product; the specific product, impact, and exploitation details are currently undisclosed.

CVE-2026-41080 vulnerability microsoft
2r 1c
high advisory

k8sGPT Operator Vulnerable to Prompt Injection

k8sGPT versions before 0.4.32 are vulnerable to prompt injection due to deserialization of AI-generated YAML without proper validation in the auto-remediation pipeline, potentially leading to arbitrary code execution within the Kubernetes cluster.

k8sgpt prompt-injection kubernetes ai vulnerability
2r 2t
high advisory

OVN DHCPv6 Out-of-Bounds Read Vulnerability (CVE-2026-5367)

A remote attacker can exploit an out-of-bounds read vulnerability in Open Virtual Network (OVN) by sending crafted DHCPv6 SOLICIT packets, leading to sensitive information disclosure.

OVN cve vulnerability network
2r 1t 1c
critical advisory

OpenClaw Remote Code Execution via Node Scope Gate Bypass (CVE-2026-41352)

OpenClaw before 2026.3.31 is vulnerable to remote code execution (CVE-2026-41352) because a device-paired node can bypass the node scope gate authentication mechanism, allowing attackers with device pairing credentials to execute arbitrary node commands.

OpenClaw rce vulnerability cve-2026-41352
2r 1t 1c
medium advisory

OpenClaw Cross-Site Request Forgery Vulnerability

OpenClaw before 2026.3.31 is vulnerable to cross-site request forgery (CSRF) attacks due to missing browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing attackers to perform unauthorized actions.

OpenClaw csrf web-application vulnerability
2r 1t 1c
critical advisory

Marimo Pre-Authentication Remote Code Execution Vulnerability (CVE-2026-39987)

CVE-2026-39987 is a pre-authentication remote code execution vulnerability in Marimo, enabling unauthenticated attackers to execute arbitrary system commands.

Marimo CVE-2026-39987 rce vulnerability
2r 1t 1c
critical advisory

Flowise Multiple Vulnerabilities

Multiple vulnerabilities in Flowise allow an attacker to execute arbitrary code, bypass security measures, disclose information, and manipulate files.

Flowise vulnerability code-execution information-disclosure file-manipulation
2r 3t 5c
critical advisory

Multiple Vulnerabilities in Cisco Products Allow for Remote Code Execution

Multiple vulnerabilities in Cisco ASA, Secure Firewall Threat Defense, IOS, IOS XE, and IOS XR allow a remote attacker to bypass authentication and execute arbitrary code with administrator privileges.

ASA +4 cisco vulnerability rce authentication-bypass
2r 4t 3c
medium advisory

Cisco Integrated Management Controller (IMC) Multiple XSS Vulnerabilities

Multiple cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct an XSS attack against a user of the interface.

Integrated Management Controller xss cisco cimc vulnerability
2r 1t 5c
critical advisory

Multiple Vulnerabilities in n8n Workflow Automation Tool

Multiple vulnerabilities in n8n can be exploited by an attacker to execute arbitrary code, bypass security measures, disclose sensitive information, conduct SQL injection attacks, cause denial-of-service, perform cross-site scripting, redirect users, or hijack sessions.

n8n vulnerability sqli xss rce session-hijacking
3r 5t 1c
medium advisory

Microsoft Product Vulnerability CVE-2026-22005

CVE-2026-22005 is a newly published vulnerability affecting a Microsoft product, requiring further investigation to determine the specific product, attack vector, and potential impact.

CVE-2026-22005 vulnerability microsoft
3r 1c
medium advisory

Microsoft Discloses Information Regarding CVE-2026-22004

Microsoft has released information regarding the vulnerability CVE-2026-22004, but details about the vulnerability and its exploitation are currently unavailable.

cve-2026-22004 vulnerability microsoft
1r 1t 1c
low advisory

Microsoft CVE-2026-35236 Information Published

Microsoft has published information regarding CVE-2026-35236, but no details about the vulnerability or its exploitation are currently available.

cve vulnerability microsoft
2r
medium advisory

CVE-2026-34303 Affecting Microsoft Products

CVE-2026-34303 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon disclosure of details.

vulnerability cve microsoft
2r 1c
critical advisory

CI4MS Backup Restore Zip Slip Vulnerability Leads to RCE

The CI4MS Backup restore function is vulnerable to Zip Slip, allowing remote code execution by uploading a malicious ZIP archive that writes PHP files to the public web root due to missing validation of entry names during extraction, affecting versions prior to 0.31.5.0.

ci4-cms-erp/ci4ms zip-slip rce code-injection vulnerability
2r 2t
critical advisory

Critical RCE Vulnerabilities in Spinnaker

Critical vulnerabilities CVE-2026-32613 and CVE-2026-32604 in Spinnaker allow authenticated attackers to execute arbitrary code due to insufficient input validation in expression parsing and gitrepo artifact handling, potentially leading to complete system compromise.

Spinnaker rce vulnerability
2r 1t 2c
medium threat

NVIDIA KAI Scheduler Authentication Bypass Vulnerability

CVE-2026-24177 describes an authentication bypass vulnerability in NVIDIA KAI Scheduler that could allow unauthorized access to API endpoints, leading to information disclosure.

exploited vulnerability authentication-bypass nvidia
2r 2t 1c
high advisory

HKUDS OpenHarness Insecure Default Configuration Vulnerability

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit permissive access, potentially leading to unauthorized file disclosure and read access.

vulnerability insecure-configuration access-control
2r 1t 1c
high advisory

FreeScout Mass Assignment Vulnerability (CVE-2026-40569)

FreeScout versions prior to 1.8.213 contain a mass assignment vulnerability allowing authenticated admins to modify sensitive mailbox settings by injecting parameters into connection settings requests, leading to email exfiltration and account compromise.

freescout mass-assignment vulnerability email-exfiltration
2r 2t 1c
medium advisory

FreeScout Incorrect Authorization Vulnerability (CVE-2026-41189)

FreeScout versions before 1.8.215 are vulnerable to an incorrect authorization issue where users without conversation access can edit customer threads due to a flaw in the `ThreadPolicy::edit()` function.

freescout authorization vulnerability
2r 1t 1c
critical advisory

CrowdStrike LogScale Unauthenticated Path Traversal Vulnerability (CVE-2026-40050)

A critical unauthenticated path traversal vulnerability (CVE-2026-40050) in CrowdStrike LogScale allows remote attackers to read arbitrary files from the server filesystem if a specific cluster API endpoint is exposed, necessitating immediate patching for self-hosted customers.

path-traversal vulnerability logscale crowdstrike
2r 1t 1c
critical threat

JetBrains TeamCity Authentication Bypass and Path Traversal Vulnerabilities

Unpatched JetBrains TeamCity servers are being actively exploited via an authentication bypass (CVE-2024-27198) and path traversal vulnerability (CVE-2024-27199), allowing attackers to perform administrative actions and potentially conduct supply-chain attacks.

exploited teamcity vulnerability authentication bypass path traversal supply-chain
2r 1t 2c
medium advisory

BigBlueButton Vulnerabilities Allow Data Manipulation and Redirects

Multiple vulnerabilities in BigBlueButton can be exploited by an attacker to manipulate data and redirect users to attacker-controlled domains.

bigbluebutton vulnerability datamanipulation redirect
2r 1t
high advisory

Multiple Vulnerabilities in OpenBao Allow for Security Bypass, DoS, and SQL Injection

Multiple vulnerabilities in OpenBao can be exploited by an attacker to bypass security measures, conduct a denial of service attack, and conduct a SQL injection attack.

openbao vulnerability sql-injection dos
3r 3t
high advisory

Oracle VM VirtualBox CVE-2026-35246 Vulnerability

CVE-2026-35246 is a vulnerability in Oracle VM VirtualBox version 7.2.6, where a high-privileged attacker with local access can exploit it to compromise the application potentially leading to a complete takeover.

cve-2026-35246 virtualbox vulnerability
2r 1c
high advisory

Multiple Vulnerabilities in Fortinet FortiSandbox

Multiple vulnerabilities in Fortinet FortiSandbox allow attackers to perform cross-site scripting attacks, disclose information, bypass security measures, and execute arbitrary code, potentially leading to system compromise.

fortinet fortisandbox vulnerability xss code-execution
3r 3t
critical advisory

Multiple Vulnerabilities in Red Hat Hardened Images RPMs

Remote, anonymous attackers can exploit vulnerabilities in Red Hat Hardened Images RPMs to bypass security measures, cause denial of service, disclose sensitive information, or potentially execute code.

redhat vulnerability denial-of-service information-disclosure code-execution linux
2r 7t
critical advisory

GIMP Multiple Vulnerabilities Allow Code Execution

A remote, anonymous attacker can exploit multiple vulnerabilities in GIMP to execute arbitrary program code, potentially leading to system compromise.

gimp code-execution vulnerability
2r 1t
critical advisory

Cisco Catalyst SD-WAN Manager Multiple Vulnerabilities

Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager allow a remote, anonymous, or local attacker to gain administrator privileges, bypass authentication, execute commands with Netadmin rights, read sensitive system information, and overwrite arbitrary files.

cisco sdwan vulnerability privilege-escalation
2r 4t
critical advisory

Libarchive Code Execution Vulnerability

A remote attacker can exploit a vulnerability in libarchive to achieve arbitrary code execution on a vulnerable system.

libarchive code-execution vulnerability
2r 1t
high advisory

Multiple Vulnerabilities in Roundcube

Multiple vulnerabilities in Roundcube allow an attacker to manipulate files, bypass security measures, perform cross-site scripting attacks, and disclose information.

roundcube vulnerability xss file-manipulation
2r 3t
high advisory

Multiple Vulnerabilities in Microsoft Developer Tools

Multiple vulnerabilities in Microsoft Visual Studio, .NET Framework, .NET, PowerShell, and Visual Studio Code can be exploited by an attacker to disclose sensitive information, conduct spoofing attacks, cause a denial of service, or bypass security measures, potentially leading to arbitrary code execution.

vulnerability code-execution spoofing denial-of-service information-disclosure windows
2r 4t
critical advisory

Multiple Vulnerabilities in Dell PowerProtect Data Domain OS

Multiple vulnerabilities in Dell PowerProtect Data Domain OS allow an attacker to execute arbitrary code with root privileges, escalate privileges to administrator, bypass security measures, manipulate data, disclose sensitive information, or conduct unspecified attacks.

dell powerprotect datadomain vulnerability privilege-escalation defense-evasion credential-access impact
2r 4t
high advisory

Multiple Vulnerabilities in FreeRDP Allow Remote Code Execution and DoS

An anonymous remote attacker can exploit multiple vulnerabilities in FreeRDP to potentially execute arbitrary code, cause a denial-of-service condition, manipulate data, disclose confidential information, or perform other unspecified attacks.

freerdp vulnerability rdp
2r 5t
medium advisory

libarchive Multiple Vulnerabilities Allow Information Disclosure and DoS

Multiple vulnerabilities in libarchive can be exploited by a remote attacker to disclose information or cause a denial-of-service condition.

vulnerability denial-of-service information-disclosure
2r 2t
high advisory

Intel IPU, UEFI Reference Firmware: Multiple Vulnerabilities

A local attacker can exploit multiple vulnerabilities in Intel Firmware to disclose confidential information or gain elevated privileges.

intel firmware vulnerability privilege-escalation credential-access
2r 2t
medium advisory

Microsoft CVE-2026-41254 Security Update

Microsoft released a security update for CVE-2026-41254, a vulnerability with unspecified details.

cve vulnerability microsoft
2r 1c
high advisory

AiAssistant Type Privilege Bypass Vulnerability (CVE-2026-31368)

CVE-2026-31368 is a type privilege bypass vulnerability in AiAssistant, potentially leading to service availability issues and complete compromise of the system.

privilege-escalation vulnerability AiAssistant
2r 2t 1c
medium advisory

Langflow Multiple Vulnerabilities

Multiple vulnerabilities in Langflow allow an attacker to manipulate files, disclose sensitive information, or conduct cross-site scripting attacks.

langflow vulnerability xss file-manipulation information-disclosure
2r 2t
medium advisory

Multiple Vulnerabilities in Gitea

Multiple vulnerabilities in Gitea could allow an attacker to disclose information, bypass security measures, and perform cross-site scripting attacks.

gitea vulnerability xss
1r 1t
critical advisory

Multiple Vulnerabilities in Firebird Database Server

Multiple vulnerabilities in Firebird allow an attacker to execute arbitrary code with administrator privileges, disclose sensitive information, or cause a denial-of-service condition.

firebird vulnerability sqldatabase
2r 3t
high advisory

ThreatSonar Anti-Ransomware Arbitrary File Deletion Vulnerability

TeamT5's ThreatSonar Anti-Ransomware is vulnerable to arbitrary file deletion via path traversal, allowing authenticated remote attackers with web access to delete arbitrary files on the system.

vulnerability file-deletion path-traversal
2r 2t 1c
critical advisory

Digiwin EasyFlow .NET SQL Injection Vulnerability (CVE-2026-5964)

Digiwin's EasyFlow .NET is susceptible to a SQL Injection vulnerability, enabling unauthenticated remote attackers to inject arbitrary SQL commands for unauthorized database access, modification, and deletion.

sql-injection vulnerability web-application
2r 1t 1c
high advisory

SecureDrop Client Code Execution via Gzip Extraction Vulnerability

A compromised SecureDrop server can achieve code execution on the SecureDrop client's virtual machine by exploiting improper filename validation during gzip archive extraction, allowing for the overwriting of critical files.

securedrop gzip code execution vulnerability linux
2r 1t 2c
high advisory

OpenClaw Environment Variable Injection Vulnerability

The openclaw package versions prior to 2026.4.10 are vulnerable to environment variable injection, where the exec environment policy missed interpreter startup variables allowing operator-supplied environment overrides to influence downstream execution or network behavior, addressed in versions 2026.4.10 and later.

npm openclaw environment-variable-injection vulnerability
2r 1t
high advisory

zrok Unauthenticated Denial-of-Service Vulnerability

An unauthenticated attacker can cause a denial-of-service (DoS) in zrok by sending a crafted HTTP request with a large cookie chunk count to an OAuth-protected proxy share, triggering unbounded memory allocation and leading to process termination.

dos vulnerability zrok CVE-2026-40303
2r 1t
high advisory

Dell PowerProtect Data Domain Improper Certificate Validation Vulnerability

Dell PowerProtect Data Domain versions 7.7.1.0 through 8.5, 8.3.1.0 through 8.3.1.20, and 7.13.1.0 through 7.13.1.60, contain an improper certificate validation vulnerability in certificate-based login, potentially leading to privilege escalation.

privilege-escalation vulnerability dell
2r 1t 1c
medium advisory

Mobatek MobaXterm Home Edition Uncontrolled Search Path Vulnerability (CVE-2026-6421)

CVE-2026-6421 is an uncontrolled search path vulnerability in Mobatek MobaXterm Home Edition up to version 26.1, affecting msimg32.dll, that can be exploited locally with high complexity.

cve vulnerability mobaxterm dll hijacking
2r 1t 1c
high advisory

Multiple Vulnerabilities in Cisco Unity Connection

Multiple vulnerabilities in Cisco Unity Connection can be exploited by an attacker to conduct cross-site scripting attacks, redirect users to malicious websites, manipulate data, and disclose confidential information.

cisco unity-connection vulnerability xss data-manipulation
2r 1t
high advisory

Multiple Vulnerabilities in libssh Allow File Manipulation and DoS

Multiple vulnerabilities in libssh allow an attacker to manipulate files or cause a denial-of-service condition, potentially leading to data corruption or service disruption.

libssh vulnerability dos file_manipulation
2r 1t
high advisory

Grafana Vulnerability Allows File Manipulation and Information Disclosure

A remote, authenticated attacker can exploit a vulnerability in Grafana to manipulate files and disclose sensitive information, potentially leading to persistence, unauthorized access, and significant impact.

grafana vulnerability file-manipulation information-disclosure
2r 4t
critical threat

Microsoft April 2026 Patch Tuesday Addresses 163 Vulnerabilities

Microsoft's April 2026 Patch Tuesday addresses 163 vulnerabilities, including 8 critical ones, ranging from Tampering to Remote Code Execution and Privilege Escalation, affecting various Microsoft products; it is recommended to apply patches immediately.

exploited patch-tuesday vulnerability remote-code-execution privilege-escalation windows
2r 4t 6c
critical advisory

Apache ActiveMQ Multiple Vulnerabilities Allow Remote Code Execution

An authenticated remote attacker can exploit multiple vulnerabilities in Apache ActiveMQ to manipulate files or execute arbitrary code.

