Tag
Vulnerabilities in MISP cti-transmute
3 IOCsThe MISP project has patched multiple security vulnerabilities in the cti-transmute tool, including arbitrary file/network access and improper authorization controls for user management.
Improper Access Control in Atlas-Livre Admin Controllers
1 rule 2 TTPs 1 CVEAn unauthenticated access control flaw in Atlas-Livre allows attackers to bypass authentication and execute privileged database operations due to a failure to terminate script execution following HTTP redirects.
Hard-Coded Cryptographic Key in Acrisure KARR BT and DR-100
1 TTPA hard-coded cryptographic key vulnerability (CVE-2026-18411) in Acrisure KARR BT and DR-100 automotive anti-theft systems allows nearby attackers to issue unauthorized commands to vehicles.
Unauthenticated Remote Code Execution in Perspective 5.0.0
3 TTPs 3 CVEsPerspective version 5.0.0 is vulnerable to unauthenticated remote code execution via unsafe Python eval() calls within the PolarsVirtualServer backend triggered by crafted protobuf messages.
Missing Authorization Vulnerability in HAVELSAN Liman MYS
1 CVEA missing authorization vulnerability (CVE-2026-18650) in HAVELSAN Liman MYS versions 2.2.3 through 2.3.0 allows authenticated users to escalate privileges.
Stack-based Buffer Overflow in Autodesk FBX SDK
1 TTP 2 CVEsA stack-based buffer overflow vulnerability (CVE-2026-10709) in the Autodesk FBX SDK allows arbitrary code execution via maliciously crafted FBX files.
Remote Code Execution Vulnerability in Zyxel Firewalls
1 TTPA vulnerability in Zyxel firewall firmware allows a remote, authenticated attacker to achieve arbitrary code execution on the device.
Multiple Vulnerabilities in Red Hat Enterprise Linux Perl Modules
1 TTPMultiple vulnerabilities in Red Hat Enterprise Linux within DBI and perl-GD components allow local or remote attackers to execute arbitrary code, manipulate data, or trigger denial-of-service conditions.
Multiple Denial of Service Vulnerabilities in IBM Tivoli Netcool/OMNIbus
1 TTPMultiple Denial of Service vulnerabilities in IBM Tivoli Netcool/OMNIbus, potentially involving vulnerable Immutable.js libraries, allow unauthenticated remote attackers to disrupt service availability.
Multiple Vulnerabilities in LibreNMS
1 TTPLibreNMS versions prior to 26.5.0 are affected by multiple vulnerabilities including RCE, SSRF, and XSS, posing a significant risk for unauthorized system access and network reconnaissance.
Critical Vulnerabilities in HUMANIST Digital Human Resources
1 rule 3 TTPs 4 CVEsMultiple critical vulnerabilities in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources version 26.0 allow unauthorized access, web shell upload, session hijacking, and remote code execution. Upgrade to version 26.1 immediately.
Guzzle Hostname Validation Bypass via Transport Discrepancy
1 TTP 1 CVEGuzzle versions before 7.15.2 and 8.0.1 are vulnerable to a host-based security check bypass where transport handlers interpret non-canonical URI hostnames differently than application-level validation, potentially enabling SSRF.
DLL Hijacking in FirmaCheck for Windows via Unvalidated OpenSSL Configuration
1 rule 2 TTPs 1 CVEFirmaCheck for Windows versions prior to 1.3.16 are susceptible to local privilege escalation and arbitrary code execution due to an unvalidated OpenSSL configuration file path.
OS Command Injection in ClearOS Log Viewer
1 rule 2 TTPs 1 CVEClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands as the webconfig user, with subsequent escalation to root.
Emlog Pro TLS Certificate Validation Bypass
2 TTPs 1 CVEEmlog Pro versions up to 2.6.23 contain a vulnerability in the AI service component that disables TLS certificate verification, allowing attackers to perform man-in-the-middle interception of LLM API keys and manipulate AI responses.
Memory Exhaustion in Socket.IO Parser
1 TTP 1 CVEA memory exhaustion vulnerability in socket.io-parser (CVE-2026-69185) allows remote attackers to trigger denial-of-service by sending specially crafted packets containing a large number of binary attachments.
Information Disclosure and Denial of Service in Undici Cache Interceptor
1 CVEThe undici library is susceptible to cache poisoning leading to information disclosure and application crashes due to improper handling of malformed Cache-Control directives in the cache interceptor.
Blind SQL Injection in Krayin CRM leads DataGrid
1 rule 1 TTP 1 CVEKrayin CRM versions prior to 2.2.4 contain a blind SQL injection vulnerability in the leads DataGrid, allowing authenticated attackers to exfiltrate database contents via the rotten_lead[in] query parameter.
Remote Stack-Based Buffer Overflow in Wavlink Networking Devices
1 TTP 1 CVE 1 IOCMultiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.
Privilege Escalation in Razer RzUpdateService
1 TTP 1 CVEA local privilege escalation vulnerability in Razer RzUpdateService version 1.10.14.0 allows local attackers to manipulate the Named Pipe Handler to gain unauthorized privileges.
Krayin CRM Installer Authentication Bypass Vulnerability
1 rule 1 TTP 1 CVEKrayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware, allowing unauthenticated remote attackers to overwrite the administrator account via crafted HTTP POST requests.
Remote Code Execution in OpenEMR Document Category Tree
8 TTPs 1 CVEOpenEMR versions 8.2.0 and earlier are vulnerable to authenticated remote code execution via SQL injection and unsafe eval() calls in the document category tree component.
Critical Pre-Authentication RCE in Gitea and Forgejo
1 rule 3 TTPsCVE-2026-60004 is a critical pre-authentication RCE vulnerability in Gitea and Forgejo platforms caused by an unsafe bare clone design in the diffpatch API endpoint, enabling arbitrary command execution via injected Git hooks.
Linux Kernel posix-cpu-timers Use-After-Free Vulnerability
1 TTP 1 CVE 1 IOCA use-after-free vulnerability in the Linux kernel posix-cpu-timers subsystem, identified as CVE-2026-64560, allows attackers to trigger kernel memory corruption via a race condition during non-leader thread exec() calls.
Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes
1 TTPA vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.
Multiple Vulnerabilities in Red Hat Ansible Automation Platform
2 TTPsMultiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.
Multiple Vulnerabilities in cPanel/WHM
2 TTPsMultiple vulnerabilities in cPanel/WHM allow remote attackers to manipulate files and escalate privileges, potentially leading to arbitrary code execution with administrative rights.
Critical RCE and Information Disclosure Vulnerability in Gitea
1 TTPGitea contains a critical vulnerability allowing remote, unauthenticated attackers to execute arbitrary code and gain unauthorized access to sensitive information.
Critical Unauthenticated RCE in Realtyna WPL Real Estate Plugin
1 rule 2 TTPs 1 CVE 1 IOCA critical unauthenticated remote code execution vulnerability, CVE-2026-13714, in Realtyna WPL Real Estate and Organic IDX plugins allows attackers to upload arbitrary PHP shells via the I/O API.
Heap-based Buffer Overflow in FreeRDP Windows Clipboard Client
1 CVEA heap-based buffer overflow in FreeRDP versions 3.29.0 and earlier allows a malicious RDP server to execute an out-of-bounds write in the memory of a paste consumer process when handling clipboard file transfers.
Arbitrary File Read Vulnerability in CubeWP Framework
2 TTPs 1 CVEAn unauthenticated directory traversal vulnerability in the CubeWP Framework plugin allows attackers to read arbitrary files by leveraging exposed AJAX nonces.
Command Injection Vulnerability in GitPython
1 TTP 1 CVEGitPython versions prior to 3.1.51 are vulnerable to command injection because the library's security blocklist fails to account for Git command-line option abbreviation, allowing attackers to execute arbitrary commands.
Heap Out-of-Bounds Read in FreeRDP Glyph Caching
1 TTP 1 CVEFreeRDP versions 3.28.0 and earlier are vulnerable to a heap out-of-bounds read during the processing of malicious RDP server glyph fragments, allowing for potential client-side crashes or information disclosure.
FreeRDP Denial of Service via Smartcard Cache Request
2 TTPs 6 CVEsA null pointer dereference vulnerability in FreeRDP prior to 3.29.0 allows remote attackers to trigger a crash in the client process via crafted smartcard cache requests.
Remote Code Execution in Savon::Model via WSDL Injection
1 TTPThe Savon Ruby library is vulnerable to remote code execution (CVE-2026-53510) due to insecure use of module_eval when processing untrusted WSDL operation names.
Pterodactyl Wings SFTP Service Denial of Service
1 TTP 1 CVEAn unauthenticated remote attacker can trigger a panic and crash the Pterodactyl Wings service by sending a maliciously crafted packet during the SFTP handshake.
NLTK pathsec DNS Rebinding SSRF Filter Bypass
1 TTPA DNS rebinding vulnerability in the NLTK pathsec module allows attackers to bypass SSRF filters and access restricted internal resources by manipulating hostname resolution during the validation and connection phases.
Apache Cassandra JavaScript User-Defined Function Execution
1 rule 1 TTP 1 CVEAdversaries can exploit the creation of JavaScript-based user-defined functions in Apache Cassandra to escape the Nashorn sandbox and achieve remote code execution, particularly when vulnerable to CVE-2021-44521.
Redis Authenticated Remote Code Execution Vulnerability
1 TTPA vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.
Multiple Vulnerabilities in Progress MOVEit Transfer
1 TTP 4 CVEsMultiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.
Unauthenticated Remote Code Injection in Logsign SIEM
1 CVELogsign SIEM versions prior to 6.4.108 are vulnerable to a critical code injection flaw (CVE-2026-17561) that enables unauthenticated remote attackers to achieve arbitrary code execution.
Remote Code Execution via Exposed H2 Database in Juggle Through
2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability in Juggle Through 1.6.0 allows attackers to leverage default credentials on the H2 database console to execute system-level commands.
Critical OS Command Injection in IBM Hardware Management Console
1 CVEA critical unauthenticated command injection vulnerability (CVE-2026-12943) in IBM HMC and Novalink allows remote attackers to execute arbitrary commands with elevated privileges.
IBM PowerVM Hypervisor Memory Integrity Vulnerability
1 CVEA buffer overflow vulnerability in IBM PowerVM Hypervisor allows a local attacker with low privileges to trigger system crashes or compromise OS memory integrity via crafted hypervisor calls.
Unauthenticated Remote Code Execution in IBM Langflow OSS
3 TTPs 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 are susceptible to unauthenticated remote code execution due to improper sanitization of environment variables in the MCP stdio launcher.
SolarWinds Web Help Desk SAML Authentication Bypass
1 TTP 1 CVESolarWinds Web Help Desk versions 2026.1 and prior are vulnerable to a critical authentication bypass via the SAML 2.0 implementation, allowing unauthenticated remote access.
Denial of Service Vulnerability in IBM WebSphere Application Server - Liberty
1 CVEA remote unauthenticated denial-of-service vulnerability in IBM WebSphere Application Server - Liberty allows attackers to cause excessive memory consumption via crafted requests.
Critical Vulnerabilities in Spring Tools IDE Extensions
5 CVEsMultiple vulnerabilities in Spring Tools for Eclipse and VSCode/Cursor/Theia allow for remote code execution, unauthorized service access, credential exposure, and cross-site scripting.
Blind SQL Injection Vulnerability in Plesk XML-RPC API
1 rule 1 TTP 1 CVEA blind SQL injection vulnerability, tracked as CVE-2026-58046, affects the Plesk XML-RPC API, potentially allowing unauthenticated attackers to execute arbitrary database queries.
Credential Exfiltration via Unrestricted Base URL in Flyto-core
2 TTPs 1 CVEFlyto-core versions prior to 2.26.7 allow unauthenticated callers to exfiltrate API provider keys by supplying a malicious 'base_url' parameter, which forces the library to append operator-configured secrets to requests sent to attacker-controlled infrastructure.
Unauthenticated SSRF and Secret Exfiltration in Flyto Core
1 rule 4 TTPs 1 CVEAn unauthenticated SSRF vulnerability in the Flyto Core /run endpoint allows attackers to exfiltrate the internal FLYTO_RUNNER_SECRET and perform unauthorized requests against internal infrastructure.
Multiple Vulnerabilities in GitLab
5 CVEsMultiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.
CVE-2026-54366 CentreStack XXE Injection
1 rule 2 TTPs 1 CVECentreStack versions prior to 17.4 are vulnerable to an unauthenticated XXE injection via the SharePoint storage configuration handler, allowing attackers to exfiltrate sensitive server-side files.
Unauthenticated Deserialization Vulnerability in CentreStack
2 TTPsAn unauthenticated deserialization vulnerability in CentreStack allows remote attackers to create unauthorized local user accounts by sending crafted XML payloads to specific API endpoints.
IBM WebSphere Application Server Security Bypass Vulnerability
1 TTPIBM WebSphere Application Server and Liberty are vulnerable to a security bypass flaw that permits remote, unauthenticated attackers to circumvent established security controls.
Denial of Service Vulnerabilities in RHEL perl-Archive-Tar and httplib2
1 TTP 2 CVEsMultiple vulnerabilities in Red Hat Enterprise Linux packages perl-Archive-Tar and httplib2 can be exploited by a remote, anonymous attacker to cause a Denial of Service condition.
Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker
2 rules 5 TTPs 12 CVEsA critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.
Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module
1 rule 1 TTP 1 CVEA file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.
Command Injection in PCP linux_sockets PMDA
1 TTP 1 CVEA command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.
SSRF Bypass Vulnerability in V Library
1 TTP 1 CVEThe V library (versions 0.5.2 and below) contains a server-side request forgery (SSRF) bypass vulnerability allowing attackers to circumvent host-based allowlists via URL parsing differentials.
SSRF Vulnerability in IBM WebSphere Application Server
1 CVEIBM WebSphere Application Server and Liberty are vulnerable to unauthenticated Server-Side Request Forgery (SSRF) when the SIP container feature is enabled, allowing attackers to perform unauthorized requests to internal services.
Critical Unauthenticated RCE in JetBrains TeamCity
2 TTPs 1 CVEA critical insecure deserialization vulnerability (CVE-2026-63077) in JetBrains TeamCity allows unauthenticated remote attackers to execute arbitrary system commands via the agent polling protocol.
Arbitrary Host File Write via Symlink Escape in proot-distro
2 TTPs 1 IOCThe proot-distro utility contains a symlink traversal vulnerability (CVE-2026-54574) that allows malicious tar archives to overwrite arbitrary files on the host filesystem during the installation or reset process.
Req Library Unbounded Archive/Compression Extraction Denial-of-Service
1 TTP 1 CVEThe Elixir library 'Req' (versions >= 0.1.0, < 0.6.1) is susceptible to a denial-of-service vulnerability (CVE-2026-49755) caused by unbounded archive and compression extraction, which an attacker can leverage by providing a malicious HTTP response with a crafted 'content-type' or 'content-encoding' header, leading to memory exhaustion and application crashes.
veraPDF Validation Module XML External Entity Injection Vulnerability (CVE-2026-54079)
4 TTPsA critical XML External Entity Injection (XXE) vulnerability, CVE-2026-54079, in veraPDF's validation-model module allows a remote attacker to read arbitrary files on the server file system or perform Server-Side Request Forgery (SSRF) by submitting a crafted PDF containing a malicious XFA stream, due to insecure XML parsing defaults.
Denial of Service Vulnerability in cJSON Library (CVE-2026-67215)
1 TTP 1 CVECVE-2026-67215 describes a denial-of-service vulnerability in cJSON through version 1.7.19, where an attacker can trigger uncontrolled recursion and stack exhaustion by supplying a crafted RFC 6902 JSON Patch to cJSONUtils_ApplyPatches() or cJSONUtils_ApplyPatchesCaseSensitive(), leading to process crash.
Apache Tomcat Denial of Service Vulnerability (CVE-2026-66299)
1 TTP 1 CVE 4 IOCsA critical vulnerability, CVE-2026-66299, has been discovered in Apache Tomcat versions 9.0.x prior to 9.0.121, 10.1.x prior to 10.1.58, and 11.0.x prior to 11.0.25, allowing a remote attacker to cause a denial of service (DoS).
Multiple Vulnerabilities in Xen Hypervisor
7 CVEs 31 IOCsMultiple vulnerabilities have been discovered in Xen, allowing an attacker to achieve privilege escalation, remote denial of service, and compromise data confidentiality across all unpatched Xen versions, necessitating immediate patching.
Apache Tomcat Vulnerability Allows Denial of Service
1 TTPA vulnerability in Apache Tomcat allows a remote, anonymous attacker to perform a Denial of Service attack, potentially disrupting service availability for applications hosted on the affected server.
BlackBerry UEM Management Console Multiple Vulnerabilities
2 TTPsAn attacker can exploit multiple vulnerabilities in BlackBerry UEM Management Console to perform cross-site scripting attacks, cause a denial of service, and disclose information.
IBM WebSphere Application Server and Liberty Multiple Vulnerabilities
5 TTPsMultiple vulnerabilities exist in IBM WebSphere Application Server and IBM WebSphere Application Server Liberty that an attacker can exploit to execute arbitrary code, escalate privileges, perform denial of service attacks, disclose sensitive information, manipulate files, conduct cross-site scripting attacks, and bypass security measures.
Broadcom Brocade SANnav Vulnerabilities Allow Information Disclosure, SQL Injection, and Data Manipulation
3 TTPsMultiple vulnerabilities in Broadcom Brocade SANnav can be exploited by an attacker from an adjacent network to achieve information disclosure, execute SQL injection attacks, and manipulate data within the system.
CVE-2026-18220: Out-of-Bounds Write in GNU Binutils BFD Library Leading to Arbitrary Code Execution
1 TTP 1 CVEAn out-of-bounds write vulnerability, CVE-2026-18220, exists in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils, allowing attackers to achieve arbitrary code execution via a specially crafted ELF/DLX object file processed by BFD-consuming tools.
Fluent Forms WordPress Plugin Stored Cross-Site Scripting Vulnerability (CVE-2026-16655)
2 TTPs 1 CVEAn unauthenticated attacker can exploit a Stored Cross-Site Scripting vulnerability (CVE-2026-16655) in the Fluent Forms WordPress plugin, versions up to and including 6.2.7, via insufficient input sanitization of the Name Field Nested `password` Member, allowing injection of arbitrary web scripts that execute in a user's browser upon page access.
Red Hat Enterprise Linux librest and pipewire Vulnerabilities Allow Code Execution
2 TTPsAn attacker can exploit multiple vulnerabilities found in Red Hat Enterprise Linux, specifically within the librest and pipewire components, to bypass security measures and achieve arbitrary code execution on affected systems, posing a significant risk to the integrity and confidentiality of the system.
PackageKit: Vulnerability Allows Bypassing Security Measures
1 TTPA remote, authenticated attacker can exploit a vulnerability in PackageKit to bypass security mechanisms.
Gitea Remote Code Execution Vulnerability
1 TTPA vulnerability in Gitea allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full compromise of the affected Gitea instance and potentially the underlying server.
Tanium Endpoint Management Vulnerability Allows Authenticated SQL Injection
2 TTPsA remote, authenticated attacker can exploit a SQL injection vulnerability in Tanium Endpoint Management, enabling the execution of arbitrary SQL commands and potentially leading to data manipulation or unauthorized access.
IBM WebSphere Application Server Liberty: Multiple Vulnerabilities Enable Denial of Service
1 TTPMultiple vulnerabilities exist in IBM WebSphere Application Server Liberty that an attacker can exploit to perform a Denial of Service attack.
Unauthenticated Credential Disclosure in Vacron VIN-DS783E-E6 via Hidden Functionality (CVE-2026-18191)
2 TTPs 1 CVECVE-2026-18191 describes a critical Hidden Functionality vulnerability in Vacron VIN-DS783E-E6 devices that allows unauthenticated remote attackers to exploit a specific hidden function to obtain administrator credentials, leading to full device compromise.
Path Traversal Vulnerability in openhole-server (CVE-2026-54650)
1 rule 2 TTPsAn unauthenticated path traversal vulnerability (CVE-2026-54650) in openhole-server and openhole CLI versions 0.1.1 and earlier allows remote attackers to read arbitrary files outside the web root on tunneled local services by exploiting URL-decoded percent-encoded dot-segments and slashes, enabling arbitrary file disclosure and potential bypass of access controls.
SQL Injection Vulnerability in @hypequery/clickhouse Allows Arbitrary SQL Execution
2 TTPsA SQL injection vulnerability exists in the `escapeValue()` function of the `@hypequery/clickhouse` library, affecting versions prior to 2.0.2, allowing attackers to leverage a trailing backslash in user-controlled query parameters to bypass escaping mechanisms, leading to arbitrary SQL execution against ClickHouse databases.
td Library Denial of Service via Unbounded Memory Allocation
1 TTPA denial-of-service vulnerability exists in the `go/github.com/gotd/td` library versions prior to 0.145.1. A remote, unauthenticated attacker can exploit this by sending a crafted unencrypted MTProto packet during the handshake. This packet declares a large `dataLen` value, forcing the application to allocate an excessive amount of memory, potentially leading to out-of-memory (OOM) termination and denial of service due to unbounded memory allocation before length validation.
Goshs WebDAV MOVE Method Bypasses No-Delete Flag
1 rule 1 TTPA critical vulnerability (CVE-2026-64863) in the goshs WebDAV server, affecting versions up to 2.1.3, allows an attacker to bypass the `--no-delete` security flag using the `MOVE` HTTP method, leading to unauthorized deletion of source files or overwriting of existing destination files, impacting data integrity.
Goshs File-Based ACL Authorization Bypass via Bulk Zip Download
1 rule 3 TTPsAn unauthenticated attacker can exploit CVE-2026-54719 in goshs versions up to 1.1.4 and goshs/v2 up to 2.1.0 to bypass file-based Access Control Lists (ACLs) and read any file under the webroot using the `?bulk` zip-download route, leading to unauthorized information disclosure.
datamodel-code-generator Arbitrary Local File Read Vulnerability
2 TTPs 1 IOCThe `datamodel-code-generator` library (versions <= 0.61.0) is vulnerable to an unauthenticated path traversal and arbitrary local file read (CVE-2026-55389), allowing an attacker to supply a crafted JSON-Schema with `$ref` fields pointing to local files using `file://` URIs or `../` path traversal sequences, bypassing the `--no-allow-remote-refs` security control, which leads to information disclosure of sensitive data and enables filesystem mapping.
datamodel-code-generator Vulnerable to Code Injection via Unescaped Carriage Return
1 TTPThe `datamodel-code-generator` Python package is vulnerable to code injection (CVE-2026-54654) when a developer uses the `--extra-template-data` option with a file whose `comment` value contains an unescaped carriage return, leading to arbitrary Python code execution during the import process of the generated code.
datamodel-code-generator Vulnerable to SSRF Protection Bypass via DNS Rebinding
4 TTPs 1 IOCThe `datamodel-code-generator` tool is vulnerable to a Server-Side Request Forgery (SSRF) protection bypass, identified as CVE-2026-55391, due to a time-of-check/time-of-use (TOCTOU) race condition through DNS rebinding, allowing attackers to access internal services like cloud instance metadata endpoints when processing attacker-influenced URLs.
datamodel-code-generator Vulnerable to Arbitrary Local File Read via XSD Path Traversal
1 TTPdatamodel-code-generator versions 0.59.0 through 0.61.0 are vulnerable to an unauthenticated path traversal and information disclosure issue, allowing an attacker to read arbitrary local files on the system where the code generator is executed by crafting a malicious XML Schema (XSD) `schemaLocation` attribute, with the contents of the files then incorporated into the generated output.
Datamodel Code Generator Vulnerable to SSRF via URL Parameter
1 rule 3 TTPs 3 IOCsThe `datamodel-code-generator` tool, specifically versions from `0.9.1` up to `0.60.2`, is vulnerable to Server-Side Request Forgery (SSRF) when using the `--url` argument with the `[http]` extra installed, allowing attackers to access internal network resources and exfiltrate sensitive data into generated Python files.
IBM WebSphere Application Server Liberty Path-Segment Injection Vulnerability (CVE-2026-15280)
1 CVEA path-segment injection vulnerability (CVE-2026-15280) in the collective routing mechanism of IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 ND Collective Controller allows an unauthenticated attacker to inject arbitrary path segments, potentially leading to information disclosure.
CVE-2026-14996: IBM Aspera Faspex 5 Session Management Vulnerability
1 TTP 1 CVECVE-2026-14996 details a high-severity vulnerability (CVSS v3.1 8.2, CWE-613) in IBM Aspera Faspex 5 versions 5.0.0 through 5.0.15.4 that allows unauthenticated, remote attackers to exploit insufficient session management, leading to high confidentiality impact and low integrity impact.
IBM WebSphere Application Server Unsafe Deserialization Vulnerability
2 TTPs 1 CVEA critical unsafe deserialization vulnerability, CVE-2026-14974, in IBM WebSphere Application Server versions 8.5 and 9.0 traditional, allows a remote attacker to execute arbitrary code by processing specially crafted untrusted data, potentially leading to full system compromise.
IBM Instana Node.js Tracer Vulnerable to Prototype Pollution (CVE-2026-14893)
1 CVE 2 IOCsA high-severity prototype pollution vulnerability, CVE-2026-14893, exists in the IBM Instana Node.js tracer component (@instana/core version 6.2.1) affecting IBM Observability with Instana Agent builds 1.0.303 through 1.0.320, allowing an attacker to modify critical application behavior through the configuration normalization API.
IBM Aspera Desktop App Path Traversal Vulnerability (CVE-2026-14973)
1 TTP 1 CVEThe IBM Aspera Desktop App (versions 1.0.5 through 1.0.19) is affected by a path traversal vulnerability (CWE-22) which allows files to be written outside of the user's selected download destination, leading to high integrity and confidentiality impacts through arbitrary file write operations, and requires user interaction to exploit.
CVE-2026-14959: IBM Aspera Faspex 5 Remote Code Execution via Shell Command Injection
2 TTPs 1 CVEA critical vulnerability, CVE-2026-14959, in IBM Aspera Faspex 5 (versions 5.0.0 through 5.0.15.4) allows a remote authenticated attacker to execute arbitrary code due to a shell command injection flaw, potentially leading to full system compromise and significant data loss or service disruption.
IBM Aspera Faspex 5 Remote Code Execution Vulnerability (CVE-2026-14958)
1 rule 2 TTPs 1 CVEA critical remote code execution vulnerability (CVE-2026-14958) in IBM Aspera Faspex 5, affecting versions 5.0.0 through 5.0.15.4, allows a remote authenticated attacker to execute arbitrary code due to unquoted shell interpolation, posing a significant risk of system compromise.
IBM WebSphere Application Server Liberty Denial of Service Vulnerability (CVE-2026-16192)
2 CVEsA denial of service vulnerability, CVE-2026-16192, affects IBM WebSphere Application Server - Liberty versions 17.0.0.3 through 26.0.0.8 when the `restConnector-2.0` feature is enabled, allowing an unauthenticated attacker to cause service unavailability.
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
Fission Zip Slip Vulnerability in pkg/utils/zip.go Unarchive Function
3 TTPs 1 CVEThe Unarchive function in Fission's pkg/utils/zip.go was vulnerable to a Zip Slip path traversal. An attacker controlling a malicious zip archive's URL could leverage this to write files outside the intended destination directory, potentially leading to overwriting sensitive files, accessing secrets from mounted volumes, or tampering with the fetcher's own binaries, impacting other tenants in a multi-tenant containerized environment. This vulnerability affects Fission versions up to and including v1.24.0 and was fixed in v1.25.0.
SQL Injection Vulnerability in IBM Sterling B2B Integrator and File Gateway (CVE-2026-7769)
3 TTPs 1 CVEA remote attacker can exploit CVE-2026-7769, an SQL injection vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway, to send specially crafted SQL statements, allowing them to view, add, modify, or delete information in the backend database.
Artica Proxy Session Fixation Vulnerability CVE-2026-66745
1 TTP 1 CVE 1 IOCA session fixation vulnerability, CVE-2026-66745, in Artica Proxy before version 4.50.000000 Service Pack 7 allows unauthenticated attackers to hijack administrative sessions by pre-setting a PHPSESSID on a victim's browser, leading to full administrative control upon victim authentication.
Adobe Bridge Untrusted Search Path Vulnerability Allows Arbitrary Code Execution (CVE-2026-48395)
2 TTPs 1 CVE 1 IOCAn Untrusted Search Path vulnerability (CVE-2026-48395) in Adobe Bridge, affecting versions up to 16.0.5 and 15.1.6, can be exploited by an attacker to achieve arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file.
Progress Software Security Advisory Addresses Multiple Vulnerabilities
5 CVEsProgress Software has issued a security advisory (AV26-755) addressing multiple vulnerabilities, identified by CVEs CVE-2026-59686 through CVE-2026-59690, across several of its products including ECS Connection Manager, LoadMaster, MOVEit WAF, Multi Tenant, and Object Scale Connection Manager, with specific versions prior to various patch levels being vulnerable, urging administrators to apply necessary updates to secure their systems.
TinyWeb Path Traversal Vulnerability (CVE-2026-67185)
1 rule 2 TTPs 1 CVEA path traversal vulnerability, tracked as CVE-2026-67185, exists in TinyWeb through version 0.0.8, allowing unauthenticated attackers to read arbitrary files by submitting '..' sequences in the URL path, bypassing security checks and potentially exposing sensitive data like credential stores or private keys when the server runs with root privileges.
Rouille HTTP Request Smuggling Vulnerability (CVE-2026-67182)
1 TTP 1 CVEAn HTTP request smuggling vulnerability, identified as CVE-2026-67182, in Rouille versions 0.3.3 through 3.6.2 allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values, causing upstream backends to misinterpret subsequent data as a separate, attacker-controlled HTTP request.
CVE-2026-16313: sg3_utils Vulnerability Allows Root Command Execution via Crafted SCSI Device
2 TTPs 1 CVE 3 IOCsA vulnerability, CVE-2026-16313, exists in the `sg_inq` command of `sg3_utils` on Red Hat Enterprise Linux systems, allowing an attacker who can present a specially crafted SCSI device to inject arbitrary properties into the `udev` device database by embedding a newline character in the device's name string, leading to arbitrary command execution as root when the device is disconnected.
SIPSorcery: Malformed UDP Packet Can Remotely Terminate Media Sessions (DoS)
2 TTPsA denial-of-service vulnerability (CVE-2026-54632) exists in the SIPSorcery NuGet package versions <= 10.0.8, allowing an unauthenticated attacker to remotely terminate an active RTP or WebRTC media session by sending a single malformed inbound UDP packet to the RTP/ICE socket, which exploits insufficient length checks and an exception handling flaw.
QTINeon NeonRelay Unauthenticated Denial-of-Service Amplification Vulnerability
3 TTPsAn unauthenticated attacker can exploit an unbounded RECONNECT_REQUEST forwarding vulnerability in QTINeon's NeonRelay component to amplify denial-of-service attacks against a connected host. By sending spoofed RECONNECT_REQUEST packets, the relay forwards each one to the host without proper deduplication or rate limiting, consuming host resources. Additionally, excessive spoofed IPs can reset legitimate rate limiting, further impacting service availability. This vulnerability affects Java, Python, and TypeScript implementations of NeonRelay.
OAuth2::Client Redirection Vulnerability Leaks Bearer Tokens
3 TTPs 3 IOCsThe `OAuth2::Client` in the `oauth2` Ruby gem is vulnerable to credential disclosure and Server-Side Request Forgery (SSRF) due to improper handling of protocol-relative redirect URLs, allowing an attacker to steal bearer tokens and access internal network resources.
Cross-origin OAuth token-request redirects can expose signed request metadata
3 TTPsThe 'oauth' Ruby gem versions 0.5.5 through 1.1.5 are vulnerable to a critical issue (CVE-2026-54605) where the 'OAuth::Consumer#token_request' method improperly handles HTTP 3xx redirects during OAuth 1.0 token exchanges, enabling an attacker to redirect the request to a malicious host, exposing sensitive OAuth 1.0 metadata, and facilitating Server-Side Request Forgery (SSRF) and confused-deputy behavior.
Rouille Web Server Vulnerability CVE-2026-66754 Allows Remote DoS
1 TTP 1 CVEA reachable assertion vulnerability exists in the `Request::remove_prefix` function of the Rouille web server framework, affecting versions 0.1.6 through 3.6.2, allowing remote, unauthenticated attackers to crash the server and cause a denial of service by sending a crafted percent-encoded URL.
HTTP Request Smuggling Vulnerability in tiny-http CVE-2026-66752
1 CVEA critical HTTP request smuggling vulnerability (CVE-2026-66752) exists in tiny-http versions up to and including 0.12.0, allowing remote attackers to desynchronize request framing by sending a Transfer-Encoding header with arbitrary values, causing the library to incorrectly apply chunk-decoding and ignore Content-Length, which enables request smuggling attacks and can lead to denial of service by tying up connections and consuming worker threads.
Authenticated Remote Code Execution in Camaleon CMS
1 TTP 1 CVECamaleon CMS versions 2.1.1 through 2.9.1 are vulnerable to authenticated remote code execution where an attacker with `custom_fields manage` permission can execute arbitrary Ruby code by injecting a malicious expression into the `select_eval` custom field type's options command parameter, which is then evaluated via `instance_eval` within an ERB view when a post edit page is rendered, leading to server-side code execution with web server process privileges.
Pterodactyl Wings Privilege Escalation via Improper JWT Scoping (CVE-2026-54593)
1 rule 1 TTPA privilege escalation vulnerability, CVE-2026-54593, exists in Pterodactyl's Wings component that allows authenticated subusers to upload arbitrary files to a server without explicit file creation permissions, due to insufficient validation of panel-signed JSON Web Tokens (JWTs.
CVE-2026-8164: ArkSigner Desktop Client Vulnerable to Search Order Hijacking
2 TTPs 1 CVEAn Uncontrolled Search Path Element vulnerability, CVE-2026-8164, in ArkSigner Desktop Client versions from v2.2.16.10 through 17062026 allows a local attacker to perform Search Order Hijacking, potentially leading to arbitrary code execution or privilege escalation with the application's privileges.
Improper Privilege Escalation in Anchore Enterprise User Management API
1 TTP 1 CVEAn improper privilege escalation vulnerability (CVE-2026-63727) exists in Anchore Enterprise versions 5.11.0 to 5.27.1 and 6.0.0, specifically within the user management API, allowing an authenticated attacker to issue a crafted API call to modify user permissions and gain elevated access to resources and operations, such as granting write access to a read-only user, with fixes available in versions 5.27.2 and 6.0.1.
Pterodactyl Panel Global Rate-Limit Vulnerability Enables Unauthenticated DoS (CVE-2026-61609)
1 rule 2 TTPsAn unauthenticated attacker can exploit CVE-2026-61609, a global rate-limit vulnerability in Pterodactyl Panel versions up to and including 1.12.4, by sending approximately 10 requests per minute to authentication endpoints, leading to a panel-wide denial of service for all legitimate users and administrators attempting to log in or complete 2FA.
GitHub MCP Server Nil Pointer Dereference DoS in completion/complete Handler (CVE-2026-47427)
1 TTPA nil pointer dereference vulnerability, tracked as CVE-2026-47427, in the GitHub MCP Server's `completion/complete` handler allows an unauthenticated attacker to cause a complete denial of service by sending a malformed JSON-RPC request with missing or empty parameters for the `ref` field, leading to an immediate server crash.
Multiple Vulnerabilities Identified in Apache Thrift
4 CVEsMultiple vulnerabilities, including decompression bombs (CVE-2026-48586, CVE-2026-49158), an integer overflow (CVE-2026-55969), and a heap out-of-bounds read (CVE-2026-58023), affect Apache Thrift prior to version 0.24.0, potentially leading to denial of service, memory corruption, or arbitrary code execution, and require immediate patching.
WordPress Coding Standards Contains an Arbitrary Code Execution Vulnerability
1 TTPWordPress Coding Standards (WordPressCS) versions before 3.4.1 are vulnerable to arbitrary code execution due to a flaw in the `WordPress.WP.EnqueuedResourceParameters` sniff, allowing an attacker to execute arbitrary commands on the scanning host by crafting a malicious `$ver` argument, posing a risk for users running PHPCS with specific rulesets in CI pipelines or developer environments.
Appium Java Client Allows Network Pivot via Unvalidated directConnect Redirect (CVE-2026-43910)
3 TTPs 1 IOCA vulnerability, CVE-2026-43910, in Appium's java-client allows a malicious Appium server to redirect all subsequent session traffic to an arbitrary internal endpoint by injecting unvalidated `directConnectHost` and `directConnectPort` parameters when `directConnect(true)` is enabled, potentially leading to session traffic interception, network pivoting, and cloud credential theft.
Vulnerability in VeloCloud Orchestrator On-Prem Allows Remote Code Execution
3 TTPsA critical vulnerability has been identified in VeloCloud Orchestrator (VCO) On-Prem that allows for remote code execution, enabling a remote attacker to gain privileged access, execute arbitrary commands on the VCO host, and potentially install programs, modify or delete data, or create new user accounts with administrative rights, with impact severity depending on the service account privileges.
Multiple Vulnerabilities in Samba
3 TTPs 1 CVEMultiple vulnerabilities have been discovered in Samba, a network file sharing service, which could allow a remote attacker to trigger a denial of service, compromise data confidentiality, and bypass security policies.
CVE-2026-7187: Missing Authentication Vulnerability in Universal Software Inc. UKBS
1 TTP 1 CVEA missing authentication for critical function vulnerability, tracked as CVE-2026-7187, in Universal Software Inc.'s UKBS product allows attackers to bypass authentication and access functionality not properly constrained by Access Control Lists (ACLs), leading to unauthorized operations.
CVE-2026-49332: OpenShift OAuth Proxy Header Smuggling Vulnerability
1 TTP 1 CVEA flaw in Red Hat OpenShift's oauth-proxy, tracked as CVE-2026-49332, allows an authenticated low-privilege user to smuggle a forged identity header by exploiting differences in how dash and underscore variants of 'X-Forwarded-User' are handled, potentially leading to privilege escalation in upstream applications.
Multiple Vulnerabilities in Apache Wicket Allow XSS and Security Bypass
2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in Apache Wicket to perform Cross-Site Scripting (XSS) attacks and bypass existing security measures, potentially leading to unauthorized client-side script execution and further compromise of user sessions or data.
binutils: Vulnerability Enables Denial of Service and Data Disclosure
2 TTPsA local attacker can exploit a vulnerability in binutils to cause a Denial of Service condition and disclose sensitive data.
Multiple Vulnerabilities in GIMP Plugins Allow Local Exploitation
2 TTPsA local attacker can exploit multiple vulnerabilities found in GIMP plugins to perform a Denial of Service attack, execute arbitrary code, or disclose confidential information on affected systems.
CVE-2026-16462: SQL Injection Vulnerability in PROCON-WEB SCADA
1 rule 2 TTPs 1 CVECVE-2026-16462 describes a critical SQL Injection vulnerability in Weidmueller Interface's PROCON-WEB SCADA, where a remote unauthenticated attacker can execute arbitrary SQL commands via the 'GetGridData' endpoint due to improper input sanitization, potentially leading to full system compromise.
Netty: Vulnerability Enables Denial of Service
1 TTPA denial of service vulnerability exists in Netty, which an unauthenticated, remote attacker can exploit, allowing the attacker to disrupt the availability of affected systems or services.
Erlang/OTP: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in Erlang/OTP allow a remote, anonymous attacker to perform a Denial of Service attack, execute arbitrary code, bypass security measures, and manipulate or disclose data.
WordPress PickPlugins Question Answer Plugin SQL Injection Vulnerability (CVE-2026-10207)
1 rule 2 TTPs 1 CVEAn unauthenticated SQL injection vulnerability, tracked as CVE-2026-10207, exists in the PickPlugins Question Answer plugin for WordPress versions up to and including 1.2.73, allowing attackers to extract sensitive database information due to insufficient input sanitization of the 'id' GET parameter and improper SQL query construction.
CVE-2026-14516 - Bookly WordPress Plugin Time-Based SQL Injection
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a time-based SQL Injection vulnerability (CVE-2026-14516) in the Bookly WordPress plugin, affecting versions up to and including 27.5, via the 'staff_ids' parameter, chaining requests to `bookly_get_form_id` and `bookly_render_time` to extract sensitive database information due to insufficient input escaping and lack of CSRF protection.
CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout
1 TTP 1 CVEA low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.
CVE-2026-14167: ads-tec Industrial IT DVG-IRF Series Privilege Escalation Vulnerability
1 TTP 1 CVEA low-privileged remote attacker can exploit CVE-2026-14167, an incorrect authorization vulnerability in multiple ads-tec Industrial IT DVG-IRF series products, to perform privileged configuration changes, including permission management, leading to privilege escalation.
CVE-2026-66759: Out-of-Bounds Read in GIMP file-icns Plugin
1 CVEA critical out-of-bounds read vulnerability (CVE-2026-66759) has been identified in the GIMP file-icns plugin, where processing a crafted ICNS file with a truncated mask resource can lead to information disclosure of heap contents via leaked alpha channel pixel values or a denial of service due to an application crash.
CVE-2026-12383: Event-Driven Ansible Server Authentication Bypass
1 rule 2 TTPs 1 CVEA flaw in the Event-Driven Ansible (EDA) server's ExternalEventStreamViewSet allows an unauthenticated attacker to bypass mTLS authentication by spoofing the Subject HTTP header, enabling injection of arbitrary events into mTLS-protected streams and triggering downstream automation actions, while also leaking the expected certificate Distinguished Name in 403 error responses.
Fortinet FortiOS CVE-2025-68686 Sensitive Information Exposure Bypass
1 TTP 3 CVEs 4 IOCsA remote unauthenticated attacker can exploit CVE-2025-68686 in Fortinet FortiOS to bypass a previously applied patch, allowing sensitive information exposure and enabling persistence post-exploitation, provided the product was already compromised at the filesystem level via another vulnerability.
CVE-2026-66730 Denial of Service in facil.io Multipart Body Parser
1 TTP 1 CVEA denial-of-service vulnerability exists in facil.io versions 0.6.0 through 0.7.6, specifically in its multipart body parser, allowing an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a malformed multipart/form-data request with a partial closing boundary, effectively disabling the server until manual restart.
CVE-2026-66729: facil.io Integer Underflow Vulnerability Leading to Server Crash
1 TTP 1 CVEAn integer underflow vulnerability in facil.io through version 0.7.6 allows unauthenticated remote attackers to crash the server process via a crafted Content-Disposition header with an empty field name, leading to a Denial of Service.
CVE-2026-66394: SiYuan XSS Vulnerabilities in SVG Sanitization
2 TTPs 1 CVEAuthenticated attackers can exploit stored and reflected cross-site scripting (XSS) vulnerabilities, identified as CVE-2026-66394, in SiYuan versions prior to v3.7.3 by bypassing the application's SVG sanitization to execute arbitrary scripts within the application's origin, potentially leading to session hijacking and data exfiltration.
Path Traversal Vulnerability in NitroShare Desktop (CVE-2026-66050)
1 rule 1 TTP 1 CVENitroShare Desktop versions up to and including 0.3.4 are vulnerable to a path traversal flaw in their LAN file transfer server, allowing unauthenticated attackers on the same network to craft malicious filenames containing directory traversal sequences within the JSON item header. Exploiting this, attackers can write arbitrary files outside the intended transfer root to any location the current user has write access, including the Windows Startup folder, leading to persistent code execution upon user login.
Multiple Vulnerabilities in GLPI
3 TTPs 1 CVE 9 IOCsMultiple vulnerabilities have been discovered in GLPI, including SQL injection, cross-site scripting (XSS), and privilege escalation, which could allow an attacker to compromise data integrity, bypass security policies, and elevate their privileges within the system.
Zabbix Cross-Site Scripting Vulnerability
1 rule 1 TTPA critical cross-site scripting (XSS) vulnerability has been identified in Zabbix, which a remote, unauthenticated attacker can exploit to execute malicious scripts within a user's browser session, potentially leading to unauthorized actions or data theft.
FFmpeg: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in ffmpeg allow a remote, anonymous attacker to cause memory corruption, execute arbitrary code, trigger a denial-of-service condition, or disclose confidential information. The attacker does not require authentication to exploit these flaws.
OpenCTI Security Bypass and Information Disclosure Vulnerability
2 TTPsA remote, anonymous attacker can exploit a vulnerability in OpenCTI to bypass security measures and disclose sensitive information, potentially leading to unauthorized access to critical threat intelligence data and circumvention of protective controls within the platform.
Multiple Vulnerabilities in libssh2 Library Discovered
2 TTPsMultiple vulnerabilities in the libssh2 library allow a remote, unauthenticated attacker to potentially disclose sensitive information, cause a denial-of-service condition, or execute arbitrary code.
Improper Signature Verification in Lenze Products (CVE-2026-14837)
2 TTPs 1 CVEA low-privileged local attacker can exploit CVE-2026-14837, an improper signature verification vulnerability, in multiple Lenze products including models c430, c520, c550, i950 GenA, and i950 GenB to bypass the verification of the SSH enable file signature, subsequently enabling SSH access on the affected device, resulting in unauthorized administrative access and complete system compromise.
Code Injection Vulnerability in datamodel-code-generator (CVE-2026-63720)
1 TTP 1 CVECVE-2026-63720 details a code injection vulnerability in datamodel-code-generator versions prior to 0.70.0, allowing attackers to achieve remote code execution by providing a malicious `customBasePath` value within input schemas that is unsafely embedded into a Python import statement.
SiYuan Missing Authorization Vulnerability in /mcp Endpoint (CVE-2026-66012)
5 TTPs 2 IOCsA critical missing authorization vulnerability, CVE-2026-66012, in SiYuan before version 3.7.2 allows a remote unauthenticated attacker to exploit the POST /mcp kernel endpoint when the Publish server is in anonymous mode, leading to arbitrary file writes, sensitive credential exposure, malicious plugin execution, and ultimately administrator takeover on affected systems.
AWS Smithy-RS HTTP Server Vulnerable to Unauthenticated Slowloris Denial of Service
1 TTP 1 CVEAn unauthenticated Slowloris denial of service vulnerability exists in the default `serve()` path of AWS's `aws-smithy-http-server` framework (versions <= 0.66.4), allowing remote attackers to exhaust server resources by initiating numerous incomplete connections.
AWS Bedrock AgentCore Python SDK Arbitrary Command Execution Vulnerability
1 TTP 1 CVEAn improper neutralization of argument delimiters vulnerability (CVE-2026-16796) in the AWS Bedrock AgentCore Python SDK's `install_packages()` method allows a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox by crafting malicious package name arguments.
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure (CVE-2026-16584)
1 CVEThe AWS API MCP Server has a high-severity vulnerability, CVE-2026-16584, where a failure to initialize security policy data at server startup leads to a silent bypass of all per-request policy checks, allowing AWS API operations to execute without the intended restrictions, though underlying IAM permissions remain enforced.
py-libp2p yamux Connection DoS via Oversized Data Frame
1 TTPA denial-of-service vulnerability in py-libp2p versions up to 0.6.0 allows an authenticated attacker to send a specially crafted 12-byte DATA or SYN frame with an oversized length field, causing the victim's yamux read loop to block indefinitely and freezing all streams on the affected connection.
Multiple HTTP/1.1 Request Smuggling Primitives in Blaze Java Parser
2 TTPsFive independent HTTP/1.1 conformance laxities in Blaze's Java parser cause request-boundary disagreement with a stricter intermediary proxy, enabling front-end ACL/authentication bypass, response-queue poisoning on pooled backend connections, and cache poisoning in affected `http4s-blaze-server` and `blaze-http` components.
Denial of Service via Unbounded Expansion Length in Node.js brace-expansion Library (CVE-2026-14257)
1 TTP 1 CVEAn attacker can exploit CVE-2026-14257, a denial of service vulnerability in the `brace-expansion` Node.js library, by crafting an input with deeply chained brace groups that causes the expanded string length to grow without bound, leading to an uncatchable out-of-memory process crash in any application processing untrusted input via `expand()` directly or through dependencies like `minimatch` or `glob`.
Poweradmin OIDC `sub` Collation Bypass Leads to Account Takeover
1 TTPA collation vulnerability in Poweradmin's OIDC integration allows an unauthenticated attacker to take over victim accounts by exploiting the case and accent-insensitive MySQL collation (`utf8mb4_unicode_ci`) used for OIDC subject (`sub`) identifiers, causing the attacker's colliding `sub` to resolve to the victim's `user_id` during authentication.
Poweradmin: Broken Access Control (IDOR) Allows DNS Record Modification
3 TTPs 5 IOCsA low-privilege authenticated user in Poweradmin (a web front-end for PowerDNS) can exploit an Insecure Direct Object Reference (IDOR) vulnerability, allowing them to modify any DNS record on the server, even those they do not own, by manipulating POST request parameters to bypass access control checks and achieve DNS record repointing, disabling, or hijacking, leading to data integrity and availability issues, and potentially cross-tenant DNS takeover.
frp: Unauthenticated Remote Denial of Service in SSH Tunnel Gateway via Integer Overflow
1 TTPAn unauthenticated remote denial-of-service vulnerability exists in the frp server's optional SSH Tunnel Gateway (frps) that allows an attacker to crash the entire frps process by sending a specially crafted five-byte message containing an integer overflow value in an SSH `exec` channel request, leading to a sustained service outage.
Vantage6 Algorithm Developer Can Edit Other Developers' Pending Algorithms
1 TTPAn algorithm developer in the vantage6 system can modify another developer's algorithm metadata or Docker image tag, even when that algorithm is pending review, allowing an attacker with low privileges to replace an approved algorithm with an unapproved or malicious image.
GitPython Environment Variable Exfiltration via Remote URL Processing
2 TTPs 2 IOCsA vulnerability in GitPython allows environment variables to be exfiltrated when using `Repo.create_remote()` or `Remote.add()`, where attacker-supplied URLs are processed by `Git.polish_url()` expanding sensitive environment variables into the URL, which is then stored in `.git/config` and transmitted to an attacker-controlled host.
Budibase MongoDB Datasource Vulnerability Allows Server Filesystem Existence/Read Oracle
2 rules 6 TTPs 2 IOCsA vulnerability in Budibase's MongoDB datasource configuration allows authenticated attackers to specify arbitrary absolute server-side file paths for `tlsCertificateKeyFile` and `tlsCAFile`, enabling the `/api/datasources/verify` endpoint to act as an arbitrary-path existence/read oracle on the underlying multi-tenant server, distinguishing between existing and non-existing files and potentially exfiltrating certificate content.
SQL Injection Vulnerability in Budibase MySQL Integration
1 rule 7 TTPsA critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.
Budibase OIDC SSO Account Takeover via Unverified Email Claim
1 TTPA critical vulnerability in Budibase versions up to 3.38.1 allows full account takeover of any existing user, including global administrators, by exploiting a flaw in its OIDC SSO implementation that links incoming identities by email address alone without validating the `email_verified` claim, enabling an attacker to log in as a victim if they can coerce a trusted Identity Provider to assert the victim's email as unverified.
Denial of Service Vulnerability in React Server Components
1 TTP 1 CVEA denial of service vulnerability (CVE-2026-44907) affects multiple versions of the react-server-dom-webpack, react-server-dom-parcel, and react-server-dom-turbopack packages, allowing threat actors to trigger out-of-memory exceptions or excessive CPU usage by sending specially crafted HTTP requests to server function endpoints.
Budibase Privilege Escalation via Role Assignment API
4 TTPsAn app-scoped builder in Budibase can exploit a missing authorization flaw in the public role assignment API (`POST /api/public/v1/roles/assign`) to escalate privileges, granting themselves builder access to any other application within the tenant, read/modify data, exfiltrate datasource credentials, and execute arbitrary code via automation steps, compromising the entire tenant's app and data plane in Budibase versions up to and including 3.39.19 and npm/@budibase/server up to 3.38.1.
Critical Unauthenticated Remote Code Execution in OpenAM WebAuthn due to Deserialization Vulnerability (CVE-2026-62263)
2 TTPsA critical remote code execution (RCE) vulnerability, CVE-2026-62263, exists in OpenAM's WebAuthn authenticator deserialization, allowing an unauthenticated attacker to bypass an `ObjectInputFilter` and execute arbitrary code by crafting a malicious serialized stream before authentication.
Open WebUI Terminal Proxy Path Traversal Bypass via 9x Encoding (CVE-2026-59221)
1 rule 1 TTP 1 CVEAn incomplete fix for a path traversal vulnerability in Open WebUI's terminal proxy allows authenticated attackers to bypass security checks by sending a 9x percent-encoded path, leading to requests being forwarded with terminal credentials and user identification headers to unintended arbitrary paths outside the intended proxy scope.
yt-dlp Shortcut Command Injection Vulnerability
1 rule 3 TTPs 1 CVEA high-severity command injection vulnerability, CVE-2026-55404, in yt-dlp versions prior to 2026.7.4 allows remote attackers to achieve arbitrary code execution by crafting malicious metadata that is improperly sanitized when generating Windows `.url` or Linux `.desktop` shortcut files, leading to remote executable execution or shell command injection upon user interaction.
FFmpeg Heap Out-of-Bounds Write Vulnerability (CVE-2026-66041)
1 CVEA heap out-of-bounds write vulnerability exists in the vf_quirc filter of FFmpeg versions 7.0 through 8.1.2, allowing an attacker to corrupt heap memory and potentially achieve arbitrary code execution by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions.
CVE-2026-66040: FFmpeg Heap Out-of-Bounds Write in PNG/APNG Encoders
1 TTP 1 CVEA heap out-of-bounds write vulnerability, CVE-2026-66040, exists in the native PNG and APNG encoders of FFmpeg through version 8.1.2, allowing remote attackers to corrupt heap memory and achieve potential arbitrary code execution by supplying a crafted PNG image with a malicious eXIf chunk.
FFmpeg Heap Out-of-Bounds Write Vulnerability (CVE-2026-66036)
1 CVEA heap out-of-bounds write vulnerability exists in FFmpeg through version 8.1.2, specifically within the vf_hqdn3d filter, allowing attackers to corrupt heap memory by providing a crafted video input where frame resolution increases between frames while filtergraph reinitialization is disabled, leading to undersized buffers and a write beyond allocation boundaries.
Red Hat Advanced Cluster Management Vulnerability Allows Cluster-Admin Privilege Escalation
1 TTP 1 CVEA flaw exists in the cluster-proxy service-proxy component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE), allowing an authenticated hub principal to inject an Impersonate-Group header into proxied requests, bypassing validation, and leveraging the spoke ServiceAccount's unrestricted impersonation permissions to escalate privileges to cluster-admin on all managed clusters.
CVE-2026-66032 - libssh2 SFTP Double-Free Vulnerability
4 TTPs 4 CVEsA double-free vulnerability, CVE-2026-66032, in libssh2 versions through 1.11.1 allows a malicious SSH server to corrupt the heap of an authenticated client opening an SFTP session, potentially leading to arbitrary code execution.
CVE-2026-65709 - sysPass JSON-RPC API Missing Object-Level Authorization
5 TTPs 3 CVEssysPass versions up to 3.2.11 are affected by a missing object-level authorization vulnerability in the JSON-RPC API. Attackers holding an API token can exploit this flaw by invoking AccountController methods (e.g., viewAction, editAction, deleteAction, editPassAction) without proper AccountFilterUser checks, allowing them to enumerate account metadata, overwrite passwords, and delete user accounts across the entire vault, bypassing per-account access control defined by their token permissions.
Open WebUI Cross-Channel Message Overwrite Vulnerability
3 TTPs 1 IOCAn authenticated user can overwrite messages in any channel, including private and DM channels, by exploiting the CVE-2026-59714 authorization bypass vulnerability in Open WebUI's chat completion API, leading to message integrity destruction and impersonation.
Open WebUI: Cross-User Code-Interpreter and Tool Execution via Unvalidated Socket.IO Session ID
1 rule 3 TTPs 1 CVEAn authenticated low-privilege user can exploit CVE-2026-59216 in Open WebUI versions prior to 0.10.0 to execute arbitrary Python code or tools within another user's authenticated session by supplying an unvalidated `session_id`, which, if targeting an administrator, leads to remote code execution on the server as the root process.
Open WebUI: Realtime Endpoints Fail to Revoke JWTs
1 TTP 1 CVEOpen WebUI versions from 0.9.0 to before 0.10.0, when configured with Redis, fail to correctly enforce JWT revocation for realtime authentication endpoints such as Socket.IO and terminal websockets, allowing attackers to maintain access to real-time features with stolen, revoked JWTs.
Netty XmlFrameDecoder CPU Exhaustion Denial of Service
1 TTPAn unauthenticated remote attacker can cause a Denial of Service (DoS) in Netty servers utilizing XmlFrameDecoder by sending a specially crafted XML payload containing repeated '</' characters, leading to CPU exhaustion of the server's EventLoop thread and unresponsiveness.
Open WebUI: Stored Web Worker XSS via Pyodide Leading to Server-Side RCE
4 TTPs 1 CVEA stored web worker XSS vulnerability, CVE-2026-59214, in Open WebUI versions prior to 0.10.0 allows a low-privileged user to inject malicious Python code into chat messages that, when executed by an administrator or privileged user via a 'Run' click, triggers authenticated same-origin requests to create server-side functions with arbitrary commands, leading to remote code execution on the Open WebUI server.
React Router RSC Mode CSRF Bypass
1 TTP 1 CVEA high-severity Cross-Site Request Forgery (CSRF) bypass vulnerability in React Router's unstable React Server Components (RSC) APIs allows for action execution before a 400 response, impacting applications utilizing these specific APIs.
js-yaml Denial of Service via Exponential Parsing Time in Flow Collections
1 TTPA denial of service vulnerability exists in the js-yaml library (versions 5.0.0 through 5.2.1) due to an exponential parsing time bug in flow collections, allowing attackers to craft a small YAML document which, when processed by `load()` or `loadAll()` functions, consumes significant CPU resources and blocks the Node.js event loop.
GitPython Incomplete Denylist Allows Arbitrary Command Execution via Git Clone Hooks
1 rule 3 TTPsA critical vulnerability in GitPython versions up to 3.1.53 allows attackers to achieve arbitrary command execution by influencing `git clone` options to include a malicious `--template` directory, which causes Git hooks to be copied and executed during cloning, even in default configurations.
Velocity.js Remote Code Execution via Function Constructor Bypass
1 rule 2 TTPs 1 IOCVelocity.js versions up to 2.1.6 are vulnerable to Remote Code Execution (RCE) through an incomplete fix for a previous prototype pollution vulnerability, enabling attackers to craft malicious Velocity templates to leverage unfiltered property-read expressions and execute arbitrary JavaScript code on the server, leading to full server compromise.
Server-Side Template Injection to Remote Code Execution in @prompty/core Nunjucks Renderer
1 TTPA critical server-side template injection vulnerability exists in the @prompty/core Nunjucks renderer, affecting versions <= 0.1.4 and >= 2.0.0-alpha.1 up to <= 2.0.0-beta.4. This flaw allows an attacker to execute arbitrary JavaScript code within the host Node.js process by crafting malicious `.prompty` template bodies. The renderer's unrestricted JavaScript member access permits traversal of constructor and prototype properties, leading to remote code execution when rendering untrusted, community-supplied, cloned, or LLM-generated `.prompty` files.
Suna Broken Access Control Vulnerability (CVE-2026-66027)
4 TTPs 1 CVEA broken access control vulnerability in Suna's message queue API allows authenticated attackers to gain unauthorized access to and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. This exploit enables attackers to read all users' pending prompt queues, read or delete individual sessions, and inject arbitrary prompts into another user's session, which causes the background drainer to forward malicious messages to the victim's AI agent using their credentials and permissions, leading to potential data manipulation, unauthorized actions, or further compromise.
Account Takeover via Pre-Account Hijacking in Better Auth Library
3 TTPsAn attacker can perform a pre-account hijacking attack against the `better-auth` library if it uses magic-link or email-OTP plugins alongside open email and password registration and allows unverified accounts. The attacker first registers an account using the victim's email with a password they control. When the legitimate victim later uses a passwordless flow to verify their account, the attacker's pre-set password remains active, granting them persistent, unauthorized access to the victim's account and data, potentially leading to account takeover and user lockout.
Account Takeover and Stale Access via SCIM Provider-ID Collision in @better-auth/scim
5 TTPsThe `@better-auth/scim` package is affected by multiple vulnerabilities, including a critical provider-ID collision flaw that allows authenticated users to craft SCIM tokens impersonating existing account providers, leading to unauthorized account access, profile modification, and user deletion, while additional issues include failed user deactivation and email update vulnerabilities bypassing uniqueness checks in versions `1.4.0-beta.27` through `1.6.21` and `1.7.0-beta.0` through `1.7.0-beta.9`.
CVE-2026-8789: Easy Appointments WordPress Plugin Data Modification Vulnerability
1 rule 1 TTP 1 CVEThe Easy Appointments plugin for WordPress, in versions up to and including 3.12.27, is vulnerable to unauthorized data modification due to a missing capability check and nonce verification on the `ea_delete_multiple_connections` AJAX action, allowing authenticated attackers with Contributor-level access or higher to delete arbitrary connection records and disrupt core booking functionality.
httplib2 Decompression Bomb Denial of Service via Unbounded Gzip/Deflate Handling
1 TTP 1 CVEA high-severity vulnerability in the `httplib2` Python client library allows a remote attacker to trigger a denial-of-service condition by sending a crafted HTTP response with a small, highly compressed payload that expands excessively upon decompression, causing memory exhaustion or OOM-kill in the client process.
LiquidJS pop Filter Bypasses Memory Limit Accounting
1 TTP 1 CVEA vulnerability (CVE-2026-55575) in the LiquidJS templating library's `pop` filter, affecting versions up to and including 10.27.0, allows an attacker to bypass the `memoryLimit` accounting, leading to uncontrolled memory allocation and potential denial of service when processing untrusted, large arrays in templates.
electron-updater Vulnerability Leaks Credentials on Cross-Origin Redirects
2 TTPs 1 CVEA vulnerability, CVE-2026-54673, in `electron-builder`'s `builder-util-runtime` package, specifically in its HTTP redirect handler, allows credential headers like `PRIVATE-TOKEN` (GitLab personal access tokens) and mixed-case `Authorization` tokens to be improperly forwarded to attacker-controlled cross-origin redirect destinations, resulting in credential disclosure and enabling unauthorized access to private GitLab resources.
Multiple Vulnerabilities in MongoDB Core Server and Compass
2 TTPs 5 CVEs 52 IOCsNumerous vulnerabilities across MongoDB Core Server and Compass, identified as CVE-2026-13055 through CVE-2026-13078, CVE-2026-14881, and CVE-2026-9737, enable attackers to bypass security policies and induce denial-of-service conditions, necessitating immediate patching.
Multiple Privilege Escalation Vulnerabilities in ESET macOS Products
1 TTP 2 CVEs 4 IOCsMultiple vulnerabilities discovered in ESET Cyber Security and Endpoint Security for macOS allow an attacker to achieve privilege escalation on affected systems, posing a significant risk to macOS users.
Multiple Vulnerabilities in Progress Software MOVEit Transfer
4 TTPsMultiple vulnerabilities in Progress Software MOVEit Transfer allow attackers to bypass security measures, achieve elevated privileges, and manipulate or disclose sensitive data, including the ability to perform Cross-Site-Scripting (XSS) attacks.
FFmpeg: Multiple Vulnerabilities Allow Code Execution and DoS
2 TTPsMultiple vulnerabilities in FFmpeg allow an attacker to achieve arbitrary code execution or cause a denial-of-service condition.
Multiple Netty Vulnerabilities Enable Denial of Service Attacks
1 TTPMultiple vulnerabilities in Netty can be exploited by an attacker to conduct Denial of Service (DoS) attacks, impacting the availability of services utilizing the Netty framework.
JetBrains WebStorm Multiple Vulnerabilities Allow Code Execution
1 TTPMultiple vulnerabilities in JetBrains WebStorm allow a local attacker to execute arbitrary program code, enabling attackers to compromise the integrity and confidentiality of the affected system.
JetBrains IntelliJ IDEA: Multiple Vulnerabilities
4 TTPsMultiple vulnerabilities have been identified in JetBrains IntelliJ IDEA, which a remote, unauthenticated attacker can exploit to disclose sensitive information, execute arbitrary code on affected systems, and bypass existing security measures.
Red Hat Quay Vulnerability Allows Authenticated Remote Attacker to Bypass Security
1 TTPAn authenticated remote attacker can exploit a vulnerability in Red Hat Quay to bypass security measures, circumventing established security controls within the container registry.
QT Vulnerability Enables File Manipulation
1 TTPA remote, anonymous attacker can exploit a vulnerability in QT to manipulate files, potentially affecting data integrity or system functionality.
Apache Tomcat mod_jk Connector: Vulnerability Enables Security Bypass or Information Disclosure
2 TTPsA vulnerability in the Apache Tomcat mod_jk Connector allows a remote, unauthenticated attacker to bypass security measures or disclose sensitive information, which could enable an adversary to gain unauthorized access or collect confidential data.
CVE-2026-57106 Microsoft Data Quality Elevation of Privilege Vulnerability
1 TTPCVE-2026-57106 describes a server-side request forgery (SSRF) vulnerability in Microsoft Data Quality that allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-63313 - Server-Side Request Forgery in 9Router
1 rule 4 TTPs 1 CVE9Router versions prior to 0.4.72 contain a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint, allowing an authenticated or locally-connected user to bypass URL validation to fetch arbitrary internal URLs, potentially exposing cloud metadata credentials, accessing internal services, and bypassing authentication on localhost endpoints.
9router Critical Vulnerability Chain Allows Remote Code Execution via Default Password and Plugin Exploitation
2 rules 3 TTPs 1 CVE 1 IOCA critical vulnerability chain, CVE-2026-63732, in 9router version 0.4.59 allows a remote, unauthenticated attacker to achieve arbitrary code execution on the host operating system by leveraging a hardcoded default password for initial access, bypassing a local-only network restriction via Host header spoofing, and exploiting unvalidated arguments during MCP plugin registration to execute malicious code when a plugin's SSE endpoint is triggered.
Repository Takeover Vulnerability in cal.com GitHub Actions (CVE-2024-58354)
1 TTP 1 CVEA critical repository takeover vulnerability (CVE-2024-58354) exists in the cal.com (calcom/cal.diy) GitHub Actions workflows, allowing an attacker to submit a malicious pull request that executes arbitrary commands with write permissions to the repository, leading to full compromise.
Critical Out-of-Bounds Write Vulnerability in FFmpeg (CVE-2026-65706)
1 TTP 1 CVEA critical out-of-bounds write vulnerability (CVE-2026-65706) exists in FFmpeg versions 3.0 through 8.1.2 within the vf_swaprect video filter, allowing attackers to corrupt heap memory and achieve potential remote code execution by providing a specially crafted NV12 video frame with odd width dimensions.
Out-of-Bounds Write Vulnerability in FFmpeg vf_floodfill Filter (CVE-2026-65705)
1 CVEA critical out-of-bounds write vulnerability exists in FFmpeg versions 3.4 through 8.1.2 within the vf_floodfill video filter, which attackers can exploit by providing a specially crafted, dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0, leading to heap corruption, a process crash, and potentially remote code execution.
FFmpeg TDSC Video Decoder Out-of-Bounds Write Vulnerability
1 TTP 1 CVEAn out-of-bounds write vulnerability (CVE-2026-65703) exists in the TDSC video decoder within FFmpeg versions 2.7 through 8.1.2, allowing remote attackers to cause heap corruption and potential code execution by supplying a specially crafted AVI file with changing frame dimensions across TDSF frames.
CVE-2026-15212: WordPress WPO365 Login Plugin Cross-Site Request Forgery Vulnerability
1 rule 4 TTPs 1 CVEA Cross-Site Request Forgery (CSRF) vulnerability in the WPO365 | Login plugin for WordPress, affecting versions up to and including 43.2, allows unauthenticated attackers to overwrite arbitrary plugin options. This is due to a misconfiguration where the nonce check is effectively disabled. By tricking a site administrator into clicking a malicious link, an attacker can manipulate settings such as enabling the SCIM REST endpoint, planting a SCIM secret token, and setting the default user role for new registrations to 'administrator', potentially leading to full site compromise and unauthorized administrative access.
Denial of Service Vulnerability in find-my-way Node.js Router
1 rule 2 TTPsA remotely triggerable Denial of Service (DoS) vulnerability exists in the 'find-my-way' router when used with Node.js HTTP/2 servers. Malicious HTTP/2 method values, such as 'constructor' or '__proto__', can be passed to the 'lookup()' function, which then indexes these values against internal data structures. This leads to a crash when the code attempts to access properties of these unexpected values, such as 'currentNode.prefix.length', causing the server to become unavailable. Users are advised to upgrade to version 9.7.0 or validate HTTP methods before processing.
CVE-2026-63765: Chatwoot Authentication Bypass Vulnerability in Direct Uploads Controller
1 rule 2 TTPs 1 CVEChatwoot before version 4.16.0 contains an authentication bypass vulnerability in its direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account by exploiting missing authentication checks, leading to data manipulation.
Vanna FileSystemConversationStore Path Traversal Vulnerability (CVE-2026-65702)
1 rule 3 TTPs 1 CVEVanna versions up to and including 2.0.2 contain a path traversal vulnerability in its FileSystemConversationStore persistence integration, allowing unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary server filesystem locations and read conversation metadata or other files from outside the intended base directory by supplying path traversal sequences within the 'conversation_id' parameter to unauthenticated chat API endpoints.
pypdf: Possible infinite loop for not terminated inline images
1 CVEAn attacker can exploit a vulnerability in the pypdf library by crafting a PDF containing a malformed, not terminated inline image. When this malicious PDF is processed by pypdf, such as during text extraction, it triggers an infinite loop, leading to a denial of service. The issue is resolved in pypdf version 6.14.1.
CyberPanel Insecure Direct Object Reference (IDOR) Vulnerability (CVE-2026-65917)
3 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability, tracked as CVE-2026-65917, exists in CyberPanel versions through 1.9.1, specifically within the IncBackups application's incremental-backup handlers, allowing authenticated panel users to exploit attacker-controlled IncJob integer IDs to access, read metadata from, delete, or trigger unauthorized restoration of other tenants' backup resources, potentially leading to operations with root privileges.
PHPSpreadsheet Denial of Service via Malformed XLS/OLE Sector Chain
1 TTPPhpSpreadsheet's OLE reader contains a denial-of-service vulnerability where it fails to detect cycles in attacker-controlled XLS/OLE sector chains, leading to infinite loops and memory exhaustion when parsing specially crafted, small malformed XLS/OLE files, which can cause PHP workers to crash and deny service to web applications processing untrusted spreadsheet uploads.
PostCSS: Arbitrary File Read and Information Disclosure via sourceMappingURL
3 TTPsA high-severity vulnerability (CVE-2026-45623) in PostCSS's `PreviousMap` component allows attackers to perform arbitrary file reads and information disclosure from the local filesystem by injecting malicious `sourceMappingURL` comments into untrusted CSS input, leading to sensitive data leakage and denial of service.
PhpSpreadsheet Gnumeric Reader Unbounded Gzip Expansion Leads to Denial of Service
1 TTPThe PhpOffice PhpSpreadsheet library is vulnerable to a denial of service (DoS) attack, identified as CVE-2026-59932, where its Gnumeric reader processes attacker-supplied `.gnumeric` files containing gzipped content without enforcing a decompressed-size limit, causing memory exhaustion and application crashes.
Auth.js getToken() Vulnerability Leads to Denial of Service
1 TTPA vulnerability in the Auth.js `getToken()` helper function (next-auth and @auth/core) allows unauthenticated attackers to trigger an uncaught exception via a malformed `Authorization: Bearer` header, leading to a per-request denial of service in affected applications.
Bold Reports Standalone Report Designer Path Traversal to RCE Vulnerability
1 rule 1 TTP 1 CVE 2 IOCsA missing filepath validation vulnerability (CVE-2026-65690) in Bold Reports Standalone Report Designer before version 14.1.12 allows authenticated attackers to perform path traversal via crafted filenames during file upload, leading to arbitrary command execution with high privileges.
CVE-2026-65689: Bold Reports Standalone Report Designer Path Traversal Vulnerability
1 rule 1 TTP 1 CVEA missing filepath validation vulnerability (CVE-2026-65689) in Bold Reports Standalone Report Designer before version 14.1.12 allows unauthenticated attackers to perform path traversal by sending a crafted request to the database download feature, enabling them to read arbitrary sensitive server files, including authentication credentials, and potentially gain full unauthorized access to the application.
Grav API Plugin Privilege Escalation via Invitation Group Manipulation (CVE-2026-65897)
1 TTP 1 CVE 4 IOCsAn authenticated attacker can exploit CVE-2026-65897 in Grav API Plugin versions prior to 1.0.10 by manipulating the 'groups' field during invitation creation, allowing invited accounts to gain super-admin API access, leading to privilege escalation.
Grav API Plugin Path Traversal Vulnerability (CVE-2026-65896)
3 TTPs 1 CVEAn authenticated API caller with 'api.pages.write' permission in Grav API Plugin (Composer package getgrav/grav-plugin-api) before version 1.0.10 can exploit a path traversal vulnerability (CVE-2026-65896). The 'POST /pages/{route}/move' endpoint's 'slug' field is not properly sanitized, allowing attackers to use path traversal sequences (e.g., '01.home/../../../pwned'). This enables them to move an entire page directory, including content and media, to an arbitrary writable location outside the intended 'user/pages/' directory, potentially leading to unauthorized file manipulation or system compromise.
Grav API Plugin Missing Authorization Allows Security Settings Modification
1 TTP 1 CVEGrav API Plugin versions prior to 1.0.10 contain a missing authorization vulnerability (CVE-2026-65895) allowing authenticated users with the 'api.config.write' privilege to modify critical security settings, including disabling site-wide rate limiting to enable credential brute-forcing attacks and reconfiguring CORS policies to include attacker-controlled origins with credentials enabled, potentially leading to unauthorized data access.
CVE-2026-65606 - SiYuan XSS to RCE Vulnerability
2 TTPs 1 CVEA critical cross-site scripting (XSS) vulnerability, CVE-2026-65606, exists in SiYuan desktop application versions prior to 3.7.2's `siyuan://` protocol handler, allowing an attacker to inject an unescaped `<img>` element into the tab header, leading to arbitrary JavaScript execution and ultimately operating system command execution due to `nodeIntegration:true`.
