Tag
Arbitrary Shortcode Execution in WP Recipe Maker Plugin
1 TTP 1 CVEThe WP Recipe Maker plugin for WordPress (<= 10.8.1) is vulnerable to arbitrary shortcode execution due to recursive do_shortcode calls on user-supplied metadata fields.
Perses Filesystem Path Traversal Vulnerability
1 rule 2 TTPs 1 CVEThe Perses project, when configured with a filesystem database, fails to validate the project parameter in list requests, enabling unauthorized directory traversal and arbitrary file read access.
Eval Injection in XWiki Rendering XML
2 TTPs 1 CVEAn evaluation injection vulnerability in xwiki-rendering-xml allows authenticated users to achieve remote code execution by injecting script macros into HTML macro output.
Arbitrary User Meta Write Vulnerability in Mapster WP Maps Plugin
1 TTP 1 CVEThe Mapster WP Maps WordPress plugin contains an arbitrary user meta write vulnerability via the my_profile_update() function, allowing authenticated users with Subscriber-level access to overwrite arbitrary user metadata.
CSRF and Stored XSS Vulnerability in django-page-cms
1 TTP 1 CVEAn improper CSRF protection flaw in django-page-cms versions up to 2.0.13 enables attackers to force authenticated editors to inject stored XSS payloads.
Stored XSS in Vendure Admin Dashboard via Unsafe HTML Stripping
2 TTPs 1 CVEA stored Cross-Site Scripting (XSS) vulnerability in the Vendure Admin Dashboard allows authenticated administrators to execute arbitrary JavaScript in the context of other users viewing entity lists, leading to potential account takeover.
Unauthenticated Insecure Deserialization in b2evolution CMS
1 rule 2 TTPs 2 CVEsb2evolution CMS versions 6.7.8 through 7.2.5 are vulnerable to insecure deserialization via improper validation of serialized objects containing negative integer array keys.
Remote Code Execution in SiYuan via Malicious Bookmark Labels
1 rule 5 TTPs 1 CVESiYuan versions prior to 3.8.4 contain a cross-site scripting vulnerability in bookmark label rendering that enables remote code execution due to insecure Electron configuration.
Path Traversal in admin3 Upload Handler
1 rule 3 TTPs 1 CVEThe admin3 application through version 3.0.0 is vulnerable to path traversal, allowing authenticated attackers on Windows to overwrite arbitrary files via malicious filenames in the upload handler.
Arbitrary File Upload Vulnerability in Paid Downloads WordPress Plugin
1 rule 1 TTP 1 CVEAn unauthenticated arbitrary file upload vulnerability in the Paid Downloads plugin (<= 3.15) allows remote attackers to execute code by bypassing file type validation via the admin_request_handler function.
Cross-Site Scripting Vulnerability in @nuxtjs/mdc
1 TTP 1 CVEThe @nuxtjs/mdc package contains an XSS vulnerability (CVE-2026-63671) due to improper sanitization of SVG xlink:href attributes and iframe data:text/html sources during markdown parsing.
Remote Code Execution in Craft CMS via HMAC Signature Misuse
3 TTPs 1 CVECraft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a critical vulnerability allowing authenticated users to achieve remote code execution by injecting malicious payloads into improperly validated redirect parameters.
Path Traversal in ComfyUI Dataset Save Nodes
2 TTPs 1 CVEComfyUI versions prior to 0.30.0 are vulnerable to path traversal via unsanitized input in dataset save nodes, allowing attackers to write arbitrary files and potentially achieve code execution.
SSRF Vulnerability in changedetection.io
2 TTPs 1 CVEchangedetection.io versions 0.60.6 and earlier contain a Server-Side Request Forgery (SSRF) vulnerability allowing unauthenticated attackers to access internal network resources.
CSRF Vulnerability in phpList Mass Subscriber Removal
1 TTP 1 CVEphpList versions prior to 3.6.17 are vulnerable to CSRF, allowing an attacker to force an authenticated administrator to delete or blacklist subscribers without authorization.
Insufficient Validation in Coze Studio Workflow SQL Nodes
1 TTP 1 CVECoze Studio versions up to 0.5.1 contain an input validation vulnerability in workflow SQL customization nodes allowing authenticated attackers to bypass workspace isolation and execute unauthorized SQL queries.
Authorization Bypass in Pelican Panel via Livewire State Manipulation
2 TTPs 1 CVEPelican Panel versions before 1.0.0-beta35 fail to enforce server-side write permissions, allowing attackers with read-only access to achieve arbitrary command execution via manipulated Livewire state updates.