apache-activemq vulnerability rce
2r 1t
high advisory

Openfind MailGates/MailAudit CRLF Injection Vulnerability

Openfind MailGates/MailAudit is vulnerable to CRLF injection (CVE-2026-6351), enabling unauthenticated remote attackers to read system files by injecting malicious CRLF sequences.

crlf-injection vulnerability mailgates mailaudit
2r 1t 1c
high advisory

Splunk MCP Server App Cleartext Credential Exposure (CVE-2026-20205)

A user with access to the `_internal` index or the `mcp_tool_admin` capability in Splunk MCP Server app versions below 1.0.3 can view user session and authorization tokens in clear text, leading to potential credential compromise.

splunk credential-access vulnerability
2r 1t 1c
high advisory

Windows Hyper-V Improper Input Validation Vulnerability (CVE-2026-32149)

CVE-2026-32149 is a vulnerability in Windows Hyper-V due to improper input validation, which allows an authorized, local attacker to execute arbitrary code.

hyper-v code-execution vulnerability windows
2r 2t 1c
critical advisory

SQL Server Untrusted Pointer Dereference Vulnerability (CVE-2026-33120)

CVE-2026-33120 is an untrusted pointer dereference vulnerability in Microsoft SQL Server that allows an authenticated attacker to achieve remote code execution over a network.

sql-server rce vulnerability
2r 1t 1c
medium advisory

Microsoft Excel Out-of-Bounds Read Vulnerability (CVE-2026-32188)

An out-of-bounds read vulnerability in Microsoft Office Excel (CVE-2026-32188) allows a local attacker to potentially disclose sensitive information through a maliciously crafted Excel file.

excel out-of-bounds read cve-2026-32188 information disclosure vulnerability
2r 1t 1c
high advisory

CVE-2026-33826: Windows Active Directory Improper Input Validation Vulnerability

An improper input validation vulnerability (CVE-2026-33826) in Windows Active Directory could allow an authenticated attacker on an adjacent network to execute code.

cve-2026-33826 active-directory code-execution vulnerability
2r 1t 1c
high advisory

Azure Monitor Agent Improper Input Validation Vulnerability (CVE-2026-32168)

CVE-2026-32168 is an improper input validation vulnerability in Azure Monitor Agent that allows a locally authorized attacker to elevate privileges.

azure privilege escalation vulnerability cve-2026-32168
2r 1t 1c
critical advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Ansible Automation Platform to perform denial of service, execute arbitrary code, bypass security measures, manipulate data, disclose information, or conduct XSS attacks.

ansible redhat vulnerability dos xss code-execution
2r 6t
high advisory

CVE-2026-32183: Windows Snipping Tool Command Injection Vulnerability

CVE-2026-32183 is a command injection vulnerability in the Windows Snipping Tool that allows a local attacker to execute arbitrary code.

command-injection windows vulnerability
2r 2t 1c
critical advisory

Fortinet FortiSandbox Path Traversal Vulnerability (CVE-2026-39813)

A path traversal vulnerability (CVE-2026-39813) in Fortinet FortiSandbox versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8 may allow an unauthenticated attacker to escalate privileges via '../filedir'.

path-traversal vulnerability privilege-escalation fortinet
2r 1t 1c
medium advisory

UniFi Play Improper Access Control Vulnerability (CVE-2026-22566)

An improper access control vulnerability in UniFi Play PowerAmp and Audio Port allows a malicious actor with access to the UniFi Play network to obtain WiFi credentials.

vulnerability access-control unifi
2r 1t 1c
critical threat

Adobe Acrobat and Reader CVE-2026-34621 Zero-Day Exploitation

Adobe patched CVE-2026-34621, a zero-day vulnerability in Acrobat and Reader exploited since December, allowing malicious PDFs to bypass sandboxes and execute arbitrary code, potentially leading to local file theft.

exploited adobe acrobat reader rce vulnerability
2r 2t 1c 1i
high advisory

SQL Injection Vulnerability in Faculty Management System

A remote attacker can exploit an SQL injection vulnerability (CVE-2026-6167) in the code-projects Faculty Management System 1.0 by manipulating the ID argument in the /subject-print.php file, potentially leading to data exfiltration or modification.

sql-injection web-application vulnerability
2r 1t 1c
high advisory

SQL Injection Vulnerability in Lost and Found Thing Management 1.0

A remote SQL injection vulnerability (CVE-2026-6163) exists in code-projects Lost and Found Thing Management 1.0 via manipulation of the 'cat' parameter in /catageory.php, potentially allowing attackers to read, modify, or delete database information.

sql-injection web-application vulnerability
2r 1t 1c
medium advisory

Huawei Communication Module Use-After-Free Vulnerability (CVE-2026-34856)

A use-after-free vulnerability, tracked as CVE-2026-34856, exists in Huawei's communication module due to improper synchronization in concurrent execution, potentially leading to a denial-of-service condition.

vulnerability uaf dos
2r 1t 1c
high advisory

Mesa WebGPU Out-of-Bounds Write Vulnerability (CVE-2026-40393)

An out-of-bounds write vulnerability exists in Mesa versions before 25.3.6 and 26 before 26.0.1 due to an untrusted allocation size in WebGPU, potentially leading to code execution.

cve vulnerability webgpu
2r 1c
critical advisory

Unauthenticated Arbitrary File Write in Saltcorn

Unauthenticated attackers can exploit a vulnerability in Saltcorn versions prior to 1.4.5, 1.5.5, and 1.6.0-beta.4 to write arbitrary files and list directory contents on the server.

saltcorn file-write vulnerability
2r 1t 1c
high advisory

Helm Plugin Path Traversal Vulnerability

A path traversal vulnerability in Helm versions 4.0.0 to 4.1.3 allows a malicious plugin to write files to arbitrary locations on the filesystem, leading to potential system compromise.

PoC Helm path-traversal vulnerability plugin kubernetes
2r 1t 1c 8i updated
high advisory

@sveltejs/adapter-node BODY_SIZE_LIMIT Bypass Vulnerability

A vulnerability exists in @sveltejs/adapter-node where requests could bypass the `BODY_SIZE_LIMIT` on SvelteKit applications, potentially leading to denial of service.

sveltekit denial-of-service vulnerability
2r 1t 1c
high advisory

OpenClaw Path Traversal Vulnerability (CVE-2026-35668)

OpenClaw before 2026.3.24 is vulnerable to path traversal, allowing sandboxed agents to read arbitrary files from other agents' workspaces via manipulated URL parameters.

path-traversal vulnerability openclaw
2r 1t 1c
critical advisory

Juju CloudSpec API Authorization Bypass (CVE-2026-5412)

CVE-2026-5412 describes an authorization issue in Juju versions prior to 2.9.57 and 3.6.21, where a low-privileged authenticated user can call the CloudSpec API method to extract cloud credentials used to bootstrap the controller, leading to sensitive credential exposure.

vulnerability authorization cloud
2r 1t 1c
critical advisory

IBM Semeru Runtime Code Execution Vulnerability

A remote, anonymous attacker can exploit a vulnerability in IBM Semeru Runtime and IBM DB2 to execute arbitrary program code.

code-execution vulnerability ibm
2r 1t
high advisory

OpenClaw Improper Access Control Vulnerability (CVE-2026-34512)

OpenClaw before 2026.3.25 contains an improper access control vulnerability (CVE-2026-34512) in the HTTP /sessions/:sessionKey/kill route, allowing any authenticated user to terminate arbitrary subagent sessions.

access-control vulnerability webserver
2r 1t 1c
high advisory

FoundationAgents MetaGPT Code Injection Vulnerability (CVE-2026-5971)

A code injection vulnerability exists in FoundationAgents MetaGPT <= 0.8.1 within the ActionNode.xml_fill function, allowing remote attackers to inject code due to improper neutralization of directives in dynamically evaluated code.

code-injection vulnerability metagpt CVE-2026-5971
2r 1t 1c
high advisory

BSV Ruby SDK Improper ARC Response Handling

BSV Ruby SDK versions before 0.8.2 improperly handle ARC responses, treating certain failure statuses as successful broadcasts, potentially tricking applications into trusting unaccepted transactions; version 0.8.2 resolves this vulnerability.

bsv ruby blockchain vulnerability
2r 1t 1c
high advisory

Tmds.DBus Vulnerability Allows Signal Spoofing and Resource Exhaustion

Tmds.DBus and Tmds.DBus.Protocol are vulnerable to signal spoofing, resource exhaustion, and application crashes due to malformed messages from malicious D-Bus peers on the same bus.

dbus vulnerability dotnet
2r 1t 1c
high advisory

OPNsense LDAP Injection Vulnerability (CVE-2026-34578)

OPNsense versions prior to 26.1.6 are vulnerable to LDAP injection, allowing unauthenticated attackers to enumerate valid LDAP usernames and bypass group membership restrictions via the WebGUI login page.

ldap-injection vulnerability opnsense
2r 1t 1c
critical advisory

Nix Package Manager Arbitrary File Overwrite Vulnerability

A flaw in Nix package manager allows arbitrary file overwrites via symlink following during fixed-output derivation registration, potentially leading to root privilege escalation on multi-user Linux systems.

nix privilege-escalation linux vulnerability
2r 1t 2c
critical advisory

Multiple Vulnerabilities in Zammad

Multiple vulnerabilities in Zammad allow a remote attacker to execute arbitrary code, bypass security measures, disclose sensitive information, and perform cross-site scripting attacks.

zammad vulnerability code execution xss
2r 3t
high advisory

UAC (Unix-like Artifacts Collector) Command Injection Vulnerability

UAC before 3.3.0-rc1 is vulnerable to command injection in the _run_command() function, allowing attackers to execute arbitrary commands with the privileges of the UAC process through manipulated input values.

command-injection vulnerability uac
2r 1t 1c
high advisory

parseusbs OS Command Injection Vulnerability (CVE-2026-40030)

parseusbs before 1.9 is vulnerable to OS command injection (CVE-2026-40030) due to improper sanitization of the volume listing path argument, potentially allowing arbitrary command execution via crafted volume paths.

command-injection vulnerability linux
2r 1t 1c
medium advisory

Red Hat Quay Image Upload Interference Vulnerability (CVE-2026-32589)

CVE-2026-32589 describes a vulnerability in Red Hat Quay's container image upload process where an authenticated user can interfere with other users' uploads, potentially leading to unauthorized access and modification.

quay image upload vulnerability
2r 2t 1c
high advisory

D-LINK Router M60 and DIR-3040 'Airsnitch' Vulnerability

The 'Airsnitch' vulnerability in D-LINK Router M60 and DIR-3040 allows an attacker from an adjacent network to bypass security measures, disclose confidential information, and manipulate network traffic.

d-link router airsnitch vulnerability network-traffic-manipulation
2r 5t
high advisory

OpenObserve SSRF via Improper IPv6 Validation

OpenObserve versions 0.70.3 and earlier are vulnerable to a server-side request forgery (SSRF) attack due to improper validation of IPv6 addresses in the validate_enrichment_url function, potentially allowing authenticated attackers to access internal services and retrieve sensitive cloud metadata.

ssrf openobserve cloud vulnerability
2r 1t 1c
high advisory

Mise Trust Bypass Vulnerability via Malicious .mise.toml

A vulnerability in mise allows an attacker who can place a malicious .mise.toml file in a repository to bypass trust checks and execute arbitrary code via `[env] _.source` due to improper loading of trust settings.

mise trust-bypass code-execution vulnerability
2r 2t
high advisory

PowerJob SQL Injection Vulnerability (CVE-2026-5736)

A remote SQL injection vulnerability, CVE-2026-5736, exists in PowerJob versions 5.1.0 through 5.1.2 within the detailPlus Endpoint, potentially allowing unauthenticated attackers to execute arbitrary SQL queries.

sql-injection vulnerability powerjob
2r 1t 1c
medium advisory

CSRF Vulnerability in WordPress Under Construction Plugin (CVE-2026-34896)

A cross-site request forgery (CSRF) vulnerability exists in the Analytify Under Construction, Coming Soon & Maintenance Mode WordPress plugin (versions n/a through 2.1.1), potentially allowing attackers to execute unauthorized actions on behalf of legitimate users.

wordpress csrf vulnerability
2r 2t 1c
critical threat

Critical Vulnerability CVE-2026-35616 Exploited in FortiClient EMS

CVE-2026-35616, a critical vulnerability in FortiClient EMS, allows unauthenticated remote attackers to execute arbitrary code or commands via crafted API requests due to improper access control, with Fortinet confirming active exploitation.

exploited fortinet forticlient ems cve-2026-35616 vulnerability
2r 1t 1c
medium advisory

Brave CMS Insecure Direct Object Reference Vulnerability (CVE-2026-35183)

Brave CMS versions prior to 2.0.6 are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability allowing authenticated users with edit permissions to delete images attached to articles owned by other users due to missing ownership verification in the deleteImage method.

idor brave-cms vulnerability
1r 1t 1c
high advisory

GPT Researcher Code Injection Vulnerability (CVE-2026-5631)

A remote code injection vulnerability exists in assafelovic gpt-researcher versions up to 3.4.3 due to improper handling of the 'args' argument in the extract_command_data function, potentially allowing attackers to execute arbitrary code.

code-injection vulnerability gpt-researcher
2r 1t 1c
high advisory

OpenDocMan 1.3.4 SQL Injection Vulnerability

OpenDocMan version 1.3.4 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries via the 'where' parameter in search.php to extract sensitive information.

sqli vulnerability opendocman
2r 1t 1c
critical advisory

Advance Gift Shop Pro Script 2.0.3 SQL Injection Vulnerability

Advance Gift Shop Pro Script 2.0.3 is vulnerable to SQL injection via the 's' search parameter, allowing unauthenticated attackers to execute arbitrary SQL queries and extract sensitive database information.

sqli vulnerability webapp
2r 1t 1c
high advisory

PilusCart 1.4.1 SQL Injection Vulnerability

PilusCart 1.4.1 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter to extract sensitive database information.

sqli vulnerability web-application
2r 1t 1c
critical threat

Fosowl agenticSeek 0.1.0 Code Injection Vulnerability (CVE-2026-5584)

A code injection vulnerability (CVE-2026-5584) exists in Fosowl agenticSeek 0.1.0, allowing remote attackers to execute arbitrary code by manipulating the query endpoint through the PyInterpreter.execute function.

exploited code-injection vulnerability fosowl cve-2026-5584
2r 1t 1c
high advisory

code-projects Simple Laundry System 1.0 SQL Injection Vulnerability

A remote SQL Injection vulnerability exists in code-projects Simple Laundry System 1.0 within the /delmemberinfo.php file's userid parameter, potentially allowing attackers to execute arbitrary SQL commands.

sql-injection web-application vulnerability
2r 1t 1c
high advisory

Provectus Kafka UI Code Injection Vulnerability (CVE-2026-5562)

A code injection vulnerability exists in provectus kafka-ui up to version 0.7.2, specifically affecting the validateAccess function within the /api/smartfilters/testexecutions endpoint, allowing remote attackers to inject code.

code-injection kafka-ui vulnerability
2r 2t 1c
high threat

SQL Injection Vulnerability in Concert Ticket Reservation System

A remote attacker can exploit CVE-2026-5554 in code-projects Concert Ticket Reservation System 1.0 to perform SQL injection by manipulating the searching argument in the process_search.php file.

exploited sql-injection web-application vulnerability
2r 1t 1c
high advisory

SQL Injection Vulnerability in Free Hotel Reservation System 1.0 (CVE-2026-5551)

A SQL injection vulnerability (CVE-2026-5551) exists in itsourcecode Free Hotel Reservation System 1.0, specifically affecting the `email` parameter within the `/hotel/admin/login.php` file, allowing remote attackers to execute arbitrary SQL queries.

sql-injection web-application vulnerability
2r 1t 1c
critical advisory

Signal K Server Privilege Escalation via Unprotected /enableSecurity Endpoint

The Signal K server is vulnerable to privilege escalation due to the /skServer/enableSecurity endpoint remaining active after initial setup, allowing unauthenticated users to inject a new admin account and gain full server control; this affects versions prior to 2.24.0-beta.4.

privilege-escalation web-application vulnerability
2r 1t 1c
critical advisory

Budibase REST Connector SSRF via Empty Blacklist

A critical Server-Side Request Forgery (SSRF) vulnerability in Budibase's REST datasource connector allows attackers with Builder privileges to exfiltrate sensitive data from internal network services due to a missing default IP blacklist.

ssrf budibase vulnerability
2r 7t
high advisory

ProfilePress WordPress Plugin Membership Payment Bypass Vulnerability

The ProfilePress WordPress plugin before 4.16.12 is vulnerable to an unauthorized membership payment bypass, allowing authenticated attackers to obtain paid memberships without payment by manipulating subscription IDs during checkout.