Exim: Multiple Vulnerabilities Allow Local Command Execution and Privilege Escalation
2 TTPsMultiple vulnerabilities in Exim allow a local attacker to execute arbitrary commands and escalate privileges on the affected system, enabling a local adversary to gain higher control over the mail transfer agent and potentially the underlying operating system.
Multiple Vulnerabilities in Mitel Products Allow Remote Code Execution and XSS
3 TTPs 2 IOCsMultiple vulnerabilities have been discovered in Mitel MiCollab and Openscape UC products, enabling a remote attacker to achieve arbitrary code execution and conduct indirect remote code injection (XSS), posing significant risks to affected organizations.
CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement
1 TTP 1 CVEA high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.
Multiple Vulnerabilities in n8n Workflow Automation Platform
5 TTPsAn attacker can exploit multiple vulnerabilities in the n8n workflow automation platform to bypass security measures, perform a Denial of Service attack, disclose sensitive information, manipulate files, conduct SQL injection, and execute arbitrary code.
Mitel MiCollab Vulnerability Allows Remote Code Execution
1 TTPA critical vulnerability in Mitel MiCollab allows a remote, unauthenticated attacker to execute arbitrary code, which could lead to full system compromise or further network penetration.
Multiple Vulnerabilities Affect MongoDB
5 TTPsMultiple vulnerabilities in MongoDB allow an attacker to execute arbitrary code, bypass security measures, disclose confidential information, manipulate data, cause memory corruption, or trigger a denial-of-service condition.
Mitel OpenScape Cross-Site Scripting Vulnerability
1 rule 1 TTPA remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Mitel OpenScape, allowing the execution of malicious scripts in the victim's browser, potentially leading to session hijacking, data theft, or redirection to malicious websites.
Budibase: Multiple Vulnerabilities
5 TTPs 1 CVE 9 IOCsMultiple vulnerabilities in Budibase allow an attacker to gain elevated privileges, perform SQL injection, bypass security measures, take over user accounts, manipulate or disclose data, and trigger a denial-of-service condition, enabling various malicious activities impacting data integrity, confidentiality, and system availability.
Internet Systems Consortium BIND: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.
Intel Ethernet Products: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities exist in various Intel Ethernet products, which an attacker can exploit to trigger a denial-of-service condition and expose confidential information.
OS Command Injection Vulnerability in Pardus-Update (CVE-2026-16287)
1 TTP 1 CVE 1 IOCA high-severity OS command injection vulnerability, tracked as CVE-2026-16287, has been identified in the TUBITAK BILGEM Software Technologies Research Institute's pardus-update software, affecting versions from 0.6.6 before 0.7.0, enabling attackers to execute arbitrary operating system commands due to improper neutralization of special elements.
ARforms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via 'password' Field (CVE-2026-12421)
2 TTPs 1 CVEAn insufficient input sanitization and output escaping vulnerability (CVE-2026-12421) in the ARforms plugin for WordPress, affecting versions up to and including 7.2.1, allows unauthenticated attackers to inject arbitrary web scripts via the 'password' field, leading to Stored Cross-Site Scripting (XSS) when a user accesses an injected page.
Excon Redirection Vulnerability (CVE-2026-54171)
1 CVEA vulnerability, CVE-2026-54171, has been identified in the Excon library concerning the redaction of sensitive or risky headers when following redirects, which could potentially expose confidential information if not properly addressed.
HAProxy Denial of Service Vulnerability (CVE-2026-26080)
1 CVEA denial of service vulnerability (CVE-2026-26080) in HAProxy Community Edition versions 3.2.x through 3.3.x before 3.3.3, HAProxy Enterprise, and ALOHA can lead to a loop or crash due to mishandled varint, impacting service availability.
Libunbound Denial of Service via unwanted-reply-threshold
1 TTP 1 CVECVE-2026-44621 describes a vulnerability in Libunbound applications where, when configured with the 'unwanted-reply-threshold' option, they can be abruptly terminated, leading to a denial of service.
Improper Input Validation in boazsegev facil.io WebSocket Frame Parser (CVE-2026-16632)
1 TTP 1 CVEA high-severity improper input validation vulnerability, CVE-2026-16632, exists in the `websocket_on_protocol_error` function of the `boazsegev facil.io` WebSocket Frame Parser, allowing a remote unauthenticated attacker to manipulate the `on_message` argument with a publicly available exploit, potentially leading to denial of service or information disclosure.
JupyterLab Cross-site Scripting via Crafted Settings File
6 TTPsA cross-site scripting (XSS) vulnerability exists in JupyterLab versions 3.3.0 through 4.5.9 and 4.6.0 through 4.6.1, allowing arbitrary code execution because notebook display settings in the `overrides.json` file are not properly validated, enabling an attacker to craft a malicious file which, when imported by a user or automatically applied on a multi-tenant file system, can execute hidden instructions and compromise user data.
JupyterLab Image Viewer XSS Vulnerability Leading to RCE
2 TTPsA cross-site scripting (XSS) vulnerability exists in JupyterLab's image viewer, allowing an attacker to achieve remote code execution (RCE) on the JupyterLab server if a specially crafted image file is opened in the image viewer and then opened in a new browser tab; affected versions include JupyterLab prior to 4.5.10 and versions from 4.6.0 up to, but not including, 4.6.2, with patches available in versions 4.5.10 and 4.6.2.
Eclipse Jetty Denial of Service Vulnerability via 100-Continue Requests (CVE-2024-7708)
1 TTP 1 CVEA memory leak vulnerability, CVE-2024-7708, in Eclipse Jetty's server handling of HTTP 100-Continue requests can be exploited by an attacker to trigger an OutOfMemory error, leading to a Denial of Service state for affected servers.
n8n Edit Image Node Format Injection Allows Arbitrary File Write
2 TTPsAn authenticated user can exploit a format injection vulnerability in the n8n Edit Image node to write arbitrary files outside the node's working directory within the n8n instance, potentially leading to remote code execution or other significant impact.
n8n Git Node Operations Bypass Sandbox Path Restriction
3 TTPsAn authenticated n8n user can exploit a path restriction bypass vulnerability within the Git node's fetch, pull, or push-tags operations to access arbitrary local Git repositories and their contents, potentially leading to sensitive data exposure.
Authenticated Code Execution Vulnerability in n8n Git Node
5 TTPsAn authenticated n8n user with workflow creation and execution rights can achieve arbitrary code execution on the n8n host by staging a crafted local Git repository within the Git node, causing Git to run malicious hooks as the n8n process user.
n8n Account Takeover via Unverified Email Claim in Token Exchange Embed Login
2 rules 7 TTPsA high-severity vulnerability in n8n's embed login feature (CVE-2026-XXXX) allows attackers to achieve full account takeover by leveraging unverified email claims in incoming tokens, enabling authentication as any existing user if the instance has embed login enabled and a trusted key source configured that emits unverified email addresses.
n8n Privilege Escalation and Code Execution via Flawed JWT Scope Assignment (CVE-2026-65595)
2 TTPs 1 CVEA critical vulnerability, CVE-2026-65595, in n8n's Token Exchange module allows low-privileged users to achieve privilege escalation and potential code execution by exploiting incorrect Public API key scope assignments to JWTs, enabling administrative operations.
n8n AI Agents Module Restriction Bypass via MCP Connector (CVE-2026-59207)
1 TTP 1 CVEThe n8n AI Agents module in versions prior to 2.27.4 and between 2.28.0 and 2.28.1 failed to enforce configured 'Allowed HTTP Request Domains' restrictions, allowing an authenticated member-level user with 'use-only' access to a shared credential to bypass these domain restrictions and exfiltrate sensitive secrets to an attacker-controlled server.
n8n Shared Credential Leakage via HTTP Request Pagination Vulnerability
5 TTPs 1 CVEAn authenticated n8n user with 'use-only editor access' can exploit CVE-2026-59209 in shared workflows when `N8N_EXPRESSION_ENGINE=vm` is enabled, allowing them to read sensitive HTTP Header Auth credentials from the `$request.headers` object within a paginated HTTP Request node's expression and exfiltrate them, bypassing credential domain restrictions.
Netty Bzip2Decoder Infinite Loop Vulnerability Leads to Event-Loop Thread Hang (CVE-2026-59901)
1 TTPA denial-of-service vulnerability exists in the `Bzip2Decoder` handler within Netty's `netty-codec-compression` and `netty-codec` libraries, allowing a remote attacker to exploit CVE-2026-59901 by providing a specially crafted bzip2 stream, which causes an infinite loop in the run-length encoding state machine, leading to the permanent hang of an event-loop thread and application denial of service.
Netty XML Injection Vulnerability (CVE-2026-56817)
1 rule 1 TTP 1 CVEA misconfiguration vulnerability (CVE-2026-56817) in Netty's XmlDecoder component allows attackers to send XML with DOCTYPE declarations to an unconfigured XML factory, potentially leading to XML External Entity (XXE) injection if the underlying Aalto XML parser resolves external entities, impacting Netty applications using `netty-codec-xml` versions 4.1.0.Final through 4.1.135.Final and 4.2.0.Final through 4.2.15.Final.
Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks
1 CVEA critical vulnerability (CVE-2026-56820) in Netty's `OcspClient` allows a bad actor to bypass certificate revocation checks by replaying a valid OCSP 'GOOD' status response from an unrelated certificate, enabling a certificate validation bypass for any certificate issued by the same Certificate Authority.
Netty HTTP/3 Codec Vulnerability Leads to Denial of Service via Memory Exhaustion
1 TTP 1 CVEA vulnerability in Netty's HTTP/3 `Http3FrameCodec`, tracked as CVE-2026-56816, allows an unauthenticated remote attacker to cause a denial of service by sending crafted reserved HTTP/3 frames with an excessively large, unvalidated payload length, leading to server memory exhaustion.
Netty HAProxyMessageDecoder Vulnerability Leads to Unbounded Memory Exhaustion
1 CVEA vulnerability, CVE-2026-55851, in Netty's `HAProxyMessageDecoder` can lead to unbounded memory exhaustion when an attacker sends a specific PROXY protocol v2 binary prefix followed by a version byte of `0xFF`, causing a signed-byte sentinel collision that traps the decoder in a version-detection loop and ultimately exhausts the JVM's direct memory allocation, resulting in a denial of service.
Netty SPDY SETTINGS Frame Denial of Service Vulnerability
3 TTPs 1 CVE 1 IOCA high-severity vulnerability, CVE-2026-55831, in Netty's SPDY SETTINGS decoder allows a remote unauthenticated attacker to trigger a denial of service by sending a crafted SPDY/3.1 SETTINGS frame that leads to excessive heap growth and CPU consumption due to unbounded map entries in `DefaultSpdySettingsFrame`.
Question2Answer Session Invalidation Vulnerability
2 TTPs 1 CVEAttackers can exploit CVE-2026-64829, a session invalidation vulnerability in Question2Answer through version 1.8.8, where the forgot-password reset flow fails to clear the sessioncode field, allowing an attacker with a previously obtained remember-me cookie to retain authenticated access even after the account's password has been reset.
Critical Access Bypass Vulnerability in Drupal Internationalization Single Sign-On Module
1 TTPA critical access bypass vulnerability (SA-CONTRIB-2026-081) exists in the Internationalization Single Sign-On module for Drupal, affecting versions prior to 1.8.0, allowing an attacker to bypass authentication mechanisms and potentially gain unauthorized access or elevate privileges within the application.
FFmpeg RTP/ASF Demuxer Infinite Loop Vulnerability (CVE-2026-64834)
1 TTP 1 CVEFFmpeg versions 0.6.3 through 8.1.2 are vulnerable to a remote denial of service (DoS) via CVE-2026-64834, allowing an attacker to trigger an infinite loop in the `rtp_asf_fix_header` function by sending a crafted RTP/ASF stream, leading to CPU exhaustion and service unavailability.
Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Actively Exploited
1 TTP 4 CVEs 6 IOCsCheck Point released a critical security advisory to address CVE-2026-16232, an authentication bypass vulnerability in SmartConsole, which is actively being exploited in the wild and affects Security Management, Multi-Domain Management, Firewall, and Multi-Domain Log Server products.
FFmpeg ADX Audio Decoder Out-of-Bounds Memory Access Vulnerability
1 CVEA high-severity out-of-bounds memory access vulnerability, tracked as CVE-2026-64835, exists in FFmpeg versions 4.4 through 8.1.2 within the ADX audio decoder, allowing attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change, potentially leading to denial of service, information disclosure, or arbitrary code execution.
FFmpeg Out-of-Bounds Read Vulnerability in S/PDIF Muxer (CVE-2026-64833)
1 TTP 1 CVEFFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer, allowing attackers to exploit a missing bounds check in the `spdif_header_dts4` function by supplying a crafted DTS stream with an oversized `core_size` value during S/PDIF re-muxing, leading to unauthorized memory reads beyond the packet buffer and potential information disclosure or denial of service.
FFmpeg NVIDIA NVDEC Double-Free Vulnerability (CVE-2026-64832)
1 CVEFFmpeg versions 4.4 through 8.1.2 are vulnerable to a double-free condition within the NVIDIA NVDEC hardware decoder component (libavcodec/nvdec.c), allowing attackers to trigger memory corruption by providing a specially crafted video file, which occurs when an error path frees memory via `nvdec_fdd_priv_free` due to no decoder surfaces remaining, and a subsequent layer attempts to free the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware acceleration.
n8n Authenticated Code Execution Vulnerability
1 TTPA security advisory from CCCS highlights an authenticated code execution vulnerability (GHSA-rcv6-pvrj-4xcg) within the n8n Git node, affecting multiple versions prior to 1.123.67, 2.32.1, and 2.31.5, which could allow an authenticated attacker to execute arbitrary code on the host system.
n8n AI Agents Privilege Escalation via run_node_tool
1 rule 1 TTP 1 CVEA privilege escalation vulnerability (CVE-2026-65015) exists in n8n's AI Agents feature, allowing users with the read-only Project Viewer role to execute arbitrary tool nodes and access unauthorized credential secrets, potentially leading to arbitrary command execution on the n8n host.
n8n DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
2 TTPs 1 CVEA DOM-Based Cross-Site Scripting (XSS) vulnerability in n8n allows an attacker to inject scripts into the HTML preview through an unsandboxed iframe srcdoc, enabling the injected script to run with the same origin as the editor; if a victim opens this compromised preview, the script can call authenticated APIs using their session, allowing an account with 'global:member' privileges to exploit this to gain unauthorized access or perform actions.
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
2 TTPs 1 CVEA stored DOM XSS vulnerability in n8n's Resource Locator feature allows attackers to inject malicious JavaScript into the cachedResultUrl parameter. When a victim opens a specially crafted workflow and interacts with external links, the JavaScript payload executes in their browser, due to a lack of scheme validation for `cachedResultUrl` passed to `window.open()`.
FFmpeg Vulkan HEVC Stack Buffer Overflow (CVE-2026-64831)
1 TTP 1 CVEA stack buffer overflow vulnerability exists in the Vulkan HEVC hardware decoder within FFmpeg versions 8.0 through 8.1.2, allowing remote attackers to achieve arbitrary code execution by crafting a malicious HEVC/H.265 bitstream with an oversized vps_num_hrd_parameters value that overwrites return addresses and adjacent stack frames in the vk_hevc_end_frame function.
FFmpeg VobSub Heap Buffer Overflow Vulnerability (CVE-2026-64830)
1 TTP 1 CVEFFmpeg versions 2.1 through 8.1.2 contain a heap buffer overflow vulnerability (CVE-2026-64830) in the VobSub subtitle demuxer, allowing attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file, potentially leading to arbitrary code execution in applications using FFmpeg's VobSub demuxer.
CVE-2026-13321 BIND Resolver Origin Validation Error
1 CVECVE-2026-13321 describes a vulnerability in the BIND resolver where it incorrectly accepts validly-signed NSEC records that contain a 'Next Domain Name' field pointing outside the signer's zone, impacting integrity with a CVSSv3.1 score of 8.6 and requiring immediate updates to affected BIND 9 installations.
CVE-2026-13204: BIND 9 Denial-of-Service Vulnerability
1 TTP 1 CVEA critical vulnerability (CVE-2026-13204) in Internet Systems Consortium (ISC) BIND 9 can lead to a denial-of-service condition where the server exits unexpectedly due to an assertion failure during DNSSEC validation of specific NSEC/NSEC3 record configurations. This allows an unauthenticated attacker to cause a BIND 9 DNS resolver to crash, disrupting DNS resolution services.
CVE-2026-12617: BIND 9 Denial of Service via Malicious DNS Responses
1 CVEThis vulnerability affects BIND 9 resolver (`named`) and can lead to unexpected program termination (denial of service). The issue occurs when the resolver receives specific, delayed, or out-of-order responses to queries for CNAME or DNAME and A records. Specifically, if an authoritative server delays a DNAME or self-referential CNAME response while providing an A record, the `named` process may crash.
CVE-2026-11622: BIND 9 DNSSEC Resolver Memory Exhaustion Vulnerability
1 TTP 1 CVEA DNSSEC validating resolver, specifically BIND 9 versions within the ranges 9.11.0-9.18.50, 9.20.0-9.20.24, 9.21.0-9.21.23, and their S1 variants, is vulnerable to a denial-of-service attack where an attacker can launch a random subdomain attack against a DNSSEC-signed zone by sending queries faster than the resolver can perform validation, leading to runaway memory usage and potentially exceeding configured limits by orders of magnitude.
Resource Exhaustion Vulnerability in BIND 9 DNSSEC Validation (CVE-2026-11605)
1 TTP 1 CVEA resource exhaustion vulnerability, CVE-2026-11605, affects specific versions of ISC BIND 9, where DNSSEC validation disproportionately consumes CPU resources when processing superfluous RRSIG records, potentially leading to a denial of service.
CVE-2026-11331: BIND 9 RPZ Bypass and Denial of Service Vulnerability
1 CVEAn attacker can exploit CVE-2026-11331, a flaw in ISC BIND 9's RPZ (Response Policy Zone) processing, by crafting long query names to trigger a mishandled NAMETOOLONG error, leading to either a bypass of RPZ rules or a denial of service due to an unexpected exit of the BIND 9 software.
CVE-2026-2395: Critical SQL Injection in Xpoda No Code Platform
1 rule 3 TTPs 1 CVE 1 IOCXpoda Türkiye Informatics Technology Inc.'s No Code Platform, specifically versions 4.3.1.0 through 20260722, is critically vulnerable to an SQL injection (CVE-2026-2395) that allows unauthenticated remote attackers to achieve high impact on the confidentiality, integrity, and availability of the system.
Multiple Vulnerabilities in Elastic Products
5 CVEsCERT-FR has issued an advisory detailing multiple vulnerabilities in Elastic products, including CVE-2026-42397 and CVE-2026-49092, which could allow an attacker to cause remote denial of service, compromise data confidentiality and integrity, and perform Server-Side Request Forgery (SSRF).
Multiple Vulnerabilities in GLPI
3 TTPsMultiple vulnerabilities have been discovered in GLPI, specifically affecting versions 11.0.x prior to 11.0.8 and all versions prior to 10.0.26, which allow an attacker to compromise data confidentiality and integrity, and bypass security policies.
CVE-2026-4773: Authentication Bypass Vulnerability in Magarsus Consulting IDM-MFA
1 TTP 1 CVECVE-2026-4773 is an improper input validation vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA, allowing authentication bypass in versions from 2025.11.27 before 2026.03.10.
Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)
1 TTP 1 CVEA command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.
Aruba AOS-CX: Multiple Vulnerabilities
1 TTPMultiple vulnerabilities in Aruba AOS-CX can be exploited by an attacker to bypass security measures, execute arbitrary code, and manipulate files, which could lead to compromise of the network device.
Ubuntu Desktop Vulnerability Allows Local Root Access via snap-confine
1 TTP 1 CVEA high-severity vulnerability, CVE-2026-8933, in Ubuntu's snap-confine component of the snapd service allows an unprivileged local user to gain root access on affected Ubuntu Desktop systems by exploiting race conditions during temporary file creation, enabling full administrative control.
SolarWinds Serv-U: Multiple Critical Vulnerabilities
7 TTPsA remote, highly privileged attacker can exploit multiple vulnerabilities in SolarWinds Serv-U to execute arbitrary code as Root, gain administrator privileges, take over accounts, disclose confidential information, or perform Cross-Site Scripting attacks.
Veeam Backup & Replication: Vulnerability Enables Privilege Escalation
1 TTPA vulnerability in Veeam Backup & Replication allows a local attacker to escalate privileges on the affected system.
Ansible: Local Code Execution Vulnerability
1 TTPA local attacker can exploit a vulnerability within Ansible software to execute arbitrary code on the affected system, potentially leading to further compromise or unauthorized actions on the host where Ansible is running.
Multiple Vulnerabilities in Red Hat Ansible Automation Platform
5 TTPsMultiple vulnerabilities exist in Red Hat Ansible Automation Platform, stemming from issues in components such as node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, and DOMPurify. A remote, unauthenticated attacker can exploit these flaws to bypass security measures, perform Cross-Site Scripting (XSS) attacks, manipulate data, trigger Denial-of-Service (DoS) conditions, or execute arbitrary code on the affected system.
Avahi Vulnerability Allows Local Denial of Service
1 TTPA vulnerability in the avahi service allows a local attacker to perform a Denial of Service (DoS) attack, potentially leading to the unavailability of services or the system itself.
Libarchive Vulnerability Enables Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in libarchive to initiate a Denial of Service attack, disrupting the availability of services or systems utilizing the affected library.
Information Published for CVE-2026-64191
1 CVEInformation has been published regarding CVE-2026-64191, which addresses an issue in the i2c stub related to rejecting I2C block transfers with invalid lengths.
Oracle Java SE and GraalVM Vulnerability CVE-2026-47063 Allows Unauthenticated Data Integrity Compromise
2 TTPs 1 CVEAn easily exploitable vulnerability, CVE-2026-47063, in Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition allows unauthenticated attackers with network access to achieve unauthorized creation, deletion, or modification of critical data via API exploitation, impacting data integrity.
Multiple High-Severity Vulnerabilities in sharp and libvips Image Processing Libraries
4 CVEsMultiple high-severity vulnerabilities, including CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, and CVE-2026-35591, have been identified and patched in the libvips dependency used by the sharp image processing library, affecting users processing untrusted input with sharp versions prior to 0.35.0 or globally installed libvips prior to 8.18.3.
Gitea OAuth Callback Re-enables Administrator-Disabled Accounts
2 TTPs 1 CVEAn improper authorization vulnerability in Gitea's OAuth2 sign-in callback mechanism (CVE-2026-58422) allows users with linked external identity providers to unilaterally re-enable their administrator-disabled accounts, regaining full access and bypassing security controls.
Server-Side Request Forgery in mcp-webresearch (CVE-2026-65056)
4 TTPs 1 CVEA server-side request forgery (SSRF) vulnerability in mcp-webresearch version 0.1.7 allows attackers to bypass URL protocol validation by supplying private IP addresses, enabling them to leverage prompt injection to steer an LLM-controlled URL, forcing the server's Playwright browser to access internal network services and cloud instance metadata, which leads to the exfiltration of sensitive internal content, including credentials, into the model's context.
CVE-2026-65057 Server-Side Request Forgery in Keep Healthcheck Endpoint
1 rule 2 TTPs 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability in Keep (commit 91c75e0) allows attackers to exploit an unprotected healthcheck endpoint by supplying crafted JSON payloads with malicious host values, forcing the backend to issue arbitrary HTTP requests to internal services or cloud metadata endpoints for internal network reconnaissance and theft of cloud credentials.
CVE-2026-63764: Server-Side Request Forgery in lmdeploy OpenAI-Compatible API Server
1 rule 1 TTP 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability, CVE-2026-63764, exists in lmdeploy's OpenAI-compatible API server, allowing attackers to access internal services and cloud metadata by submitting a crafted image_url that redirects to internal targets.
Gitea OAuth2 Sign-in Flaw Reactivates Administrator-Deactivated Accounts
3 TTPsA vulnerability (CVE-2026-55987) in Gitea's OAuth2 sign-in allows administrator-deactivated user accounts to be reactivated upon re-authentication through specific authentication sources (like GitHub or OIDC/OAuth2 without refresh tokens), enabling users to regain full access, potentially including administrator privileges, by bypassing the intended deactivation.
Gitea LFS Authentication Bypass via Malformed SSH Sub-Verb
1 rule 4 TTPs 1 CVEA high-severity authentication bypass vulnerability (CVE-2026-58423) in Gitea's SSH Git LFS handling allows any authenticated SSH user to obtain valid LFS credentials for any private repository, enabling unauthorized download of all LFS objects from instances running Gitea versions 1.23.0 through 1.26.2.
Gitea Incomplete SSRF Protection in Webhook and Migration Allow-list
4 TTPs 1 CVE 1 IOCAn incomplete Server-Side Request Forgery (SSRF) protection in Gitea versions prior to 1.26.3 allows authenticated users to bypass the allow-list in webhook delivery and repository migrations, enabling internal network probing and data exfiltration from sensitive services like cloud metadata endpoints.
Gitea Branch Protection Bypass via Pull Request Retargeting
1 rule 7 TTPsAn attacker with write access to a Gitea repository can bypass branch protection rules by exploiting a logic flaw, obtaining an 'official' approval on a pull request (PR) targeting an unprotected branch, then retargeting the PR to a protected branch, preserving the stale approval and leading to unauthorized code merges and privilege escalation.
@vitest/browser File Access Bypass Vulnerability (GHSA-p63j-vcc4-9vmv)
5 TTPsA critical vulnerability in `@vitest/browser`'s Browser Mode allows arbitrary file system access due to a bypass of the `allowWrite` permission gate and lack of path confinement, enabling an attacker to read, create, overwrite, or delete files on the local filesystem where the Vitest process is running.
Sigstore/OCI Credential Confusion Vulnerability (CVE-2026-59891)
1 TTP 1 CVE 1 IOCA critical credential exposure vulnerability (CVE-2026-59891) exists in `@sigstore/oci` versions prior to 0.7.1. The `getRegistryCredentials()` function, used to read credentials from `~/.docker/config.json`, employs a substring match instead of an exact host match when selecting credentials. This flaw allows credentials for a legitimate registry (e.g., `ghcr.io`) to be inadvertently transmitted to an attacker-controlled registry if its hostname is a substring of the legitimate one (e.g., `cr.io`). This impacts consumers of `@sigstore/oci` and related GitHub Actions (`actions/attest`, `actions/attest-build-provenance`, `actions/attest-sbom`) when pushing artifacts to untrusted or attacker-influenced destination registries, potentially leading to the leakage of long-lived registry tokens. The vulnerability is fixed in `@sigstore/oci@0.7.1` by enforcing exact host matching.
Unauthenticated SQL Injection Vulnerability in Linknat VOS3000 and VOS2009
1 rule 3 TTPs 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2016-20096) exists in Linknat VOS3000 and VOS2009 through version 2.1.2.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'name' parameter in a POST request to the login endpoint, which leads to the extraction of plaintext credentials and other database content with DBA-level privileges.
Gitea Repository Migration SSRF and Internal Git Repository Exfiltration
2 rules 9 TTPs 1 CVEA critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.
pyasn1 Uncontrolled Resource Consumption (CVE-2026-59886)
1 TTP 1 CVEThe pyasn1 library is vulnerable to uncontrolled resource consumption (excessive CPU and memory) when converting BER/CER/DER-encoded REAL values to Python floats, which can lead to a denial of service (DoS) in applications that decode untrusted ASN.1 data and then perform operations like printing, logging, comparing, or arithmetic on the decoded `univ.Real` objects.
CVE-2026-59892: OpenTelemetry JaegerPropagator Denial of Service
1 TTP 1 CVEA critical denial of service vulnerability, CVE-2026-59892, exists in `@opentelemetry/propagator-jaeger` versions prior to 2.9.0, allowing an unauthenticated remote attacker to terminate Node.js applications configured with `JaegerPropagator` by sending a malformed percent-encoded value in `uber-trace-id` or `uberctx-*` HTTP headers, leading to an uncaught `URIError`.
OS Command Injection in AWS CDK NodejsFunction Docker Bundling (CVE-2026-13760)
1 TTP 1 CVEAn OS command injection vulnerability, CVE-2026-13760, in AWS CDK's `aws-cdk-lib` package before version 2.260.0 allows an attacker to execute arbitrary commands on the host running the CDK toolchain by injecting shell metacharacters into dependency version strings within a project's `package.json` file when using Docker-based NodejsFunction bundling.
Linkify-it Denial of Service via Mailto Validator Quadratic Complexity
1 TTP 1 CVEThe JavaScript library linkify-it is vulnerable to a quadratic-complexity Denial of Service (DoS) (CVE-2026-59887) due to an inefficient regular expression in its `mailto:` schema validator, which allows an unauthenticated attacker to block application event loops by supplying specially crafted input with repeated 'mailto:' strings.
Immutable.js Map/Set Hash Collision Denial of Service Vulnerability
2 TTPs 1 CVEA high-severity algorithmic complexity vulnerability (CVE-2026-59880) in the Immutable.js library's `Immutable.Map` and `Immutable.Set` allows an attacker to craft object keys that cause hash collisions, degrading performance from O(1) to O(N²) and leading to a CPU-bound denial of service in applications, particularly those running on single-threaded Node.js environments that ingest untrusted input as object keys.
Immutable.js List 32-bit Trie Overflow Leads to Denial of Service
1 TTP 1 CVE 2 IOCsA vulnerability in Immutable.js List methods (`#set`, `#setSize`, `#setIn`, `#updateIn`) allows a remote, unauthenticated attacker to trigger an infinite loop or heap exhaustion by providing a crafted numeric string index in the range `[2 ** 30, 2 ** 31)`. This leads to an unrecoverable Denial of Service (DoS) by causing a tight CPU spin or process abortion, with an additional silent data corruption issue in `setSize`. This vulnerability impacts application availability but not confidentiality or integrity, and can be triggered by a single small HTTP request.
Denial of Service in websocket-driver-ruby via Malformed Host Header (CVE-2026-61666)
1 rule 1 TTPA denial of service vulnerability (CVE-2026-61666) exists in the websocket-driver-ruby library when used to implement a WebSocket server via `WebSocket::Driver.server()`, allowing a remote attacker to send a malformed `Host` header causing a `URI::InvalidURIError` exception and subsequent server process crash if unhandled.
Home Assistant Core Path Traversal Vulnerability (CVE-2026-64825)
2 TTPs 2 CVEsA critical path traversal vulnerability, CVE-2026-64825, in Home Assistant Core versions before 2026.6.0 allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window, potentially leading to full system compromise with root privileges.
SolarWinds Serv-U Privilege Escalation Vulnerability (CVE-2026-28310)
1 TTP 1 CVE 2 IOCsCVE-2026-28310 describes a critical privilege escalation vulnerability (CVSS 9.1) affecting SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing a domain administrator to elevate their user type to that of a system administrator, with lower impact noted in Windows deployments.
Remote Code Execution Vulnerability in SolarWinds Serv-U (CVE-2026-28304)
5 TTPs 8 CVEs 3 IOCsA critical remote code execution vulnerability (CVE-2026-28304) has been identified in SolarWinds Serv-U versions 15.5.4 HF1 and below, allowing an attacker with high privileges to execute arbitrary code remotely as root, posing a severe risk to affected systems, though with lower impact on Windows deployments.
SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Vulnerability Allows Privilege Escalation and RCE
3 TTPs 4 CVEsA critical insecure direct object reference (IDOR) vulnerability, CVE-2026-28302, in SolarWinds Serv-U allows authenticated group administrators to achieve privilege escalation and remote code execution as root.
CVE-2026-59851: Libssh GSSAPIKeyExchange Authorization Bypass
1 TTP 5 CVEs 22 IOCsA vulnerability in libssh, tracked as CVE-2026-59851, allows an authenticated Kerberos principal to bypass authorization checks on servers with GSSAPIKeyExchange enabled, enabling arbitrary local user login and potential privilege escalation.
Critical SQL Injection Vulnerability in Turkhotspot 5651 Loglama (CVE-2026-1617)
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-1617) exists in Turkmesh Communication Services Inc. Turkhotspot 5651 Loglama software, affecting versions from 5.1.2 before 5.1.3. This flaw, rated with a CVSS v3.1 Base Score of 9.8, allows attackers to execute arbitrary SQL commands due to improper neutralization of special elements in an SQL query.
Multiple Vulnerabilities in Synacor Zimbra
5 TTPsAn attacker can exploit multiple vulnerabilities in Synacor Zimbra to execute arbitrary code, perform cross-site scripting attacks, bypass security measures, disclose confidential information, and carry out unauthorized actions.
OPNsense: Multiple Vulnerabilities
4 TTPsAn attacker can exploit multiple vulnerabilities in OPNsense to bypass security controls, disclose information, perform Cross-Site Scripting (XSS) attacks, and execute Denial of Service (DoS) attacks.
ProFTPD: Multiple Vulnerabilities Leading to RCE and Information Disclosure
3 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in ProFTPD to achieve arbitrary code execution and disclose confidential information, leading to system compromise and data theft.
CUPS (libcupsfilters, cups-filters) Denial of Service Vulnerability
1 TTPA vulnerability in CUPS, specifically affecting libcupsfilters and cups-filters, allows a remote, unauthenticated attacker to exploit the system, leading to a denial-of-service condition that disrupts the availability of the printing system.
rsyslog Vulnerability Allows Denial of Service and Potential Code Execution
2 TTPsA remote, unauthenticated attacker can exploit a vulnerability in rsyslog to perform a Denial of Service attack and potentially execute arbitrary code.
Red Hat Enterprise Linux Vulnerabilities Allow Privilege Escalation and DoS
4 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux, affecting components such as sssd, glib, and c-ares, can be exploited by an attacker to gain administrator privileges, bypass security measures, manipulate data, and trigger a denial-of-service condition.
BusyBox AWK Vulnerability Leads to Denial of Service
1 TTP 1 CVEA stack overflow vulnerability, identified as CVE-2026-38752, exists in the evaluate() function within the AWK editor (editors/awk.c) of BusyBox commit 371fe9, which allows attackers to trigger a Denial of Service (DoS) condition by providing a specially crafted AWK script.
ethtool RSS Resource Leak on get_rxfh Failure
1 CVEA vulnerability, CVE-2026-63999, has been identified in the `ethtool` utility on Linux systems, involving a resource leak of `indir_table` and `hkey` when the `get_rxfh` function related to Receive Side Scaling (RSS) functionality fails, which could lead to system instability or resource exhaustion.
Linux Kernel USB Type-C Wcove Driver Buffer Overflow Vulnerability
1 CVEA buffer overflow vulnerability, identified as CVE-2026-63960, exists in the `wcove_read_rx_buffer()` function within the USB Type-C `wcove` driver in the Linux kernel, potentially leading to memory corruption or system instability upon exploitation.
CVE-2026-64117 Vulnerability in Linux Kernel mac80211 Wi-Fi Subsystem
1 CVEA vulnerability, CVE-2026-64117, has been disclosed in the Linux kernel's mac80211 Wi-Fi subsystem, potentially leading to unexpected behavior or information exposure due to incorrect handling of fast-RX rates and `skb->cb` buffer reuse in mesh networking contexts.
CVE-2026-64097: AMD Display Module Vulnerability in Linux Kernel
1 CVEA vulnerability, CVE-2026-64097, affects the `drm/amd/display` module in the Linux kernel due to insufficient validation of GPIO pin LUT table size, potentially leading to system instability or other security impacts on Linux systems utilizing AMD display drivers.
Qemu-kvm HyperV Syndbg Out-of-Bounds Write Vulnerability
1 CVEA critical vulnerability, CVE-2026-3842, exists in the `hyperv/syndbg` component of Qemu-kvm, allowing an attacker to perform out-of-bounds writes on the host system due to a missing mapped-length guard after a `cpu_physical_memory_map` operation.
CVE-2026-38754: Busybox Heap Overflow Leads to Denial of Service
1 TTP 3 CVEsA heap overflow vulnerability (CVE-2026-38754) exists in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0. This flaw allows attackers to trigger a Denial of Service (DoS) by providing a specially crafted input, leading to application instability or unavailability.
Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday
8 TTPs 4 CVEs 8 IOCsMicrosoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.
Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)
1 TTP 1 CVEA post-authentication command injection vulnerability (CVE-2026-6952) in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.
CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability
4 rules 4 TTPs 2 IOCsA high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.
Pillow Decompression Bomb DoS via PdfParser.PdfStream.decode()
1 TTP 2 CVEs 2 IOCsA denial-of-service vulnerability (CVE-2026-59200) exists in Pillow's `PdfParser.PdfStream.decode()` function across versions 5.1.0 to 12.2.x, allowing an unauthenticated attacker to craft a malicious PDF file that, when processed by a vulnerable application, triggers excessive memory allocation (e.g., a ~950 KB file expanding to 1 GB), leading to server Out-of-Memory termination or severe service degradation.
FileBrowser Username Normalization Collision Leads to Authorization Bypass
4 TTPs 1 CVEA critical authorization bypass vulnerability, CVE-2026-62685, in FileBrowser versions <= 2.63.16 enables an attacker to gain full read and write access to other users' files by exploiting a username normalization collision during self-registration, thus bypassing per-user isolation and allowing data tampering or exfiltration.
Engine.IO Polling Transport Connection Exhaustion Vulnerability (CVE-2026-59725)
1 rule 1 TTP 1 CVEAn unauthenticated remote attacker can cause a denial of service in `engine.io` by sending invalid binary POST requests with `Content-Type: application/octet-stream` to Engine.IO protocol v4 polling transports, leading to exhaustion of server-side resources such as HTTP connections, sockets, and file descriptors due to improper connection closure.
File Browser Symlink Following Vulnerability Allows Out-of-Scope File Deletion (CVE-2026-55667)
2 TTPs 2 CVEsA File Browser user with only `Create` permission can exploit CVE-2026-55667, an incomplete fix for CVE-2026-54094, to delete arbitrary files and directories outside their authorized scope by abusing the `ScopedFs.RemoveAll` function's symlink-following behavior during failed upload cleanup, leading to data loss, cross-tenant data deletion, or denial of service.
Cloudreve OAuth Access Token Scope Bypass Vulnerability
1 TTP 1 CVECloudreve's OAuth implementation contains a vulnerability, CVE-2026-54560, where OAuth access tokens bypass intended scope enforcement due to a missing `client_id` claim, allowing an attacker with a low-scope token to access sensitive APIs requiring higher privileges, effectively leading to privilege escalation.
Pillow FontFile.compile() Vulnerability Bypasses Decompression Checks Leading to DoS (CVE-2026-54060)
1 TTP 1 CVEA vulnerability, CVE-2026-54060, in the Pillow library's `FontFile.compile()` method allows attackers to craft malicious BDF or PCF font files that bypass standard decompression bomb checks, causing an unchecked, massive memory allocation when processed, which can lead to a Denial of Service (DoS) via an Out-Of-Memory (OOM) crash in vulnerable applications.
Pillow BdfFontFile Decompression Bomb Bypass Vulnerability
4 TTPs 1 CVEA vulnerability (CVE-2026-55379) in Pillow's BdfFontFile component allows attackers to craft a malicious BDF font file with oversized BBX dimensions and an empty BITMAP section, bypassing documented decompression bomb protection and causing the Image.new() function to silently allocate large amounts of memory in the C-heap, leading to resource exhaustion and denial-of-service for applications processing untrusted BDF fonts.
@better-auth/sso Authorization Bypass Allows Unauthorized SSO Provider Registration
2 TTPs 1 CVEA high-severity authorization bypass vulnerability (CVE-2026-53515) in `@better-auth/sso` versions `>= 1.2.10, < 1.6.11` allows regular organization members to register new SSO providers for an organization, potentially leading to unauthorized user creation and, under specific configurations, unauthorized administrative access within the target organization.
Pillow Out-of-Bounds Read Vulnerability in McIdas AREA Plugin (CVE-2026-54058)
2 TTPs 1 CVEThe Pillow library contains an out-of-bounds read vulnerability in its McIdas AREA plugin when processing specially crafted image files opened from a filename, allowing an attacker to manipulate header words to define a 'stride' value smaller than the actual row width, leading to information disclosure through adjacent process memory leakage or denial of service due to a process crash (SIGBUS).
Critical Unauthenticated RCE in ktransformers (CVE-2026-63767)
2 rules 2 TTPs 1 CVEA critical unauthenticated pickle deserialization vulnerability (CVE-2026-63767) in ktransformers versions up to 0.6.3 allows remote attackers to execute arbitrary commands by sending specially crafted pickle payloads containing malicious `__reduce__` methods to the SchedulerServer ZMQ ROUTER socket, leading to complete server compromise.
CVE-2026-64619: FileCodeBox Rate Limit Bypass Vulnerability
2 TTPs 1 CVE 4 IOCsUnauthenticated attackers can bypass rate limits in FileCodeBox versions before 2.4 due to a vulnerability in the IPRateLimit class, allowing them to enumerate share codes and retrieve other users' files without authentication by spoofing X-Real-IP and X-Forwarded-For headers without proper verification.
CVE-2026-63770: Glance IP Address Spoofing Vulnerability Bypasses Brute-Force Lockout
1 rule 2 TTPs 1 CVEA vulnerability in Glance through version 0.8.5 allows unauthenticated attackers to bypass brute-force lockout protections by manipulating the X-Forwarded-For HTTP header with arbitrary values, making each login attempt appear to originate from a distinct IP address when the server's proxied option is enabled, thereby enabling unlimited credential guessing against the authentication endpoint.
Server-Side Request Forgery in HyperDX via ClickHouse Proxy Test Endpoint
1 rule 2 TTPs 1 CVEAn authenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-63731, in HyperDX before version 2.31.0 by manipulating the `host` parameter of the ClickHouse proxy test endpoint, leading to disclosure of internal service response bodies and potential access to internal APIs, container services, and cloud provider metadata.
LimeSurvey Server-Side Request Forgery Vulnerability (CVE-2026-63107)
1 rule 1 TTP 1 CVEAn authenticated attacker can exploit CVE-2026-63107, a server-side request forgery vulnerability in LimeSurvey versions through 6.17.10 and 7.0.4, by manipulating the HTTP Host header in the REST API survey template endpoint, allowing the server to issue arbitrary HTTP requests to internal networks and cloud metadata services, potentially leading to the extraction of sensitive credentials like IAM tokens.
Composer: Arbitrary File Write via Malicious Transitive Package Name
3 TTPs 1 CVEA critical vulnerability, CVE-2026-59948, in Composer allows for arbitrary file write outside the project's vendor directory when processing a maliciously crafted package from an untrusted third-party repository during `install` or `update` operations, enabling code execution.
CVE-2026-64612 - libcupsfilters and cups-filters Denial of Service
1 TTP 1 CVEA high-severity denial-of-service vulnerability (CVE-2026-64612) exists in libcupsfilters and cups-filters, allowing an unauthenticated attacker to cause the CUPS image filter process to abort by submitting a specially crafted PNG print job, leading to service disruption.
Public Exploit for Apache Camel CVE-2026-49098 Improper Input Validation
1 TTP 1 CVEA public exploit has been released for CVE-2026-49098, an improper input validation vulnerability in Apache Camel's 'camel-kafka' component, which allows an attacker to perform message-header injection by supplying 'kafka.OVERRIDE_TOPIC' in HTTP headers, enabling cross-topic message injection and integrity compromise of sensitive Kafka topics.
ProFTPD mod_sftp Heap Buffer Overflow Leads to Arbitrary Code Execution
1 TTP 1 CVEA heap-based buffer overflow vulnerability exists in the mod_sftp module of ProFTPD versions prior to 1.3.9c and 1.3.10rc3, allowing authenticated low-privilege attackers to achieve arbitrary code execution by sending specially crafted SFTP packet fragments exceeding 16 KB, corrupting memory and redirecting function calls.
Path Traversal Vulnerability in Pulpcore (CVE-2026-12701)
3 TTPs 1 CVEAn authenticated administrator can exploit a path traversal vulnerability in the 'relative_path_validator' function within 'pulpcore'. During 'FilesystemExport' operations, specially crafted 'relative_path' values containing directory traversal sequences (e.g., "../") can bypass validation, leading to arbitrary file writes. This allows an attacker to write files to any location writable by the Pulp service user, such as '/etc/shadow', potentially leading to service compromise, privilege escalation, or further system exploitation.
QEMU Guest Agent Vulnerability Allows Local Privilege Escalation (CVE-2026-12080)
2 TTPs 1 CVEA local unprivileged user within a QEMU guest can exploit CVE-2026-12080, a vulnerability in the QEMU Guest Agent's 'guest-ssh-add-authorized-keys' command handler, by manipulating symbolic links through a directory-symlink bypass or a Time-of-Check to Time-of-Use (TOCTOU) file-symlink race to gain ownership of arbitrary root-owned files or directories, leading to root access within the guest OS.
Potential CVE-2025-41244 vmtoolsd Local Privilege Escalation Attempt
1 rule 3 TTPs 1 CVEAttackers can exploit CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools' `vmtoolsd` service and its `get-versions.sh` script on Linux, by manipulating the `PATH` environment variable to execute malicious binaries with elevated privileges when the service attempts to retrieve version information, potentially leading to a root shell.
Sudo Chroot Privilege Escalation via NSSwitch File Manipulation (CVE-2025-32463)
1 rule 2 TTPs 1 CVEAttackers can exploit CVE-2025-32463, a privilege escalation vulnerability in `sudo` when used with `chroot`, by creating a malicious `nsswitch.conf` file and associated Name Service Switch (NSS) modules within a controlled chroot environment to trick `sudo` into loading attacker-controlled code, leading to root privileges on Linux systems.
CVE-2026-64623: Jovancoding Network-AI Signature Verification Bypass Leading to Remote Code Execution
4 TTPs 1 CVEJovancoding Network-AI versions before 5.13.4 are vulnerable to an improper cryptographic signature verification flaw (CVE-2026-64623) in the APSAdapter component, allowing unauthenticated attackers to bypass signature validation by submitting forged APS delegation payloads with arbitrary scopes to obtain signed permission tokens for sensitive resources, including SHELL_EXEC capabilities.
Authorization Bypass in Network-AI npm Package CVE-2026-64622
1 rule 2 TTPs 1 CVENetwork-AI (npm: network-ai) versions 5.12.2 through 5.13.3 are vulnerable to an authorization bypass (CVE-2026-64622) that allows unauthenticated actors to access sensitive approval request details via specific GET read routes like /approvals/. This vulnerability discloses critical information such as shell-command strings, file paths, justifications, and risk levels. Additionally, a hardcoded 'Access-Control-Allow-Origin: *' header in responses facilitates cross-origin data disclosure, enabling potential exfiltration from malicious websites an operator might visit.
FreeRDP Double-Free Vulnerability (CVE-2026-64621)
2 TTPs 1 CVEA double-free vulnerability exists in FreeRDP versions 3.x through 3.27.1 within the freerdp_client_rdp_file_apply_to_settings() function, specifically when parsing the selectedmonitors field of a .rdp connection file. An attacker can exploit this by convincing a victim to open a crafted .rdp file containing oversized monitor tokens, leading to a size-controlled double-free in FreeRDP CLI clients like xfreerdp, sdl-freerdp, or wlfreerdp. This vulnerability can result in denial of service or potentially lead to arbitrary code execution.
CVE-2026-63757: SurrealDB Session Hijacking Vulnerability
5 TTPs 1 CVESurrealDB versions prior to 3.1.0 are vulnerable to a session hijacking flaw (CVE-2026-63757) where unauthenticated attackers can enumerate session UUIDs via the HTTP /rpc sessions method and impersonate authenticated sessions to read, write, and delete data, leading to privilege escalation.
SurrealDB RPC Endpoint Race Condition Allows Privilege Escalation (CVE-2026-63756)
2 TTPs 1 CVESurrealDB versions before 3.1.0 contain a time-of-check/time-of-use (TOCTOU) race condition in the HTTP /rpc endpoint that allows unauthenticated attackers to hijack authenticated session state and execute operations with elevated user privileges, leading to privilege escalation.
SurrealDB Denial of Service Vulnerability (CVE-2026-63747)
1 TTP 1 CVESurrealDB versions prior to 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when the 'db' parameter is set without a corresponding namespace, allowing unauthenticated attackers to crash the server by sending a malformed WebSocket message to the /rpc endpoint.
SurrealDB Arbitrary File Read Vulnerability CVE-2026-63739
3 TTPs 1 CVESurrealDB versions prior to 3.1.5 contain an arbitrary file read vulnerability (CVE-2026-63739) within the DEFINE ANALYZER mapper filter that allows authenticated database users with EDITOR or OWNER roles to read arbitrary files from the server filesystem by injecting file paths into query error messages, especially when the SURREAL_FILE_ALLOWLIST is unconfigured.
CVE-2026-63735: SurrealDB Scope Validation Bypass in Custom API Routes
2 TTPs 1 CVE 2 IOCsA vulnerability, CVE-2026-63735, in SurrealDB versions prior to 3.2.0 allows authenticated users to bypass namespace and database scope validation in custom API routes by manipulating the URL path, potentially leading to unauthorized data reading or triggering unintended operations across different tenants.
CVE-2026-14448: Authenticated OS Command Injection in MB connect line and Helmholz Products
1 rule 2 TTPs 1 CVECVE-2026-14448 describes an authenticated OS command injection vulnerability in the system_certificates view of MB connect line's mbCONNECT24 and mymbCONNECT24 products, as well as Helmholz's myREX24V2 and myREX24V2.virtual products, all versions up to and including 2.20.0, allowing a high-privileged remote attacker to execute arbitrary commands leading to a total loss of confidentiality, availability, and integrity.
CVE-2026-64620 - FreeRDP Heap-based Buffer Overflow
2 TTPs 1 CVEFreeRDP before version 3.28.0 contains a heap-based buffer overflow in the `crypto_rsa_common()` function, exploitable pre-authentication by an unauthenticated attacker crafting a malicious ciphertext to cause a denial of service on the server when a client uses RDP Standard Security.
PHP File Creation in WordPress Plugin Directory
1 rule 3 TTPs 1 CVE 1 IOCAttackers commonly establish persistence on compromised Linux WordPress web servers by creating malicious PHP files, often web shells, within the WordPress plugin directory, enabling remote access and command execution following initial compromise of a public-facing application.
Multiple Vulnerabilities in Proxmox Virtual Environment
1 TTPAn attacker can exploit multiple vulnerabilities in Proxmox Virtual Environment to conduct Cross-Site Scripting attacks, bypass security measures, and disclose confidential information, potentially leading to unauthorized data access or session hijacking.
IBM DB2: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in IBM DB2 allow an attacker to perform a Denial of Service (DoS) attack and execute arbitrary code, which could lead to system disruption or full compromise.
Multiple Vulnerabilities in Extreme Networks ExtremeXOS Allow Privilege Escalation and Data Manipulation
3 TTPsMultiple vulnerabilities in Extreme Networks ExtremeXOS can be exploited by a remote, authenticated attacker to achieve privilege escalation, bypass security controls, and manipulate data on affected network devices.
FreeRDP: Vulnerability Enables Remote Code Execution
2 TTPsA high-severity vulnerability in the FreeRDP software allows a remote, unauthenticated attacker to execute arbitrary code on systems running FreeRDP, enabling system compromise without prior authentication.
Multiple Vulnerabilities in IBM Langflow Desktop OSS
6 TTPsAn attacker can exploit multiple vulnerabilities in IBM Langflow Desktop OSS to gain administrator privileges, execute arbitrary code, bypass security measures, manipulate and disclose data, or cause a denial-of-service condition, leading to full system compromise and data integrity/confidentiality breaches.
ProFTPD: Vulnerability Enables Denial of Service
1 TTPAn authenticated remote attacker can exploit a vulnerability within ProFTPD to initiate a denial-of-service attack, leading to the unavailability of the FTP service. This flaw could be triggered by legitimate users or adversaries with valid credentials, causing operational disruption.
CVE-2026-16242: Konnectivity Proxy-Server Authentication Bypass
4 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-16242, exists in the Konnectivity proxy-server configuration for hosted control planes, allowing a remote unauthenticated attacker to connect as an agent and potentially proxy, inspect, modify, or drop control-plane-to-node traffic due to improper client certificate validation.
Linux Kernel fbdev Use-After-Free Vulnerability (CVE-2026-53401)
1 CVEA high-severity use-after-free vulnerability, CVE-2026-53401, has been identified in the Linux kernel's fbdev subsystem affecting omap2 processors, potentially allowing for privilege escalation or denial of service.
CVE-2026-63825: gcov Utility Concurrent Access Crash Vulnerability
1 CVEA vulnerability, CVE-2026-63825, has been disclosed for the 'gcov' utility, which is part of the GNU Compiler Collection, involving concurrent access crashes fixed by using atomic counter updates to ensure thread-safe operations, potentially leading to system instability or denial of service due to race conditions during data access.
Potential Out-of-Bounds Write in rust-openssl AES-KW-PAD Cipher Operations
1 CVEA potential out-of-bounds write vulnerability, CVE-2026-45784, has been identified in the `rust-openssl` library's `CipherCtxRef::cipher_update_inplace` function when processing AES-KW-PAD ciphers, which could lead to unexpected behavior or potential exploitation by corrupting memory.
Linux Kernel ip_gre Module Vulnerability CVE-2026-63829
1 CVEA vulnerability identified as CVE-2026-63829 affects the `ip_gre` module in the Linux kernel, involving a security fix to ensure that the `changelink` operation properly requires `CAP_NET_ADMIN` capabilities within the device's network namespace, addressing a potential privilege escalation or security bypass scenario.
CVE-2026-63833: Linux Kernel ntfs3 Privilege Escalation Vulnerability
1 CVEThe Microsoft Security Response Center has published information concerning CVE-2026-63833, a privilege escalation vulnerability in the Linux kernel's `ntfs3` module that allows direct userspace writes to reserved `$LX*` extended attributes.
CVE-2026-16227: SourceCodester Class and Exam Timetabling System SQL Injection
1 rule 1 TTP 2 CVEsA high-severity SQL injection vulnerability (CVE-2026-16227) in SourceCodester Class and Exam Timetabling System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/edit_subject.php' file, with the exploit publicly disclosed.
Unauthenticated Access in Newpanjing simpleui via AjaxAdmin Endpoint (CVE-2026-16210)
1 TTP 2 CVEs 6 IOCsA high-severity authentication bypass vulnerability, CVE-2026-16210, exists in newpanjing simpleui version 2026.01.13, specifically within the `self.get_action` function of the `AjaxAdmin AJAX Endpoint` component, allowing remote attackers to perform unauthorized manipulations due to missing authentication, with a public exploit available.
CVE-2026-16200: Remote Authorization Bypass in zevorn rt-claw
1 TTP 1 CVEA high-severity remote authorization bypass vulnerability (CVE-2026-16200) has been identified in zevorn rt-claw versions up to 0.2.0, specifically within the RPC Handler's claw_tool_invoke function, allowing remote exploitation with a public exploit.
ProFTPD mod_sftp Heap Overflow Allows Authenticated Denial of Service (CVE-2026-53994)
1 TTP 1 CVEAn authenticated SFTP user can trigger a heap-based buffer overflow in ProFTPD's mod_sftp module (CVE-2026-53994) by sending a malformed SFTP packet, leading to an integer underflow, an undersized buffer allocation, and subsequent heap corruption, which results in a reliable remote denial of service.
Server-Side Request Forgery in zevorn rt-claw (CVE-2026-16128)
3 TTPs 1 CVE 5 IOCsA server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16128, exists in zevorn rt-claw versions up to and including 0.2.0. The flaw is located within the `receiver_thread` function of the `http_request` component in `claw/services/swarm/swarm.c`. This critical vulnerability allows remote attackers to perform server-side request forgery, and a public exploit is available, increasing the urgency for detection and mitigation efforts.
CVE-2026-16125: Server-Side Request Forgery in zevorn rt-claw
1 rule 3 TTPs 2 CVEs 10 IOCsA critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16125, affects zevorn rt-claw versions up to and including 0.2.0, residing in the claw_net_get/claw_net_post functions within the http_request component, allowing remote attackers to manipulate the URL argument and access internal resources or perform port scanning.
SurrealDB Default Permissions Vulnerability
3 TTPs 1 CVESurrealDB versions prior to 1.0.1 are vulnerable due to default table permissions being set to FULL instead of NONE, allowing attackers with existing database access or unauthenticated users on publicly exposed instances to perform unrestricted SELECT, CREATE, UPDATE, and DELETE operations on tables that lack explicit permission settings, leading to unauthorized data access, modification, or deletion.
Arbitrary Code Execution in uproot via Crafted ROOT Files (CVE-2026-9147)
1 TTP 1 CVEA vulnerability, CVE-2026-9147, in the uproot library allows arbitrary Python code execution when processing crafted ROOT files due to improper handling of streamer metadata fields during dynamic code generation, impacting applications that open or process untrusted ROOT files.
Shibby Tomato Router Firmware Out-of-Bounds Write Vulnerability (CVE-2026-16095)
3 TTPs 2 CVEsA remote out-of-bounds write vulnerability, CVE-2026-16095, affects Shibby Tomato firmware version 1.28 RT-N5x MIPSR2 Build 124, where manipulating the `ct_tcp_timeout` argument in the `setup_conntrack` function of `/sbin/rc` can lead to memory corruption, potentially allowing arbitrary code execution or denial of service.
Remote Server-Side Request Forgery in Sipeed PicoClaw (CVE-2026-16084)
1 rule 3 TTPs 1 CVE 9 IOCsA server-side request forgery (SSRF) vulnerability, CVE-2026-16084, has been identified in Sipeed PicoClaw versions up to 0.2.9, allowing remote exploitation due to a weakness in the `web_fetch` function of `pkg/tools/integration/web.go`, with a public exploit available.
CoreDNS Rewrite Plugin Vulnerability Allows Remote Denial of Service
1 TTP 1 CVEA remote denial-of-service vulnerability (CVE-2026-62299) has been discovered in the CoreDNS rewrite-plugin that can lead to a nil-pointer panic when a downstream plugin returns an EDNS0 response without an OPT record, potentially causing service disruption.
CVE-2026-48373: Adobe Acrobat Reader Heap-based Buffer Overflow
2 TTPs 1 CVEA heap-based buffer overflow vulnerability, CVE-2026-48373, in Adobe Acrobat Reader could allow an attacker to achieve arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file.
CVE-2026-16118: Heap-Based Buffer Overflow in xdgmime
2 TTPs 1 CVEA heap-based buffer overflow vulnerability exists in the `xdgmime` library, specifically within the `_xdg_mime_magic_parse_magic_line()` function, which can be triggered on little-endian systems when an application parses an attacker-controlled MIME magic file in a user-writable XDG data location, leading to an application crash or memory corruption.
IBM Engineering AI Hub Information Disclosure via URL Session Tokens (CVE-2026-15322)
1 TTP 1 CVEA remote attacker can exploit CVE-2026-15322 in IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0 to obtain sensitive session tokens exposed in URLs, potentially leading to unauthorized access and information disclosure.
IBM Langflow OSS Command Injection Vulnerability
1 rule 2 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-14499 in IBM Langflow OSS versions 1.0.0 through 1.10.1 due to improper validation of user input in the Python Interpreter component, leading to arbitrary command execution with elevated privileges.
IBM Storage Protect Client Heap Buffer Overflow Allows Remote Code Execution
2 TTPs 1 CVEIBM Storage Protect Client versions 8.1.0.0 through 8.1.27.1 and 8.2.0.0 through 8.2.1.0 are vulnerable to CVE-2026-13473, a heap-based buffer overflow caused by improper bounds checking, allowing a remote attacker to execute arbitrary code or crash the server.
IBM Langflow OSS Remote Code Execution via Deserialization
1 rule 5 TTPs 7 CVEs 1 IOCIBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.
Arbitrary Code Execution via JavaScript Frontmatter in Prompty TypeScript Loader
1 TTP 1 CVEA high-severity vulnerability, CVE-2026-53597, in the Prompty TypeScript loader (`@prompty/core`) versions `>= 2.0.0-alpha.1 < 2.0.0-beta.3` allows arbitrary JavaScript code execution in the host Node.js process when parsing untrusted `.prompty` files due to improper handling of `gray-matter`'s executable frontmatter engines.
IBM PowerVM Novalink Vulnerable to Denial of Service via Specially-Crafted Request
1 TTP 1 CVE 1 IOCIBM PowerVM Novalink is vulnerable to CVE-2026-9171, a denial-of-service attack where a remote unauthenticated attacker can send a specially-crafted request to cause the server to consume excessive memory resources, leading to system unavailability.
IBM Langflow OSS Code Injection Vulnerability in ToolGuard (CVE-2026-9135)
3 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-9135, a code injection vulnerability in IBM Langflow OSS versions 1.0.0 through 1.9.2, to bypass security controls and achieve arbitrary Python code execution on the backend through unvalidated dynamic CodeInput fields in the ToolGuard integration, potentially escalating privileges via cross-tenant flow manipulation.
IBM Langflow OSS Improper Authentication Vulnerability
2 rules 5 TTPs 3 CVEsA remote attacker can gain full administrative access to IBM Langflow OSS versions 1.0.0 through 1.10.0 by exploiting an improper authentication vulnerability. The /api/v1/login/auto_login endpoint, when the default AUTO_LOGIN configuration is enabled, issues long-lived superuser bearer tokens without requiring authentication. This allows an unauthenticated network attacker to obtain these tokens and achieve superuser privileges. Additionally, permissive Cross-Origin Resource Sharing (CORS) settings could expose these tokens to unintended origins, exacerbating the risk.
Unauthenticated Server-Side Request Forgery in meta-ads-mcp via image_url
3 TTPs 2 IOCsAn unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in `meta-ads-mcp` v1.0.113, specifically within the `upload_ad_image` function, by providing a malicious `image_url` parameter that causes the server to make arbitrary outbound HTTP requests to internal services, RFC 1918 addresses, or cloud metadata endpoints, leading to information disclosure and potential internal network compromise.
Incomplete Privilege Drop in 'sh' Package Allows Privilege Escalation
1 TTPA vulnerability in the 'sh' package, affecting Linux/Unix-like systems, allows for an incomplete privilege drop when the `_uid` option is used. When a process with elevated privileges launches a child process with `_uid=<unprivileged user>`, the child process changes its UID and primary GID but fails to reset its supplementary groups. This flaw enables the child process to retain potentially privileged supplementary groups (e.g., root, docker), bypassing intended privilege boundaries and granting access to resources beyond its expected permissions.
Privilege Escalation in AWS Advanced JDBC Wrapper for Aurora PostgreSQL
1 CVEA privilege escalation vulnerability (CVE-2026-11400) exists in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL, affecting versions 3.0.0 through 4.0.0. A low-privileged authenticated user can craft a function to execute with rds_superuser permissions.
IBM Db2 Remote Code Execution via JDBC URL Vulnerability (CVE-2026-9762)
2 TTPs 1 CVEA critical remote code execution vulnerability, identified as CVE-2026-9762, exists in IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4, allowing attackers to execute arbitrary code if a JDBC URL is under user control, categorized as an improper control of code generation.
Authentication Bypass Vulnerability in Vimesoft Enterprise Video Platform (CVE-2026-12691)
1 TTP 1 CVECVE-2026-12691 describes a critical authentication bypass vulnerability in Vimesoft Inc.'s Enterprise Video Platform versions from 3.11.0.0 before 3.25.0, allowing unauthenticated attackers to bypass security mechanisms for critical functions and potentially gain unauthorized access to sensitive information, with a CVSS v3.1 base score of 7.5.
CVE-2026-8297: Critical SQL Injection in GisLab Laboratory Management System
1 rule 1 TTP 1 CVECVE-2026-8297 is a critical SQL injection vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.'s GisLab Laboratory Management System, affecting versions 1.4.03 through 08072026, which allows unauthenticated remote attackers to execute arbitrary SQL commands and achieve high impact on confidentiality, integrity, and availability of sensitive data.
CVE-2026-12693 Authorization Bypass in Vimesoft Enterprise Video Platform
2 TTPs 1 CVEA critical authorization bypass vulnerability, identified as CVE-2026-12693, exists in Vimesoft Inc.'s Enterprise Video Platform, affecting versions from 3.11.0.0 before 3.25.0, allowing an unauthenticated, remote attacker to gain unauthorized access to functionality not properly constrained by Access Control Lists (ACLs) via a user-controlled key, leading to high confidentiality and integrity impacts.
CVE-2026-12692: Unverified Password Change Vulnerability in Vimesoft Enterprise Video Platform
1 TTP 2 CVEs 1 IOCAn unverified password change vulnerability (CVE-2026-12692) exists in Vimesoft Inc.'s Enterprise Video Platform, affecting versions from 3.11.0.0 up to, but not including, 3.25.0, which allows an attacker to bypass authentication mechanisms, potentially leading to unauthorized access to the platform by changing user passwords without proper verification.
SigNoz Open Redirect Vulnerability Allows Session Token Theft (CVE-2026-63094)
3 TTPs 1 CVEAn open redirect vulnerability exists in SigNoz through version 0.133.0 within its SSO authentication flow, affecting instances configured with Google OAuth, SAML, or OIDC. Unauthenticated attackers can exploit this by crafting a login URL with a malicious `ref` parameter pointing to an attacker-controlled host. By delivering this crafted URL to a victim, attackers can steal the victim's access and refresh tokens upon successful SSO authentication, leading to session compromise.
CVE-2026-63093: Binary Planting Vulnerability in Cursor for Windows
1 rule 3 TTPs 1 CVECVE-2026-63093 describes a binary planting vulnerability in Cursor for Windows version 3.2.16 that allows a remote attacker to achieve arbitrary code execution by placing a malicious `git.exe` file in a crafted repository's root, which the Cursor IDE automatically executes during startup or on a recurring cadence when a developer opens the repository, running the malicious binary under the privileges of the current user.
CVE-2026-7488 IKAS E-Commerce Sensitive Information Disclosure Vulnerability
1 TTP 1 CVEA sensitive information insertion vulnerability (CVE-2026-7488) in IKAS Technology Inc. E-Commerce software allows an unauthenticated attacker to retrieve embedded sensitive data by crafting specific requests, leading to potential data exposure.
Improper Restriction of XML External Entity Reference in Netcad Software NetGIS (CVE-2026-8396)
2 TTPs 1 CVEA critical XML External Entity (XXE) vulnerability, CVE-2026-8396, in Netcad Software Inc.'s NetGIS allows unauthenticated remote attackers to perform serialized data external linking, potentially leading to sensitive information disclosure or server-side request forgery.
Proliz OBS Vulnerability Allows Sensitive Information Insertion Leading to ACL Bypass (CVE-2026-7189)
1 CVEA high-severity vulnerability, CVE-2026-7189, in Proliz Software Ltd. Co.'s Proliz OBS before version 3.6.0 allows for the insertion of sensitive information into sent data, enabling attackers to access functionality not properly constrained by Access Control Lists (ACLs).
Multiple Vulnerabilities in Ubuntu Pro Client
3 TTPsMultiple vulnerabilities exist in the ubuntu-pro-client within Ubuntu Linux, allowing an attacker to execute arbitrary program code with administrator privileges and disclose confidential information.
nginx-ui: Multiple Vulnerabilities
4 TTPsMultiple vulnerabilities in nginx-ui allow an attacker to execute arbitrary code, including with root privileges, gain elevated privileges, perform account takeover, bypass security measures, and disclose or manipulate data.
pyasn1: Quadratic Complexity in OBJECT IDENTIFIER and RELATIVE-OID Processing Allows Denial of Service
1 CVEA denial of service vulnerability, identified as CVE-2026-59885, exists in the pyasn1 library caused by quadratic complexity in the processing of OBJECT IDENTIFIER and RELATIVE-OID, which can lead to a denial of service.
CVE-2026-15392: DBD::File Module Symlink Vulnerability
1 CVECVE-2026-15392 is a medium-severity vulnerability affecting versions of the Perl module DBD::File prior to 1.651, where the module fails to prevent symlinks to untrusted locations, potentially allowing local attackers to achieve information disclosure or local privilege escalation through symlink following.
libsoup Websocket Unbounded Decompression Denial of Service Vulnerability
1 CVEA remote denial of service vulnerability, CVE-2026-15709, exists in the libsoup library's websocket permessage-deflate extension, allowing an attacker to trigger a denial of service through unbounded decompression.
Libsoup WebSocket Remote Denial of Service Vulnerability
1 CVEA remote denial of service vulnerability, CVE-2026-15711, exists in the libsoup library's WebSocket connection handling due to an oversized control frame protocol violation, allowing an attacker to cause service disruption.
Vulnerability in Perl DBI Module Before 1.651 (CVE-2026-60082)
1 CVEA vulnerability, identified as CVE-2026-60082, exists in the DBI module for Perl, specifically in versions before 1.651, related to the module not enforcing statement handle consistency with the row.
Libsoup Vulnerability CVE-2026-15714 Allows Out-of-Bounds Read
1 CVEA vulnerability identified as CVE-2026-15714 in the Libsoup library's soupmultipartinputstream component allows an out-of-bounds read when processing an oversized multipart boundary string, potentially leading to information disclosure or application instability.
Libsoup HTTP/2 Frame Window Exhaustion Remote Denial of Service
1 CVEA remote denial of service vulnerability, CVE-2026-15713, exists in the soupcache component of the Libsoup library due to a memory leak that leads to HTTP/2 frame window exhaustion, potentially causing application crashes or unresponsiveness.
CoreDNS: Multiple Vulnerabilities Enable Denial of Service
1 TTP 1 CVEMultiple vulnerabilities exist in CoreDNS that allow a remote, unauthenticated attacker to execute a Denial of Service (DoS) attack against the service, potentially leading to service disruption and unavailability for affected systems utilizing CoreDNS.
Sensitive Information Exposure in LearnPress WordPress Plugin (CVE-2026-13765)
1 rule 2 TTPs 1 CVEAn unauthenticated sensitive information exposure vulnerability (CVE-2026-13765) in the LearnPress - WordPress LMS Plugin for Create and Sell Online Courses, versions up to 4.4.1, allows attackers to extract quiz answers, options, explanations, and question content, including for paid courses.
Arbitrary File Upload Vulnerability in ProfilePress WordPress Plugin (CVE-2026-13352)
3 TTPs 1 CVEAn arbitrary file upload vulnerability, CVE-2026-13352, affects the ProfilePress plugin for WordPress up to version 4.16.18, allowing authenticated attackers with author-level privileges or higher to upload executable files, which can lead to remote code execution.
Grav API Plugin Vulnerability Exposes JWT Access Tokens via URL Parameter
1 rule 6 TTPs 1 CVEThe Grav API plugin (getgrav/grav-plugin-api) before version 1.0.0-rc.16 is vulnerable to sensitive information exposure, accepting JWT access tokens via the '?token=' URL query parameter, causing these tokens to be logged in web server access logs, browser history, and potentially leaked through Referer headers, proxy, or CDN logs, which allows an attacker to gain unauthorized API access, read configuration and user data, create new admin accounts, modify system settings, and delete pages.
CVE-2026-62234: Grav SSRF Vulnerability via Unrestricted cURL Protocols in Webhooks
5 TTPs 1 CVEAn authenticated user with `api.webhooks.write` permissions can exploit CVE-2026-62234, a Server-Side Request Forgery (SSRF) vulnerability in Grav before version 2.0.4, by creating webhooks with unrestricted cURL protocols like `file://`, `dict://`, or `gopher://` to read local files, access process information, and pivot to internal services.
Grav Plugin API Privilege Escalation via Authorization Bypass (CVE-2026-62233)
1 TTP 1 CVEA privilege escalation vulnerability (CVE-2026-62233) in grav-plugin-api before version 1.0.6 allows non-super api.users.write managers to bypass authorization checks on administrative API endpoints, enabling the creation of super-admin API keys or disabling super-admin Two-Factor Authentication (2FA), leading to full Grav instance takeover.
Grav Two-Factor Authentication Bypass Vulnerability (CVE-2026-62232)
1 rule 2 TTPs 1 CVEA high-severity two-factor authentication bypass vulnerability (CVE-2026-62232) in Grav CMS before version 2.0.4 allows an attacker with a victim's password to overwrite their 2FA secret via the `regenerate2FASecret` task, enabling unauthorized access by generating a valid TOTP code and reducing multi-factor authentication to password-only protection.
OpenClaw SSRF Vulnerability (CVE-2026-62227) Allows Network Policy Bypass
1 rule 3 TTPs 1 CVEA server-side request forgery (SSRF) vulnerability, CVE-2026-62227, in OpenClaw versions before 2026.5.26 allows attackers with lower-trust access to bypass network policy checks through browser snapshot routes, leading to unauthorized access to internal network destinations.
OpenClaw Authorization Bypass Vulnerability (CVE-2026-62226)
2 TTPs 1 CVE 2 IOCsAn authorization bypass vulnerability, CVE-2026-62226, affects OpenClaw versions 2026.3.28 through 2026.5.18, enabling attackers with lower-trust access to perform actions requiring stronger authorization due to improper validation of current-tab URL checks in the browser act route.
OpenClaw Vulnerability Allows Untrusted Workspace Plugin Loading (CVE-2026-62222)
3 TTPs 1 CVE 2 IOCsA vulnerability, CVE-2026-62222, exists in OpenClaw versions prior to 2026.5.22, where an attacker with lower-trust caller access or control over configured input paths can exploit a flaw in the setup-mode discovery to load untrusted workspace plugins, leading to arbitrary code execution, persistence, and privilege escalation.
OpenClaw Authorization Flaw in QQBot Exec Approvals (CVE-2026-62217)
2 TTPs 1 CVE 2 IOCsAn authorization flaw (CVE-2026-62217, CWE-863) in OpenClaw versions 2026.5.14-beta.1 before 2026.5.27 allows lower-trust callers or non-allowlisted senders to execute or persist unauthorized operations via the QQBot exec approvals feature, potentially leading to privilege escalation and system compromise.
OpenClaw Race Condition Bypasses Authorization via DNS Rebinding Timing Window (CVE-2026-62212)
1 CVEA race condition exists in OpenClaw versions before 2026.5.28 within the MS Teams safeFetch DNS rebinding check, allowing a lower-trust caller to exploit a timing window between the DNS validation check and its use, potentially bypassing authorization or policy checks if the affected feature is enabled and reachable.
OpenClaw Environment Variable Filtering Vulnerability Allows Execution and Persistence
2 TTPs 2 CVEsOpenClaw versions prior to 2026.6.6 contain an environment variable filtering vulnerability in its host exec component that fails to properly sanitize rustup startup variables, allowing attackers with lower-trust caller access or configured input paths to execute or persist actions beyond their intended authorization level.
CVE-2026-62202 - OpenClaw Privilege Escalation via Isolated Cron Jobs
2 TTPs 2 CVEs 2 IOCsOpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability, CVE-2026-62202, in isolated cron jobs that allows lower-trust callers to regain denied execution tools and execute or persist actions beyond their intended authorization by leveraging misconfigured input paths.
OpenClaw Network Policy Bypass Vulnerability CVE-2026-62201
1 rule 2 TTPs 1 CVEOpenClaw versions prior to 2026.6.6 contain a network policy bypass vulnerability, CVE-2026-62201, within its sandbox exec-server that allows lower-trust callers to send HTTP requests to internal network destinations, effectively bypassing configured security policies and leading to server-side request forgery (SSRF).
Clawvet API Server Hard-Coded JWT Secret Vulnerability (CVE-2026-62241)
3 TTPs 1 CVE 1 IOCA critical vulnerability exists in the clawvet self-hosted API server (apps/api) before version 0.7.5 due to a hard-coded fallback JWT secret ('clawvet-dev-secret-change-me') shipped in the default .env.example, allowing an unauthenticated remote attacker to harvest user IDs, forge session cookies, and retrieve sensitive user information including email address, subscription plan, and API key via the /api/v1/auth/me endpoint.
Bricksforge WordPress Plugin Privilege Escalation Vulnerability (CVE-2026-14956)
1 TTP 1 CVEThe Bricksforge plugin for WordPress, in versions up to and including 3.1.8.6, contains a critical privilege escalation vulnerability, CVE-2026-14956, allowing unauthenticated attackers to register new administrator accounts by manipulating the 'fieldIds' parameter in Pro Forms registration actions, leading to full compromise of the WordPress site.
CVE-2026-63089: WireGuard Easy Weak One-Time Link Token Generation Vulnerability
1 rule 2 TTPs 1 CVEUnauthenticated network attackers can exploit a cryptographically weak one-time link token generation vulnerability, CVE-2026-63089, in WireGuard Easy through version 15.3.0 by brute-forcing a limited keyspace against the unauthenticated `/cnf/:oneTimeLink` route, allowing them to recover WireGuard peer credentials (PrivateKey and PresharedKey) and impersonate legitimate peers to gain unauthorized VPN access.
MCP Python SDK WebSocket Server Lacks Host/Origin Validation
2 TTPs 1 CVEA high-severity vulnerability (CVE-2026-59950) in the deprecated `mcp.server.websocket.websocket_server` component of the MCP Python SDK allows malicious webpages to bypass same-origin policy and establish unauthorized WebSocket connections, enabling attackers to invoke server tools and read resources from affected local or LAN-bound MCP servers.
ArcadeDB Trigger Script RCE via Java.lang.* Allow-list
3 TTPsA vulnerability in ArcadeDB's ScriptTriggerExecutor allows users with UPDATE_SCHEMA privileges to achieve OS Remote Code Execution (RCE) due to a permissive allow-list for trigger scripts, enabling direct calls to `java.lang.Runtime.exec()` when a malicious trigger script is created and fired.
MCP Python SDK Authentication Bypass Vulnerability (CVE-2026-52869)
1 TTP 1 CVEA high-severity authentication bypass vulnerability, CVE-2026-52869, exists in affected versions of the MCP Python SDK's HTTP transports, allowing an attacker who obtains or guesses a session ID to send JSON-RPC messages to an existing session without verifying the authenticated principal, thereby bypassing per-client isolation and potentially injecting messages.
MCP Python SDK Vulnerability Allows Cross-Client Task Access and Cancellation (CVE-2026-52870)
3 TTPs 1 CVEA high-severity vulnerability (CVE-2026-52870) in the MCP Python SDK's experimental task handlers, specifically in versions 1.23.0 through 1.27.1, allows any connected client to observe, read results from, and cancel tasks belonging to other clients due to a lack of session validation, potentially leading to unauthorized data access and denial of service.
Envoy Gateway xDS Control Plane Information Disclosure Vulnerability (CVE-2026-53714)
2 TTPsA vulnerability in Envoy Gateway, when operating in GatewayNamespaceMode, allows unauthenticated access to the xDS gRPC server on port 18000. This is due to a missing unary interceptor and an authentication bypass in the JWT interceptor that fails to validate specific message types (DiscoveryRequest). Any pod within the cluster can exploit this flaw using the State-of-the-World (SotW) xDS protocol to retrieve sensitive information, including TLS private keys, all xDS resources, backend endpoints, and routing rules.
Envoy Gateway Authentication Bypass via Path Traversal Leads to Secret Disclosure
2 TTPsA critical path traversal vulnerability (CVE-2026-53713) exists in the `to_absolute_normalized_path` function of Envoy Gateway due to improper input validation, allowing specially crafted Lua code submitted via an `EnvoyExtensionPolicy` to bypass critical-path checks and read arbitrary sensitive files from the gateway controller pod's filesystem, potentially leading to authentication bypass to the Kubernetes API Server or Gateway XDS server.
Grafana MCP Server SSRF and Loki DoS Vulnerabilities Addressed
1 rule 3 TTPs 2 CVEsGrafana has published security advisories for vulnerabilities in Grafana MCP Server (CVE-2026-15583), leading to server-side request forgery, and Grafana Loki (CVE-2026-21729), resulting in unbounded memory allocation and denial of service, impacting versions 0.17.1 and prior for MCP Server and 3.7.0 and prior for Loki, urging users to update to mitigate potential exploitation.
CVE-2026-63088: stoatchat Server-Side Request Forgery (SSRF) via DNS Blocklist Bypass
1 TTP 1 CVEAn unauthenticated, network-accessible Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2026-63088, exists in stoatchat versions prior to 0.14.0, allowing attackers to bypass DNS-based IP blocklists by exploiting incomplete address validation, potentially leading to unauthorized access to internal network resources.
Server-Side Request Forgery in text-generation-inference Allows Internal Access
1 rule 3 TTPs 1 CVEAn unauthenticated network attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability, identified as CVE-2026-63086, in the OpenAI-compatible multimodal chat completions endpoint of text-generation-inference through version 3.3.7 to coerce the server into issuing arbitrary HTTP GET requests, enabling internal port scanning and credential theft from internal services and cloud instance metadata endpoints.
Authorization Bypass in Axelor Open Platform (CVE-2026-63085)
1 TTP 1 CVEAn authorization bypass vulnerability, CVE-2026-63085, in Axelor Open Platform versions 8.x prior to 8.2.2 allows authenticated non-admin users to exploit unenforced field restrictions during nested relational save operations to modify sensitive user record fields like roles and groups, thereby escalating privileges to administrative levels.
Lenovo App Store Path Traversal Vulnerability (CVE-2026-13103) Leading to Arbitrary Code Execution
1 TTP 1 CVEA critical path traversal vulnerability, identified as CVE-2026-13103, exists in the Lenovo App Store, enabling a local authenticated user to achieve arbitrary code execution on affected Windows systems within the Chinese market.
Grafana OnCall Unauthenticated Access Vulnerability (CVE-2026-63087)
4 TTPs 1 CVEA critical unauthenticated access vulnerability, CVE-2026-63087, in Grafana OnCall through version 1.16.11 allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to an internal plugin install endpoint using hardcoded default stack_id and org_id values, enabling authentication to all internal API endpoints, creation of arbitrary administrative users, and redirection of API calls to an attacker-controlled host.
Rockwell Automation Communication Modules Denial-of-Service Vulnerability
1 TTP 1 CVEA denial-of-service vulnerability (CVE-2026-9653) in Rockwell Automation 1756-EN2, 1756-EN3, and 1756-ENBT communication modules, due to improper validation of CIP Implicit Connection packets, allows an unauthenticated network attacker to continuously disrupt device connections.
Multiple Vulnerabilities in AutomationDirect Productivity Suite Could Lead to Privilege Escalation and DoS
2 TTPsMultiple vulnerabilities, including out-of-bounds write, out-of-bounds read, and divide-by-zero, exist in AutomationDirect Productivity Suite versions up to and including v4.6.2.2, allowing an attacker with local or physical access to exploit these flaws via crafted IOCTL requests, potentially leading to kernel memory corruption, privilege escalation, information disclosure, application instability, or a denial-of-service condition.
Multiple Out-of-Bounds Write Vulnerabilities in Rockwell Automation Arena
1 rule 3 TTPs 4 CVEsMultiple out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in Rockwell Automation Arena versions prior to V17.00.01 could allow an attacker to execute arbitrary code by convincing a user to open a malicious file.
NASA Core Flight System Health & Safety Application Denial-of-Service Vulnerability
1 TTPA high-severity denial-of-service vulnerability, CVE-2026-15352, affects NASA Core Flight System (cFS) Health & Safety (HS) Application versions prior to v7.0.1, allowing an unauthenticated attacker to crash the application via a crafted Housekeeping Telemetry request, leading to service disruption in critical infrastructure sectors like Transportation Systems.
Rockwell Automation FactoryTalk DataMosaix Stored XSS Vulnerability (CVE-2026-9292)
2 TTPs 1 CVEAn authenticated attacker with high privileges can exploit CVE-2026-9292, a Stored Cross-Site Scripting (XSS) vulnerability, in Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier by injecting malicious scripts into the Workflows configuration, leading to execution of malicious JavaScript in other users' browsers and potential account takeover or credential theft.
Rockwell Automation Flex 5000 Adapter Vulnerability Leads to Denial of Service
2 TTPs 1 CVEA denial-of-service vulnerability (CVE-2026-12659), categorized as a Double Free issue (CWE-415), exists in Rockwell Automation Flex 5000 Adapter version 6.011 due to improper handling of crafted CIP packets, which could allow an unauthenticated attacker to cause a denial-of-service condition requiring a power cycle to recover.
Rockwell Automation CompactLogix and ControlLogix Vulnerabilities Lead to Denial-of-Service
2 TTPs 3 CVEsMultiple Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product versions are vulnerable to denial-of-service conditions through CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, which an attacker can exploit via buffer overflows by loading invalid project files or writing invalid data, causing controllers to enter a major non-recoverable fault.
Unauthenticated Server-Side Request Forgery (SSRF) Vulnerability in stoatchat CVE-2026-63306
1 rule 3 TTPs 1 CVEAn unauthenticated server-side request forgery vulnerability, tracked as CVE-2026-63306, exists in stoatchat versions prior to 0.13.5 in the /proxy and /embed endpoints, allowing attackers to enumerate internal services, fingerprint applications, and access instance metadata endpoints, leading to unauthorized information disclosure and potential further compromise of internal infrastructure.
Denial-of-Service Vulnerability Affects ESET Endpoint Antivirus and Server Security Products (CVE-2026-6424)
1 TTP 1 CVEA vulnerability, identified as CVE-2026-6424, has been discovered in various ESET Endpoint Antivirus and Server Security product versions, allowing an attacker to cause a denial of service, impacting the availability of the affected systems.
Multiple Vulnerabilities Discovered in Drupal Leading to XSS and Data Confidentiality Breach
3 TTPsMultiple vulnerabilities have been discovered in Drupal, allowing an attacker to achieve indirect remote code injection via Cross-Site Scripting (XSS) and compromise data confidentiality across various versions.
Vulnerability in Traefik Allows Security Policy Bypass
1 IOCA vulnerability has been discovered in Traefik versions 3.7.x prior to 3.7.8, enabling an attacker to bypass security policies, potentially leading to unauthorized access or actions.
FreeRDP: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in FreeRDP allow an attacker to execute arbitrary code, bypass security controls, disclose sensitive information, tamper with data, or cause a denial-of-service, posing a high risk to systems using the software.
X.Org X11 Server (libXfont2): Multiple Vulnerabilities Allow Arbitrary Code Execution with Administrator Rights
1 TTPMultiple vulnerabilities in X.Org X11 Server and libXfont2 allow a local attacker to gain elevated privileges and execute arbitrary code with root rights, posing a significant risk for systems utilizing the X.Org display server.
LiteLLM Vulnerability Allows Remote Code Execution with Service Privileges
2 TTPsA remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code with the privileges of the service.
Multiple Vulnerabilities in Absolute Secure Access
2 TTPsAn attacker can exploit multiple vulnerabilities in Absolute Secure Access to perform a denial of service attack or disclose confidential information.
X-Rite MA-T6 Remote Code Execution Vulnerability (CVE-2023-49899)
2 TTPs 1 CVEAn unauthenticated remote attacker can exploit CVE-2023-49899 in X-Rite MA-T6 devices (versions prior to v2.33) to achieve arbitrary command execution by bypassing origin verification, leading to full compromise of the device.
Drupal Core: Multiple Vulnerabilities Allowing Information Disclosure and XSS
2 TTPsA remote, unauthenticated attacker can exploit multiple vulnerabilities in Drupal Core to achieve information disclosure and Cross-Site Scripting (XSS) attacks, potentially compromising user data or session integrity.
Apache Ivy: Vulnerability Allows File Manipulation
1 TTPA remote, authenticated attacker can exploit a vulnerability in Apache Ivy to manipulate files on the system, leading to unauthorized modification of data and potential integrity compromise.
7-Zip: Vulnerability Enables Code Execution
1 TTPA remote, anonymous attacker can exploit an unspecified vulnerability in 7-Zip to execute arbitrary code, leading to potential compromise of the system running the vulnerable software.
F5 BIG-IP and BIG-IP Next Vulnerability Enables Denial of Service
1 TTPAn unauthenticated, remote attacker can exploit a vulnerability in F5 BIG-IP and BIG-IP Next to perform a Denial of Service attack, potentially disrupting services.
Unpatched Shark Vacuum Flaw Allows Region-Wide Remote Control and Data Theft
6 TTPsA researcher discovered an unpatched vulnerability in Shark RV2320EDUS robot vacuums that allows an attacker with physical access to extract an overly permissive AWS IoT certificate, enabling region-wide remote command execution and data theft on other Shark vacuums.
Red Hat OpenShift Container Platform Vulnerability Allows Security Bypass
1 TTPA vulnerability in the Red Hat OpenShift Container Platform allows a local attacker to bypass security controls, potentially leading to unauthorized access or further compromise of the platform.
Gitea: Multiple Vulnerabilities
2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in Gitea to manipulate data or trigger a denial of service.
Argo CD: Multiple Vulnerabilities
2 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in Argo CD, including Cross-Site Scripting (XSS) and information disclosure flaws, which could lead to sensitive information exposure and potentially allow the attacker to gain administrator privileges.
Stored Cross-Site Scripting Vulnerability in Breakdance WordPress Plugin
1 rule 2 TTPs 1 CVEThe Breakdance plugin for WordPress, in versions up to and including 2.7.1, is susceptible to CVE-2026-7543, a Stored Cross-Site Scripting (XSS) vulnerability via the 'fields' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute when users access affected pages, potentially leading to session hijacking, data theft, or defacement.
Uncanny Automator WordPress Plugin Vulnerable to Arbitrary File Deletion (CVE-2026-15008)
2 TTPs 1 CVEA critical arbitrary file deletion vulnerability, CVE-2026-15008, exists in The Uncanny Automator plugin for WordPress, versions up to and including 7.3.1.4, due to insufficient file path validation in the `fr_token` function, allowing unauthenticated attackers to delete arbitrary files on the server and potentially achieve remote code execution (RCE) by targeting critical files like `wp-config.php`, provided a Forminator form is linked to an 'Everyone' configured Uncanny Automator recipe, enabling the submission of a malicious serialized payload that leverages a gadget chain within the plugin's `Action_Helpers_Email __destruct()` method.
CVE-2026-48863: libsolv Stack-Based Buffer Overflow Leading to Denial of Service
1 CVEA critical stack-based buffer overflow vulnerability, CVE-2026-48863, has been identified in the PGP verification component of libsolv, allowing a remote attacker to trigger a denial of service by crafting a malicious Ed25519 PGP signature with mismatched MPI lengths, impacting automated package or repository processing workflows.
Feast Feature Server Denial of Service via Unauthenticated WebSocket Connections (CVE-2026-23538)
1 rule 1 TTP 1 CVEA vulnerability (CVE-2026-23538) exists in the Feast Feature Server's /ws/chat endpoint, allowing remote attackers to establish numerous unauthenticated, persistent WebSocket connections. This exploit, a form of resource exhaustion (CWE-770), consumes server resources like memory, CPU, and file descriptors, leading to a complete denial of service for legitimate users. Affected versions are those prior to 0.59.0.
Unauthenticated Access to @andrea9293/mcp-documentation-server Web UI/API
1 rule 4 TTPsThe `@andrea9293/mcp-documentation-server` version 1.13.0 defaults to binding its Web UI/API to all network interfaces (0.0.0.0:3080) and lacks authentication for its document-management endpoints, enabling any network-reachable attacker to perform unauthorized operations such as reading, searching, adding, and deleting documents, potentially corrupting the user's knowledge base.
dd-trace-rb: Improper Parsing of W3C Baggage Headers Leads to DoS
1 TTPA vulnerability (CVE-2026-50276) in Datadog tracing libraries, specifically `dd-trace-rb` versions prior to 2.32.0, allows a remote and unauthenticated attacker to perform a Denial of Service (DoS) by sending HTTP requests with malformed W3C baggage headers, leading to unbounded CPU and memory consumption.
Pomerium Pre-Auth Memory Exhaustion via Unbounded zstd Decompression
1 TTP 1 IOCPomerium proxy deployments using the stateless authentication flow (Pomerium Zero or hosted authenticate) are vulnerable to a pre-authentication memory exhaustion denial of service, allowing an unauthenticated attacker to send specially crafted HPKE-encrypted zstd payloads to the `/.pomerium/callback` endpoint, leading to excessive memory allocation and potential proxy crashes.
Datadog dd-trace-go Library Vulnerability May Lead to Denial of Service
1 TTPA vulnerability, CVE-2026-50274, in Datadog's `dd-trace-go` library (versions <= 1.24.1 and v2 < 2.8.1) allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending HTTP requests with oversized W3C baggage headers, leading to unbounded CPU and memory consumption in instrumented services.
Datadog dd-trace-dotnet Improper W3C Baggage Header Parsing Leads to DoS
1 TTPA Denial of Service (DoS) vulnerability exists in Datadog tracing libraries (`dd-trace-dotnet`) due to improper parsing of W3C baggage HTTP headers, allowing remote, unauthenticated attackers to send requests with arbitrarily large baggage headers, causing unbounded CPU and memory consumption and leading to service unavailability for any HTTP service instrumented with affected library versions where baggage propagation is enabled by default. The issue, tracked as CVE-2026-50273, is resolved in version 3.43.0 and later.
Datadog dd-trace-js W3C Baggage Header Denial of Service Vulnerability
1 TTPThe Datadog `dd-trace-js` library, specifically versions older than 5.100.0, is vulnerable to a Denial of Service (DoS) attack where improper parsing of W3C baggage HTTP headers allows a remote, unauthenticated attacker to send requests with an arbitrarily large number of comma-separated key-value pairs, leading to unbounded CPU and memory consumption and enabling a remote DoS against any HTTP service instrumented with the affected library where baggage propagation is enabled.
Datadog dd-trace-py Improper Parsing of W3C Baggage Headers Leads to DoS
1 TTPThe Datadog dd-trace-py tracing library, versions prior to 4.8.2, is vulnerable to a Denial of Service (DoS) attack due to improper parsing of W3C baggage HTTP headers, which fails to enforce item-count or byte-size limits on the extraction path, allowing an unauthenticated attacker to send a request with an arbitrarily large baggage header causing unbounded CPU and memory consumption.
Datadog dd-trace-java DoS Vulnerability via W3C Baggage Headers
1 TTPA denial-of-service vulnerability, CVE-2026-50270, exists in Datadog tracing libraries (dd-trace-java prior to version 1.62.0) that implement W3C baggage propagation. Remote, unauthenticated attackers can exploit this by sending HTTP requests with W3C baggage headers containing an arbitrarily large number of comma-separated key-value pairs. The tracer, when extracting these headers, fails to enforce item-count or byte-size limits, leading to unbounded CPU and memory consumption as it allocates hash-map entries for each pair, thereby causing a denial of service against the instrumented HTTP service.
ViewComponent HTML-Safety Bypass Leads to Cross-Site Scripting (CVE-2026-54498)
3 TTPsA critical HTML-safety bypass vulnerability, CVE-2026-54498, exists in ViewComponent versions prior to 4.12.0, allowing attackers to inject raw HTML via the `around_render` method, bypassing standard escaping and leading to Cross-Site Scripting (XSS) in affected Ruby on Rails applications.
Message Corruption Vulnerability in websocket-driver Library (CVE-2026-54466)
A critical vulnerability, CVE-2026-54466, in the `websocket-driver` npm library allows remote attackers to cause message corruption by sending specially crafted WebSocket frames that exploit improper handling of the protocol's length header, leading to incorrect parsing of subsequent payload data.
Authenticated Path Traversal in Obsidian Local REST API
1 rule 4 TTPsAn authenticated path traversal vulnerability (GHSA-62gx-5q78-wrvx) in the Obsidian Local REST API's `/vault/{path}` endpoints allows an attacker to bypass path normalization checks using URL-encoded `%2F` sequences, enabling arbitrary file read, write, and delete operations outside the intended vault directory with the privileges of the Obsidian process.
CVE-2026-62389 - ws Library Memory Exhaustion Vulnerability
1 TTP 1 CVEA memory exhaustion vulnerability, CVE-2026-62389, exists in the 'ws' WebSocket library versions prior to 8.21.1, allowing attackers to exhaust server memory via incomplete fragmented WebSocket messages and cause denial of service.
CVE-2026-59255: Missing Authorization in BloodHound Custom Node API
4 TTPs 1 CVEAn authenticated attacker can exploit CVE-2026-59255, a missing authorization vulnerability in BloodHound versions through 9.4.0's custom-nodes API endpoints, to modify the global graph schema by creating, updating, or deleting custom node types, affecting all users and tenants.
Remote Code Execution Vulnerability in PyTorch Lightning via Malicious Checkpoint Files (CVE-2026-58659)
1 TTP 1 CVE 1 IOCA remote code execution vulnerability, CVE-2026-58659, exists in PyTorch Lightning through version 2.6.5, allowing attackers to craft malicious checkpoint files that execute arbitrary code by exploiting a flaw in the `_load_state` function when `LightningModule.load_from_checkpoint` is called.
Unauthenticated Information Disclosure in GPUStack
1 rule 1 TTP 1 CVEAn unauthenticated information disclosure vulnerability, CVE-2026-58658, in GPUStack through version 2.2.1 allows attackers to access sensitive inference logs containing prompts and completions and modify worker configurations by exploiting unprotected /serveLogs and /debug endpoints.
Splunk Path Traversal Vulnerability Allows Arbitrary File Writes (CVE-2026-20297)
3 TTPs 1 CVEA path traversal vulnerability (CVE-2026-20297) in Splunk Enterprise and Splunk Cloud Platform allows an authenticated user with `edit_local_apps` and `install_apps` capabilities to write files outside the intended application directory during app installation, specifically into the `$SPLUNK_HOME/etc/` directory and its subdirectories, leading to configuration manipulation, persistence, or privilege escalation.
Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)
4 TTPs 3 CVEsA Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.
Unbounded Recursion Depth in Elixir Protobuf Decoder Causes Denial of Service
1 TTPAn unauthenticated attacker can trigger a denial-of-service condition in services that decode untrusted protobuf messages using the `Protobuf.Decoder` (Hex package `protobuf`) versions between 0.8.0 and 0.16.1 by crafting deeply nested self-referential message types, leading to memory exhaustion and service crashes.
Insecure Permission Assignment for Garmin OAuth Token Store
4 TTPsThe `garminconnect` Python library versions 0.3.4 and earlier insecurely assigned world-readable file permissions to the `garmin_tokens.json` OAuth token store, allowing local attackers on multi-user systems to steal refresh tokens and gain persistent, unauthorized access to victims' Garmin Connect accounts.
Koel Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
1 rule 2 TTPsAn authenticated user can exploit a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-54493, in Koel v9.6.0 via the Subsonic-compatible radio endpoints, which lack proper URL validation, allowing the server to fetch and return the body of internal network resources.
KNX Protocol Vulnerability CVE-2023-4346 Allows Device Purging and Lockout
2 TTPs 1 CVEAn overly restrictive account lockout mechanism vulnerability, CVE-2023-4346, in KNX Association KNX Protocol Connection Authorization Option 1 could allow an attacker to purge all devices without additional security options enabled and set a BCU key to lock the device, leading to denial of service and data destruction.
MantisBT SQL Injection via history_order Configuration Value
2 rules 8 TTPsMantisBT versions 2.28.3 and earlier are vulnerable to a SQL injection within the `history_order` configuration value in `core/history_api.php`, allowing an authenticated administrator to inject malicious SQL via the web UI or REST API, which then executes whenever any user views a bug with history entries, leading to sensitive data extraction and potential Remote Code Execution (RCE) via webshell if the MySQL FILE privilege is enabled.
CVE-2026-59762: F5 BIG-IP HTTP/2 Profile Denial of Service Vulnerability
1 TTP 1 CVEA denial-of-service vulnerability (CVE-2026-59762) exists in F5 BIG-IP systems when an HTTP/2 profile is configured on a virtual server, where undisclosed requests can lead to increased memory resource utilization, degrading system performance and potentially causing the TMM process to restart, allowing a remote, unauthenticated attacker to cause a denial-of-service condition affecting the data plane.
NGINX Ingress Controller Injection Vulnerability via CRDs/Annotations (CVE-2026-55723)
2 TTPs 1 CVEAn injection vulnerability exists in the NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. An authenticated attacker with write permissions to these CRDs or annotations via the Kubernetes API can craft values to inject arbitrary NGINX configuration directives. This can lead to creating or deleting files and disabling services, affecting the control plane without exposing the data plane.
CVE-2026-42533 Heap Buffer Overflow in NGINX Map Directive
3 TTPs 2 CVEsA heap buffer overflow vulnerability, CVE-2026-42533, exists in NGINX Plus and NGINX Open Source when a 'map' directive uses regex matching and references its capture variables before the map's output variable or uses a non-cacheable variable under certain conditions, allowing an unauthenticated attacker to send crafted HTTP requests causing denial-of-service or remote code execution.
Cornac Tar Slip Vulnerability Allows Arbitrary File Writes via Path Traversal (CVE-2026-43637)
2 TTPs 1 CVEA path traversal vulnerability, dubbed 'Tar Slip' and tracked as CVE-2026-43637, exists in Cornac versions prior to 2.6.0, allowing attackers to write arbitrary files outside the intended cache directory by supplying a specially crafted TAR archive containing path manipulation sequences, which is then processed by built-in dataset loaders.
Vulnerability in ESET Inspect Connector Allowing Privilege Escalation
A vulnerability, CVE-2026-6423, in ESET Inspect Connector versions prior to 3.1.6017.0 for Windows allows an attacker to achieve privilege escalation on affected systems.
Vulnerability in Tenable Nessus Agent Allows Remote Code Execution and Security Bypass
2 TTPs 1 CVEA critical vulnerability, CVE-2026-15265, has been discovered in Tenable Nessus Agent versions prior to 11.2.1 and 11.1.4, which allows an attacker to achieve remote code execution and bypass security policies on affected systems, necessitating immediate patching.
Vulnerability in Veeam Backup & Replication Allows Privilege Escalation
1 IOCA privilege escalation vulnerability has been discovered in Veeam Backup & Replication, affecting versions prior to 12.3.0.65, which allows an attacker to elevate their privileges within the system.
Multiple Vulnerabilities in Citrix Products
2 CVEs 5 IOCsMultiple vulnerabilities have been discovered in various Citrix products, including Endpoint Analysis Client, Secure Access Client, XenCenter SDK client, and XenCenter. These flaws allow an attacker to achieve privilege escalation, compromise data confidentiality, and bypass security policies.
Multiple Vulnerabilities in Apache Tomcat
1 TTP 2 CVEsMultiple vulnerabilities, including CVE-2026-59083 and CVE-2026-59084, have been discovered in Apache Tomcat versions 10.1.x prior to 10.1.57, 11.0.x prior to 11.0.24, and 9.0.x prior to 9.0.120, allowing an attacker to bypass security policies and cause an unspecified security issue.
Vulnerability in Schneider Electric EcoStruxure Allows Security Policy Bypass
2 IOCsA vulnerability, identified as CVE-2026-14354, exists in Schneider Electric EcoStruxure Cybersecurity Admin Expert versions prior to or equal to 4.2.0, allowing an attacker to bypass the product's security policy, potentially leading to unauthorized access or actions.
CRI-O Environment Variable Injection Vulnerability (CVE-2026-15809)
1 rule 1 TTP 2 CVEsA critical vulnerability, CVE-2026-15809, in CRI-O allows an attacker with the ability to set container environment variables to bypass a previous fix (CVE-2022-4318), inject a newline character into the HOME environment variable, and add arbitrary lines to /etc/passwd, potentially leading to privilege escalation or persistence within the container.
Authentication Bypass in PraisonAI Call API via Host Header Spoofing (CVE-2026-61435)
1 rule 2 TTPs 1 CVEPraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability in the Call API agent invocation endpoints when PRAISONAI_CALL_AUTH=disabled is configured, allowing an unauthenticated attacker to remotely list and invoke registered agents by sending a spoofed 'Host: 127.0.0.1' HTTP header.
PraisonAI web_crawl Tool Vulnerable to DNS Rebinding SSRF (CVE-2026-61430)
1 rule 3 TTPs 1 CVEPraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) within its web_crawl tool, allowing attackers to bypass hostname validation using DNS rebinding and retrieve sensitive internal HTTP response bodies from private or loopback services.
CVE-2026-56400 open-webui Cross-Origin Resource Sharing Misconfiguration Leads to RCE
3 TTPs 1 CVEA cross-origin resource sharing (CORS) misconfiguration in open-webui versions prior to 0.3.14 allows remote attackers to achieve arbitrary code execution by crafting malicious cross-site requests that an authenticated administrator user visits.
Information Disclosure in Capgo Supabase Integration via RPC Function
2 TTPs 1 CVEAn information disclosure vulnerability in Capgo (Cap-go/capgo) before version 12.128.2 allows unauthenticated attackers to enumerate organization existence. This flaw resides within the Supabase PostgREST SECURITY DEFINER RPC function 'public.rescind_invitation', which returns distinct error messages (NO_ORG vs. NO_RIGHTS) when called with only a publishable API key. This enables attackers to discover valid organization IDs, increasing the attack surface for targeted phishing or social engineering campaigns.
Wazuh Manager Vulnerability CVE-2026-56699 Allows NDJSON Injection
2 TTPs 1 CVEWazuh Manager versions prior to 5.0.0-beta3 are critically vulnerable to an injection flaw, CVE-2026-56699 (CWE-74), enabling enrolled agents to inject arbitrary NDJSON operations into OpenSearch bulk requests, leading to data integrity compromise and defense evasion.
Perl Denial of Service Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Perl to cause a Denial of Service condition.
Octopus Deploy: Vulnerability Allows Security Bypass
1 TTPA remote, authenticated attacker can exploit a vulnerability in Octopus Deploy to bypass security measures, potentially leading to unauthorized access or actions within the affected system.
Multiple WebKitGTK Vulnerabilities
4 TTPsMultiple vulnerabilities exist in WebKitGTK that can be exploited by a remote, unauthenticated attacker for information disclosure, denial of service, data manipulation, and security mechanism bypass.
Multiple Vulnerabilities in Zoom Video Communications Rooms and Workplace
2 TTPsMultiple vulnerabilities have been identified in Zoom Video Communications Rooms and Zoom Video Communications Workplace, which an attacker can exploit to elevate privileges and ultimately take control of a user account.
Netty: Multiple Vulnerabilities
1 TTPAn attacker can exploit multiple vulnerabilities within the Netty framework to bypass security checks, manipulate requests or headers, circumvent certificate validations, and cause a denial of service.
Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service
1 TTPA vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.
SonicWall SMA: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in SonicWall SMA allow an unauthenticated, remote attacker to bypass security mechanisms and execute arbitrary operating system commands on the affected system, leading to full compromise of the appliance.
Citrix Secure Access Client for Windows Vulnerabilities Lead to Privilege Escalation and Information Disclosure
2 TTPsMultiple vulnerabilities in Citrix Systems Secure Access Client for Windows can be exploited by a local attacker to achieve privilege escalation and information disclosure on affected Windows systems.
Rockwell Automation Studio 5000 Logix Designer: Multiple Vulnerabilities Enable Code Execution
1 TTPMultiple vulnerabilities in Rockwell Automation Studio 5000 Logix Designer allow a local attacker to execute arbitrary program code, which could lead to a compromise of the affected system or unauthorized control over the design environment.
Multiple Vulnerabilities in Fortinet FortiSIEM
3 TTPsMultiple vulnerabilities have been identified in Fortinet FortiSIEM that could allow an attacker to perform Cross-Site Scripting (XSS) attacks or achieve arbitrary code execution, enabling unauthorized script injection into web pages or direct execution of attacker-controlled code within the system.
MetaGuru HCM SQL Injection Vulnerability (CVE-2026-15804)
2 TTPs 1 CVEA SQL Injection vulnerability (CVE-2026-15804) in MetaGuru's HCM software allows authenticated remote attackers to inject SQL commands via specific parameters, compromising database confidentiality, integrity, and availability.
OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision
1 TTP 1 CVEA high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.
RabbitMQ Management UI UNC SSRF Vulnerability (CVE-2026-57211) on Windows
1 CVECVE-2026-57211 details a Server-Side Request Forgery (SSRF) vulnerability within the RabbitMQ management UI when deployed on Windows, enabling an attacker to coerce the server into making requests to arbitrary UNC paths, potentially leading to NTLM credential disclosure or internal network reconnaissance.
RabbitMQ Topic Authorization Bypass via Cross-Tenant Routing-Key Vulnerability
1 CVECVE-2026-57217 details a vulnerability in RabbitMQ where topic authorization can be bypassed, leading to cross-tenant routing-key bypass, potentially allowing unauthorized access to or manipulation of routing keys in a multi-tenant environment.
RabbitMQ Stream Listener Vulnerability CVE-2026-57220 Allows Unauthenticated Memory Exhaustion DoS
1 TTP 1 CVEA denial-of-service vulnerability, CVE-2026-57220, exists in the RabbitMQ stream listener that allows an unauthenticated attacker to exhaust memory resources by not properly enforcing frame-size limits during authentication, leading to service disruption.
GitHub CLI `gh codespace jupyter` Command Remote Code Execution Vulnerability
1 TTP 1 CVEA remote code execution vulnerability, CVE-2026-59831, has been identified in the GitHub CLI's `gh codespace jupyter` command, allowing attackers to execute arbitrary code on a user's system when connecting to a specially crafted malicious Codespace.
Perl Regex Engine Vulnerability Allows Silently Incorrect Matches
1 CVEA vulnerability exists in Perl versions up to and including 5.43.9 where regular expression matches can be silently incorrect when an alternation of more than 65535 fixed string branches is compiled into a trie within the Perl_study_chunk function, potentially leading to incorrect logic or data processing.
RabbitMQ Unauthenticated OAuth Client Credential Disclosure via HTTP API (CVE-2026-57219)
1 TTP 1 CVECVE-2026-57219 describes an unauthenticated disclosure vulnerability in RabbitMQ, allowing an attacker to obtain OAuth client credentials via an HTTP API endpoint when RabbitMQ is configured with certain less common OAuth 2 configurations, potentially leading to unauthorized access to other systems or services.
Libarchive Heap Overflow and Out-of-Bounds Read via Pax Extended Header (CVE-2026-15028)
1 CVEA heap overflow and out-of-bounds read vulnerability (CVE-2026-15028) has been identified in the Libarchive library, triggered by parsing a tar archive with a specially crafted pax extended header, potentially leading to denial of service or arbitrary code execution.
CVE-2025-44904 HDF5 Heap Buffer Overflow in H5VM_memcpyvv Function
1 CVECVE-2025-44904 describes a heap buffer overflow vulnerability in HDF5 version 1.14.6 that occurs via the H5VM_memcpyvv function, which could lead to potential security risks such as denial of service or arbitrary code execution.
Multiple Vulnerabilities in Python Lead to Denial of Service
1 TTPRemote and unauthenticated attackers can exploit multiple unspecified vulnerabilities within Python to conduct Denial of Service attacks, potentially disrupting the availability of services or applications running on the language.
Red Hat Enterprise Linux Plexus-Utils Vulnerability Allows Remote Code Execution
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within the plexus-utils component, to execute arbitrary program code with user privileges, leading to system compromise.
Zhinianboke Xianyu-Auto-Reply Missing Authorization Vulnerability (CVE-2026-15752)
1 TTP 1 CVEA missing authorization vulnerability (CVE-2026-15752) exists in the /api/v1/users/ endpoint of zhinianboke xianyu-auto-reply, affecting versions up to commit dcb445ad97816ad65299a7580ee0c8c8f929da84, allowing a remote attacker to bypass authentication or authorization checks. An exploit for this vulnerability has been made public, and organizations using this product should apply the patch named 19fc3282a1bb78a05c34945c088525d20e081cbd to mitigate the risk.
Adobe Premiere Pro Out-of-Bounds Write Vulnerability (CVE-2026-48369)
3 TTPs 1 CVEAn out-of-bounds write vulnerability (CVE-2026-48369) in Adobe Premiere Pro, requiring user interaction to open a malicious file, can lead to arbitrary code execution in the context of the current user.
Adobe Bridge Integer Overflow Vulnerability (CVE-2026-48342) Leads to Arbitrary Code Execution
3 TTPs 1 CVECVE-2026-48342 is an Integer Overflow or Wraparound vulnerability in Adobe Bridge that could enable an attacker to achieve arbitrary code execution on a victim's system if the victim opens a specially crafted malicious file, affecting versions up to 16.0.3 and 15.1.5.
Adobe Creative Cloud Desktop Vulnerability Allows Arbitrary Code Execution via Uncontrolled Search Path
1 TTP 1 CVEAn Uncontrolled Search Path Element vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop versions up to 6.9.1.1 could allow arbitrary code execution in the context of the current user, requiring no user interaction but dependent on conditions beyond the attacker's full control.
Adobe Media Encoder Stack-based Buffer Overflow Vulnerability (CVE-2026-47971)
2 TTPs 1 CVEA critical stack-based buffer overflow vulnerability, CVE-2026-47971, in Adobe Media Encoder versions prior to 26.3 and 25.6.6 could lead to arbitrary code execution within the context of the current user when a victim opens a specially crafted malicious file.
Denial-of-Service Vulnerability in Pillow EPS Parser (CVE-2026-59203)
1 TTP 1 CVEA denial-of-service vulnerability, CVE-2026-59203, exists in the Python imaging library Pillow, affecting versions 12.0.0 through 12.2.0, where a specially crafted EPS file with a negative byte count in the `%%BeginBinary` directive can cause an infinite loop and resource exhaustion when processed by the `Image.open()` function, leading to application unresponsiveness.
Pillow TGA RLE Encoder Out-of-Bounds Read (CVE-2026-59198)
1 TTP 1 CVEA critical out-of-bounds read vulnerability, CVE-2026-59198, exists in Pillow versions 5.2.0 through 12.2.x, specifically within its TGA RLE encoder, allowing adjacent process heap bytes to be copied into generated TGA files, which can lead to information disclosure.
Critical Vulnerability in Podlove Podcast Publisher Plugin Allows Unauthenticated File Uploads Leading to RCE
1 rule 3 TTPs 1 CVE 4 IOCsA critical vulnerability, CVE-2026-13001, in the Podlove Podcast Publisher plugin for WordPress, impacting versions up to and including 4.5.1, allows unauthenticated attackers to upload arbitrary files due to missing file type validation, potentially leading to remote code execution on the server.
Anyquery Server-Side Request Forgery via Unrestricted SQLite Virtual Table Modules
3 rules 4 TTPsUnauthenticated attackers can exploit a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-54628) in Anyquery's `server` mode (versions prior to 0.4.5) by creating SQLite virtual tables that fetch internal network resources or cloud metadata, leading to internal network mapping and exfiltration of sensitive information like cloud credentials.
Netty StompSubframeDecoder Denial of Service Vulnerability (CVE-2026-44891)
1 TTPA high-severity denial of service vulnerability, identified as CVE-2026-44891, exists in the `StompSubframeDecoder` component of Netty's `netty-codec-stomp` library, allowing an unauthenticated attacker to exhaust server memory and cause an `OutOfMemoryError` by sending a STOMP message with an excessive number of headers, leading to application crashes.
Nebula-Mesh Stores Operator Session Tokens in Plaintext, Enabling Session Hijacking (CVE-2026-53603)
1 TTPOperator session tokens in ForgeKeep's nebula-mesh application are stored in plaintext within the database, allowing an attacker who gains read access to the database to retrieve active session tokens and hijack operator sessions, bypassing further authentication.
Woodpecker Privilege Escalation via Unrestricted Kubernetes serviceAccountName
2 TTPsA high-severity privilege escalation vulnerability (CVE-2026-61549) in Woodpecker CI, specifically affecting instances using the Kubernetes backend, allows any user with Push permissions on a connected repository to run pipeline pods under an arbitrary ServiceAccount, potentially leading to secret exfiltration and full cluster takeover.
Pillow Python Imaging Library Vulnerable to Out-of-Memory via Crafted JPEG2000
1 TTP 1 CVEA denial-of-service vulnerability, CVE-2026-59204, exists in the Pillow Python imaging library versions 8.2.0 through 12.2.0, allowing a remote attacker to trigger an out-of-memory error and crash applications by processing a specially crafted tiled JPEG2000 image.
EasyAdmin Bundle Stored Cross-Site Scripting via File Uploads (CVE-2026-54087)
1 TTPA high-severity stored cross-site scripting (XSS) vulnerability, tracked as CVE-2026-54087, exists in EasyAdmin Bundle versions >= 5.0.0 and < 5.0.13, allowing attackers to upload malicious HTML or SVG files containing JavaScript which executes in an administrator's session when viewed in the backend, leading to session/CSRF token theft and privilege escalation.
Trivy Unbounded Read Leads to Denial of Service via Helm Chart Tar Bomb
1 TTP 1 CVETrivy versions prior to 0.71.0 are vulnerable to CVE-2026-54448, a denial-of-service attack where a crafted Helm chart archive (.tgz) can cause unbounded memory consumption, leading to the OS OOM killer terminating the Trivy process and other services on the host or CI runner.
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import
1 rule 3 TTPs 4 IOCsA critical remote code execution (RCE) vulnerability exists in TidGi Desktop through version 0.13.0, allowing attackers to execute arbitrary code with full Node.js access by tricking victims into importing a specially crafted TiddlyWiki Git repository, leveraging the automatic execution of 'startup' modules during the wiki boot sequence.
Critical Remote Code Execution in Totolink NR1800X Routers (CVE-2026-15701)
2 TTPs 1 CVE 5 IOCsA critical stack-based buffer overflow vulnerability, CVE-2026-15701 (CVSS 9.8), in Totolink NR1800X firmware version 9.1.0u.6279_B20210910 allows remote attackers to execute arbitrary code by manipulating the 'Host' argument in the 'Form_Logout' function, with a public exploit available.
Ivanti Xtraction Vulnerabilities CVE-2026-14902 and CVE-2026-14903
2 CVEsIvanti has published a security advisory (AV26-696) on July 14, 2026, to address two vulnerabilities, CVE-2026-14902 and CVE-2026-14903, affecting Ivanti Xtraction version 2026.2 and prior, urging users to apply necessary updates to mitigate potential risks.
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)
2 TTPs 2 CVEs 6 IOCsA critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection Vulnerability
1 rule 4 TTPs 2 IOCsOpenCost contains an unauthenticated file write vulnerability, tracked as GHSA-wmj8-9953-vff5, in its `/serviceKey` endpoint that allows remote attackers to overwrite the GCP service account key file (`key.json`) without any authentication or input validation, leading to service disruption, credential theft, and potential privilege escalation within Kubernetes clusters or GCP environments.
Fedify SSRF Mitigation Bypass via Incomplete IPv4 Validation (CVE-2026-50131)
1 rule 2 TTPs 1 CVEFedify's `validatePublicUrl()` function, intended to mitigate Server-Side Request Forgery (SSRF), contains an incomplete IPv4 validation logic. It incorrectly treats several special-use, reserved, multicast, benchmarking, and carrier-grade NAT IPv4 ranges as valid public destinations, allowing an attacker to bypass the SSRF protection and cause the Fedify server to initiate requests to internal or non-public network ranges when processing attacker-controlled ActivityPub object, activity, document, or media URLs.
Woodpecker CI gRPC Vulnerability Allows Cross-Tenant Agent Impersonation (CVE-2026-50141)
1 TTP 1 CVEA high-severity vulnerability (CVE-2026-50141) in Woodpecker CI's gRPC layer allowed any authenticated agent to impersonate any other agent on the same server by injecting a forged `agent_id` into gRPC metadata, leading to potential privilege escalation and unauthorized access within CI/CD pipelines.
Anyquery Arbitrary File Write (AFW) Leads to Remote Code Execution (RCE)
3 rules 4 TTPsAnyquery in server mode is vulnerable to arbitrary file write (AFW) due to its failure to restrict native SQLite disk manipulation commands like `ATTACH DATABASE`. Unauthenticated attackers can connect to the MySQL-compatible server port and write arbitrary files (e.g., PHP webshells, malicious cronjobs) to any path writable by the Anyquery process, which can lead to remote code execution (RCE) with the privileges of the Anyquery process, significantly impacting system integrity and availability.
n8n-mcp Cross-Tenant Workflow Version Access Vulnerability
2 TTPsA critical cross-tenant access vulnerability exists in n8n-mcp versions up to 2.56.0, specifically in multi-tenant HTTP deployments. An authenticated tenant can read, delete, or destroy workflow version backups belonging to other tenants due to insufficient isolation of locally stored version history. This exposure includes sensitive data such as credential references and authorization headers embedded in node definitions, posing both a confidentiality and integrity/availability risk.
GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
A vulnerability, identified as CVE-2026-47282, in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose sensitive information over a network due to insufficiently protected credentials.
Vulnerability in ABB Advant Master Online Builder Allows Code Execution
1 TTP 1 CVEA vulnerability (CVE-2025-13162) exists in ABB Advant Master Online Builder products, including Control Builder A and 800xA for Advant Master, enabling an attacker with necessary local access to execute unauthorized code by exploiting an uncontrolled search path element (CWE-427) to load malicious DLLs, compromising system integrity within critical manufacturing environments.
Critical Unauthenticated Remote Access Vulnerability in Rockwell Automation 1715-AENTR EtherNet/IP Adapter (CVE-2026-10577)
1 TTP 1 CVEA critical unauthenticated remote access vulnerability, CVE-2026-10577, in Rockwell Automation 1715-AENTR EtherNet/IP Adapter versions <=3.003 allows an attacker to exploit a network-accessible debug port with missing privilege controls, enabling remote command-line interface access to read/delete files, modify memory, and change I/O states, impacting the confidentiality, integrity, and availability of industrial control systems.
Multiple Critical and High-Severity Vulnerabilities in ABB T-MAC Plus
4 TTPs 4 CVEsCISA has issued an advisory regarding critical and high-severity vulnerabilities CVE-2025-14771, CVE-2025-14772, CVE-2025-14773, and CVE-2025-14774 in ABB T-MAC Plus version 4.0-24, which could allow authenticated attackers to exfiltrate sensitive files, bypass authorization for administrative operations, execute arbitrary client-side code via cross-site scripting, or for unauthenticated attackers to cause a denial-of-service condition.
ServiceNow Critical Sandbox Escape Vulnerability (CVE-2026-6875)
3 CVEsServiceNow has released a security advisory addressing CVE-2026-6875, a critical sandbox escape vulnerability affecting multiple product versions including Brazil, Australia, Zurich, and Yokohama, which could allow an attacker to bypass security boundaries and execute arbitrary code with elevated privileges.
CVE-2026-15692: Tenda BE12 Pro Stack-Based Buffer Overflow Vulnerability
1 rule 2 TTPs 1 CVE 6 IOCsA stack-based buffer overflow vulnerability, identified as CVE-2026-15692, exists in Tenda BE12 Pro firmware version 16.03.66.23's `fromSafeUrlFilter` function, allowing remote attackers to achieve arbitrary code execution by manipulating the 'page' argument via a crafted HTTP request, with a public exploit available.
Tenda BE12 Pro Remote Code Execution Vulnerability (CVE-2026-15691)
2 TTPs 5 CVEs 8 IOCsA critical remote stack-based buffer overflow vulnerability (CVE-2026-15691) has been discovered in Tenda BE12 Pro firmware 16.03.66.23, affecting the `fromSafeClientFilter` function and allowing remote attackers to achieve arbitrary code execution by manipulating the `page` argument, with a public exploit available.
OpenSSH Vulnerability Allows Privilege Escalation
1 TTPA local attacker can exploit an unspecified vulnerability in OpenSSH to elevate their privileges on the affected system.
Remote Code Execution Vulnerability in ServiceNow AI Platform
2 TTPsA remote, anonymous attacker can exploit a vulnerability in ServiceNow AI Platform to execute arbitrary program code, leading to unauthorized control over the platform's underlying systems.
Unauthenticated Remote Code Execution in Argo CD Repo-Server (CVE-2026-15416)
3 TTPs 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-15416) exists in Argo CD's repo-server, the GitOps engine used by Red Hat OpenShift GitOps, allowing an attacker with network access to achieve RCE and deploy malicious Kubernetes resources, leading to potential cluster compromise.
Ollama: Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability in Ollama to execute a Denial of Service (DoS) attack, disrupting service availability.
QEMU Privilege Escalation Vulnerability
2 TTPsA local attacker can exploit a vulnerability in QEMU to elevate their privileges and execute arbitrary code on the host system where QEMU is running.
Remote SQL Injection in code-projects Online Job Portal (CVE-2026-15675)
2 rules 5 TTPs 1 CVEA SQL injection vulnerability (CVE-2026-15675) has been identified in code-projects Online Job Portal version 1.0, located in the `/Admin/EditUser.php` file and triggered by manipulating the `UserId` argument, allowing for remote SQL injection attacks with publicly available exploit code.
Unauthenticated Arbitrary Code Execution in SAProuter via DLL Hijacking (CVE-2026-0487)
1 rule 1 TTP 1 CVE 2 IOCsAn unauthenticated attacker can exploit CVE-2026-0487, a vulnerability in SAProuter running on Microsoft Windows, by loading malicious DLL files from an untrusted location, allowing them to execute arbitrary code on the affected system with high impact on confidentiality, integrity, and availability.
SAP Approuter HTTP Request Smuggling Vulnerability Allows Confidentiality and Availability Impact (CVE-2026-27690)
3 TTPs 1 CVEAn HTTP Request Smuggling vulnerability (CVE-2026-27690, CWE-444) in SAP Approuter allows an unauthenticated attacker to send a specially crafted HTTP request leading to request-response desynchronization, which can result in the exposure of user responses and cause a denial of service by making the system unavailable.
Kimai REST API Two-Factor Authentication Bypass Vulnerability
2 TTPsA critical vulnerability, CVE-2026-52827, in Kimai versions prior to 2.59.0 allows an attacker who has compromised a user's password to bypass Two-Factor Authentication (TOTP) for the REST API by intercepting and replaying the `KIMAI_SESSION` cookie obtained after password verification but before TOTP completion, granting full authenticated API access.
Kimai Docker Image Default APP_SECRET Allows Account Takeover (CVE-2026-52824)
3 TTPsA critical vulnerability, CVE-2026-52824, in the official Kimai Docker image allows unauthenticated attackers to forge authentication tokens and achieve account takeover, including super_admin accounts, due to the image shipping with a default, publicly known APP_SECRET environment variable used by Symfony to HMAC-sign session cookies and login links.
Cockpit CMS Missing Authorization Vulnerability in Bucket File Storage API (CVE-2026-57855)
4 TTPs 1 CVEA missing authorization vulnerability, CVE-2026-57855, in the Cockpit CMS Bucket file storage API allows any authenticated user, regardless of their assigned role, to perform all file operations on any named bucket, including those designated for administrative use, potentially leading to privilege escalation, data manipulation, or data destruction.
CrewAI Server-Side Request Forgery Vulnerability (CVE-2026-62240)
1 rule 3 TTPs 1 CVEA critical server-side request forgery (SSRF) vulnerability, CVE-2026-62240, exists in the `validate_url` function of CrewAI versions prior to 1.15.1, allowing attackers to bypass security filters using URL redirects or DNS rebinding to access internal services and cloud metadata endpoints.
CVE-2026-59801: 9Router Unauthenticated API Access Vulnerability
1 rule 3 TTPs 1 CVEA critical unauthenticated access vulnerability, CVE-2026-59801, in 9Router versions up to 0.4.41 allows remote attackers to bypass authentication on provider management API endpoints, enabling them to enumerate, create, modify, or delete connections, leading to credential exposure, AI traffic redirection, or complete denial of service.
9Router Unauthenticated Information Disclosure (CVE-2026-62328)
2 rules 2 TTPs 1 CVEAn unauthenticated information disclosure vulnerability in 9Router through version 0.4.41 allows remote attackers to access sensitive user data by querying unprotected API endpoints like `/request-logs` and `/request-details` to enumerate paginated request logs and retrieve complete AI conversation histories, including system prompts, user messages, assistant responses, tool calls, and user email addresses, due to a lack of authentication middleware.
Spring Boot Admin Server SSRF Vulnerability (CVE-2026-62242)
5 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-62242, a server-side request forgery vulnerability in Spring Boot Admin Server before 4.1.2, to force the server to make requests to arbitrary internal addresses and exfiltrate sensitive data, including cloud credentials.
OpenClaw Git Ext Transport Vulnerability Allows Unauthorized Code Execution (CVE-2026-62200)
2 TTPs 1 CVEA critical vulnerability, CVE-2026-62200, in OpenClaw versions before 2026.6.1 allows a lower-trust caller to execute or persist unauthorized actions via the Git ext transport feature, potentially leading to remote code execution due to improper host exec environment filtering.
OpenClaw Environment Filtering Bypass Vulnerability (CVE-2026-62199)
2 TTPs 1 CVEA critical vulnerability, CVE-2026-62199, in OpenClaw versions prior to 2026.6.6 allows a lower-trust caller to bypass host execution environment filtering by supplying crafted interpreter startup variables, leading to unauthorized code execution and persistence.
OpenClaw Policy Bypass Vulnerability in Browser CDP Discovery
1 CVEOpenClaw before version 2026.6.6 contains a policy bypass vulnerability in its browser CDP discovery feature that allows attackers with lower-trust access to circumvent network blocking policies by accepting WebSocket URLs that should have been blocked, enabling them to reach otherwise restricted network destinations when the affected feature is enabled.
OpenClaw Symlink Following Vulnerability (CVE-2026-62189)
5 TTPs 4 CVEs 8 IOCsA symlink following vulnerability, identified as CVE-2026-62189, in OpenClaw versions prior to 2026.6.9's mirror sync feature allows attackers with low privileges to bypass authorization boundaries by exploiting remote symlink parents, enabling unauthorized actions requiring stronger permissions.
OpenClaw Feishu Tools Authorization Bypass Vulnerability (CVE-2026-62187)
1 TTP 1 CVEOpenClaw Feishu tools (npm package @openclaw/feishu) versions up to and including 2026.6.6 contain CVE-2026-62187, an authorization bypass vulnerability that allows lower-trust callers to perform unauthorized operations by ignoring per-account disablement or policy checks, leading to potential data manipulation or information disclosure.
CVE-2026-62184 - luci-app-banip Log Parsing Vulnerability
1 CVEA log parsing vulnerability in OpenWrt's luci-app-banip allows an unauthenticated remote attacker to inject arbitrary IPv4 addresses into log lines via crafted input fields, leading to the misidentification and blocking of legitimate users or services while the true attacker remains unblocked.
CVE-2026-61458 Brute-Force Vulnerability in PasswordPusher
1 rule 1 TTP 1 CVEA brute-force vulnerability, tracked as CVE-2026-61458, exists in PasswordPusher versions prior to 2.9.2, allowing attackers with a known push token to systematically guess passphrases at high rates due to a lack of route-specific rate limiting and per-push lockout mechanisms on the POST /p/:token/access endpoint, potentially leading to the recovery of sensitive secrets within hours or days.
9Router Unauthenticated API Key Disclosure Vulnerability
1 rule 2 TTPs 1 CVEAn unauthenticated information disclosure vulnerability, CVE-2026-62327, in 9Router through version 0.4.41 allows remote attackers to retrieve plaintext AI provider API keys via a missing authentication middleware on the Next.js API route accessible at /api/usage/stats, enabling unauthorized access to sensitive data, potential billing fraud, and quota exhaustion.
Server-Side Request Forgery in Laravel-Mediable Allows Credential Exfiltration
4 rules 4 TTPs 1 CVEA Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-49969, exists in Laravel-Mediable versions prior to 7.0.0, allowing remote attackers to force the server to make arbitrary HTTP requests to attacker-controlled URLs provided to `MediaUploader::fromSource()` to target internal network resources, access sensitive files, and exfiltrate cloud credentials like IAM tokens.
DIRAC Vulnerable to Remote Code Execution via SQL Injection and Eval in DatasetManager
6 TTPsAn authenticated user can achieve remote code execution in DIRAC's FileCatalog DatasetManager due to an SQL injection vulnerability (CVE-2026-61667) that allows manipulation of query results passed to an `eval` function, leading to full system compromise.
Apollo ConfigService Authentication Bypass via Raw Config File AppId Parsing
2 TTPsAn authentication bypass vulnerability (CVE-2026-59955) in Apollo ConfigService allows unauthenticated remote attackers to read raw configuration data by exploiting an incorrect appId parsing logic for the raw config file endpoint, affecting versions prior to 2.5.2.
Shiori Privilege Escalation via Account Update Endpoint (CVE-2026-61463)
1 TTP 1 CVE 4 IOCsShiori contains a privilege escalation vulnerability in its account update endpoint that allows authenticated users to exploit this by sending a crafted PATCH request to modify the 'owner' field to 'true' without proper authorization checks, leading to administrative access and full system control.
DIRAC Vulnerable to Remote Code Execution via eval on Untrusted Input in RequestManager
2 rules 6 TTPsA critical remote code execution vulnerability (CVE-2026-45579) in DIRAC's RequestManager allows any authenticated user to execute arbitrary commands or code on the DIRAC server due to the improper use of `eval()` on untrusted input, leading to full system compromise including data exfiltration and log manipulation.
Decidim JWT Replay Vulnerability Allows Cross-Organization Data Access
2 TTPsA vulnerability, CVE-2026-45414, in Decidim allows an attacker to replay a JSON Web Token (JWT) issued for one organization against another organization's API, permitting an authenticated user from Org 1 to access and retrieve sensitive data, such as GraphQL `participantDetails` and `proposal.answer` mutation paths, from Org 2, effectively bypassing cross-organizational access controls.
CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool
1 TTP 1 CVEA privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.
Multiple Vulnerabilities in Netwrix Password Secure
2 TTPsMultiple vulnerabilities in Netwrix Password Secure allow a remote, authenticated attacker to execute arbitrary program code and disclose sensitive information, potentially leading to full system compromise and data exfiltration.
Checkmk: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities in Checkmk allow an attacker to escalate privileges and bypass security measures, potentially leading to unauthorized access and control within the affected system.
libTIFF Vulnerability Enables Arbitrary Code Execution and Denial of Service
1 TTPA local attacker can exploit a vulnerability in libTIFF to execute arbitrary code and perform a denial of service attack against the system where the library is used.
CVE-2026-15557: Improper Authentication Vulnerability in waooAI waoowaoo
1 rule 2 TTPs 1 CVEA high-severity improper authentication vulnerability, CVE-2026-15557, exists in waooAI waoowaoo up to version 0.4.1, allowing remote attackers to bypass authentication and gain unauthorized access by manipulating the 'x-internal-user-id' request argument in the Internal Task Header Handler component, with a public exploit available.
Multiple Vulnerabilities in Grafana Could Lead to DoS and XSS
2 TTPsAttackers can exploit multiple vulnerabilities in Grafana to conduct Denial of Service attacks or Cross-Site Scripting attacks, potentially leading to service disruption or client-side code execution.
Multiple Vulnerabilities in JetBrains TeamCity
2 TTPsMultiple vulnerabilities in JetBrains TeamCity could allow an attacker to execute arbitrary code, manipulate data, or perform Cross-Site Scripting (XSS) attacks, potentially leading to system compromise or client-side attacks.
Contao Information Disclosure Vulnerability
1 TTPAn authenticated remote attacker can exploit a vulnerability in Contao to disclose sensitive information, gaining unauthorized access to data within the system.
JetBrains IntelliJ IDEA Vulnerability Allows Code Execution
2 TTPsA remote, anonymous attacker can exploit an unspecified vulnerability in JetBrains IntelliJ IDEA to achieve arbitrary code execution, enabling them to execute arbitrary program code on the affected system.
Linux Kernel Vulnerability (xfrm: iptfs) Allows Local DoS and Data Manipulation
2 TTPsA local attacker can exploit a vulnerability in the Linux Kernel's xfrm: iptfs component to potentially trigger a denial-of-service condition or manipulate data on affected systems.
Shibby Tomato Firmware Vulnerability CVE-2026-15545 Leads to Remote Out-of-Bounds Write
2 TTPs 1 CVEA critical out-of-bounds write vulnerability (CVE-2026-15545) exists in Shibby Tomato firmware up to version 1.28.0000, specifically within the `main` function of the `www/apcupsd/tomatodata.cgi` file in the `apcupsd` component, which can be exploited remotely with a publicly available exploit, posing a significant risk to affected network devices.
Wget Vulnerability Allows Security Bypass and Server-Side Request Forgery
1 TTPA local attacker can exploit a vulnerability in wget to bypass existing security measures and perform a Server-Side Request Forgery (SSRF) attack, enabling requests to internal or restricted resources from the local system.
GraphicsMagick PCD Decoder Vulnerability Allows Code Execution
2 TTPsA remote, anonymous attacker can exploit a vulnerability in the GraphicsMagick PCD decoder to potentially execute arbitrary code, corrupt memory, or cause a denial-of-service condition. This flaw could lead to compromise of the system running the affected software or disruption of its availability.
Critical Buffer Overflow in Tenda CH22 Leads to Remote Code Execution (CVE-2026-15543)
1 TTP 1 CVEA critical buffer overflow vulnerability, CVE-2026-15543, exists in the Tenda CH22 1.0.0.1 firmware's `formCertListInfo` function, allowing unauthenticated remote attackers to achieve arbitrary code execution by manipulating the 'Name' argument, with a public exploit available.
CVE-2026-15541: Missing Authorization in will-moss Isaiah Master Websocket Handler
2 TTPs 1 CVEA critical missing authorization vulnerability (CVE-2026-15541) exists in the `Server.Handle` function of the `Master Websocket Handler` component within `will-moss Isaiah` versions up to 1.36.9, allowing a remote attacker to bypass authorization controls by manipulating the `Agent` argument, potentially leading to unauthorized access or privilege escalation.
Public Exploit for Linux Kernel Use-After-Free Vulnerability CVE-2026-43499
1 TTP 2 CVEs 6 IOCsA public exploit has been published for CVE-2026-43499, a Use-After-Free vulnerability in the Linux Kernel, demonstrated to achieve KASLR bypass and potential privilege escalation on Android 15 devices running Linux Kernel 5.15.149, significantly elevating risk for unpatched systems.
Multiple Vulnerabilities in SaltStack Salt
2 TTPsMultiple vulnerabilities in SaltStack Salt allow an attacker to execute arbitrary program code on affected systems and bypass security measures, potentially leading to unauthorized access and control over managed infrastructure.
Django, Debian, and Ubuntu Vulnerability Allows Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Django, Debian Linux, and Ubuntu Linux to initiate a Denial of Service attack, potentially disrupting services and making them unavailable to legitimate users.
CPython Vulnerability Enables Remote Denial of Service
1 TTPA remote, unauthenticated attacker can exploit an unspecified vulnerability within CPython to launch a Denial of Service attack, affecting the CPython interpreter across various operating systems.
CVE-2026-9492 - Improper Access Control in Gigabyte Control Center MBStorage Module
1 TTP 1 CVEAn Improper Access Control vulnerability (CVE-2026-9492) in the MBStorage DRAM lighting control module of Gigabyte Control Center (GCC) allows authenticated local attackers to achieve kernel-level privileges by sending specific IOCTL commands to the `MyPortIO_x64.sys` driver, enabling arbitrary physical memory read/write.
Remote SQL Injection Vulnerability in Jinher OA 1.0 (CVE-2026-15517)
1 rule 2 TTPs 1 CVE 5 IOCsA remote SQL injection vulnerability, CVE-2026-15517, has been discovered in Jinher OA 1.0, allowing unauthenticated attackers to execute arbitrary SQL commands by manipulating the `httpOID` argument in the `/C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx` file, with a public exploit available.
Tencent PC Manager QMUDisk Driver Uncontrolled Search Path Vulnerability (CVE-2026-15515)
1 CVEA high-severity uncontrolled search path vulnerability (CVE-2026-15515) in the `qmudisk64.sys` component of Tencent PC Manager 18.1.30242.301 allows a local attacker to execute arbitrary code with elevated privileges, despite high complexity and difficult exploitability, due to public exploit disclosure.
Comfast Router CVE-2026-15511: Remote OS Command Injection
1 rule 2 TTPs 1 CVEA critical remote OS command injection vulnerability, CVE-2026-15511, affects Comfast CF-WR631AX V3 WiFi routers, allowing unauthenticated remote attackers to execute arbitrary operating system commands by manipulating the 'filename' argument in the FastCGI Backend's file upload function, leading to full device compromise.
CVE-2026-15506: SecureAge CatchPulse Local Privilege Escalation via Heap-based Buffer Overflow
1 TTP 1 CVEA heap-based buffer overflow vulnerability, CVE-2026-15506, in the `saappctl.sys` driver of SecureAge CatchPulse versions up to 10.9.3 allows a local attacker to achieve privilege escalation, and an exploit has been publicly disclosed.
Capgo Email Change Vulnerability Bypasses Authentication (CVE-2026-56308)
2 TTPs 1 CVE 2 IOCsA vulnerability (CVE-2026-56308) in Capgo before version 12.128.2 allows an attacker with an authenticated session to change a user's email address without re-authentication or verification of the existing email, leading to account takeover through recovery mechanisms and multi-factor authentication bypass.
Crawl4AI Credential Exfiltration and Authentication Bypass Vulnerabilities
1 rule 4 TTPs 1 CVEA critical vulnerability, CVE-2026-56259, in Crawl4AI versions prior to 0.8.8 allows attackers to exploit unauthenticated Docker API server endpoints by manipulating the `base_url` and `api_token` parameters, leading to credential exfiltration and authentication bypass.
Capgo Privilege Escalation via Retained Super_Admin Privileges (CVE-2026-56241)
1 TTP 1 CVEA privilege escalation vulnerability, CVE-2026-56241, in Capgo versions prior to 12.128.2 allows demoted super_admin users to retain access to critical RPCs, enabling them to indefinitely enumerate and bulk delete non-compliant bundles across an organization.
CVE-2026-56238 - Capgo Supabase PostgREST Information Disclosure
1 rule 2 TTPs 1 CVEAn information disclosure vulnerability (CVE-2026-56238) in Capgo before 12.128.2's Supabase PostgREST global_stats endpoint allows unauthenticated attackers to retrieve sensitive financial and operational metrics using a public API key.
SQL Injection Vulnerability in sergomanov SmartHomeAdatum Login Component (CVE-2026-15498)
1 rule 2 TTPs 1 CVEA SQL injection vulnerability, identified as CVE-2026-15498, exists in the Login component of sergomanov SmartHomeAdatum, affecting versions up to commit cf495353d81b680675eb8d9aa14a318aa45ce12c. This flaw allows remote attackers to perform SQL injection by manipulating the 'Login' argument in the 'users.php' file.
SonicCloudOrg Sonic-Agent Code Injection Vulnerability (CVE-2026-15497)
1 rule 2 TTPs 1 CVEA critical vulnerability (CVE-2026-15497) exists in SonicCloudOrg's sonic-agent, affecting versions up to 2.7.2. The flaw resides within an unknown function in the `ExchangeController.java` file, specifically within the JWT Authentication Filter component of the `sonic-server-controller`. This vulnerability allows for remote code injection, and public exploits are available. The vendor was notified but has not responded, and the affected products are no longer supported.
Crawl4AI Arbitrary File Write via Docker API Server Endpoints (CVE-2026-56260)
1 rule 3 TTPs 1 CVECrawl4AI versions prior to 0.8.7 are vulnerable to CVE-2026-56260, an arbitrary file write vulnerability in its Docker API server's /screenshot and /pdf endpoints, allowing unauthenticated attackers to supply path traversal or absolute file paths via the output_path parameter to overwrite server files, leading to denial of service or impaired defenses.
Unrestricted File Upload Vulnerability in hcr707305003 shiroiAdmin
1 rule 3 TTPs 1 CVEA remote unrestricted file upload vulnerability (CVE-2026-15488) exists in hcr707305003 shiroiAdmin versions 1.1 and 1.3, allowing attackers to upload arbitrary files by manipulating the 'File' argument in FileController::upload, potentially leading to remote code execution.
Remote Buffer Overflow Vulnerability in TRENDnet TEW-821DAP Access Point
1 CVEA critical buffer overflow vulnerability (CVE-2026-15484) exists in the `sub_41EC14` function within the `/goform/tools_nslookup` component of the TRENDnet TEW-821DAP 1.12B01 wireless access point, which can be exploited remotely due to improper handling of the ssi element, potentially leading to arbitrary code execution on an End-of-Life device.
Trendnet TEW-635BRM Web Service Stack-based Buffer Overflow Vulnerability
2 TTPs 1 CVECVE-2026-15480 describes a stack-based buffer overflow vulnerability in the Trendnet TEW-635BRM router firmware, specifically in the start_httpd function within the /sbin/rc component's Web Service, which can be exploited remotely by manipulating the 'device_name' argument, potentially leading to arbitrary code execution; an exploit is publicly available, but the product is End-of-Life (EOL) since 2011, and the vendor advises users to switch devices.
H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)
2 TTPs 1 CVE 5 IOCsA critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.
CVE-2026-61442: PraisonAI Platform Authorization Bypass
2 TTPs 1 CVEPraisonAI Platform versions before 0.1.9 are vulnerable to an authorization bypass on PATCH routes for projects, issues, and agents, allowing an attacker with a workspace-member role to modify owner-created records, reassign the lead_id to their own user ID, and subsequently delete owner-created projects, bypassing standard permission checks and leading to unauthorized data manipulation and deletion.
PraisonAI Prompt Injection Defense Bypass Vulnerability (CVE-2026-61439)
3 TTPs 1 CVEA prompt injection defense misconfiguration in PraisonAI versions before 4.6.78 allows high-severity threats to bypass blocking mechanisms due to a default block threshold set to CRITICAL severity, enabling attackers to submit instruction overrides or financial manipulation for system prompt extraction and unauthorized tool invocations.
PraisonAI Server-Side Request Forgery via DNS Rebinding and Redirects (CVE-2026-61429)
4 TTPs 1 CVEPraisonAI versions prior to 1.6.78 are vulnerable to server-side request forgery (SSRF) due to an issue in the Crawl4AI/Chromium backend, allowing attackers to bypass existing SSRF validation by employing DNS rebinding and HTTP redirects to access and exfiltrate sensitive internal responses, including canary values.
Insecure Default Configuration in PraisonAI Allows Unauthenticated Access
2 rules 3 TTPs 1 CVEAn insecure default configuration in PraisonAI before version 1.7.3 allows unauthenticated attackers to exploit CVE-2026-61426 by reading sensitive agent instructions and system prompts via the `/api/agents` endpoint and invoking agents without authentication through the `/api/chat` endpoint, leading to unauthorized information disclosure and potential control over AI functionalities.
Capgo API Key Information Disclosure Vulnerability (CVE-2026-56303)
1 rule 1 TTP 1 CVEAn information disclosure vulnerability (CVE-2026-56303) in Capgo versions before 12.128.2 allows unauthenticated attackers to retrieve sensitive API key metadata, including user ID, mode, organization scoping, and expiration details, by exploiting a misconfigured PostgreSQL function via the `/rest/v1/rpc/find_apikey_by_value` endpoint.
CVE-2026-61447 PraisonAI Remote Code Execution Vulnerability via Prompt Injection
1 TTP 1 CVEAttackers can exploit CVE-2026-61447, a critical remote code execution vulnerability in PraisonAI versions before 1.6.78, by using prompt injection to manipulate LLM-generated Python code, leading to arbitrary code execution and exfiltration of environment secrets on the host system.
Vulnerability in Genolve WordPress Plugin Allows Privilege Escalation
1 rule 1 TTP 1 CVEA vulnerability in the Genolve AI image AI video generation plugin for WordPress, affecting versions up to and including 5.0.5, allows authenticated attackers with Contributor-level access to achieve privilege escalation due to a missing capability check in the `genolve_setOpt()` function, enabling them to modify arbitrary WordPress options such as enabling user registration and setting the default role to administrator.
CVE-2026-59869: js-yaml Vulnerability Leading to Quadratic CPU Consumption and DoS
2 TTPs 1 CVEA vulnerability, CVE-2026-59869, in the `js-yaml` library allows attackers to craft malicious YAML merge-key chains, which can lead to quadratic CPU consumption and a Denial of Service condition in applications processing the input.
CVE-2026-59928 Mistune block_parser: Quadratic-Time Parsing Leading to Denial of Service
1 CVECVE-2026-59928 identifies a vulnerability in the Mistune block_parser component where quadratic-time parsing of long lists of repeated reference-link definitions can be exploited by an attacker to cause a denial-of-service condition due to excessive resource consumption.