wordpress plugin vulnerability membership
2r 1t 1c
critical advisory

Directus Aggregate Query Vulnerability Allows Disclosure of Concealed Data

A vulnerability in Directus versions prior to 11.17.0 allows authenticated users to extract concealed field values, including static API tokens and two-factor authentication secrets from directus_users, via aggregate queries.

directus vulnerability credential-access api-token 2fa-bypass
2r 1t
critical advisory

PraisonAI Gateway Unauthenticated Access Vulnerability

PraisonAI Gateway server versions prior to 4.5.97 allow unauthenticated access to WebSocket connections and agent topology, enabling unauthorized message sending and agent enumeration.

vulnerability authentication bypass websocket
2r 1t 1c
medium advisory

Piwigo Unauthenticated History Search Access

Piwigo versions prior to 16.3.0 expose the full browsing history of gallery visitors to unauthenticated users via the pwg.history.search API method due to a missing authorization check.

piwigo vulnerability information-disclosure
2r 1t 1c 1i
high advisory

fast-jwt Library Vulnerability Allows crit Header Validation Bypass

The fast-jwt library fails to validate the 'crit' header, allowing attackers to bypass security policies and potentially achieve split-brain verification in mixed-library environments.

jwt vulnerability authentication authorization
2r 1t 1c
critical advisory

SandboxJS Integrity Escape Vulnerability

A sandbox integrity escape vulnerability exists in SandboxJS versions prior to 0.8.36, allowing untrusted code to bypass global write protections and mutate host shared global objects, potentially leading to cross-context persistence and broader compromise.

sandbox-escape javascript vulnerability
2r 2t
critical advisory

Budibase Path Traversal Vulnerability in Plugin Upload

A path traversal vulnerability exists in Budibase versions prior to 3.33.4, allowing attackers with Global Builder privileges to delete arbitrary directories and write arbitrary files via crafted plugin uploads.

path-traversal vulnerability budibase
2r 1t 1c
critical advisory

fast-jwt Library JWT Algorithm Confusion Vulnerability

The fast-jwt library is vulnerable to JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key due to an incomplete fix for CVE-2023-48223, allowing attackers to bypass intended security measures by exploiting leading whitespace in the RSA public key, enabling attackers to sign arbitrary payloads that will be accepted by the verifier, potentially leading to privilege escalation.

jwt algorithm-confusion vulnerability fast-jwt nodejs
2r 1t 1c
medium advisory

ManageEngine Exchange Reporter Plus Stored XSS Vulnerability

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in the Distribution Lists report, allowing attackers to inject malicious scripts.

xss vulnerability manageengine
2r 2t 1c
high advisory

Swift Crypto X-Wing HPKE Decapsulation Vulnerability

The X-Wing decapsulation path in swift-crypto accepts attacker-controlled encapsulated ciphertext bytes without enforcing the required fixed ciphertext length of 1120 bytes, leading to a potential out-of-bounds read.

vulnerability memory-safety swift-crypto
2r 1t
high advisory

Electron Use-After-Free Vulnerability in Offscreen Rendering with Child Windows

A use-after-free vulnerability (CVE-2026-34774) exists in Electron applications using offscreen rendering and allowing child windows, potentially leading to crashes or memory corruption if the parent WebContents is destroyed before the child window.

electron use-after-free vulnerability cve-2026-34774
2r
high advisory

Electron Use-After-Free Vulnerability in PowerMonitor Module

A use-after-free vulnerability exists in the `powerMonitor` module of Electron applications on Windows and macOS. When the native `PowerMonitor` object is garbage-collected, dangling references are retained by OS-level resources. Subsequent session-change events on Windows or system shutdowns on macOS may dereference freed memory, potentially leading to a crash or memory corruption.

electron use-after-free vulnerability powermonitor windows macos
2r 1t
critical advisory

Azure MCP Server Missing Authentication Vulnerability (CVE-2026-32211)

CVE-2026-32211 is a critical vulnerability in Azure MCP Server due to missing authentication for a critical function, allowing an unauthorized attacker to disclose information over the network.

azure information-disclosure vulnerability
2r 1t 1c
critical advisory

OneUptime Unauthenticated Endpoint Access Vulnerability (CVE-2026-34758)

OneUptime versions prior to 10.0.42 are vulnerable to unauthenticated access to Notification test and Phone Number management endpoints, leading to potential abuse of SMS, Call, Email, and WhatsApp functionalities, and unauthorized phone number purchases, fixed in version 10.0.42.

cve vulnerability oneuptime unauthenticated-access
2r 1t 1c
critical advisory

Endian Firewall Command Injection Vulnerability (CVE-2026-34791)

Endian Firewall version 3.3.25 and prior allows authenticated users to execute arbitrary OS commands due to an OS command injection vulnerability in the DATE parameter of the /cgi-bin/logs_proxy.cgi endpoint.

command-injection rce vulnerability
2r 1t 1c
medium advisory

Suricata DCERPC Buffering Inefficiency Vulnerability (CVE-2026-31937)

Suricata versions prior to 7.0.15 are vulnerable to CVE-2026-31937, where inefficient DCERPC buffering can lead to a denial-of-service condition through performance degradation.

vulnerability dos suricata
2r 1t 1c
critical advisory

Unauthenticated SQL Injection Vulnerability in setinfo Endpoint

An unauthenticated remote attacker can exploit a SQL Injection vulnerability (CVE-2026-33615) in the setinfo endpoint by injecting malicious code into a SQL UPDATE command, leading to a total loss of integrity and availability.

sql-injection vulnerability web-application
2r 1t 1c 2i
critical advisory

Unauthenticated SQL Injection Vulnerability in getinfo Endpoint (CVE-2026-33614)

An unauthenticated SQL Injection vulnerability (CVE-2026-33614) in the getinfo endpoint allows a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements, potentially leading to a total loss of confidentiality.

sql-injection vulnerability web-application
2r 1t 1c
critical advisory

Juju Controller Vulnerable to Unauthorized Database Access Due to Improper TLS Configuration

Juju controller versions 3.2.0 up to 3.6.20 and 4.0.5 are vulnerable to unauthorized database access due to improper TLS client/server authentication and certificate verification, allowing an attacker with network access to modify all information, escalate privileges, and open firewall ports.

juju dqlite tls vulnerability
2r 3t
critical advisory

Payload CMS Password Reset Vulnerability (CVE-2026-34751)

An unauthenticated attacker can perform actions on behalf of a user initiating a password reset in Payload CMS versions prior to 3.79.1 due to a flaw in the password recovery flow, potentially leading to account takeover or privilege escalation.

cve-2026-34751 payload-cms password-reset vulnerability
2r 1t 1c
high advisory

pandas-ai SQL Injection Vulnerability (CVE-2026-30273)

pandas-ai v3.0.0 is vulnerable to SQL injection via the pandasai.agent.base._execute_sql_query component, potentially allowing unauthorized database access and modification.

sql-injection vulnerability pandas-ai
2r 1t 1c
critical advisory

Critical Vulnerability in FastGPT Allows API Key Exfiltration and Internal Network Access

CVE-2026-34162 in FastGPT allows unauthenticated attackers to exfiltrate API keys and gain complete access to internal services managed by Docker Compose by sending arbitrary HTTP requests, leading to potential compromise of the internal network.

fastgpt vulnerability information-disclosure
2r 3t 1c 1i
critical threat

F5 BIG-IP APM CVE-2025-53521 Reclassified as Actively Exploited Unauthenticated RCE

F5 has reclassified CVE-2025-53521, a vulnerability in BIG-IP APM, as a critical unauthenticated remote code execution vulnerability and reports it is being actively exploited in the wild.

exploited f5 big-ip apm cve-2025-53521 rce vulnerability
2r 1t 1c updated
high advisory

7-Zip Multiple Vulnerabilities Allow Remote Code Execution

Multiple vulnerabilities in 7-Zip allow an attacker to execute arbitrary program code with the privileges of the service, potentially leading to system compromise.

7-zip code-execution vulnerability windows
2r 1t
high advisory

Multiple Vulnerabilities in PowerDNS

Multiple vulnerabilities in PowerDNS could be exploited by an attacker to disclose information, bypass security measures, cause a denial of service, and potentially execute code.

powerdns vulnerability dos information-disclosure code-execution
1r
critical advisory

Multiple Vulnerabilities in libpng Allow Remote Code Execution and Denial of Service

A remote, anonymous attacker can exploit multiple vulnerabilities in libpng to execute arbitrary program code or cause a denial of service.

libpng vulnerability remote-code-execution denial-of-service
2r 2t
medium advisory

7-Zip Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in 7-Zip to manipulate files, leading to potential data integrity issues.

7-zip file-manipulation vulnerability
2r 2t
high advisory

IBM App Connect Enterprise Multiple Vulnerabilities

A remote, anonymous attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to cause a denial-of-service condition or bypass security measures, enabling cross-site scripting attacks.

vulnerability dos xss ibm
2r 2t
critical advisory

Red Hat Enterprise Linux libxslt Vulnerability Allows DoS and Code Execution

A local attacker can exploit a vulnerability in libxslt on Red Hat Enterprise Linux to cause a denial of service or execute arbitrary program code.

libxslt rhel vulnerability code-execution denial-of-service linux
2r 2t
medium advisory

MPPX TypeScript Interface Vulnerability (CVE-2026-34209)

A vulnerability exists in mppx TypeScript interface before version 0.4.11, allowing attackers to close or grief channels for free by submitting close vouchers equal to the settled amount due to incorrect validation.

vulnerability payment-channel typescript
1r 1t 1c
high advisory

SQL Injection Vulnerability in Student Membership System 1.0

CVE-2026-5198 is a SQL injection vulnerability in the Admin Login component of code-projects Student Membership System 1.0, affecting the /admin/index.php file, enabling remote exploitation through manipulation of username/password parameters.

sql-injection vulnerability web-application
2r 1t 1c
medium advisory

OpenClaw Information Disclosure via Telegram Bot Token Exposure

OpenClaw before version 2026.3.13 exposes Telegram bot tokens in error messages due to the fetchRemoteMedia function embedding these tokens in MediaFetchError strings when media downloads fail.

information-disclosure vulnerability telegram
2r 1c
high advisory

DELMIA Factory Resource Manager Stored XSS Vulnerability (CVE-2025-10553)

A stored cross-site scripting (XSS) vulnerability in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x (CVE-2025-10553) allows attackers to execute arbitrary script code within a user's browser session.

xss vulnerability web-application
2r 1t 1c
high advisory

DELMIA Factory Resource Manager Path Traversal Vulnerability (CVE-2025-10559)

CVE-2025-10559 is a path traversal vulnerability in DELMIA Factory Resource Manager, affecting versions 3DEXPERIENCE R2023x through R2025x, which allows an attacker with low privileges to read or write files in specific directories on the server, potentially leading to information disclosure or code execution.

path-traversal vulnerability delmia cve-2025-10559
2r 1t 1c
critical advisory

ImageMagick Multiple Vulnerabilities Leading to DoS, Code Execution, or Data Manipulation

Multiple vulnerabilities in ImageMagick could allow an attacker to perform a denial of service attack, execute arbitrary code, or manipulate data.

imagemagick vulnerability dos code_execution data_manipulation
2r 1t
high advisory

SQL Injection Vulnerability in SourceCodester Simple Doctors Appointment System 1.0 (CVE-2026-5180)

A SQL Injection vulnerability (CVE-2026-5180) exists in SourceCodester Simple Doctors Appointment System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'email' parameter in the /admin/ajax.php?action=login2 endpoint.

sql-injection vulnerability web-application
2r 1t 1c
high advisory

SQL Injection Vulnerability in SourceCodester Simple Doctors Appointment System 1.0 (CVE-2026-5179)

A SQL injection vulnerability (CVE-2026-5179) exists in SourceCodester Simple Doctors Appointment System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username argument in the /admin/login.php file, with a public exploit available.

sql-injection web-application vulnerability
2r 1t 1c
high advisory

vcpkg OpenSSL Windows Build Path Vulnerability (CVE-2026-34054)

A vulnerability exists in vcpkg versions prior to 3.6.1#3, where Windows builds of OpenSSL set openssldir to a path on the build machine, making that path vulnerable to attack on customer machines.

vulnerability openssl vcpkg cwe-427 windows
2r 2t 1c
high advisory

SciTokens Library Path Traversal Vulnerability (CVE-2026-32727)

A path traversal vulnerability (CVE-2026-32727) in SciTokens library versions prior to 1.9.7 allows attackers to bypass intended directory restrictions using dot-dot sequences in the scope claim of a token due to improper path normalization.

scitokens path-traversal cve-2026-32727 vulnerability
2r 1t 1c
medium advisory

baserCMS DOM-Based Cross-Site Scripting Vulnerability (CVE-2026-32734)

baserCMS versions prior to 5.2.3 are vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation, potentially allowing a remote attacker to execute arbitrary JavaScript in a user's browser.

xss vulnerability basercms
2r 1t 1c
high advisory

Botan SM2 Decryption Heap Over-read Vulnerability (CVE-2026-32877)

Botan C++ cryptography library versions 2.3.0 before 3.11.0 are vulnerable to a heap over-read during SM2 decryption due to insufficient validation of the authentication code length, potentially leading to crashes or undefined behavior.

cve vulnerability heap-overread botan
2r 1t 1c
medium advisory

Symantec DLP Windows Endpoint Elevation of Privilege Vulnerability (CVE-2026-3991)

CVE-2026-3991 is an elevation of privilege vulnerability in Symantec Data Loss Prevention (DLP) Windows Endpoint that could allow a local attacker to gain elevated access to resources.

vulnerability privilege-escalation symantec dlp windows
2r 1t
high advisory

Glances XML-RPC Server Cross-Origin Information Disclosure

The Glances XML-RPC server exposes sensitive system information due to a permissive CORS policy and missing Content-Type validation, enabling attackers to bypass CORS restrictions and steal data like hostnames, OS details, IP addresses, and process lists.

glances cors information-disclosure vulnerability
2r 3t 1i
high advisory

Gotenberg Chromium Deny-List Bypass via Case-Insensitive URL Scheme

Gotenberg versions before 8.29.0 are vulnerable to unauthenticated arbitrary file read, where a case-insensitive URL scheme bypasses the Chromium deny-list, allowing attackers to read sensitive files such as /etc/passwd by using mixed-case or uppercase URL schemes like FILE:///etc/passwd, leading to the leakage of sensitive data from the Gotenberg container and bypassing the fix for CVE-2024-21527.

gotenberg file-read vulnerability chromium
2r 1t
critical advisory

Multiple Vulnerabilities in Wazuh Leading to Code Execution and Data Manipulation

Multiple vulnerabilities in Wazuh allow an attacker to perform denial-of-service attacks, execute arbitrary code, manipulate data, and disclose sensitive information, potentially leading to significant data breaches and system compromise.

wazuh vulnerability code-execution data-manipulation
2r 6t
critical advisory

Multiple Vulnerabilities in Fleet

Multiple vulnerabilities in Fleet allow an attacker to perform SQL injection, denial of service, bypass security measures, disclose information, and execute arbitrary program code with administrator privileges.

fleet vulnerability sql-injection denial-of-service
2r 8t
critical advisory

Multiple Vulnerabilities in Grafana

Multiple vulnerabilities in Grafana allow a remote attacker to conduct a denial-of-service attack, execute code, or disclose information.

grafana vulnerability dos code-execution information-disclosure
2r 4t
high advisory

Langflow Vulnerability Allows File Manipulation

An authenticated, remote attacker can exploit a vulnerability in Langflow to manipulate files, potentially leading to unauthorized data modification or application compromise.

langflow file-manipulation vulnerability
2r 1t
high advisory

OpenBao Multiple Vulnerabilities Allow Security Bypass and XSS

An anonymous, remote attacker can exploit multiple vulnerabilities in OpenBao to bypass security measures or conduct cross-site scripting attacks.

openbao vulnerability security-bypass xss
2r 4t
high advisory

Multiple Vulnerabilities in Dovecot Mail Server

Multiple vulnerabilities in Dovecot can be exploited by an attacker to perform SQL injection attacks, bypass authentication, disclose sensitive information, or cause a denial-of-service condition.

dovecot vulnerability sql-injection authentication-bypass dos
2r 2t
critical advisory

Multiple Vulnerabilities in NGINX and NGINX Plus

Multiple vulnerabilities in NGINX Plus and NGINX can be exploited by an attacker to perform a denial of service attack, manipulate data, bypass security measures, and potentially execute arbitrary program code, leading to significant impact.

nginx vulnerability denial-of-service code-execution webserver linux
2r 1t
critical advisory

Multiple Vulnerabilities in F5 BIG-IP and F5OS

Multiple vulnerabilities in F5 BIG-IP and F5OS allow an attacker to bypass security mechanisms, escalate privileges, cause a denial-of-service condition, perform a cross-site scripting attack, and disclose or manipulate information.