CVE-2026-14739 DBI for Perl Heap Overflow Vulnerability
1 CVECVE-2026-14739 details a heap overflow vulnerability affecting DBI for Perl versions prior to 1.650, which arises during the preparsing of SQL statements with an excessive number of placeholders, potentially leading to arbitrary code execution or a denial of service.
Out-of-Bound Read Vulnerability in mtr (CVE-2026-14461)
1 CVECVE-2026-14461 identifies an out-of-bound read vulnerability in the mtr network diagnostic tool that could lead to information disclosure or denial of service on Linux and macOS systems.
NATS Server Authorization Bypass Vulnerability (CVE-2026-58252)
2 TTPs 1 CVECVE-2026-58252 identifies an authorization bypass vulnerability in NATS Server, described as a 'Subscribe Authz Bypass via Wildcard-Overlap', which allows unauthorized access or actions by exploiting how wildcard subscriptions are handled.
Setuptools Unicode Normalization Collision Bypass on macOS
1 CVEA vulnerability, CVE-2026-59890, affects the setuptools project, allowing a MANIFEST.in exclusion bypass during source distribution package creation due to Unicode normalization collisions (NFC/NFD) on macOS systems using APFS or HFS+ file systems.
Mistune Markdown Parser Vulnerability CVE-2026-59930 Allows HTML ID Collision
1 CVEA vulnerability, CVE-2026-59930, in the Mistune markdown parser's TableOfContents directive creates predictable HTML heading IDs, enabling an attacker to inject content with colliding IDs for client-side content manipulation.
Perl DBI Out-of-Bounds Read Vulnerability CVE-2026-14740
1 CVECVE-2026-14740 describes an out-of-bounds read vulnerability in DBI versions prior to 1.650 for Perl, occurring during the preparse stage when deleting an initial SQL comment, which can lead to information disclosure or denial of service.
OpenSSH sshd GSSAPI Behavior Vulnerability CVE-2026-59998
1 CVECVE-2026-59998 describes an undocumented security-relevant behavior in sshd, a component of OpenSSH, specifically in versions prior to 10.4, where the GSSAPIStrictAcceptorCheck setting reportedly has no value when the server is operating within a Windows Active Directory environment.
Dahua IPC Vulnerability CVE-2026-29114 Exposes CA Root Certificate
2 rules 3 TTPs 3 CVEsA low-severity certificate-trust vulnerability (CVE-2026-29114) has been identified in select Dahua IPC (IP camera) models with firmware builds before April 15, 2026. A remote attacker can obtain the device's internal CA root certificate, which, if trusted by client workstations, browsers, or middleware, allows the attacker to mint fraudulent X.509 certificates, enabling person-in-the-middle (MITM) attacks against HTTPS or TLS-protected sessions, undermining confidentiality and integrity, with related CVEs for different impacts. Remediation involves upgrading firmware and removing improperly trusted device CAs from client trust stores.
CVE-2026-13378 - Form Vibes WordPress Plugin Vulnerable to Stored Cross-Site Scripting
1 rule 2 TTPs 1 CVE 5 IOCsThe Form Vibes - Database Manager for Forms plugin for WordPress, including all versions up to and including 1.5.2, is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts into pages that execute when a user accesses an injected page.
Local File Inclusion Vulnerability in LA-Studio Element Kit for Elementor Plugin for WordPress
4 TTPs 1 CVEA Local File Inclusion vulnerability exists in the LA-Studio Element Kit for Elementor plugin for WordPress, affecting all versions up to and including 1.6.1, which allows authenticated attackers with contributor-level access or higher to include and execute arbitrary .php files on the server due to improper path traversal handling and an easily bypassed extension check, leading to PHP code execution, access control bypass, and sensitive data exposure.
TSDProxy Internal Authentication Token Vulnerability Leading to Management API Escalation
1 rule 4 TTPs 1 IOCA critical vulnerability in TSDProxy allows its internal per-process authentication token to be unconditionally forwarded to proxied backend services when `identityHeaders` is enabled, enabling an attacker with code execution on a co-located backend to replay the token to the local TSDProxy management API (port 8080) and bypass authentication, leading to full management API control.
Clauster Dashboard Unauthenticated Access Vulnerability
2 TTPs 1 IOCA Clauster instance deployed on a non-loopback address can be accessed unauthenticated, even if password protection is configured, due to auth.enabled defaulting to false. This allows an attacker with network access to gain full control of the dashboard, including listing projects, spawning remote-control bridges, editing files, reading logs, and cloning repositories, ultimately leading to remote code execution in project directories.
RustDesk Authorization Bypass via Session Scope Enforcement Failure (CVE-2026-57850)
1 TTP 1 CVEAn authorization vulnerability exists in RustDesk before version 1.4.9 where the server-side fails to properly enforce connection scope for authenticated peers, allowing an attacker, having been granted a limited session type, to inject control messages typically reserved for a full Remote session and gain unauthorized observation and control over the host.
SafeInstall CLI Guard Bypass Vulnerability Allows Unauthorized Package Execution
2 TTPsA vulnerability in SafeInstall CLI through version 0.10.1 allows attackers to bypass its agent guard and execute unauthorized package installation or registry-provided scaffolding commands, potentially compromising developer environments.
CVE-2026-5801 - SQL Injection Leading to Command Line Execution in Semtek SEM-PMP
1 rule 2 TTPs 1 CVE 1 IOCAn SQL injection vulnerability, tracked as CVE-2026-5801, has been identified in Semtek Informatics Software Consulting Trade Ltd. Co. SEM-PMP versions through 23042026, allowing unauthenticated attackers to achieve command line execution on the underlying system with a critical CVSS v3.1 score of 9.8.
SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding
1 rule 3 TTPs 2 CVEs 1 IOCAn incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.
Excelize Unbounded Row Index Allocation Denial-of-Service Vulnerability
1 TTPAn unbounded row index allocation vulnerability (CWE-770) exists in the `checkSheet()` function of the `github.com/xuri/excelize/v2` library, allowing an unauthenticated attacker to craft a malicious XLSX file with a specially crafted row index value that triggers an out-of-memory error or runtime panic, leading to a denial-of-service condition in Go applications processing untrusted spreadsheets.
Authorizer Unvalidated Redirect Vulnerability Allows OAuth2 Token Theft
1 rule 2 TTPs 1 IOCAn unvalidated redirect vulnerability, CVE-2026-54072, in the Authorizer `/authorize` endpoint allows an unauthenticated attacker to steal OAuth2 access, ID, and refresh tokens by crafting a malicious URL with an attacker-controlled `redirect_uri` to which the application redirects a logged-in user, exposing their tokens.
Authorization Bypass Vulnerability in Teracity TeraMIS (CVE-2026-6212)
1 TTP 1 CVEA critical authorization bypass vulnerability (CVE-2026-6212) in Teracity Software Technologies Inc. TeraMIS, affecting versions V03.26.01.14 through 30.04.2026, allows an attacker to achieve Privilege Abuse by manipulating user-controlled keys.
Krayin CRM Insecure Direct Object Reference Vulnerability (CVE-2026-61460)
3 TTPs 1 CVEAn Insecure Direct Object Reference (IDOR) vulnerability, CVE-2026-61460, in Krayin CRM through version 2.2.3 allows authenticated users to modify, update, or delete records owned by other users by exploiting missing record-level ownership validation in various controllers, leading to unauthorized data manipulation.
HestiaCP Authenticated OS Command Injection via DNS Record Types (CVE-2025-30007)
2 TTPs 1 CVEAn authenticated OS command injection vulnerability, CVE-2025-30007, in HestiaCP before version 1.9.5 allows low-privilege users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types, leading to full root code execution on the underlying host.
CVE-2026-61459 - Argument Injection in MCP Server Kubernetes Structured Tools Leads to Cluster Compromise
4 TTPs 1 CVEAn argument injection vulnerability, CVE-2026-61459, in MCP Server Kubernetes versions prior to 3.9.0 within structured tools like kubectl_get, kubectl_describe, and kubectl_delete allows attackers to bypass the assertNoDangerousFlags security check by injecting parameters with leading dashes to redirect kubectl commands to an attacker-controlled API server, enabling the exfiltration of the operator's bearer token and leading to full Kubernetes cluster compromise.
Critical SQL Injection Vulnerability in Adam Retail Automation MobilMen 20T
2 TTPs 1 CVEA critical SQL injection vulnerability, tracked as CVE-2026-2397 with a CVSS v3.1 score of 9.8, affects Adam Retail Automation Ltd.'s MobilMen 20T software, allowing remote attackers to execute arbitrary SQL commands due to improper neutralization of special elements in input, potentially leading to unauthorized data access or system compromise.
CVE-2026-2398: Authorization Bypass Leads to Privilege Escalation in Adam Retail Automation MobilMen 20T
1 TTP 1 CVEAn authorization bypass vulnerability, identified as CVE-2026-2398, exists in Adam Retail Automation Ltd.'s MobilMen 20T software, affecting versions from v3 through 10072026, allowing an attacker to achieve privilege escalation by manipulating user-controlled keys.
CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 CVEA critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.
Arbitrary XML Schema Definition Processing in guardrails-detectors Leads to SSRF and Local File Read
3 TTPs 1 CVEA flaw in the 'file_type' content detector of 'guardrails-detectors' allows a remote attacker to provide an arbitrary XML Schema Definition (XSD) string, leading to server-side request forgery (SSRF) and local file reads, potentially exposing sensitive information such as cloud provider credentials or granting access to internal network services.
PraisonAI praisonaiagents Unsafe Dynamic Module Loading Vulnerability (CVE-2026-61437)
2 TTPs 1 CVEA critical vulnerability, CVE-2026-61437, in PraisonAI's `praisonaiagents` pip package before version 1.6.78 allows an attacker to achieve remote code execution by exploiting an unsafe dynamic module loading mechanism when a malicious workflow file and an adjacent `tools.py` are executed, bypassing sandboxing and leading to arbitrary Python code execution with workflow runner privileges.
CVE-2026-61434: PraisonAI Shell Command Allowlist Bypass
1 rule 3 TTPs 1 CVE 2 IOCsPraisonAI versions prior to 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to use find's built-in -exec, -execdir, and -delete actions to execute restricted commands, read or delete files, or run non-allowlisted binaries, bypassing existing shell metacharacter filters, which can lead to arbitrary command execution and impact system integrity.
Capgo Information Disclosure in get_orgs_v7 RPC Function (CVE-2026-56279)
1 rule 4 TTPs 1 CVECapgo versions prior to 12.128.2 are vulnerable to an information disclosure flaw in the `get_orgs_v7(userid)` RPC function, allowing unauthenticated attackers to retrieve sensitive foreign user and organization data by supplying arbitrary user UUIDs.
Capacitor Updater Vulnerability Allows Malicious Update Installation via Private Key Distribution
2 TTPs 1 CVEA vulnerability, CVE-2026-56254, in @capgo/capacitor-updater (Cap-go/capgo) before version 12.128.2 allows an attacker to create and distribute validly signed malicious application updates by leveraging the improper distribution of a private key to each client device, enabling man-in-the-middle or server compromise scenarios.
FlaskBB Authorization Bypass Vulnerability (CVE-2026-22659)
2 TTPs 1 CVEAn authorization bypass vulnerability exists in FlaskBB through version 2.2.0, allowing authenticated moderators to perform unauthorized administrative actions such as locking, unlocking, deleting, or hiding topics in forums they do not control. This is achieved by crafting batch requests that include a low-ID topic from a permitted forum, which bypasses permission checks applied only to the first item, and then executing actions on topics from unmoderated forums.
CPython Denial-of-Service Vulnerability
1 TTP 1 CVE 1 IOCA remote denial-of-service vulnerability, CVE-2026-15308, has been discovered in CPython, allowing an attacker to cause service disruption to affected systems not running the latest security patch.
Security Risks Associated with AI Coding Tools, Including GhostApproval Vulnerability
3 TTPsThe adoption of AI coding tools introduces significant security risks, such as the generation of vulnerable code with OWASP Top 10 flaws, the inadvertent leakage of sensitive secrets and hardcoded credentials, and supply chain compromise via 'slopsquatting,' alongside specific vulnerabilities like 'GhostApproval' which allows remote code execution on developer machines.
Critical Blind SSRF Vulnerability in guardrails-detectors (CVE-2026-15378)
6 TTPs 1 CVEA critical blind Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-15378, exists in the `guardrails-detectors` component, allowing a remote attacker to exploit specially crafted XML Schema Definition (XSD) strings to gain unauthorized access to sensitive information from cloud metadata services, Kubernetes API, internal MinIO, and facilitate local file reads of service account tokens and pod secrets.
CVE-2026-59818 etcd: gRPC client listener does not enforce certificate revocation
1 CVEThe etcd gRPC client listener is affected by CVE-2026-59818, a vulnerability where it fails to properly enforce Certificate Revocation Lists (CRLs) when the `--client-crl-file` flag is used, potentially allowing clients with revoked certificates to bypass authentication and gain unauthorized access to etcd instances.
[UPDATE] Python: Schwachstelle ermöglicht Codeausführung
2 TTPsA high-severity vulnerability in Python allows a remote, unauthenticated attacker to execute arbitrary program code, potentially leading to full system compromise on machines running vulnerable Python installations.
Python Privilege Escalation Vulnerability
1 TTPA local attacker can exploit an unspecified vulnerability within Python to elevate their privileges on the affected system.
Multiple Python Vulnerabilities Allow Code Execution and DoS
2 TTPsMultiple vulnerabilities in Python allow an attacker to execute arbitrary code or cause a Denial of Service condition, potentially leading to system compromise or service disruption.
Python: Vulnerability Enables File Manipulation
1 TTPAn authenticated remote attacker can exploit a vulnerability in Python to manipulate files, which could lead to unauthorized modification of data or disruption of system integrity across Windows, Linux, and macOS environments.
Splunk Enterprise: Multiple Vulnerabilities
6 TTPsAttackers can exploit multiple, unspecified vulnerabilities in Splunk Enterprise to bypass security measures, disclose sensitive information, manipulate data, execute arbitrary code, and cause denial-of-service conditions, potentially leading to other unspecified impacts.
CVE-2026-15288: SureForms WordPress Plugin Payment Manipulation Vulnerability
1 rule 1 TTP 1 CVEThe SureForms - Drag and Drop Form Builder for WordPress plugin (versions up to and including 2.2.1) is vulnerable to improper input validation (CVE-2026-15288), allowing unauthenticated attackers to modify payment amounts in user-controlled POST data when submitting Stripe payment forms, enabling them to purchase products or services at arbitrarily reduced prices.
CVE-2026-15300: Critical SQL Injection in GEO my WP WordPress Plugin
1 rule 2 TTPs 1 CVEA critical SQL Injection vulnerability, identified as CVE-2026-15300, was found in the GEO my WP plugin for WordPress, affecting versions up to and including 4.5.4, allowing attackers to inject SQL payloads through the 'distance', 'lat', and 'lng' parameters, leading to potential data compromise or denial of service.
CVE-2026-15282: WordPress Instant Appointment Plugin Arbitrary File Upload to RCE
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-15282, an arbitrary file upload vulnerability due to missing file type validation in the `insapp_upload_image_as_attachment` function of the WordPress Instant Appointment plugin up to version 1.2, to upload malicious files and achieve remote code execution on the affected server.
CVE-2026-15070: WordPress Salon Booking Plugin CSRF to RCE
1 rule 3 TTPsThe Salon Booking System - Free Version plugin for WordPress (versions up to and including 10.30.32) is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability stemming from a lack of nonce validation in the setCustomText function, allowing unauthenticated attackers to inject arbitrary PHP code into the web-accessible translate-constants.php file, which can lead to remote code execution (RCE) on the server if an administrator is tricked into clicking a crafted link.
CVE-2026-15319: Remote Improper Access Control in Sipeed PicoClaw
1 CVEA remote improper access control vulnerability (CVE-2026-15319) exists in the IPAllowlist function of the Launcher component in Sipeed PicoClaw versions up to and including 0.2.9, allowing unauthorized remote access due to publicly disclosed exploit.
Tesla Elixir HTTP Client Header Leak via Case-Sensitive Redirect Filtering (CVE-2026-48595)
2 TTPs 1 CVEA vulnerability in the `Tesla.Middleware.FollowRedirects` component of the `tesla` Elixir HTTP client library allows `Authorization` headers to be leaked during cross-origin redirects due to a case-sensitive comparison, enabling an attacker controlling a redirect destination to receive bearer tokens or other credentials from applications using `tesla` versions 0.6.0 through 1.18.2.
Tesla HTTP Client Library Vulnerable to Atom Exhaustion Leading to Denial of Service (CVE-2026-48597)
1 TTP 1 CVEA high-severity denial-of-service vulnerability (CVE-2026-48597) in the `Tesla.Adapter.Mint` component of the Elixir Tesla HTTP client library, affecting versions 1.3.0 through 1.18.2, allows an unauthenticated attacker to crash the underlying BEAM VM by supplying untrusted URL schemes, leading to atom exhaustion.
Mistune Markdown Parser Vulnerable to CPU Exhaustion DoS (CVE-2026-49851)
1 TTP 1 CVEThe Mistune Python Markdown parser is vulnerable to a CPU exhaustion Denial of Service (DoS) attack, identified as CVE-2026-49851, due to a superlinear (O(n²)) parsing behavior in the `parse_link_text` function when processing specially crafted input containing repeated square brackets, allowing an attacker to significantly degrade application performance with a small payload.
Mint HTTP/2 Client Vulnerable to Unbounded CONTINUATION Frame Accumulation (CVE-2026-49754)
1 TTP 1 CVEA malicious or compromised HTTP/2 server can exploit CVE-2026-49754 in the Elixir Mint HTTP/2 client by sending an endless chain of CONTINUATION frames without an END_HEADERS flag, leading to unbounded memory accumulation, process exhaustion, and remote unauthenticated denial-of-service.
Mint HTTP/2 Client Unbounded Stream Map Growth Denial-of-Service (CVE-2026-48862)
1 TTP 1 CVEA malicious or compromised HTTP/2 server can exploit CVE-2026-48862 in Mint HTTP/2 clients by flooding them with PUSH_PROMISE frames and withholding corresponding HEADERS, leading to unbounded memory consumption and denial-of-service.
CVE-2026-58143 - Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows una...
1 rule 3 TTPs 1 CVEA Cross-Site Request Forgery (CSRF) vulnerability in Cotonti Siena versions 0.9.26 and earlier allows unauthenticated attackers to modify administrator configuration by tricking a logged-in administrator into submitting a forged POST request, enabling the upload and execution of arbitrary PHP files leading to remote code execution.
CVE-2026-57028: Juniper Junos OS Evolved License Exhaustion via Improper Communication Channel Restriction
2 TTPs 1 CVEA vulnerability, CVE-2026-57028, in Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to gain unauthorized access to internal license management processes via an exposed internal port, leading to license exhaustion and ultimately a denial-of-service condition.
CVE-2026-57026 - Improper Validation of SIP Input in Juniper Junos OS Leads to DoS
1 TTP 1 CVEAn unauthenticated, network-based attacker can exploit CVE-2026-57026, an improper input validation vulnerability, in the SIP plugin of Juniper Networks Junos OS. If the SIP ALG is enabled on affected MX Series with SPC3 or SRX Series devices, processing a malformed SIP invite packet will cause the flow processing daemon (flowd) to crash and restart, leading to a complete denial of service until the system recovers.
CVE-2026-57023: Juniper Junos OS TCP Proxy Denial of Service
1 TTP 1 CVEAn Improper Validation of Specified Quantity in Input vulnerability (CVE-2026-57023) in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3 and SRX Series allows an unauthenticated, network-based attacker to cause a complete Denial of Service (DoS) by sending a specifically malformed TCP header packet, crashing the flow processing daemon (flowd) until automated recovery.
Laravel-Backup-Restore OS Command Injection (CVE-2026-53932)
2 rules 2 TTPsA critical OS command injection vulnerability, tracked as CVE-2026-53932, exists in the wnx/laravel-backup-restore package (versions <= 1.9.3), allowing an attacker to execute arbitrary shell commands on the hosting system by crafting a malicious backup archive with shell metacharacters in a database dump filename, leading to application compromise, data tampering, and potential lateral movement.
YesWiki Public Bazar API Unauthenticated SQL Injection (CVE-2026-52770)
1 rule 4 TTPsAn unauthenticated attacker can exploit CVE-2026-52770, an SQL injection vulnerability in YesWiki's public Bazar entry-listing APIs, by manipulating numeric `query` or `queries` GET parameters, to use the application as a boolean oracle for inferring sensitive database contents like user accounts and password hashes.
YesWiki Second-Order SQL Injection via Unescaped Page Tag in API Controller
1 rule 4 TTPsA critical second-order SQL injection vulnerability (GHSA-8f2v-2qhj-gfwg) in YesWiki versions up to 4.6.5 allows a low-privilege authenticated attacker to execute arbitrary SQL commands via an unescaped page tag in the `ApiController::deletePage()` API, leading to time-based blind data exfiltration.
YesWiki PHP Object Injection Vulnerability (CVE-2026-52777)
1 rule 4 TTPsAn authenticated PHP Object Injection vulnerability (CVE-2026-52777) in YesWiki's `BazarImportAction`, specifically within the `unserialize` function, allows remote code execution (RCE) on the YesWiki server when an authenticated administrator's browser is targeted via a cross-site request forgery (CSRF) attack.
Active Exploitation of CVE-2026-1207 in Django Framework
1 CVEA critical vulnerability, CVE-2026-1207, affecting Django versions prior to 4.2.28, 5.2.11, and 6.0.2, is actively being exploited, posing a significant risk of web server compromise and data exfiltration to organizations using the affected framework.
UsersWP Plugin Arbitrary File Deletion (CVE-2026-13492)
1 rule 3 TTPs 1 CVEThe UsersWP plugin for WordPress contains an Arbitrary File Deletion vulnerability, CVE-2026-13492, in versions up to and including 1.2.65, allowing an authenticated attacker with Subscriber-level access or higher to exploit insufficient validation in file-field values combined with an AJAX handler that lacks proper path canonicalization to delete arbitrary files on the server, including critical files like `wp-config.php`, leading to system impact.
FreePBX API and Backup Modules Vulnerabilities Allowing Authenticated RCE and SSH Key Injection
2 TTPsFreePBX has released security advisories to address critical vulnerabilities in its API and Backup modules, affecting FreePBX API (versions prior to 17.0.9) and FreePBX Backup (versions prior to 17.0.11), which include authenticated command injection and arbitrary SSH key injection leading to remote code execution and unauthorized access.
CVE-2026-58459 - gpsd gpsprof Command Injection
2 rules 1 TTP 1 CVEA command injection vulnerability, CVE-2026-58459, exists in the gpsprof utility of gpsd through version 3.27.5, allowing an attacker to exploit this by controlling the GPS device subtype value and embedding backtick payloads within the gnuplot plot title, which leads to arbitrary shell command execution as the user running gnuplot when a victim renders a generated plot via the gpsprof and gnuplot workflow due to improper escaping.
CVE-2026-15190: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 3 TTPs 1 CVE 3 IOCsA critical SQL injection vulnerability (CVE-2026-15190) exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing unauthenticated remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument on the `/login.php` page, with a public exploit now available.
CVE-2026-11404: Cesanta Mongoose TLS Out-of-Bounds Read Leading to Denial of Service
1 TTP 1 CVECesanta Mongoose before version 7.22 contains an out-of-bounds read vulnerability (CVE-2026-11404) in its built-in TLS server function, `mg_tls_server_recv_hello()`, allowing a remote, unauthenticated attacker to send a specially crafted TLS ClientHello message with an oversized session ID length, leading to a service crash and denial of service for HTTPS, MQTTS, or WSS services.
Schneider Electric Easergy MiCOM Px40 Series Information Disclosure via Hard-coded Credentials (CVE-2026-4832)
2 TTPs 1 CVESchneider Electric Easergy MiCOM Px40 Series products are vulnerable to CVE-2026-4832, a hard-coded credentials flaw (CWE-798) that allows unauthenticated attackers to interrogate the SNMP port and expose basic device identification information from critical manufacturing, energy, and transportation systems assets globally.
OpenPLC v3 Arbitrary File Write Leads to Native Code Execution (CVE-2026-14480)
3 TTPsAn authenticated arbitrary file write vulnerability (CVE-2026-14480) in OpenPLC v3's legacy web UI program-upload workflow allows attackers to write arbitrary files, escalating to arbitrary native code execution as the OpenPLC runtime user when an operator triggers program compilation.
Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown
5 TTPs 5 CVEsMultiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.
CVE-2026-60109 - Zeek Kerberos Protocol Analyzer Null Pointer Dereference
1 TTP 1 CVEA null pointer dereference vulnerability (CVE-2026-60109) exists in Zeek's Kerberos protocol analyzer before version 8.0.9, allowing unauthenticated remote attackers to crash a Zeek sensor by sending a specially crafted KRB_ERROR message with error-code 25 and specific PA-DATA elements, leading to a denial-of-service condition.
CVE-2026-60108 - Zeek FTP Analyzer Uncontrolled Memory Consumption leading to DoS
1 TTP 1 CVEAn uncontrolled memory consumption vulnerability in the Zeek FTP analyzer, versions prior to 8.0.9, allows unauthenticated remote attackers to cause process termination and denial of service of the Zeek sensor. This occurs when a crafted FTP control session with AUTH GSSAPI and a large ADAT control line exploits the NVT_Analyzer component's lack of a maximum line length check, leading to an unbounded internal buffer during base64 decoding.
Multiple Vulnerabilities Discovered in GitLab CE/EE
1 TTP 5 CVEsMultiple vulnerabilities have been discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) across versions 19.0.x, 19.1.x, and 18.11.x, allowing an attacker to compromise data confidentiality, inject remote code via Cross-Site Scripting (XSS) (CVE-2026-11827), and bypass security policies (CVE-2026-13320).
Multiple Vulnerabilities Discovered in Wireshark Leading to DoS and Data Confidentiality Compromise
2 TTPs 5 CVEsMultiple vulnerabilities (CVE-2026-15163 through CVE-2026-15174) have been discovered in Wireshark, impacting versions 4.6.x prior to 4.6.7 and versions prior to 4.4.17, which could allow a remote attacker to cause a denial of service and compromise data confidentiality.
Multiple Security Policy Bypass Vulnerabilities in Traefik Edge Router
3 IOCsMultiple vulnerabilities have been discovered in Traefik, affecting versions 3.6.x prior to 3.6.23, 3.7.x prior to 3.7.7, and versions prior to 2.11.52, which allow an attacker to bypass security policies, potentially leading to unauthorized access or actions.
CVE-2026-4256 - PEAKUP PassGate LDAP Injection Vulnerability
4 TTPs 1 CVEA high-severity LDAP injection vulnerability, CVE-2026-4256, exists in PEAKUP Technology Inc.'s PassGate product through version 30042026, allowing an unauthenticated attacker to manipulate LDAP queries, potentially leading to high confidentiality impact and low integrity impact.
Ruby CSS Parser Vulnerable to SSRF and Local File Disclosure via `read_remote_file`
4 TTPsThe `css_parser` library, specifically in versions up to and including 2.2.0, is vulnerable to Server-Side Request Forgery (SSRF) and local file disclosure through improper URI validation in the `CssParser::Parser#read_remote_file` method, allowing attackers to access internal network resources or read local files when processing attacker-controlled CSS.
CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS
2 TTPs 1 CVEA stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.
CVE-2026-59691: GStreamer rfbsrc Heap Buffer Overflow Leads to DoS
1 TTP 1 CVEA heap buffer overflow vulnerability (CVE-2026-59691) exists in GStreamer's rfbsrc plugin, allowing a malicious RFB/VNC server to trigger an out-of-bounds heap write in connecting clients, leading to denial of service and potential memory corruption.
CVE-2026-4275 - The Divi Torque Lite - Divi Theme, Divi Builder & Extra Theme plugin for WordPress is vulnerable to CSRF
1 rule 1 TTP 1 CVEThe Divi Torque Lite plugin for WordPress, in versions up to 4.2.3, is vulnerable to Cross-Site Request Forgery (CVE-2026-4275), allowing an unauthenticated attacker to exploit inadequate nonce verification on the /install_plugin and /activate_plugin REST API endpoints to install arbitrary WordPress plugins, potentially leading to remote code execution or further system compromise.
CVE-2026-14372 - The Bit Form WordPress Plugin Arbitrary File Deletion
3 TTPs 1 CVEThe Bit Form WordPress plugin (versions up to 3.1.1) is vulnerable to arbitrary file deletion due to insufficient file path validation, allowing authenticated attackers with subscriber-level access to delete critical server files like wp-config.php, potentially leading to remote code execution.
rclone: Multiple Vulnerabilities
5 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in rclone to gain unauthorized capabilities, allowing them to read and write arbitrary files on the system, disclose sensitive information, and bypass existing security mechanisms, potentially leading to data compromise or system integrity issues.
GitLab: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in GitLab allow a remote, authenticated attacker to execute arbitrary code, perform Cross-Site Scripting (XSS), manipulate data, or disclose sensitive information.
CVE-2026-1989: Authorization Bypass in PAVO Pay through User-Controlled Key
3 TTPs 1 CVECVE-2026-1989 describes a high-severity authorization bypass vulnerability affecting PAVO Financial Technology Solutions Inc.'s PAVO Pay, allowing attackers to exploit trusted identifiers via a user-controlled key to gain unauthorized access or escalate privileges within the system.
CVE-2026-15158: Blocksy Companion Plugin Arbitrary File Upload Leading to RCE
2 TTPs 1 CVEThe Blocksy Companion plugin for WordPress, specifically the premium version (blocksy-companion-pro) with the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active, is vulnerable to Arbitrary File Upload (CVE-2026-15158). This flaw, present in versions up to and including 2.1.46, arises from improper file type validation within the `save_attachments` function, allowing double-extension files like `shell.woff2.php` to bypass MIME checks, which unauthenticated attackers can exploit to upload executable files, leading to remote code execution.
MailPit: Multiple Vulnerabilities Lead to Denial of Service
1 TTPMultiple vulnerabilities in MailPit allow an attacker to perform a Denial of Service attack against the application, leading to disruption of service for users.
Juniper JUNOS and JUNOS Evolved: Multiple Critical Vulnerabilities
2 TTPsMultiple vulnerabilities exist in Juniper JUNOS, JUNOS Evolved, and various Juniper network device series (EX, MX, QFX, SRX), allowing an attacker to achieve denial of service, disclose sensitive information, execute arbitrary code, or trigger undefined system behavior.
IBM Operational Decision Manager: Multiple Vulnerabilities Reported
4 TTPsMultiple critical vulnerabilities in IBM Operational Decision Manager allow an attacker to achieve arbitrary code execution, elevate privileges, perform denial of service attacks, disclose information, manipulate files, and bypass security measures.
Wazuh Denial of Service Vulnerability
1 TTPA vulnerability in Wazuh allows a remote, authenticated attacker to perform a denial of service attack, which could disrupt the availability of the Wazuh platform.
Multiple Vulnerabilities in Red Hat Enterprise Linux Components libsolv and aardvark-dns
3 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux components libsolv and aardvark-dns could allow an attacker to perform a Denial of Service attack, manipulate data, or disclose confidential information.
QEMU and libvirt: Multiple Vulnerabilities
1 TTPMultiple vulnerabilities exist in QEMU and libvirt, which can be exploited by a local attacker to disclose sensitive information and bypass security mechanisms, potentially leading to privilege escalation.
Red Hat Enterprise Linux: Golang Component Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Golang components within Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a Denial of Service attack, leading to service disruption.
CVE-2026-8848: Popup Maker WordPress Plugin Authorization Bypass Leading to RCE
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability, CVE-2026-8848, exists in the Popup Maker WordPress plugin versions up to and including 1.22.0, allowing authenticated attackers with editor-level access or higher to install and activate arbitrary plugins from a controlled URL, which leads to remote code execution, provided a valid Popup Maker Pro license is active and the Pro version is not yet installed.
CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader
1 CVECVE-2026-14191 describes an out-of-bounds heap write vulnerability in WinRAR and UnRAR when processing RAR5 recovery volumes (.rev), allowing an unauthenticated attacker to achieve remote code execution on a victim's system by tricking a user into opening a specially crafted archive.
CVE-2026-55999 xorg-server / xwayland glamor font atlas Heap Buffer Overflow
1 CVEA heap buffer overflow vulnerability, identified as CVE-2026-55999, has been discovered in the xorg-server and xwayland components, specifically within the glamor font atlas functionality, affecting systems using these display servers and potentially leading to arbitrary code execution or denial of service.
CVE-2026-38968: ntopng Predictable Session Identifier Vulnerability Leading to Session Hijacking
1 CVECVE-2026-38968 affects ntopng versions up to 6.6, enabling session hijacking through predictable session identifiers generated with weak time-seeded pseudo-randomness in `src/HTTPserver.cpp`, allowing attackers to gain unauthorized access to legitimate user sessions.
CVE-2026-59999: OpenSSH sshd Configuration Bypass via PermitTunnel
1 CVEA logic error in OpenSSH's sshd daemon before version 10.4 allowed the PermitTunnel configuration to take precedence over DisableForwarding=yes, leading to unintended SSH tunnel establishment and potential unauthorized network access through the tunnel feature.
CVE-2026-59995: OpenSSH SFTP Arbitrary File Placement Vulnerability
1 CVECVE-2026-59995 describes a vulnerability in the OpenSSH sftp client, specifically versions before 10.4, that allows an attacker to control the location of downloaded files when a user executes 'sftp server:/path .' against an attacker-controlled server, potentially leading to arbitrary file placement and subsequent system compromise.
CVE-2026-59996: OpenSSH scp File Placement Vulnerability
1 CVECVE-2026-59996 details a vulnerability in OpenSSH's `scp` utility, allowing a remote attacker to cause a copied file to be placed in a parent directory of the intended destination during a remote-to-remote transfer, potentially leading to unintended file system modification.
OpenSSH internal-sftp Vulnerability (CVE-2026-59997) Allows Security Property Bypass
1 CVECVE-2026-59997 describes a vulnerability in the internal-sftp component of OpenSSH's sshd service, affecting versions before 10.4, where the service only processes the first nine command-line arguments, potentially leading to a bypass of security controls or unintended configuration.
CVE-2026-53359: KVM x86 Use-After-Free in Shadow Paging
1 CVE 6 IOCsCVE-2026-53359 is a high-severity use-after-free vulnerability affecting the KVM virtualization component on x86 architectures within the Linux kernel, stemming from an unexpected role in shadow paging, which could lead to host system compromise.
Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification
1 TTPMultiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.
CVE-2026-47241: Net::IMAP Denial of Service Vulnerability
1 CVEA Denial of Service vulnerability, identified as CVE-2026-47241, exists in the Net::IMAP library due to incomplete raw argument validation, potentially allowing an attacker to cause an application crash or unresponsiveness.
Divi Form Builder Missing Authorization Vulnerability (CVE-2026-5523) Leads to Account Takeover
3 TTPs 1 CVEThe Divi Form Builder plugin for WordPress versions up to 5.1.8 is vulnerable to Missing Authorization, allowing authenticated attackers with subscriber-level access to change the email and password of any user, including administrators, by exploiting improper authorization checks in the update_user() and handle_register_submission() functions, enabling complete account takeover.
CVE-2026-15137: Remote SQL Injection in code-projects Interview Management System
1 rule 2 TTPs 1 CVE 6 IOCsA critical SQL injection vulnerability (CVE-2026-15137) has been identified in code-projects Interview Management System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in the '/inc/classes/View.php' file, leading to arbitrary SQL query execution and potential data compromise; a public exploit is available.
CVE-2026-60105: Monsta FTP SSRF Vulnerability Leading to Credential Disclosure
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-60105, a Server-Side Request Forgery vulnerability in Monsta FTP before 2.14.5, by leveraging an incomplete IP blocklist check with IPv4-mapped IPv6 addresses to force the server to issue HTTP requests to internal services and write responses to an attacker-controlled FTP destination, potentially enabling retrieval of cloud instance metadata credentials.
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
2 rules 5 TTPs 1 IOCJoro's default proxy mode (versions ≤ v1.1.0) is vulnerable to unauthenticated remote code execution (CVE-2026-53649) via a local API on `127.0.0.1:9090` that allows cross-origin JavaScript to upload a malicious native plugin and trigger a system restart, leading to RCE as the operator's user from a single page visit.
DSpace RCE via Velocity Templates (CVE-2026-49832)
1 TTPDSpace versions 8.0 through 8.3, 9.0 through 9.2, and 10.0-rc1 are vulnerable to Remote Code Execution (RCE) via Velocity Templates used for COAR Notify/LDN messages, allowing an attacker with DSpace administrator credentials to execute direct Java code using reflection, a high-impact vulnerability that can be chained with a related path traversal attack (GHSA-9qm4-rh6w-pq5x).
`lxml_html_clean` `javascript:` URL Bypass via `xlink:href` (CVE-2026-49825)
2 TTPsThe `lxml_html_clean.Cleaner` Python library, and the `lxml.html.clean` module in `lxml`, fails to strip `javascript:`, `vbscript:`, and `data:` URLs from namespaced attributes like `xlink:href` when configured with `safe_attrs_only=False`. This vulnerability, identified as CVE-2026-49825, is a form of stored Cross-Site Scripting (XSS) that allows malicious JavaScript to bypass sanitization, enabling client-side code execution if an application processes and renders untrusted HTML containing such payloads.
Zalando Skipper OPA Policy Bypass via Chunked Encoding
1 rule 1 TTPA critical vulnerability in `zalando/skipper`'s OpenPolicyAgent integration, tracked as GHSA-659f-rgp5-w4wf, allows attackers to bypass `opaAuthorizeRequestWithBody` policies using HTTP/1.1 `Transfer-Encoding: chunked` or HTTP/2 requests lacking a `content-length` pseudo-header, leading to unauthorized access to upstream services with uninspected payloads.
CVE-2026-60104 - Bitwarden Server Vault Key Disclosure and Account Takeover
7 TTPs 1 CVEA low-privileged Bitwarden organization member can exploit CVE-2026-60104 in Bitwarden Server versions prior to 2026.6.0, which allows an attacker to obtain another user's vault key and access token by creating a Trusted Device Encryption authentication request bound to an attacker-controlled public key, leading to account takeover.
CVE-2026-59803: rpcx Denial-of-Service Vulnerability
1 TTP 1 CVEA denial-of-service vulnerability (CVE-2026-59803) in rpcx through version 1.9.3 allows an unauthenticated attacker to trigger out-of-memory conditions and service unavailability by sending a small, compressed message that expands to gigabytes of memory during decompression.
CVE-2026-59802 - PasswordPusher Data URI Scheme Vulnerability Leading to Client-Side JavaScript Execution
3 TTPs 1 CVEPasswordPusher versions prior to 2.8.1 contain a client-side vulnerability (CVE-2026-59802) due to insufficient validation of URL push payloads, allowing attackers to embed malicious data URI schemes that execute arbitrary JavaScript in victims' browsers when clicked, enabling phishing and credential theft under the trusted PasswordPusher domain.
Progress MOVEit Transfer Critical Security Advisory (AV26-678)
3 CVEsProgress Software has issued a critical security advisory (AV26-678) detailing multiple vulnerabilities, including CVE-2026-10699, CVE-2026-10698, and CVE-2026-11903, affecting various versions of its MOVEit Transfer product, necessitating immediate patching to prevent potential exploitation.
Juniper Networks Releases Security Advisories for Multiple Vulnerabilities, Including Heap Buffer Overflow and Memory Leak
2 TTPs 1 CVEJuniper Networks has released security advisories to address multiple vulnerabilities across several products, including Juniper cRPD, CTPView, Network Director, Junos OS, Junos OS Evolved, Junos OS on MX Series with SPC3 and SRX Series, and Junos Space, with key vulnerabilities like a heap buffer overflow (CVE-2020-7450) and a memory leak (CVE-2026-33799) potentially leading to arbitrary code execution or denial of service.
CVE-2026-59261 - OpenClaw Credential Exposure via Workspace Dotenv Files
1 TTP 1 CVEA critical vulnerability, CVE-2026-59261, in OpenClaw before version 2026.5.28, allows attackers with lower-trust access to configured input paths to expose sensitive provider credentials by leveraging workspace dotenv files that override legitimate configurations, leading to unauthorized access to sensitive data.
CVE-2026-29009 - U-Boot Buffer Overflow in nfs_readlink_reply()
1 CVEA buffer overflow vulnerability exists in the nfs_readlink_reply() function of U-Boot versions up to 2026.04-rc3 when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to exploit it by sending multiple relative symlink targets, each approximately 1100 bytes long, to overflow the 2048-byte nfs_path_buff, corrupting adjacent BSS variables and potentially leading to memory corruption and control over the NFS client's state machine.
CVE-2026-29008: U-Boot Integer Underflow Leads to Bootloader Crash
1 TTP 1 CVEAn integer underflow vulnerability (CVE-2026-29008) in U-Boot's `tcp_rx_state_machine()` function allows a network-adjacent attacker to crash the bootloader by sending a crafted TCP SYN+ACK packet, potentially preventing device boot and leading to memory corruption.
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
3 TTPsAn XML injection vulnerability (CVE-2026-0284) in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI
3 TTPsA command injection vulnerability, CVE-2026-0286, in the management plane of Palo Alto Networks PAN-OS software allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series) devices, potentially leading to high system compromise.
CVE-2026-0280 PAN-OS: IPv6 Firewall Policy Bypass
1 TTPAn unauthenticated attacker can exploit CVE-2026-0280, an IPv6 packet processing vulnerability in the dataplane of Palo Alto Networks PAN-OS software, to bypass firewall security policy enforcement, allowing network traffic that should be blocked to reach protected services.
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
3 TTPsA server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-0285, exists in the management web interface of Palo Alto Networks PAN-OS software, allowing an authenticated administrator with network access to make unauthorized requests from the firewall to internal services, potentially leading to information disclosure or further network compromise.
CVE-2026-0276: Palo Alto Networks Cortex XDR Broker VM Privilege Escalation
1 TTPA local privilege escalation vulnerability, CVE-2026-0276, in Palo Alto Networks Cortex XDR Broker VM allows a locally authenticated low-privileged user to gain root access, potentially leading to compromise of the security solution itself.
CVE-2026-0288 PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent
3 TTPsPalo Alto Networks has disclosed multiple buffer overflow vulnerabilities (CVE-2026-0288) in their PAN-OS User-ID Terminal Server Agent (TSA) component, which an unauthenticated attacker with network access can exploit by sending specially crafted network traffic to cause a denial of service (DoS) or potentially achieve arbitrary code execution, affecting various versions of PAN-OS, Cloud NGFW, and Prisma Access if the TSA is exposed to untrusted networks.
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
2 TTPsPalo Alto Networks has disclosed multiple low-severity cross-site scripting (XSS) vulnerabilities, CVE-2026-0279, in PAN-OS software affecting the User-ID Authentication Portal, GlobalProtect gateway/portal features, and Clientless VPN, which could allow a malicious unauthenticated user to inject and execute JavaScript in a victim's browser.
CVE-2026-0278 Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
1 TTPCVE-2026-0278 describes multiple protection mechanism failures in the Prisma Access Agent's Data Loss Prevention (DLP) component for Windows, allowing a local user to bypass DLP policy enforcement controls and exfiltrate sensitive data on affected versions prior to 26.2.1.
CVE-2026-0277 Prisma Access Agent: Improper Certificate Validation on iOS
1 TTPAn improper certificate validation vulnerability (CVE-2026-0277) in the Prisma Access Agent for iOS, affecting versions prior to 26.2.1, enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic, leading to potential compromise of data confidentiality and integrity.
CVE-2026-0287 PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing
1 TTPMultiple denial of service vulnerabilities, tracked as CVE-2026-0287, in Palo Alto Networks PAN-OS software allow an unauthenticated attacker to cause a DoS condition by sending specially crafted network traffic, potentially forcing the firewall into maintenance mode.
CVE-2026-0282 PAN-OS: Unauthenticated File Deletion Vulnerability
An unauthenticated attacker with network access to the management web interface of Palo Alto Networks PAN-OS software can exploit CVE-2026-0282, a file deletion vulnerability, to delete files from a temporary directory, impacting PA-Series and VM-Series firewalls, and Panorama appliances.
CVE-2026-56776 - n8n Authorization Bypass via Workflow Test Run Endpoint
1 rule 3 TTPs 1 CVEAn authenticated user can exploit CVE-2026-56776, an authorization bypass vulnerability in n8n versions prior to 1.123.55, 2.25.7, and 2.26.2, by sending a POST request to the `/workflows/{workflowId}/test-runs/new` endpoint to trigger unauthorized workflow execution, leading to unintended outbound API calls, data mutations, and other side effects in connected downstream systems.
CVE-2026-56297 - FreeRDP Use-After-Free Vulnerability Leading to RCE/DoS
2 TTPs 1 CVEA use-after-free vulnerability (CVE-2026-56297) in the FreeRDP client before version 3.22.0 allows a malicious RDP server to achieve remote code execution or denial of service on connecting clients by triggering a race condition through concurrent DYNVC_DATA and DYNVC_CLOSE messages.
CVE-2026-56250: Capgo R2 Bundle Object Deletion via Mutable r2_path
2 TTPs 1 CVE 2 IOCsA critical vulnerability, CVE-2026-56250, in Capgo before version 12.128.2 allows an authenticated attacker with upload-scoped API keys to manipulate the app_versions.r2_path field via PostgREST, leading to arbitrary R2 bundle object deletion and denial of service.
CVE-2026-56246 - Capgo Broken Access Control in Organization Management API
3 TTPs 1 CVECapgo versions prior to 12.128.2 contain a broken access control vulnerability (CVE-2026-56246) in their organization management API where a scoped API key inherits the full permissions of its owner-user, allowing an attacker to perform destructive operations against unauthorized organizations, bypassing intended scope and leading to privilege escalation and impact.
CVE-2026-56226 - Capgo Unauthenticated Data Exposure via Supabase PostgREST RPC
1 rule 2 TTPs 1 CVECVE-2026-56226 details a high-severity vulnerability in Capgo versions prior to 12.128.2 that exposes a Supabase PostgREST RPC function, `public.get_orgs_v6`, to unauthenticated attackers, allowing them to retrieve sensitive user organization membership and PII by supplying an arbitrary user UUID.
CVE-2026-5356: LatePoint WordPress Plugin Improper Input Validation Leading to Arbitrary Payments
2 TTPs 1 CVEAn improper input validation vulnerability (CVE-2026-5356) in the LatePoint - Calendar Booking Plugin for Appointments and Events for WordPress, versions up to and including 5.4.0, allows unauthenticated attackers to exploit its Stripe Connect payment processor by supplying a previously succeeded PaymentIntent ID, resulting in the processing of arbitrary payments.
CVE-2026-6230: Tainacan WordPress Plugin SQL Injection Vulnerability
1 rule 1 TTP 1 CVEAn unauthenticated attacker can exploit CVE-2026-6230, a time-based blind SQL Injection vulnerability in the Tainacan plugin for WordPress (versions up to and including 1.0.3) via the 'geoquery' parameter, to append arbitrary SQL queries and exfiltrate sensitive information from the database due to insufficient input validation.
CVE-2026-6854 - WordPress My Calendar Plugin Time-Based Blind SQL Injection
1 rule 2 TTPs 1 CVEA time-based blind SQL Injection vulnerability exists in the My Calendar - Accessible Event Manager plugin for WordPress, affecting all versions up to and including 3.7.8. This flaw, located in the 'mc_auth' parameter, stems from insufficient input sanitization and improper SQL query preparation, allowing unauthenticated attackers to inject additional SQL queries to extract sensitive information from the underlying database.
CVE-2026-3688: WordPress WCFM Membership Plugin Insecure Direct Object Reference
2 TTPs 1 CVEAuthenticated attackers with vendor-level access can exploit an Insecure Direct Object Reference (IDOR) vulnerability (CVE-2026-3688) in the WCFM Membership - WooCommerce Memberships for Multivendor Marketplace plugin for WordPress to change any user's role to 'wcfm_vendor' by manipulating membership plans, leading to unauthorized privilege escalation.
Multiple Vulnerabilities in IBM Operational Decision Manager
4 TTPsMultiple vulnerabilities in IBM Operational Decision Manager can be exploited by a remote, unauthenticated attacker, allowing them to bypass security restrictions, achieve remote code execution, and cause a denial of service condition.
Red Hat Enterprise Linux (389-ds-base): Multiple Vulnerabilities Allow Code Execution and DoS
2 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux and the 389-ds-base component allow a remote, authenticated attacker to execute arbitrary code or cause a Denial-of-Service condition.
X.Org X11 and Xwayland Multiple Vulnerabilities Allowing Code Execution and DoS
2 TTPsMultiple vulnerabilities in X.Org X11 and Xwayland allow an attacker to cause a denial of service or potentially execute arbitrary program code, posing a significant risk to systems utilizing these display server implementations, potentially leading to system instability or full compromise.
Multiple Vulnerabilities in ESRI ArcGIS Allow Privilege Escalation and Security Bypass
3 TTPsMultiple unpatched vulnerabilities in ESRI ArcGIS allow a remote, anonymous attacker to bypass security measures or gain elevated user rights, potentially leading to unauthorized access and privilege escalation within affected systems.
IBM WebSphere Application Server: Authenticated Remote Action Execution Vulnerability
1 TTPA vulnerability in IBM WebSphere Application Server allows a remote, authenticated attacker to execute arbitrary actions on the server, potentially leading to a compromise of the host system.
dpkg: Vulnerability Enables Information Disclosure
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in the dpkg package management system to disclose information from the affected system, potentially exposing sensitive data or system details to unauthorized parties.
ILIAS: Multiple Vulnerabilities Identified by BSI
2 TTPsAn attacker can leverage several vulnerabilities within the ILIAS e-learning platform to bypass security controls, disclose sensitive information, and execute Cross-Site Scripting (XSS) attacks, potentially leading to unauthorized access, data compromise, and client-side code execution.
GStreamer (webrtcbin): Vulnerability Allows Circumvention of Security Measures
1 TTPA remote, unauthenticated attacker can exploit a low-severity vulnerability within the GStreamer webrtcbin component to bypass existing security measures, potentially allowing for the circumvention of protective mechanisms without further details on specific impact.
Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.
Better Auth OAuth Refresh Token Replay via Missing Client Authentication (CVE-2026-53512)
1 TTPThe legacy `oidcProvider` and `mcp` plugins in the `better-auth` library versions prior to 1.6.11 are vulnerable to CVE-2026-53512, an OAuth refresh-token replay attack where the plugins fail to verify the `client_secret` of confidential clients during the `refresh_token` grant, allowing an attacker who obtains a valid `refresh_token` and `client_id` to indefinitely mint new access tokens and impersonate the client for unauthorized resource access.
CVE-2026-59708: Ghostfolio Unauthenticated Portfolio Data Exposure
3 TTPs 1 CVEAn authorization bypass vulnerability (CVE-2026-59708) in Ghostfolio's GET /api/v1/public/:accessId/portfolio endpoint allows unauthenticated attackers with a private access ID to retrieve sensitive financial portfolio data, including holdings and performance metrics, due to missing `granteeUserId` filtering validation.
CVE-2026-57851 — MSI Feature Manager Kernel Driver Local Privilege Escalation
1 TTP 1 CVEA local privilege escalation vulnerability (CVE-2026-57851) exists in the MSI Feature Manager's KernCoreLib64.sys kernel driver that allows any local user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without requiring administrator privileges, enabling manipulation of kernel objects, tampering with kernel-mode callbacks, bypassing Protected Process Light, and disabling security software.
CVE-2026-13020: Weak Password Recovery in Esri Portal for ArcGIS Leading to Account Takeover
2 TTPs 1 CVEA critical vulnerability (CVE-2026-13020) exists in Esri Portal for ArcGIS versions 12.1 and earlier, affecting deployments on Windows, Linux, and Kubernetes, where a weak password recovery mechanism allows a remote, unauthorized attacker to assume ownership of a user's account by exploiting this flaw.
Critical Unauthenticated API Access in Esri Portal for ArcGIS (CVE-2026-13019)
1 TTP 1 CVEA critical missing authentication vulnerability (CVE-2026-13019) in Esri Portal for ArcGIS versions 12.1 and earlier allows a remote, unauthenticated attacker to access unprotected critical APIs, impacting deployments on Windows, Linux, and Kubernetes environments.
Hitachi Energy PROMOD V Insecure HTTP Transmission Vulnerability (CVE-2026-10763)
2 TTPs 1 CVEHitachi Energy PROMOD V versions 1.0.10 and prior are affected by CVE-2026-10763, an insecure HTTP transmission vulnerability that allows attackers to intercept or manipulate sensitive data in transit, potentially leading to credential theft, session hijacking, or unauthorized access, impacting the energy sector globally.
Multiple Vulnerabilities in Digi International PortServer TS and Digi One SP IA Devices
2 TTPs 2 CVEsMultiple vulnerabilities, including CVE-2026-12352 (incorrect authorization) and CVE-2026-12948 (stored cross-site scripting), affect Digi International PortServer TS, Digi One SP, Digi One SP IA, and Digi One IA devices with firmware prior to 2025, allowing unauthenticated bypass, access to restricted resources, credential acquisition, and client-side script execution in critical infrastructure environments.
Critical Vulnerabilities in Hydro-Québec Le Circuit Electrique Charging Station Backend
4 TTPsMultiple critical vulnerabilities, including improper access control (CVE-2026-20744), improper restriction of excessive authentication attempts (CVE-2026-42952), and insufficient session expiration (CVE-2026-44383), affect Hydro-Québec Le Circuit Electrique charging station backend versions prior to June 2026, which if exploited could lead to privilege escalation or denial-of-service impacting critical transportation infrastructure.
Public Exploit for MCPJam Inspector Remote Code Execution (EDB-52625)
2 TTPsA public exploit (EDB-52625) has been published for the web application MCPJam Inspector, demonstrating a Remote Code Execution vulnerability, significantly elevating the risk for unpatched systems and allowing attackers to execute arbitrary code.
ProtonVPN v4.4.1 Unquoted Service Path Vulnerability with Public Exploit
1 rule 1 TTPA local privilege escalation vulnerability (Unquoted Service Path) in ProtonVPN v4.4.1 has a public exploit, allowing a local attacker to execute arbitrary code with 'LocalSystem' privileges by placing a malicious executable in a specific directory, which is then launched by the vulnerable 'ProtonVPN Wireguard' service upon startup or restart.
Critical XSS Vulnerability in Synacor Zimbra Collaboration
1 TTPA critical cross-site scripting (XSS) vulnerability, affecting Synacor Zimbra Collaboration versions prior to 10.1.19, allows an attacker to achieve remote indirect code injection, potentially leading to session hijacking, data exfiltration, or defacement.
Multiple Vulnerabilities in Postfix Mail Server
1 TTP 1 IOCMultiple vulnerabilities have been identified in various versions of the Postfix mail server, potentially allowing an attacker to cause a denial of service (DoS) and other unspecified security issues, requiring immediate patching across affected installations.
Multiple Vulnerabilities in SPIP CMS Lead to Data Confidentiality Loss
3 TTPsMultiple vulnerabilities, including SQL injection and indirect remote code injection (XSS), were discovered in SPIP Content Management System versions prior to 4.4.16, allowing an attacker to compromise data confidentiality and execute malicious code in user browsers.
Multiple Vulnerabilities in PHP (CVE-2026-12184, CVE-2026-14355)
1 CVEMultiple critical vulnerabilities (CVE-2026-12184, CVE-2026-14355) have been discovered in various PHP versions, allowing an attacker to cause an unspecified security issue, as reported by CERT-FR on July 7, 2026.
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
2 TTPsAn SSRF protection bypass vulnerability, CVE-2026-33655, in the QuantumNous new-api, affecting versions prior to v0.12.0-alpha.1, allows authenticated users to send requests to internal HTTP services by configuring notification URLs with unresolved hostnames, leading to potential sensitive internal data exposure through timing, errors, or response-dependent behavior.
CVE-2026-13696: HAVELSAN Liman MYS LDAP Injection Vulnerability
1 CVEA high-severity LDAP injection vulnerability, tracked as CVE-2026-13696 with a CVSS v3.1 base score of 8.8, affects HAVELSAN Inc.'s Liman MYS versions prior to release.Master.1107, allowing attackers to bypass authentication or exfiltrate sensitive data via improper neutralization of special characters in LDAP queries.
CVE-2026-11348: HAVELSAN Liman MYS Cryptographic Signature Bypass Vulnerability
1 CVEA critical improper verification of cryptographic signature vulnerability, tracked as CVE-2026-11348, in HAVELSAN Inc.'s Liman MYS product allows an unauthenticated attacker to fake the source of data, leading to potential data integrity compromise.
Red Hat Enterprise Linux (perl-HTTP-Daemon): Remote Code Execution Vulnerability
2 TTPsA remote, unauthenticated attacker can exploit a vulnerability in the 'perl-HTTP-Daemon' component within Red Hat Enterprise Linux to execute arbitrary program code with the privileges of the affected service, potentially gaining control over the compromised system.
DriveLock On-Premise and Cloud: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities exist in DriveLock's On-Premise and Cloud solutions, allowing an authenticated remote attacker to disclose sensitive information, execute arbitrary code, and escalate privileges, posing a significant risk to the integrity and confidentiality of systems protected by DriveLock.
CVE-2026-11340 — Missing Authorization in HAVELSAN Liman MYS
1 TTP 1 CVEA missing authorization vulnerability (CVE-2026-11340) in HAVELSAN Inc. Liman MYS versions prior to release.Master.1107 allows an attacker with low privileges to access functionality not properly constrained by ACLs, leading to high impact on integrity and availability.
Devolutions Server: Vulnerability Allows Multi-Factor Authentication Bypass
1 TTPA remote, authenticated attacker can exploit a vulnerability in Devolutions Server to bypass its multi-factor authentication (MFA) security measures, potentially leading to unauthorized access to sensitive data and systems.
CVE-2026-14474 - SSSD LDAP sudo Provider Privilege Escalation
2 TTPs 1 CVEA vulnerability in SSSD's LDAP sudo provider, CVE-2026-14474, allows an authenticated attacker to achieve root-level privilege escalation by injecting a malicious sudoRole object into any writable LDAP subtree when the `ldap_sudo_search_base` option is not explicitly configured on SSSD-enrolled Linux hosts.
CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS
2 TTPs 1 CVEAn integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.
Synacor Zimbra Classic Web Client XSS Vulnerability
1 TTPAn unauthenticated remote attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the Synacor Zimbra Classic Web Client, allowing the attacker to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, data theft, or defacement.
Hashicorp Terraform: Information Disclosure Vulnerability
1 TTPA vulnerability in Hashicorp Terraform allows a remote, authenticated attacker to disclose sensitive information, which could lead to the exposure of confidential data.
CVE-2026-8377: Missing Authorization in Armiya GKS Allows Data Collection
2 TTPs 1 CVEA critical Missing Authorization vulnerability (CVE-2026-8377) in Armiya Information Technologies Ltd. Co.'s Access Control System (GKS) before Version 2 allows an unauthenticated or unauthorized attacker to collect sensitive data from common resource locations, leading to unauthorized information disclosure.
CVE-2026-5799: Authorization Bypass in Idvlabs Ontime
1 TTP 1 CVEA high-severity authorization bypass vulnerability (CVE-2026-5799) exists in Idvlabs Software and Consulting Services Inc. Ontime versions through 04052026, allowing an unauthenticated attacker to exploit trusted identifiers by manipulating user-controlled keys, leading to unauthorized access.
CVE-2026-12480 Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras
1 CVEA high-severity vulnerability, CVE-2026-12480, affects the `keras-team/keras` library, enabling an arbitrary HDF5 file read via a virtual dataset bypass, potentially leading to sensitive information disclosure or exfiltration from systems utilizing the library.
Coder Workspace Agent API Insecure Redirect Handling Allows Cross-Agent File Access and RCE
2 TTPsAn authenticated user can exploit insecure redirect handling in the Coder workspace agent API to redirect API requests from their modified agent to a victim's online agent, enabling unauthorized file read/write operations and potential remote command execution across workspace and tenant boundaries.
mkfifo: permissions of an existing file are changed after FIFO creation fails
3 TTPs 1 CVEA vulnerability (CVE-2026-35341) exists in the `uu_mkfifo` utility of `uutils coreutils`, affecting versions prior to 0.6.0. When `mkfifo()` fails because the target file already exists, the utility incorrectly proceeds to modify the permissions of the pre-existing file to `0644`. This can inadvertently relax permissions on sensitive owner-only files, such as SSH private keys, making them accessible to other users on the system and potentially enabling unauthorized access or information disclosure. The issue has been patched in PR #10376.
9router: Login Brute-Force Protection Bypass via Spoofed X-Forwarded-For Header
1 rule 2 TTPsThe 9router dashboard login rate limiter incorrectly uses the attacker-controlled X-Forwarded-For HTTP header to identify clients, leading to a brute-force protection bypass (CVE-2026-55501) that allows attackers to circumvent the lockout mechanism and conduct unlimited password brute-force attempts to gain administrative access.
CVE-2026-59713: Leantime OIDC Login CSRF leading to Session Fixation
3 TTPs 1 CVECVE-2026-59713 identifies a high-severity OIDC login Cross-Site Request Forgery (CSRF) vulnerability in Leantime's verifyState() method, allowing attackers to craft malicious callback URLs with attacker-controlled authorization codes to perform session fixation and log victims into an attacker's session.
CVE-2026-25271: Memory Corruption in Qualcomm Snapdragon
1 CVEA high-severity memory corruption vulnerability (CVE-2026-25271) exists in Qualcomm Snapdragon products due to improper handling of asynchronous input parameters, enabling a local, low-privileged attacker to achieve high impact on confidentiality, integrity, and availability without user interaction.
Coder AI Bridge Proxy TLS Certificate Verification Bypass (CVE-2026-55436)
3 TTPsThe AI Bridge Proxy (`aibridgeproxyd`) in Coder's platform, when running in its default configuration without an upstream proxy, failed to perform TLS certificate verification for outbound HTTPS connections to the Coder server (CVE-2026-55436), allowing an on-path attacker to intercept sensitive data including Coder session tokens, user-supplied API keys, and full request/response bodies.
Coder `coder open app` Session Token Leakage Vulnerability (CVE-2026-55431)
1 TTP 1 IOCA high-severity vulnerability, CVE-2026-55431, in the Coder CLI's `coder open app` command allows malicious workspace template authors to exfiltrate user session tokens via crafted external app URLs, leading to full account impersonation.
Coder's Workspace App Vulnerability Allows Cross-Workspace Agent Rebinding
4 TTPsA critical authorization bypass vulnerability (CVE-2026-55429) exists in Coder's workspace application, allowing an attacker with template authorship or external provisioner access to rebind a victim's workspace app to their own agent, enabling them to proxy and compromise the victim's IDE and terminal sessions.
Coder Tailnet Vulnerability (CVE-2026-55428) Leads to Route Hijacking
1 TTPA high-severity vulnerability (CVE-2026-55428) in Coder's tailnet coordinator allows a malicious workspace agent to hijack network routes by advertising arbitrary `AllowedIPs` prefixes, enabling interception and spoofing of web terminal and workspace application traffic.
OpenRemote Incomplete Fix for XXE in KNXProtocol Leads to Arbitrary File Read (CVE-2026-54640)
4 TTPs 1 CVE 3 IOCsAn incomplete fix for CVE-2026-40882 in OpenRemote's KNXProtocol module (specifically in versions <= 1.24.1 of the agent module) allows authenticated users to perform an XML External Entity (XXE) injection, enabling arbitrary file read from the server's filesystem, including sensitive configuration files and potentially leading to server-side request forgery (SSRF) against cloud metadata endpoints or internal services, without requiring administrator access.
Coder OIDC email_verified Type Coercion Bypass (CVE-2026-55076)
3 TTPsA vulnerability, CVE-2026-55076, in Coder's OpenID Connect (OIDC) authentication callback allowed an attacker to bypass email verification due to improper Go boolean type assertion of the `email_verified` claim, leading to full account takeover for existing user accounts.
Coder OIDC Account Takeover Vulnerabilities (CVE-2026-55075)
2 TTPsTwo critical flaws in Coder's OIDC login mechanism, CVE-2026-55075, allow an attacker to achieve account takeover by exploiting email-based user matching without proper IdP subject checks and bypassing the `email_verified` claim, leading to full access to victim workspaces and resources.
Coder SSH Config Injection Vulnerability (CVE-2026-55427)
1 TTPA malicious or compromised Coder server can exploit CVE-2026-55427 to inject unsanitized SSH configuration values via `coder config-ssh` into developer workstations, enabling arbitrary code execution on client machines.
OpenRemote Cross-Realm User Information Disclosure (CVE-2026-54641)
1 rule 2 TTPsA high-severity vulnerability (CVE-2026-54641) in OpenRemote's `UserResourceImpl.java` allows a realm administrator in a multi-tenant deployment to perform cross-realm user enumeration and privilege-level reconnaissance by reading sensitive user information (profile, client roles, and realm roles) from any other realm, including the master realm, due to missing authorization checks in specific REST API endpoints.
Langroid Tool Invocation Bypass via Unverified User Messages (CVE-2026-54771)
1 TTPA high-severity vulnerability, CVE-2026-54771, in Langroid applications allows untrusted users to directly invoke internal tools via raw JSON payloads, even when these tools are configured not to be used by the LLM, enabling malicious actors to bypass security controls and execute sensitive operations like file read/write, database queries, or access to internal orchestration tools.
Decompress Archive Extraction Vulnerability Allows Path Traversal and Privilege Escalation (CVE-2026-53486)
2 TTPsA critical vulnerability (CVE-2026-53486) in the `@xhmikosr/decompress` and unmaintained `decompress` npm packages allows attackers to craft malicious archives that, upon extraction, can write or read files outside the target directory, expose arbitrary file contents, or create setuid/setgid files leading to arbitrary file system modification, information disclosure, and potential privilege escalation.
Scriban Template Engine Vulnerability: Arbitrary CLR Property Writes (Mass Assignment & Setter Bypass)
2 TTPsThe Scriban templating engine, specifically its `TypedObjectAccessor`, allows template code to write to arbitrary CLR object properties, including those with `private set`, `internal set`, and `init` modifiers, effectively bypassing intended C# access restrictions. This mass assignment (CWE-915) and access-modifier bypass (CWE-284) vulnerability can lead to unauthorized modification of sensitive host object properties, such as changing `user.is_admin = true`, with changes persisting after template rendering, affecting Scriban versions up to and including 7.2.1, with the `init` bypass specifically impacting .NET 5+.
flyto-core SSRF Bypass via IPv6 Transition Addresses (CWE-918)
3 TTPs 3 IOCsAn authenticated workflow author can bypass `flyto-core`'s Server-Side Request Forgery (SSRF) protection by crafting URLs with IPv6 transition addresses that embed private IPv4s, allowing for data exfiltration from internal services like cloud instance metadata.
Cilium L7 Envoy Admin Socket Vulnerability (CVE-2026-49445)
2 TTPsWhen Cilium L7 functionality is enabled, a world-accessible Envoy admin socket is inadvertently created on cluster nodes. This misconfiguration (CVE-2026-49445) allows a local attacker to gain unauthorized access to Envoy's administrative endpoints, leading to sensitive information disclosure, such as the exposure of TLS secrets, and significant cluster disruption, including the interruption of traffic and the termination of Envoy processes.
CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE
1 CVEA high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.
Multiples vulnérabilités dans OpenSSH
2 TTPsMultiple vulnerabilities in OpenSSH versions prior to 10.4 allow attackers to bypass security policies, cause denial of service, and exploit other unspecified security issues, requiring users to update to OpenSSH 10.4 or later.
Multiple Vulnerabilities in Roundcube Webmail (CVE-2026-54432, CVE-2026-54433)
Multiple vulnerabilities, including Server-Side Request Forgery (SSRF), Cross-Site Scripting (XSS), and Denial of Service (DoS), have been discovered in Roundcube Webmail versions 1.6.x prior to 1.6.17 and 1.7.x prior to 1.7.2, allowing remote attackers to impact service availability and potentially execute malicious code or access internal resources.
Vulnerability in PostgreSQL JDBC Allows Security Policy Bypass (CVE-2026-54291)
2 IOCsA vulnerability, CVE-2026-54291, has been discovered in PostgreSQL JDBC versions 42.7.4 up to, but not including, 42.7.12, allowing an attacker to bypass security policies within applications utilizing the affected driver, potentially leading to unauthorized access or actions.
KeepInMind 0.8.4.2 - Stored XSS Public Exploit
1 TTPA public exploit has been published for a Stored XSS vulnerability in KeepInMind version 0.8.4.2, significantly increasing the risk for unpatched installations.
Windows Defender Race Condition (EDB-52612) Leads to Local Privilege Escalation and AV Bypass
1 TTP 3 IOCsA critical local race condition (EDB-52612) exists in Microsoft Windows Defender's MsMpEng.exe, specifically between its cleanup routine (`MpCleanCallbackFunction`) and Volume Shadow Copy creation, allowing Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM and temporary disabling of antivirus protection through a use-after-free vulnerability, with a public exploit demonstrating the risk.
Proof-of-Concept Exploit Released for Linux 'Bad Epoll' Root Access Vulnerability (CVE-2026-46242)
1 TTP 1 CVEA publicly available proof-of-concept exploit for CVE-2026-46242, a race-condition use-after-free vulnerability dubbed 'Bad Epoll' in the Linux kernel's `epoll` facility, enables unprivileged processes to gain root privileges on affected Linux and Android systems.
Multiple Vulnerabilities in Apache Camel Lead to Arbitrary Code Execution
1 TTPMultiple vulnerabilities exist in Apache Camel that an attacker can exploit to bypass security controls and execute arbitrary program code, potentially leading to system compromise and unauthorized operations.
OpenVPN: Multiple Vulnerabilities
3 TTPsA local attacker can exploit multiple vulnerabilities in OpenVPN to achieve arbitrary code execution, manipulate data, or cause a denial of service.
CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service
1 TTP 1 CVEAn authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.
CVE-2026-14809: Unauthenticated SQL Injection in Prog Management System
1 rule 2 TTPs 1 CVEA SQL Injection vulnerability, identified as CVE-2026-14809, exists in the Prog Management System developed by PROG MIS, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
CVE-2026-14807: PROG MIS ERP App Hard-coded Credentials Vulnerability
3 TTPs 1 CVEAn unauthenticated remote attacker can exploit a Use of Hard-coded Credentials vulnerability (CWE-798) in the ERP App developed by PROG MIS, allowing the attacker to log in to view application code and obtain database account and password information, leading to high impact on confidentiality, integrity, and availability.
Gitea: Multiple Vulnerabilities Leading to XSS, Info Disclosure, and File Manipulation
4 TTPsAn attacker can exploit multiple unpatched vulnerabilities in Gitea to bypass security measures, disclose sensitive information, perform Cross-Site Scripting (XSS) attacks, and manipulate files, posing a high risk to self-hosted Git instances.
CVE-2026-14802: Remote OS Command Injection in React Create React App
2 TTPs 1 CVE 6 IOCsA high-severity OS command injection vulnerability (CVE-2026-14802) exists in `react create-react-app` up to version 5.0.1, specifically within the `startBrowserProcess` function of the `openBrowser.js` file in the `react-dev-utils` component, allowing for remote exploitation and arbitrary OS command execution on affected macOS development environments.
Red Hat JBoss Enterprise Application Platform: Multiple Vulnerabilities
5 TTPsMultiple vulnerabilities in Red Hat JBoss Enterprise Application Platform allow a remote, unauthenticated attacker to execute arbitrary code, perform cross-site scripting (XSS) attacks, disclose sensitive information, cause a denial of service, or bypass security mechanisms, posing a significant risk of system compromise and data exposure.
Eclipse Jetty: Multiple Vulnerabilities Including Arbitrary Code Execution
2 TTPsAn authenticated remote attacker can exploit multiple vulnerabilities in Eclipse Jetty to achieve arbitrary code execution, bypass security measures, or perform an HTTP cache poisoning attack, necessitating immediate patching and enhanced monitoring of Jetty instances.
CVE-2026-14771: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability
1 rule 1 TTP 1 CVE 6 IOCsA critical SQL injection vulnerability (CVE-2026-14771) has been discovered in SourceCodester Class and Exam Timetabling System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in `/edit_exam1.php`, leading to arbitrary SQL command execution and potential data compromise.
CVE-2026-14770: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability
1 rule 1 TTP 1 CVEA high-severity SQL injection vulnerability, CVE-2026-14770, exists in SourceCodester Class and Exam Timetabling System version 1.0 within the `/edit_room.php` file, allowing remote, unauthenticated attackers to manipulate the 'ID' argument with public exploits, leading to data exposure and potential database compromise.
CVE-2026-9085: Incorrect Permissions Allow DNS Spoofing in Pardus-Parental-Control
1 CVEAn Improper Access Control and Incorrect Permission Assignment vulnerability (CVE-2026-9085) in TUBITAK BILGEM's Pardus-Parental-Control software, affecting versions up to 0.5.1 and all versions before 0.7.0, allows a local attacker to perform DNS Spoofing.
CVE-2026-6509 — Missing Authorization Vulnerability in Pardus Update Allows Privilege Escalation
1 TTP 1 CVEA Missing Authorization vulnerability (CVE-2026-6509) in TUBITAK BILGEM Software Technologies Research Institute's Pardus Update software allows a local, low-privileged attacker to escalate privileges on affected Pardus Linux systems by bypassing authorization checks in versions up to and including 0.6.3.
CVE-2026-12250: Pardus Domain Joiner Vulnerability Exposes Sensitive Information
1 CVEA high-severity vulnerability, CVE-2026-12250, in TUBITAK BILGEM Software Technologies Research Institute's Pardus Domain Joiner (versions 0.5.2 before 0.5.4) allows local attackers to excavate sensitive information by observing process invocations that expose credentials or other confidential data.
CVE-2026-14753: mjperpinosa stumasy Authorization Bypass
2 TTPs 1 CVE 1 IOCA critical authorization bypass vulnerability (CVE-2026-14753) has been identified in mjperpinosa stumasy, affecting versions up to and including commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be. This flaw, residing in an unknown function within the /PHP/objects/notes file of the Note Handler/Assignment Handler component, allows a remote attacker to bypass authorization by manipulating the 'assignment_item_id' argument. A public exploit is available, posing an immediate threat.
CVE-2026-14745: SQL Injection in code-projects Real State Services
1 rule 3 TTPs 1 CVEA critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.
CVE-2026-14743: Remote SQL Injection in code-projects Real State Services 1.0
1 rule 2 TTPs 1 CVEA high-severity remote SQL injection vulnerability (CVE-2026-14743) in code-projects Real State Services 1.0 allows an unauthenticated attacker to manipulate the 'loc' argument in the `/normalHomeSale.php` file, leading to arbitrary SQL command execution and potential compromise of confidentiality, integrity, and availability of data, with an exploit publicly available.
CVE-2026-14737: Hanwang e-Face General Management Platform SQL Injection
1 rule 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-14737) affects Hanwang e-Face General Management Platform version 6.3.5.4, specifically within the `/sysAuthStr/querySysAuthStr.do` file, triggered by manipulating argument order, allowing remote attackers to potentially gain unauthorized access to or modify database contents with a publicly available exploit.
CVE-2026-14736: Ruijie RG-UAC Unrestricted Upload Vulnerability
3 TTPs 1 CVEA critical unrestricted file upload vulnerability, CVE-2026-14736, in Ruijie RG-UAC up to version 1.0-R1.8.2.p5 allows unauthenticated remote attackers to upload arbitrary files via manipulation of the `upload_image` argument in `user_auth_commit.php`, potentially leading to remote code execution.
CVE-2026-14735: SQL Injection Vulnerability in code-projects Smart Parking System
1 rule 2 TTPs 1 CVE 6 IOCsA high-severity SQL injection vulnerability, CVE-2026-14735, exists in code-projects Smart Parking System 1.0, allowing remote attackers to manipulate the `street`, `city`, or `status` arguments in `/parkings/parkings.php` to execute arbitrary SQL queries, potentially leading to arbitrary file read and data exfiltration, with public exploit details available.
CVE-2026-14734: SQL Injection in SourceCodester Class and Exam Timetabling System
1 rule 3 TTPs 1 CVE 6 IOCsA high-severity SQL injection vulnerability (CVE-2026-14734) exists in SourceCodester Class and Exam Timetabling System version 1.0, allowing unauthenticated remote attackers to manipulate the 'ID' argument in `/edit_product.php` to execute arbitrary SQL queries, with a publicly available exploit increasing the risk of unauthorized data access, modification, or exfiltration.
CVE-2026-14722: Remote Code Injection in TidGi-Desktop Git Repository Import Component
2 TTPs 1 CVE 6 IOCsA critical remote code injection vulnerability, CVE-2026-14722, has been identified in tiddly-gittly TidGi-Desktop versions up to 0.13.0, allowing unauthenticated attackers to execute arbitrary code by manipulating the Git Repository Import component, with public exploits available and confirmed active exploitation potential.
CVE-2026-14690: Improper Authorization in SourceCodester Multi-Vendor Online Grocery Management System
3 TTPs 1 CVEA high-severity improper authorization vulnerability (CVE-2026-14690) in the `save_users` function of SourceCodester Multi-Vendor Online Grocery Management System 1.0 allows remote unauthenticated attackers to manipulate user accounts, potentially leading to privilege escalation or unauthorized access, with a public exploit readily available.
CVE-2026-14648: Remote SQL Injection in code-projects Online Voting System
1 rule 2 TTPs 1 CVEA high-severity SQL injection vulnerability, identified as CVE-2026-14648, exists in the code-projects Online Voting System up to versions 0.x/1.0, allowing remote unauthenticated attackers to bypass authentication and execute arbitrary SQL commands by manipulating `adminUserName` or `adminPassword` parameters in the `/authentication.php` login component, with public exploit details increasing the risk of active exploitation.
CVE-2026-14640: CodeAstro Apartment Visitor Management System SQL Injection
1 rule 1 TTP 1 CVE 6 IOCsA critical SQL injection vulnerability (CVE-2026-14640) in CodeAstro Apartment Visitor Management System 1.0 allows remote attackers to execute arbitrary SQL queries via manipulation of the 'Username' argument in the Login component's '/index.php' file, leading to unauthorized data access, modification, and potential system compromise.
CVE-2025-71380: Authenticated Remote Code Execution in n8n via Execute Command Node
2 rules 6 TTPs 1 CVECVE-2025-71380 is an improper access control vulnerability (CWE-284) in n8n versions up to and including 1.114.4 that allows authenticated users to execute arbitrary commands on the underlying host system where n8n runs, potentially leading to data exfiltration, service disruption, or complete system compromise.
CVE-2025-71375: Picklescan Arbitrary Code Execution via _operator.methodcaller Evasion
1 TTP 1 CVEA vulnerability in `picklescan` versions prior to 0.0.34 (CVE-2025-71375) allows attackers to craft malicious Python pickle payloads using the `_operator.methodcaller` built-in function, which evades detection by the `picklescan` library and enables arbitrary code execution when the payload is loaded by an application using `pickle.load()`.
CVE-2025-71373: Picklescan Bypass via `operator.methodcaller` Leads to Arbitrary Code Execution
1 TTP 1 CVERemote attackers can bypass security checks in `picklescan` versions prior to 0.0.33 by crafting malicious pickle payloads utilizing `operator.methodcaller` function calls, which upon loading by systems relying on `picklescan` for validation, results in arbitrary code execution and system compromise.
CVE-2025-71372: Picklescan Deserialization Vulnerability (Numpy Gadget)
2 TTPs 1 CVE 2 IOCsCVE-2025-71372 describes a critical vulnerability in Picklescan versions prior to 0.0.33, where the tool fails to detect a specific numpy gadget in pickle `__reduce__` methods, allowing attackers to craft malicious pickle files that execute arbitrary Python code when loaded, bypassing safety checks and enabling supply-chain poisoning of shared model files.
CVE-2025-71369: Picklescan Malicious Pickle Detection Bypass Leading to RCE
2 TTPs 1 CVEA critical vulnerability, CVE-2025-71369, in `picklescan` versions prior to 0.0.28 allows remote attackers to bypass safety checks for malicious Python pickle files that utilize specific `torch.utils.data.datapipes` methods, enabling undetected embedded malicious code to execute during deserialization, which results in remote code execution (RCE) on the victim's system.
CVE-2025-71367: Picklescan Bypass Leading to Arbitrary Code Execution
2 TTPs 1 CVEPicklescan versions prior to 0.0.34 contain a deserialization vulnerability (CVE-2025-71367) that allows remote attackers to bypass security checks by crafting malicious pickle files using `_operator.attrgetter` in reduce methods, leading to arbitrary code execution when `pickle.load()` processes the file.
CVE-2025-71366: Picklescan Deserialization Vulnerability Leads to RCE
2 TTPs 1 CVEA critical deserialization vulnerability (CVE-2025-71366) exists in picklescan versions prior to 0.0.28, allowing remote attackers to bypass safety checks by embedding malicious `torch.utils.bottleneck.__main__.run_cprofile` function calls in pickle files, leading to arbitrary code execution when victims load the crafted files.
CVE-2025-71362 — picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functio...
2 TTPs 1 CVEpicklescan versions prior to 0.0.33 are vulnerable to unsafe deserialization via CVE-2025-71362, allowing attackers to embed malicious code in pickle files that executes due to `numpy.f2py.crackfortran` calling `eval` on arbitrary strings when loaded from untrusted sources, leading to arbitrary code execution.
CVE-2025-71360: Picklescan RCE via Undetected Malicious Pickle Files
2 TTPs 1 CVEA high-severity deserialization of untrusted data vulnerability (CVE-2025-71360) in picklescan versions before 0.0.29 allows attackers to embed undetected remote command execution code within malicious pickle files, leading to arbitrary code execution when loaded by victims.
CVE-2025-71359: Picklescan Deserialization RCE Bypass
2 TTPs 1 CVEPicklescan versions prior to 0.0.29 are vulnerable to remote code execution (CVE-2025-71359) due to a failure in detecting malicious Python pickle payloads that utilize `lib2to3.pgen2.grammar.Grammar.loads`, allowing attackers to craft files that evade detection and execute arbitrary code during deserialization.
CVE-2025-71356: picklescan Deserialization Vulnerability Leads to RCE
1 TTP 1 CVEA critical deserialization vulnerability (CVE-2025-71356) in `picklescan` versions prior to 0.0.28 allows attackers to embed undetected malicious code within Python pickle files, leading to remote code execution when these files are loaded by victims.
CVE-2025-71353: Picklescan Deserialization Vulnerability Leads to Remote Code Execution
1 TTP 1 CVE 2 IOCsPicklescan before version 0.0.28 contains a deserialization vulnerability where it fails to properly detect malicious pickle files. Attackers can craft these files with embedded code that exploits the `torch._dynamo.guards.GuardBuilder.get` function in reduce methods, leading to arbitrary command execution when loaded on a victim system.
CVE-2025-71347: Picklescan Bypass Leads to Arbitrary Code Execution via Malicious Pickle Files
2 TTPs 1 CVE 2 IOCsA critical vulnerability (CVE-2025-71347) exists in picklescan prior to version 0.0.33, allowing remote attackers to bypass security checks by failing to detect malicious pickle files leveraging the numpy.f2py.crackfortran.param_eval function, leading to arbitrary code execution upon deserialization of untrusted data.
CVE-2025-71345: Picklescan Malicious Pickle File Detection Bypass Leading to RCE
2 TTPs 1 CVECVE-2025-71345 describes a critical vulnerability in `picklescan` versions prior to 0.0.30, where attackers can embed undetected malicious code within pickle files that specifically invoke the `torch.utils.bottleneck.__main__.run_autograd_prof` function, leading to remote code execution upon deserialization by bypassing `picklescan`'s security checks.
CVE-2025-71343 — picklescan Detection Bypass via Malicious Pickle Files
2 TTPs 1 CVEA deserialization vulnerability, CVE-2025-71343, in picklescan before version 0.0.30 allows attackers to craft malicious pickle files that evade detection and lead to arbitrary code execution when loaded via `pickle.load()`.
CVE-2025-71342: picklescan Remote Code Execution Vulnerability
1 TTP 1 CVEA critical vulnerability (CVE-2025-71342) exists in picklescan versions prior to 0.0.30, where it fails to detect malicious code embedded in Python pickle files by leveraging `idlelib.run.Executive.runcode` in reduce methods, allowing attackers to conceal and execute arbitrary code during `pickle.load` operations, leading to remote code execution (RCE) and potential supply chain attacks, particularly impacting PyTorch models.
CVE-2026-14606 — Stack-Based Buffer Overflow in RT-Thread CAN_Receive
1 CVEA stack-based buffer overflow vulnerability (CVE-2026-14606) exists in RT-Thread versions up to 5.0.2, specifically in the `CAN_Receive` function of the SWM341 CAN Handler component, allowing for local exploitation via manipulation, with a public exploit available.
CVE-2026-58379: GIMP Heap Buffer Overflow in PSP Parser Allows RCE
3 TTPs 1 CVEA heap buffer overflow vulnerability (CVE-2026-58379) in GIMP's Paint Shop Pro (PSP) file format parser allows a remote attacker to achieve arbitrary code execution or cause a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file, exploiting incorrect buffer size calculations when processing low bit-depth images.
RPC (Remote Procedure Call) Services Exposed to the Internet
1 rule 3 TTPsThreat actors frequently exploit internet-exposed Remote Procedure Call (RPC) services, primarily on port TCP/135, as an initial access or backdoor vector, leading to unauthorized system access, internal network compromise, and potentially data exfiltration or ransomware deployment.
SMB (Windows File Sharing) Activity from the Internet
1 rule 4 TTPs 1 CVEDetection rule identifies inbound Windows file sharing (SMB/CIFS) traffic originating from the Internet to internal hosts, posing a critical initial access risk due to potential exploitation of vulnerabilities like CVE-2017-0144 (EternalBlue).
CVE-2026-14460: Missing Authorization and Argument Injection in TUBITAK BILGEM Pardus-Software
1 CVEA Missing Authorization vulnerability, identified as CVE-2026-14460, in TUBITAK BILGEM Software Technologies Research Institute's pardus-software versions up to 1.0.4, allows for Argument Injection, posing a high severity risk to confidentiality, integrity, and availability.
CVE-2026-14459: Argument Injection Vulnerability in TUBITAK BILGEM pardus-software
1 TTP 2 CVEs 2 IOCsA critical argument injection vulnerability (CVE-2026-14459) in TUBITAK BILGEM Software Technologies Research Institute's pardus-software versions up to 1.0.4 allows a local, low-privileged attacker to achieve unauthorized command execution, severely impacting confidentiality, integrity, and availability.
WatchGuard Firebox and Mobile VPN Client Vulnerabilities
2 TTPsWatchGuard has released security advisories to address critical vulnerabilities, including a race condition, use-after-free, and local privilege escalation, in its Fireware OS and Mobile VPN with SSL client for Windows, which could lead to remote code execution on appliances and local privilege escalation on client systems if not patched immediately.
Splunk Code Injection via Custom Dashboard Leading to RCE (CVE-2022-43571)
1 TTP 1 CVEAn authenticated user can exploit CVE-2022-43571, a code injection vulnerability within Splunk Enterprise or Splunk Cloud's dashboard PDF generation component, leading to remote code execution (RCE) and potential compromise of the Splunk environment.
Splunk XSS Privilege Escalation via Custom URLs in Dashboard (CVE-2024-36992)
2 rules 1 TTP 1 CVEA critical cross-site scripting (XSS) vulnerability, identified as CVE-2024-36992, affects Splunk Enterprise and Splunk Cloud Platform, allowing attackers to achieve privilege escalation by exploiting custom URLs within Splunk dashboards via malicious POST requests to the `splunk_internal_metrics/data/ui/views` endpoint, leading to the creation of new user accounts with elevated access permissions on the Splunk server.
Splunk RCE via User XSLT Exploitation (CVE-2023-46214)
1 rule 1 TTP 1 CVEThis brief identifies potential remote code execution (RCE) attempts targeting Splunk servers by exploiting CVE-2023-46214, a vulnerability related to user-supplied Extensible Stylesheet Language Transformations (XSLT) that allows attackers to execute arbitrary code leading to full system compromise.
Splunk Authentication Token Exposure in Debug Logs (CVE-2024-29945)
1 rule 1 TTP 1 CVEA critical vulnerability, CVE-2024-29945, allows for the exposure of authentication tokens in debug logs within Splunk Enterprise and Splunk Cloud, enabling an attacker with access to internal log files to gain unauthorized access, exfiltrate data, and potentially achieve full compromise of the Splunk infrastructure if unpatched versions (prior to 9.2.1, 9.1.4, and 9.0.9 for Enterprise) are in use.
FreeBSD Vulnerability CVE-2026-49424 Allows Data Confidentiality Breach
A vulnerability, identified as CVE-2026-49424, has been discovered in FreeBSD versions 14.3 (prior to 14.3-RELEASE-p16), 14.4 (prior to 14.4-RELEASE-p7), and 15.0 (prior to 15.0-RELEASE-p11) that could allow an attacker to compromise data confidentiality.
CVE-2026-4321: Critical SQL Injection in Raera Destekz Product
1 TTP 1 CVECVE-2026-4321 describes a critical SQL Injection vulnerability with a CVSS v3.1 score of 9.8 in the Destekz product by Raera - Ankara Web Design and Digital Advertising Agency, affecting all versions through June 2nd, 2026, which remains unpatched due to the vendor discontinuing support for the product, enabling unauthenticated attackers to potentially achieve full system compromise and data exfiltration.
Open Babel Heap Buffer Overflow in SMILES Parsing (CVE-2025-10996)
1 CVEA heap buffer overflow vulnerability (CVE-2025-10996) in Open Babel's `OBSmilesParser::ParseSmiles` function allows attackers to achieve denial of service or arbitrary code execution by crafting and supplying a malformed SMILES input string to affected versions up to 3.1.1.
Open Babel Heap Buffer Overflow in ChemKin Parser (CVE-2025-10997)
1 TTP 1 CVEA heap buffer overflow vulnerability (CVE-2025-10997) in Open Babel's ChemKin parser allows an attacker to achieve memory corruption when a victim processes a specially crafted ChemKin file, potentially leading to denial of service or arbitrary code execution.
Open Babel Uninitialized Pointer Dereference Vulnerability (CVE-2022-42885)
1 TTP 1 CVEA high-severity memory-safety vulnerability (CVE-2022-42885) in Open Babel's GRO residue parser allows an uninitialized pointer dereference when processing a specially crafted GRO input file, potentially leading to application crash or arbitrary code execution.
Open Babel PQS coord_file parser suffers from out-of-bounds write vulnerability (CVE-2022-43467)
2 TTPs 1 CVEA high-severity memory-safety vulnerability (CVE-2022-43467) in Open Babel's PQS `coord_file` parser allows an attacker to achieve an out-of-bounds write by tricking a victim into opening a specially crafted PQS file, potentially leading to arbitrary code execution or denial of service in systems processing untrusted chemistry file formats.
Open Babel MOL2 Parser Out-of-Bounds Write (CVE-2022-43607)
1 rule 1 TTP 1 CVEA memory-safety vulnerability, CVE-2022-43607, in Open Babel's MOL2 parser allows an out-of-bounds write when processing a crafted input file, potentially leading to denial of service or arbitrary code execution.
Open Babel Has Uninitialized Pointer Dereference in MSI Atom Parser
1 TTP 1 CVEA memory-safety vulnerability (CVE-2022-44451) in Open Babel's MSI parser allows for an uninitialized pointer dereference when processing a specially crafted MSI input file, affecting versions prior to 3.2.0 and potentially leading to application instability or denial of service when a victim opens a malicious file.
Open Babel PQS Parser Uninitialized Pointer Dereference (CVE-2022-46280)
1 CVEA memory-safety vulnerability, CVE-2022-46280, in Open Babel's PQS parser (versions prior to 3.2.0) allows an uninitialized pointer dereference when processing a specially crafted input file, potentially leading to application crashes and denial of service if a victim opens a malicious PQS file.
Open Babel Out-of-Bounds Write in MSI Parser (CVE-2022-46295)
1 TTP 1 CVEAn out-of-bounds write vulnerability (CVE-2022-46295) in Open Babel's MSI parser allows remote attackers to cause memory corruption, denial of service, or potentially arbitrary code execution when a victim opens a specially crafted MSI file using the `obabel` tool or any application linked to the `OBConversion` API.
auth-fetch-mcp SSRF Protection Bypass via IPv4-mapped IPv6 Loopback
auth-fetch-mcp versions up to and including 3.0.1 contain an SSRF protection bypass vulnerability (CVE-2026-49857) where the `isPrivateV6()` function fails to correctly identify IPv4-mapped IPv6 loopback addresses after Node.js URL normalization, allowing URLs like `http://[::ffff:127.0.0.1]:PORT/` to bypass the `assertSafeUrl()` check, enabling an attacker to coerce the `auth_fetch` or `download_media` tools to make requests to internal or loopback services and compromising the confidentiality of internal service responses.
Wetty Client DOM XSS via Base64 Filename in File Download Escape Sequence (CVE-2026-49864)
1 rule 4 TTPsA high-severity DOM XSS vulnerability (CVE-2026-49864) in the wetty SSH client allows an attacker to achieve keystroke injection and command execution on the victim's SSH session by embedding a crafted base64-encoded filename within a terminal file-download escape sequence, which is then unescaped and rendered as raw HTML.
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
2 TTPsA high-severity vulnerability, CVE-2026-49981, in the Twig templating engine allows for a sandbox bypass when the sandbox state changes between renders for a cached `Template` instance, enabling the execution of otherwise restricted filters, tags, and functions in sandboxed contexts.
Non-Constant-Time HMAC Comparison in Pay Gem Paddle Billing Webhook Signature Verifier
3 TTPsA timing side-channel vulnerability in the `Pay` gem's Paddle Billing webhook signature verification component (`Pay::Webhooks::PaddleBillingController#valid_signature?` <= v11.6.1) allows an unauthenticated attacker to recover the HMAC signing secret by observing response time variations in `String#==` comparisons, enabling the forgery of arbitrary webhook events and leading to business logic abuses such as unauthorized feature provisioning or fraudulent refunds.
Sigstore `certificateOIDs` Verification Bypass Vulnerability (CVE-2026-48815)
A high-severity vulnerability (CVE-2026-48815) in the `npm/sigstore` library (versions <= 4.1.0) causes the `certificateOIDs` verification constraint to be silently ignored, allowing applications to accept unauthorized certificates that should have been rejected based on extension policy, which could lead to supply chain attacks by trusting malicious artifacts.
SurrealDB HTTP /rpc Session Hijack Vulnerability
5 TTPsA critical vulnerability (versions prior to 3.1.0) in SurrealDB's HTTP /rpc endpoint allowed unauthenticated attackers to enumerate session UUIDs via the `sessions` method, enabling full session hijack of any attached and authenticated session due to a lack of ownership checks, leading to unauthorized data manipulation and privilege escalation.
Rancher Fleet Unauthenticated Webhook Regex Injection (CVE-2026-44937)
1 TTPAn unauthenticated regex injection vulnerability exists in Rancher Fleet's webhook endpoint when it's configured without a secret, allowing attackers to forge webhook requests using unsanitized repository URL components, which leads to continuous repository re-cloning, causing network and resource exhaustion (Denial of Service) on the management cluster, and potentially service downgrades if the attacker has read access to the target Git repository.
Oras-Go Tar Extraction Vulnerability Allows Current Working Directory Escape (CVE-2026-50163)
5 TTPs 3 IOCsAn attacker can craft a malicious OCI artifact with a tarball layer containing a hardlink entry that uses a relative path for its target, which, when extracted by `oras-go` (<= 2.6.1) or the `oras` CLI, allows the hardlink to resolve against the process's current working directory (CWD) instead of the intended extraction base, leading to arbitrary file read or modification in the victim's CWD via an inode-sharing vulnerability.
goshs WebDAV Listener Bypasses Access Restriction Flags
4 TTPsA vulnerability (CVE-2026-50138) in `goshs` versions up to `v2.0.9` allows an authenticated attacker to bypass intended access restriction flags like `--read-only`, `--upload-only`, and `--no-delete` when the WebDAV listener is enabled, leading to unauthorized file creation, modification, deletion, and content exfiltration on the server, compromising data integrity and confidentiality.
OpenClaw Vulnerability Allows Loading of Unscanned Payloads via Malicious Metadata
3 TTPs 1 CVEA high-severity vulnerability, CVE-2026-53810, in OpenClaw's marketplace runtime extension metadata allows an attacker to craft a malicious package that, when installed by a trusted operator, redirects runtime loading to hidden, unscanned code, potentially leading to unauthorized code execution and bypassing security checks.
OpenClaw Vulnerability Allows Local Forged Identity Headers
2 TTPsA vulnerability (GHSA-rggc-m335-3wvj) in OpenClaw's trusted-proxy deployments allows a local attacker on the same host to forge identity headers, bypassing intended security controls and potentially leading to unauthorized access or privilege escalation if the affected feature is enabled and reachable.
OpenClaw Control UI Locality Spoofing Vulnerability
2 TTPs 1 CVEAn authentication bypass vulnerability (CVE-2026-53817) in OpenClaw's Control UI pairing mechanism allows an attacker with existing network/authentication foothold in LAN/shared-token deployments to spoof locality information, leading to the acquisition of a durable admin-capable device token that grants persistent administrative access, even after shared gateway tokens are rotated.
OpenClaw's POSIX Node system.run Safe-Bin Widened by Shell Expansion (GHSA-mhq8-78pj-5j79)
2 TTPsA vulnerability in OpenClaw's `system.run` safe-bin feature on POSIX nodes could allow a lower-privilege operator flow to read local files not intended by policy, as shell expansion can alter the interpretation of an approved command, causing a seemingly safe argument to expand into additional shell words and become a file operand, potentially exposing OpenClaw configuration data or other node-local information.
OpenClaw Scoped Chat Route Inheritance Could Bypass Admin Command Scope Gates
1 TTPA vulnerability in OpenClaw allows an attacker with `operator.write` privileges to bypass intended administrative command scope gates by delivering a scoped Gateway `chat.send` request through an inherited external route, leading to unauthorized execution of critical administrative commands.
OpenClaw Matrix allowFrom Vulnerability (CVE-2026-53811)
1 CVEA high-severity vulnerability (CVE-2026-53811) in OpenClaw's Matrix `allowFrom` feature allows threat actors to exploit mutable display names to match policy entries, potentially granting unauthorized agent access intended for another Matrix identity.
OpenClaw PowerShell Encoded-Command Alias Bypass Vulnerability
1 rule 2 TTPsA high-severity vulnerability (GHSA-j472-gf56-x589) in OpenClaw allows an attacker to bypass allowlist checks for PowerShell encoded commands by using abbreviated encoded-command flags, leading to unauthorized code execution on the underlying Windows system if a vulnerable feature is enabled and reachable.
Langroid File Tools Path Traversal Vulnerability (CVE-2026-50181)
3 TTPsA path traversal vulnerability (CVE-2026-50181) exists in Langroid's `ReadFileTool` and `WriteFileTool` components (versions <= 0.63.0), allowing an attacker to read or write arbitrary files outside the configured `curr_dir` via crafted `file_path` arguments, potentially leading to sensitive information disclosure or unauthorized file modification in applications exposing these tools to user or LLM input.
OpenClaw Slack allowFrom Vulnerability (GHSA-c29c-2q9c-pc86)
1 TTPA high-severity vulnerability (GHSA-c29c-2q9c-pc86) in OpenClaw's handling of Slack's `allowFrom` feature could allow an attacker to gain unintended agent access by manipulating their Slack display name metadata to match a policy entry, especially in configurations where the affected feature is enabled and reachable.
OpenClaw Trusted-proxy Control UI Privilege Escalation (GHSA-qjpc-qf9m-xwmr)
1 TTPA vulnerability in OpenClaw's trusted-proxy Control UI mode allows an unpaired or restricted trusted-proxy client to gain temporary `operator.admin` authority by declaring elevated WebSocket scopes before proper server-side authorization, enabling the execution of admin-gated Gateway RPCs until the connection is closed or revalidated.
OpenClaw Device Pairing Vulnerability Allows Unauthorized Device Enrollment
2 TTPsA high-severity vulnerability (affecting OpenClaw versions prior to 2026.5.4) in the bundled device-pair plugin allowed authorized non-owner chat senders to issue device-pairing bootstrap codes, enabling them to enroll devices with operator/node capabilities and gain persistent unauthorized access within the OpenClaw environment.
OpenClaw Workspace .env Homebrew Executable Override Vulnerability (CVE-2026-53819)
1 TTP 1 CVEA high-severity vulnerability (CVE-2026-53819) in OpenClaw versions prior to 2026.5.27 allows a malicious `.env` file within a repository to override the Homebrew executable selection during skill installation flows, potentially leading to arbitrary code execution on trusted operator systems running macOS or Linux.
OpenClaw Vulnerability Allows Unintended Artifact Loading (CVE-2026-53813)
1 CVEA high-severity vulnerability, CVE-2026-53813, in npm/openclaw versions <= 2026.4.24 allows fake package roots to influence memory-core artifact loading, potentially leading to the selection and execution of unintended local artifacts based on attacker-controlled or lower-trust input reaching the affected path.
OpenClaw Vulnerability Allows Execution Revalidation Bypass (CVE-2026-53806)
1 CVEA high-severity vulnerability, CVE-2026-53806, in npm/openclaw versions up to 2026.5.7, allows attackers to bypass 'exec revalidation' controls by confusing the application with combined POSIX shell options, leading to unauthorized inline shell content execution and potential remote code execution.
OpenClaw Node Forgery via Missing Provenance Check (CVE-2026-53816)
2 TTPs 1 CVEA vulnerability, CVE-2026-53816, in npm/openclaw versions prior to 2026.5.18, allows a malicious or compromised paired node to forge 'exec' lifecycle events and send them to the gateway, which, due to a missing provenance check, accepts the attacker-supplied event data as legitimate execution results, leading to unauthorized capability exposure for the compromised node.
OpenClaw Telegram Callback Authorization Bypass (GHSA-w5ww-7chg-mxcq)
3 TTPsA high-severity vulnerability (GHSA-w5ww-7chg-mxcq) in OpenClaw allows an unauthorized Telegram user to bypass the `commands.allowFrom` sender check via interactive callbacks, leading to unauthorized command execution on the OpenClaw Gateway.
OpenClaw Trusted Retry Endpoint Hostname Bypass
2 TTPsA vulnerability in OpenClaw allows an attacker to bypass trusted retry endpoint validation by crafting a URL with a hostname prefix that resembles a trusted host, which, if the feature is enabled and reachable by lower-trust input, could lead to sensitive authentication material being sent to an unintended external endpoint.
Craft CMS Vulnerability Allows Low-Privilege Users to Delete Peer Assets
1 TTP 1 CVEA low-privilege user with `deleteAssets` permission in Craft CMS can bypass the `deletePeerAssets` check in the `AssetsController::actionDeleteFolder` function, allowing them to delete assets uploaded by other users (peer assets) within a shared volume, despite lacking the specific `deletePeerAssets` permission, leading to unauthorized data destruction.
@asymmetric-effort/specifyjs: URL Parse Failure Silently Allows Request (CVE-2026-50288)
1 TTPA high-severity vulnerability, CVE-2026-50288, in the `@asymmetric-effort/specifyjs` npm package (versions prior to 0.2.136) allows for the silent bypass of HTTPS validation by mishandling URL parse errors in the `assertSecureUrl` function, which can lead to Server-Side Request Forgery (SSRF).
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (CVE-2026-49852)
1 TTPA critical vulnerability, CVE-2026-49852, exists in the Python `joserfc` library (versions `<= 1.6.7`) where HMAC-signed JSON Web Tokens can be forged, leading to complete authentication bypass, if the application is configured to verify tokens with an empty or `None` HMAC key.
@conform-to/dom Vulnerable to CPU Exhaustion via Crafted Form Submissions
A CPU exhaustion vulnerability (CVE-2026-49250) exists in Conform's `parseSubmission` API when parsing `FormData` or `URLSearchParams` with many unique field names, allowing an attacker to craft a submission that causes excessive synchronous CPU work and potential denial of service by repeatedly scanning submitted entries.
electerm Path Traversal Vulnerability in Zmodem and Trzsz Download Handling (CVE-2026-49253)
3 TTPsA path traversal vulnerability exists in electerm's Zmodem and Trzsz file download handlers (CVE-2026-49253), allowing a malicious SSH server to send specially crafted filenames (e.g., `../escaped.txt`) that, when accepted by the user, can cause files to be written to arbitrary locations on the user's filesystem, potentially overwriting sensitive files or introducing malicious content.
Zebra Block Suppression Vulnerability (CVE-2026-52736) via P2P Body Poisoning
2 TTPsA remote unauthenticated attacker can exploit CVE-2026-52736 in Zebra's `zebrad` node (versions up to and including `v4.4.1`) to permanently stall a targeted blockchain node by poisoning its sent-hash cache, leading to a denial of service.
Craft CMS Mass Assignment Vulnerability Allows Element Overwrites (CVE-2026-50281)
1 TTP 1 CVEA high-severity mass assignment vulnerability (CVE-2026-50281) in Craft CMS versions prior to 5.9.21 allows a low-privileged authenticated attacker to overwrite arbitrary existing element data, such as entries or user profiles, by manipulating the `newAttributes` parameter during a bulk duplication action.
JSONata $toMillis Function Vulnerability Leads to Denial of Service (CVE-2026-52746)
1 TTPA high-severity vulnerability, CVE-2026-52746, in JSONata versions prior to 2.2.0 allows unauthenticated attackers to cause a denial of service by exploiting superlinear backtracking in the ISO-8601 validation regex through malicious inputs to the `$toMillis` function, leading to resource exhaustion and application unresponsiveness.
Path Traversal Vulnerability in @asymmetric-effort/nogginlessdom Allows Arbitrary File Write
4 TTPsA path traversal vulnerability (GHSA-322x-v876-g883) in the `matchFileSnapshot` function of the `@asymmetric-effort/nogginlessdom` library allows an attacker to write arbitrary content to any filesystem path with write access when snapshot update mode is active, potentially leading to supply chain compromise in CI/CD environments.
SimpleSAMLphp HTTP-Artifact Authentication Bypass via TLS Validator Confusion (CVE-2026-49283)
1 TTPA critical vulnerability (CVE-2026-49283) in SimpleSAMLphp's HTTP-Artifact receive path allows a malicious or lower-trust Identity Provider (IdP) to bypass authentication and impersonate users from a higher-trust IdP by leveraging a flaw where `SOAPClient::validateSSL()` fails to properly validate TLS public keys for unsigned SAML Responses.
Zebra Node Denial-of-Service via IPv4-Mapped Mempool Misbehavior Panic (CVE-2026-52829)
1 TTPA remote unauthenticated peer can exploit an address normalization mismatch in Zebra's address book when connecting via IPv4 to a dual-stack IPv6 listener on a Linux host, by then advertising an invalid mempool transaction, which triggers a deterministic assertion panic after a 30-second delay, causing the `zebrad` process to terminate, leading to persistent denial of service.
SimpleSAMLphp Vulnerable to Denial-of-Service via Malicious XPath Transform
1 TTPSimpleSAMLphp and its SAML2 library are vulnerable to CVE-2026-49289, allowing attackers to perform a Denial-of-Service attack by sending specially crafted SAML messages containing XPath transforms, leading to resource exhaustion and service unavailability.
Steeltoe Host Header Bypass Vulnerability (CVE-2026-50194)
1 rule 2 TTPs 1 CVEAn unauthenticated remote attacker can bypass port isolation in Steeltoe applications configured with `Management:Endpoints:Port` by spoofing the Host HTTP header, allowing access to all actuator endpoints (CVE-2026-50194).
Steeltoe.Discovery.Eureka Deserialization Denial-of-Service (CVE-2026-50196)
1 CVEThe Steeltoe.Discovery.Eureka client contains a vulnerability (CVE-2026-50196) where its `DataCenterInfo.FromJson` method throws an `ArgumentException` if a `DataCenterInfo.name` value other than 'MyOwn' or 'Amazon' is encountered, specifically missing the valid 'Netflix' value from the Java Eureka specification, which causes the local service registry to become permanently empty or stale, leading to a complete service discovery outage for all connected Steeltoe Eureka clients.
Steeltoe Environment Actuator Vulnerability (CVE-2026-50200) Leaks Database Passwords
1 rule 1 TTP 1 CVEA high-severity vulnerability, CVE-2026-50200, in the Steeltoe `Sanitizer` component of the Environment actuator allows for the unintended disclosure of sensitive connection string values, including embedded plaintext credentials, when the `/actuator/env` endpoint is accessed, enabling direct database connection and bypassing application-tier security.
WatchGuard Firebox: Multiple Critical Vulnerabilities
2 TTPsMultiple vulnerabilities in WatchGuard Firebox appliances allow a remote, unauthenticated attacker to execute arbitrary code, cause a denial of service, manipulate or disclose data, and perform Cross-Site Scripting attacks, necessitating immediate patching to mitigate critical risks.
Algernon Server-Side Script Source Disclosure via NTFS Filename Manipulation (CVE-2026-52792)
1 rule 2 TTPsAlgernon, when running on a Windows host, is vulnerable to CVE-2026-52792, allowing an unauthenticated attacker to exploit its `filepath.Ext()` processing to bypass script execution and obtain the raw source code of server-side scripts by appending NTFS-equivalent suffixes (such as `::$DATA`, trailing dot, or trailing space) to the URL, thereby leaking sensitive embedded secrets like database credentials, API keys, and `SetCookieSecret` values, which can lead to authentication bypass.
SimpleSAMLphp SP IdP Bypass Vulnerability (CVE-2026-49284)
3 TTPsSimpleSAMLphp's Service Provider (SP) does not properly enforce the expected Identity Provider (IdP) for an SP-initiated login when a response from a different IdP is received, allowing an attacker to exploit CVE-2026-49284 in multi-IdP deployments to bypass authentication and authorization controls by substituting a lower-trust IdP's response for a higher-trust one, potentially gaining unauthorized access or elevating privileges if application authorization relies on the specific IdP used.
XWiki Pro Macros Remote Code Execution via Excerpt-Include Macro (CVE-2026-44179)
1 TTPA critical vulnerability, CVE-2026-44179, exists in XWiki Pro Macros versions before 1.14.5, allowing remote code execution for any user with page editing rights due to improper escaping of page titles and content processed by the excerpt-include macro, leading to XWiki syntax injection and full compromise of the XWiki installation.
Gogs Remote Code Execution via git rebase --exec Argument Injection (GHSA-qf6p-p7ww-cwr9)
1 rule 5 TTPsGogs, a self-hosted Git service, is vulnerable to a Critical (CVSS 9.9) Remote Code Execution (RCE) via `git rebase --exec` argument injection (GHSA-qf6p-p7ww-cwr9) during pull request merge operations, allowing an authenticated attacker to execute arbitrary commands as the Gogs server process user and achieve full server compromise.
motionEye: LFI → Pass-the-Hash Admin → Unsafe Restore → Unauthenticated Action Execution (RCE)
1 rule 5 TTPsAn attacker can chain multiple vulnerabilities in motionEye, including an arbitrary file read (LFI), a signature bypass using password hashes, and an unsafe configuration restore, to achieve unauthenticated remote code execution (RCE) if the normal user password is unset, or authenticated RCE from a normal user account.
dnsmasq Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in dnsmasq to initiate a Denial of Service attack, disrupting the service's availability.
Dell PowerProtect Data Domain: Multiple Vulnerabilities
6 TTPsMultiple vulnerabilities in Dell PowerProtect Data Domain could allow an attacker to elevate privileges, execute arbitrary code, bypass security controls, perform a Denial of Service attack, conduct Cross-Site Scripting, disclose information, and manipulate files.
OpenAM Pre-auth User Profile Tampering via Anonymous SOAP Authn in Liberty IDPP/Discovery Endpoints (CVE-2026-45052)
2 TTPsAn improper authorization vulnerability (CVE-2026-45052) in OpenAM Community Edition through version 16.0.6 allows an unauthenticated attacker to write persistent entries into the Liberty Discovery store on any user's LDAP entry and a shared root-realm Discovery branch, due to a flaw in the Liberty Web Services SOAP receiver that permits anonymous writes with elevated internal privileges, potentially influencing service routing or security mechanisms if Liberty discovery data is consumed.
i18next-fs-backend Prototype Pollution via Crafted Missing-Key String (CVE-2026-48713)
1 rule 1 TTP 1 CVEUntrusted input can exploit a prototype pollution vulnerability (CVE-2026-48713) in `i18next-fs-backend` versions prior to 2.6.6, particularly via `i18next-http-middleware`'s `missingKeyHandler`, by submitting crafted missing-key strings that leverage the `keySeparator` to write arbitrary properties onto `Object.prototype`, leading to crashes, configuration poisoning, or security bypasses.
golang.org/x/crypto/ssh FIDO/U2F Physical Presence Bypass (CVE-2026-39831)
1 CVEA critical vulnerability (CVE-2026-39831) in the `Verify()` method of the `golang.org/x/crypto/ssh` package (versions prior to 0.52.0) allowed the physical presence check for FIDO/U2F security key types to be bypassed, enabling unattended use of hardware security keys and potentially leading to unauthorized SSH access.
Critical Incus Vulnerability (CVE-2026-48752) Allows Host Arbitrary File Read/Write Leading to RCE
1 rule 6 TTPsA critical vulnerability, CVE-2026-48752, in Incus versions prior to 7.2.0 allows an unauthenticated attacker to achieve arbitrary file read and write on the host system via specially crafted container images or instance backups containing unsanitized symlinks, potentially leading to arbitrary command execution as root.
Incus S3 Multipart Upload Path Traversal Leading to RCE (CVE-2026-48753)
1 rule 3 TTPsThe Incus `incusd` daemon, specifically its S3 protocol multipart upload endpoint in versions prior to 7.1.0, is vulnerable to CVE-2026-48753, a critical path traversal flaw via the `uploadId` parameter, enabling unauthenticated attackers to write arbitrary files to any location on the host system, which can be leveraged for persistent arbitrary command execution.
Deepstream Server Prototype Pollution (CVE-2026-49252) Allows Privilege Escalation
1 rule 1 TTP 1 CVEDeepstream server versions up to and including 10.0.4 are vulnerable to prototype pollution (CVE-2026-49252), a critical flaw allowing any authenticated user with write permissions to any record to potentially escalate their privileges; the vulnerability is patched in version 10.0.5.
Multiple Vulnerabilities in Google Chrome (CVE-2026-13774 through CVE-2026-13895)
5 CVEs 5 IOCsMultiple vulnerabilities, including CVE-2026-13774 through CVE-2026-13895, have been discovered in Google Chrome, allowing an attacker to cause an unspecified security problem on affected Windows, Linux, and macOS systems by exploiting these flaws.
CVE-2026-58593: NodeBB ActivityPub Forgery Vulnerability
1 TTP 1 CVEA critical vulnerability (CVE-2026-58593) in NodeBB's ActivityPub implementation allows a remote attacker to forge posts and direct messages attributed to arbitrary local users, including administrators, by manipulating the 'attributedTo' field in inbound ActivityPub objects.
CVE-2026-58457: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated OS Command Injection
1 rule 2 TTPs 4 IOCsAn unauthenticated OS command injection vulnerability, CVE-2026-58457, exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02), allowing network-adjacent attackers to execute arbitrary shell commands and gain full root-level control by injecting unsanitized input into the `smacfilter_conf` handler's GET parameters within the `commuos` web backend.
CVE-2026-57516: Ray Unsafe Deserialization Leading to RCE
1 TTP 1 CVEAn unsafe deserialization vulnerability (CVE-2026-57516) exists in the WebDataset reader of the Ray framework prior to version 2.56.0, allowing remote attackers to achieve arbitrary code execution on Ray remote workers by supplying a malicious tar archive to the `read_webdataset()` function, which then unconditionally calls `pickle.loads()` on .pkl/.pickle entries or `torch.load()` with `weights_only=False` on .pt/.pth entries, executing arbitrary code.
ClamAV Vulnerabilities Lead to Denial of Service in Cisco Secure Endpoint Products
1 TTP 7 CVEsMultiple vulnerabilities (CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244) in ClamAV, as integrated into Cisco Secure Endpoint Connector, allow a remote attacker to cause a denial of service (DoS) condition by interrupting scanning operations, with a High severity impact on Windows platforms and Medium on Linux/Mac.
Multiple SQL Injection Vulnerabilities in Tenable Nessus (CVE-2026-57587, CVE-2026-57588)
1 TTP 2 CVEs 10 IOCsMultiple SQL injection vulnerabilities, CVE-2026-57587 and CVE-2026-57588, have been discovered in Tenable Nessus versions prior to 10.12.0, allowing an attacker to perform unauthorized access to or manipulation of the underlying database through specially crafted input.
CVE-2026-12957: Amazon Q VS Code Extension Arbitrary Code Execution
1 rule 4 TTPs 5 CVEs 2 IOCsA high-severity vulnerability (CVE-2026-12957) in the Amazon Q Developer Extension for Visual Studio Code allowed attackers to achieve arbitrary code execution and cloud credential theft by automatically loading and executing malicious Model Context Protocol (MCP) server configurations from a `.amazonq/mcp.json` file in a repository without user consent, providing full access to a developer's environment and cloud credentials.
Multiple Vulnerabilities in Squid Proxy (CVE-2026-47729, CVE-2026-50012)
3 TTPs 2 CVEsMultiple vulnerabilities, including CVE-2026-47729 and CVE-2026-50012, have been identified in Squid proxy versions prior to 7.6, allowing an attacker to compromise data confidentiality and cause other unspecified security issues.
CVE-2026-56073: Cap-go OTP Verification Authentication Bypass
2 rules 2 TTPsCap-go versions prior to 12.128.2 are susceptible to an authentication bypass vulnerability (CVE-2026-56073) in OTP verification that allows attackers to manipulate server responses to falsely mark verification successful, leading to unauthorized 2FA enablement and subsequent account takeover.
Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent (CVE-2026-54896)
2 rules 2 TTPsThe `Oj.dump` function in the Ruby `oj` gem, when operating in object mode, is vulnerable to a heap buffer overflow (CVE-2026-54896) when serializing `Exception` objects with an excessively large `:indent` value, leading to memory corruption and potential denial of service or remote code execution.
Arbitrary Host File Read via Symlink Following in containerd CRI Checkpoint Restore (CVE-2026-53489)
3 rules 2 TTPsA high-severity vulnerability (CVE-2026-53489) in containerd's CRI plugin allows an unprivileged attacker to read arbitrary files on the host system by crafting a malicious checkpoint with a symlink that `containerd` follows during `container.log` restoration, enabling data exfiltration via `kubectl logs`.
containerd CRI Checkpoint Restore CDI Annotation Smuggling Vulnerability (CVE-2026-53492)
2 rules 2 TTPsA high-severity vulnerability (CVE-2026-53492) in containerd's CRI implementation allows an attacker with pod creation permissions to smuggle arbitrary Container Device Interface (CDI) annotations during container restoration, bypassing Kubernetes resource allocation and enabling unauthorized device and host mount injection into the restored container.
Hugo security.http.urls Bypass via Alternate IPv4 Encodings (SSRF)
2 rules 3 TTPsA Server-Side Request Forgery (SSRF) vulnerability exists in Hugo versions 0.162.0 through 0.163.0, where the 'security.http.urls' policy designed to deny requests to loopback, internal, and cloud-metadata IPv4 literals could be bypassed as the policy only matched dotted-decimal notation, allowing alternate IPv4 encodings (integer, hex, octal) to pass, enabling build-time server-side requests to internal services and cloud-metadata endpoints when untrusted or data-derived URLs are passed to 'resources.GetRemote'.
Joomla! Component Sponsor Wall 8.0 SQL Injection (CVE-2017-20264)
1 rule 3 TTPsAn unauthenticated SQL injection vulnerability (CVE-2017-20264) in Joomla! Component Sponsor Wall version 8.0 allows attackers to execute arbitrary SQL queries by injecting malicious code into the `wallid` parameter of GET requests to `index.php`, leading to the extraction of sensitive database information such as credentials and configuration data.
CVE-2017-20256 - Joomla Survey Force Deluxe SQL Injection Vulnerability
2 rules 3 TTPsCVE-2017-20256 describes an SQL injection vulnerability in Joomla Survey Force Deluxe 3.2.4 that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'invite' parameter in GET requests, enabling the extraction of sensitive database information.
CVE-2016-20089: Iperius Remote Unquoted Service Path Vulnerability
2 rules 1 TTP 4 IOCsAn unquoted service path vulnerability, CVE-2016-20089, in Iperius Remote version 1.7.0 allows a local attacker to execute arbitrary code with SYSTEM privileges by placing a malicious executable in a specific directory when the legitimate service path contains spaces, enabling privilege escalation upon service restart or system reboot.
DotVVM AuthorizeActionFilter Critical Authorization Bypass
2 rules 2 TTPsA critical authorization bypass vulnerability exists in the `AuthorizeActionFilter` class within the DotVVM framework, failing to perform any authorization checks and allowing attackers to bypass intended access restrictions without specific exploitation techniques, impacting all users relying on `AuthorizeActionFilter` for security. Patched versions include DotVVM 4.3.15, 4.2.11, and 5.0.0-preview09; `AuthorizeAttribute` can be used as a workaround.
undici WebSocket Client Vulnerable to Denial of Service (CVE-2026-12151)
2 rules 1 TTPThe `undici` WebSocket client is vulnerable to CVE-2026-12151, a high-severity denial of service attack where a malicious WebSocket server can stream numerous small continuation frames that bypass `maxPayloadSize` checks, causing unbounded memory growth and exhaustion in affected client processes.
Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server
2 rules 3 TTPsAn unauthenticated attacker can exploit CVE-2026-55882 in Tilt HUD server versions 0.19.5 through 0.37.3, when exposed on a non-loopback address, by accessing the `/debug/pprof` endpoints to read sensitive process memory, including session and API server tokens, and to degrade application performance through prolonged CPU profiling or tracing.
Gitea Security Bypass Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Gitea to bypass existing security measures, potentially leading to unauthorized access, privilege escalation, or data manipulation within the application.
Vim Denial of Service Vulnerability
2 rules 1 TTPA vulnerability in the vim text editor allows a remote, unauthenticated attacker to perform a Denial of Service attack by exploiting a weakness to disrupt the service without requiring prior authentication.
libssh2 Vulnerability: Denial of Service and Information Disclosure
3 rules 2 TTPsA vulnerability in the libssh2 library allows a remote, unauthenticated attacker to perform a Denial of Service (DoS) attack or disclose sensitive information, potentially leading to service disruption or unauthorized data exposure.
Multiple Vulnerabilities in expat XML Parser Library
2 rules 2 TTPsMultiple vulnerabilities have been discovered in the expat XML parser library that can be exploited by a local attacker, potentially leading to a Denial of Service condition or allowing for arbitrary code execution on the affected system.
Google Cloud Platform (GKE containerd): Multiple Vulnerabilities
3 rules 5 TTPsAn authenticated remote attacker can exploit multiple vulnerabilities in Google Cloud Platform, specifically within GKE containerd, to achieve arbitrary code execution, bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.
pgAdmin: Multiple Vulnerabilities Lead to RCE, SQLi, XSS
3 rules 6 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in pgAdmin to achieve arbitrary code execution with user or administrator privileges, bypass security measures, perform SQL Injection and Cross-Site Scripting attacks, redirect users to malicious websites, disclose sensitive information, and manipulate data. This comprehensive set of capabilities allows for significant compromise of system integrity, confidentiality, and potentially availability, posing a high risk to affected environments.
OpenBSD Information Disclosure Vulnerability
3 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in OpenBSD to disclose sensitive information, potentially leading to unauthorized data exposure.
CVE-2026-47647: Critical Privilege Escalation in Microsoft Dynamics 365
2 rules 1 TTP 1 CVECVE-2026-47647 describes a critical improper access control vulnerability in Microsoft Dynamics 365 that allows an authorized attacker to elevate privileges over a network, potentially leading to full compromise of the affected system.
PHP JWT Framework Algorithm Confusion Vulnerability (TOCTOU)
2 rules 2 TTPsA Time-of-Check/Time-of-Use (TOCTOU) vulnerability exists in the `JWSVerifier` and `JWEDecrypter` components of the `web-token/jwt-framework` and `web-token/jwt-library` PHP packages, allowing an attacker to override the integrity-protected `alg` parameter from the unprotected header, leading to authentication bypass and unauthorized access.
spomky-labs/otphp Unbounded Digits Parameter Leads to Denial of Service
2 rules 1 TTPThe spomky-labs/otphp library is vulnerable to a denial of service (GHSA-g7m4-839x-ch6v) where an unbounded 'digits' parameter in an otpauth provisioning URI causes a DivisionByZeroError, leading to unhandled fatal errors in applications trying to generate or verify OTPs.
Drupal Security Advisory AV26-615: Multiple Critical Vulnerabilities
3 rules 7 TTPsOn June 17, 2026, Drupal released critical security advisories (AV26-615) addressing multiple vulnerabilities in Drupal core and several modules including Plotly.js Graphing, Flag attendance field, and Formatter Field, which, if unpatched, could allow remote attackers to compromise affected web servers and sensitive data.
CVE-2026-55204: HAProxy Null Pointer Dereference Leads to Denial of Service
2 rules 1 TTPAn unauthenticated attacker can exploit CVE-2026-55204, a null pointer dereference vulnerability in HAProxy through version 3.4.0, by triggering excessive HPACK dynamic table insertions under memory pressure, causing HAProxy worker processes to crash and resulting in a denial of service.
CVE-2026-55203 HAProxy Integer Overflow in FastCGI Handling
2 rules 3 TTPsAn integer overflow vulnerability (CVE-2026-55203) in HAProxy through version 3.4.0 allows malicious FastCGI backends to desynchronize the FCGI framing parser, leading to request routing errors, response smuggling, or memory safety issues.
Kirby CMS Missing Authorization Vulnerability in /api/site/find (CVE-2026-54005)
2 rules 3 TTPsAn authenticated user can exploit CVE-2026-54005, a high-severity missing authorization vulnerability in Kirby CMS versions <= 4.9.3 and from 5.0.0-alpha.1 to <= 5.4.3, via the `/api/site/find` REST API route to bypass `pages.access` permissions and retrieve sensitive content and metadata from unauthorized pages.
Exploitation of CVE-2026-8024 in ibaPDA and ibaDatCoordinator via Deserialization of Untrusted Data
2 rules 2 TTPsA remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability (CVE-2026-8024) in ibaPDA (versions prior to 8.14.0) or ibaDatCoordinator (versions prior to 4.0.7) to gain full access to the affected systems, potentially leading to arbitrary code execution and system compromise.
Heimdall Proxy Forwarded Header Injection via Unsanitized Host Header
1 rule 1 TTPAttackers can exploit Heimdall proxy versions <= 0.17.16 operating in proxy mode by injecting malicious values into the `Host` HTTP header, leading to the construction of a manipulated `Forwarded` header that can spoof client IP addresses for upstream services, potentially bypassing IP-based access controls.
npm PraisonAI SandboxExecutor Network Isolation Bypass Vulnerability (GHSA-gqmf-56h7-rrpf)
2 rules 3 TTPsThe npm package `praisonai` versions 1.2.3 through 1.7.1 contain a network isolation bypass vulnerability (GHSA-gqmf-56h7-rrpf) in its `SandboxExecutor` component's `network-isolated` mode, allowing non-proxy-aware client commands to establish direct network connections, leading to potential data exfiltration and access to internal services.
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
1 rule 1 TTPA critical command injection vulnerability exists in the `npm:praisonai` package versions >= 1.2.3 and <= 1.7.1, where the `SandboxExecutor`'s `allowedCommands` policy is bypassed by allowing arbitrary shell command chaining after an allowlisted command, leading to remote code execution with the PraisonAI process privileges.
undici TLS Validation Bypass via SOCKS5 ProxyAgent (CVE-2026-9697)
2 rulesA vulnerability in undici's ProxyAgent, when configured with a SOCKS5 proxy, causes the `requestTls` option to be silently dropped. This bypasses user-configured TLS certificate validation settings (e.g., custom CAs), allowing HTTPS connections through the SOCKS5 tunnel to fall back to the Node.js default trust store. This flaw enables Man-in-the-Middle (MITM) attacks, where any publicly-trusted certificate for the target hostname would be accepted, compromising the intended certificate pinning and allowing attackers to read or tamper with HTTPS traffic.
CVE-2026-8863 UEFI Secure Boot Security Feature Bypass Vulnerability
2 rules 1 TTP 1 CVE 11 IOCsAn authorized attacker with local access can exploit CVE-2026-8863, a security feature bypass vulnerability in Windows UEFI, to circumvent Secure Boot and load unauthorized software, potentially enabling persistent rootkit installation.
Multiple Vulnerabilities in Microsoft .Net (CVE-2026-45491, CVE-2026-45591)
2 rules 2 TTPs 2 CVEsMultiple vulnerabilities, CVE-2026-45491 and CVE-2026-45591, have been discovered in Microsoft .Net and ASP.NET Core versions, allowing a remote attacker to cause a denial of service and compromise data integrity across Windows, Linux, and macOS platforms.
Multiple Xen Hypervisor Vulnerabilities Leading to Privilege Escalation, DoS, and Data Confidentiality Compromise
3 rules 3 TTPs 1 CVEMultiple vulnerabilities, including CVE-2025-10263, CVE-2026-42487, CVE-2026-42488, CVE-2026-42489, and CVE-2026-42490, have been discovered in Xen, allowing an attacker to achieve privilege escalation, trigger a remote denial of service, and compromise data confidentiality on vulnerable hypervisor instances.
Multiple Vulnerabilities in Microsoft Office Products (June 2026)
3 rules 4 TTPs 5 CVEsCERT-FR has disclosed 31 vulnerabilities in various Microsoft Office products, including CVE-2026-44803 and CVE-2026-47635, which could allow remote code execution, privilege escalation, and data confidentiality compromise.
Multiple Privilege Escalation Vulnerabilities in FreeBSD (CVE-2026-45257, CVE-2026-49413)
3 rules 4 IOCsMultiple vulnerabilities, including CVE-2026-45257 (kernel out-of-bounds write) and CVE-2026-49413 (Linux compatibility layer memory mapping), exist in FreeBSD branches 14 and 15, allowing a local unprivileged attacker to achieve privilege escalation.
Multiple Critical Vulnerabilities in Fortinet Products Lead to RCE and Data Exposure
2 rules 4 TTPs 3 CVEs 6 IOCsMultiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been discovered across Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox, enabling unauthenticated attackers to achieve remote arbitrary code execution and compromise data confidentiality.
Multiple Critical Vulnerabilities in Siemens SCALANCE Industrial Network Products, Including Unpatched Devices
3 rules 4 TTPs 1 CVEMultiple high-severity vulnerabilities, including CVE-2025-15467, affect various Siemens SCALANCE LPE, M, W, and X series industrial network devices, potentially allowing a remote attacker to achieve arbitrary code execution, provoke a denial of service, or compromise data confidentiality, with some products confirmed to receive no future patches.
Vulnerability in Veeam Backup & Replication Allowing Remote Code Execution (CVE-2026-44963)
3 rules 2 TTPs 1 CVE 2 IOCsA critical remote code execution vulnerability, tracked as CVE-2026-44963, has been discovered in Veeam Backup & Replication versions prior to 12.3.2.4854, which could allow an unauthenticated attacker to execute arbitrary code on affected systems, leading to full compromise of the backup infrastructure and potential data exfiltration or destruction.
Vulnerability in Schneider Electric EcoStruxure IT Data Center Expert Leads to Data Confidentiality Compromise (CVE-2026-8045)
2 rules 3 TTPs 1 CVEA critical vulnerability, CVE-2026-8045, has been identified in Schneider Electric EcoStruxure IT Data Center Expert versions prior to 9.1.2, allowing an attacker to achieve unauthorized access to sensitive data and compromise its confidentiality.
Multiple Vulnerabilities Discovered in SAP Products Including SQLi, XSS, and Policy Bypass
2 rules 5 TTPs 5 IOCsMultiple high-severity vulnerabilities discovered in various SAP products, including SQL injection (SQLi), remote indirect code injection (XSS), and security policy bypasses, could allow unauthenticated attackers to compromise sensitive enterprise systems by June 2026.
CloudCharge Vulnerabilities Allow Charging Station Impersonation and DoS
2 rules 3 TTPs 2 IOCsMultiple vulnerabilities in CloudCharge cloudcharge.se allow attackers to impersonate charging stations, hijack sessions, cause denial of service, and manipulate backend data, impacting energy and transportation sectors.
Pixa Bank 2.0 Unauthenticated SQL Injection Vulnerability
2 rules 1 TTP 1 CVEPixa Bank 2.0 is vulnerable to SQL injection, allowing unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter via POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads, potentially leading to the retrieval of user information such as names, email addresses, and phone numbers from the database.
Suspicious Command Execution via Web Server on Linux
2 rules 3 TTPsIdentifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.
Suspicious Command Execution via Web Server on Linux
3 rules 2 TTPsIdentifies suspicious command executions via a web server on Linux systems, potentially indicating a vulnerability exploitation or remote shell access for persistence.
Multiple Vulnerabilities in NetApp Products
2 rules 5 CVEsMultiple vulnerabilities in NetApp products, including CVE-2023-0482, CVE-2023-20863, CVE-2024-22257, CVE-2025-23367, CVE-2025-48976, CVE-2025-53816, and CVE-2025-53817, could lead to remote denial of service, data confidentiality breaches, and data integrity breaches.
Keycloak Vulnerability Allows Data Confidentiality Breach and Security Policy Bypass
2 rules 1 TTP 1 CVEA vulnerability in Keycloak versions prior to 26.2.14, 26.4.10, and 26.5.5 allows an attacker to cause a breach of data confidentiality and bypass the security policy, as tracked by CVE-2026-2092.
CISA ICS Advisories Address Vulnerabilities in Multiple Vendor Products
2 rulesCISA published ICS advisories between May 25 and 31, 2026, addressing vulnerabilities across various vendors including ABB, CP Plus, Eppendorf, Frontier, Jinan USR IOT, KMW, MacGregor, Schneider Electric, and XCharge, impacting industrial control systems and related applications.
Dell Security Advisory Addressing Multiple Product Vulnerabilities
2 rulesDell released security advisories in May 2026 to address vulnerabilities in PowerEdge Server Chipset Driver, Data Lakehouse, Dell Enterprise SONiC Distribution, and Dell Unity/UnityVSA/Unity XT.
Multiple Vulnerabilities in JetBrains TeamCity
2 rules 3 TTPsMultiple vulnerabilities in JetBrains TeamCity allow an attacker to disclose information, perform a cross-site scripting attack, bypass security measures, and execute arbitrary program code.
Multiple Vulnerabilities in IBM Business Automation Workflow
2 rules 2 TTPsMultiple vulnerabilities in IBM Business Automation Workflow can be exploited by an attacker to bypass security measures, conduct a denial of service attack, disclose information, manipulate files, and conduct a cross-site scripting attack.
Multiple Vulnerabilities in IBM App Connect Enterprise
2 rulesMultiple vulnerabilities in IBM App Connect Enterprise could allow an attacker to bypass security measures, manipulate data, disclose sensitive information, cause a denial-of-service condition, or perform other unspecified attacks.
Notepad++ Vulnerability Allows Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Notepad++ to execute arbitrary program code, potentially leading to system compromise.
SQL Injection Vulnerability in student_management_system_by_php (CVE-2026-10225)
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in raisulislamg4's student_management_system_by_php up to commit 310d950e09013d5133c6b9210aff9444382d16d1, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username argument in login_check.php.
GoClaw OS Command Injection Vulnerability (CVE-2026-10219)
2 rules 1 TTP 1 CVEnextlevelbuilder GoClaw up to 3.11.3 is vulnerable to remote OS command injection via manipulation of the write_file Tool component's FsBridge.WriteFile function (CVE-2026-10219), with a public exploit available.
Open ISES Project 3.30A Unauthenticated Path Traversal Vulnerability
2 rules 1 TTP 1 CVEOpen ISES Project 3.30A is vulnerable to path traversal (CVE-2018-25408), allowing unauthenticated attackers to download arbitrary files by manipulating the filename parameter in the ajax/download.php endpoint, potentially exposing configuration and system files.
CVE-2026-41184 ServiceAccount Token Disclosure via install-cni Container Logs
2 rules 1 TTP 1 CVECVE-2026-41184 is a ServiceAccount token disclosure vulnerability in container logs addressed by a Microsoft security update.
praisonai-platform: Cross-Workspace Label IDOR Vulnerability
2 rules 3 TTPsPraison AI's praisonai-platform is vulnerable to an insecure direct object reference (IDOR) in the label endpoints (CVE-2026-47414), allowing cross-workspace label modification and information disclosure due to improper validation of label and issue IDs.
Ouroboros-AI Remote Code Execution via Malicious .env File
2 rules 1 TTPA remote code execution vulnerability exists in Ouroboros-AI versions prior to 0.39.0, enabling attackers to inject malicious scripts via CLI path variables within a cloned repository's .env file, leading to arbitrary code execution when Ouroboros commands are executed.
AgenticMail API and Core Packages Vulnerabilities
2 rulesMultiple vulnerabilities, including SQL injection and SMTP header injection, have been discovered in AgenticMail API and Core packages, addressed in versions greater than 0.9.31 and 0.9.9 respectively, posing a risk of unauthorized access and control.
SQL Injection Vulnerability in ezsystems ezpublish-legacy dfscleanup
1 rule 1 TTPA SQL injection vulnerability exists in ezpublish-legacy, specifically in the dfscleanup.php script and the `_getFileList` function of the `eZDFSFileHandlerMySQLiBackend` class, allowing an attacker with local shell access to potentially expose sensitive data such as user credentials.
Multiple Vulnerabilities in Elastic Kibana
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities in Elastic Kibana allow for privilege escalation, remote denial of service, data breach, server-side request forgery (SSRF), and cross-site scripting (XSS).
Multiple Vulnerabilities in OpenClaw Allow for Privilege Escalation, Code Execution, and SSRF
2 rules 4 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in OpenClaw to bypass security mechanisms, gain elevated privileges, disclose information, manipulate configurations, execute arbitrary commands or code, and attack internal systems via SSRF.
Red Hat Enterprise Linux Flatpak Multiple Vulnerabilities Allow Code Execution and File Deletion
2 rules 1 TTPAn authenticated attacker can exploit multiple vulnerabilities in the Flatpak package of Red Hat Enterprise Linux to execute arbitrary program code and delete files.
Mautic SQL Injection Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Mautic to perform a SQL injection attack, potentially leading to unauthorized data access or modification.
Multiple Vulnerabilities in Check Point Security Gateway
2 rules 3 TTPsMultiple vulnerabilities exist in Check Point Security Gateway that could be exploited by an attacker to perform a denial of service attack, disclose information, and perform a SQL injection attack.
Red Hat OpenShift Tempo Vulnerabilities Allow Remote Exploitation
1 rule 3 TTPsMultiple vulnerabilities in Red Hat OpenShift Tempo allow an unauthenticated remote attacker to bypass security measures, disclose sensitive information, manipulate data, or cause a denial of service condition.
CVE-2026-46834 - Oracle Database Server Net Service Denial of Service
2 rules 1 TTP 1 CVECVE-2026-46834 is a vulnerability in the Net Service component of Oracle Database Server versions 23.4.0 to 23.26.2 that allows an unauthenticated attacker with network access via TLS to cause a denial-of-service (DoS) condition.
CVE-2026-46826 - Oracle Payroll Vulnerability Allows Takeover
2 rules 2 TTPs 1 CVECVE-2026-46826 is a vulnerability in Oracle Payroll within Oracle E-Business Suite, where a low-privileged attacker can achieve a system takeover via network access over HTTPS.
CVE-2026-35266: Oracle REST Data Services Vulnerability Allows Unauthorized Data Access and Modification
2 rules 1 CVEA vulnerability exists in Oracle REST Data Services versions 24.2.0 to 26.1.0, where a low-privileged attacker with network access via HTTPS can, with human interaction, gain unauthorized data access, modification, and cause a partial denial of service.
CVE-2026-46840 - Oracle REST Data Services Takeover Vulnerability
2 rules 1 CVECVE-2026-46840 is a critical vulnerability in Oracle REST Data Services (ORDS) that allows an unauthenticated attacker with network access to achieve complete takeover of the service, potentially impacting additional products due to scope change.
CVE-2026-46822 - Oracle iAssets Remote Code Execution Vulnerability
2 rules 1 CVECVE-2026-46822 is a vulnerability in Oracle iAssets within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15, allowing a low-privileged attacker with network access via HTTP to compromise the application, potentially impacting other products within the environment.
CVE-2026-46775 - Oracle REST Data Services Takeover via Network Access
2 rules 1 CVECVE-2026-46775 is a critical vulnerability in Oracle REST Data Services (Core component) versions 24.2.0-26.1.0, allowing a low-privileged attacker with network access via HTTPS to achieve complete takeover of the service and potentially impact other products.
Tanium Connect Multiple Vulnerabilities
3 rulesTanium released security advisories addressing vulnerabilities in Connect versions prior to Update 25 (v5.26.191), Update 19 (v5.29.237), and Update 9 (v5.37.140), potentially leading to unauthorized access and data compromise.
OpenBao Cross-Namespace Lease Revocation via Legacy sys/revoke Path
2 rules 1 TTPOpenBao versions up to 2.5.3 allow cross-namespace lease revocation by exploiting legacy sys/revoke endpoints, potentially leading to unauthorized credential access and denial of service.
phpMyFAQ Unauthenticated Password Reset Vulnerability (CVE-2026-35676)
2 rules 1 TTP 1 CVEphpMyFAQ before 4.1.3 is vulnerable to an unauthenticated password reset, allowing attackers to change account passwords without token validation by sending crafted PUT requests to the /api/index.php/user/password/update endpoint.
Zimbra Security Advisory Addresses Vulnerabilities in Zimbra Daffodil
2 rulesZimbra released a security advisory on May 28, 2026, addressing unspecified vulnerabilities in Zimbra Daffodil versions prior to v10.1.17, urging users to apply necessary updates.
Multiple Vulnerabilities in Veeam Products Allow Remote Code Execution
2 rules 1 TTP 1 CVEMultiple vulnerabilities in Veeam ONE and Service Provider Console allow remote code execution (CVE-2026-32998) and an unspecified security issue, potentially leading to complete system compromise.
Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass
2 rules 2 TTPs 5 CVEsMultiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.
Langflow Multiple Vulnerabilities Allow Remote Code Execution and Denial of Service
2 rules 2 TTPsMultiple vulnerabilities in Langflow allow a remote, anonymous attacker to execute arbitrary code or cause a denial of service.
Gitea Unauthenticated Container Registry Access (CVE-2026-27771)
2 rules 1 TTP 1 CVE 2 IOCsA vulnerability in Gitea's built-in container registry (CVE-2026-27771) allows unauthenticated attackers to pull private container images, potentially exposing source code, secrets, and production infrastructure details, affecting over 30,000 deployments.
Multiple Vulnerabilities in Jenkins Plugins
3 rules 4 TTPsMultiple vulnerabilities exist in Jenkins Plugins that could allow an attacker to disclose information, manipulate files, conduct cross-site scripting attacks, execute arbitrary code, and bypass security measures.
KubeVirt virt-exportserver Path Traversal Vulnerability (CVE-2026-9804)
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in KubeVirt's virt-exportserver component, where an attacker with namespace-level access can exploit this flaw by creating a symbolic link within an exported filesystem PVC to read arbitrary files from the exporter pod, leading to information disclosure.
Apache Tika Vulnerability Allows Information Disclosure or Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Apache Tika to read sensitive data or trigger malicious requests to internal resources or third-party servers.
VMware Tanzu Spring Security Vulnerability Allows File Manipulation
2 rules 1 TTPA local attacker can exploit a vulnerability in VMware Tanzu Spring Security to manipulate files, potentially leading to privilege escalation.
Multiple Vulnerabilities in Vim Could Lead to Arbitrary Code Execution or Denial of Service
2 rules 3 TTPsMultiple vulnerabilities in Vim could allow an attacker to execute arbitrary code or cause a denial of service condition.
CVE-2026-46072 ntfs3 Buffer Boundary Check Vulnerability
2 rules 1 CVECVE-2026-46072 is a buffer boundary check vulnerability in ntfs3 affecting an unspecified Microsoft product, requiring further investigation upon patch application to understand exploitation vectors and develop detections.
CVE-2026-45842: Unspecified Vulnerability in Microsoft Products
2 rules 1 TTP 1 CVECVE-2026-45842 is an unspecified vulnerability affecting Microsoft products, requiring further investigation to determine the specific attack vector, impact, and affected systems.
CVE-2026-44899 Mistune Image Directive CSS Injection Vulnerability
2 rules 1 CVECVE-2026-44899 is a CSS Injection vulnerability in the Mistune Image Directive, potentially allowing for malicious CSS injection if user-supplied content is not properly sanitized.
CVE-2025-71305 Published - Insufficient DP MST VCPI Protection
2 rules 1 CVEMicrosoft published CVE-2025-71305, addressing a vulnerability related to insufficient protection against zero VCPI values in DisplayPort Multi-Stream Transport (MST), although specifics on exploitation and impact are not detailed in the provided source.
CVE-2026-45843 slip: bound decode() vulnerability
1 rule 1 CVECVE-2026-45843 is a Microsoft vulnerability with unspecified details at the time of this brief.
CVE-2026-44844 eml_parser Recursion Denial-of-Service
2 rules 1 TTP 1 CVECVE-2026-44844 is a denial-of-service vulnerability in Microsoft's eml_parser due to recursion in nested message/rfc822 attachments, potentially causing a service outage.
CVE-2026-45991 UDF Partition Descriptor Append Bookkeeping Vulnerability
2 rules 1 CVECVE-2026-45991 is a security vulnerability affecting a Microsoft product, related to UDF partition descriptor append bookkeeping.
Deno TLS Plaintext Injection Vulnerability
2 rules 1 TTPA vulnerability in Deno's Node.js tls compatibility layer (versions 2.0.0 to 2.7.7) allows a network attacker to intercept and tamper with plaintext application data transmitted over a supposedly TLS-protected connection when `autoSelectFamily` is enabled and the initial connection attempt fails, leading to potential information disclosure and data manipulation.
Google Chrome Security Update Released
2 rulesGoogle released a security update on May 27, 2026, to address vulnerabilities in Chrome for Desktop versions prior to 0.7778.216/217 for Windows, 148.0.7778.215/216 for Mac, and 148.0.7778.215 for Linux, requiring users to apply the necessary updates to mitigate potential exploitation.
Daemon Tools Lite Embedded Malicious Code Vulnerability
2 rules 1 CVEDaemon Tools Lite contains an unspecified vulnerability (CVE-2026-8398) that has a high impact on confidentiality, integrity, and availability, requiring immediate mitigation or discontinuation of use.
Multiple Vulnerabilities in Veeam Backup & Replication
2 rules 1 TTPMultiple vulnerabilities in Veeam Backup & Replication prior to version 13.0.2.29 allow an attacker to cause privilege escalation and compromise data integrity.
Multiple Vulnerabilities in Symfony Framework
2 rules 1 TTPMultiple vulnerabilities in Symfony, including SSRF, XSS, and security policy bypass, can be exploited by an attacker to compromise the application.
Multiple Vulnerabilities in Check Point Products
2 rules 3 TTPs 4 CVEsMultiple vulnerabilities in Check Point Security Gateways and Spark Firewalls allow for remote denial of service, data confidentiality breaches, and data integrity compromise.
Multiple Vulnerabilities in Joomla! Allow Privilege Escalation and Data Breaches
2 rules 2 TTPs 5 CVEsMultiple vulnerabilities in Joomla! versions before 5.4.6 and 6.x before 6.1.1 can allow attackers to perform privilege escalation, compromise data confidentiality, perform cross-site scripting (XSS), and conduct cross-site request forgery (CSRF) attacks.
Kaspersky Anti Targeted Attack Platform Multiple XSS Vulnerabilities
2 rules 2 TTPs 2 CVEsMultiple vulnerabilities have been discovered in Kaspersky Anti Targeted Attack Platform versions prior to 7.1.7, allowing an attacker to cause a remote cross-site scripting (XSS) vulnerability, tracked as CVE-2026-28348 and CVE-2026-28350.