f5 big-ip f5os vulnerability
2r 5t
high advisory

CVE-2026-2328 Unauthenticated Path Traversal Vulnerability

CVE-2026-2328 describes a vulnerability where an unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, leading to the exposure of sensitive information.

path-traversal vulnerability webserver
2r 1t
high advisory

OpenClaw Gateway Plugin Subagent Admin Scope Vulnerability

The openclaw package versions 2026.3.24 and earlier are vulnerable due to the gateway plugin subagent fallback `deleteSession` function dispatching `sessions.delete` with a synthetic `operator.admin` runtime scope, potentially leading to unauthorized session deletion.

openclaw vulnerability authorization
2r 1t
high advisory

OpenClaw Credential Exposure via Leaked Pairing Codes

OpenClaw before 2026.3.12 embeds long-lived shared gateway credentials in pairing setup codes, allowing attackers with access to leaked codes to reuse credentials and gain unauthorized access.

credential-access vulnerability openclaw
2r 1t
high advisory

SQL Injection Vulnerability in Simple Food Order System 1.0

A SQL injection vulnerability exists in code-projects Simple Food Order System 1.0 within the register-router.php file, where manipulation of the Name argument can lead to remote code execution.

sql-injection web-application vulnerability
2r 1t
high advisory

code-projects Simple Food Order System SQL Injection Vulnerability (CVE-2026-5017)

CVE-2026-5017 is a SQL injection vulnerability in code-projects Simple Food Order System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'Status' parameter in the `/all-tickets.php` file.

sql-injection web-application vulnerability
2r 1t
high advisory

SQL Injection Vulnerability in Sinaptik AI PandasAI lancedb Extension

A SQL injection vulnerability exists in Sinaptik AI PandasAI up to version 0.1.4 within the pandasai-lancedb Extension, allowing remote exploitation through manipulation of multiple functions in the lancedb.py file.

sql-injection vulnerability pandasai
2r 1t
high advisory

Clerk SSRF Vulnerability in frontendApiProxy Allows Secret Key Leakage

A server-side request forgery (SSRF) vulnerability exists in the `clerkFrontendApiProxy` function of the `@clerk/backend` package, allowing an unauthenticated attacker to send the application's `Clerk-Secret-Key` to an attacker-controlled server.

ssrf vulnerability clerk cloud
2r 1t
high advisory

LangChain Core Path Traversal Vulnerability in Legacy APIs

A path traversal vulnerability in LangChain Core's legacy `load_prompt` functions allows attackers to read arbitrary files by injecting malicious paths into prompt configurations.

langchain path-traversal vulnerability
1r 1t
high advisory

OpenClaw Gateway Plugin Grants Unrestricted operator.admin Runtime Scope

The openclaw gateway plugin versions 2026.3.24 and earlier incorrectly grants operator.admin runtime scope to all callers, regardless of their granted scopes, potentially allowing unauthorized actions.

openclaw privilege-escalation vulnerability
2r 1t
critical advisory

Giskard-agents ChatWorkflow.chat() Server-Side Template Injection

Giskard-agents versions 0.3.3 and earlier, and versions 1.0.1a1 through 1.0.2a1 are vulnerable to remote code execution via server-side template injection where the ChatWorkflow.chat() method passes user-supplied strings directly to a non-sandboxed Jinja2 Environment, allowing attackers to execute arbitrary code on the server.

ssti jinja2 rce giskard-agents vulnerability
2r 1t
high advisory

LinkAce Server-Side Request Forgery Vulnerability (CVE-2026-33953)

LinkAce versions prior to 2.5.3 are vulnerable to server-side request forgery (SSRF), allowing an authenticated user to trigger server-side requests to internal services by referencing internal hostnames.

ssrf linkace vulnerability
2r 1t
high advisory

Langflow IDOR Vulnerability Allows Cross-User Flow Manipulation

Langflow versions 1.5.0 and earlier contain an IDOR vulnerability (CVE-2026-34046) that allows authenticated users to read, modify, and delete flows belonging to other users due to a missing ownership check, potentially exposing sensitive information and enabling unauthorized control over AI agent logic.

idor langflow vulnerability
2r 3t
high advisory

Postiz App SSRF Vulnerability via Next.js

A high-severity SSRF vulnerability exists in the Postiz application via Next.js, allowing attackers to bypass firewalls, scan internal networks, access sensitive cloud metadata (AWS IMDS), potentially leak instance credentials, and pivot within the internal network.

ssrf vulnerability cloud
2r 1t
critical advisory

Multiple Vulnerabilities in Canva Affinity, TP-Link, and HikVision Devices

Cisco Talos disclosed multiple vulnerabilities in Canva Affinity, TP-Link Archer AX53, and HikVision Ultra Face Recognition Terminal products which could lead to sensitive information disclosure, arbitrary code execution, or credentials leak if exploited.

vulnerability code-execution information-disclosure
3r 6t
high advisory

OpenClaw Symlink Traversal via IDENTITY.md appendFile in agents.create/update

OpenClaw is vulnerable to symlink traversal via IDENTITY.md appendFile in agents.create/update. An attacker who can place a symlink in the agent workspace can hijack the IDENTITY.md path to append attacker-controlled content to arbitrary files on the system leading to remote code execution, persistent code execution, unauthorized SSH access, or service disruption.

openclaw symlink-traversal vulnerability npm rce persistence
2r 2t
high advisory

LIBPNG Out-of-Bounds Read/Write Vulnerability in Neon Optimization (CVE-2026-33636)

An out-of-bounds read and write vulnerability in LIBPNG's ARM/AArch64 Neon-optimized palette expansion path (CVE-2026-33636) allows attackers to potentially achieve denial-of-service or arbitrary code execution by crafting malicious PNG images.

libpng png oob CVE-2026-33636 vulnerability defense-evasion privilege-escalation
2r 2t
critical advisory

Critical Vulnerabilities in n8n Workflow Automation Tool

Multiple critical vulnerabilities in n8n, including prototype pollution, code injection, and SQL injection, allow authenticated users to achieve remote code execution, read sensitive files, and perform unauthorized database operations.

n8n vulnerability rce sqli code-injection
3r 2t
high advisory

Doveadm Credentials Vulnerable to Timing Oracle Attack (CVE-2026-27856)

Doveadm credentials are verified using direct comparison, making it susceptible to timing oracle attacks, allowing attackers to determine credentials and gain full access.

vulnerability timing oracle credential access doveadm
2r 1t
high advisory

OpenClaw ACP Chat Command Injection Vulnerability

A vulnerability in the openclaw npm package before version 2026.3.22 allowed mutating internal ACP chat commands without requiring operator.admin scope enforcement, potentially allowing unauthorized control-plane actions.

openclaw acp chat-command-injection vulnerability
2r
high advisory

OpenClaw Nostr DM Unauthorized Crypto Computation Vulnerability

The openclaw npm package before version 2026.3.22 allows unauthorized pre-authentication computation due to improper handling of inbound Nostr DMs, where crypto and dispatch work are performed before enforcing sender and pairing policies.

supply-chain vulnerability npm
2r
high advisory

KomSeo Cart 1.3 SQL Injection Vulnerability

KomSeo Cart 1.3 is vulnerable to SQL injection via the 'my_item_search' parameter in edit.php, allowing attackers to inject SQL commands and extract sensitive database information.

sqli vulnerability web-application
2r 1t
high advisory

ASP.NET jVideo Kit 1.0 SQL Injection Vulnerability

ASP.NET jVideo Kit 1.0 is vulnerable to SQL injection via the 'query' parameter in the search functionality, allowing unauthenticated attackers to inject malicious SQL payloads to extract sensitive database information.

sql-injection vulnerability asp.net
2r 1t
critical advisory

School Management System CMS 1.0 SQL Injection Vulnerability

School Management System CMS 1.0 is vulnerable to SQL injection in the admin login functionality, allowing attackers to bypass authentication by injecting SQL code through the username parameter.

sql-injection web-application vulnerability
2r 1t
high advisory

SQL Injection Vulnerability in Simple Laundry System 1.0

A remote SQL Injection vulnerability exists in code-projects Simple Laundry System 1.0 within the Parameter Handler component's /checkregisitem.php file, where manipulating the Long-arm-shirtVol argument can trigger the injection, with a publicly available exploit.

sqli web-application vulnerability
2r 1t
high advisory

SQL Injection Vulnerability in itsourcecode Online Enrollment System 1.0

A remote SQL injection vulnerability exists in itsourcecode Online Enrollment System 1.0 within the Parameter Handler component affecting the `/sms/grades/index.php` file, allowing unauthorized database access and has been publicly disclosed.

sqli vulnerability web-application
2r 1t
critical advisory

Netcore Power 15AX Remote Command Execution Vulnerability

CVE-2026-4840 is a critical command injection vulnerability in the Netcore Power 15AX router that allows remote attackers to execute arbitrary OS commands by manipulating the IpAddr argument in the setTools function of the /bin/netis.cgi file.

command-injection rce vulnerability netcore router
2r 1t
high advisory

OpenEMR Blind SQL Injection Vulnerability in Patient Search (CVE-2026-29187)

OpenEMR versions prior to 8.0.0.3 are susceptible to a blind SQL injection vulnerability in the Patient Search functionality, allowing authenticated attackers to execute arbitrary SQL commands by manipulating HTTP parameter keys.

sqli openemr vulnerability
2r 1t
critical advisory

SiYuan Arbitrary Document Reading Vulnerability in Publishing Service

SiYuan is vulnerable to arbitrary document reading via the publishing service, allowing attackers to retrieve document IDs and view the content of all documents, including encrypted or prohibited ones, by exploiting the `/api/file/readDir` and `/api/block/getChildBlocks` interfaces.

siyuan arbitrary-document-access vulnerability webserver
2r 1t
high advisory

Kiteworks Core Access Control Vulnerability (CVE-2026-23514)

Kiteworks Core versions 9.2.0 and 9.2.1 contain an access control vulnerability (CVE-2026-23514) due to improper ownership management, allowing authenticated users to access unauthorized content, which can be mitigated by upgrading to version 9.2.2 or later.

access-control vulnerability kiteworks
2r 1t
critical advisory

Multiple Vulnerabilities in GnuPG and Gpg4win Allow for Arbitrary Code Execution and Denial of Service

Multiple vulnerabilities exist in GnuPG and Gpg4win that could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

gnupg gpg4win vulnerability code-execution denial-of-service
2r 2t
high advisory

Langflow Path Traversal Vulnerability (CVE-2026-33497)

A path traversal vulnerability in Langflow versions before 1.7.1 allows unauthenticated attackers to read sensitive files via the download_profile_picture endpoint due to insufficient filtering of the folder_name and file_name parameters.

path-traversal vulnerability web-application
2r 1t
critical advisory

GoHarbor Harbor v2.15.0 and Below Vulnerable to Hardcoded Credentials

GoHarbor Harbor version 2.15.0 and below is vulnerable to the use of hard-coded credentials, allowing an attacker to use the default password and gain unauthorized access to the web UI.

vulnerability hardcoded-credentials goharbor
2r 1t
medium advisory

CPython Zipfile Module Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in the zipfile module of CPython to manipulate files on affected systems.

cpython zipfile file-manipulation vulnerability
2r 1t
high advisory

IBM WebSphere Application Server Liberty Multiple Vulnerabilities

A remote, authenticated attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server Liberty to escalate privileges, bypass security measures, and disclose information.

websphere vulnerability privilege-escalation defense-evasion information-disclosure
2r 3t
high advisory

TIBCO ActiveMatrix Vulnerability Allows Information Disclosure and Data Manipulation

A remote, authenticated attacker can exploit a vulnerability in TIBCO ActiveMatrix and TIBCO Administrator to disclose information and manipulate data, potentially leading to unauthorized access and control.

tibco vulnerability information-disclosure data-manipulation
2r 2t
critical advisory

Langflow Vulnerability Allows Arbitrary Code Execution

A vulnerability in Langflow allows an attacker to execute arbitrary code, potentially leading to system compromise.

langflow code-execution vulnerability
2r 1t
critical advisory

Multiple Vulnerabilities in Redis

Multiple vulnerabilities in Redis allow an attacker to execute arbitrary program code and perform a denial-of-service attack.

redis vulnerability code execution denial of service
2r 2t
critical advisory

Multiple Vulnerabilities in Red Hat Developer Hub

Multiple vulnerabilities in Red Hat Developer Hub allow a remote attacker to perform denial of service, execute arbitrary code, bypass security measures, and manipulate data.

redhat developer hub vulnerability denial of service code execution
2r 8t
high advisory

Multiple Vulnerabilities in Grub Bootloader

Multiple vulnerabilities in the Grub bootloader allow attackers to execute arbitrary code and cause denial-of-service conditions.

bootloader grub2 vulnerability denial-of-service arbitrary-code-execution
2r 2t
critical advisory

Multiple Vulnerabilities in Apache Tomcat Allow for Remote Code Execution and Data Manipulation

Multiple vulnerabilities in Apache Tomcat can be exploited by a remote, authenticated or anonymous attacker to execute arbitrary code, bypass security measures, manipulate data, and cause a denial of service.

apache-tomcat vulnerability remote-code-execution data-manipulation denial-of-service
2r 3t
medium advisory

Red Hat OpenShift GitOps Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift GitOps to manipulate data, misrepresent information, or cause a denial of service.

openshift gitops vulnerability cloud
2r 1t
critical advisory

IBM Tivoli Netcool/OMNIbus Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus to achieve arbitrary code execution, information disclosure, file manipulation, or denial of service.

ibm tivoli netcool omnibus vulnerability code-execution dos
2r 3t
high advisory

Checkmk Vulnerability Allows Session Hijacking

An authenticated remote attacker can exploit a vulnerability in Checkmk to bypass security measures, leading to session hijacking.

checkmk session-hijacking vulnerability
2r 1t
high advisory

Multiple Vulnerabilities in Vim Allow Local Code Execution and DoS

Multiple vulnerabilities in vim allow a local attacker to execute arbitrary code, cause a denial-of-service condition, or manipulate data.

vim vulnerability code execution denial of service
2r 2t
critical advisory

Multiple Vulnerabilities in Langflow Allow for Arbitrary Code Execution and Information Disclosure

Multiple vulnerabilities in Langflow could be exploited by an attacker to execute arbitrary program code, disclose information, and potentially manipulate data, leading to potential system compromise.

langflow vulnerability code-execution information-disclosure
2r 4t
high advisory

Froxlor Vulnerability Allows File Manipulation and Information Disclosure

A vulnerability in Froxlor allows an attacker to manipulate files and disclose sensitive information, potentially leading to data breaches or system compromise.

froxlor vulnerability file-manipulation information-disclosure
2r 1t
critical advisory

CODESYS Multiple Vulnerabilities Allow Arbitrary Code Execution and DoS

Multiple vulnerabilities in CODESYS allow a remote attacker to execute arbitrary program code and conduct a denial-of-service attack.

codesys vulnerability arbitrary-code-execution denial-of-service ics
2r 2t
critical advisory

Multiple Vulnerabilities in GStreamer

Multiple vulnerabilities in GStreamer allow a remote, anonymous attacker to cause a denial-of-service condition, memory corruption, and potentially execute arbitrary code.

gstreamer vulnerability denial-of-service memory-corruption code-execution
3r 2t
critical advisory

Critical Unauthenticated RCE Vulnerability Exploited in Microsoft SharePoint

A remote code execution vulnerability in Microsoft SharePoint (CVE not specified) is being actively exploited by unauthenticated attackers, prompting urgent patching recommendations for internet-facing servers.

sharepoint rce vulnerability
2r 2t
high advisory

Out-of-Cancel Vulnerability Class in Linux Workqueue Cancellation APIs

The 'Out-of-Cancel' vulnerability class stems from flaws in Linux workqueue cancellation APIs, potentially leading to exploitable conditions within the kernel.

linux kernel vulnerability workqueue
2r 1t
high advisory

Craft CMS Authenticated Remote Code Execution via Malicious Attached Behavior

A remote code execution vulnerability exists in Craft CMS versions 5.6.0 through 5.9.12, where any authenticated user with control panel access can exploit the vulnerability by injecting malicious behavior via the `fieldLayouts` parameter in `ElementIndexesController::actionFilterHud()` due to the unsanitized parameter being passed to `FieldLayout::createFromConfig()`.

craftcms rce vulnerability webserver
2r 1t
critical advisory

Vikunja Account Reactivation Vulnerability (CVE-2026-33316)

A critical vulnerability in Vikunja versions prior to 2.2.0 allows disabled users to bypass administrator controls and reactivate their accounts by exploiting a flaw in the password reset logic.

vikunja account-reactivation vulnerability
3r 1t
critical advisory

Uninitialized Memory Vulnerability in Firefox Canvas2D (CVE-2026-4715)

CVE-2026-4715 is a critical vulnerability involving uninitialized memory in the Graphics: Canvas2D component of Firefox, Firefox ESR, and Thunderbird, potentially leading to information disclosure or arbitrary code execution.

cve-2026-4715 firefox thunderbird uninitialized-memory vulnerability
2r
medium advisory

Mozilla Firefox and Thunderbird Graphics Text Component Vulnerability (CVE-2026-4719)

CVE-2026-4719 describes an incorrect boundary condition in the Graphics: Text component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition in vulnerable versions.

cve vulnerability firefox thunderbird
2r 2t
critical advisory

Multiple Vulnerabilities in Cpython Allow Remote Code Execution

A remote, authenticated attacker can exploit multiple vulnerabilities in Cpython to manipulate files or execute arbitrary code.

cpython vulnerability code execution
2r 1t
critical advisory

Oracle MySQL Multiple Vulnerabilities

A remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle MySQL to compromise confidentiality, integrity, and availability.

mysql vulnerability database
2r 1t
high advisory

libpng Vulnerability Allows Code Execution

A vulnerability in libpng allows a remote, anonymous attacker to potentially execute arbitrary code, disclose sensitive information, or cause a denial-of-service condition.

libpng code-execution vulnerability
2r 4t
critical advisory

Citrix Systems NetScaler Vulnerabilities Allow Information Disclosure and Session Hijacking

An anonymous or authenticated remote attacker can exploit multiple vulnerabilities in Citrix Systems NetScaler to disclose information and take over a user session.

citrix netscaler vulnerability session-hijacking information-disclosure
2r 2t
critical advisory

PhreeBooks ERP 5.2.3 Remote Code Execution Vulnerability

PhreeBooks ERP 5.2.3 is vulnerable to remote code execution, allowing authenticated attackers to upload and execute arbitrary PHP files via the image manager, leading to reverse shell connections and system command execution.

rce vulnerability php
2r 3t
critical advisory

Netartmedia Vlog System SQL Injection Vulnerability

Netartmedia Vlog System is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter in the forgotten_password module.

sqli vulnerability web-application
2r 1t 1i
critical advisory

Bootstrapy CMS Unauthenticated SQL Injection Vulnerabilities

Bootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters to extract sensitive database information or cause denial of service.

sql-injection bootstrapy-cms vulnerability
3r 1t
high advisory

AIDA64 Extreme 5.99.4900 Structured Exception Handler Buffer Overflow

AIDA64 Extreme 5.99.4900 is vulnerable to a structured exception handler buffer overflow, allowing local attackers to execute arbitrary code by supplying a malicious CSV log file path through the Hardware Monitoring logging preferences.

aida64 buffer-overflow vulnerability
2r 1t 1i
high advisory

Multiple Vulnerabilities in cPanel/WHM

An anonymous remote attacker can exploit multiple vulnerabilities in cPanel/WHM to bypass security measures, perform XSS and SSRF attacks, disclose information, and potentially execute code.

cPanel WHM XSS SSRF vulnerability
2r 2t
critical advisory

ReviewX WordPress Plugin Arbitrary Method Call Vulnerability

The ReviewX WordPress plugin is vulnerable to arbitrary method calls, allowing unauthenticated attackers to potentially achieve remote code execution.

wordpress woocommerce reviewx rce vulnerability
2r 1t
critical advisory

Oracle Fusion Middleware RCE Vulnerability (CVE-2026-21992)

CVE-2026-21992 allows an unauthenticated attacker to gain network access via HTTP and execute code remotely on Oracle Identity Manager and Oracle Web Services Manager.

vulnerability rce oracle
2r 2t
medium advisory

cURL Vulnerability Allows File Manipulation

A remote, anonymous attacker can exploit a vulnerability in cURL to manipulate files on a vulnerable system.

curl vulnerability file-manipulation
2r 2t
critical advisory

Multiple Vulnerabilities in libpng Allow Remote Code Execution and Denial of Service

Multiple vulnerabilities in libpng allow a remote, anonymous attacker to perform denial of service attacks and execute arbitrary code.

libpng vulnerability denial-of-service code execution
2r 2t
critical advisory

GIMP Vulnerability Allows Remote Code Execution

A remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary code on a targeted system.

gimp code-execution vulnerability
2r 1t
high advisory

Multiple Vulnerabilities in FreeRDP Allow for DoS and Potential Code Execution

A remote, anonymous attacker can exploit multiple vulnerabilities in FreeRDP to cause a denial of service or potentially execute arbitrary program code.

freerdp rdp vulnerability denial-of-service code-execution
2r 2t
medium advisory

Apache Commons FileUpload Denial of Service Vulnerability

A remote, anonymous attacker can exploit a vulnerability in Apache Commons FileUpload to perform a denial of service attack.

apache commons-fileupload denial-of-service vulnerability
2r 1t
medium advisory

Apache Commons BeanUtils Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Apache Commons BeanUtils to bypass security measures, potentially leading to unauthorized access or privilege escalation.

apache-commons-beanutils vulnerability security-bypass
1r 1t
high advisory

Out-of-bounds Write Vulnerability in DualSenseY-v2

CVE-2026-33850 is an out-of-bounds write vulnerability in WujekFoliarz DualSenseY-v2 before version 54, potentially allowing an attacker to execute arbitrary code or cause a denial-of-service by writing data outside the allocated buffer.

cve vulnerability oob-write dualsensey-v2
2r 3t
high advisory

SourceCodester Online Admission System 1.0 SQL Injection Vulnerability

A SQL injection vulnerability in SourceCodester Online Admission System 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'program' argument in the /programmes.php file.

sql-injection web-application vulnerability
2r 1t 1i
medium advisory

Citrix NetScaler ADC and Gateway Vulnerabilities

Citrix has released a security advisory addressing multiple vulnerabilities in NetScaler ADC and NetScaler Gateway that could lead to sensitive information disclosure and user session mix-up under specific configurations.

citrix netscaler vulnerability information-disclosure
2r
high advisory

Erupt Framework SQL Injection Vulnerability (CVE-2026-4594)

A SQL injection vulnerability (CVE-2026-4594) exists in erupts erupt up to version 1.13.3, allowing remote attackers to execute arbitrary SQL commands by manipulating the sort.field argument in the geneEruptHqlOrderBy function.

sql-injection vulnerability erupt
2r 1t
high advisory

WWBN AVideo Unauthorized File Access and Deletion Vulnerability

WWBN AVideo platform versions up to 26.0 are vulnerable to unauthorized file access and deletion, where an authenticated user with upload permissions can exploit the `objects/import.json.php` endpoint by manipulating the `fileURI` parameter to steal private video files, read adjacent text files, and delete `.mp4` and other writable files on the filesystem.

avideo file-access vulnerability
2r 2t
high advisory

Xenstore Crash Vulnerability via Malicious Node Path Access (CVE-2026-23555)

A guest VM issuing a Xenstore command with the node path '/local/domain/' can crash xenstored (CVE-2026-23555), or, if NDEBUG is defined, cause denial of service by consuming all CPU resources.

xen xenstore denial-of-service CVE-2026-23555 hypervisor vulnerability linux
2r 1t
high advisory

Jsrsasign < 11.1.1 Incorrect Conversion Vulnerability (CVE-2026-4602)

Jsrsasign versions before 11.1.1 are vulnerable to an incorrect conversion between numeric types vulnerability, where an attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.

jsrsasign vulnerability signature-bypass
2r 1t
high advisory

Jsrsasign Infinite Loop Vulnerability (CVE-2026-4598)

Jsrsasign versions before 11.1.1 are vulnerable to an infinite loop via the bnModInverse function when processing zero or negative inputs, potentially leading to a denial of service.

denial-of-service javascript node.js jsrsasign vulnerability
2r 1t
critical advisory

Critical Vulnerabilities in Quest KACE SMA Allow System Takeover

Multiple critical vulnerabilities in Quest KACE Systems Management Appliance (SMA), including authentication bypass and 2FA bypass, allow unauthenticated attackers to achieve system takeover and cause denial of service; active exploitation is reported.

quest-kace vulnerability authentication-bypass 2fa-bypass denial-of-service sma
2r 4t
high advisory

Vulnerabilities in Paxton Net2 Access Control Units

Vulnerabilities in Paxton Net2 Access Control Units (ACUs) could allow unauthorized remote access and control of secured doors, potentially affecting prisons and other high-security facilities.

access-control physical-security vulnerability
2r 8t 1i
high advisory

Memory Exhaustion Vulnerability in Widely Used Python Library

A memory exhaustion vulnerability (CVE-2026-33155) exists in a widely used Python library, affecting services like SageMaker, DataHub, and acryl-datahub due to an incomplete patch for CVE-2025-58367, requiring pinning to version 8.6.2.

memory-exhaustion vulnerability denial-of-service python supply-chain
2r 1t
high advisory

Vulnerabilities Disclosed in IP KVM Devices from Multiple Vendors

Researchers have disclosed unspecified vulnerabilities in IP KVM devices from four manufacturers, potentially allowing attackers to gain unauthorized access to connected systems.

ip-kvm vulnerability remote-access
2r 2t
critical advisory

Critical XSS Vulnerabilities in AFFiNE

Two critical XSS vulnerabilities, Reflected XSS in the /image-proxy endpoint and Stored XSS in bookmark cards, were discovered in AFFiNE, a self-hosted alternative to Notion, with the vendor being unresponsive.

xss vulnerability affine
2r 1t 2i
high advisory

ScreenConnect 26.1 Cryptographic Material Protection Vulnerability

ScreenConnect version 26.1 has a vulnerability related to the insufficient protection of server-level cryptographic material, potentially allowing unauthorized access and data compromise.

screenconnect vulnerability cryptographic-material
2r 1t
high advisory

Angular Cross-Site Scripting (XSS) Vulnerability

A cross-site scripting (XSS) vulnerability exists in Angular versions prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, allowing attackers to execute arbitrary code within the context of the vulnerable application, potentially leading to session hijacking, data exfiltration, and unauthorized actions.

angular xss vulnerability
2r 5t
critical advisory

Multiple Critical Vulnerabilities in Veeam Backup & Replication Allow Remote Code Execution

Multiple critical vulnerabilities in Veeam Backup & Replication, including CVE-2026-21666, CVE-2026-21668, CVE-2026-21669, CVE-2026-21670, CVE-2026-21671, CVE-2026-21672, and CVE-2026-21708, allow for remote code execution, privilege escalation, and arbitrary file manipulation by authenticated users, potentially leading to a complete compromise of the backup infrastructure.

veeam rce vulnerability privilege-escalation
2r 3t
high threat

CISA Adds Google Skia and Chromium V8 Vulnerabilities to KEV Catalog

CISA added CVE-2026-3909, an out-of-bounds write vulnerability in Google Skia, and CVE-2026-3910, an unspecified vulnerability in Google Chromium V8 to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation, highlighting the need for timely remediation.

vulnerability chrome skia cve-2026-3909 cve-2026-3910
2r 3t
critical advisory

Critical Unauthenticated RCE Vulnerability in Junos OS Evolved

A critical unauthenticated remote code execution vulnerability, CVE-2026-21902, exists in Juniper Networks Junos OS Evolved PTX Series, allowing a network-based attacker to execute code as root, requiring immediate patching and increased monitoring.

junos rce vulnerability
2r 3t
critical advisory

Critical Vulnerabilities in n8n Workflow Automation Platform

Multiple critical vulnerabilities in n8n versions prior to 2.10.1, 2.9.3, and 1.123.22 enable authenticated users to execute arbitrary code and system commands, potentially leading to full system compromise.

n8n code-injection sql-injection vulnerability
3r 3t
critical advisory

Mobility46 Charging Station Vulnerabilities Allow Unauthorized Control and Disruption

Multiple vulnerabilities in Mobility46 charging stations allow attackers to gain unauthorized administrative control or disrupt charging services through missing authentication, improper authentication restrictions, insufficient session expiration, and exposed credentials.

mobility46 charging-station vulnerability ics
2r 3t 1i
critical advisory

EV2GO Charging Station Vulnerabilities Allow Impersonation and Denial of Service

Multiple vulnerabilities in EV2GO charging stations, including missing authentication and session management flaws, could allow attackers to impersonate stations, hijack sessions, and cause denial-of-service conditions.

ev2go charging-station vulnerability denial-of-service
2r 3t 1i
critical advisory

Critical RCE Vulnerability in Cisco Catalyst SD-WAN Controller

A critical remote code execution vulnerability exists in Cisco Catalyst SD-WAN Controllers (CVE-2026-20127) due to improper authentication, allowing unauthenticated remote attackers to bypass authentication and gain administrative privileges, potentially leading to network configuration manipulation.

cisco sd-wan rce vulnerability
2r 2t
critical advisory

Multiple Vulnerabilities in EV Energy ev.energy Charging Stations

Multiple vulnerabilities exist in EV Energy ev.energy that could allow an attacker to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.

ev.energy charging-station ics vulnerability dos
2r
critical advisory

Multiple Vulnerabilities in Chargemap Charging Stations

Unauthenticated attackers can exploit multiple vulnerabilities in Chargemap's charging stations, including missing authentication, improper authentication attempt restrictions, insufficient session expiration, and unprotected credentials, potentially leading to unauthorized control and denial-of-service.

ics ot vulnerability denial-of-service
2r 5t 1i
critical advisory

Johnson Controls Frick Controls Quantum HD Multiple Vulnerabilities

Multiple vulnerabilities in Johnson Controls, Inc. Frick Controls Quantum HD versions <=10.22 can lead to pre-authentication remote code execution, information leak, or denial of service.

ics ot vulnerability
2r 4t
critical advisory

Critical Vulnerabilities in SolarWinds Serv-U Allow Remote Code Execution

Multiple critical vulnerabilities in SolarWinds Serv-U MFT and FTP Server allow remote code execution, potentially leading to system compromise.

solarwinds serv-u rce vulnerability
2r 3t
critical advisory

Copeland XWEB and XWEB Pro Multiple Vulnerabilities

Multiple vulnerabilities in Copeland XWEB and XWEB Pro versions 1.12.1 and earlier could allow attackers to bypass authentication, inject commands, and execute arbitrary code, leading to complete system compromise.

copeland xweb vulnerability ics
2r 6t
critical advisory

Critical Vulnerabilities in FreeScout Help Desk Allow Remote Code Execution

Critical vulnerabilities, CVE-2026-27636 and CVE-2026-27637, exist in FreeScout Help Desk that could be exploited to achieve remote code execution, potentially leading to data exfiltration and system compromise.

freescout rce vulnerability apache
2r 2t
critical advisory

Ongoing Exploitation of Cisco SD-WAN Systems

Malicious actors are actively exploiting CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation and persistence on Cisco SD-WAN systems globally.

cisco-sdwan vulnerability exploitation network
3r 4t
high advisory

Potential Foxmail Exploitation Leading to Initial Access

This rule detects potential exploitation of Foxmail client to gain initial access and execute malicious code by monitoring for Foxmail client spawning child processes with arguments pointing to user-profile AppData paths or remote shares, indicating exploitation of a Foxmail vulnerability through a malicious email.

Foxmail client initial-access execution foxmail vulnerability
2r 1t
medium advisory

VMware Tanzu Spring Framework Multiple Vulnerabilities

An anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Framework to disclose information or circumvent security measures.

Tanzu Spring Framework spring-framework vulnerability information-disclosure
2r 2t
high advisory

Open WebUI Improper Authorization Control Vulnerability

Open WebUI version 0.1.105 is vulnerable to an improper authorization control issue, where user accounts with a `pending` status can bypass authorization checks and make authenticated API calls as a `user` context due to the application failing to properly validate the user's role beyond JWT validation.

Open WebUI authorization web-application vulnerability
2r 1t 1i
high advisory

libxml2 Vulnerability Allows XXE Attacks

A remote, anonymous attacker can exploit a vulnerability in libxml2 to manipulate files or cause a denial of service.

libxml2 xxe vulnerability
2r 2t
critical advisory

Grafana Vulnerability Allows Remote Code Execution

An authenticated remote attacker can exploit a vulnerability in Grafana to execute arbitrary code, potentially leading to system compromise and data exfiltration.

Grafana code-execution vulnerability
2r 1t
high advisory

VMware Tanzu Spring Framework Vulnerability Allows File Manipulation

An anonymous remote attacker can exploit a vulnerability in VMware Tanzu Spring Framework to manipulate files or disclose information.