Multiple Vulnerabilities in Apple macOS Sequoia, Sonoma, and Tahoe
2 rules 5 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Apple macOS to gain root privileges, execute arbitrary code, cause a denial-of-service condition, disclose confidential information, modify data, or bypass security measures.
Multiple Vulnerabilities in Oracle MySQL
2 rulesA remote, anonymous, or authenticated attacker can exploit multiple vulnerabilities in Oracle MySQL to compromise confidentiality, integrity, and availability.
Multiple Vulnerabilities in IBM DB2
2 rules 3 TTPsMultiple vulnerabilities in IBM DB2 allow a remote, authenticated, or local attacker to disclose information, bypass security measures, or cause a denial of service.
Multiple Vulnerabilities in CODESYS
3 rules 2 TTPsMultiple vulnerabilities in CODESYS could allow an attacker to escalate privileges, manipulate data, or cause a denial of service.
CVE-2026-39832: Agent Constraints Dropped When Forwarding Keys in golang.org/x/crypto/ssh/agent
2 rules 1 CVECVE-2026-39832 describes a vulnerability where agent constraints are dropped when forwarding keys in golang.org/x/crypto/ssh/agent, potentially leading to unauthorized access.
GnuTLS Certificate Spoofing Vulnerability (CVE-2026-42012)
2 rules 1 TTP 1 CVECVE-2026-42012 describes a vulnerability in GnuTLS where a remote attacker can spoof legitimate services or intercept sensitive information by presenting a specially crafted certificate with URI or SRV SANs, causing the certificate validation process to incorrectly fall back to checking DNS hostnames against the Common Name (CN).
Multiple Critical Vulnerabilities in Ubiquiti UniFi OS
2 rules 1 TTP 5 CVEs 1 IOCUbiquiti has addressed multiple critical vulnerabilities including CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, and CVE-2026-33000 in UniFi OS, which could allow remote attackers to make unauthorized system changes, access sensitive files, disclose information, or execute arbitrary commands on vulnerable systems.
CVE-2026-9170: IBM WebSphere Application Server and Liberty Improper Input Validation Vulnerability
2 rules 2 TTPs 1 CVEIBM WebSphere Application Server and WebSphere Liberty versions 8.5 and 9.0 are vulnerable to denial of service and potential remote code execution due to improper input validation as described in CVE-2026-9170.
ABB PPT30 Operating System Vulnerability (CVE-2025-11482)
1 rule 1 TTP 1 CVEA vulnerability, CVE-2025-11482, exists in ABB's PPT30 Operating System related to handling concurrent connections in the PPT30 OPC-UA Server, affecting versions prior to 1.8.0.
SQL Injection Vulnerability in StudentManagementSystem
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in the /success.php file of yashpokharna2555 StudentManagementSystem, allowing remote attackers to execute arbitrary SQL commands by manipulating the User argument.
Splinterware System Scheduler Pro 5.12 Privilege Escalation via Insecure Permissions (CVE-2018-25359)
2 rules 1 TTP 1 CVESplinterware System Scheduler Pro 5.12 is vulnerable to privilege escalation (CVE-2018-25359) due to insecure file permissions, allowing low-privilege users to replace the service executable with a malicious one, leading to arbitrary code execution as LocalSystem.
CVE-2026-9452 FoundDream miniclawd Remote Command Injection
2 rules 1 TTP 1 CVEA command injection vulnerability exists in FoundDream miniclawd within the ExecTool.execute function in /src/tools/exec.ts, which can be triggered remotely, allowing attackers to execute arbitrary OS commands.
CVE-2026-40411: Azure Virtual Network Gateway Improper Input Validation RCE
2 rules 1 TTP 1 CVECVE-2026-40411 describes an improper input validation vulnerability in Azure Virtual Network Gateway that allows an authorized attacker to execute code over a network.
itsourcecode Electronic Judging System SQL Injection Vulnerability (CVE-2026-9383)
2 rules 1 TTP 1 CVECVE-2026-9383 is a SQL injection vulnerability in itsourcecode Electronic Judging System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username parameter in the /intrams/admin/login.php file.
NousResearch hermes-agent OS Command Injection Vulnerability (CVE-2026-9367)
2 rules 1 TTP 1 CVENousResearch hermes-agent up to version 5157f5427f19488b31c6fdebbacd15d798ce7f63 is vulnerable to OS command injection (CVE-2026-9367) in the `detect_dangerous_command` function allowing a remote attacker to execute arbitrary commands.
Online Art Gallery Shop 1.0 SQL Injection Vulnerability (CVE-2026-9364)
2 rules 2 TTPs 1 CVEA SQL injection vulnerability (CVE-2026-9364) exists in projectworlds Online Art Gallery Shop version 1.0, specifically in the /admin/adminHome.php file, which can be exploited remotely by manipulating the social_linked argument, potentially leading to unauthorized data access or modification.
Joomla! Ek Rishta Component 2.10 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEJoomla! Component Ek Rishta version 2.10 is vulnerable to SQL injection allowing unauthenticated attackers to manipulate database queries by injecting SQL code via the cid parameter through GET requests to the user_detail view, potentially extracting sensitive database information.
Mattermost File Access Vulnerability (CVE-2026-3473)
1 rule 1 TTP 1 CVEMattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, allowing an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.
Spring AI Data Integrity Vulnerability (CVE-2026-41863)
2 rulesA data integrity vulnerability exists in Spring AI versions 1.1.x before 1.1.7, potentially allowing an attacker to compromise data integrity, as identified by CVE-2026-41863.
Multiple Vulnerabilities in Roundcube Webmail
2 rules 3 TTPsMultiple vulnerabilities in Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1 could lead to remote code execution, data confidentiality breaches, data integrity breaches, SSRF, and SQL Injection.
CPython Unspecified Vulnerability (CVE-2026-8328)
2 rules 1 CVEAn unspecified vulnerability in CPython, tracked as CVE-2026-8328, allows an attacker to cause an unspecified security issue.
Multiple Vulnerabilities in Devolutions Server
2 rulesMultiple vulnerabilities in Devolutions Server could allow an attacker to bypass security measures, disclose information, and manipulate files.
Multiple Vulnerabilities in PuTTY Allow for DoS, Data Manipulation, and Spoofing
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in PuTTY to perform a denial of service attack, manipulate data, and possibly carry out spoofing attacks.
Multiple Vulnerabilities in Roundcube Webmail
2 rules 3 TTPsMultiple vulnerabilities in Roundcube Webmail allow an attacker to perform SQL injection attacks, bypass security measures, manipulate data, disclose confidential information, obtain extended privileges, execute arbitrary code, or perform cross-site scripting attacks.
Microsoft 365 Copilot Multiple Vulnerabilities
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Microsoft 365 Copilot to execute arbitrary program code and disclose confidential information.
LiteLLM Multiple Vulnerabilities Allow Privilege Escalation
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in LiteLLM to escalate their privileges.
CISA ICS Security Advisories Address Vulnerabilities in Multiple Vendor Products
2 rulesCISA published ICS advisories addressing vulnerabilities in products from ABB, Hitachi Energy, Kieback & Peter, ScadaBR, Siemens, and ZKTeco, recommending mitigations and updates.
Nezha Monitoring RoleMember SSRF with Full Response Body Reflection
2 rules 3 TTPsNezha Monitoring is vulnerable to a server-side request forgery (SSRF) vulnerability, where a low-privilege RoleMember user can call notification routes and send HTTP requests to a user-controlled URL, with the entire response body reflected back to the caller, potentially exposing intranet resources and causing denial of service.
HPE Telco Universal SLA Management Multiple Vulnerabilities
2 rulesHPE published a security advisory addressing multiple unspecified vulnerabilities in HPE Telco Universal SLA Management version 4.6 and prior, prompting users to apply necessary updates.
Debian LTS Linux Kernel Vulnerability Allows Privilege Escalation and Data Breach
3 rules 1 TTPA vulnerability in the Debian LTS Linux kernel allows attackers to perform privilege escalation and breach data confidentiality, specifically affecting Debian 11 bullseye versions prior to 5.10.251-5 and 6.1.172-1~deb11u1; tracked as CVE-2026-46333.
Multiple Vulnerabilities in Tenable Sensor Proxy
1 rule 1 TTP 5 CVEsMultiple vulnerabilities in Tenable Sensor Proxy versions prior to 1.4.0 could allow a remote attacker to cause a denial of service, data confidentiality breaches, and other unspecified security impacts.
SPIP Security Policy Bypass Vulnerability
2 rules 1 TTPA vulnerability in SPIP versions prior to 4.4.15 allows an attacker to bypass the security policy, potentially leading to unauthorized actions.
IBM App Connect Enterprise Multiple Vulnerabilities
2 rules 3 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to execute arbitrary program code, manipulate data, conduct cross-site scripting attacks, disclose confidential information, or cause a denial-of-service condition.
XWiki Multiple Vulnerabilities Allow File Manipulation and Information Disclosure
2 rules 2 TTPsAn authenticated remote attacker can exploit multiple vulnerabilities in XWiki to manipulate files and disclose information.
AudioIgniter WordPress Plugin Vulnerable to Insecure Direct Object Reference (CVE-2026-8679)
2 rules 1 TTPThe AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference (CVE-2026-8679) in versions up to 2.0.2, allowing unauthenticated attackers to view track metadata of any playlist, regardless of its status.
Roundcube Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Roundcube to execute arbitrary program code, potentially leading to complete system compromise.
Exim Vulnerability Allows SQL Injection
2 rules 1 TTPA vulnerability in Exim allows an attacker to perform a SQL injection attack, potentially leading to unauthorized data access or modification.
Multiple Vulnerabilities in PHP Allow for Information Disclosure, DoS, SSRF, and Unknown Impacts
2 rules 3 TTPsA remote attacker can exploit multiple vulnerabilities in PHP to disclose information, cause a denial-of-service condition, perform a Server-Side Request Forgery (SSRF) attack, or achieve unknown impacts.
Kemp LoadMaster and Progress Software MOVEit WAF: Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in Kemp LoadMaster and Progress Software MOVEit WAF could allow an attacker to execute arbitrary code or circumvent security measures.
PowerDNS Authoritative Server Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in PowerDNS Authoritative Server allow an attacker to disclose information, manipulate data, and cause a denial-of-service condition.
Prototype Pollution Vulnerability in @nevware21/ts-utils Library (CVE-2026-46681)
2 rules 2 TTPsThe `_copyProps` function in the `@nevware21/ts-utils` library is vulnerable to prototype pollution due to the use of `for...in` without proper `hasOwnProperty` checks, allowing attackers to modify object prototypes by injecting properties like `__proto__`.
@hulumi/drift Orphan Reconciler Accepts Externally Supplied Execute Plans
2 rules@hulumi/drift versions before 1.3.2 could accept externally supplied execute plans without sufficient provenance checks, allowing unsafe reconciliation input to be treated as trusted; upgrade to version 1.3.2 or later to resolve this vulnerability.
@hulumi/policies: CIS 1.16 Admin Policy Bypass Vulnerability
2 rules 1 TTP@hulumi/policies versions before 1.3.2 improperly inspect inline and attached IAM policies, potentially allowing admin-equivalent policy paths to bypass the administrator-policy guardrail, resulting in a CIS 1.16 admin policy bypass.
Open ISES Tickets Hardcoded MySQL Credentials Vulnerability (CVE-2026-48241)
2 rules 1 TTP 1 CVEOpen ISES Tickets before version 3.44.2 contains hardcoded MySQL database credentials in loader.php, allowing an attacker with access to the source code or the file on a deployed installation to read the username, password, and database name and use them to connect to the database (CVE-2026-48241).
ConnectWise Automate Vulnerability Addressed in Security Update
2 rulesConnectWise released a security advisory addressing a vulnerability in ConnectWise Automate versions prior to 2026.5, prompting users to apply the necessary updates.
ABB B&R PCs Vulnerable to Multiple Attacks via EDK2 Network Package
2 rules 1 TTP 2 CVEsMultiple vulnerabilities in ABB B&R PCs, specifically within the EDK2 Network Package, can be exploited by a network attacker to execute remote code, initiate DoS attacks, conduct DNS cache poisoning, or extract sensitive information (CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237).
Trend Micro Security Advisory Addressing Apex One and Vision One Vulnerabilities
2 rulesTrend Micro released a security advisory addressing vulnerabilities in Apex One (on-premise), Apex One as a service, and Trend Vision One Endpoint, prompting users to apply necessary updates to mitigate potential risks.
Multiple Vulnerabilities in Progress MOVEit Automation
2 rules 2 TTPs 4 CVEsMultiple vulnerabilities in Progress MOVEit Automation allow for remote denial of service, security policy bypass, and unspecified security issues.
Budibase Multiple Vulnerabilities
2 rules 5 TTPsMultiple vulnerabilities in Budibase could be exploited by an attacker to gain administrative privileges, bypass security measures, perform cross-site scripting attacks, manipulate data, or disclose confidential information.
Actively Exploited Vulnerabilities in Sparx Pro Cloud Server and Enterprise Architect
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities, including a critical authentication bypass (CVE-2026-42097), affect Sparx Systems Pro Cloud Server and Enterprise Architect, potentially leading to remote code execution and data compromise; active exploitation is likely given available PoCs.
MongoDB Compass Vulnerability Allows File Manipulation and Potential Code Execution
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in MongoDB Compass to manipulate files and potentially execute arbitrary code.
vllm Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in vllm to achieve arbitrary code execution.
vllm Vulnerability Allows Information Disclosure and DoS
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in vllm to disclose information or cause a denial-of-service condition.
Multiple Vulnerabilities in Trend Micro Products Including TrendAI Apex One
2 rules 1 TTP 1 IOCMultiple vulnerabilities exist in Trend Micro products, including TrendAI Apex One, potentially allowing authenticated attackers to tamper with files, distribute malicious code, or escalate privileges; CVE-2026-34926 is being actively exploited.
Splunk Releases Security Advisory Addressing Multiple Products
2 rulesSplunk released security advisories on May 20, 2026, addressing vulnerabilities in Splunk User Behavior Analytics, AppDynamics Agents, Universal Forwarder, Enterprise, Cloud Platform, and AI Toolkit, prompting users to apply necessary updates.
Cisco Secure Workload Unauthorized API Access Vulnerability
1 ruleCisco Secure Workload versions 3.9 and prior, versions prior to 3.10.8.3, and versions prior to 4.0.3.17 are vulnerable to unauthorized API access, requiring an urgent update.
Microsoft Defender Denial of Service Vulnerability (CVE-2026-45498)
2 rules 1 TTP 1 CVECVE-2026-45498 is a denial-of-service vulnerability in Microsoft Defender that could disrupt endpoint protection capabilities, requiring timely mitigation per vendor instructions.
FreePBX Security Advisories for Security-Reporting Module Vulnerabilities
2 rules 1 TTPFreePBX released security advisories addressing authenticated SQL injection and local file inclusion vulnerabilities in the Security-Reporting cdr and dashboard modules for FreePBX 16 and 17.
Multiple Vulnerabilities in Mozilla Products Lead to Potential RCE and Privilege Escalation
2 rules 3 TTPs 4 CVEsMultiple vulnerabilities in Mozilla Firefox ESR, Firefox, Firefox for iOS, and Thunderbird products can lead to arbitrary code execution, privilege escalation, and remote denial of service.
Multiple Vulnerabilities in Suricata Network Threat Detection Engine
2 rules 2 TTPsMultiple vulnerabilities in Suricata versions before 8.0.5 and 7.0.16 could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.
Multiple Vulnerabilities in Symfony Framework
3 rules 1 TTPMultiple vulnerabilities in Symfony, including CVE-2026-45070, CVE-2026-45077, CVE-2026-45304, CVE-2026-45305, CVE-2026-45753, CVE-2026-45754, CVE-2026-45755, CVE-2026-45756, CVE-2026-46626, and CVE-2026-47212, can lead to remote denial of service, cross-site scripting (XSS), and cross-site request forgery (CSRF) attacks.
Multiple Vulnerabilities in Docker Desktop Allow Remote Code Execution
2 rules 1 TTPMultiple vulnerabilities in Docker Desktop versions prior to 4.71.0 allow a remote attacker to execute arbitrary code.
Squid Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Squid to execute arbitrary program code, leading to potential system compromise.
Multiple Vulnerabilities in Rsync
2 rules 4 TTPsMultiple vulnerabilities in Rsync could be exploited by an attacker to elevate privileges, disclose information, bypass security precautions, and perform a denial of service attack.
Multiple Vulnerabilities in Atlassian Products
2 rules 4 TTPsMultiple vulnerabilities exist in Atlassian products including Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira which could lead to arbitrary code execution, denial of service, information disclosure, cross-site scripting, and security bypass.
Multiple Vulnerabilities in Mozilla Firefox and Thunderbird
2 rules 5 TTPsMultiple vulnerabilities in Mozilla Firefox, Firefox ESR, and Thunderbird could allow a remote attacker to execute arbitrary code, disclose information, bypass security restrictions, deceive the user, escalate privileges, or cause a denial-of-service condition.
Vaultwarden Vulnerabilities Allow Privilege Escalation and Information Disclosure
2 rules 3 TTPsMultiple vulnerabilities in Vaultwarden allow a remote, anonymous attacker to gain user privileges and disclose sensitive information.
Multiple Vulnerabilities in Nvidia GPU Display Drivers
2 rules 3 TTPsMultiple vulnerabilities in Nvidia GPU Display Drivers allow a local attacker to escalate privileges, manipulate data, disclose information, cause a denial of service, or execute code.
Multiple Vulnerabilities in Mozilla Firefox and Thunderbird
2 rules 2 TTPsMultiple vulnerabilities exist in Mozilla Firefox, Firefox ESR, and Thunderbird that could allow a remote attacker to execute arbitrary code, disclose sensitive information, bypass security measures, or conduct cross-site scripting or spoofing attacks.
CVE-2026-7637 - Boost Plugin for WordPress PHP Object Injection
2 rules 1 TTP 1 CVEThe Boost plugin for WordPress is vulnerable to PHP Object Injection (CVE-2026-7637) due to deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie, potentially leading to arbitrary code execution if a suitable property-oriented programming (POP) chain is present.
CVE-2026-45585: Windows BitLocker Security Feature Bypass Vulnerability ('YellowKey')
2 rulesCVE-2026-45585 is a security feature bypass vulnerability in Windows BitLocker, known as 'YellowKey', for which a public proof of concept exists, prompting Microsoft to release mitigation guidance prior to a security update.
Atlassian Security Advisory Addressing Multiple Vulnerabilities
2 rulesAtlassian released a security advisory on May 19, 2026, addressing vulnerabilities in multiple products including Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira, and Jira Service Management Data Center and Server.
Angular platform-server SSRF via Hostname Hijacking (CVE-2026-46417)
2 rules 1 TTPA server-side request forgery (SSRF) vulnerability exists in `@angular/platform-server` due to improper processing of the request URL by the server-side rendering engine, allowing attackers to redirect relative HTTP requests to attacker-controlled servers, potentially exposing internal APIs or metadata services; patch CVE-2026-46417 immediately.
Dell Security Advisory Addresses Vulnerabilities in Multiple Products
2 rulesDell published security advisories between May 11 and 17, 2026, addressing vulnerabilities in Dell Enterprise Sonic Distribution, Dell Live Optics Collector, Intel 800 Series Ethernet Adapters, Dell PowerEdge with AMD Graphics, and PowerScale InsightIQ, prompting users to apply necessary updates.
Bandit HTTP/1 Chunked Request DoS Vulnerability
1 rule 1 TTP 1 CVEBandit's HTTP/1 chunked-body reader silently drops the request size cap, leading to excessive memory buffering. An unauthenticated attacker can crash Bandit-fronted Phoenix/Plug applications by sending a single 'Transfer-Encoding: chunked' request to any URL, causing BEAM memory exhaustion and a denial-of-service.
Mozilla Firefox Security Updates Released
1 ruleMozilla released security updates on May 19, 2026, addressing vulnerabilities in Firefox versions prior to 151, Firefox ESR versions prior to 115.36, and Firefox ESR versions prior to 140.11.
Kopia RCE via SSH ProxyCommand Injection (CVE-2026-45695)
2 rules 1 TTPKopia's HTTP server, when started without `--without-password`, accepts unauthenticated requests which can lead to arbitrary command execution as the Kopia process user via `-oProxyCommand` in `sshArguments` for SFTP backends with `externalSSH: true`. An attacker-supplied storage configuration is forwarded to `blob.NewStorage`, and the `sshArguments` are split on spaces and passed directly to `exec.CommandContext("ssh")`, resulting in command injection.
Critical Vulnerability in HPE Unified OSS Console (UOC)
1 rule 1 TTPHPE published a security advisory (AV26-477) addressing a critical vulnerability in HPE Unified OSS Console (UOC) version 3.1.20 and prior, potentially leading to unauthorized access and control of network operations.
libcrux-ml-dsa Signature Verification Bypass Vulnerability
2 rulesThe AVX2 implementation of ML-DSA verification in libcrux-ml-dsa mishandles an edge case in the `use_hint` function, potentially allowing an attacker to craft an invalid signature that is accepted by the verifier if the AVX2 implementation is used.
ABB CoreSense HM and CoreSense M10 Path Traversal Vulnerability (CVE-2025-3465)
2 rules 1 TTP 1 CVEA path traversal vulnerability (CVE-2025-3465) in ABB CoreSense HM and CoreSense M10 allows unauthenticated local users to access restricted directories, potentially leading to system compromise and information exposure; patch to CoreSense™ HM v2.3.4 and CoreSense™ M10 v1.4.1.31.
Kieback & Peter DDC Building Controllers Cross-Site Scripting Vulnerability (CVE-2026-4293)
2 rules 1 TTPA cross-site scripting vulnerability, CVE-2026-4293, exists in multiple Kieback & Peter DDC Building Controllers that could allow an attacker to take control of the victim's browser.
HAXcms createSite SSRF Enables Arbitrary File Read
2 rules 1 TTP 2 IOCsHAXcms is vulnerable to Server-Side Request Forgery (SSRF) via the createSite endpoint, allowing an authenticated user to supply arbitrary URLs or local file paths, which are fetched server-side without validation and written to a web-accessible directory, enabling arbitrary file read, internal network access, and cloud credential exposure; this vulnerability is tracked as CVE-2026-46393.
Multiple Vulnerabilities in Atlassian Jira
1 rule 1 TTPMultiple vulnerabilities in Atlassian Jira could allow an attacker to execute arbitrary code, manipulate and disclose data, conduct cross-site scripting attacks, or cause a denial-of-service condition.
Multiple Vulnerabilities in GLPI Allow Data Confidentiality Breach and Security Policy Bypass
2 rules 2 TTPs 1 CVEMultiple vulnerabilities in GLPI versions prior to 11.0.7 and 10.0.25 allow an attacker to compromise data confidentiality and bypass security policies.
Multiple Vulnerabilities in Mattermost Products
2 rulesMultiple unspecified vulnerabilities in Mattermost Desktop App and Mattermost Server allow an attacker to cause an unspecified security issue.
Multiple Vulnerabilities in Docker Allow Privilege Escalation and DoS
2 rules 3 TTPsMultiple vulnerabilities in Docker allow a local attacker to execute arbitrary code with administrator privileges, cause a denial-of-service condition, or manipulate data.
Multiple Vulnerabilities in TYPO3 Extensions
2 rules 1 TTPMultiple vulnerabilities in TYPO3 extensions allow an attacker to execute arbitrary program code, conduct SQL injection attacks, disclose information, and circumvent security measures.
Multiple Vulnerabilities in Apache OFBiz
2 rules 9 TTPsMultiple vulnerabilities in Apache OFBiz could allow an attacker to execute arbitrary code, circumvent security measures, manipulate data, disclose confidential information, or conduct cross-site scripting attacks.
Multiple Vulnerabilities in Red Hat Build of Quarkus
2 rules 2 TTPsAn authenticated or unauthenticated remote attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Quarkus to perform a denial of service attack, disclose sensitive information, or manipulate data.
CUPS Multiple Vulnerabilities Allow Arbitrary Code Execution
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in CUPS to execute arbitrary program code with the privileges of the service and to disclose information.
Multiple Vulnerabilities in Red Hat Enterprise Linux and OpenShift Grafana Component
2 rules 3 TTPsA remote anonymous attacker can exploit multiple vulnerabilities in the Grafana component of Red Hat Enterprise Linux and OpenShift to execute arbitrary code, disclose confidential information, and cause a denial-of-service condition.
Multiple Vulnerabilities in Ruby Allow for DoS and Information Disclosure
2 rules 3 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Ruby to cause a denial-of-service condition and disclose confidential information.
libsndfile Vulnerability Allows Remote Code Execution and Denial-of-Service
2 rules 2 TTPsA remote attacker can exploit a vulnerability in libsndfile to execute arbitrary code or cause a denial of service, potentially leading to complete system compromise or service disruption.
CVE-2026-5773: SMB Connection Reuse Vulnerability
2 rules 1 CVEMicrosoft published information about CVE-2026-5773, a vulnerability related to the incorrect reuse of SMB connections.
Claude HUD Command Injection Vulnerability via COMSPEC Manipulation (CVE-2026-47092)
2 rules 1 TTP 1 CVEClaude HUD through version 0.0.12 is vulnerable to command injection (CVE-2026-47092) allowing a local attacker to execute arbitrary commands on a Windows system by manipulating the COMSPEC environment variable; this vulnerability has been patched in commit 234d9aa.
Summarize Path Traversal Vulnerability (CVE-2026-45242)
2 rules 1 TTP 1 CVESummarize versions prior to 0.15.1 are vulnerable to path traversal in the /v1/summarize daemon endpoint, allowing authenticated callers to write files to arbitrary directories via the slidesDir request parameter and subsequently delete files.
Postgrex SQL Injection Vulnerability in Notifications.listen/3 (CVE-2026-32687)
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in Postgrex versions 0.16.0 to before 0.22.2 within the `Postgrex.Notifications.listen/3` function allowing attackers to execute arbitrary SQL commands on the notifications connection by manipulating the channel name.
async-http-client Cookie Header Leak on Cross-Origin Redirect
2 rules 1 TTPThe async-http-client library leaks `Cookie` headers to cross-origin redirect targets due to missing header stripping in `Redirect30xInterceptor.java`, potentially exposing sensitive information to malicious third parties.
eduMFA Token Reusage Vulnerability due to Incorrect InnoDB Snapshot Isolation
2 ruleseduMFA versions prior to 2.9.1 are vulnerable to token reusage due to incorrect InnoDB snapshot isolation in MySQL and MariaDB versions prior to 11.6.2 (or newer with innodb_snapshot_isolation=off), affecting token types such as TOTP, HOTP, and likely WebAuthN, where tokens are intended for single use, requiring racing the transaction for exploitation.
Q1 2026 Malware Trends: Ransomware and Miners
2 rules 2 TTPs 1 CVEKaspersky's Q1 2026 report highlights trends in malware targeting Windows, macOS, and IoT devices, including the exploitation of CVE-2026-20131 in Cisco Secure FMC firewalls and the rise of new ransomware variants and mining activities.
Multiple Vulnerabilities in Joplin Allow for DoS, Information Disclosure, and Arbitrary File Overwrite
2 rules 1 TTPMultiple vulnerabilities in Joplin allow an attacker to perform a denial of service attack, disclose sensitive information, or overwrite arbitrary files, potentially leading to arbitrary code execution.
GIMP Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary program code.
Multiple Vulnerabilities in NGINX Open Source and NGINX Plus
2 rules 8 TTPsMultiple vulnerabilities in NGINX Open Source and NGINX Plus allow a remote, anonymous attacker to bypass security measures, execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.
CVE-2026-8757: adenhq hive Path Traversal Vulnerability
2 rules 1 TTP 1 CVEadenhq hive versions up to 0.11.0 are vulnerable to path traversal via manipulation of the _read_events_tail function in core/framework/server/routes_sessions.py, allowing a remote attacker to potentially access sensitive files.
CVE-2018-25330: Joomla! EkRishta Extension Vulnerabilities
2 rules 1 TTP 1 CVEJoomla! extension EkRishta 2.10 contains persistent cross-site scripting and SQL injection vulnerabilities, allowing attackers to inject malicious code through profile fields and POST parameters, potentially leading to information disclosure or arbitrary code execution.
ACL Analytics Arbitrary Code Execution Vulnerability (CVE-2018-25320)
2 rules 1 TTP 1 CVEACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability (CVE-2018-25320) that allows attackers to execute arbitrary commands by leveraging the EXECUTE function, potentially leading to remote code execution with system privileges.
CVE-2026-8725 - CoreWorxLab CAAL SSRF Vulnerability
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability, identified as CVE-2026-8725, exists in CoreWorxLab CAAL up to version 1.6.0, allowing remote attackers to potentially trigger internal requests.
CVE-2026-43490: ksmbd inherited ACE SID length validation vulnerability
2 rules 1 CVEMicrosoft published information about CVE-2026-43490, a vulnerability in ksmbd related to the validation of inherited ACE SID length.
phpMyFAQ SQL Injection Vulnerability in CurrentUser::setTokenData (CVE-2026-46359)
2 rules 1 TTP 1 CVEphpMyFAQ before version 4.1.2 contains a SQL injection vulnerability in CurrentUser::setTokenData, allowing authenticated attackers with crafted Azure AD accounts to execute arbitrary SQL queries by injecting malicious OAuth token claims.
Multiple Vulnerabilities in PostgreSQL Allow for Remote Code Execution and Data Breach
2 rules 6 TTPs 4 CVEsMultiple vulnerabilities in PostgreSQL versions 14.x, 15.x, 16.x, 17.x and 18.x could allow for arbitrary code execution, remote denial of service, and data breach, potentially leading to complete system compromise.
Multiple Vulnerabilities in GitLab CE/EE Allow for Arbitrary Code Execution, Data Confidentiality Compromise, and SSRF
2 rules 3 CVEsMultiple vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE) can allow an attacker to perform arbitrary code execution, compromise data confidentiality, perform server-side request forgery (SSRF), and other security breaches.
Multiple Vulnerabilities in Tenable Network Monitor
2 rules 2 TTPs 5 CVEsMultiple vulnerabilities in Tenable Network Monitor versions prior to 6.5.4 can lead to remote denial of service, security policy bypass, and unspecified security issues.
Multiple Vulnerabilities in Strapi
3 rules 4 TTPsMultiple vulnerabilities in Strapi could allow an attacker to cause a denial-of-service condition, gain administrator privileges, manipulate data, disclose confidential information, or bypass security measures.
Shibboleth Identity Provider Vulnerabilities Leading to SMTP Injection and Denial of Service
1 rule 1 TTPMultiple vulnerabilities in Shibboleth Identity Provider allow an attacker to perform SMTP injection or cause a denial of service.
HCL BigFix Vulnerability Allows Data Manipulation and Cross-Site Scripting
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in HCL BigFix to manipulate data and conduct a cross-site scripting attack.
Multiple Vulnerabilities in MISP and MISP Modules
2 rules 4 TTPsMultiple vulnerabilities in MISP and MISP Modules could allow an attacker to disclose information, gain admin rights, bypass security measures, manipulate data, or disclose sensitive information.
Multiple Vulnerabilities in PostgreSQL Allow for Remote Code Execution, Denial of Service, and Information Disclosure
2 rules 3 TTPsMultiple vulnerabilities in PostgreSQL could be exploited by an attacker to execute arbitrary code, conduct a denial of service attack, disclose information, manipulate files, conduct a SQL injection attack, and bypass security measures.
Multiple Vulnerabilities in Palo Alto Networks GlobalProtect App
2 rules 4 TTPsMultiple vulnerabilities in the Palo Alto Networks GlobalProtect App could allow an attacker to gain administrator privileges, execute arbitrary code with administrator privileges, disclose sensitive information, manipulate data, and cause a denial-of-service condition.
Multiple Vulnerabilities in F5 BIG-IP Products
3 rules 5 TTPsMultiple vulnerabilities in F5 BIG-IP products could allow an attacker to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
Multiple Vulnerabilities in GStreamer
2 rules 3 TTPsMultiple vulnerabilities in GStreamer can be exploited by a remote, anonymous attacker to disclose information, conduct a denial-of-service attack, corrupt data, or execute arbitrary code.
TeamViewer DEX Vulnerability Allows Remote Code Execution
2 rules 1 TTPAn authenticated, remote attacker can exploit a vulnerability in TeamViewer DEX to execute arbitrary program code.
SAP Patchday April 2026: Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in SAP software could allow an attacker to perform SQL injection, gain elevated privileges, execute arbitrary code, bypass security measures, perform cross-site scripting attacks, manipulate data, disclose sensitive information, or cause other unspecified impacts.
Multiple Vulnerabilities in GIMP
2 rules 3 TTPsMultiple vulnerabilities in GIMP could allow an attacker to execute arbitrary code, disclose sensitive information, manipulate data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Apache Camel
3 rules 2 TTPsMultiple vulnerabilities in Apache Camel could allow an attacker to execute arbitrary code, manipulate data, or disclose sensitive information.
Multiple Vulnerabilities in AMD EPYC, Athlon, and Ryzen Processors
2 rules 7 TTPsMultiple vulnerabilities in AMD EPYC, Athlon, and Ryzen processors can be exploited by an attacker to execute arbitrary code, escalate privileges, bypass security measures, cause a denial-of-service condition, disclose sensitive information, or manipulate data.
Multiple Vulnerabilities in rclone Allow Arbitrary Code Execution
2 rules 1 TTPMultiple vulnerabilities in rclone could be exploited by an attacker to bypass security measures and execute arbitrary program code, potentially leading to complete system compromise.
Multiple Vulnerabilities in Apache Solr
2 rules 3 TTPsMultiple vulnerabilities in Apache Solr could be exploited by an attacker to bypass security measures, manipulate data, and disclose sensitive information.
Multiple Vulnerabilities in Microsoft Windows Products
2 rules 5 TTPsMultiple vulnerabilities exist in Microsoft Windows products, enabling attackers to execute arbitrary code, escalate privileges, perform denial-of-service attacks, disclose information, or bypass security measures.
Electerm Local Code Execution via Single-Instance Socket (CVE-2026-45353)
2 rules 1 TTPElecterm versions 3.0.6 through 3.8.8 are vulnerable to local code execution (CVE-2026-45353) where a same-user process can send a JSON payload to the application's single-instance socket/pipe, leading to arbitrary tab creation and local process spawning.
Crabbox Privilege Escalation Vulnerability (CVE-2026-8629)
1 rule 1 TTP 1 CVECrabbox versions prior to v0.12.0 contain a privilege escalation vulnerability (CVE-2026-8629) that allows users with visibility-only access to obtain elevated agent tickets and impersonate trusted lease-side bridges via unauthorized POST requests to specific ticket endpoints.
Portainer Endpoint Security Bypass via Docker Swarm Service API
2 rules 1 TTPPortainer is vulnerable to an endpoint security bypass via Swarm service create/update, enabling non-admin users with access to a Docker Swarm endpoint to bypass `EndpointSecuritySettings` restrictions and gain elevated privileges such as configuring services with elevated Linux capabilities, disabling syscall filtering and AppArmor confinement, setting arbitrary sysctl values, and mounting arbitrary host paths.
Portainer Bind Mount Restriction Bypass via HostConfig.Mounts (CVE-2026-44850)
2 rules 1 TTPPortainer versions 2.33.0 through 2.33.7, 2.39.0 through 2.39.1, and 2.40.0 through 2.40.9 are vulnerable to CVE-2026-44850, a bind-mount restriction bypass via the `HostConfig.Mounts` array allowing regular users to mount host paths into containers and potentially compromise the host filesystem.
Portainer Arbitrary File Read via Git Symlink Injection
2 rules 5 TTPsPortainer is vulnerable to an arbitrary file read vulnerability due to Git symlink injection when deploying stacks from Git repositories, allowing authenticated users to read sensitive files accessible to the Portainer process.
wger IDOR Vulnerability Exposes Private Workout Data (CVE-2026-43977)
2 rules 1 TTPwger 2.5 and earlier is vulnerable to CVE-2026-43977, an Insecure Direct Object Reference (IDOR) vulnerability that allows any authenticated user to read another user's private workout session notes, exercise history, and training statistics by accessing the `/logs/` and `/stats/` actions on a public template routine they do not own.
Cisco Catalyst SD-WAN Manager Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow a remote attacker to gain access to sensitive information, elevate privileges, or gain unauthorized access to the application.
Siemens Opcenter RDnL Missing Authentication Vulnerability (CVE-2026-27446)
2 rules 1 TTP 1 CVESiemens Opcenter RDnL is vulnerable to missing authentication in critical function (CVE-2026-27446), where an unauthenticated attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled rogue broker, potentially leading to availability impacts and message injection.
Strapi Unauthenticated Account Takeover via Relational Filtering Vulnerability (CVE-2026-27886)
2 rules 1 TTPStrapi versions prior to 5.37.0 are vulnerable to an unauthenticated boolean-oracle attack against private fields on the joined `admin_users` table, including the `resetPasswordToken` field, via the 'where' query parameter on publicly accessible content-types; extracting an admin reset token via this oracle makes full administrative account takeover possible without authentication.
Exim Mail Transfer Agent User-After-Free Remote Code Execution Vulnerability (CVE-2026-45185)
2 rules 1 TTP 1 CVECVE-2026-45185, a user-after-free vulnerability in Exim versions 4.97 through 4.99.2, allows an unauthenticated remote attacker to execute arbitrary code by sending crafted SMTP traffic with BDAT chunking during TLS shutdown.
Strapi Content-Type Builder SQL Injection Vulnerability (CVE-2026-22599)
2 rules 1 TTPA SQL injection vulnerability, identified as CVE-2026-22599, affects Strapi's Content-Type Builder, where an authenticated administrator could inject arbitrary database statements through the `column.defaultTo` attribute, potentially leading to arbitrary file read, denial of service, or remote code execution on the database server.
HPE Security Advisory for Telco Intelligent Assurance Vulnerabilities
2 rulesHPE released a security advisory addressing multiple vulnerabilities in Telco Intelligent Assurance version 4.2.14, prompting users to apply necessary updates to mitigate potential risks.
Drupal Date iCal Module Vulnerability Allows Information Disclosure
2 rules 1 TTPA critical information disclosure vulnerability exists in the Drupal Date iCal module versions prior to 4.0.15, potentially allowing unauthorized access to sensitive information.
CVE-2026-42930: F5 BIG-IP Appliance Mode Restriction Bypass
2 rules 1 TTP 1 CVECVE-2026-42930 allows an authenticated attacker with 'Administrator' privileges to bypass Appliance mode restrictions on F5 BIG-IP systems.
CVE-2026-0239 Chronosphere Chronocollector Information Disclosure Vulnerability
1 ruleCVE-2026-0239 is an information disclosure vulnerability in Chronosphere Chronocollector versions earlier than v0.116.0, allowing an unauthenticated attacker with network access to retrieve sensitive information.
CVE-2026-0244 Prisma SD-WAN ION Improper Certificate Validation Vulnerability
2 rules 1 TTPCVE-2026-0244 is an improper certificate validation vulnerability in Palo Alto Networks Prisma SD-WAN ION that allows a man-in-the-middle (MitM) attacker to impersonate the controller.
CVE-2026-0238: Palo Alto Networks Broker VM Improper Input Validation
2 rulesCVE-2026-0238 is an improper input validation vulnerability in Palo Alto Networks Broker VM that allows an authenticated administrator to inject arbitrary content into certain fields, affecting versions 30.0 prior to 30.0.24.
Uniget Command Injection Vulnerability via Malicious Metadata
2 rules 1 TTPUniget is vulnerable to command injection because the `check` field is loaded directly from untrusted JSON metadata without validation, allowing an attacker to execute arbitrary shell commands on the victim's system when performing common uniget operations.
Exim Internet Mailer Vulnerability (Versions 4.97 to 4.99.2)
2 rules 1 TTPA critical vulnerability exists in Exim Internet Mailer versions 4.97 to 4.99.2, requiring users and administrators to apply necessary updates.
n8n Patches Multiple Vulnerabilities Across Products
2 rulesOn May 13, 2026, n8n released security advisories addressing vulnerabilities in several products, including prototype pollution and OAuth endpoint issues.
HPE ArubaOS Multiple Vulnerabilities
2 rulesHPE published security advisories addressing vulnerabilities in ArubaOS versions AOS-10.8.x.x, AOS-10.7.x.x, AOS-10.4.x.x, AOS-8.13.x.x, AOS-8.12.x.x, and AOS-8.10.x.x, as well as Aruba Networking AOS-8 Instant AP and AOS-10 AP, potentially allowing unauthorized access and control.
Multiple Vulnerabilities in n8n Allow for Remote Code Execution and Data Manipulation
2 rules 7 TTPsAn authenticated, remote attacker can exploit multiple vulnerabilities in n8n to execute arbitrary code, bypass security measures, conduct SQL injection attacks, manipulate data, or disclose sensitive information.
MongoDB Multiple Vulnerabilities
2 rules 4 TTPsAn authenticated remote attacker can exploit vulnerabilities in MongoDB to execute arbitrary code, manipulate data, disclose confidential information, or cause a denial-of-service condition.
Multiple Vulnerabilities in Aruba AOS-8 and AOS-10 Allow for Arbitrary Code Execution, XSS, and DoS
2 rules 2 TTPsMultiple vulnerabilities in ArubaOS allow an attacker to execute arbitrary code, perform cross-site scripting attacks, or cause a denial-of-service condition.
Multiple Vulnerabilities in Kiali for Red Hat OpenShift Service Mesh
2 rules 4 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in Kiali for Red Hat OpenShift Service Mesh to gain extended privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Aruba ArubaOS
2 rules 3 TTPsMultiple vulnerabilities in Aruba ArubaOS could allow an attacker to perform a denial of service attack, disclose information, perform a SQL injection attack, bypass security measures, and execute arbitrary code.
Devolutions Server Vulnerability Allows File Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Devolutions Server to manipulate files.
OX Dovecot Pro Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in OX Dovecot Pro could allow an attacker to perform SQL injection attacks, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Adobe Creative Cloud Applications
2 rules 3 TTPsA local attacker can exploit multiple vulnerabilities in Adobe Creative Cloud applications to execute arbitrary program code, disclose confidential information, or cause a denial-of-service condition.
Fortinet FortiSandbox Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Fortinet FortiSandbox to execute arbitrary program code, potentially leading to system compromise.
Multiple Vulnerabilities in Microsoft Developer Tools
3 rules 6 TTPsMultiple vulnerabilities in Microsoft developer tools and platforms could allow an attacker to achieve arbitrary code execution, data manipulation, privilege escalation, bypassing security measures, information disclosure, and denial of service.
Keycloak Vulnerability Allows Arbitrary Email Sending
2 rules 1 TTPAn anonymous, remote attacker can exploit a vulnerability in Keycloak to send arbitrary emails, potentially leading to phishing or social engineering attacks.
strongSwan eap-mschapv2 Plugin Vulnerability
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in strongSwan's eap-mschapv2 plugin to cause a denial of service condition or possibly execute arbitrary code.
Microsoft May 2026 Security Updates Address Remote Code Execution Vulnerabilities
2 rules 1 TTP 1 IOCMicrosoft's May 2026 Security Updates address vulnerabilities that could allow remote attackers to execute arbitrary code on affected systems.
Adobe Acrobat Reader Vulnerability Allows Information Disclosure and Code Execution
2 rules 3 TTPsA local attacker can exploit a vulnerability in Adobe Acrobat Reader to disclose sensitive information and execute arbitrary code, potentially leading to a complete system compromise.
Multiple Vulnerabilities in Fortinet Products Could Allow for Remote Code Execution
2 rules 1 TTPMultiple vulnerabilities in Fortinet's FortiAuthenticator and FortiSandbox products could lead to remote code execution, potentially allowing attackers to install programs, modify data, or create new accounts.
SPIP RCE Vulnerability in Nginx Configurations (CVE-2026-8430)
2 rules 1 TTP 1 CVESPIP versions prior to 4.4.14 contain a remote code execution vulnerability exploitable in certain Nginx configurations, allowing attackers to execute arbitrary code within the web server's context.
Fortinet Patches Multiple Vulnerabilities in FortiAuthenticator, FortiOS, and FortiSandbox
2 rulesFortinet released security advisories on May 12, 2026, addressing critical vulnerabilities including improper access control, incorrect global authorization, and out-of-bounds access across FortiAuthenticator, FortiOS, and FortiSandbox product lines, urging users to apply necessary updates.
CVE-2026-40410 - Windows SMB Client Use-After-Free Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-40410 is a use-after-free vulnerability in the Windows SMB Client that allows an authorized attacker to elevate privileges locally.
Intel Addresses Vulnerabilities in Multiple Software Products
3 rulesIntel released security advisories addressing vulnerabilities in Display Virtualization for Windows OS driver software, Intel EMA software, AI Playground software, and Intel Vision software, requiring users to update to the latest versions.
CVE-2026-41086: Windows Admin Center Privilege Escalation via Improper Access Control
2 rules 1 TTP 1 CVECVE-2026-41086 describes an improper access control vulnerability in Windows Admin Center, allowing an authorized attacker to elevate privileges over a network.
CVE-2026-35438: Windows Admin Center Missing Authorization Vulnerability
2 rules 1 TTP 1 CVECVE-2026-35438 is a missing authorization vulnerability in Windows Admin Center that allows an authorized attacker to elevate privileges over a network.
CVE-2026-35424: Windows IKE Protocol Memory Leak Denial-of-Service
1 rule 1 CVECVE-2026-35424 is a denial-of-service vulnerability in the Windows Internet Key Exchange (IKE) Protocol caused by a missing release of memory after its effective lifetime, allowing an unauthenticated remote attacker to trigger a denial of service over a network.
CVE-2026-35415: Windows Storage Spaces Controller Integer Overflow Privilege Escalation
2 rules 1 TTP 1 CVECVE-2026-35415 is an integer overflow vulnerability in the Windows Storage Spaces Controller that allows a locally authorized attacker to elevate privileges.
CVE-2026-34336 - Windows DWM Core Library Buffer Over-Read Information Disclosure
2 rules 2 TTPs 1 CVECVE-2026-34336 is a buffer over-read vulnerability in the Windows DWM Core Library, allowing a local, authenticated attacker to disclose sensitive information.
Ivanti Addresses Multiple Vulnerabilities in Various Products
2 rules 4 CVEsIvanti released security advisories on May 12, 2026, to address vulnerabilities in Xtraction, Endpoint Manager (EPM), Virtual Traffic Manager (vTM), and Secure Access Client (Windows), urging users to apply necessary updates to mitigate potential risks from CVE-2026-8043, CVE-2026-8051, CVE-2026-7431, and CVE-2026-7432.
Dalfox Unauthenticated Remote DoS via Closed-Channel Write in ParameterAnalysis
2 rules 1 TTPDalfox is vulnerable to an unauthenticated remote denial-of-service (DoS) vulnerability (CVE-2026-45090) due to a closed channel write in the `ParameterAnalysis` function, triggered by a crafted POST request that crashes the Dalfox server process.
Schneider Electric Security Advisory AV26-449 Addressing Multiple Vulnerabilities
2 rulesSchneider Electric published advisories on May 12, 2026, addressing vulnerabilities in multiple products including Ecostruxure Machine Expert HVAC, Easergy MiCOM C264, Easergy C5, Easergy MiCOM P30, Easergy MiCOM P40, EcoStruxure Power Automation System, iPMFLS, PowerLogic, Saitel DP, EasyLogic T150, EasyLogic T150 Remote Terminal Unit and Controller, Saitel DP Remote Terminal Unit and Controller, EcoStruxure Panel Server PAS400, PAS600, PAS600V2, PAS800, PAS800V2 and Easergy MiCOM Px40 Series related to clear text storage, insufficient entropy, improper path restrictions and insecure defaults.
Multiple Vulnerabilities in Microsoft Azure
2 rules 3 CVEsMultiple vulnerabilities exist in Microsoft Azure, specifically affecting azl3 kernel and azl3 krb5, potentially leading to an unspecified security issue.
Multiple Vulnerabilities in Microsoft Edge Allow for Privilege Escalation, Data Breach, and Security Policy Bypass
2 rules 1 TTP 1 CVEMultiple vulnerabilities in Microsoft Edge and Microsoft Edge for Android can allow an attacker to perform privilege escalation, cause a data breach, and bypass security policies.
Multiple Vulnerabilities in Centreon Products
2 rules 1 TTP 1 IOCMultiple vulnerabilities in Centreon products allow for remote code execution, SQL injection, and cross-site scripting.
Multiple Vulnerabilities in Schneider Electric Products
2 rules 2 CVEsMultiple vulnerabilities in Schneider Electric products can allow an attacker to perform privilege escalation, data confidentiality breaches, and data integrity breaches.
Multiple Vulnerabilities in Apple Products Allow for Arbitrary Code Execution, Privilege Escalation, and Data Confidentiality Compromise
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities in Apple products could allow an attacker to execute arbitrary code, escalate privileges, and compromise data confidentiality.
Multiple Vulnerabilities in Nextcloud Products
2 rules 5 CVEs 6 IOCsMultiple vulnerabilities in Nextcloud products can lead to data confidentiality breaches, data integrity compromise, and security policy bypass.
Multiple Vulnerabilities in Axis Products Allow Remote Code Execution and Privilege Escalation
2 rules 2 TTPs 4 CVEsMultiple vulnerabilities in Axis products allow remote arbitrary code execution and privilege escalation in Axis OS versions 12.10.x prior to 12.10.37 and 12.9.x prior to 12.9.33 for Active Track.
CPython Security Policy Bypass Vulnerability
2 rules 1 TTP 1 CVEA vulnerability in CPython, tracked as CVE-2026-7210, allows an attacker to bypass the security policy, requiring the latest security patch for mitigation.
Traefik Security Policy Bypass Vulnerability
1 rule 1 TTPA security policy bypass vulnerability exists in Traefik versions prior to v2.11.46, v3.6.x before v3.6.17, and v3.7.x before v3.7.1, allowing attackers to potentially circumvent intended access controls.
Siemens Teamcenter Hardcoded Key Vulnerability (CVE-2026-33893)
2 rules 2 TTPs 1 CVECVE-2026-33893 describes a vulnerability in Siemens Teamcenter where hardcoded keys used for obfuscation are stored directly within the application, potentially allowing an attacker to obtain these keys and gain unauthorized access.
ROS# Path Traversal Vulnerability (CVE-2026-41551)
2 rules 1 TTP 1 CVEROS# versions prior to V2.2.2 are vulnerable to path traversal (CVE-2026-41551) due to insufficient sanitization of user input, potentially enabling remote attackers to read arbitrary files.
Multiple Vulnerabilities in dnsmasq
2 rules 9 TTPsMultiple vulnerabilities in dnsmasq could allow an attacker to cause a denial of service, execute arbitrary code with root privileges, disclose sensitive information, manipulate data, and redirect users to malicious domains.
KACO blueplanet Devices Vulnerable to Credential Derivation (CVE-2025-40946)
2 rules 1 CVECVE-2025-40946 describes a vulnerability in KACO new energy blueplanet products where a weak CRC16-based algorithm for generating Technical Service credentials could allow an attacker to derive the credentials from the device's serial number and misuse them to gain unauthorized access.
Multiple Vulnerabilities in pgAdmin
2 rules 9 TTPsMultiple vulnerabilities in pgAdmin could allow an attacker to escalate privileges, execute arbitrary code, bypass security measures, perform SQL injection and cross-site scripting attacks, manipulate data, or disclose sensitive information.
Multiple Vulnerabilities in Apple macOS Sonoma, Sequoia, and Tahoe
2 rules 6 TTPsMultiple vulnerabilities exist in Apple macOS Sonoma, macOS Sequoia, and macOS Tahoe that could allow an attacker to elevate privileges, conduct a denial-of-service attack, disclose information, execute arbitrary code, and bypass security measures.
Multiple Vulnerabilities in ImageMagick Allow for DoS and Potential Data Exposure
2 rules 2 TTPsA local attacker can exploit multiple vulnerabilities in ImageMagick to perform a denial of service attack or affect confidentiality, availability, and integrity.
Multiple Vulnerabilities in Apple macOS
2 rules 4 TTPsMultiple vulnerabilities in Apple macOS allow an attacker to bypass security measures, conduct denial of service attacks, disclose information, manipulate files, and escalate privileges.
Poppler Vulnerability Allows Code Execution
2 rules 1 TTPA local attacker can exploit a vulnerability in poppler to execute arbitrary program code on a vulnerable system.
Sonatype Nexus Repository Manager Security Bypass Vulnerability
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Sonatype Nexus Repository Manager to bypass security precautions.
Red Hat Enterprise Linux Multiple Vulnerabilities Leading to RCE/DoS
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.
Multiple Vulnerabilities in Red Hat Build of Keycloak
2 rules 5 TTPsMultiple vulnerabilities in Red Hat Build of Keycloak could allow an attacker to bypass authentication, gain elevated privileges, disclose sensitive information, cause a denial of service condition, execute arbitrary code, or manipulate data.
Multiple Vulnerabilities in 7-Zip Allow File Manipulation and Information Disclosure
2 rules 2 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in 7-Zip to manipulate files or disclose sensitive information on Windows systems.
CVE-2026-34259: SAP Forecasting & Replenishment OS Command Execution
2 rules 3 TTPs 1 CVECVE-2026-34259 is an OS Command Execution vulnerability in SAP Forecasting & Replenishment that allows an authenticated attacker with administrative privileges to execute arbitrary OS commands, potentially leading to complete system compromise.
SAP S/4HANA SQL Injection Vulnerability (CVE-2026-34260)
2 rules 2 TTPs 1 CVESAP S/4HANA (SAP Enterprise Search for ABAP) is vulnerable to SQL injection (CVE-2026-34260) via user-controlled input, allowing an authenticated attacker to inject malicious SQL statements, leading to unauthorized data access and potential application crashes.
JetBrains TeamCity Vulnerability
2 rulesA security advisory released by JetBrains on May 11, 2026, addresses a vulnerability in JetBrains TeamCity versions prior to 2026.1 and 2025.11.5, requiring users to apply updates to mitigate potential risks.
OpenClaw Arbitrary Code Execution via Malicious Plugin
2 rules 1 TTP 1 CVEOpenClaw before version 2026.4.23 is vulnerable to arbitrary code execution (CVE-2026-45004) due to insecurely loading the setup-api.js file from the current working directory, allowing attackers to execute arbitrary JavaScript under the current user account.
OpenClaw Gateway Config Mutation Guard Bypass (CVE-2026-45001)
2 rules 2 TTPs 1 CVEOpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.apply endpoints, allowing a prompt-injected model with access to the owner-only gateway tool to persist unauthorized changes to protected operator settings.
Broadcom Patches Multiple Vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes
2 rulesBroadcom published a security advisory addressing vulnerabilities in VMware Tanzu RabbitMQ on Kubernetes versions prior to 4.3.0, 4.2.6, 4.1.11, 4.0.20 and 3.13.15, potentially allowing an attacker to compromise the affected system.
Next.js i18n Pages Router Middleware Authentication Bypass (CVE-2026-44573)
2 rules 1 TTPNext.js applications using the Pages Router with `i18n` and middleware-based authorization are vulnerable to an authentication bypass (CVE-2026-44573), allowing unauthorized access to protected page data via locale-less `/_next/data/<buildId>/<page>.json` requests.
Ubuntu Linux Kernel Vulnerabilities Addressed in Security Notices
2 rulesUbuntu released security notices between May 4 and 10, 2026, addressing vulnerabilities in the Linux kernel affecting Ubuntu 20.04 LTS, 22.04 LTS, 24.04 LTS, and 25.10, requiring timely updates.
Ella Core Vulnerable to UE Downlink Redirection via Forged PDUSessionResourceSetupResponse (CVE-2026-44473)
2 rules 1 TTPElla Core is vulnerable to UE downlink redirection (CVE-2026-44473) due to missing SCTP association verification, enabling a malicious radio to forge a PDUSessionResourceSetupResponse and redirect downlink traffic.
urllib3 Sensitive Header Leak in Low-Level Redirects (CVE-2026-44431)
2 rulesSensitive headers (`Authorization`, `Cookie`, and `Proxy-Authorization`) are forwarded across origins in proxied low-level redirects when using `HTTPConnection.urlopen()` instances created via `ProxyManager.connection_from_url()` in urllib3 versions before 2.7.0, potentially exposing credentials to unintended third parties; upgrade to version 2.7.0 or later to remediate this issue.
Urllib3 Decompression Bomb Vulnerability in Streaming API (CVE-2026-44432)
2 rules 1 TTPUrllib3 versions before 2.7.0 are vulnerable to excessive resource consumption when using the streaming API to decompress responses, particularly when using the Brotli library or calling HTTPResponse.drain_conn() after partial decompression, leading to high CPU usage and memory allocation, potentially causing a denial-of-service condition (CVE-2026-44432).
go-git Improper Parsing of Malformed Git Objects
2 rulesgo-git may parse malformed Git objects differently than upstream Git, leading to inconsistent interpretation and potentially allowing the signing or verification of commits with altered metadata, as described in CVE-2026-45022.
Open WebUI Inconsistent Authorization Controls in Memories API
2 rules 1 TTPOpen WebUI versions before 0.6.19 have inconsistent authorization controls within the memories API, allowing standard users to view, delete, and restore other users' memories, potentially leading to sensitive data disclosure and unauthorized access as tracked by CVE-2026-44570.
PraisonAI Unsafe Tool Resolution Vulnerability
2 rules 1 TTP 1 CVEPraisonAI resolves tool names against module globals and `__main__` after failing to match declared tools, allowing an attacker who can influence tool-call names to invoke unintended application callables, leading to potential unauthorized state changes and command execution.
Multiple Vulnerabilities in KDE Kdenlive and Okular
2 rules 4 TTPsMultiple vulnerabilities in KDE Kdenlive and Okular allow a remote, anonymous attacker to execute arbitrary code, bypass security measures, manipulate data, disclose confidential information, or cause a denial-of-service condition.
jq Vulnerability Allows Security Bypass
1 ruleA local attacker can exploit a vulnerability in jq to bypass security measures.
Multiple Vulnerabilities in Red Hat Hardened Images RPMs
2 rules 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to cause a denial-of-service condition and possibly manipulate data or perform path traversal attacks.
Multiple Vulnerabilities in HCL BigFix
2 rules 3 TTPsMultiple vulnerabilities in HCL BigFix could allow an attacker to disclose information, execute arbitrary code, perform a denial of service attack, and manipulate files.
CVE-2026-23377 Vulnerability
1 CVECVE-2026-23377 is a reported vulnerability with no further details available from the Microsoft Security Response Center.
Apache NiFi Multiple Vulnerabilities Allow Remote Code Execution
2 rulesAn authenticated, remote attacker can exploit multiple vulnerabilities in Apache NiFi to execute arbitrary code and achieve unspecified impacts.
CVE-2025-37877 iommu: Clear iommu-dma ops on cleanup
1 CVECVE-2025-37877 is a vulnerability in the iommu component requiring proper cleanup, affecting Microsoft products.
CVE-2025-38717 KCM Race Condition Vulnerability
2 rules 1 CVECVE-2025-38717 is a race condition vulnerability in the kcm_unattach() function of a Microsoft product, potentially leading to denial of service or privilege escalation.
CVE-2024-26756: Unspecified Vulnerability in Microsoft Products
2 rules 1 CVEMicrosoft released details for CVE-2024-26756, an unspecified vulnerability affecting Microsoft products, but provided no further information.
CVE-2024-26757: Unspecified Vulnerability in Microsoft md
2 rules 1 CVECVE-2024-26757 is an unspecified vulnerability in a Microsoft product, potentially allowing an attacker to perform unauthorized actions.
SmarterTools SmarterMail Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in SmarterTools SmarterMail could allow an attacker to gain elevated privileges, bypass security measures, manipulate data, disclose sensitive information, cause a denial-of-service condition, or carry out other unspecified attacks.
OpenCATS 0.9.4 Remote Code Execution Vulnerability (CVE-2021-47936)
2 rules 2 TTPs 1 CVEOpenCATS 0.9.4 is vulnerable to remote code execution (CVE-2021-47936) allowing unauthenticated attackers to execute arbitrary commands by uploading malicious PHP files disguised as resume attachments through the careers job application endpoint, leading to potential system compromise.
CVE-2026-41889 pgx: SQL Injection via Placeholder Confusion
2 rules 1 TTP 1 CVECVE-2026-41889 is a critical SQL Injection vulnerability involving placeholder confusion with dollar-quoted string literals in the pgx library, potentially allowing attackers to execute arbitrary SQL queries.
free5GC NEF PATCH Handler Vulnerability Leads to Denial of Service
2 rules 1 TTP 3 IOCsA nil pointer dereference vulnerability exists in free5GC's NEF PATCH /3gpp-pfd-management/v1/{afId}/transactions/{transId}/applications/{appId} handler when UDR access fails, causing a denial-of-service condition.
Atlassian Security Advisory Addresses Critical Vulnerabilities in Multiple Products
2 rulesAtlassian released a security advisory addressing multiple critical vulnerabilities in Bamboo, Bitbucket, Confluence, Jira, and Jira Service Management Data Center and Server products.
Velocity.js Prototype Pollution Vulnerability via #set Directive (CVE-2026-44966)
2 rules 1 TTPA prototype pollution vulnerability exists in Velocity.js versions 2.1.5 and earlier, allowing attackers to modify Object.prototype via crafted #set directives in Velocity templates, potentially leading to Denial of Service (DoS) or Remote Code Execution (RCE).
ex_webrtc Missing DTLS Fingerprint Validation Allows MITM
2 rules 1 TTPThe ex_webrtc library is vulnerable to a man-in-the-middle attack due to missing DTLS peer certificate fingerprint validation in the DTLS client role, potentially allowing interception of media and data channels when chained with insecure signaling or a peer with similar validation gaps; upgrade to versions 0.15.1 or 0.16.1 to mitigate this vulnerability.
Dirty Frag Linux Kernel Local Privilege Escalation Vulnerability
2 rules 1 TTPThe Dirty Frag vulnerability (CVE-2026-43284 and CVE-2026-43500) is a Linux kernel local privilege escalation that allows an unprivileged local user to gain root privileges by exploiting flaws in the networking subsystem to overwrite protected file contents in the page cache.
Spring Cloud Config Vulnerabilities Allow Secret Access and Directory Traversal
2 rules 3 CVEsMultiple vulnerabilities in Spring Cloud Config, including CVE-2026-40981, CVE-2026-40982, and CVE-2026-41002, could allow unauthorized access to secrets and directory traversal attacks, potentially leading to data exposure and system compromise.
Mozilla Firefox Multiple Vulnerabilities
2 rules 2 TTPsMozilla released security updates to address vulnerabilities in Firefox and Firefox ESR versions, potentially allowing for exploitation if left unpatched.
Multiple Vulnerabilities in Ivanti Endpoint Manager Mobile
2 rules 4 TTPsMultiple vulnerabilities in Ivanti Endpoint Manager Mobile allow an attacker to gain administrator privileges, execute arbitrary code with administrator privileges, bypass security measures, manipulate data, and disclose sensitive information.
Ruby Multiple Vulnerabilities Lead to DoS and Information Disclosure
2 rules 1 TTPA remote, anonymous attacker can exploit multiple unspecified vulnerabilities in Ruby to perform a denial of service attack or disclose sensitive information.
LiteLLM Vulnerability Allows Code Execution and Information Disclosure
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in LiteLLM to execute arbitrary program code and disclose sensitive information.
Red Hat Build of Debezium for Red Hat Application Foundations Vulnerabilities Allow Code Execution
2 rules 1 TTPMultiple vulnerabilities in Red Hat Build of Debezium for Red Hat Application Foundations could allow an attacker to execute arbitrary code.
IBM WebSphere Application Server Liberty Vulnerability Allows Code Execution
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in IBM WebSphere Application Server Liberty to execute arbitrary program code on the target system.
LiteLLM Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in LiteLLM could allow an attacker to perform a SQL injection attack and gain unauthorized access or execute arbitrary code with the privileges of the service.
CodeAstro Leave Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-8132) exists in CodeAstro Leave Management System 1.0 via manipulation of the txt_username parameter in /login.php, enabling remote exploitation and potential database compromise.
SourceCodester SUP Online Shopping SQL Injection Vulnerability (CVE-2026-8130)
2 rules 1 TTP 1 CVESourceCodester SUP Online Shopping 1.0 is vulnerable to SQL injection via the 'seenid' parameter in /admin/message.php, allowing remote attackers to execute arbitrary SQL commands; exploit code is publicly available.
Zebra Consensus Divergence in Transparent Sighash Hash-Type Handling (CVE-2026-44497)
2 rulesZebra versions prior to 4.4.0 exhibit a consensus divergence vulnerability (CVE-2026-44497) due to insufficient error handling of invalid sighash types during sighash computation, potentially leading to network partitioning and double-spend attacks.
Broadcom Patches Multiple Vulnerabilities in Tanzu Products
2 rules 1 TTPBroadcom released security advisories on May 7, 2026, addressing vulnerabilities in several Tanzu products, requiring users and administrators to apply necessary updates to mitigate potential risks.
Ivanti EPMM Authenticated Remote Code Execution Vulnerability Exploited
2 rules 4 TTPs 1 CVECVE-2026-6973, an authenticated remote code execution vulnerability in Ivanti Endpoint Manager Mobile (EPMM), is being actively exploited, potentially leading to data breaches and system compromise.
PAN-OS Authentication Portal Remote Code Execution Vulnerability
2 rules 1 TTPAn unauthenticated remote code execution vulnerability exists in the PAN-OS Authentication Portal (Captive Portal) service, potentially allowing attackers to execute arbitrary code with root privileges on PA-Series and VM-Series firewalls by sending crafted network packets.
CVE-2026-7925 Use-After-Free Vulnerability in Chromium Chromoting
2 rules 1 CVECVE-2026-7925 is a use-after-free vulnerability in the Chromoting component of Google Chrome, also affecting Microsoft Edge.
CVE-2026-33844 Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
2 rules 1 TTPCVE-2026-33844 is a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra due to improper input validation, allowing an authorized network attacker to execute code.
CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability
2 rules 1 TTPCVE-2026-26164 is an information disclosure vulnerability in M365 Copilot due to improper neutralization of special elements, allowing unauthorized information disclosure over a network.
AxonFlow Platform Multi-Tenant Isolation and Access Control Vulnerabilities
2 rules 5 TTPsMultiple vulnerabilities in AxonFlow platform versions prior to 7.5.0, including multi-tenant isolation issues and SQL injection, could lead to unauthorized access, information disclosure, denial of service, and other security impacts; AxonFlow v7.5.0 resolves these issues.
DivvyDrive Cross-Site Request Forgery Vulnerability (CVE-2026-5791)
2 rules 1 TTP 1 CVEDivvyDrive versions 4.8.2.9 through 4.8.3.2 are susceptible to cross-site request forgery (CSRF), allowing an attacker to execute unauthorized actions on behalf of an authenticated user.
wger Cross-Tenant Password Reset and Plaintext Disclosure Vulnerability
2 rules 1 TTPA vulnerability in wger version 2.5 and earlier allows an attacker with `gym.manage_gym` permission and `gym=None` to reset the password of any other `gym=None` user, disclosing the new password in plaintext and allowing account takeover.
QuantumNous new-api SSRF Bypass via 0.0.0.0
2 rules 1 TTP 2 CVEs 2 IOCsThe QuantumNous new-api is vulnerable to SSRF attacks. The SSRF protection implemented in versions v0.9.0.5 (CVE-2025-59146) and v0.9.6 (CVE-2025-62155) can be bypassed by using the address `0.0.0.0`. An attacker with a valid API token can send a request to `/v1/chat/completions`, `/v1/responses`, or `/v1/messages` with `0.0.0.0` as the image/file URL host, which bypasses the private-IP filter and allows the server to issue HTTP requests to localhost, enabling a blind SSRF and possibly a full-read SSRF in specific configurations.
Google Chrome Security Update Required
2 rulesGoogle released a security advisory addressing vulnerabilities in Chrome for Desktop versions prior to 148.0.7778.96/97 on Windows/Mac and 148.0.7778.96 on Linux, requiring users to update to mitigate potential exploits.
Broadcom Tanzu Jammy Stemcell Vulnerability (CVE-2026-341431)
2 rules 1 TTPA vulnerability in Broadcom's Tanzu Jammy Stemcell versions prior to 1.1193, tracked as CVE-2026-341431, requires patching to prevent potential exploitation.
Cisco Unity Connection Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in Cisco Unity Connection allow an attacker to execute arbitrary code with administrator privileges or perform Server-Side Request Forgery (SSRF) attacks.
Multiple Vulnerabilities in Oracle Java SE
2 rules 1 TTPA remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle Java SE to compromise confidentiality, integrity, and availability.
CPython Multiple Vulnerabilities Allow File Manipulation and DoS
2 rules 2 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in CPython to manipulate files or cause a denial-of-service condition.
Erlang/OTP Information Disclosure Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit an unspecified vulnerability in Erlang/OTP to disclose sensitive information.
Multiple Vulnerabilities in Red Hat Enterprise Linux
2 rules 3 TTPsAn unauthenticated or authenticated remote attacker can exploit vulnerabilities in Red Hat Enterprise Linux to perform cross-site scripting, cause denial of service, or disclose sensitive information.
Red Hat OpenShift Service Mesh Multiple Vulnerabilities
2 rules 4 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.
Microsoft CVE-2026-25833 Vulnerability Published
1 CVEMicrosoft published CVE-2026-25833, a security vulnerability for which details are currently unavailable, impacting systems and requiring further investigation upon release of additional information.
Microsoft Published Information Regarding CVE-2025-66442
2 rules 1 TTP 1 CVEMicrosoft has published information regarding the vulnerability CVE-2025-66442; details are currently unavailable, limiting specific analysis and detection strategies.
Microsoft Published Information Regarding CVE-2026-25835
2 rules 1 CVEMicrosoft has published information regarding the vulnerability CVE-2026-25835, but details about the vulnerability, affected products, and exploitation are currently unavailable.
Gotenberg Unauthenticated SSRF Vulnerability
2 rules 3 IOCsGotenberg is vulnerable to Server-Side Request Forgery (SSRF) due to bypassable default deny-lists in the `downloadFrom` and `webhook` features, where case-sensitive regex matching allows attackers to use IPv6 loopback URLs to bypass the deny-list and access internal HTTP services.
Gotenberg SSRF Vulnerability in LibreOffice Conversion Endpoint
2 rules 1 IOCGotenberg is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient hardening in the LibreOffice conversion endpoint, allowing attackers to make outbound HTTP requests by embedding external URLs in uploaded documents, bypassing Gotenberg's SSRF filters, affecting versions up to 8.31.0, and potentially enabling access to internal services, data exfiltration, or port scanning.
Netty DNS Codec Input Validation Bypass Vulnerability
2 rules 1 TTPNetty's DNS codec fails to enforce RFC 1035 domain name constraints, leading to potential DNS cache poisoning, denial-of-service, and domain validation bypass through null byte injection, overlength labels, silent truncation, and unbounded memory allocation.
rmcp Streamable HTTP Server Transport DNS Rebinding Vulnerability
2 rules 1 TTPThe `rmcp` crate before v1.4.0 is vulnerable to DNS rebinding attacks via the Streamable HTTP server transport due to missing Host header validation, potentially allowing arbitrary code execution on a victim's machine if they visit a malicious website.
PraisonAI SSRF Vulnerability via URL Parsing Discrepancy
2 rules 1 TTPPraisonAI versions 1.6.31 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability due to inconsistent URL parsing between the application's validation logic and the underlying requests library, allowing attackers to bypass intended security checks and access internal resources.
OpenClaw Insufficient Environment Variable Denylist Vulnerability (CVE-2026-43584)
3 rules 3 TTPs 1 CVEOpenClaw before 2026.4.10 is vulnerable to an insufficient environment variable denylist, allowing attackers to manipulate interpreter startup variables to influence execution behavior or network connectivity.
OpenClaw Privilege Escalation Vulnerability (CVE-2026-43578)
2 rules 1 TTP 1 CVEOpenClaw versions before 2026.4.10 are vulnerable to privilege escalation due to improper handling of background async exec completion events, potentially allowing attackers to execute code with elevated privileges by providing untrusted completion content.
OpenClaw Incomplete Navigation Guard SSRF Bypass (CVE-2026-43580)
2 rules 1 TTP 1 CVEOpenClaw before version 2026.4.10 contains an incomplete navigation guard vulnerability, allowing attackers to trigger navigation without proper SSRF policy enforcement by bypassing post-action security checks via browser interactions like pressKey and type submit flows, potentially leading to unauthorized Server-Side Request Forgery (SSRF).
Cisco Releases Security Advisories for Multiple Products
3 rules 3 TTPsCisco released security advisories on May 6, 2026, addressing vulnerabilities including remote code execution, server-side request forgery, and denial of service in Crosswork Network Controller, IoT Field Network Director, Network Services Orchestrator, SG350/SG350X Managed Switches, and Unity Connection.
Vvveb Hardcoded Credentials Vulnerability in phpMyAdmin Container
2 rules 1 TTP 1 CVEVvveb versions before 1.0.8.2 contain a hardcoded credentials vulnerability in the docker-compose-apache.yaml configuration, allowing unauthenticated attackers to access the phpMyAdmin container and gain unrestricted read and write access to the Vvveb database, leading to account takeover and data manipulation.
Vvveb CMS XML External Entity Injection Vulnerability
2 rules 3 TTPs 1 CVEVvveb before 1.0.8.2 is vulnerable to XML external entity (XXE) injection in the admin import feature, allowing authenticated site administrators to read arbitrary files and modify database records, potentially leading to privilege escalation.
dssrf SSRF Protection Bypass via IPv6 Addresses
2 rules 12 IOCsA vulnerability in the dssrf npm package allows attackers to bypass SSRF protections by using specially crafted IPv6 addresses, despite documentation claiming IPv6 is disabled, which can lead to internal resource access or other malicious activities.
Samsung Mobile Devices Multiple Vulnerabilities
2 rulesSamsung released a security update to address multiple vulnerabilities in Samsung mobile devices running versions prior to SMR-MAY-2026 Release 1, potentially allowing attackers to exploit these vulnerabilities for malicious purposes.
Mistune Markdown Parser Denial-of-Service Vulnerability
2 rules 1 TTPA denial-of-service vulnerability exists in Mistune version 3.2.0 due to excessive parsing and CPU consumption when processing specially crafted reference links, leading to application hangs and service unavailability.
Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities
2 rules 1 TTPMultiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code or conduct server-side request forgery (SSRF) attacks.
Cisco Prime Infrastructure Information Disclosure Vulnerability
2 rules 3 TTPsCisco Prime Infrastructure is vulnerable to an information disclosure vulnerability, allowing authenticated remote attackers to download arbitrary log files due to insufficient authorization checks.
Cisco IoT Field Network Director Multiple Vulnerabilities
3 rules 4 TTPsMultiple vulnerabilities in Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial-of-service (DoS) conditions on managed routers.
Cisco Identity Services Engine Authentication Bypass Vulnerabilities
2 rules 1 TTPMultiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information.
Broadcom Patches Vulnerabilities in Tanzu GemFire Management Console
2 rules 1 TTPBroadcom released a security advisory addressing vulnerabilities in Tanzu GemFire Management Console versions prior to 1.4.4, prompting users to apply necessary updates to mitigate potential risks.
Vulnerabilities in Unitree Embodied AI Systems
3 rules 7 TTPs 1 CVE 1 IOCCommercially available Unitree robots are susceptible to multiple vulnerabilities, including hardcoded keys and command injection, allowing attackers to gain root-level access, exfiltrate data, and potentially create physical botnets.
ssrfcheck vulnerable to SSRF via IPv4-mapped IPv6 bypass
2 rules 1 TTPssrfcheck version 1.3.0 and earlier is vulnerable to server-side request forgery (SSRF) attacks because it fails to block private IP addresses encoded as IPv4-mapped IPv6 addresses due to WHATWG URL parsing.
Dell Security Advisories Address Multiple Vulnerabilities
2 rulesDell published security advisories addressing vulnerabilities in APEX Cloud Platform, Automation Platform, Command | Monitor, CyberSense, NativeEdge Orchestrator, SmartFabric Manager, iDRAC, Disk Library, and PowerProtect Cyber Recovery, requiring users to apply necessary updates.
CISA ICS Advisories Addressing ABB and NSA Products
2 rulesCISA published ICS advisories addressing vulnerabilities in multiple ABB products including AWIN Gateways, Ability OPTIMAX, Symphony Plus Engineering, Edgenius Management Portal, PCM600, System 800xA, Symphony Plus IEC 61850, and NSA GRASSMARLIN, prompting users to apply mitigations and updates.
awslabs/tough Delegated Roles Signature Threshold Bypass
2 rules 1 TTP 1 IOCAn improper verification of cryptographic signature uniqueness vulnerability in awslabs/tough before v0.22.0 allows remote authenticated users to bypass TUF signature threshold requirements by duplicating a valid signature, leading to the acceptance of forged delegated role metadata.
Multiple Vulnerabilities in Apache Wicket
2 rules 2 TTPsMultiple vulnerabilities in Apache Wicket could allow an attacker to bypass security measures, perform Cross-Site Scripting (XSS) attacks, disclose confidential information, or manipulate data.
Multiple Vulnerabilities in Rapid7 Velociraptor
2 rules 2 TTPsMultiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to perform a denial-of-service attack or disclose sensitive information.
Red Hat Hardened Images RPMs Fontconfig Vulnerability
2 rules 2 TTPsA local attacker can exploit a vulnerability in Red Hat Hardened Images RPMs to execute arbitrary code or cause a denial of service.
ProFTPD Vulnerability Allows SQL Injection
2 rules 1 TTPA remote, anonymous attacker can exploit a SQL injection vulnerability in ProFTPD, potentially leading to unauthorized data access or modification.
Multiple Vulnerabilities in Vaultwarden
2 rules 3 TTPsMultiple vulnerabilities in Vaultwarden could be exploited by an attacker to bypass security measures, conduct a denial-of-service attack, and disclose information, potentially leading to unauthorized access and service disruption.
Multiple Vulnerabilities in Red Hat Hardened Images RPMs
2 rules 5 TTPsMultiple vulnerabilities in Red Hat Hardened Images RPMs can be exploited by an attacker to bypass security measures, escalate privileges, disclose sensitive information, manipulate data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Red Hat Enterprise Linux and Satellite
2 rules 2 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux and Red Hat Satellite could allow a remote, anonymous attacker to disclose information or execute arbitrary code.
tigervnc Vulnerability Allows Information Disclosure, File Manipulation, and Denial of Service
2 rules 3 TTPsA local attacker can exploit a vulnerability in tigervnc to disclose information, manipulate files, and perform a denial of service attack.
Multiple Vulnerabilities in OpenSSL Allow for DoS, Information Disclosure, and Ciphertext Recovery
2 rules 2 TTPsMultiple vulnerabilities in OpenSSL can be exploited by a remote attacker to conduct a denial-of-service attack, disclose information, or recover ciphertext over a network.
Microsoft Releases Security Update for CVE-2026-43964
2 rules 1 CVEMicrosoft has released a security update to address the vulnerability CVE-2026-43964.
Multiple Vulnerabilities in Zabbix
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Zabbix versions 6.0.x before 6.0.45, 7.0.x before 7.0.24, and 7.4.x before 7.4.8 allow for data confidentiality breaches and remote cross-site scripting (XSS) attacks.
Multiple Vulnerabilities in Redis Allow Remote Code Execution
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Redis could allow an attacker to execute arbitrary code remotely, potentially leading to complete system compromise.
Multiple Unspecified Vulnerabilities in Google Chrome
2 rulesMultiple unspecified vulnerabilities in Google Chrome prior to version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac could allow an attacker to cause an unspecified security issue.
JupyterHub Extension Manager API/GUI Policy Discrepancy Allows Malicious Extension Installation
2 rules 1 TTPJupyterLab versions prior to 4.5.7 do not correctly enforce the allow-list of extensions that can be installed from PyPI Extension Manager, allowing authenticated attackers to escalate privileges and potentially exfiltrate data, move laterally, and persistently compromise server infrastructure.
Open-WebSearch SSRF Vulnerability in fetchWebContent Tool
2 rules 1 TTP 1 IOCOpen-WebSearch has a Server-Side Request Forgery (SSRF) vulnerability in the `fetchWebContent` MCP tool due to improper validation of IPv6 literals and lack of DNS resolution, allowing attackers to fetch arbitrary private-network URLs and receive the response body.
ssrfcheck SSRF Bypass Vulnerability
2 rules 1 TTP 1 CVEThe `ssrfcheck` npm package is vulnerable to SSRF bypass due to an incomplete denylist of IP addresses. The package fails to classify the reserved IP address space 224.0.0.0/4 (Multicast) as invalid, allowing potential SSRF attacks. All versions up to and including 1.1.1 are affected. A patch has been released in version 1.2.0.
awslabs/tough Missing Delegated Metadata Validation
2 rules 1 TTP 1 CVE 1 IOCThe tough library before version 0.22.0 and tuftool before version 0.15.0 do not properly verify delegated target metadata, allowing an attacker with write access to serve expired or otherwise invalid targets from a TUF repository, potentially leading to the library trusting invalid targets.
OpenClaw Gateway Configuration Mutation Vulnerability
2 rules 1 TTPA vulnerability in OpenClaw versions before 2026.4.23 allows a compromised model with access to the `gateway` tool to persist unsafe config changes that cross security boundaries due to an insufficient denylist.
Langflow Knowledge Bases API Path Traversal Vulnerability
2 rules 1 TTPA path traversal vulnerability exists in the Langflow Knowledge Bases API (`DELETE /api/v1/knowledge_bases`) that allows an authenticated attacker to delete arbitrary directories on the server's filesystem, leading to data loss and potential service disruption.
graphql-php OverlappingFieldsCanBeMerged Quadratic Complexity Vulnerability
2 rules 1 TTP 1 CVEThe `OverlappingFieldsCanBeMerged` validation rule in `webonyx/graphql-php` has an `O(n^2 x m^2)` worst-case complexity due to flattened inline fragments, leading to potential resource exhaustion.
OpenClaw Weakened Exec Approval Binding Vulnerability
2 rules 2 TTPs 1 CVEOpenClaw versions 2026.2.23 before 2026.4.12 contain a weakened exec approval binding vulnerability in busybox and toybox applet execution, allowing attackers to obscure which applet would run, bypass exec approval mechanisms, and weaken risk classification of unsafe applet invocations.
OpenClaw Sandbox Media Normalization Bypass via Discord Event Cover Image
2 rules 1 TTP 1 CVEOpenClaw versions 2026.4.7 before 2026.4.10 fail to normalize Discord event cover image parameters in sandbox media processing, allowing attackers to bypass media normalization and inject host-local media references into channel action paths expecting normalized media.
OpenClaw Sender Policy Bypass Vulnerability Leading to Local File Disclosure
2 rules 2 TTPs 1 CVEOpenClaw versions prior to 2026.4.10 are vulnerable to a sender policy bypass, allowing attackers with restricted read access to disclose local files by triggering host-media attachment loading, bypassing authorization boundaries.
OpenClaw Shell Wrapper Detection Bypass via Environment Variable Injection
2 rules 1 TTP 1 CVEOpenClaw versions before 2026.4.12 are vulnerable to environment variable injection, allowing attackers to bypass shell wrapper detection and manipulate execution semantics by modifying shell variables.
Dell Computer Vulnerability Allows Local Code Execution
2 rules 1 TTPA local attacker can exploit a vulnerability in Dell computers to execute arbitrary code.
Multiple Vulnerabilities in Apache HTTP Server
2 rules 6 TTPsMultiple vulnerabilities in Apache HTTP Server can be exploited by an attacker to gain elevated privileges, execute arbitrary code, bypass security measures, disclose sensitive information, or cause a denial-of-service condition.
Red Hat Enterprise Linux freeipmi Vulnerability Allows Code Execution
2 rules 4 TTPsA remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux freeipmi to cause a denial of service condition or memory corruption, potentially allowing arbitrary code execution.
Multiple Vulnerabilities in Prometheus Allow for DoS, Information Disclosure, and XSS
2 rules 2 TTPsMultiple vulnerabilities in Prometheus could allow an attacker to perform a Denial of Service attack, disclose sensitive information, or execute Cross-Site Scripting attacks.
Microsoft Product Vulnerability CVE-2026-37457
2 rules 1 CVECVE-2026-37457 is a vulnerability affecting a Microsoft product, for which details are currently unavailable.
Path Traversal Vulnerability in UsamaK98 python-notebook-mcp
3 rules 1 TTP 1 CVEA path traversal vulnerability exists in the create_notebook/read_notebook/edit_cell/add_cell functions of server.py in UsamaK98's python-notebook-mcp, allowing remote attackers to access arbitrary files.
Axle-Bucamp MCP-Docusaurus Path Traversal Vulnerability
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in Axle-Bucamp MCP-Docusaurus versions up to commit 404bc028e15ec304c9a045528560f4b5f27a17e0, allowing remote attackers to access sensitive files by manipulating the DOCS_DIR/path argument in specific functions.
Traefik Data Confidentiality Vulnerability
2 rules 1 TTPA vulnerability in Traefik allows an attacker to compromise the confidentiality of data, affecting versions v2.11.x prior to v2.11.44, v3.6.x prior to v3.6.15, and v3.7.0-rc.x prior to v3.7.0-rc.3.
Multiple Vulnerabilities in PaperCut Allow Data Confidentiality Breach and Security Policy Bypass
2 rules 2 TTPs 3 CVEsMultiple vulnerabilities in PaperCut Embedded App versions prior to 2.2.0 on Ricoh devices and PaperCut NG/MF versions prior to 25.0.11 allow attackers to compromise data confidentiality and bypass security policies, potentially leading to unauthorized access and control.
Multiple Vulnerabilities in Apache HTTP Server Allow Remote Code Execution, Privilege Escalation, and Denial of Service
3 rules 3 TTPs 5 CVEsMultiple vulnerabilities in Apache HTTP Server versions prior to 2.4.67 can allow remote attackers to execute arbitrary code, escalate privileges, or cause a denial of service.
Google Android Remote Code Execution Vulnerability
2 rules 1 TTP 1 CVEA vulnerability in Google Android allows a remote attacker to execute arbitrary code, affecting versions prior to 14, 15, 16 and 16-qpr2 before the May 4, 2026 patch.
Arelle Unauthenticated Remote Code Execution Vulnerability
2 rules 1 TTP 1 CVEArelle before 2.39.10 is vulnerable to unauthenticated remote code execution via the /rest/configure REST endpoint, allowing attackers to execute arbitrary Python code by supplying a malicious URL through the plugins parameter.
WordPress Easy PayPal Events & Tickets Plugin Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVE 1 IOCAn unauthenticated remote attacker can exploit a hardcoded authentication bypass vulnerability in the Easy PayPal Events & Tickets plugin for WordPress (versions 1.3 and earlier) by providing 'test' as the hash parameter, allowing retrieval of sensitive order details.
WHM, cPanel, and WP Squared Vulnerability Allows Remote Code Execution
2 rules 1 TTPA vulnerability exists in WHM, cPanel, and WP Squared, Linux-based web hosting control panels, which could allow for remote code execution by bypassing authentication and gaining administrative access.
Norton Secure VPN Privilege Escalation Vulnerability (CVE-2025-58074)
2 rules 1 TTP 1 CVEA privilege escalation vulnerability exists in Norton Secure VPN during installation via the Microsoft Store (CVE-2025-58074), allowing a low-privilege user to replace files leading to arbitrary file deletion and potential elevation of privileges.
Multiple Vulnerabilities in FreeBSD
2 rules 2 TTPs 4 CVEsFreeBSD published security advisories addressing multiple vulnerabilities including remote code execution, local privilege escalation, heap overflow, and stack overflow, affecting all supported versions.
libexif Vulnerability Allows Code Execution
2 rules 2 TTPsA local attacker can exploit a vulnerability in libexif to potentially execute arbitrary code, cause a denial of service, or disclose sensitive information.
Multiple Vulnerabilities in Rapid7 Velociraptor
2 rules 3 TTPsMultiple vulnerabilities in Rapid7 Velociraptor could allow an attacker to disclose information or cause a denial of service.
osrg GoBGP Integer Underflow Vulnerability
2 rules 1 TTP 1 CVEosrg GoBGP up to version 4.3.0 is vulnerable to an integer underflow in the parseRibEntry function, potentially allowing a remote attacker to cause a denial of service or other unspecified impacts; version 4.4.0 addresses this issue.
Multiple Vulnerabilities in Mozilla Thunderbird Allow for Remote Code Execution and Data Breach
2 rules 4 TTPs 5 CVEsMultiple vulnerabilities in Mozilla Thunderbird prior to versions 150.0.1 and Thunderbird ESR prior to 140.10.1 could allow a remote attacker to achieve arbitrary code execution, data confidentiality breach, and security policy bypass.
Microsoft Product Vulnerability CVE-2026-37555
2 rules 1 CVECVE-2026-37555 is a vulnerability affecting a Microsoft product, requiring further investigation upon patch release.
Microsoft CVE-2026-30656 Information Published
1 CVEMicrosoft published information regarding CVE-2026-30656, but the details of the vulnerability are not available.
code-projects Online Hospital Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-7632 is a SQL injection vulnerability in code-projects Online Hospital Management System 1.0, allowing a remote attacker to execute arbitrary SQL commands by manipulating the 'delid' argument in the '/viewappointment.php' file.
Paid Memberships Pro Plugin Vulnerability Allows Unauthorized Stripe Webhook Modification
2 rules 3 TTPs 1 CVEThe Paid Memberships Pro plugin for WordPress is vulnerable to unauthorized modification of Stripe webhook configurations due to missing capability checks, allowing authenticated attackers with Subscriber-level access to disrupt payment processing.
Zyosoft School App Insecure Direct Object Reference Vulnerability
2 rules 3 TTPs 1 CVEZyosoft's School App contains an Insecure Direct Object Reference vulnerability (CVE-2026-7491) that allows authenticated remote attackers to modify parameters and access or modify other users' data.
Flux159 mcp-game-asset-gen Path Traversal Vulnerability
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in Flux159 mcp-game-asset-gen version 0.1.0, where manipulation of the `statusFile` argument in the `image_to_3d_async` function allows for remote exploitation.
JetBrains IntelliJ IDEA Vulnerability
2 rulesA vulnerability exists in JetBrains IntelliJ IDEA versions prior to 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1 and 2026.1.1, requiring users to update to the latest versions.
Microsoft Edge Stable Channel Vulnerabilities Addressed in April 2026 Update
2 rulesMicrosoft addressed vulnerabilities in Microsoft Edge Stable Channel versions prior to 147.0.3912.98 with a security update released on April 30, 2026, requiring users to update to the latest version.
WP Editor Plugin CSRF Vulnerability
2 rules 1 TTP 1 CVEThe WP Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 1.2.9.2, allowing unauthenticated attackers to overwrite arbitrary plugin and theme PHP files with malicious code by tricking a site administrator into clicking a link.
Microsoft Product Vulnerability CVE-2026-41526
1 CVECVE-2026-41526 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon patch release for exploitation details.
Chromium Use-After-Free Vulnerability in Codecs (CVE-2026-7348)
2 rules 1 TTP 1 CVECVE-2026-7348 is a use-after-free vulnerability in the Codecs component of Chromium, affecting Google Chrome and Microsoft Edge.
SourceCodester Advanced School Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-7545) exists in SourceCodester Advanced School Management System 1.0 within the checkEmail endpoint of commonController.php, allowing remote attackers to potentially execute arbitrary SQL commands.
HKUDS OpenHarness Remote Code Execution via /bridge Slash Command (CVE-2026-7551)
2 rules 1 TTP 1 CVEHKUDS OpenHarness contains a remote code execution vulnerability (CVE-2026-7551) in the /bridge slash command, allowing remote attackers to execute arbitrary operating system commands by injecting malicious commands via the /bridge spawn command, leading to unauthorized shell access and data exposure.
IBM Turbonomic prometurbo Agent Privilege Escalation via Excessive Permissions (CVE-2026-6389)
2 rules 2 TTPs 1 CVEIBM Turbonomic prometurbo agent versions 8.16.0 through 8.17.6 grants excessive cluster-wide permissions, including unrestricted read access to all secrets, allowing a compromised operator or service account to exfiltrate credentials, escalate privileges, and achieve full cluster compromise.
IBM Langflow Desktop Unauthenticated Image Access via IDOR
2 rules 1 TTP 1 CVEIBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to an indirect object reference (IDOR) vulnerability (CVE-2026-4503), allowing unauthenticated users to view other users' images due to a user-controlled key.
Sentry SAML SSO Improper Authentication Allows User Identity Linking
2 rules 1 TTPA critical vulnerability (CVE-2026-42354) exists in Sentry's SAML SSO implementation that allows an attacker to take over any user account by using a malicious SAML Identity Provider and another organization on the same Sentry instance, affecting self-hosted users with multiple organizations configured if a malicious user has permissions to modify SSO settings, while Sentry SaaS was patched in April and self-hosted users are advised to upgrade to version 26.4.1 or higher.
HPE Security Advisory for Telco Service Orchestrator and Activator
2 rulesHPE released a security advisory addressing multiple vulnerabilities in HPE Telco Service Orchestrator (versions prior to v5.6.0) and HPE Telco Service Activator (versions 10.5.0 and prior), urging users to apply necessary updates.
Jupyter Notebook Authentication Token Theft via CommandLinker XSS
2 rulesA stored Cross-Site Scripting (XSS) vulnerability in Jupyter Notebook versions 7.0.0 through 7.5.5 and JupyterLab versions up to 4.5.6 allows attackers to steal authentication tokens by tricking users into interacting with malicious notebook files, leading to complete account takeover via the Jupyter REST API.
Potential Copy Fail (CVE-2026-31431) Exploitation via AF_ALG Socket
2 rules 2 TTPs 1 CVEThis rule detects potential exploitation of CVE-2026-31431, a Copy Fail vulnerability in the Linux kernel, via AF_ALG socket abuse, by correlating non-root AF_ALG-class socket or splice events with a subsequent process execution where the effective user is root but the login user remains non-root, indicating a privilege escalation attempt.
GNU InetUtils Vulnerabilities Prior to 2.8
2 rulesGNU released a security advisory addressing critical vulnerabilities in GNU InetUtils versions prior to 2.8, prompting users to apply necessary updates.
Local Privilege Escalation Vulnerability 'Copy Fail' in Linux Kernel
2 rules 1 TTP 1 CVEA local privilege escalation vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), affects Linux kernels released since 2017, allowing an unprivileged local attacker to gain root permissions by exploiting a logic bug in the authencesn cryptographic template.
Critical Authentication Bypass Vulnerability in cPanel & WHM (CVE-2026-41940)
2 rules 1 TTP 1 CVECVE-2026-41940 is a critical authentication bypass vulnerability in cPanel & WHM, allowing unauthenticated remote attackers to gain administrative access by manipulating session data.
ABB AWIN Gateway Vulnerabilities Allow Remote Reboot and Information Disclosure
3 rules 1 TTP 3 CVEsMultiple vulnerabilities in ABB AWIN Gateways allow an unauthenticated attacker to remotely reboot the device (CVE-2025-13778) or disclose sensitive system configuration details (CVE-2025-13777, CVE-2025-13779).
ABB Ability Symphony Plus Engineering Vulnerabilities Allow Remote Code Execution
2 rules 3 TTPs 3 CVEsMultiple vulnerabilities in ABB Ability Symphony Plus Engineering, stemming from underlying PostgreSQL flaws, could allow a remote attacker with network access to execute arbitrary code and compromise the system.
ABB Ability OPTIMAX Authentication Bypass Vulnerability
2 rules 1 TTP 1 CVECVE-2025-14510 allows an attacker to bypass Azure Active Directory Single-Sign On authentication in vulnerable ABB Ability OPTIMAX versions, potentially granting unauthorized access to critical infrastructure systems.
Multiple Vulnerabilities in Absolute Secure Access
2 rules 3 TTPs 1 CVEMultiple vulnerabilities in Absolute Secure Access could allow an attacker to escalate privileges, conduct a denial-of-service attack, and disclose sensitive information.
Multiple Vulnerabilities in SonicWall SonicOS Allow Privilege Escalation and DoS
2 rules 3 TTPs 3 CVEsMultiple vulnerabilities in SonicWall SonicOS allow a remote attacker to escalate privileges, bypass security measures, or cause a denial-of-service condition.
Multiple Vulnerabilities in Red Hat Enterprise Linux Fast Datapath
2 rules 4 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Fast Datapath for Red Hat Enterprise Linux to perform a denial-of-service attack or disclose sensitive information.
libsndfile Vulnerability Allows Denial of Service
2 rules 1 TTPA remote, unauthenticated attacker can exploit an unpatched vulnerability in libsndfile to cause a denial of service.
Multiple Vulnerabilities in CUPS
2 rules 4 TTPs 1 CVEMultiple vulnerabilities in CUPS allow an attacker to bypass security measures, execute arbitrary code, escalate privileges, manipulate data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Xen and Citrix Systems XenServer
3 rules 7 TTPsMultiple vulnerabilities exist in Xen and Citrix Systems XenServer that could allow an attacker to escalate privileges, bypass security measures, modify and disclose data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Wazuh Allow for Code Execution and Data Manipulation
2 rules 6 TTPs 5 CVEsMultiple vulnerabilities in Wazuh allow an attacker to perform a denial of service attack, execute arbitrary code, manipulate data, disclose confidential information, or bypass security measures.
DNSdist Multiple Vulnerabilities Leading to Denial of Service
2 rules 1 TTP 1 CVEMultiple vulnerabilities in DNSdist can be exploited by an attacker to perform a denial of service attack, impacting the availability of DNS services.
Microsoft Published Information on CVE-2026-32777
1 CVEMicrosoft has published information regarding CVE-2026-32777, but no further details regarding the vulnerability or its exploitation are currently available.
Microsoft Published Information on CVE-2026-32776
1 CVEMicrosoft published information regarding CVE-2026-32776, however, further details require JavaScript to be enabled, limiting the actionable intelligence at this time.
Microsoft CVE-2026-32778 Vulnerability Published
2 rules 1 CVEMicrosoft published information regarding vulnerability CVE-2026-32778, but no details regarding the vulnerability are available at this time.
1024-lab smart-admin Improper Access Control Vulnerability (CVE-2026-7468)
2 rules 1 TTP 1 CVECVE-2026-7468 is an improper access control vulnerability in 1024-lab smart-admin up to version 3.30.0, affecting the /smart-admin-api/druid/index.html file, which can be exploited remotely.
VetCoders mcp-server-semgrep OS Command Injection Vulnerability
2 rules 1 TTP 1 CVEVetCoders mcp-server-semgrep version 1.0.0 is vulnerable to remote OS command injection due to manipulation of the ID argument in several functions of the MCP Interface component.
Netgate pfSense XSS Vulnerability
2 rulesA cross-site scripting (XSS) vulnerability affects Netgate pfSense CE (<= 2.8.1) and pfSense Plus (<= 26.03), potentially allowing attackers to inject malicious code.
Multiple Vulnerabilities in Wireshark Lead to Remote Code Execution and Denial of Service
2 rulesMultiple vulnerabilities in Wireshark versions 4.4.x before 4.4.15 and 4.6.x before 4.6.5 could allow remote attackers to execute arbitrary code, cause a denial of service, or compromise data confidentiality.
Multiple Vulnerabilities in Red Hat Linux Kernel
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities in the Red Hat Linux kernel allow for arbitrary code execution, privilege escalation, and remote denial of service.
Multiple Vulnerabilities in MISP Threat Intelligence Platform
2 rules 1 TTPMultiple vulnerabilities in MISP versions prior to 2.5.37 allow attackers to perform privilege escalation, SQL injection (SQLi), and security policy bypass.
Multiple Vulnerabilities in Exim Mail Transfer Agent
3 rules 3 TTPsMultiple vulnerabilities in Exim versions prior to 4.99.2 allow an attacker to cause a remote denial of service, a breach of data confidentiality, and an unspecified security problem.
PolarVista xcode-mcp-server OS Command Injection Vulnerability
2 rules 1 TTP 1 CVEPolarVista xcode-mcp-server 1.0.0 is vulnerable to remote OS command injection via manipulation of the Request argument in the `build_project/run_tests` function, allowing attackers to execute arbitrary commands on the server.
n8n Python Task Runner Sandbox Escape Vulnerability
2 rules 2 TTPsA sandbox escape vulnerability exists in n8n's Python Task Runner that allows an authenticated user with workflow creation/modification permissions to achieve arbitrary code execution on the task runner container, impacting n8n instances with the Python Task Runner enabled; upgrade to versions 1.123.32, 2.17.4, 2.18.1 or later to remediate the vulnerability.
SysGauge Pro 4.6.12 Local Buffer Overflow Vulnerability (CVE-2018-25307)
2 rules 2 TTPs 1 CVESysGauge Pro 4.6.12 is vulnerable to a local buffer overflow in the Register function, allowing local attackers to overwrite the structured exception handler and execute arbitrary code by supplying a crafted unlock key during registration.
SonicWall Firewall Vulnerabilities Addressed in Security Advisory AV26-405
2 rulesSonicWall released a security advisory to address vulnerabilities in Gen6, Gen7, and Gen8 firewalls and SonicOS, urging users to update affected firmware versions to mitigate potential exploits.
Path Traversal Vulnerability in mail-mcp-bridge
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in fatbobman mail-mcp-bridge version 1.3.3 and earlier, allowing a remote attacker to read arbitrary files by manipulating the message_ids argument in the src/mail_mcp_server.py file.
Jenkins Security Advisory Addressing Multiple Plugin Vulnerabilities
2 rulesJenkins released a security advisory on April 29, 2026, detailing vulnerabilities in Credentials Binding Plugin, GitHub Plugin, GitHub Branch Source Plugin, HTML Publisher Plugin, Matrix Authorization Strategy Plugin, Microsoft Entra ID Plugin, and Script Security Plugin, urging users to apply necessary updates.
Zyxel Command Injection Vulnerabilities in CPE and Extenders
2 rules 1 TTPZyxel released a security advisory on April 28, 2026, addressing command injection vulnerabilities across multiple versions of their 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and Wireless Extender products, potentially allowing attackers to execute arbitrary commands.
SmarterTools SmarterMail Vulnerability Prior to Build 9610
2 rulesSmarterTools released a security advisory addressing a vulnerability in SmarterMail versions prior to Build 9610, prompting users to update their software.
OpenClaw StrictInlineEval Approval Bypass Vulnerability (CVE-2026-42423)
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that allows attackers to bypass strictInlineEval explicit-approval requirements on gateway and node exec hosts, leading to arbitrary command execution.
OpenClaw Plugin Archive Integrity Vulnerability (CVE-2026-42428)
2 rules 1 TTP 1 CVEOpenClaw versions before 2026.4.8 fail to enforce integrity verification on downloaded plugin archives, allowing attackers to install malicious plugins and compromise the local assistant environment.
OpenClaw Incomplete Host Environment Variable Sanitization Vulnerability (CVE-2026-41387)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.22 is vulnerable to incomplete host environment variable sanitization, allowing attackers to redirect package resolution or runtime bootstrap to attacker-controlled infrastructure and execute trojanized content.
Notepad++ Vulnerability in Version 8.9.3 and Prior
2 rules 1 TTPA vulnerability exists in Notepad++ version 8.9.3 and prior, prompting a security advisory and the release of version 8.9.4 to address the issue.
Multiple Vulnerabilities in Spring Boot Allow Authorization Bypass and Potential RCE
2 rules 3 TTPs 3 CVEsMultiple vulnerabilities in Spring Boot, including CVE-2026-40976, CVE-2026-40973, and CVE-2026-40972, can allow attackers to bypass authorization, hijack sessions, or achieve remote code execution, potentially leading to data breaches and system compromise.
Mozilla Firefox Multiple Vulnerabilities
2 rules 3 TTPsMozilla released a security advisory addressing vulnerabilities in Firefox and Firefox ESR versions prior to 150.0.1, 140.10.1, and 115.35.1, potentially leading to arbitrary code execution or information disclosure.
Citrix XenServer Vulnerabilities Addressed in Security Advisory AV26-400
2 rules 1 TTPCitrix released security advisory AV26-400 on April 28, 2026, addressing vulnerabilities in XenServer versions prior to 8.4, prompting users to apply mitigations.
Google Chrome Security Update Released
2 rulesGoogle released a security advisory to address vulnerabilities in Chrome for Desktop versions prior to 147.0.7727.137/138 on Windows/Mac and 147.0.7727.137 on Linux, prompting users to apply necessary updates.
Multiple Vulnerabilities in cURL
2 rules 3 TTPs 4 CVEsMultiple vulnerabilities in cURL could allow an attacker to bypass security measures, disclose confidential information, or manipulate data.
Multiple Vulnerabilities in GNU libc
2 rules 3 TTPs 5 CVEsA remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary program code, cause a denial-of-service condition, or disclose sensitive information.
Red Hat Enterprise Linux LibRaw Multiple Vulnerabilities Allow Code Execution or DoS
2 rules 2 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux's LibRaw component allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.
CoreDNS DoQ Server Denial-of-Service Vulnerability
2 rules 3 TTPs 1 CVECoreDNS' DNS-over-QUIC (DoQ) server can be driven into large goroutine and memory growth by a remote client that opens many QUIC streams and stalls after sending only 1 byte, leading to denial of service in versions before 1.14.3.
OpenClaw Improper Authorization Vulnerability (CVE-2026-42426)
2 rules 1 TTP 1 CVEOpenClaw before 2026.4.8 contains an improper authorization vulnerability (CVE-2026-42426) allowing attackers with `operator.write` permissions to bypass node pairing approval and gain unauthorized access to `exec`-capable nodes by exploiting the `node.pair.approve` method which incorrectly accepts the `operator.write` scope instead of the narrower `operator.pairing` scope.
Spring AI Vulnerabilities CVE-2026-40967 and CVE-2026-40978
2 rules 1 TTP 2 CVEsSpring released security advisories on April 27, 2026, to address a VectorStore FilterExpression Converter injection vulnerability (CVE-2026-40967) and a SQL Injection vulnerability (CVE-2026-40978) in Spring AI versions prior to 1.0.6 and 1.1.5.
Broadcom Addresses Critical Vulnerabilities in VMware Tanzu Products
2 rulesBroadcom released a security advisory addressing critical vulnerabilities in VMware Tanzu Data Lake (versions prior to 4.0.0) and VMware Tanzu Greenplum Platform Extension Framework (versions prior to 8.0.0), requiring immediate patching to prevent potential exploitation.
VMware Tanzu Spring Boot Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in VMware Tanzu Spring Boot allow attackers to execute arbitrary code, bypass security measures, manipulate or disclose sensitive data, or hijack authenticated users.
Multiple Vulnerabilities in Atlassian Products
2 rules 4 TTPs 26 CVEsMultiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Jira, and Jira Service Management allow attackers to execute arbitrary code, bypass security measures, manipulate data, disclose information, or perform cross-site scripting attacks.
Path Traversal Vulnerability in engineer-your-data
2 rules 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-7214) exists in eghuzefa's engineer-your-data up to version 0.1.3, allowing remote attackers to read or write arbitrary files by manipulating the WORKSPACE_PATH argument.
Duartium papers-mcp-server Path Traversal Vulnerability (CVE-2026-7205)
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in the `search_papers` function of `src/main.py` in duartium papers-mcp-server version 9ceb3812a6458ba7922ca24a7406f8807bc55598, allowing remote attackers to read arbitrary files by manipulating the `topic` argument, with a public exploit available.
dvladimirov MCP Git Search API Command Injection Vulnerability
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-7211) exists in the GitSearchRequest function of dvladimirov MCP up to version 0.1.0, allowing a remote attacker to execute arbitrary commands by manipulating the repo_url or pattern argument.
Moxa Security Advisory Addresses Vulnerabilities in Multiple Router Series
3 rules 2 CVEsMoxa released a security advisory addressing CVE-2026-3867 and CVE-2026-3868, which affect TN-4900, EDR-8010, EDR-G9010, OnCell G4302-LTE4, OnCell G4308-LTE4, and EDF-G1002-BP series routers, potentially allowing for unauthorized access and control.
Dell Security Advisories Address Vulnerabilities in Multiple Products
2 rulesDell published security advisories addressing vulnerabilities in Dell Networking OS10, Dell Storage Monitoring and Reporting, Dell Storage Resource Manager, and Dell VxRail Appliance, urging users to apply necessary updates.
tufantunc ssh-mcp Command Injection Vulnerability (CVE-2026-7039)
2 rules 1 TTP 1 CVEA command injection vulnerability exists in tufantunc ssh-mcp up to version 1.5.0 via manipulation of the Description argument in the shell.write function.
SQL Injection Vulnerability in code-projects Inventory Management System 1.0
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in code-projects Inventory Management System 1.0 within the Login component, specifically affecting the Username argument, where a remote attacker can manipulate the Username parameter, leading to unauthorized data access or modification.
KLiK SocialMediaWebsite SQL Injection Vulnerability (CVE-2026-7002)
2 rules 1 TTP 1 CVEKLiK SocialMediaWebsite up to version 1.0.1 is vulnerable to SQL injection via manipulation of the c_id argument in the /includes/get_message_ajax.php file, specifically affecting the Private Message Handler component, which can be exploited remotely.
CVE-2026-23398 ICMP NULL Pointer Dereference
2 rules 1 TTP 1 CVECVE-2026-23398 is a vulnerability related to a NULL pointer dereference in the ICMP protocol, potentially leading to a denial-of-service condition in affected Microsoft products.
PicoClaw Web Launcher Management Plane Command Injection Vulnerability
2 rules 1 TTP 1 CVEPicoClaw version 0.2.4 is vulnerable to command injection via the /api/gateway/restart endpoint of the Web Launcher Management Plane, allowing a remote attacker to execute arbitrary commands by manipulating input.
Rclone Unauthenticated Remote Code Execution Vulnerabilities
2 rules 2 TTPs 2 CVEsRclone versions prior to 1.73.5 are vulnerable to two critical unauthenticated remote code execution vulnerabilities (CVE-2026-41176 and CVE-2026-41179) when the remote control API is enabled without authentication, potentially allowing attackers to execute arbitrary commands and compromise the system.
vanna-ai vanna Improper Authorization Vulnerability (CVE-2026-6977)
2 rules 1 TTP 1 CVEAn improper authorization vulnerability (CVE-2026-6977) exists in vanna-ai vanna up to version 2.0.2 due to manipulation of an unknown function within the Legacy Flask API, potentially allowing remote attackers to bypass intended access restrictions.
Microsoft Product Vulnerability CVE-2026-41080
2 rules 1 CVECVE-2026-41080 is a vulnerability affecting a Microsoft product; the specific product, impact, and exploitation details are currently undisclosed.
k8sGPT Operator Vulnerable to Prompt Injection
2 rules 2 TTPsk8sGPT versions before 0.4.32 are vulnerable to prompt injection due to deserialization of AI-generated YAML without proper validation in the auto-remediation pipeline, potentially leading to arbitrary code execution within the Kubernetes cluster.
OVN DHCPv6 Out-of-Bounds Read Vulnerability (CVE-2026-5367)
2 rules 1 TTP 1 CVEA remote attacker can exploit an out-of-bounds read vulnerability in Open Virtual Network (OVN) by sending crafted DHCPv6 SOLICIT packets, leading to sensitive information disclosure.
OpenClaw Remote Code Execution via Node Scope Gate Bypass (CVE-2026-41352)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.31 is vulnerable to remote code execution (CVE-2026-41352) because a device-paired node can bypass the node scope gate authentication mechanism, allowing attackers with device pairing credentials to execute arbitrary node commands.
OpenClaw Cross-Site Request Forgery Vulnerability
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.31 is vulnerable to cross-site request forgery (CSRF) attacks due to missing browser-origin validation in HTTP operator endpoints when operating in trusted-proxy mode, allowing attackers to perform unauthorized actions.
Marimo Pre-Authentication Remote Code Execution Vulnerability (CVE-2026-39987)
2 rules 1 TTP 1 CVECVE-2026-39987 is a pre-authentication remote code execution vulnerability in Marimo, enabling unauthenticated attackers to execute arbitrary system commands.
Flowise Multiple Vulnerabilities
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities in Flowise allow an attacker to execute arbitrary code, bypass security measures, disclose information, and manipulate files.
Multiple Vulnerabilities in Cisco Products Allow for Remote Code Execution
2 rules 4 TTPs 3 CVEsMultiple vulnerabilities in Cisco ASA, Secure Firewall Threat Defense, IOS, IOS XE, and IOS XR allow a remote attacker to bypass authentication and execute arbitrary code with administrator privileges.
Cisco Integrated Management Controller (IMC) Multiple XSS Vulnerabilities
2 rules 1 TTP 5 CVEsMultiple cross-site scripting (XSS) vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct an XSS attack against a user of the interface.
Multiple Vulnerabilities in n8n Workflow Automation Tool
3 rules 5 TTPs 1 CVEMultiple vulnerabilities in n8n can be exploited by an attacker to execute arbitrary code, bypass security measures, disclose sensitive information, conduct SQL injection attacks, cause denial-of-service, perform cross-site scripting, redirect users, or hijack sessions.
Microsoft Product Vulnerability CVE-2026-22005
3 rules 1 CVECVE-2026-22005 is a newly published vulnerability affecting a Microsoft product, requiring further investigation to determine the specific product, attack vector, and potential impact.
Microsoft Discloses Information Regarding CVE-2026-22004
1 rule 1 TTP 1 CVEMicrosoft has released information regarding the vulnerability CVE-2026-22004, but details about the vulnerability and its exploitation are currently unavailable.
Microsoft CVE-2026-35236 Information Published
2 rulesMicrosoft has published information regarding CVE-2026-35236, but no details about the vulnerability or its exploitation are currently available.
CVE-2026-34303 Affecting Microsoft Products
2 rules 1 CVECVE-2026-34303 is a vulnerability affecting an unspecified Microsoft product, requiring further investigation upon disclosure of details.
CI4MS Backup Restore Zip Slip Vulnerability Leads to RCE
2 rules 2 TTPsThe CI4MS Backup restore function is vulnerable to Zip Slip, allowing remote code execution by uploading a malicious ZIP archive that writes PHP files to the public web root due to missing validation of entry names during extraction, affecting versions prior to 0.31.5.0.
Critical RCE Vulnerabilities in Spinnaker
2 rules 1 TTP 2 CVEsCritical vulnerabilities CVE-2026-32613 and CVE-2026-32604 in Spinnaker allow authenticated attackers to execute arbitrary code due to insufficient input validation in expression parsing and gitrepo artifact handling, potentially leading to complete system compromise.
NVIDIA KAI Scheduler Authentication Bypass Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-24177 describes an authentication bypass vulnerability in NVIDIA KAI Scheduler that could allow unauthorized access to API endpoints, leading to information disclosure.
HKUDS OpenHarness Insecure Default Configuration Vulnerability
2 rules 1 TTP 1 CVEHKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit permissive access, potentially leading to unauthorized file disclosure and read access.
FreeScout Mass Assignment Vulnerability (CVE-2026-40569)
2 rules 2 TTPs 1 CVEFreeScout versions prior to 1.8.213 contain a mass assignment vulnerability allowing authenticated admins to modify sensitive mailbox settings by injecting parameters into connection settings requests, leading to email exfiltration and account compromise.
FreeScout Incorrect Authorization Vulnerability (CVE-2026-41189)
2 rules 1 TTP 1 CVEFreeScout versions before 1.8.215 are vulnerable to an incorrect authorization issue where users without conversation access can edit customer threads due to a flaw in the `ThreadPolicy::edit()` function.
CrowdStrike LogScale Unauthenticated Path Traversal Vulnerability (CVE-2026-40050)
2 rules 1 TTP 1 CVEA critical unauthenticated path traversal vulnerability (CVE-2026-40050) in CrowdStrike LogScale allows remote attackers to read arbitrary files from the server filesystem if a specific cluster API endpoint is exposed, necessitating immediate patching for self-hosted customers.
JetBrains TeamCity Authentication Bypass and Path Traversal Vulnerabilities
2 rules 1 TTP 2 CVEsUnpatched JetBrains TeamCity servers are being actively exploited via an authentication bypass (CVE-2024-27198) and path traversal vulnerability (CVE-2024-27199), allowing attackers to perform administrative actions and potentially conduct supply-chain attacks.
BigBlueButton Vulnerabilities Allow Data Manipulation and Redirects
2 rules 1 TTPMultiple vulnerabilities in BigBlueButton can be exploited by an attacker to manipulate data and redirect users to attacker-controlled domains.
Multiple Vulnerabilities in OpenBao Allow for Security Bypass, DoS, and SQL Injection
3 rules 3 TTPsMultiple vulnerabilities in OpenBao can be exploited by an attacker to bypass security measures, conduct a denial of service attack, and conduct a SQL injection attack.
Oracle VM VirtualBox CVE-2026-35246 Vulnerability
2 rules 1 CVECVE-2026-35246 is a vulnerability in Oracle VM VirtualBox version 7.2.6, where a high-privileged attacker with local access can exploit it to compromise the application potentially leading to a complete takeover.
Multiple Vulnerabilities in Fortinet FortiSandbox
3 rules 3 TTPsMultiple vulnerabilities in Fortinet FortiSandbox allow attackers to perform cross-site scripting attacks, disclose information, bypass security measures, and execute arbitrary code, potentially leading to system compromise.
Multiple Vulnerabilities in Red Hat Hardened Images RPMs
2 rules 7 TTPsRemote, anonymous attackers can exploit vulnerabilities in Red Hat Hardened Images RPMs to bypass security measures, cause denial of service, disclose sensitive information, or potentially execute code.
GIMP Multiple Vulnerabilities Allow Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in GIMP to execute arbitrary program code, potentially leading to system compromise.
Cisco Catalyst SD-WAN Manager Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in Cisco Catalyst SD-WAN Manager allow a remote, anonymous, or local attacker to gain administrator privileges, bypass authentication, execute commands with Netadmin rights, read sensitive system information, and overwrite arbitrary files.
Libarchive Code Execution Vulnerability
2 rules 1 TTPA remote attacker can exploit a vulnerability in libarchive to achieve arbitrary code execution on a vulnerable system.
Multiple Vulnerabilities in Roundcube
2 rules 3 TTPsMultiple vulnerabilities in Roundcube allow an attacker to manipulate files, bypass security measures, perform cross-site scripting attacks, and disclose information.
Multiple Vulnerabilities in Microsoft Developer Tools
2 rules 4 TTPsMultiple vulnerabilities in Microsoft Visual Studio, .NET Framework, .NET, PowerShell, and Visual Studio Code can be exploited by an attacker to disclose sensitive information, conduct spoofing attacks, cause a denial of service, or bypass security measures, potentially leading to arbitrary code execution.
Multiple Vulnerabilities in Dell PowerProtect Data Domain OS
2 rules 4 TTPsMultiple vulnerabilities in Dell PowerProtect Data Domain OS allow an attacker to execute arbitrary code with root privileges, escalate privileges to administrator, bypass security measures, manipulate data, disclose sensitive information, or conduct unspecified attacks.
Multiple Vulnerabilities in FreeRDP Allow Remote Code Execution and DoS
2 rules 5 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in FreeRDP to potentially execute arbitrary code, cause a denial-of-service condition, manipulate data, disclose confidential information, or perform other unspecified attacks.
libarchive Multiple Vulnerabilities Allow Information Disclosure and DoS
2 rules 2 TTPsMultiple vulnerabilities in libarchive can be exploited by a remote attacker to disclose information or cause a denial-of-service condition.
Intel IPU, UEFI Reference Firmware: Multiple Vulnerabilities
2 rules 2 TTPsA local attacker can exploit multiple vulnerabilities in Intel Firmware to disclose confidential information or gain elevated privileges.
Microsoft CVE-2026-41254 Security Update
2 rules 1 CVEMicrosoft released a security update for CVE-2026-41254, a vulnerability with unspecified details.
AiAssistant Type Privilege Bypass Vulnerability (CVE-2026-31368)
2 rules 2 TTPs 1 CVECVE-2026-31368 is a type privilege bypass vulnerability in AiAssistant, potentially leading to service availability issues and complete compromise of the system.
Langflow Multiple Vulnerabilities
2 rules 2 TTPsMultiple vulnerabilities in Langflow allow an attacker to manipulate files, disclose sensitive information, or conduct cross-site scripting attacks.
Multiple Vulnerabilities in Gitea
1 rule 1 TTPMultiple vulnerabilities in Gitea could allow an attacker to disclose information, bypass security measures, and perform cross-site scripting attacks.
Multiple Vulnerabilities in Firebird Database Server
2 rules 3 TTPsMultiple vulnerabilities in Firebird allow an attacker to execute arbitrary code with administrator privileges, disclose sensitive information, or cause a denial-of-service condition.
ThreatSonar Anti-Ransomware Arbitrary File Deletion Vulnerability
2 rules 2 TTPs 1 CVETeamT5's ThreatSonar Anti-Ransomware is vulnerable to arbitrary file deletion via path traversal, allowing authenticated remote attackers with web access to delete arbitrary files on the system.
Digiwin EasyFlow .NET SQL Injection Vulnerability (CVE-2026-5964)
2 rules 1 TTP 1 CVEDigiwin's EasyFlow .NET is susceptible to a SQL Injection vulnerability, enabling unauthenticated remote attackers to inject arbitrary SQL commands for unauthorized database access, modification, and deletion.
SecureDrop Client Code Execution via Gzip Extraction Vulnerability
2 rules 1 TTP 2 CVEsA compromised SecureDrop server can achieve code execution on the SecureDrop client's virtual machine by exploiting improper filename validation during gzip archive extraction, allowing for the overwriting of critical files.
OpenClaw Environment Variable Injection Vulnerability
2 rules 1 TTPThe openclaw package versions prior to 2026.4.10 are vulnerable to environment variable injection, where the exec environment policy missed interpreter startup variables allowing operator-supplied environment overrides to influence downstream execution or network behavior, addressed in versions 2026.4.10 and later.
zrok Unauthenticated Denial-of-Service Vulnerability
2 rules 1 TTPAn unauthenticated attacker can cause a denial-of-service (DoS) in zrok by sending a crafted HTTP request with a large cookie chunk count to an OAuth-protected proxy share, triggering unbounded memory allocation and leading to process termination.
Dell PowerProtect Data Domain Improper Certificate Validation Vulnerability
2 rules 1 TTP 1 CVEDell PowerProtect Data Domain versions 7.7.1.0 through 8.5, 8.3.1.0 through 8.3.1.20, and 7.13.1.0 through 7.13.1.60, contain an improper certificate validation vulnerability in certificate-based login, potentially leading to privilege escalation.
Mobatek MobaXterm Home Edition Uncontrolled Search Path Vulnerability (CVE-2026-6421)
2 rules 1 TTP 1 CVECVE-2026-6421 is an uncontrolled search path vulnerability in Mobatek MobaXterm Home Edition up to version 26.1, affecting msimg32.dll, that can be exploited locally with high complexity.
Multiple Vulnerabilities in Cisco Unity Connection
2 rules 1 TTPMultiple vulnerabilities in Cisco Unity Connection can be exploited by an attacker to conduct cross-site scripting attacks, redirect users to malicious websites, manipulate data, and disclose confidential information.
Multiple Vulnerabilities in libssh Allow File Manipulation and DoS
2 rules 1 TTPMultiple vulnerabilities in libssh allow an attacker to manipulate files or cause a denial-of-service condition, potentially leading to data corruption or service disruption.
Grafana Vulnerability Allows File Manipulation and Information Disclosure
2 rules 4 TTPsA remote, authenticated attacker can exploit a vulnerability in Grafana to manipulate files and disclose sensitive information, potentially leading to persistence, unauthorized access, and significant impact.
Microsoft April 2026 Patch Tuesday Addresses 163 Vulnerabilities
2 rules 4 TTPs 6 CVEsMicrosoft's April 2026 Patch Tuesday addresses 163 vulnerabilities, including 8 critical ones, ranging from Tampering to Remote Code Execution and Privilege Escalation, affecting various Microsoft products; it is recommended to apply patches immediately.
Apache ActiveMQ Multiple Vulnerabilities Allow Remote Code Execution
2 rules 1 TTPAn authenticated remote attacker can exploit multiple vulnerabilities in Apache ActiveMQ to manipulate files or execute arbitrary code.
Openfind MailGates/MailAudit CRLF Injection Vulnerability
2 rules 1 TTP 1 CVEOpenfind MailGates/MailAudit is vulnerable to CRLF injection (CVE-2026-6351), enabling unauthenticated remote attackers to read system files by injecting malicious CRLF sequences.
Splunk MCP Server App Cleartext Credential Exposure (CVE-2026-20205)
2 rules 1 TTP 1 CVEA user with access to the `_internal` index or the `mcp_tool_admin` capability in Splunk MCP Server app versions below 1.0.3 can view user session and authorization tokens in clear text, leading to potential credential compromise.
Windows Hyper-V Improper Input Validation Vulnerability (CVE-2026-32149)
2 rules 2 TTPs 1 CVECVE-2026-32149 is a vulnerability in Windows Hyper-V due to improper input validation, which allows an authorized, local attacker to execute arbitrary code.
SQL Server Untrusted Pointer Dereference Vulnerability (CVE-2026-33120)
2 rules 1 TTP 1 CVECVE-2026-33120 is an untrusted pointer dereference vulnerability in Microsoft SQL Server that allows an authenticated attacker to achieve remote code execution over a network.
Microsoft Excel Out-of-Bounds Read Vulnerability (CVE-2026-32188)
2 rules 1 TTP 1 CVEAn out-of-bounds read vulnerability in Microsoft Office Excel (CVE-2026-32188) allows a local attacker to potentially disclose sensitive information through a maliciously crafted Excel file.
CVE-2026-33826: Windows Active Directory Improper Input Validation Vulnerability
2 rules 1 TTP 1 CVEAn improper input validation vulnerability (CVE-2026-33826) in Windows Active Directory could allow an authenticated attacker on an adjacent network to execute code.
Azure Monitor Agent Improper Input Validation Vulnerability (CVE-2026-32168)
2 rules 1 TTP 1 CVECVE-2026-32168 is an improper input validation vulnerability in Azure Monitor Agent that allows a locally authorized attacker to elevate privileges.
Multiple Vulnerabilities in Red Hat Ansible Automation Platform
2 rules 6 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Ansible Automation Platform to perform denial of service, execute arbitrary code, bypass security measures, manipulate data, disclose information, or conduct XSS attacks.
CVE-2026-32183: Windows Snipping Tool Command Injection Vulnerability
2 rules 2 TTPs 1 CVECVE-2026-32183 is a command injection vulnerability in the Windows Snipping Tool that allows a local attacker to execute arbitrary code.
Fortinet FortiSandbox Path Traversal Vulnerability (CVE-2026-39813)
2 rules 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-39813) in Fortinet FortiSandbox versions 5.0.0 through 5.0.5 and 4.4.0 through 4.4.8 may allow an unauthenticated attacker to escalate privileges via '../filedir'.
UniFi Play Improper Access Control Vulnerability (CVE-2026-22566)
2 rules 1 TTP 1 CVEAn improper access control vulnerability in UniFi Play PowerAmp and Audio Port allows a malicious actor with access to the UniFi Play network to obtain WiFi credentials.
Adobe Acrobat and Reader CVE-2026-34621 Zero-Day Exploitation
2 rules 2 TTPs 1 CVE 1 IOCAdobe patched CVE-2026-34621, a zero-day vulnerability in Acrobat and Reader exploited since December, allowing malicious PDFs to bypass sandboxes and execute arbitrary code, potentially leading to local file theft.
SQL Injection Vulnerability in Faculty Management System
2 rules 1 TTP 1 CVEA remote attacker can exploit an SQL injection vulnerability (CVE-2026-6167) in the code-projects Faculty Management System 1.0 by manipulating the ID argument in the /subject-print.php file, potentially leading to data exfiltration or modification.
SQL Injection Vulnerability in Lost and Found Thing Management 1.0
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-6163) exists in code-projects Lost and Found Thing Management 1.0 via manipulation of the 'cat' parameter in /catageory.php, potentially allowing attackers to read, modify, or delete database information.
Huawei Communication Module Use-After-Free Vulnerability (CVE-2026-34856)
2 rules 1 TTP 1 CVEA use-after-free vulnerability, tracked as CVE-2026-34856, exists in Huawei's communication module due to improper synchronization in concurrent execution, potentially leading to a denial-of-service condition.
Mesa WebGPU Out-of-Bounds Write Vulnerability (CVE-2026-40393)
2 rules 1 CVEAn out-of-bounds write vulnerability exists in Mesa versions before 25.3.6 and 26 before 26.0.1 due to an untrusted allocation size in WebGPU, potentially leading to code execution.
Unauthenticated Arbitrary File Write in Saltcorn
2 rules 1 TTP 1 CVEUnauthenticated attackers can exploit a vulnerability in Saltcorn versions prior to 1.4.5, 1.5.5, and 1.6.0-beta.4 to write arbitrary files and list directory contents on the server.
Helm Plugin Path Traversal Vulnerability
2 rules 1 TTP 1 CVE 8 IOCsA path traversal vulnerability in Helm versions 4.0.0 to 4.1.3 allows a malicious plugin to write files to arbitrary locations on the filesystem, leading to potential system compromise.
@sveltejs/adapter-node BODY_SIZE_LIMIT Bypass Vulnerability
2 rules 1 TTP 1 CVEA vulnerability exists in @sveltejs/adapter-node where requests could bypass the `BODY_SIZE_LIMIT` on SvelteKit applications, potentially leading to denial of service.
OpenClaw Path Traversal Vulnerability (CVE-2026-35668)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.24 is vulnerable to path traversal, allowing sandboxed agents to read arbitrary files from other agents' workspaces via manipulated URL parameters.
Juju CloudSpec API Authorization Bypass (CVE-2026-5412)
2 rules 1 TTP 1 CVECVE-2026-5412 describes an authorization issue in Juju versions prior to 2.9.57 and 3.6.21, where a low-privileged authenticated user can call the CloudSpec API method to extract cloud credentials used to bootstrap the controller, leading to sensitive credential exposure.
IBM Semeru Runtime Code Execution Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in IBM Semeru Runtime and IBM DB2 to execute arbitrary program code.
OpenClaw Improper Access Control Vulnerability (CVE-2026-34512)
2 rules 1 TTP 1 CVEOpenClaw before 2026.3.25 contains an improper access control vulnerability (CVE-2026-34512) in the HTTP /sessions/:sessionKey/kill route, allowing any authenticated user to terminate arbitrary subagent sessions.
FoundationAgents MetaGPT Code Injection Vulnerability (CVE-2026-5971)
2 rules 1 TTP 1 CVEA code injection vulnerability exists in FoundationAgents MetaGPT <= 0.8.1 within the ActionNode.xml_fill function, allowing remote attackers to inject code due to improper neutralization of directives in dynamically evaluated code.
BSV Ruby SDK Improper ARC Response Handling
2 rules 1 TTP 1 CVEBSV Ruby SDK versions before 0.8.2 improperly handle ARC responses, treating certain failure statuses as successful broadcasts, potentially tricking applications into trusting unaccepted transactions; version 0.8.2 resolves this vulnerability.
Tmds.DBus Vulnerability Allows Signal Spoofing and Resource Exhaustion
2 rules 1 TTP 1 CVETmds.DBus and Tmds.DBus.Protocol are vulnerable to signal spoofing, resource exhaustion, and application crashes due to malformed messages from malicious D-Bus peers on the same bus.
OPNsense LDAP Injection Vulnerability (CVE-2026-34578)
2 rules 1 TTP 1 CVEOPNsense versions prior to 26.1.6 are vulnerable to LDAP injection, allowing unauthenticated attackers to enumerate valid LDAP usernames and bypass group membership restrictions via the WebGUI login page.
Nix Package Manager Arbitrary File Overwrite Vulnerability
2 rules 1 TTP 2 CVEsA flaw in Nix package manager allows arbitrary file overwrites via symlink following during fixed-output derivation registration, potentially leading to root privilege escalation on multi-user Linux systems.
Multiple Vulnerabilities in Zammad
2 rules 3 TTPsMultiple vulnerabilities in Zammad allow a remote attacker to execute arbitrary code, bypass security measures, disclose sensitive information, and perform cross-site scripting attacks.
UAC (Unix-like Artifacts Collector) Command Injection Vulnerability
2 rules 1 TTP 1 CVEUAC before 3.3.0-rc1 is vulnerable to command injection in the _run_command() function, allowing attackers to execute arbitrary commands with the privileges of the UAC process through manipulated input values.
parseusbs OS Command Injection Vulnerability (CVE-2026-40030)
2 rules 1 TTP 1 CVEparseusbs before 1.9 is vulnerable to OS command injection (CVE-2026-40030) due to improper sanitization of the volume listing path argument, potentially allowing arbitrary command execution via crafted volume paths.
Red Hat Quay Image Upload Interference Vulnerability (CVE-2026-32589)
2 rules 2 TTPs 1 CVECVE-2026-32589 describes a vulnerability in Red Hat Quay's container image upload process where an authenticated user can interfere with other users' uploads, potentially leading to unauthorized access and modification.
D-LINK Router M60 and DIR-3040 'Airsnitch' Vulnerability
2 rules 5 TTPsThe 'Airsnitch' vulnerability in D-LINK Router M60 and DIR-3040 allows an attacker from an adjacent network to bypass security measures, disclose confidential information, and manipulate network traffic.
OpenObserve SSRF via Improper IPv6 Validation
2 rules 1 TTP 1 CVEOpenObserve versions 0.70.3 and earlier are vulnerable to a server-side request forgery (SSRF) attack due to improper validation of IPv6 addresses in the validate_enrichment_url function, potentially allowing authenticated attackers to access internal services and retrieve sensitive cloud metadata.
Mise Trust Bypass Vulnerability via Malicious .mise.toml
2 rules 2 TTPsA vulnerability in mise allows an attacker who can place a malicious .mise.toml file in a repository to bypass trust checks and execute arbitrary code via `[env] _.source` due to improper loading of trust settings.
PowerJob SQL Injection Vulnerability (CVE-2026-5736)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability, CVE-2026-5736, exists in PowerJob versions 5.1.0 through 5.1.2 within the detailPlus Endpoint, potentially allowing unauthenticated attackers to execute arbitrary SQL queries.
CSRF Vulnerability in WordPress Under Construction Plugin (CVE-2026-34896)
2 rules 2 TTPs 1 CVEA cross-site request forgery (CSRF) vulnerability exists in the Analytify Under Construction, Coming Soon & Maintenance Mode WordPress plugin (versions n/a through 2.1.1), potentially allowing attackers to execute unauthorized actions on behalf of legitimate users.
Critical Vulnerability CVE-2026-35616 Exploited in FortiClient EMS
2 rules 1 TTP 1 CVECVE-2026-35616, a critical vulnerability in FortiClient EMS, allows unauthenticated remote attackers to execute arbitrary code or commands via crafted API requests due to improper access control, with Fortinet confirming active exploitation.
Brave CMS Insecure Direct Object Reference Vulnerability (CVE-2026-35183)
1 rule 1 TTP 1 CVEBrave CMS versions prior to 2.0.6 are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability allowing authenticated users with edit permissions to delete images attached to articles owned by other users due to missing ownership verification in the deleteImage method.
GPT Researcher Code Injection Vulnerability (CVE-2026-5631)
2 rules 1 TTP 1 CVEA remote code injection vulnerability exists in assafelovic gpt-researcher versions up to 3.4.3 due to improper handling of the 'args' argument in the extract_command_data function, potentially allowing attackers to execute arbitrary code.
OpenDocMan 1.3.4 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEOpenDocMan version 1.3.4 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries via the 'where' parameter in search.php to extract sensitive information.
Advance Gift Shop Pro Script 2.0.3 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEAdvance Gift Shop Pro Script 2.0.3 is vulnerable to SQL injection via the 's' search parameter, allowing unauthenticated attackers to execute arbitrary SQL queries and extract sensitive database information.
PilusCart 1.4.1 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEPilusCart 1.4.1 is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter to extract sensitive database information.
Fosowl agenticSeek 0.1.0 Code Injection Vulnerability (CVE-2026-5584)
2 rules 1 TTP 1 CVEA code injection vulnerability (CVE-2026-5584) exists in Fosowl agenticSeek 0.1.0, allowing remote attackers to execute arbitrary code by manipulating the query endpoint through the PyInterpreter.execute function.
code-projects Simple Laundry System 1.0 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA remote SQL Injection vulnerability exists in code-projects Simple Laundry System 1.0 within the /delmemberinfo.php file's userid parameter, potentially allowing attackers to execute arbitrary SQL commands.
Provectus Kafka UI Code Injection Vulnerability (CVE-2026-5562)
2 rules 2 TTPs 1 CVEA code injection vulnerability exists in provectus kafka-ui up to version 0.7.2, specifically affecting the validateAccess function within the /api/smartfilters/testexecutions endpoint, allowing remote attackers to inject code.
SQL Injection Vulnerability in Concert Ticket Reservation System
2 rules 1 TTP 1 CVEA remote attacker can exploit CVE-2026-5554 in code-projects Concert Ticket Reservation System 1.0 to perform SQL injection by manipulating the searching argument in the process_search.php file.
SQL Injection Vulnerability in Free Hotel Reservation System 1.0 (CVE-2026-5551)
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-5551) exists in itsourcecode Free Hotel Reservation System 1.0, specifically affecting the `email` parameter within the `/hotel/admin/login.php` file, allowing remote attackers to execute arbitrary SQL queries.
Signal K Server Privilege Escalation via Unprotected /enableSecurity Endpoint
2 rules 1 TTP 1 CVEThe Signal K server is vulnerable to privilege escalation due to the /skServer/enableSecurity endpoint remaining active after initial setup, allowing unauthenticated users to inject a new admin account and gain full server control; this affects versions prior to 2.24.0-beta.4.
Budibase REST Connector SSRF via Empty Blacklist
2 rules 7 TTPsA critical Server-Side Request Forgery (SSRF) vulnerability in Budibase's REST datasource connector allows attackers with Builder privileges to exfiltrate sensitive data from internal network services due to a missing default IP blacklist.
ProfilePress WordPress Plugin Membership Payment Bypass Vulnerability
2 rules 1 TTP 1 CVEThe ProfilePress WordPress plugin before 4.16.12 is vulnerable to an unauthorized membership payment bypass, allowing authenticated attackers to obtain paid memberships without payment by manipulating subscription IDs during checkout.
Directus Aggregate Query Vulnerability Allows Disclosure of Concealed Data
2 rules 1 TTPA vulnerability in Directus versions prior to 11.17.0 allows authenticated users to extract concealed field values, including static API tokens and two-factor authentication secrets from directus_users, via aggregate queries.
PraisonAI Gateway Unauthenticated Access Vulnerability
2 rules 1 TTP 1 CVEPraisonAI Gateway server versions prior to 4.5.97 allow unauthenticated access to WebSocket connections and agent topology, enabling unauthorized message sending and agent enumeration.
Piwigo Unauthenticated History Search Access
2 rules 1 TTP 1 CVE 1 IOCPiwigo versions prior to 16.3.0 expose the full browsing history of gallery visitors to unauthenticated users via the pwg.history.search API method due to a missing authorization check.
fast-jwt Library Vulnerability Allows crit Header Validation Bypass
2 rules 1 TTP 1 CVEThe fast-jwt library fails to validate the 'crit' header, allowing attackers to bypass security policies and potentially achieve split-brain verification in mixed-library environments.
SandboxJS Integrity Escape Vulnerability
2 rules 2 TTPsA sandbox integrity escape vulnerability exists in SandboxJS versions prior to 0.8.36, allowing untrusted code to bypass global write protections and mutate host shared global objects, potentially leading to cross-context persistence and broader compromise.
Budibase Path Traversal Vulnerability in Plugin Upload
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in Budibase versions prior to 3.33.4, allowing attackers with Global Builder privileges to delete arbitrary directories and write arbitrary files via crafted plugin uploads.
fast-jwt Library JWT Algorithm Confusion Vulnerability
2 rules 1 TTP 1 CVEThe fast-jwt library is vulnerable to JWT Algorithm Confusion via Whitespace-Prefixed RSA Public Key due to an incomplete fix for CVE-2023-48223, allowing attackers to bypass intended security measures by exploiting leading whitespace in the RSA public key, enabling attackers to sign arbitrary payloads that will be accepted by the verifier, potentially leading to privilege escalation.
ManageEngine Exchange Reporter Plus Stored XSS Vulnerability
2 rules 2 TTPs 1 CVEZohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in the Distribution Lists report, allowing attackers to inject malicious scripts.
Swift Crypto X-Wing HPKE Decapsulation Vulnerability
2 rules 1 TTPThe X-Wing decapsulation path in swift-crypto accepts attacker-controlled encapsulated ciphertext bytes without enforcing the required fixed ciphertext length of 1120 bytes, leading to a potential out-of-bounds read.
Electron Use-After-Free Vulnerability in Offscreen Rendering with Child Windows
2 rulesA use-after-free vulnerability (CVE-2026-34774) exists in Electron applications using offscreen rendering and allowing child windows, potentially leading to crashes or memory corruption if the parent WebContents is destroyed before the child window.
Electron Use-After-Free Vulnerability in PowerMonitor Module
2 rules 1 TTPA use-after-free vulnerability exists in the `powerMonitor` module of Electron applications on Windows and macOS. When the native `PowerMonitor` object is garbage-collected, dangling references are retained by OS-level resources. Subsequent session-change events on Windows or system shutdowns on macOS may dereference freed memory, potentially leading to a crash or memory corruption.
Azure MCP Server Missing Authentication Vulnerability (CVE-2026-32211)
2 rules 1 TTP 1 CVECVE-2026-32211 is a critical vulnerability in Azure MCP Server due to missing authentication for a critical function, allowing an unauthorized attacker to disclose information over the network.
OneUptime Unauthenticated Endpoint Access Vulnerability (CVE-2026-34758)
2 rules 1 TTP 1 CVEOneUptime versions prior to 10.0.42 are vulnerable to unauthenticated access to Notification test and Phone Number management endpoints, leading to potential abuse of SMS, Call, Email, and WhatsApp functionalities, and unauthorized phone number purchases, fixed in version 10.0.42.
Endian Firewall Command Injection Vulnerability (CVE-2026-34791)
2 rules 1 TTP 1 CVEEndian Firewall version 3.3.25 and prior allows authenticated users to execute arbitrary OS commands due to an OS command injection vulnerability in the DATE parameter of the /cgi-bin/logs_proxy.cgi endpoint.
Suricata DCERPC Buffering Inefficiency Vulnerability (CVE-2026-31937)
2 rules 1 TTP 1 CVESuricata versions prior to 7.0.15 are vulnerable to CVE-2026-31937, where inefficient DCERPC buffering can lead to a denial-of-service condition through performance degradation.
Unauthenticated SQL Injection Vulnerability in setinfo Endpoint
2 rules 1 TTP 1 CVE 2 IOCsAn unauthenticated remote attacker can exploit a SQL Injection vulnerability (CVE-2026-33615) in the setinfo endpoint by injecting malicious code into a SQL UPDATE command, leading to a total loss of integrity and availability.
Unauthenticated SQL Injection Vulnerability in getinfo Endpoint (CVE-2026-33614)
2 rules 1 TTP 1 CVEAn unauthenticated SQL Injection vulnerability (CVE-2026-33614) in the getinfo endpoint allows a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements, potentially leading to a total loss of confidentiality.
Juju Controller Vulnerable to Unauthorized Database Access Due to Improper TLS Configuration
2 rules 3 TTPsJuju controller versions 3.2.0 up to 3.6.20 and 4.0.5 are vulnerable to unauthorized database access due to improper TLS client/server authentication and certificate verification, allowing an attacker with network access to modify all information, escalate privileges, and open firewall ports.
Payload CMS Password Reset Vulnerability (CVE-2026-34751)
2 rules 1 TTP 1 CVEAn unauthenticated attacker can perform actions on behalf of a user initiating a password reset in Payload CMS versions prior to 3.79.1 due to a flaw in the password recovery flow, potentially leading to account takeover or privilege escalation.
pandas-ai SQL Injection Vulnerability (CVE-2026-30273)
2 rules 1 TTP 1 CVEpandas-ai v3.0.0 is vulnerable to SQL injection via the pandasai.agent.base._execute_sql_query component, potentially allowing unauthorized database access and modification.
Critical Vulnerability in FastGPT Allows API Key Exfiltration and Internal Network Access
2 rules 3 TTPs 1 CVE 1 IOCCVE-2026-34162 in FastGPT allows unauthenticated attackers to exfiltrate API keys and gain complete access to internal services managed by Docker Compose by sending arbitrary HTTP requests, leading to potential compromise of the internal network.
F5 BIG-IP APM CVE-2025-53521 Reclassified as Actively Exploited Unauthenticated RCE
2 rules 1 TTP 1 CVEF5 has reclassified CVE-2025-53521, a vulnerability in BIG-IP APM, as a critical unauthenticated remote code execution vulnerability and reports it is being actively exploited in the wild.
7-Zip Multiple Vulnerabilities Allow Remote Code Execution
2 rules 1 TTPMultiple vulnerabilities in 7-Zip allow an attacker to execute arbitrary program code with the privileges of the service, potentially leading to system compromise.
Multiple Vulnerabilities in PowerDNS
1 ruleMultiple vulnerabilities in PowerDNS could be exploited by an attacker to disclose information, bypass security measures, cause a denial of service, and potentially execute code.
Multiple Vulnerabilities in libpng Allow Remote Code Execution and Denial of Service
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in libpng to execute arbitrary program code or cause a denial of service.
7-Zip Vulnerability Allows File Manipulation
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in 7-Zip to manipulate files, leading to potential data integrity issues.
IBM App Connect Enterprise Multiple Vulnerabilities
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in IBM App Connect Enterprise to cause a denial-of-service condition or bypass security measures, enabling cross-site scripting attacks.
Red Hat Enterprise Linux libxslt Vulnerability Allows DoS and Code Execution
2 rules 2 TTPsA local attacker can exploit a vulnerability in libxslt on Red Hat Enterprise Linux to cause a denial of service or execute arbitrary program code.
MPPX TypeScript Interface Vulnerability (CVE-2026-34209)
1 rule 1 TTP 1 CVEA vulnerability exists in mppx TypeScript interface before version 0.4.11, allowing attackers to close or grief channels for free by submitting close vouchers equal to the settled amount due to incorrect validation.
SQL Injection Vulnerability in Student Membership System 1.0
2 rules 1 TTP 1 CVECVE-2026-5198 is a SQL injection vulnerability in the Admin Login component of code-projects Student Membership System 1.0, affecting the /admin/index.php file, enabling remote exploitation through manipulation of username/password parameters.
OpenClaw Information Disclosure via Telegram Bot Token Exposure
2 rules 1 CVEOpenClaw before version 2026.3.13 exposes Telegram bot tokens in error messages due to the fetchRemoteMedia function embedding these tokens in MediaFetchError strings when media downloads fail.
DELMIA Factory Resource Manager Stored XSS Vulnerability (CVE-2025-10553)
2 rules 1 TTP 1 CVEA stored cross-site scripting (XSS) vulnerability in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x (CVE-2025-10553) allows attackers to execute arbitrary script code within a user's browser session.
DELMIA Factory Resource Manager Path Traversal Vulnerability (CVE-2025-10559)
2 rules 1 TTP 1 CVECVE-2025-10559 is a path traversal vulnerability in DELMIA Factory Resource Manager, affecting versions 3DEXPERIENCE R2023x through R2025x, which allows an attacker with low privileges to read or write files in specific directories on the server, potentially leading to information disclosure or code execution.
ImageMagick Multiple Vulnerabilities Leading to DoS, Code Execution, or Data Manipulation
2 rules 1 TTPMultiple vulnerabilities in ImageMagick could allow an attacker to perform a denial of service attack, execute arbitrary code, or manipulate data.
SQL Injection Vulnerability in SourceCodester Simple Doctors Appointment System 1.0 (CVE-2026-5180)
2 rules 1 TTP 1 CVEA SQL Injection vulnerability (CVE-2026-5180) exists in SourceCodester Simple Doctors Appointment System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'email' parameter in the /admin/ajax.php?action=login2 endpoint.