Tanzu Spring Framework vmware spring-framework vulnerability
2r 1t
critical advisory

Apache Tomcat Vulnerability Allows Remote Code Execution

An anonymous, remote attacker can exploit an unspecified vulnerability in Apache Tomcat to achieve arbitrary code execution.

Apache Tomcat apache-tomcat rce vulnerability
2r 1t
high advisory

Oracle Fusion Middleware Multiple Vulnerabilities

An unauthenticated or authenticated remote attacker can exploit multiple vulnerabilities in Oracle Fusion Middleware to compromise confidentiality, integrity, and availability.

Fusion Middleware vulnerability oracle
2r 1t
medium advisory

Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure

Multiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.

Roundcube xss vulnerability
2r 1t 3c
high advisory

Phoenix Contact FL MGUARD Multiple Vulnerabilities

A remote attacker can exploit multiple vulnerabilities in Phoenix Contact FL MGUARD to escalate privileges, disclose sensitive information, or cause a denial-of-service condition.

FL MGUARD phoenix-contact vulnerability privilege-escalation information-disclosure denial-of-service
2r 3t
high advisory

NetScaler ADC and Gateway Vulnerabilities Lead to Session Mixup

A race condition vulnerability in NetScaler ADC and Gateway (CVE-2026-3055 and CVE-2026-4368) could lead to user session mixup, potentially allowing unauthorized access to sensitive information.

NetScaler ADC +1 netscaler citrix session-hijacking vulnerability
2r 1t
high advisory

zyx0814 FilePress SQL Injection Vulnerability (CVE-2026-8133)

A remote SQL injection vulnerability (CVE-2026-8133) exists in zyx0814 FilePress up to version 2.2.0 via the Shares Filelist API by manipulating the argument order, potentially leading to unauthorized data access or modification.

FilePress sql-injection vulnerability web-application
2r 1t 1c
high advisory

Open WebUI Cross-Instance Cache Poisoning Vulnerability

Open WebUI versions up to 0.8.12 are vulnerable to cross-instance cache poisoning when multiple instances share a Redis backend, allowing an attacker with admin access on one instance to overwrite cache values used by other instances, leading to data exfiltration and prompt injection attacks.

open-webui +1 cache-poisoning redis vulnerability
2r 2t
high advisory

phpseclib Library Vulnerable to Prime Number Generation Weakness

The phpseclib library has a vulnerability affecting prime number generation and primality testing, impacting versions >= 0.1.1 and < 1.0.23, >= 2.0.0 and < 2.0.47, and >= 3.0.0 and < 3.0.36, potentially leading to insecure cryptographic operations.

phpseclib/phpseclib cryptography vulnerability phpseclib prime_number
2r 1t
high advisory

Argo Workflows ConfigMap Sync Service Missing Authorization Vulnerability

The Sync Service's ConfigMap-backed provider in Argo Workflows performs zero authorization checks on all CRUD operations, allowing any authenticated user to create, read, update, and delete Kubernetes ConfigMaps containing synchronization limits, potentially leading to denial of service, workflow disruption, information disclosure, or arbitrary ConfigMap manipulation in Argo Workflows versions v4.0.0 to v4.0.4.

argo-workflows/v4 argo-workflows kubernetes configmap authorization vulnerability
2r 1t
critical advisory

GStreamer Multiple Vulnerabilities Allow for Remote Code Execution and Denial of Service

Multiple vulnerabilities in GStreamer allow a remote, anonymous attacker to cause a denial-of-service condition or execute arbitrary code.

GStreamer vulnerability denial-of-service remote-code-execution
2r 2t 5c
high advisory

WSO2 Products Vulnerable to XML External Entity (XXE) Injection via CVE-2024-2374

CVE-2024-2374 describes an XML External Entity (XXE) vulnerability in multiple WSO2 products, where improperly configured XML parsers allow attackers to inject malicious XML payloads to include external resources, leading to confidential file access, limited HTTP resource access, and denial-of-service attacks.

WSO2 xxe cve-2024-2374 xml vulnerability attack cloud network
2r 2t
high advisory

Azure Sign-In Log Bypass Vulnerabilities

A recently disclosed vulnerability allows attackers to bypass Azure sign-in logs, potentially masking malicious activity within cloud environments.

Azure sign-in bypass cloud security vulnerability
2r 2t 1i
critical advisory

MPPX Payment Bypass and Griefing Vulnerabilities

Multiple vulnerabilities in the `mppx` npm package (versions prior to 0.4.8) allow for payment bypass, transaction replay attacks, fee manipulation, signature bypass, and channel griefing, potentially leading to financial loss and service disruption.

mppx npm vulnerability payment bypass
2r 5t
high advisory

Red Hat Integration Camel for Spring Boot Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat Integration Camel for Spring Boot to compromise confidentiality, availability, and integrity.

Red Hat Integration Camel for Spring Boot redhat camel springboot vulnerability webserver
2r 1t
high advisory

Postiz File Upload Vulnerability Leads to Stored XSS (CVE-2026-40487)

An authenticated file upload validation bypass in Postiz prior to version 2.21.6 allows attackers to upload arbitrary HTML, SVG, or other executable file types by spoofing the `Content-Type` header, resulting in stored XSS and potential account takeover.

Postiz xss file-upload vulnerability cve-2026-40487
2r 5t 1c
high advisory

Oxia TLS Certificate Chain Validation Failure

Oxia's `trustedCertPool()` function fails to parse multi-certificate PEM bundles, leading to certificate chain validation failure and rejection of legitimate clients in mTLS deployments.

Oxia tls mtls certificate-validation vulnerability
2r 1t
high advisory

Matrimony Website Script M-Plus SQL Injection Vulnerabilities

Matrimony Website Script M-Plus is vulnerable to unauthenticated SQL injection via POST parameters, enabling attackers to extract sensitive data or execute arbitrary SQL commands.

Matrimony Website Script M-Plus sql-injection vulnerability web-application
2r 1t
critical advisory

DigitalOcean Droplet Agent Command Injection Vulnerability (CVE-2026-24516)

CVE-2026-24516 is a command injection vulnerability in DigitalOcean Droplet Agent through 1.3.2, allowing attackers to execute arbitrary OS commands with root privileges by manipulating metadata responses due to insufficient input validation in the troubleshooting actioner component.

DigitalOcean Droplet Agent command-injection vulnerability cloud
2r 3t 1i
medium advisory

DiceBear SVG Size Capping Bypass Leads to Denial of Service

A denial-of-service vulnerability exists in DiceBear versions prior to 9.4.2 due to a bypassable regex in the `ensureSize()` function, allowing attackers to craft SVGs that cause out-of-memory crashes during rendering on Node.js.

DiceBear +1 dos svg vulnerability
2r 1t
high advisory

changedetection.io XXE Vulnerability

A vulnerability in changedetection.io versions 0.54.9 and earlier allows a remote attacker to perform XML External Entity (XXE) attacks, potentially exposing sensitive local files.

changedetection.io XXE vulnerability
2r 1t
medium advisory

free5GC PCF Nil Pointer Dereference Vulnerability

A nil-pointer dereference vulnerability exists in free5GC's PCF when handling POST requests to `/npcf-smpolicycontrol/v1/sm-policies`. When a downstream UDR lookup returns a 404 error, the handler continues execution instead of returning, leading to a nil response struct dereference and a panic. This results in an HTTP 500 error for the request, but the PCF process continues running. The vulnerability is triggered by sending a POST request with input that causes the downstream UDR lookup to fail, such as an unknown DNN. This issue affects free5GC versions v4.1.0 and v4.2.1.

PCF denial-of-service vulnerability web-application
2r 1t 2i
critical advisory

OpenHarness Command Injection Vulnerability (CVE-2026-40502)

OpenHarness versions prior to commit dd1d235 are vulnerable to command injection, allowing remote gateway users with chat access to execute administrative commands and alter system permissions.

OpenHarness command-injection vulnerability
2r 1t 1c
high advisory

Connect-CMS Code Study Plugin Arbitrary Code Execution

An authenticated user of the Connect-CMS Code Study Plugin can execute arbitrary code due to a vulnerability (CVE-2026-32276) in versions 1.x before 1.41.1 and 2.x before 2.41.1, potentially leading to code execution on the server or information disclosure.

Connect-CMS code-execution vulnerability
2r 1t
high advisory

AVideo CDN Plugin Unauthenticated Configuration Modification

AVideo is vulnerable to unauthenticated configuration modification in its CDN plugin due to a bypassed key validation check when the default empty key is used, allowing modification of CDN URLs, storage credentials, and the authentication key itself.

AVideo cdn configuration-modification vulnerability
2r 3t
high advisory

Acrel EEMS Enterprise Power Operation and Maintenance Cloud Platform SQL Injection Vulnerability

A SQL injection vulnerability exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0 when manipulating the 'fCircuitids' argument in the '/SubstationWEBV2/main/elecMaxMinAvgValue' file, potentially allowing for remote code execution or data exfiltration.

EEMS Enterprise Power Operation and Maintenance Cloud Platform sql-injection web-application vulnerability
2r 1t 1c
high advisory

@fastify/middie Middleware Bypass Vulnerability via Duplicate Slashes

`@fastify/middie` versions 9.3.1 and earlier are vulnerable to middleware bypass via URLs with duplicate leading slashes due to improper handling of the deprecated `ignoreDuplicateSlashes` option, potentially allowing unauthorized access to protected resources.

Fastify +1 middie middleware-bypass vulnerability defense-evasion
2r 1t 1c
high advisory

Vite Arbitrary File Read Vulnerability via WebSocket

Vite versions 6.0.0 to 8.0.4 are vulnerable to arbitrary file read, allowing attackers to bypass access controls and retrieve the contents of arbitrary files on the server via the WebSocket path when the dev server is exposed to the network.

Vite file-read vulnerability websocket
2r 1t
high advisory

GitLab MCP Server Unauthenticated Access via SSE Transport

The @yoda.digital/gitlab-mcp-server's SSE transport lacks authentication and uses wildcard CORS, enabling unauthenticated attackers to execute arbitrary GitLab API calls using the operator's GitLab PAT, including destructive operations.

@yoda.digital/gitlab-mcp-server gitlab auth-bypass sse cors vulnerability
2r 2t
medium advisory

Simple Social Media Share Buttons CSRF Vulnerability (CVE-2026-34904)

A cross-site request forgery (CSRF) vulnerability exists in the Simple Social Media Share Buttons WordPress plugin (versions through 6.2.0), potentially allowing attackers to perform unauthorized actions on behalf of authenticated users.

Simple Social Media Share Buttons csrf wordpress plugin vulnerability
2r 1t 1c
high advisory

xmldom XML Node Injection via Comment Serialization

The xmldom library is vulnerable to XML node injection, allowing attackers to inject arbitrary XML nodes into serialized output by manipulating comment content; this is mitigated by using the `requireWellFormed` option in `serializeToString` after upgrading to version 0.8.13 or 0.9.10.

xmldom xml injection deserialization vulnerability
2r 1t
critical advisory

MindsDB Unrestricted File Upload Vulnerability (CVE-2026-7711)

CVE-2026-7711 allows for remote, unrestricted file uploads in MindsDB up to version 26.01 due to insufficient validation in the `exec` function of `proc_wrapper.py`, potentially leading to code execution or data exfiltration.

MindsDB cve vulnerability file-upload
2r 1t 1c
medium advisory

Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)

Langflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.

Langflow unauthenticated-access image-retrieval vulnerability
2r 1t
critical threat

MISP Modules Website CSRF Vulnerability

A critical Cross-Site Request Forgery (CSRF) vulnerability in the MISP Modules website allows an attacker to induce an authenticated user to submit unintended requests to the home endpoint, potentially modifying session query data.

misp-modules +1 csrf vulnerability web-application
2r 1t
high advisory

goxmlsig Vulnerability CVE-2026-33487 Loop Variable Capture

A vulnerability exists in goxmlsig versions prior to 1.6.0 related to loop variable capture in the `validateSignature` function when using older Go versions, leading to incorrect signature validation.

goxmlsig xml signature-bypass vulnerability
2r
medium advisory

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability

A cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) could allow attackers to execute arbitrary JavaScript within a user's session, potentially leading to unauthorized access to sensitive information.

Zimbra Collaboration Suite xss vulnerability zimbra
2r 1t 1c
high advisory

OpenClaw Lower-Trust Output Injection Vulnerability

A vulnerability in OpenClaw versions 2026.4.2 and earlier allows lower-trust runtime output to be injected into trusted system events, potentially leading to prompt injection.

OpenClaw prompt-injection vulnerability
2r
high advisory

NATS.io MQTT ACL Bypass Vulnerability

A vulnerability in NATS.io versions before v2.12.6 or v2.11.15 allows MQTT clients to bypass ACL checks for MQTT subjects due to ACLs not being applied in the `$MQTT.>` namespace, potentially allowing unauthorized access and control of MQTT communications.

NATS server nats.io mqtt acl-bypass vulnerability
2r 1t
high advisory

Mako Template Engine Path Traversal Vulnerability on Windows

A path traversal vulnerability exists in Mako versions 1.3.11 and earlier on Windows, allowing attackers to read arbitrary files outside the configured template directory by using backslashes in URIs to bypass directory traversal checks.

Mako path-traversal vulnerability windows
2r 1t
critical advisory

goshs SimpleHTTPServer SFTP Authentication Bypass Vulnerability (CVE-2026-40884)

goshs SimpleHTTPServer prior to version 2.0.0-beta.6 contains an SFTP authentication bypass vulnerability that allows unauthenticated network attackers to access files when the server is started with specific configuration parameters.

SimpleHTTPServer authentication-bypass sftp vulnerability network
2r 1t 1c
high advisory

Flowise DocumentStore IDOR Vulnerability

A mass assignment vulnerability in the DocumentStore creation endpoint of Flowise allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. By exploiting the implicit UPSERT operation, an attacker can overwrite existing DocumentStore objects, potentially leading to cross-workspace object takeover and broken object-level authorization (IDOR) in multi-tenant deployments.

Flowise idor mass-assignment vulnerability
2r 1t
high advisory

CVE-2026-31611: ksmbd Sub-Authority Validation Vulnerability

CVE-2026-31611 is a vulnerability in ksmbd, requiring at least three sub-authorities before reading sub_auth[2], potentially leading to unauthorized access or code execution.

cve-2026-31611 ksmbd smb vulnerability
2r 1t 1c
high advisory

Connect CMS Form Plugin Stored XSS Vulnerability

A stored cross-site scripting (XSS) vulnerability exists in the file field of the Form Plugin in Connect CMS versions 1.x series <= 1.41.0 and 2.x series <= 2.41.0, allowing arbitrary script execution in an administrator's browser, potentially leading to unauthorized actions or information theft.

Connect CMS +1 connect-cms stored-xss vulnerability form-plugin
2r
high advisory

ORY Oathkeeper Authentication Bypass Vulnerability (CVE-2026-33496)

ORY Oathkeeper before 26.2.0 is vulnerable to authentication bypass (CVE-2026-33496) due to cache key confusion in the `oauth2_introspection` authenticator, allowing attackers with a valid token to bypass authentication by reusing it with different introspection URLs.

Oathkeeper authentication-bypass vulnerability cache-poisoning cloud
2r 1t
high advisory

NATS Server MQTT Password Disclosure Vulnerability

The NATS server exposes MQTT passwords in plaintext via monitoring endpoints due to incorrect classification as JWTs, affecting versions before v2.12.6 or v2.11.15.

NATS server nats mqtt credential-access vulnerability
3r 1t
critical advisory

Intake Package Remote Code Execution via Malicious Catalog

A remote code execution vulnerability exists in Intake versions prior to 2.0.9 due to the automatic expansion of the `shell()` syntax within parameter default values during catalog parsing, allowing an attacker to execute arbitrary commands by loading a malicious catalog YAML file.

Intake rce vulnerability
2r 1t
high advisory

BigSweetPotatoStudio HyperChat AI Proxy Middleware Server-Side Request Forgery

A server-side request forgery (SSRF) vulnerability exists in BigSweetPotatoStudio HyperChat up to version 2.0.0-alpha.63, allowing a remote attacker to manipulate the 'baseurl' argument in the 'fetch' function of the AI Proxy Middleware component to make arbitrary HTTP requests.

HyperChat ssrf vulnerability webserver
2r 1t 1c
high advisory

Auth0.js SDK Improper Permission Checking Vulnerability

The Auth0.js SDK versions 8.11.0 to 9.32.0 improperly returns user profile information when provided a crafted invalid ID token, potentially bypassing access controls relying on Auth0 Actions.

auth0.js SDK auth0 sdk vulnerability authentication
2r 1t
critical threat

Atlassian Confluence CVE-2023-22515 Exploitation Attempt

Detection of CVE-2023-22515 exploitation attempts targeting Atlassian Confluence servers by sending crafted HTTP requests to specific vulnerable endpoints, potentially leading to unauthorized access and privilege escalation.