SQL Injection Vulnerability in SourceCodester Simple Doctors Appointment System 1.0 (CVE-2026-5179)
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-5179) exists in SourceCodester Simple Doctors Appointment System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the Username argument in the /admin/login.php file, with a public exploit available.
vcpkg OpenSSL Windows Build Path Vulnerability (CVE-2026-34054)
2 rules 2 TTPs 1 CVEA vulnerability exists in vcpkg versions prior to 3.6.1#3, where Windows builds of OpenSSL set openssldir to a path on the build machine, making that path vulnerable to attack on customer machines.
SciTokens Library Path Traversal Vulnerability (CVE-2026-32727)
2 rules 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-32727) in SciTokens library versions prior to 1.9.7 allows attackers to bypass intended directory restrictions using dot-dot sequences in the scope claim of a token due to improper path normalization.
baserCMS DOM-Based Cross-Site Scripting Vulnerability (CVE-2026-32734)
2 rules 1 TTP 1 CVEbaserCMS versions prior to 5.2.3 are vulnerable to DOM-based Cross-Site Scripting (XSS) due to improper neutralization of input during web page generation, potentially allowing a remote attacker to execute arbitrary JavaScript in a user's browser.
Botan SM2 Decryption Heap Over-read Vulnerability (CVE-2026-32877)
2 rules 1 TTP 1 CVEBotan C++ cryptography library versions 2.3.0 before 3.11.0 are vulnerable to a heap over-read during SM2 decryption due to insufficient validation of the authentication code length, potentially leading to crashes or undefined behavior.
Symantec DLP Windows Endpoint Elevation of Privilege Vulnerability (CVE-2026-3991)
2 rules 1 TTPCVE-2026-3991 is an elevation of privilege vulnerability in Symantec Data Loss Prevention (DLP) Windows Endpoint that could allow a local attacker to gain elevated access to resources.
Glances XML-RPC Server Cross-Origin Information Disclosure
2 rules 3 TTPs 1 IOCThe Glances XML-RPC server exposes sensitive system information due to a permissive CORS policy and missing Content-Type validation, enabling attackers to bypass CORS restrictions and steal data like hostnames, OS details, IP addresses, and process lists.
Gotenberg Chromium Deny-List Bypass via Case-Insensitive URL Scheme
2 rules 1 TTPGotenberg versions before 8.29.0 are vulnerable to unauthenticated arbitrary file read, where a case-insensitive URL scheme bypasses the Chromium deny-list, allowing attackers to read sensitive files such as /etc/passwd by using mixed-case or uppercase URL schemes like FILE:///etc/passwd, leading to the leakage of sensitive data from the Gotenberg container and bypassing the fix for CVE-2024-21527.
Multiple Vulnerabilities in Wazuh Leading to Code Execution and Data Manipulation
2 rules 6 TTPsMultiple vulnerabilities in Wazuh allow an attacker to perform denial-of-service attacks, execute arbitrary code, manipulate data, and disclose sensitive information, potentially leading to significant data breaches and system compromise.
Multiple Vulnerabilities in Fleet
2 rules 8 TTPsMultiple vulnerabilities in Fleet allow an attacker to perform SQL injection, denial of service, bypass security measures, disclose information, and execute arbitrary program code with administrator privileges.
Multiple Vulnerabilities in Grafana
2 rules 4 TTPsMultiple vulnerabilities in Grafana allow a remote attacker to conduct a denial-of-service attack, execute code, or disclose information.
Langflow Vulnerability Allows File Manipulation
2 rules 1 TTPAn authenticated, remote attacker can exploit a vulnerability in Langflow to manipulate files, potentially leading to unauthorized data modification or application compromise.
OpenBao Multiple Vulnerabilities Allow Security Bypass and XSS
2 rules 4 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in OpenBao to bypass security measures or conduct cross-site scripting attacks.
Multiple Vulnerabilities in Dovecot Mail Server
2 rules 2 TTPsMultiple vulnerabilities in Dovecot can be exploited by an attacker to perform SQL injection attacks, bypass authentication, disclose sensitive information, or cause a denial-of-service condition.
Multiple Vulnerabilities in NGINX and NGINX Plus
2 rules 1 TTPMultiple vulnerabilities in NGINX Plus and NGINX can be exploited by an attacker to perform a denial of service attack, manipulate data, bypass security measures, and potentially execute arbitrary program code, leading to significant impact.
Multiple Vulnerabilities in F5 BIG-IP and F5OS
2 rules 5 TTPsMultiple vulnerabilities in F5 BIG-IP and F5OS allow an attacker to bypass security mechanisms, escalate privileges, cause a denial-of-service condition, perform a cross-site scripting attack, and disclose or manipulate information.
CVE-2026-2328 Unauthenticated Path Traversal Vulnerability
2 rules 1 TTPCVE-2026-2328 describes a vulnerability where an unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, leading to the exposure of sensitive information.
OpenClaw Gateway Plugin Subagent Admin Scope Vulnerability
2 rules 1 TTPThe openclaw package versions 2026.3.24 and earlier are vulnerable due to the gateway plugin subagent fallback `deleteSession` function dispatching `sessions.delete` with a synthetic `operator.admin` runtime scope, potentially leading to unauthorized session deletion.
OpenClaw Credential Exposure via Leaked Pairing Codes
2 rules 1 TTPOpenClaw before 2026.3.12 embeds long-lived shared gateway credentials in pairing setup codes, allowing attackers with access to leaked codes to reuse credentials and gain unauthorized access.
SQL Injection Vulnerability in Simple Food Order System 1.0
2 rules 1 TTPA SQL injection vulnerability exists in code-projects Simple Food Order System 1.0 within the register-router.php file, where manipulation of the Name argument can lead to remote code execution.
code-projects Simple Food Order System SQL Injection Vulnerability (CVE-2026-5017)
2 rules 1 TTPCVE-2026-5017 is a SQL injection vulnerability in code-projects Simple Food Order System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'Status' parameter in the `/all-tickets.php` file.
SQL Injection Vulnerability in Sinaptik AI PandasAI lancedb Extension
2 rules 1 TTPA SQL injection vulnerability exists in Sinaptik AI PandasAI up to version 0.1.4 within the pandasai-lancedb Extension, allowing remote exploitation through manipulation of multiple functions in the lancedb.py file.
Clerk SSRF Vulnerability in frontendApiProxy Allows Secret Key Leakage
2 rules 1 TTPA server-side request forgery (SSRF) vulnerability exists in the `clerkFrontendApiProxy` function of the `@clerk/backend` package, allowing an unauthenticated attacker to send the application's `Clerk-Secret-Key` to an attacker-controlled server.
LangChain Core Path Traversal Vulnerability in Legacy APIs
1 rule 1 TTPA path traversal vulnerability in LangChain Core's legacy `load_prompt` functions allows attackers to read arbitrary files by injecting malicious paths into prompt configurations.
OpenClaw Gateway Plugin Grants Unrestricted operator.admin Runtime Scope
2 rules 1 TTPThe openclaw gateway plugin versions 2026.3.24 and earlier incorrectly grants operator.admin runtime scope to all callers, regardless of their granted scopes, potentially allowing unauthorized actions.
Giskard-agents ChatWorkflow.chat() Server-Side Template Injection
2 rules 1 TTPGiskard-agents versions 0.3.3 and earlier, and versions 1.0.1a1 through 1.0.2a1 are vulnerable to remote code execution via server-side template injection where the ChatWorkflow.chat() method passes user-supplied strings directly to a non-sandboxed Jinja2 Environment, allowing attackers to execute arbitrary code on the server.
LinkAce Server-Side Request Forgery Vulnerability (CVE-2026-33953)
2 rules 1 TTPLinkAce versions prior to 2.5.3 are vulnerable to server-side request forgery (SSRF), allowing an authenticated user to trigger server-side requests to internal services by referencing internal hostnames.
Langflow IDOR Vulnerability Allows Cross-User Flow Manipulation
2 rules 3 TTPsLangflow versions 1.5.0 and earlier contain an IDOR vulnerability (CVE-2026-34046) that allows authenticated users to read, modify, and delete flows belonging to other users due to a missing ownership check, potentially exposing sensitive information and enabling unauthorized control over AI agent logic.
Postiz App SSRF Vulnerability via Next.js
2 rules 1 TTPA high-severity SSRF vulnerability exists in the Postiz application via Next.js, allowing attackers to bypass firewalls, scan internal networks, access sensitive cloud metadata (AWS IMDS), potentially leak instance credentials, and pivot within the internal network.
Multiple Vulnerabilities in Canva Affinity, TP-Link, and HikVision Devices
3 rules 6 TTPsCisco Talos disclosed multiple vulnerabilities in Canva Affinity, TP-Link Archer AX53, and HikVision Ultra Face Recognition Terminal products which could lead to sensitive information disclosure, arbitrary code execution, or credentials leak if exploited.
OpenClaw Symlink Traversal via IDENTITY.md appendFile in agents.create/update
2 rules 2 TTPsOpenClaw is vulnerable to symlink traversal via IDENTITY.md appendFile in agents.create/update. An attacker who can place a symlink in the agent workspace can hijack the IDENTITY.md path to append attacker-controlled content to arbitrary files on the system leading to remote code execution, persistent code execution, unauthorized SSH access, or service disruption.
LIBPNG Out-of-Bounds Read/Write Vulnerability in Neon Optimization (CVE-2026-33636)
2 rules 2 TTPsAn out-of-bounds read and write vulnerability in LIBPNG's ARM/AArch64 Neon-optimized palette expansion path (CVE-2026-33636) allows attackers to potentially achieve denial-of-service or arbitrary code execution by crafting malicious PNG images.
Critical Vulnerabilities in n8n Workflow Automation Tool
3 rules 2 TTPsMultiple critical vulnerabilities in n8n, including prototype pollution, code injection, and SQL injection, allow authenticated users to achieve remote code execution, read sensitive files, and perform unauthorized database operations.
Doveadm Credentials Vulnerable to Timing Oracle Attack (CVE-2026-27856)
2 rules 1 TTPDoveadm credentials are verified using direct comparison, making it susceptible to timing oracle attacks, allowing attackers to determine credentials and gain full access.
OpenClaw ACP Chat Command Injection Vulnerability
2 rulesA vulnerability in the openclaw npm package before version 2026.3.22 allowed mutating internal ACP chat commands without requiring operator.admin scope enforcement, potentially allowing unauthorized control-plane actions.
OpenClaw Nostr DM Unauthorized Crypto Computation Vulnerability
2 rulesThe openclaw npm package before version 2026.3.22 allows unauthorized pre-authentication computation due to improper handling of inbound Nostr DMs, where crypto and dispatch work are performed before enforcing sender and pairing policies.
KomSeo Cart 1.3 SQL Injection Vulnerability
2 rules 1 TTPKomSeo Cart 1.3 is vulnerable to SQL injection via the 'my_item_search' parameter in edit.php, allowing attackers to inject SQL commands and extract sensitive database information.
ASP.NET jVideo Kit 1.0 SQL Injection Vulnerability
2 rules 1 TTPASP.NET jVideo Kit 1.0 is vulnerable to SQL injection via the 'query' parameter in the search functionality, allowing unauthenticated attackers to inject malicious SQL payloads to extract sensitive database information.
School Management System CMS 1.0 SQL Injection Vulnerability
2 rules 1 TTPSchool Management System CMS 1.0 is vulnerable to SQL injection in the admin login functionality, allowing attackers to bypass authentication by injecting SQL code through the username parameter.
SQL Injection Vulnerability in Simple Laundry System 1.0
2 rules 1 TTPA remote SQL Injection vulnerability exists in code-projects Simple Laundry System 1.0 within the Parameter Handler component's /checkregisitem.php file, where manipulating the Long-arm-shirtVol argument can trigger the injection, with a publicly available exploit.
SQL Injection Vulnerability in itsourcecode Online Enrollment System 1.0
2 rules 1 TTPA remote SQL injection vulnerability exists in itsourcecode Online Enrollment System 1.0 within the Parameter Handler component affecting the `/sms/grades/index.php` file, allowing unauthorized database access and has been publicly disclosed.
Netcore Power 15AX Remote Command Execution Vulnerability
2 rules 1 TTPCVE-2026-4840 is a critical command injection vulnerability in the Netcore Power 15AX router that allows remote attackers to execute arbitrary OS commands by manipulating the IpAddr argument in the setTools function of the /bin/netis.cgi file.
OpenEMR Blind SQL Injection Vulnerability in Patient Search (CVE-2026-29187)
2 rules 1 TTPOpenEMR versions prior to 8.0.0.3 are susceptible to a blind SQL injection vulnerability in the Patient Search functionality, allowing authenticated attackers to execute arbitrary SQL commands by manipulating HTTP parameter keys.
SiYuan Arbitrary Document Reading Vulnerability in Publishing Service
2 rules 1 TTPSiYuan is vulnerable to arbitrary document reading via the publishing service, allowing attackers to retrieve document IDs and view the content of all documents, including encrypted or prohibited ones, by exploiting the `/api/file/readDir` and `/api/block/getChildBlocks` interfaces.
Kiteworks Core Access Control Vulnerability (CVE-2026-23514)
2 rules 1 TTPKiteworks Core versions 9.2.0 and 9.2.1 contain an access control vulnerability (CVE-2026-23514) due to improper ownership management, allowing authenticated users to access unauthorized content, which can be mitigated by upgrading to version 9.2.2 or later.
Multiple Vulnerabilities in GnuPG and Gpg4win Allow for Arbitrary Code Execution and Denial of Service
2 rules 2 TTPsMultiple vulnerabilities exist in GnuPG and Gpg4win that could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.
Langflow Path Traversal Vulnerability (CVE-2026-33497)
2 rules 1 TTPA path traversal vulnerability in Langflow versions before 1.7.1 allows unauthenticated attackers to read sensitive files via the download_profile_picture endpoint due to insufficient filtering of the folder_name and file_name parameters.
GoHarbor Harbor v2.15.0 and Below Vulnerable to Hardcoded Credentials
2 rules 1 TTPGoHarbor Harbor version 2.15.0 and below is vulnerable to the use of hard-coded credentials, allowing an attacker to use the default password and gain unauthorized access to the web UI.
CPython Zipfile Module Vulnerability Allows File Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in the zipfile module of CPython to manipulate files on affected systems.
IBM WebSphere Application Server Liberty Multiple Vulnerabilities
2 rules 3 TTPsA remote, authenticated attacker can exploit multiple vulnerabilities in IBM WebSphere Application Server Liberty to escalate privileges, bypass security measures, and disclose information.
TIBCO ActiveMatrix Vulnerability Allows Information Disclosure and Data Manipulation
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in TIBCO ActiveMatrix and TIBCO Administrator to disclose information and manipulate data, potentially leading to unauthorized access and control.
Langflow Vulnerability Allows Arbitrary Code Execution
2 rules 1 TTPA vulnerability in Langflow allows an attacker to execute arbitrary code, potentially leading to system compromise.
Multiple Vulnerabilities in Redis
2 rules 2 TTPsMultiple vulnerabilities in Redis allow an attacker to execute arbitrary program code and perform a denial-of-service attack.
Multiple Vulnerabilities in Red Hat Developer Hub
2 rules 8 TTPsMultiple vulnerabilities in Red Hat Developer Hub allow a remote attacker to perform denial of service, execute arbitrary code, bypass security measures, and manipulate data.
Multiple Vulnerabilities in Grub Bootloader
2 rules 2 TTPsMultiple vulnerabilities in the Grub bootloader allow attackers to execute arbitrary code and cause denial-of-service conditions.
Multiple Vulnerabilities in Apache Tomcat Allow for Remote Code Execution and Data Manipulation
2 rules 3 TTPsMultiple vulnerabilities in Apache Tomcat can be exploited by a remote, authenticated or anonymous attacker to execute arbitrary code, bypass security measures, manipulate data, and cause a denial of service.
Red Hat OpenShift GitOps Multiple Vulnerabilities
2 rules 1 TTPAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift GitOps to manipulate data, misrepresent information, or cause a denial of service.
IBM Tivoli Netcool/OMNIbus Multiple Vulnerabilities
2 rules 3 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus to achieve arbitrary code execution, information disclosure, file manipulation, or denial of service.
Checkmk Vulnerability Allows Session Hijacking
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Checkmk to bypass security measures, leading to session hijacking.
Multiple Vulnerabilities in Vim Allow Local Code Execution and DoS
2 rules 2 TTPsMultiple vulnerabilities in vim allow a local attacker to execute arbitrary code, cause a denial-of-service condition, or manipulate data.
Multiple Vulnerabilities in Langflow Allow for Arbitrary Code Execution and Information Disclosure
2 rules 4 TTPsMultiple vulnerabilities in Langflow could be exploited by an attacker to execute arbitrary program code, disclose information, and potentially manipulate data, leading to potential system compromise.
Froxlor Vulnerability Allows File Manipulation and Information Disclosure
2 rules 1 TTPA vulnerability in Froxlor allows an attacker to manipulate files and disclose sensitive information, potentially leading to data breaches or system compromise.
CODESYS Multiple Vulnerabilities Allow Arbitrary Code Execution and DoS
2 rules 2 TTPsMultiple vulnerabilities in CODESYS allow a remote attacker to execute arbitrary program code and conduct a denial-of-service attack.
Multiple Vulnerabilities in GStreamer
3 rules 2 TTPsMultiple vulnerabilities in GStreamer allow a remote, anonymous attacker to cause a denial-of-service condition, memory corruption, and potentially execute arbitrary code.
Critical Unauthenticated RCE Vulnerability Exploited in Microsoft SharePoint
2 rules 2 TTPsA remote code execution vulnerability in Microsoft SharePoint (CVE not specified) is being actively exploited by unauthenticated attackers, prompting urgent patching recommendations for internet-facing servers.
Out-of-Cancel Vulnerability Class in Linux Workqueue Cancellation APIs
2 rules 1 TTPThe 'Out-of-Cancel' vulnerability class stems from flaws in Linux workqueue cancellation APIs, potentially leading to exploitable conditions within the kernel.
Craft CMS Authenticated Remote Code Execution via Malicious Attached Behavior
2 rules 1 TTPA remote code execution vulnerability exists in Craft CMS versions 5.6.0 through 5.9.12, where any authenticated user with control panel access can exploit the vulnerability by injecting malicious behavior via the `fieldLayouts` parameter in `ElementIndexesController::actionFilterHud()` due to the unsanitized parameter being passed to `FieldLayout::createFromConfig()`.
Vikunja Account Reactivation Vulnerability (CVE-2026-33316)
3 rules 1 TTPA critical vulnerability in Vikunja versions prior to 2.2.0 allows disabled users to bypass administrator controls and reactivate their accounts by exploiting a flaw in the password reset logic.
Uninitialized Memory Vulnerability in Firefox Canvas2D (CVE-2026-4715)
2 rulesCVE-2026-4715 is a critical vulnerability involving uninitialized memory in the Graphics: Canvas2D component of Firefox, Firefox ESR, and Thunderbird, potentially leading to information disclosure or arbitrary code execution.
Mozilla Firefox and Thunderbird Graphics Text Component Vulnerability (CVE-2026-4719)
2 rules 2 TTPsCVE-2026-4719 describes an incorrect boundary condition in the Graphics: Text component of Mozilla Firefox and Thunderbird, potentially leading to a denial-of-service condition in vulnerable versions.
Multiple Vulnerabilities in Cpython Allow Remote Code Execution
2 rules 1 TTPA remote, authenticated attacker can exploit multiple vulnerabilities in Cpython to manipulate files or execute arbitrary code.
Oracle MySQL Multiple Vulnerabilities
2 rules 1 TTPA remote attacker, either anonymous or authenticated, can exploit multiple vulnerabilities in Oracle MySQL to compromise confidentiality, integrity, and availability.
libpng Vulnerability Allows Code Execution
2 rules 4 TTPsA vulnerability in libpng allows a remote, anonymous attacker to potentially execute arbitrary code, disclose sensitive information, or cause a denial-of-service condition.
Citrix Systems NetScaler Vulnerabilities Allow Information Disclosure and Session Hijacking
2 rules 2 TTPsAn anonymous or authenticated remote attacker can exploit multiple vulnerabilities in Citrix Systems NetScaler to disclose information and take over a user session.
PhreeBooks ERP 5.2.3 Remote Code Execution Vulnerability
2 rules 3 TTPsPhreeBooks ERP 5.2.3 is vulnerable to remote code execution, allowing authenticated attackers to upload and execute arbitrary PHP files via the image manager, leading to reverse shell connections and system command execution.
Netartmedia Vlog System SQL Injection Vulnerability
2 rules 1 TTP 1 IOCNetartmedia Vlog System is vulnerable to SQL injection, allowing unauthenticated attackers to manipulate database queries by injecting SQL code through the email parameter in the forgotten_password module.
Bootstrapy CMS Unauthenticated SQL Injection Vulnerabilities
3 rules 1 TTPBootstrapy CMS contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters to extract sensitive database information or cause denial of service.
AIDA64 Extreme 5.99.4900 Structured Exception Handler Buffer Overflow
2 rules 1 TTP 1 IOCAIDA64 Extreme 5.99.4900 is vulnerable to a structured exception handler buffer overflow, allowing local attackers to execute arbitrary code by supplying a malicious CSV log file path through the Hardware Monitoring logging preferences.
Multiple Vulnerabilities in cPanel/WHM
2 rules 2 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in cPanel/WHM to bypass security measures, perform XSS and SSRF attacks, disclose information, and potentially execute code.
ReviewX WordPress Plugin Arbitrary Method Call Vulnerability
2 rules 1 TTPThe ReviewX WordPress plugin is vulnerable to arbitrary method calls, allowing unauthenticated attackers to potentially achieve remote code execution.
Oracle Fusion Middleware RCE Vulnerability (CVE-2026-21992)
2 rules 2 TTPsCVE-2026-21992 allows an unauthenticated attacker to gain network access via HTTP and execute code remotely on Oracle Identity Manager and Oracle Web Services Manager.
cURL Vulnerability Allows File Manipulation
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in cURL to manipulate files on a vulnerable system.
Multiple Vulnerabilities in libpng Allow Remote Code Execution and Denial of Service
2 rules 2 TTPsMultiple vulnerabilities in libpng allow a remote, anonymous attacker to perform denial of service attacks and execute arbitrary code.
GIMP Vulnerability Allows Remote Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in GIMP to execute arbitrary code on a targeted system.
Multiple Vulnerabilities in FreeRDP Allow for DoS and Potential Code Execution
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in FreeRDP to cause a denial of service or potentially execute arbitrary program code.
Apache Commons FileUpload Denial of Service Vulnerability
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Apache Commons FileUpload to perform a denial of service attack.
Apache Commons BeanUtils Security Bypass Vulnerability
1 rule 1 TTPAn authenticated remote attacker can exploit a vulnerability in Apache Commons BeanUtils to bypass security measures, potentially leading to unauthorized access or privilege escalation.
Out-of-bounds Write Vulnerability in DualSenseY-v2
2 rules 3 TTPsCVE-2026-33850 is an out-of-bounds write vulnerability in WujekFoliarz DualSenseY-v2 before version 54, potentially allowing an attacker to execute arbitrary code or cause a denial-of-service by writing data outside the allocated buffer.
SourceCodester Online Admission System 1.0 SQL Injection Vulnerability
2 rules 1 TTP 1 IOCA SQL injection vulnerability in SourceCodester Online Admission System 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'program' argument in the /programmes.php file.
Citrix NetScaler ADC and Gateway Vulnerabilities
2 rulesCitrix has released a security advisory addressing multiple vulnerabilities in NetScaler ADC and NetScaler Gateway that could lead to sensitive information disclosure and user session mix-up under specific configurations.
Erupt Framework SQL Injection Vulnerability (CVE-2026-4594)
2 rules 1 TTPA SQL injection vulnerability (CVE-2026-4594) exists in erupts erupt up to version 1.13.3, allowing remote attackers to execute arbitrary SQL commands by manipulating the sort.field argument in the geneEruptHqlOrderBy function.
WWBN AVideo Unauthorized File Access and Deletion Vulnerability
2 rules 2 TTPsWWBN AVideo platform versions up to 26.0 are vulnerable to unauthorized file access and deletion, where an authenticated user with upload permissions can exploit the `objects/import.json.php` endpoint by manipulating the `fileURI` parameter to steal private video files, read adjacent text files, and delete `.mp4` and other writable files on the filesystem.
Xenstore Crash Vulnerability via Malicious Node Path Access (CVE-2026-23555)
2 rules 1 TTPA guest VM issuing a Xenstore command with the node path '/local/domain/' can crash xenstored (CVE-2026-23555), or, if NDEBUG is defined, cause denial of service by consuming all CPU resources.
Jsrsasign < 11.1.1 Incorrect Conversion Vulnerability (CVE-2026-4602)
2 rules 1 TTPJsrsasign versions before 11.1.1 are vulnerable to an incorrect conversion between numeric types vulnerability, where an attacker can force the computation of incorrect modular inverses and break signature verification by calling modPow with a negative exponent.
Jsrsasign Infinite Loop Vulnerability (CVE-2026-4598)
2 rules 1 TTPJsrsasign versions before 11.1.1 are vulnerable to an infinite loop via the bnModInverse function when processing zero or negative inputs, potentially leading to a denial of service.
Critical Vulnerabilities in Quest KACE SMA Allow System Takeover
2 rules 4 TTPsMultiple critical vulnerabilities in Quest KACE Systems Management Appliance (SMA), including authentication bypass and 2FA bypass, allow unauthenticated attackers to achieve system takeover and cause denial of service; active exploitation is reported.
Vulnerabilities in Paxton Net2 Access Control Units
2 rules 8 TTPs 1 IOCVulnerabilities in Paxton Net2 Access Control Units (ACUs) could allow unauthorized remote access and control of secured doors, potentially affecting prisons and other high-security facilities.
Memory Exhaustion Vulnerability in Widely Used Python Library
2 rules 1 TTPA memory exhaustion vulnerability (CVE-2026-33155) exists in a widely used Python library, affecting services like SageMaker, DataHub, and acryl-datahub due to an incomplete patch for CVE-2025-58367, requiring pinning to version 8.6.2.
Vulnerabilities Disclosed in IP KVM Devices from Multiple Vendors
2 rules 2 TTPsResearchers have disclosed unspecified vulnerabilities in IP KVM devices from four manufacturers, potentially allowing attackers to gain unauthorized access to connected systems.
Critical XSS Vulnerabilities in AFFiNE
2 rules 1 TTP 2 IOCsTwo critical XSS vulnerabilities, Reflected XSS in the /image-proxy endpoint and Stored XSS in bookmark cards, were discovered in AFFiNE, a self-hosted alternative to Notion, with the vendor being unresponsive.
ScreenConnect 26.1 Cryptographic Material Protection Vulnerability
2 rules 1 TTPScreenConnect version 26.1 has a vulnerability related to the insufficient protection of server-level cryptographic material, potentially allowing unauthorized access and data compromise.
Angular Cross-Site Scripting (XSS) Vulnerability
2 rules 5 TTPsA cross-site scripting (XSS) vulnerability exists in Angular versions prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19.2.20, allowing attackers to execute arbitrary code within the context of the vulnerable application, potentially leading to session hijacking, data exfiltration, and unauthorized actions.
Multiple Critical Vulnerabilities in Veeam Backup & Replication Allow Remote Code Execution
2 rules 3 TTPsMultiple critical vulnerabilities in Veeam Backup & Replication, including CVE-2026-21666, CVE-2026-21668, CVE-2026-21669, CVE-2026-21670, CVE-2026-21671, CVE-2026-21672, and CVE-2026-21708, allow for remote code execution, privilege escalation, and arbitrary file manipulation by authenticated users, potentially leading to a complete compromise of the backup infrastructure.
CISA Adds Google Skia and Chromium V8 Vulnerabilities to KEV Catalog
2 rules 3 TTPsCISA added CVE-2026-3909, an out-of-bounds write vulnerability in Google Skia, and CVE-2026-3910, an unspecified vulnerability in Google Chromium V8 to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation, highlighting the need for timely remediation.
Critical Unauthenticated RCE Vulnerability in Junos OS Evolved
2 rules 3 TTPsA critical unauthenticated remote code execution vulnerability, CVE-2026-21902, exists in Juniper Networks Junos OS Evolved PTX Series, allowing a network-based attacker to execute code as root, requiring immediate patching and increased monitoring.
Critical Vulnerabilities in n8n Workflow Automation Platform
3 rules 3 TTPsMultiple critical vulnerabilities in n8n versions prior to 2.10.1, 2.9.3, and 1.123.22 enable authenticated users to execute arbitrary code and system commands, potentially leading to full system compromise.
Mobility46 Charging Station Vulnerabilities Allow Unauthorized Control and Disruption
2 rules 3 TTPs 1 IOCMultiple vulnerabilities in Mobility46 charging stations allow attackers to gain unauthorized administrative control or disrupt charging services through missing authentication, improper authentication restrictions, insufficient session expiration, and exposed credentials.
EV2GO Charging Station Vulnerabilities Allow Impersonation and Denial of Service
2 rules 3 TTPs 1 IOCMultiple vulnerabilities in EV2GO charging stations, including missing authentication and session management flaws, could allow attackers to impersonate stations, hijack sessions, and cause denial-of-service conditions.
Critical RCE Vulnerability in Cisco Catalyst SD-WAN Controller
2 rules 2 TTPsA critical remote code execution vulnerability exists in Cisco Catalyst SD-WAN Controllers (CVE-2026-20127) due to improper authentication, allowing unauthenticated remote attackers to bypass authentication and gain administrative privileges, potentially leading to network configuration manipulation.
Multiple Vulnerabilities in EV Energy ev.energy Charging Stations
2 rulesMultiple vulnerabilities exist in EV Energy ev.energy that could allow an attacker to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
Multiple Vulnerabilities in Chargemap Charging Stations
2 rules 5 TTPs 1 IOCUnauthenticated attackers can exploit multiple vulnerabilities in Chargemap's charging stations, including missing authentication, improper authentication attempt restrictions, insufficient session expiration, and unprotected credentials, potentially leading to unauthorized control and denial-of-service.
Johnson Controls Frick Controls Quantum HD Multiple Vulnerabilities
2 rules 4 TTPsMultiple vulnerabilities in Johnson Controls, Inc. Frick Controls Quantum HD versions <=10.22 can lead to pre-authentication remote code execution, information leak, or denial of service.
Critical Vulnerabilities in SolarWinds Serv-U Allow Remote Code Execution
2 rules 3 TTPsMultiple critical vulnerabilities in SolarWinds Serv-U MFT and FTP Server allow remote code execution, potentially leading to system compromise.
Copeland XWEB and XWEB Pro Multiple Vulnerabilities
2 rules 6 TTPsMultiple vulnerabilities in Copeland XWEB and XWEB Pro versions 1.12.1 and earlier could allow attackers to bypass authentication, inject commands, and execute arbitrary code, leading to complete system compromise.
Critical Vulnerabilities in FreeScout Help Desk Allow Remote Code Execution
2 rules 2 TTPsCritical vulnerabilities, CVE-2026-27636 and CVE-2026-27637, exist in FreeScout Help Desk that could be exploited to achieve remote code execution, potentially leading to data exfiltration and system compromise.
Ongoing Exploitation of Cisco SD-WAN Systems
3 rules 4 TTPsMalicious actors are actively exploiting CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation and persistence on Cisco SD-WAN systems globally.
Potential Foxmail Exploitation Leading to Initial Access
2 rules 1 TTPThis rule detects potential exploitation of Foxmail client to gain initial access and execute malicious code by monitoring for Foxmail client spawning child processes with arguments pointing to user-profile AppData paths or remote shares, indicating exploitation of a Foxmail vulnerability through a malicious email.
VMware Tanzu Spring Framework Multiple Vulnerabilities
2 rules 2 TTPsAn anonymous, remote attacker can exploit multiple vulnerabilities in VMware Tanzu Spring Framework to disclose information or circumvent security measures.
Open WebUI Improper Authorization Control Vulnerability
2 rules 1 TTP 1 IOCOpen WebUI version 0.1.105 is vulnerable to an improper authorization control issue, where user accounts with a `pending` status can bypass authorization checks and make authenticated API calls as a `user` context due to the application failing to properly validate the user's role beyond JWT validation.
libxml2 Vulnerability Allows XXE Attacks
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in libxml2 to manipulate files or cause a denial of service.
Grafana Vulnerability Allows Remote Code Execution
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Grafana to execute arbitrary code, potentially leading to system compromise and data exfiltration.
VMware Tanzu Spring Framework Vulnerability Allows File Manipulation
2 rules 1 TTPAn anonymous remote attacker can exploit a vulnerability in VMware Tanzu Spring Framework to manipulate files or disclose information.
Apache Tomcat Vulnerability Allows Remote Code Execution
2 rules 1 TTPAn anonymous, remote attacker can exploit an unspecified vulnerability in Apache Tomcat to achieve arbitrary code execution.
Oracle Fusion Middleware Multiple Vulnerabilities
2 rules 1 TTPAn unauthenticated or authenticated remote attacker can exploit multiple vulnerabilities in Oracle Fusion Middleware to compromise confidentiality, integrity, and availability.
Roundcube Vulnerabilities Leading to Cross-Site Scripting and Information Disclosure
2 rules 1 TTP 3 CVEsMultiple vulnerabilities in Roundcube allow an attacker to perform a cross-site scripting attack and disclose confidential information.
Phoenix Contact FL MGUARD Multiple Vulnerabilities
2 rules 3 TTPsA remote attacker can exploit multiple vulnerabilities in Phoenix Contact FL MGUARD to escalate privileges, disclose sensitive information, or cause a denial-of-service condition.
NetScaler ADC and Gateway Vulnerabilities Lead to Session Mixup
2 rules 1 TTPA race condition vulnerability in NetScaler ADC and Gateway (CVE-2026-3055 and CVE-2026-4368) could lead to user session mixup, potentially allowing unauthorized access to sensitive information.
zyx0814 FilePress SQL Injection Vulnerability (CVE-2026-8133)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-8133) exists in zyx0814 FilePress up to version 2.2.0 via the Shares Filelist API by manipulating the argument order, potentially leading to unauthorized data access or modification.
Open WebUI Cross-Instance Cache Poisoning Vulnerability
2 rules 2 TTPsOpen WebUI versions up to 0.8.12 are vulnerable to cross-instance cache poisoning when multiple instances share a Redis backend, allowing an attacker with admin access on one instance to overwrite cache values used by other instances, leading to data exfiltration and prompt injection attacks.
phpseclib Library Vulnerable to Prime Number Generation Weakness
2 rules 1 TTPThe phpseclib library has a vulnerability affecting prime number generation and primality testing, impacting versions >= 0.1.1 and < 1.0.23, >= 2.0.0 and < 2.0.47, and >= 3.0.0 and < 3.0.36, potentially leading to insecure cryptographic operations.
Argo Workflows ConfigMap Sync Service Missing Authorization Vulnerability
2 rules 1 TTPThe Sync Service's ConfigMap-backed provider in Argo Workflows performs zero authorization checks on all CRUD operations, allowing any authenticated user to create, read, update, and delete Kubernetes ConfigMaps containing synchronization limits, potentially leading to denial of service, workflow disruption, information disclosure, or arbitrary ConfigMap manipulation in Argo Workflows versions v4.0.0 to v4.0.4.
GStreamer Multiple Vulnerabilities Allow for Remote Code Execution and Denial of Service
2 rules 2 TTPs 5 CVEsMultiple vulnerabilities in GStreamer allow a remote, anonymous attacker to cause a denial-of-service condition or execute arbitrary code.
WSO2 Products Vulnerable to XML External Entity (XXE) Injection via CVE-2024-2374
2 rules 2 TTPsCVE-2024-2374 describes an XML External Entity (XXE) vulnerability in multiple WSO2 products, where improperly configured XML parsers allow attackers to inject malicious XML payloads to include external resources, leading to confidential file access, limited HTTP resource access, and denial-of-service attacks.
Azure Sign-In Log Bypass Vulnerabilities
2 rules 2 TTPs 1 IOCA recently disclosed vulnerability allows attackers to bypass Azure sign-in logs, potentially masking malicious activity within cloud environments.
MPPX Payment Bypass and Griefing Vulnerabilities
2 rules 5 TTPsMultiple vulnerabilities in the `mppx` npm package (versions prior to 0.4.8) allow for payment bypass, transaction replay attacks, fee manipulation, signature bypass, and channel griefing, potentially leading to financial loss and service disruption.
Red Hat Integration Camel for Spring Boot Multiple Vulnerabilities
2 rules 1 TTPAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat Integration Camel for Spring Boot to compromise confidentiality, availability, and integrity.
Postiz File Upload Vulnerability Leads to Stored XSS (CVE-2026-40487)
2 rules 5 TTPs 1 CVEAn authenticated file upload validation bypass in Postiz prior to version 2.21.6 allows attackers to upload arbitrary HTML, SVG, or other executable file types by spoofing the `Content-Type` header, resulting in stored XSS and potential account takeover.
Oxia TLS Certificate Chain Validation Failure
2 rules 1 TTPOxia's `trustedCertPool()` function fails to parse multi-certificate PEM bundles, leading to certificate chain validation failure and rejection of legitimate clients in mTLS deployments.
Matrimony Website Script M-Plus SQL Injection Vulnerabilities
2 rules 1 TTPMatrimony Website Script M-Plus is vulnerable to unauthenticated SQL injection via POST parameters, enabling attackers to extract sensitive data or execute arbitrary SQL commands.
DigitalOcean Droplet Agent Command Injection Vulnerability (CVE-2026-24516)
2 rules 3 TTPs 1 IOCCVE-2026-24516 is a command injection vulnerability in DigitalOcean Droplet Agent through 1.3.2, allowing attackers to execute arbitrary OS commands with root privileges by manipulating metadata responses due to insufficient input validation in the troubleshooting actioner component.
DiceBear SVG Size Capping Bypass Leads to Denial of Service
2 rules 1 TTPA denial-of-service vulnerability exists in DiceBear versions prior to 9.4.2 due to a bypassable regex in the `ensureSize()` function, allowing attackers to craft SVGs that cause out-of-memory crashes during rendering on Node.js.
changedetection.io XXE Vulnerability
2 rules 1 TTPA vulnerability in changedetection.io versions 0.54.9 and earlier allows a remote attacker to perform XML External Entity (XXE) attacks, potentially exposing sensitive local files.
free5GC PCF Nil Pointer Dereference Vulnerability
2 rules 1 TTP 2 IOCsA nil-pointer dereference vulnerability exists in free5GC's PCF when handling POST requests to `/npcf-smpolicycontrol/v1/sm-policies`. When a downstream UDR lookup returns a 404 error, the handler continues execution instead of returning, leading to a nil response struct dereference and a panic. This results in an HTTP 500 error for the request, but the PCF process continues running. The vulnerability is triggered by sending a POST request with input that causes the downstream UDR lookup to fail, such as an unknown DNN. This issue affects free5GC versions v4.1.0 and v4.2.1.
OpenHarness Command Injection Vulnerability (CVE-2026-40502)
2 rules 1 TTP 1 CVEOpenHarness versions prior to commit dd1d235 are vulnerable to command injection, allowing remote gateway users with chat access to execute administrative commands and alter system permissions.
Connect-CMS Code Study Plugin Arbitrary Code Execution
2 rules 1 TTPAn authenticated user of the Connect-CMS Code Study Plugin can execute arbitrary code due to a vulnerability (CVE-2026-32276) in versions 1.x before 1.41.1 and 2.x before 2.41.1, potentially leading to code execution on the server or information disclosure.
AVideo CDN Plugin Unauthenticated Configuration Modification
2 rules 3 TTPsAVideo is vulnerable to unauthenticated configuration modification in its CDN plugin due to a bypassed key validation check when the default empty key is used, allowing modification of CDN URLs, storage credentials, and the authentication key itself.
Acrel EEMS Enterprise Power Operation and Maintenance Cloud Platform SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0 when manipulating the 'fCircuitids' argument in the '/SubstationWEBV2/main/elecMaxMinAvgValue' file, potentially allowing for remote code execution or data exfiltration.
@fastify/middie Middleware Bypass Vulnerability via Duplicate Slashes
2 rules 1 TTP 1 CVE`@fastify/middie` versions 9.3.1 and earlier are vulnerable to middleware bypass via URLs with duplicate leading slashes due to improper handling of the deprecated `ignoreDuplicateSlashes` option, potentially allowing unauthorized access to protected resources.
Vite Arbitrary File Read Vulnerability via WebSocket
2 rules 1 TTPVite versions 6.0.0 to 8.0.4 are vulnerable to arbitrary file read, allowing attackers to bypass access controls and retrieve the contents of arbitrary files on the server via the WebSocket path when the dev server is exposed to the network.
GitLab MCP Server Unauthenticated Access via SSE Transport
2 rules 2 TTPsThe @yoda.digital/gitlab-mcp-server's SSE transport lacks authentication and uses wildcard CORS, enabling unauthenticated attackers to execute arbitrary GitLab API calls using the operator's GitLab PAT, including destructive operations.
Simple Social Media Share Buttons CSRF Vulnerability (CVE-2026-34904)
2 rules 1 TTP 1 CVEA cross-site request forgery (CSRF) vulnerability exists in the Simple Social Media Share Buttons WordPress plugin (versions through 6.2.0), potentially allowing attackers to perform unauthorized actions on behalf of authenticated users.
xmldom XML Node Injection via Comment Serialization
2 rules 1 TTPThe xmldom library is vulnerable to XML node injection, allowing attackers to inject arbitrary XML nodes into serialized output by manipulating comment content; this is mitigated by using the `requireWellFormed` option in `serializeToString` after upgrading to version 0.8.13 or 0.9.10.
MindsDB Unrestricted File Upload Vulnerability (CVE-2026-7711)
2 rules 1 TTP 1 CVECVE-2026-7711 allows for remote, unrestricted file uploads in MindsDB up to version 26.01 due to insufficient validation in the `exec` function of `proc_wrapper.py`, potentially leading to code execution or data exfiltration.
Langflow Unauthenticated Image Retrieval Vulnerability (CVE-2026-33484)
2 rules 1 TTPLangflow versions 1.0.0 through 1.8.1 are vulnerable to an unauthenticated image retrieval vulnerability (CVE-2026-33484) that allows attackers to download any user's uploaded images without credentials in multi-tenant deployments by accessing the `/api/v1/files/images/{flow_id}/{file_name}` endpoint.
MISP Modules Website CSRF Vulnerability
2 rules 1 TTPA critical Cross-Site Request Forgery (CSRF) vulnerability in the MISP Modules website allows an attacker to induce an authenticated user to submit unintended requests to the home endpoint, potentially modifying session query data.
goxmlsig Vulnerability CVE-2026-33487 Loop Variable Capture
2 rulesA vulnerability exists in goxmlsig versions prior to 1.6.0 related to loop variable capture in the `validateSignature` function when using older Go versions, leading to incorrect signature validation.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability
2 rules 1 TTP 1 CVEA cross-site scripting (XSS) vulnerability in Synacor Zimbra Collaboration Suite (ZCS) could allow attackers to execute arbitrary JavaScript within a user's session, potentially leading to unauthorized access to sensitive information.
OpenClaw Lower-Trust Output Injection Vulnerability
2 rulesA vulnerability in OpenClaw versions 2026.4.2 and earlier allows lower-trust runtime output to be injected into trusted system events, potentially leading to prompt injection.
NATS.io MQTT ACL Bypass Vulnerability
2 rules 1 TTPA vulnerability in NATS.io versions before v2.12.6 or v2.11.15 allows MQTT clients to bypass ACL checks for MQTT subjects due to ACLs not being applied in the `$MQTT.>` namespace, potentially allowing unauthorized access and control of MQTT communications.
Mako Template Engine Path Traversal Vulnerability on Windows
2 rules 1 TTPA path traversal vulnerability exists in Mako versions 1.3.11 and earlier on Windows, allowing attackers to read arbitrary files outside the configured template directory by using backslashes in URIs to bypass directory traversal checks.
goshs SimpleHTTPServer SFTP Authentication Bypass Vulnerability (CVE-2026-40884)
2 rules 1 TTP 1 CVEgoshs SimpleHTTPServer prior to version 2.0.0-beta.6 contains an SFTP authentication bypass vulnerability that allows unauthenticated network attackers to access files when the server is started with specific configuration parameters.
Flowise DocumentStore IDOR Vulnerability
2 rules 1 TTPA mass assignment vulnerability in the DocumentStore creation endpoint of Flowise allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. By exploiting the implicit UPSERT operation, an attacker can overwrite existing DocumentStore objects, potentially leading to cross-workspace object takeover and broken object-level authorization (IDOR) in multi-tenant deployments.
CVE-2026-31611: ksmbd Sub-Authority Validation Vulnerability
2 rules 1 TTP 1 CVECVE-2026-31611 is a vulnerability in ksmbd, requiring at least three sub-authorities before reading sub_auth[2], potentially leading to unauthorized access or code execution.
Connect CMS Form Plugin Stored XSS Vulnerability
2 rulesA stored cross-site scripting (XSS) vulnerability exists in the file field of the Form Plugin in Connect CMS versions 1.x series <= 1.41.0 and 2.x series <= 2.41.0, allowing arbitrary script execution in an administrator's browser, potentially leading to unauthorized actions or information theft.
ORY Oathkeeper Authentication Bypass Vulnerability (CVE-2026-33496)
2 rules 1 TTPORY Oathkeeper before 26.2.0 is vulnerable to authentication bypass (CVE-2026-33496) due to cache key confusion in the `oauth2_introspection` authenticator, allowing attackers with a valid token to bypass authentication by reusing it with different introspection URLs.
NATS Server MQTT Password Disclosure Vulnerability
3 rules 1 TTPThe NATS server exposes MQTT passwords in plaintext via monitoring endpoints due to incorrect classification as JWTs, affecting versions before v2.12.6 or v2.11.15.
Intake Package Remote Code Execution via Malicious Catalog
2 rules 1 TTPA remote code execution vulnerability exists in Intake versions prior to 2.0.9 due to the automatic expansion of the `shell()` syntax within parameter default values during catalog parsing, allowing an attacker to execute arbitrary commands by loading a malicious catalog YAML file.
BigSweetPotatoStudio HyperChat AI Proxy Middleware Server-Side Request Forgery
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability exists in BigSweetPotatoStudio HyperChat up to version 2.0.0-alpha.63, allowing a remote attacker to manipulate the 'baseurl' argument in the 'fetch' function of the AI Proxy Middleware component to make arbitrary HTTP requests.
Auth0.js SDK Improper Permission Checking Vulnerability
2 rules 1 TTPThe Auth0.js SDK versions 8.11.0 to 9.32.0 improperly returns user profile information when provided a crafted invalid ID token, potentially bypassing access controls relying on Auth0 Actions.
PHPGurukul Online Course Registration 3.1 SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-5814) exists in PHPGurukul Online Course Registration 3.1, allowing remote attackers to execute arbitrary SQL queries by manipulating the 'regno' argument in the /admin/check_availability.php file.
CVE-2026-34293: Unspecified Vulnerability in Microsoft Product
2 rules 1 CVECVE-2026-34293 is an unspecified vulnerability affecting a Microsoft product, for which details are currently unavailable, posing a potential risk to affected systems.
CVE-2026-31613 SMB Client Out-of-Bounds Read Vulnerability
2 rules 1 TTP 1 CVECVE-2026-31613 is an out-of-bounds read vulnerability in the SMB client when parsing symlink error responses, requiring patching to prevent potential information disclosure or denial-of-service.
AVideo CSRF Vulnerability Allows Admin Impersonation
2 rules 1 TTP 1 CVEAVideo versions 29.0 and prior contain a CSRF vulnerability in admin-only JSON endpoints, allowing attackers to perform unauthorized actions if they can lure a logged-in administrator to visit a malicious page.
SiYuan Path Traversal Vulnerability (CVE-2026-40318)
3 rules 1 TTP 1 CVESiYuan versions 3.6.3 and prior are vulnerable to path traversal (CVE-2026-40318), allowing attackers to delete arbitrary .json files on the server via the /api/av/removeUnusedAttributeView endpoint.
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability (CVE-2026-20133)
2 rules 1 TTP 1 CVECisco Catalyst SD-WAN Manager contains an information disclosure vulnerability (CVE-2026-20133) that could allow remote attackers to view sensitive information on affected systems, requiring immediate patching or mitigation.
OpenClaw Configuration Redaction Bypass Vulnerability
2 rulesA vulnerability in the openclaw npm package before version 2026.4.14 allows authenticated clients with config read access to receive unredacted secrets due to bypasses in `sourceConfig` and `runtimeConfig` alias fields.
Mozilla Firefox and Thunderbird WebRTC Undefined Behavior Vulnerability (CVE-2026-4705)
2 rules 3 TTPs 2 IOCsAn undefined behavior vulnerability in the WebRTC signaling component affects Mozilla Firefox and Thunderbird, potentially leading to arbitrary code execution.
SiYuan Unauthorized Attribute View Deletion Vulnerability (CVE-2026-40259)
2 rules 1 CVESiYuan versions 3.6.3 and below are vulnerable to unauthorized attribute view deletion via the /api/av/removeUnusedAttributeView endpoint, allowing authenticated users with publish-service RoleReader tokens to delete arbitrary attribute view definitions, leading to database view breakage and workspace rendering issues.
Rails Active Storage Vulnerability Allows Arbitrary File Deletion
2 rules 1 TTPA vulnerability in Rails Active Storage allows attackers to delete arbitrary files in the storage directory by exploiting glob metacharacters in blob keys passed to `Dir.glob`.
chatboxai chatbox Command Injection Vulnerability (CVE-2026-6130)
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-6130) exists in chatboxai chatbox versions up to 1.20.0, allowing a remote attacker to execute arbitrary OS commands by manipulating the 'args/env' argument in the StdioClientTransport function, potentially leading to complete system compromise.
Web Server Potential Remote File Inclusion Activity
2 rules 2 TTPsThis rule detects potential Remote File Inclusion (RFI) activity on web servers by identifying HTTP GET requests that attempt to access sensitive remote files through directory traversal techniques or known file paths, potentially leading to information disclosure or further compromise.
PraisonAI Browser Server Unauthenticated Session Hijacking Vulnerability
2 rules 1 TTPPraisonAI Browser Server is vulnerable to unauthenticated WebSocket client hijacking due to exposing the browser bridge on 0.0.0.0 by default and accepting WebSocket clients that omit the Origin header, allowing unauthorized remote use of a connected browser automation session.
OpenClaw MCP Loopback Token Spoofing Vulnerability
2 rules 1 TTPA vulnerability in OpenClaw versions 2026.4.21 and earlier allows a non-owner loopback client to spoof the owner context by manipulating request headers, potentially gaining unauthorized access to owner-gated operations.
FlowiseAI API Chain SSRF Vulnerability
2 rules 2 TTPs 2 IOCsA Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components, allowing unauthenticated attackers to force the server to make arbitrary HTTP requests to internal and external systems by injecting malicious prompt templates.
Directus SSRF Vulnerability via IPv4-Mapped IPv6 Addresses
2 rules 1 TTP 3 IOCsDirectus versions before 11.16.0 are vulnerable to Server-Side Request Forgery (SSRF) due to a bypass in IP address validation using IPv4-Mapped IPv6 addresses, allowing attackers to access internal services and sensitive cloud metadata.
ArchiveBox RCE via Unvalidated Configuration Overrides
2 rules 1 TTPArchiveBox versions 0.8.6rc0 and earlier are vulnerable to remote code execution (RCE) due to unvalidated configuration overrides in the AddView (/add/ endpoint) allowing arbitrary command execution.
GitPython Command Injection Vulnerability
2 rules 1 TTPGitPython versions 3.1.30 through 3.1.46 are vulnerable to command injection by passing attacker-controlled kwargs into `Repo.clone_from()`, `Remote.fetch()`, `Remote.pull()`, or `Remote.push()`, leading to arbitrary command execution due to bypassed safety checks.
LangChain Unsafe Deserialization Vulnerability
2 rules 1 TTPLangChain is vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists, potentially leading to persistent chat-history poisoning, prompt injection, credential disclosure, or server-side requests.
Netty HttpClientCodec Response Desynchronization Vulnerability
2 rulesThe Netty HttpClientCodec is vulnerable to response desynchronization when configured with HTTP/1.1 pipelining, HEAD requests, and the server sends 1xx responses, leading to a response body from one request being parsed as another and potentially unsafe socket reuse.
YAFNET Pre-Handler Authorization Bypass Leads to SQL Injection
2 rules 8 TTPsYAFNET's flawed authorization allows low-privileged users to execute arbitrary SQL commands via the `/Admin/RunSql` endpoint, potentially leading to data exfiltration, application modification, and denial-of-service.
itsourcecode Electronic Judging System SQL Injection Vulnerability (CVE-2026-7555)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-7555) exists in itsourcecode Electronic Judging System 1.0 via manipulation of the Username argument in the /intrams/login.php file, potentially leading to unauthorized data access and modification.
CVE-2026-32073 - Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
2 rules 1 TTP 1 CVECVE-2026-32073 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, enabling a locally authorized attacker to escalate privileges.
AWS ECR Container Scanning Reveals Low Severity Vulnerabilities
2 rules 1 TTP 1 CVEThis analytic identifies low, informational, or unknown severity findings from AWS Elastic Container Registry (ECR) image scans using AWS CloudTrail logs, indicating potential vulnerabilities or misconfigurations in container images that could lead to unauthorized access or data breaches.
SourceCodester Hotel Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in SourceCodester Hotel Management System 1.0 in the /index.php/reservation/check component due to improper sanitization of the room_type parameter, allowing a remote attacker to execute arbitrary SQL commands.
Zebra Consensus Split Vulnerability Due to SIGHASH_SINGLE Handling
2 rulesZebra and zcashd disagree on a consensus rule for V5+ transparent spends related to SIGHASH_SINGLE handling when the input index has no corresponding output, leading to a consensus split where Zebra accepts invalid blocks rejected by zcashd.
Cocos AI Attested TLS Relay Attack Vulnerability (CVE-2026-33697)
2 rules 1 TTPA relay attack vulnerability, tracked as CVE-2026-33697, exists in the attested TLS (aTLS) implementation of Cocos AI, versions v0.4.0 through v0.8.2, allowing attackers to impersonate a legitimate service and potentially access sensitive data.
Weaver E-cology Arbitrary File Read Vulnerability (CVE-2022-50992)
2 rules 1 TTP 1 CVEUnauthenticated remote attackers can exploit an arbitrary file read vulnerability (CVE-2022-50992) in Weaver E-cology 9.5 versions prior to 10.52 via the XML-RPC endpoint to access sensitive files.
TransformerOptimus SuperAGI Path Traversal Vulnerability
2 rules 1 TTP 1 CVEA path traversal vulnerability (CVE-2026-6615) exists in TransformerOptimus SuperAGI version 0.0.14, allowing remote attackers to read or write arbitrary files via manipulation of the 'Name' argument in the Multipart Upload Handler component.
Simple IT Discussion Forum 1.0 SQL Injection Vulnerability (CVE-2026-5672)
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 via manipulation of the cat_id parameter in the /edit-category.php file.
Server-Side Request Forgery in mcp-data-vis
2 rules 1 TTP 1 CVEA server-side request forgery (SSRF) vulnerability exists in AlejandroArciniegas' mcp-data-vis due to improper handling of HTTP requests, potentially allowing remote attackers to make arbitrary requests through the vulnerable server.
Scramble Remote Code Execution via User-Controlled Input
3 rules 1 TTPScramble versions 0.13.2 through 0.13.21 are vulnerable to remote code execution due to the evaluation of user-controlled input in validation rules during documentation generation, potentially allowing attackers to execute arbitrary PHP code.
rust-openssl X509Ref::ocsp_responders Undefined Behavior Vulnerability
2 rules 1 TTPThe `X509Ref::ocsp_responders` function in rust-openssl versions 0.9.7 to 0.10.78 returns OCSP responder URLs from a certificate's AIA extension without proper UTF-8 validation, leading to undefined behavior when processing certificates with non-UTF-8 OCSP URLs.
rust-openssl Stack Buffer Overflow Vulnerability
2 rulesThe rust-openssl crate is vulnerable to a stack-based buffer overflow (CVE-2026-41681) where the `EVP_DigestFinal()` function writes beyond the allocated buffer, potentially corrupting the stack, affecting versions >= 0.10.39 and < 0.10.78.
pygeoapi Unauthenticated SSRF Vulnerability in OGC API - Processes Subscriber
2 rules 1 TTPpygeoapi versions 0.23.0 to 0.23.2 contain an unauthenticated server-side request forgery (SSRF) vulnerability where OGC API process execution requests can use the subscriber object to make requests to internal HTTP services, which is resolved in version 0.23.3 by disabling internal requests by default.
pygeoapi Path Traversal Vulnerability in STAC FileSystemProvider
2 rules 1 TTPA path traversal vulnerability exists in pygeoapi versions 0.23.0 to 0.23.2 within the STAC FileSystemProvider plugin, allowing unauthenticated access to directories when deployed without a URL-normalizing proxy.
PrestaShop Stored XSS Vulnerability via Unprotected Template Variables
3 rules 1 TTPMultiple stored XSS vulnerabilities exist in PrestaShop, where an attacker with database access can exploit unprotected variables in back-office templates to execute malicious scripts in a user's browser.
Patreon OAuth Provider ID Collision Vulnerability in go-pkgz/auth
2 rules 1 TTPThe Patreon OAuth provider in go-pkgz/auth and go-pkgz/auth/v2 maps every authenticated Patreon account to the same local user ID, leading to cross-account access, privilege confusion, and subscription-state leakage.
PaperCut NG Remote Web Access Attempt Detection
2 rules 2 TTPsThis analytic detects potential exploitation attempts on publicly accessible PaperCut NG servers by identifying connections from public IP addresses to the server, specifically monitoring URI paths commonly used in proof-of-concept scripts for exploiting PaperCut NG vulnerabilities.
Paperclip AI OS Command Injection via Execution Workspace cleanupCommand
2 rules 1 TTPA critical OS command injection vulnerability exists in Paperclip AI v2026.403.0 within the execution workspace lifecycle. By injecting arbitrary shell commands into the `cleanupCommand` field via the `PATCH /api/execution-workspaces/:id` endpoint, an attacker can execute these commands on the server when the workspace is archived.
Ory Keto SQL Injection Vulnerability via GetRelationships API (CVE-2026-33505)
2 rules 1 TTPOry Keto versions prior to 26.2.0 are vulnerable to SQL injection via the GetRelationships API due to flaws in its pagination implementation, enabling attackers with knowledge of the pagination secret (or the default secret) to craft malicious tokens leading to arbitrary SQL query execution.
Oracle PeopleSoft Enterprise PeopleTools Unauthorized Data Access Vulnerability (CVE-2026-34309)
2 rules 1 TTP 1 CVECVE-2026-34309 is an easily exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools versions 8.61-8.62, allowing a low-privileged attacker with network access via HTTP to gain unauthorized access to create, delete, or modify sensitive data.
OpenClaw Matrix Profile Config Persistence Vulnerability
2 rules 1 TTPA vulnerability in the openclaw npm package before version 2026.4.10 allows unauthorized modification of Matrix profile configurations via the `operator.write` message tool.
Netty HTTP/3 QPACK Literal Unbounded Allocation Vulnerability
3 rules 1 TTPA vulnerability in Netty's HTTP/3 QPACK decoder allows an attacker to cause a denial of service by sending a crafted HTTP/3 header that triggers excessive memory allocation, leading to a server crash.
MiroFish Command Injection Vulnerability (CVE-2026-7058)
2 rules 1 TTP 1 CVEA command injection vulnerability exists in 666ghj MiroFish version 0.1.2 via the SimulationIPCClient.send_command function, allowing remote attackers to execute arbitrary commands.
Microsoft CVE-2017-3736 Vulnerability
2 rulesCVE-2017-3736 is a vulnerability tracked by Microsoft, potentially leading to exploitation of affected systems.
mcp-dnstwist OS Command Injection Vulnerability (CVE-2026-7443)
2 rules 1 TTP 1 CVEAn OS command injection vulnerability exists in BurtTheCoder's mcp-dnstwist version 1.0.4 and earlier due to improper handling of the Request argument in the fuzz_domain function within src/index.ts, potentially allowing remote attackers to execute arbitrary commands.
ManageEngine Log360 Authentication Bypass Vulnerability (CVE-2026-3324)
2 rules 1 TTP 1 CVEZohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration, potentially allowing unauthorized access.
lxml Library Vulnerable to XXE Attacks via iterparse() and ETCompatXMLParser()
2 rules 1 TTPlxml versions before 6.1.0 are vulnerable to XML External Entity (XXE) attacks when using iterparse() or ETCompatXMLParser() with default settings, potentially allowing local file reads.
Katalyst Koi Session Cookies Replayable After Logout
2 rules 1 TTPKatalyst Koi versions before 4.20.0 and between 5.0.0 and 5.6.0 fail to invalidate admin session cookies upon logout, allowing attackers with a valid cookie to maintain unauthorized access.
Gotenberg Denial of Service via Context Pool Reuse
2 rules 2 TTPsGotenberg versions 8.31.0 and earlier are vulnerable to an unauthenticated denial-of-service attack where a race condition in the webhook middleware causes a panic and process termination when handling concurrent requests.
GNUTLS RSA-PSK Authentication Bypass Vulnerability (CVE-2026-42010)
2 rules 1 TTP 1 CVEA vulnerability in GNUTLS (CVE-2026-42010) allows a remote attacker to bypass authentication on servers configured with RSA-PSK by sending a specially crafted username containing a NUL character, leading to unauthorized access.
Flight Framework SQL Injection Vulnerability
2 rules 2 TTPsFlight framework is vulnerable to SQL Injection; an attacker can inject arbitrary SQL by crafting malicious array keys due to SimplePdo::insert(), SimplePdo::update(), and SimplePdo::delete() building SQL statements by concatenating the $table argument and the keys of the $data array directly into the query, with no identifier quoting or validation, leading to privilege escalation, arbitrary column writes, data destruction, and exfiltration.
fast-jwt Authentication Bypass Vulnerability via Empty HMAC Secret
2 rules 2 TTPsA critical vulnerability in the fast-jwt library allows attackers to forge JWTs by exploiting the acceptance of empty HMAC secrets in the async key resolver, leading to authentication bypass.
Esri Portal for ArcGIS Privilege Escalation via CVE-2026-33518
2 rules 1 TTP 1 CVEEsri Portal for ArcGIS 11.5 on Windows and Linux is vulnerable to privilege escalation (CVE-2026-33518), allowing highly privileged users to create developer credentials with excessive permissions.
Dgraph Pre-Auth Full Database Exfiltration via DQL Injection
2 rules 6 TTPsA pre-authentication DQL injection vulnerability in Dgraph's default configuration allows attackers to exfiltrate the entire database by crafting malicious JSON mutations to the `/mutate` endpoint, exploiting unsanitized language tags in predicates.
Detection of Abnormally Large DNS Responses Indicative of CVE-2020-1350 Exploitation
2 rules 2 TTPsThis rule detects abnormally large DNS responses indicative of exploitation attempts targeting a known overflow vulnerability (CVE-2020-1350) in Windows DNS servers, potentially leading to Remote Code Execution (RCE) or Denial of Service (DoS).
Denial of Service Vulnerability in marked via Infinite Recursion
2 rules 1 TTPA denial of service vulnerability exists in marked version 18.0.0 due to infinite recursion when processing a specific 3-byte sequence (tab, vertical tab, and newline), leading to unbounded memory allocation and application crash.
CVE-2026-28390 NULL Dereference in CMS KeyTransportRecipientInfo Processing
2 rules 1 CVECVE-2026-28390 is a vulnerability related to a possible NULL pointer dereference when processing CMS KeyTransportRecipientInfo, potentially leading to a denial-of-service condition.
CKAN Unauthenticated SQL Injection in datastore_search_sql
2 rules 1 TTPAn unauthenticated SQL injection vulnerability in CKAN's `datastore_search_sql` function allows attackers to access private resources and PostgreSQL system information, affecting versions prior to 2.10.10 and versions 2.11.0 through 2.11.4.
ChatGPTNextWeb NextChat SSRF Vulnerability (CVE-2026-7178)
2 rules 1 TTP 1 CVEChatGPTNextWeb NextChat versions up to 2.16.1 are vulnerable to server-side request forgery (SSRF) due to improper input validation in the storeUrl function, allowing remote attackers to potentially access internal resources or conduct other malicious activities.
changedetection.io Arbitrary Local File Read via Crafted Backup Restore
2 rules 1 TTPchangedetection.io is vulnerable to arbitrary local file read due to insufficient validation of snapshot paths restored from backup files, allowing attackers to read sensitive files by crafting a malicious backup archive containing a manipulated `history.txt` file.
AWS ECR Container Scanning Reveals Medium Severity Vulnerabilities
2 rules 1 TTP 1 CVEAWS Elastic Container Registry (ECR) image scans reveal medium-severity vulnerabilities, potentially leading to unauthorized access and data breaches if exploited within containerized applications.
Arcane Unauthenticated Compose Template Content Disclosure
2 rules 1 TTPArcane versions before 1.18.0 are vulnerable to an unauthenticated information disclosure on four GET endpoints under `/api/templates*`, allowing unauthorized access to Compose YAML and `.env` content including sensitive secrets.
Aider-MCP Command Injection Vulnerability (CVE-2026-7316)
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-7316) exists in eiliyaabedini aider-mcp, allowing remote attackers to execute arbitrary commands by manipulating the working_dir/editable_files argument in the aider_mcp.py file.
free5GC NEF Denial-of-Service via Unreachable notifyUri
2 rules 1 TTP 1 IOCfree5GC's NEF component is vulnerable to a denial-of-service attack where an attacker can create a PFD subscription with an attacker-controlled `notifyUri`, and when a PFD change is triggered, NEF attempts to deliver a notification to the specified URI, and if the URI is unreachable, NEF terminates the entire process, causing a service outage, and this can be triggered without authentication in version 4.2.1, making it easily exploitable.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-6187 is a remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 via the ID parameter in /ajax.php?action=chk_prod_availability, allowing unauthenticated attackers to execute arbitrary SQL queries.
Rack::Session::Cookie Vulnerability Enables Secretless Session Forgery
2 rules 2 TTPs 1 CVERack::Session::Cookie incorrectly handles decryption failures, falling back to a default decoder and allowing attackers to forge session cookies without knowing the secret, potentially leading to authentication bypass or privilege escalation in vulnerable Rack applications.
Oracle Life Sciences Empirica Signal CVE-2026-21997 Vulnerability
2 rules 1 TTP 1 CVECVE-2026-21997 allows a low-privileged attacker with network access via HTTP to compromise Oracle Life Sciences Empirica Signal versions 9.2.1-9.2.3, leading to unauthorized data access and modification with potential impact on other products.
OpenClaw Synology Chat Reply Delivery Vulnerability
2 rulesA vulnerability exists in OpenClaw versions prior to 2026.3.22 where Synology Chat reply delivery can be rebound to a mutable username match instead of the stable numeric user_id, potentially leading to information disclosure or privilege escalation.
OpenClaw Inconsistent Host Exec Environment Override Sanitization
2 rules 1 TTPOpenClaw versions before 2026.3.22 have an inconsistent host execution environment override sanitization, allowing blocked or malformed override keys to bypass sanitization, which could lead to unauthorized access or code execution.
Note Mark JWT Secret Weakness Allows Account Takeover
2 rules 2 TTPsNote Mark is vulnerable to a JWT secret weakness that allows for full account takeover via token forgery by accepting secrets as short as 1 byte, enabling attackers to crack the signing secret offline and forge valid JWTs for any user.
nginx-ui Backup Restore Allows Tampering with Encrypted Backups
3 rules 2 TTPsThe nginx-ui backup restore mechanism allows attackers to tamper with encrypted backup archives and inject malicious configuration during restoration, potentially leading to arbitrary command execution.
n8n Unauthenticated Denial of Service via MCP Client Registration
2 rules 1 TTPn8n is vulnerable to an unauthenticated denial of service (DoS) attack due to missing resource controls in the MCP OAuth client registration endpoint, allowing an attacker to exhaust server memory by sending large registration payloads, leading to service unavailability; this is resolved in versions 1.123.32, 2.17.4, and 2.18.1 and tracked as CVE-2026-42236.
n8n External Secrets Authorization Bypass Vulnerability
2 rules 1 TTPAn authorization bypass vulnerability in n8n allows authenticated users without 'externalSecret:list' permission to retrieve plaintext values of external secrets when saving credentials, if the attacker knows or can guess the secret name.
LMDeploy Vision-Language Module SSRF Vulnerability
2 rules 1 TTP 1 CVE 4 IOCsA server-side request forgery (SSRF) vulnerability exists in LMDeploy's vision-language module, allowing attackers to access cloud metadata services and internal networks by exploiting the lack of URL validation in the `load_image()` function.
livewire-markdown-editor Arbitrary File Upload Vulnerability
2 rules 1 TTPThe livewire-markdown-editor versions before v1.3 contain an arbitrary file upload vulnerability in the MarkdownEditor::updatedAttachments() Livewire handler, allowing authenticated users to upload any file type, potentially leading to stored XSS, phishing, malware distribution, and markdown injection.
Graphiti JSONAPI Arbitrary Method Execution Vulnerability (CVE-2026-33286)
2 rules 1 TTPGraphiti versions prior to 1.10.2 are vulnerable to arbitrary method execution via maliciously crafted JSONAPI payloads, allowing attackers to invoke public methods on model instances, classes, or associations.
Gotenberg ExifTool Argument Injection via Metadata Values
2 rules 1 TTPGotenberg version 8.30.1 and earlier is vulnerable to argument injection, where an unauthenticated attacker can inject arbitrary ExifTool pseudo-tags via newline characters in metadata values, leading to arbitrary file manipulation within the container filesystem.
FuelCMS Vulnerability Report
2 rules 2 TTPs 1 IOCA vulnerability in FuelCMS has been reported, details available at pentesttools.com/blog/throwing-a-spark-in-fuelcms, potentially allowing attackers to compromise vulnerable systems.
free5GC SMF Unauthenticated State-Mutating Panic-DoS Vulnerability
2 rules 2 TTPs 2 IOCsfree5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted DELETE request to the /upi/v1/upNodesLinks/{ref} endpoint triggers a nil-pointer dereference, causing a panic and mutating the in-memory user-plane topology, impacting the selection of UPFs for legitimate UE sessions.
FHIR Validator SSRF via /loadIG Leads to Credential Theft
2 rules 2 TTPs 1 IOCThe FHIR Validator HTTP service is vulnerable to server-side request forgery (SSRF) via the `/loadIG` endpoint, enabling attackers to steal authentication tokens by exploiting a prefix-matching flaw in the credential provider.
epa4all-client Signature Verification Bypass Vulnerability
2 rulesepa4all-client is vulnerable to a signature verification bypass where the ECDSA signature verification discards the boolean return value, allowing any structurally valid signature to be considered trusted.
Ella Core NGAP Message Handling Vulnerability Leads to Denial of Service
3 rules 1 TTPElla Core versions prior to 1.6.0 are vulnerable to a denial-of-service attack where a crafted NGAP LocationReport message with a missing `UEPresenceInAreaOfInterestList` can crash the process, disrupting service for all connected subscribers.
DevSpace UI Server WebSocket Origin Validation Vulnerability
2 rules 2 TTPsDevSpace's UI server WebSocket accepts connections from any origin, enabling attackers to access pod logs, interactive shells, and execute commands via cross-origin WebSocket connections; versions up to 6.3.20 are affected, patched in 6.3.21.
Detect-It-Easy Path Traversal Vulnerability (CVE-2026-43616)
2 rules 1 TTP 1 CVEDetect-It-Easy versions prior to 3.21 are vulnerable to path traversal, allowing attackers to write arbitrary files to the filesystem and potentially achieve code execution by crafting malicious archive entries.
Decidim Amendment Manipulation Vulnerability (CVE-2026-40869)
2 rules 1 TTP 1 CVECVE-2026-40869 allows authenticated users to manipulate amendments in Decidim versions 0.19.0 prior to 0.30.5 and 0.31.1, potentially hijacking authorship and impacting proposal integrity.
CVE-2017-3735 Vulnerability Targeting Microsoft Products
2 rules 1 TTP 1 CVECVE-2017-3735 is a vulnerability impacting Microsoft products, potentially allowing unauthorized access or code execution.
Craft CMS Authenticated Remote Code Execution via Malicious Attached Behavior
2 rules 2 TTPsCraft CMS versions before 4.17.12 and 5.9.18 are vulnerable to authenticated remote code execution via malicious behavior injection in the field layout hydration path.
CI4MS Theme Upload Zip Slip Vulnerability
2 rules 2 TTPsA critical vulnerability exists in ci4ms Theme::upload, where improper validation of ZIP archive entry names allows authenticated users with theme creation permissions to write files to arbitrary locations, leading to remote code execution.
choieastsea simple-openstack-mcp OS Command Injection Vulnerability (CVE-2026-7066)
3 rules 1 TTP 1 CVEThe choieastsea simple-openstack-mcp application is vulnerable to OS command injection via the exec_openstack function in server.py, allowing remote attackers to execute arbitrary commands.
Apko DirFS Symlink Path Traversal Vulnerability
2 rules 1 TTPA symlink-following path traversal vulnerability exists in apko versions prior to 1.2.5 allowing a malicious .apk file to create a symbolic link pointing outside the build root and subsequently modify files on the host system.
WordPress Redsys Payment Gateway Plugin Vulnerable to Payment Forgery (CVE-2026-5050)
2 rules 1 TTP 1 CVE 1 IOCThe Payment Gateway for Redsys & WooCommerce Lite plugin for WordPress is vulnerable to cryptographic signature forgery, allowing unauthenticated attackers to mark pending orders as paid by forging payment callback data in versions up to 7.0.0.
OpenClaw Feishu Webhook Vulnerability: Unauthenticated Command Execution
2 rules 1 TTPOpenClaw versions before 2026.4.15 are vulnerable to unauthenticated webhook or card-action traffic due to missing encryption key configuration and improper handling of card-action callbacks, potentially allowing network-triggered access to OpenClaw command handling without Feishu signature or replay protection.
Gramps Web API Zip Slip Vulnerability in Media Archive Import
2 rules 1 TTPA path traversal vulnerability (Zip Slip) exists in the gramps-webapi media archive import feature, allowing authenticated users with owner privileges to write arbitrary files outside the intended temporary extraction directory via malicious ZIP files, potentially leading to data corruption or replacement.