PoC confluence cve-2023-22515 privilege-escalation vulnerability
2r 1t 1c updated
high threat

PHPGurukul Online Course Registration 3.1 SQL Injection Vulnerability

A SQL injection vulnerability (CVE-2026-5814) exists in PHPGurukul Online Course Registration 3.1, allowing remote attackers to execute arbitrary SQL queries by manipulating the 'regno' argument in the /admin/check_availability.php file.

exploited Online Course Registration sql-injection web-application vulnerability
2r 1t 1c
medium advisory

CVE-2026-34293: Unspecified Vulnerability in Microsoft Product

CVE-2026-34293 is an unspecified vulnerability affecting a Microsoft product, for which details are currently unavailable, posing a potential risk to affected systems.

cve vulnerability microsoft
2r 1c
medium advisory

CVE-2026-31613 SMB Client Out-of-Bounds Read Vulnerability

CVE-2026-31613 is an out-of-bounds read vulnerability in the SMB client when parsing symlink error responses, requiring patching to prevent potential information disclosure or denial-of-service.

cve-2026-31613 smb out-of-bounds read vulnerability
2r 1t 1c
high advisory

AVideo CSRF Vulnerability Allows Admin Impersonation

AVideo versions 29.0 and prior contain a CSRF vulnerability in admin-only JSON endpoints, allowing attackers to perform unauthorized actions if they can lure a logged-in administrator to visit a malicious page.

AVideo csrf web-application vulnerability
2r 1t 1c
critical advisory

SiYuan Path Traversal Vulnerability (CVE-2026-40318)

SiYuan versions 3.6.3 and prior are vulnerable to path traversal (CVE-2026-40318), allowing attackers to delete arbitrary .json files on the server via the /api/av/removeUnusedAttributeView endpoint.

SiYuan path-traversal vulnerability
3r 1t 1c
high advisory

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability (CVE-2026-20133)

Cisco Catalyst SD-WAN Manager contains an information disclosure vulnerability (CVE-2026-20133) that could allow remote attackers to view sensitive information on affected systems, requiring immediate patching or mitigation.

Catalyst SD-WAN Manager cve vulnerability cisco sd-wan
2r 1t 1c
high advisory

OpenClaw Configuration Redaction Bypass Vulnerability

A vulnerability in the openclaw npm package before version 2026.4.14 allows authenticated clients with config read access to receive unredacted secrets due to bypasses in `sourceConfig` and `runtimeConfig` alias fields.

openclaw npm vulnerability redaction-bypass
2r
critical advisory

Mozilla Firefox and Thunderbird WebRTC Undefined Behavior Vulnerability (CVE-2026-4705)

An undefined behavior vulnerability in the WebRTC signaling component affects Mozilla Firefox and Thunderbird, potentially leading to arbitrary code execution.

Firefox +1 cve-2026-4705 webrtc thunderbird vulnerability
2r 3t 2i
high advisory

SiYuan Unauthorized Attribute View Deletion Vulnerability (CVE-2026-40259)

SiYuan versions 3.6.3 and below are vulnerable to unauthorized attribute view deletion via the /api/av/removeUnusedAttributeView endpoint, allowing authenticated users with publish-service RoleReader tokens to delete arbitrary attribute view definitions, leading to database view breakage and workspace rendering issues.

SiYuan attribute-deletion vulnerability webserver
2r 1c
high advisory

Rails Active Storage Vulnerability Allows Arbitrary File Deletion

A vulnerability in Rails Active Storage allows attackers to delete arbitrary files in the storage directory by exploiting glob metacharacters in blob keys passed to `Dir.glob`.

Active Storage rails active_storage file_deletion vulnerability
2r 1t
critical advisory

chatboxai chatbox Command Injection Vulnerability (CVE-2026-6130)

A command injection vulnerability (CVE-2026-6130) exists in chatboxai chatbox versions up to 1.20.0, allowing a remote attacker to execute arbitrary OS commands by manipulating the 'args/env' argument in the StdioClientTransport function, potentially leading to complete system compromise.

chatboxai chatbox command-injection vulnerability chatboxai CVE-2026-6130
2r 1t 1c
medium advisory

Web Server Potential Remote File Inclusion Activity

This rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths, potentially leading to information disclosure or further compromise.

Nginx +4 rfi webserver vulnerability
2r 2t
critical advisory

PraisonAI Browser Server Unauthenticated Session Hijacking Vulnerability

PraisonAI Browser Server is vulnerable to unauthenticated WebSocket client hijacking due to exposing the browser bridge on 0.0.0.0 by default and accepting WebSocket clients that omit the Origin header, allowing unauthorized remote use of a connected browser automation session.

PraisonAI Browser Server praisonai websocket session-hijacking vulnerability
2r 1t
high advisory

OpenClaw MCP Loopback Token Spoofing Vulnerability

A vulnerability in OpenClaw versions 2026.4.21 and earlier allows a non-owner loopback client to spoof the owner context by manipulating request headers, potentially gaining unauthorized access to owner-gated operations.

openclaw vulnerability npm token spoofing
2r 1t
high advisory

FlowiseAI API Chain SSRF Vulnerability

A Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components, allowing unauthenticated attackers to force the server to make arbitrary HTTP requests to internal and external systems by injecting malicious prompt templates.

FlowiseAI +2 ssrf prompt-injection vulnerability
2r 2t 2i
high advisory

Directus SSRF Vulnerability via IPv4-Mapped IPv6 Addresses

Directus versions before 11.16.0 are vulnerable to Server-Side Request Forgery (SSRF) due to a bypass in IP address validation using IPv4-Mapped IPv6 addresses, allowing attackers to access internal services and sensitive cloud metadata.

Directus <= 12.0.0 ssrf directus vulnerability
2r 1t 3i updated
critical advisory

ArchiveBox RCE via Unvalidated Configuration Overrides

ArchiveBox versions 0.8.6rc0 and earlier are vulnerable to remote code execution (RCE) due to unvalidated configuration overrides in the AddView (/add/ endpoint) allowing arbitrary command execution.

archivebox rce vulnerability
2r 1t
high advisory

GitPython Command Injection Vulnerability

GitPython versions 3.1.30 through 3.1.46 are vulnerable to command injection by passing attacker-controlled kwargs into `Repo.clone_from()`, `Remote.fetch()`, `Remote.pull()`, or `Remote.push()`, leading to arbitrary command execution due to bypassed safety checks.

GitPython command-injection vulnerability
2r 1t
high advisory

LangChain Unsafe Deserialization Vulnerability

LangChain is vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists, potentially leading to persistent chat-history poisoning, prompt injection, credential disclosure, or server-side requests.

langchain-core langchain deserialization vulnerability
2r 1t
high advisory

Netty HttpClientCodec Response Desynchronization Vulnerability

The Netty HttpClientCodec is vulnerable to response desynchronization when configured with HTTP/1.1 pipelining, HEAD requests, and the server sends 1xx responses, leading to a response body from one request being parsed as another and potentially unsafe socket reuse.

netty-codec-http +1 netty http desynchronization vulnerability
2r
critical advisory

YAFNET Pre-Handler Authorization Bypass Leads to SQL Injection

YAFNET's flawed authorization allows low-privileged users to execute arbitrary SQL commands via the `/Admin/RunSql` endpoint, potentially leading to data exfiltration, application modification, and denial-of-service.

YAFNET.Core sql-injection web-application vulnerability
2r 8t
high advisory

itsourcecode Electronic Judging System SQL Injection Vulnerability (CVE-2026-7555)

A remote SQL injection vulnerability (CVE-2026-7555) exists in itsourcecode Electronic Judging System 1.0 via manipulation of the Username argument in the /intrams/login.php file, potentially leading to unauthorized data access and modification.

Electronic Judging System 1.0 sql-injection vulnerability web-application
2r 1t 1c
high threat

CVE-2026-32073 - Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

CVE-2026-32073 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, enabling a locally authorized attacker to escalate privileges.

exploited Windows vulnerability privilege-escalation
2r 1t 1c
medium advisory

AWS ECR Container Scanning Reveals Low Severity Vulnerabilities

This analytic identifies low, informational, or unknown severity findings from AWS Elastic Container Registry (ECR) image scans using AWS CloudTrail logs, indicating potential vulnerabilities or misconfigurations in container images that could lead to unauthorized access or data breaches.

Elastic Container Registry aws ecr container vulnerability
2r 1t 1c
high advisory

SourceCodester Hotel Management System SQL Injection Vulnerability

A SQL injection vulnerability exists in SourceCodester Hotel Management System 1.0 in the /index.php/reservation/check component due to improper sanitization of the room_type parameter, allowing a remote attacker to execute arbitrary SQL commands.

Hotel Management System 1.0 sqli vulnerability web application
2r 1t 1c
critical advisory

Zebra Consensus Split Vulnerability Due to SIGHASH_SINGLE Handling

Zebra and zcashd disagree on a consensus rule for V5+ transparent spends related to SIGHASH_SINGLE handling when the input index has no corresponding output, leading to a consensus split where Zebra accepts invalid blocks rejected by zcashd.

Zebra +2 consensus vulnerability blockchain
2r
high advisory

Cocos AI Attested TLS Relay Attack Vulnerability (CVE-2026-33697)

A relay attack vulnerability, tracked as CVE-2026-33697, exists in the attested TLS (aTLS) implementation of Cocos AI, versions v0.4.0 through v0.8.2, allowing attackers to impersonate a legitimate service and potentially access sensitive data.

Cocos AI vulnerability relay attack attested TLS
2r 1t
critical threat

Weaver E-cology Arbitrary File Read Vulnerability (CVE-2022-50992)

Unauthenticated remote attackers can exploit an arbitrary file read vulnerability (CVE-2022-50992) in Weaver E-cology 9.5 versions prior to 10.52 via the XML-RPC endpoint to access sensitive files.

exploited E-cology 9.5 cve-2022-50992 file-read vulnerability webserver
2r 1t 1c
high advisory

TransformerOptimus SuperAGI Path Traversal Vulnerability

A path traversal vulnerability (CVE-2026-6615) exists in TransformerOptimus SuperAGI version 0.0.14, allowing remote attackers to read or write arbitrary files via manipulation of the 'Name' argument in the Multipart Upload Handler component.

TransformerOptimus SuperAGI path-traversal web-application vulnerability
2r 1t 1c
high advisory

Simple IT Discussion Forum 1.0 SQL Injection Vulnerability (CVE-2026-5672)

A remote SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 via manipulation of the cat_id parameter in the /edit-category.php file.

Simple IT Discussion Forum sql-injection web-application vulnerability
2r 1t 1c
high advisory

Server-Side Request Forgery in mcp-data-vis

A server-side request forgery (SSRF) vulnerability exists in AlejandroArciniegas' mcp-data-vis due to improper handling of HTTP requests, potentially allowing remote attackers to make arbitrary requests through the vulnerable server.

mcp-data-vis ssrf vulnerability
2r 1t 1c
critical advisory

Scramble Remote Code Execution via User-Controlled Input

Scramble versions 0.13.2 through 0.13.21 are vulnerable to remote code execution due to the evaluation of user-controlled input in validation rules during documentation generation, potentially allowing attackers to execute arbitrary PHP code.

scramble rce vulnerability php
3r 1t
high advisory

rust-openssl X509Ref::ocsp_responders Undefined Behavior Vulnerability

The `X509Ref::ocsp_responders` function in rust-openssl versions 0.9.7 to 0.10.78 returns OCSP responder URLs from a certificate's AIA extension without proper UTF-8 validation, leading to undefined behavior when processing certificates with non-UTF-8 OCSP URLs.

openssl vulnerability rust certificate
2r 1t
high advisory

rust-openssl Stack Buffer Overflow Vulnerability

The rust-openssl crate is vulnerable to a stack-based buffer overflow (CVE-2026-41681) where the `EVP_DigestFinal()` function writes beyond the allocated buffer, potentially corrupting the stack, affecting versions >= 0.10.39 and < 0.10.78.

openssl buffer overflow rust vulnerability
2r
high advisory

pygeoapi Unauthenticated SSRF Vulnerability in OGC API - Processes Subscriber

pygeoapi versions 0.23.0 to 0.23.2 contain an unauthenticated server-side request forgery (SSRF) vulnerability where OGC API process execution requests can use the subscriber object to make requests to internal HTTP services, which is resolved in version 0.23.3 by disabling internal requests by default.

pygeoapi ssrf ogc api cve-2026-42352 vulnerability cloud
2r 1t
high advisory

pygeoapi Path Traversal Vulnerability in STAC FileSystemProvider

A path traversal vulnerability exists in pygeoapi versions 0.23.0 to 0.23.2 within the STAC FileSystemProvider plugin, allowing unauthenticated access to directories when deployed without a URL-normalizing proxy.

pygeoapi path-traversal vulnerability webserver
2r 1t
high advisory

PrestaShop Stored XSS Vulnerability via Unprotected Template Variables

Multiple stored XSS vulnerabilities exist in PrestaShop, where an attacker with database access can exploit unprotected variables in back-office templates to execute malicious scripts in a user's browser.

PrestaShop xss vulnerability web-application
3r 1t
critical advisory

Patreon OAuth Provider ID Collision Vulnerability in go-pkgz/auth

The Patreon OAuth provider in go-pkgz/auth and go-pkgz/auth/v2 maps every authenticated Patreon account to the same local user ID, leading to cross-account access, privilege confusion, and subscription-state leakage.

auth +1 authentication oauth id_collision vulnerability
2r 1t
high advisory

PaperCut NG Remote Web Access Attempt Detection

This analytic detects potential exploitation attempts on publicly accessible PaperCut NG servers by identifying connections from public IP addresses to the server, specifically monitoring URI paths commonly used in proof-of-concept scripts for exploiting PaperCut NG vulnerabilities.

PaperCut NG papercut vulnerability webserver
2r 2t
critical advisory

Paperclip AI OS Command Injection via Execution Workspace cleanupCommand

A critical OS command injection vulnerability exists in Paperclip AI v2026.403.0 within the execution workspace lifecycle. By injecting arbitrary shell commands into the `cleanupCommand` field via the `PATCH /api/execution-workspaces/:id` endpoint, an attacker can execute these commands on the server when the workspace is archived.

Paperclip AI command-injection rce paperclip vulnerability
2r 1t
critical advisory

Ory Keto SQL Injection Vulnerability via GetRelationships API (CVE-2026-33505)

Ory Keto versions prior to 26.2.0 are vulnerable to SQL injection via the GetRelationships API due to flaws in its pagination implementation, enabling attackers with knowledge of the pagination secret (or the default secret) to craft malicious tokens leading to arbitrary SQL query execution.

Keto sql-injection vulnerability ory-keto cve-2026-33505
2r 1t
high advisory

Oracle PeopleSoft Enterprise PeopleTools Unauthorized Data Access Vulnerability (CVE-2026-34309)

CVE-2026-34309 is an easily exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.62, allowing a low-privileged attacker with network access via HTTP to gain unauthorized access to create, delete, or modify sensitive data.

PeopleSoft Enterprise PeopleTools peoplesoft rce vulnerability network
2r 1t 1c
high advisory

OpenClaw Matrix Profile Config Persistence Vulnerability

A vulnerability in the openclaw npm package before version 2026.4.10 allows unauthorized modification of Matrix profile configurations via the `operator.write` message tool.

openclaw npm vulnerability persistence
2r 1t
medium advisory

Netty HTTP/3 QPACK Literal Unbounded Allocation Vulnerability

A vulnerability in Netty's HTTP/3 QPACK decoder allows an attacker to cause a denial of service by sending a crafted HTTP/3 header that triggers excessive memory allocation, leading to a server crash.

netty-codec-http3 netty http3 qpack denial-of-service vulnerability
3r 1t
high advisory

MiroFish Command Injection Vulnerability (CVE-2026-7058)

A command injection vulnerability exists in 666ghj MiroFish version 0.1.2 via the SimulationIPCClient.send_command function, allowing remote attackers to execute arbitrary commands.

MiroFish command-injection vulnerability ipc
2r 1t 1c
medium advisory

Microsoft CVE-2017-3736 Vulnerability

CVE-2017-3736 is a vulnerability tracked by Microsoft, potentially leading to exploitation of affected systems.

vulnerability microsoft
2r
high advisory

mcp-dnstwist OS Command Injection Vulnerability (CVE-2026-7443)

An OS command injection vulnerability exists in BurtTheCoder's mcp-dnstwist version 1.0.4 and earlier due to improper handling of the Request argument in the fuzz_domain function within src/index.ts, potentially allowing remote attackers to execute arbitrary commands.

mcp-dnstwist command-injection vulnerability
2r 1t 1c
critical advisory

ManageEngine Log360 Authentication Bypass Vulnerability (CVE-2026-3324)

Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration, potentially allowing unauthorized access.

Log360 vulnerability authentication-bypass manageengine
2r 1t 1c
high advisory

lxml Library Vulnerable to XXE Attacks via iterparse() and ETCompatXMLParser()

lxml versions before 6.1.0 are vulnerable to XML External Entity (XXE) attacks when using iterparse() or ETCompatXMLParser() with default settings, potentially allowing local file reads.

lxml library lxml XXE vulnerability CVE-2026-41066
2r 1t
medium advisory

Katalyst Koi Session Cookies Replayable After Logout

Katalyst Koi versions before 4.20.0 and between 5.0.0 and 5.6.0 fail to invalidate admin session cookies upon logout, allowing attackers with a valid cookie to maintain unauthorized access.

katalyst-koi +2 session-replay vulnerability authentication
2r 1t
medium advisory

Gotenberg Denial of Service via Context Pool Reuse

Gotenberg versions 8.31.0 and earlier are vulnerable to an unauthenticated denial-of-service attack where a race condition in the webhook middleware causes a panic and process termination when handling concurrent requests.

Gotenberg denial-of-service vulnerability
2r 2t
high advisory

GNUTLS RSA-PSK Authentication Bypass Vulnerability (CVE-2026-42010)

A vulnerability in GNUTLS (CVE-2026-42010) allows a remote attacker to bypass authentication on servers configured with RSA-PSK by sending a specially crafted username containing a NUL character, leading to unauthorized access.

gnutls authentication-bypass vulnerability
2r 1t 1c
high advisory

Flight Framework SQL Injection Vulnerability

Flight framework is vulnerable to SQL Injection; an attacker can inject arbitrary SQL by crafting malicious array keys due to SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() building SQL statements by concatenating the $table argument and the keys of the $data array directly into the query, with no identifier quoting or validation, leading to privilege escalation, arbitrary column writes, data destruction, and exfiltration.

flightphp/core sql-injection web-application vulnerability
2r 2t
critical advisory

fast-jwt Authentication Bypass Vulnerability via Empty HMAC Secret

A critical vulnerability in the fast-jwt library allows attackers to forge JWTs by exploiting the acceptance of empty HMAC secrets in the async key resolver, leading to authentication bypass.

fast-jwt jwt authentication-bypass vulnerability
2r 2t
high advisory

Esri Portal for ArcGIS Privilege Escalation via CVE-2026-33518

Esri Portal for ArcGIS 11.5 on Windows and Linux is vulnerable to privilege escalation (CVE-2026-33518), allowing highly privileged users to create developer credentials with excessive permissions.

Portal for ArcGIS esri arcgis privilege-escalation CVE-2026-33518 vulnerability
2r 1t 1c
critical advisory

Dgraph Pre-Auth Full Database Exfiltration via DQL Injection

A pre-authentication DQL injection vulnerability in Dgraph's default configuration allows attackers to exfiltrate the entire database by crafting malicious JSON mutations to the `/mutate` endpoint, exploiting unsanitized language tags in predicates.

Dgraph dql-injection vulnerability
2r 6t
medium advisory

Detection of Abnormally Large DNS Responses Indicative of CVE-2020-1350 Exploitation

This rule detects abnormally large DNS responses indicative of exploitation attempts targeting a known overflow vulnerability (CVE-2020-1350) in Windows DNS servers, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS).

Windows DNS Server sigred dns-server vulnerability
2r 2t
medium advisory

Denial of Service Vulnerability in marked via Infinite Recursion

A denial of service vulnerability exists in marked version 18.0.0 due to infinite recursion when processing a specific 3-byte sequence (tab, vertical tab, and newline), leading to unbounded memory allocation and application crash.

marked denial-of-service javascript vulnerability
2r 1t
medium advisory

CVE-2026-28390 NULL Dereference in CMS KeyTransportRecipientInfo Processing

CVE-2026-28390 is a vulnerability related to a possible NULL pointer dereference when processing CMS KeyTransportRecipientInfo, potentially leading to a denial-of-service condition.

vulnerability denial-of-service
2r 1c
high advisory

CKAN Unauthenticated SQL Injection in datastore_search_sql

An unauthenticated SQL injection vulnerability in CKAN's `datastore_search_sql` function allows attackers to access private resources and PostgreSQL system information, affecting versions prior to 2.10.10 and versions 2.11.0 through 2.11.4.

ckan sql-injection vulnerability
2r 1t
high threat

ChatGPTNextWeb NextChat SSRF Vulnerability (CVE-2026-7178)

ChatGPTNextWeb NextChat versions up to 2.16.1 are vulnerable to server-side request forgery (SSRF) due to improper input validation in the storeUrl function, allowing remote attackers to potentially access internal resources or conduct other malicious activities.

exploited NextChat ssrf cve vulnerability web-application
2r 1t 1c
medium advisory

changedetection.io Arbitrary Local File Read via Crafted Backup Restore

changedetection.io is vulnerable to arbitrary local file read due to insufficient validation of snapshot paths restored from backup files, allowing attackers to read sensitive files by crafting a malicious backup archive containing a manipulated `history.txt` file.

changedetection.io arbitrary-file-read vulnerability
2r 1t
medium advisory

AWS ECR Container Scanning Reveals Medium Severity Vulnerabilities

AWS Elastic Container Registry (ECR) image scans reveal medium-severity vulnerabilities, potentially leading to unauthorized access and data breaches if exploited within containerized applications.

Elastic Container Registry cloud aws ecr container vulnerability
2r 1t 1c
high advisory

Arcane Unauthenticated Compose Template Content Disclosure

Arcane versions before 1.18.0 are vulnerable to an unauthenticated information disclosure on four GET endpoints under `/api/templates*`, allowing unauthorized access to Compose YAML and `.env` content including sensitive secrets.

Arcane information-disclosure vulnerability
2r 1t
high advisory

Aider-MCP Command Injection Vulnerability (CVE-2026-7316)

A command injection vulnerability (CVE-2026-7316) exists in eiliyaabedini aider-mcp, allowing remote attackers to execute arbitrary commands by manipulating the working_dir/editable_files argument in the aider_mcp.py file.

aider-mcp command-injection vulnerability
2r 1t 1c
high advisory

free5GC NEF Denial-of-Service via Unreachable notifyUri

free5GC's NEF component is vulnerable to a denial-of-service attack where an attacker can create a PFD subscription with an attacker-controlled `notifyUri`, and when a PFD change is triggered, NEF attempts to deliver a notification to the specified URI, and if the URI is unreachable, NEF terminates the entire process, causing a service outage, and this can be triggered without authentication in version 4.2.1, making it easily exploitable.

nef +1 dos vulnerability free5gc
2r 1t 1i
critical advisory

SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability

CVE-2026-6187 is a remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 via the ID parameter in /ajax.php?action=chk_prod_availability, allowing unauthenticated attackers to execute arbitrary SQL queries.

Pharmacy Sales and Inventory System sqli vulnerability web-application
2r 1t 1c
critical advisory

Rack::Session::Cookie Vulnerability Enables Secretless Session Forgery

Rack::Session::Cookie incorrectly handles decryption failures, falling back to a default decoder and allowing attackers to forge session cookies without knowing the secret, potentially leading to authentication bypass or privilege escalation in vulnerable Rack applications.

rack-session rack session cookie deserialization vulnerability privilege-escalation
2r 2t 1c
high advisory

Oracle Life Sciences Empirica Signal CVE-2026-21997 Vulnerability

CVE-2026-21997 allows a low-privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal versions 9.2.1-9.2.3, leading to unauthorized data access and modification with potential impact on other products.

Oracle Life Sciences Empirica Signal CVE-2026-21997 oracle empirica-signal vulnerability network
2r 1t 1c
high advisory

OpenClaw Synology Chat Reply Delivery Vulnerability

A vulnerability exists in OpenClaw versions prior to 2026.3.22 where Synology Chat reply delivery can be rebound to a mutable username match instead of the stable numeric user_id, potentially leading to information disclosure or privilege escalation.

OpenClaw +1 synology-chat vulnerability
2r
high advisory

OpenClaw Inconsistent Host Exec Environment Override Sanitization

OpenClaw versions before 2026.3.22 have an inconsistent host execution environment override sanitization, allowing blocked or malformed override keys to bypass sanitization, which could lead to unauthorized access or code execution.

OpenClaw sanitization vulnerability
2r 1t
critical advisory

Note Mark JWT Secret Weakness Allows Account Takeover

Note Mark is vulnerable to a JWT secret weakness that allows for full account takeover via token forgery by accepting secrets as short as 1 byte, enabling attackers to crack the signing secret offline and forge valid JWTs for any user.

note-mark/backend jwt account-takeover vulnerability
2r 2t
critical advisory

nginx-ui Backup Restore Allows Tampering with Encrypted Backups

The nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration, potentially leading to arbitrary command execution.

nginx-ui backup-tampering vulnerability
3r 2t
medium advisory

n8n Unauthenticated Denial of Service via MCP Client Registration

n8n is vulnerable to an unauthenticated denial of service (DoS) attack due to missing resource controls in the MCP OAuth client registration endpoint, allowing an attacker to exhaust server memory by sending large registration payloads, leading to service unavailability; this is resolved in versions 1.123.32, 2.17.4, and 2.18.1 and tracked as CVE-2026-42236.

n8n denial-of-service vulnerability
2r 1t
high advisory

n8n External Secrets Authorization Bypass Vulnerability

An authorization bypass vulnerability in n8n allows authenticated users without 'externalSecret:list' permission to retrieve plaintext values of external secrets when saving credentials, if the attacker knows or can guess the secret name.

n8n authorization-bypass vulnerability
2r 1t
high advisory

LMDeploy Vision-Language Module SSRF Vulnerability

A server-side request forgery (SSRF) vulnerability exists in LMDeploy's vision-language module, allowing attackers to access cloud metadata services and internal networks by exploiting the lack of URL validation in the `load_image()` function.

LMDeploy ssrf vulnerability
2r 1t 1c 4i
high advisory

livewire-markdown-editor Arbitrary File Upload Vulnerability

The livewire-markdown-editor versions before v1.3 contain an arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler, allowing authenticated users to upload any file type, potentially leading to stored XSS, phishing, malware distribution, and markdown injection.

mckenziearts/livewire-markdown-editor +3 arbitrary-file-upload stored-xss vulnerability
2r 1t
critical advisory

Graphiti JSONAPI Arbitrary Method Execution Vulnerability (CVE-2026-33286)

Graphiti versions prior to 1.10.2 are vulnerable to arbitrary method execution via maliciously crafted JSONAPI payloads, allowing attackers to invoke public methods on model instances, classes, or associations.

Graphiti jsonapi method-execution vulnerability
2r 1t
critical advisory

Gotenberg ExifTool Argument Injection via Metadata Values

Gotenberg version 8.30.1 and earlier is vulnerable to argument injection, where an unauthenticated attacker can inject arbitrary ExifTool pseudo-tags via newline characters in metadata values, leading to arbitrary file manipulation within the container filesystem.

Gotenberg <= 8.30.1 argument-injection vulnerability container
2r 1t
high advisory

FuelCMS Vulnerability Report

A vulnerability in FuelCMS has been reported, details available at pentesttools.com/blog/throwing-a-spark-in-fuelcms, potentially allowing attackers to compromise vulnerable systems.

FuelCMS vulnerability cms
2r 2t 1i
high advisory

free5GC SMF Unauthenticated State-Mutating Panic-DoS Vulnerability

free5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted DELETE request to the /upi/v1/upNodesLinks/{ref} endpoint triggers a nil-pointer dereference, causing a panic and mutating the in-memory user-plane topology, impacting the selection of UPFs for legitimate UE sessions.

free5GC SMF free5GC dos vulnerability
2r 2t 2i
critical advisory

FHIR Validator SSRF via /loadIG Leads to Credential Theft

The FHIR Validator HTTP service is vulnerable to server-side request forgery (SSRF) via the `/loadIG` endpoint, enabling attackers to steal authentication tokens by exploiting a prefix-matching flaw in the credential provider.

FHIR Validator ssrf fhir credential-theft vulnerability
2r 2t 1i
high advisory

epa4all-client Signature Verification Bypass Vulnerability

epa4all-client is vulnerable to a signature verification bypass where the ECDSA signature verification discards the boolean return value, allowing any structurally valid signature to be considered trusted.

epa4all-client signature-bypass vulnerability
2r
high advisory

Ella Core NGAP Message Handling Vulnerability Leads to Denial of Service

Ella Core versions prior to 1.6.0 are vulnerable to a denial-of-service attack where a crafted NGAP LocationReport message with a missing `UEPresenceInAreaOfInterestList` can crash the process, disrupting service for all connected subscribers.

Ella Core vulnerability denial-of-service 5G ellacore
3r 1t
high advisory

DevSpace UI Server WebSocket Origin Validation Vulnerability

DevSpace's UI server WebSocket accepts connections from any origin, enabling attackers to access pod logs, interactive shells, and execute commands via cross-origin WebSocket connections; versions up to 6.3.20 are affected, patched in 6.3.21.

DevSpace UI <= 6.3.20 websocket kubernetes vulnerability
2r 2t
high advisory

Detect-It-Easy Path Traversal Vulnerability (CVE-2026-43616)

Detect-It-Easy versions prior to 3.21 are vulnerable to path traversal, allowing attackers to write arbitrary files to the filesystem and potentially achieve code execution by crafting malicious archive entries.

Detect-It-Easy path-traversal vulnerability archive-extraction
2r 1t 1c
medium advisory

Decidim Amendment Manipulation Vulnerability (CVE-2026-40869)

CVE-2026-40869 allows authenticated users to manipulate amendments in Decidim versions 0.19.0 prior to 0.30.5 and 0.31.1, potentially hijacking authorship and impacting proposal integrity.

Decidim vulnerability amendment manipulation
2r 1t 1c
medium advisory

CVE-2017-3735 Vulnerability Targeting Microsoft Products

CVE-2017-3735 is a vulnerability impacting Microsoft products, potentially allowing unauthorized access or code execution.

vulnerability microsoft cve-2017-3735
2r 1t 1c
high advisory

Craft CMS Authenticated Remote Code Execution via Malicious Attached Behavior

Craft CMS versions before 4.17.12 and 5.9.18 are vulnerable to authenticated remote code execution via malicious behavior injection in the field layout hydration path.

cms +1 craft-cms rce vulnerability
2r 2t
critical advisory

CI4MS Theme Upload Zip Slip Vulnerability

A critical vulnerability exists in ci4ms Theme::upload, where improper validation of ZIP archive entry names allows authenticated users with theme creation permissions to write files to arbitrary locations, leading to remote code execution.

ci4-cms-erp/ci4ms zip-slip rce codeigniter vulnerability
2r 2t
high advisory

choieastsea simple-openstack-mcp OS Command Injection Vulnerability (CVE-2026-7066)

The choieastsea simple-openstack-mcp application is vulnerable to OS command injection via the exec_openstack function in server.py, allowing remote attackers to execute arbitrary commands.

simple-openstack-mcp command-injection vulnerability openstack
3r 1t 1c
high advisory

Apko DirFS Symlink Path Traversal Vulnerability

A symlink-following path traversal vulnerability exists in apko versions prior to 1.2.5 allowing a malicious .apk file to create a symbolic link pointing outside the build root and subsequently modify files on the host system.

apko path-traversal symlink vulnerability CVE-2026-42574
2r 1t
high advisory

WordPress Redsys Payment Gateway Plugin Vulnerable to Payment Forgery (CVE-2026-5050)

The Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to cryptographic signature forgery, allowing unauthenticated attackers to mark pending orders as paid by forging payment callback data in versions up to 7.0.0.

PoC LDAP authentication services wordpress woocommerce redsys payment-gateway vulnerability
2r 1t 1c 1i updated
critical advisory

OpenClaw Feishu Webhook Vulnerability: Unauthenticated Command Execution

OpenClaw versions before 2026.4.15 are vulnerable to unauthenticated webhook or card-action traffic due to missing encryption key configuration and improper handling of card-action callbacks, potentially allowing network-triggered access to OpenClaw command handling without Feishu signature or replay protection.

OpenClaw feishu webhook vulnerability
2r 1t
critical advisory

Gramps Web API Zip Slip Vulnerability in Media Archive Import

A path traversal vulnerability (Zip Slip) exists in the gramps-webapi media archive import feature, allowing authenticated users with owner privileges to write arbitrary files outside the intended temporary extraction directory via malicious ZIP files, potentially leading to data corruption or replacement.

Gramps Web API path-traversal zip-slip gramps-webapi vulnerability
2r 1t