IDOR Vulnerability in SIMAC MyPHR
2 TTPs 1 CVESIMAC MyPHR version 1.1 contains an IDOR vulnerability allowing authenticated attackers to modify arbitrary employee records and hijack user accounts.
Arbitrary File Upload and RCE in Pluck CMS via CVE-2023-50564
1 rule 2 TTPs 1 CVEAn authenticated arbitrary file upload vulnerability in Pluck CMS v4.7.18 allows remote attackers to achieve code execution by uploading a malicious ZIP archive via the module installation interface.
SQL Injection in SourceCodester Inventory and Monitoring System
1 rule 1 TTP 1 CVESourceCodester Inventory and Monitoring System 1.0 is vulnerable to remote SQL injection via the Username argument in index.php, allowing unauthenticated attackers to execute arbitrary database commands.
SQL Injection in code-projects Matrimonial System
1 rule 1 TTP 1 CVEMatrimonial System 1.0 contains a remote SQL injection vulnerability in the search.php script, allowing unauthenticated attackers to manipulate search arguments to execute arbitrary database commands.
Command Injection in /index.php/ajax/parameterManage Endpoint
1 rule 1 TTP 1 CVEA low-privileged remote attacker can exploit a command injection vulnerability at the /index.php/ajax/parameterManage endpoint using valid credentials to gain root-level code execution.
Unauthenticated PHP Object Injection in Cotonti Comments Plugin
1 rule 1 TTP 1 CVECotonti 1.0.0 is vulnerable to unauthenticated remote code execution via a PHP object injection flaw in the Comments plugin's 'ci' GET parameter.
SQL Injection Vulnerability in WuzhiCMS
2 rules 1 TTP 1 CVEWuzhiCMS versions up to 4.1.0 contain a SQL injection vulnerability in the article::getDataOfJson function, allowing remote attackers to execute arbitrary SQL commands via the title or master_table parameters.
Reflected Cross-Site Scripting Vulnerability in Siemens Teamcenter
1 rule 1 TTP 1 CVEAn unauthenticated remote attacker can exploit a reflected XSS vulnerability in the Teamcenter authentication redirect flow to execute arbitrary JavaScript in the context of an authenticated user session.
Cross-Site Scripting Vulnerability in Governikus AusweisApp2
1 TTPA vulnerability in the Governikus AusweisApp2 software allows a remote, unauthenticated attacker to execute a Cross-Site Scripting (XSS) attack.
Authenticated IDOR Vulnerability in FlowForms
1 rule 1 TTP 1 CVEAn authenticated Insecure Direct Object Reference (IDOR) vulnerability in FlowForms version 1.1.1 and earlier allows attackers with contributor-level access to modify arbitrary forms.
SQL Injection in FilePress Publish Module
1 TTP 1 CVEAn unpatched SQL injection vulnerability in zyx0814 FilePress versions 3.0.1 and earlier allows remote attackers to manipulate the orderby or order arguments within search.php.
SQL Injection in SourceCodester Online Faculty Clearance System
1 rule 1 TTP 1 CVESourceCodester Online Faculty Clearance System 1.0 is vulnerable to remote SQL injection in /delete_requirement.php via the ID argument, allowing unauthorized database access.
SQL Injection Vulnerability in Online Food Ordering System
1 rule 1 TTP 1 CVEOnline Food Ordering System 1.0 contains a SQL injection vulnerability in /web/category-foods.php that allows remote, unauthenticated attackers to execute arbitrary database queries via the ID argument.
Path Traversal Vulnerability in Flextype CMS Entries REST API
1 rule 1 TTP 1 CVEFlextype CMS versions through 1.0.0-alpha.3 are vulnerable to path traversal via the Entries REST API, allowing authenticated attackers to read, create, or overwrite arbitrary files on the filesystem.
SQL Injection in PHPGurukul Daily Expense Tracker System
2 rules 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability in the login component of PHPGurukul Daily Expense Tracker System 1.1 allows remote attackers to execute arbitrary database queries.
Path Traversal Vulnerability in ZFile Download Endpoint
1 rule 1 CVEZFile versions through 5.0.5 are vulnerable to a path traversal attack allowing unauthenticated attackers to download arbitrary files via manipulated share link query parameters.
XML External Entity Injection in IBM Business Automation Workflow
1 TTP 1 CVEIBM Business Automation Workflow contains a vulnerability in default programming artifacts that allows for XML External Entity (XXE) injection attacks, potentially enabling unauthorized file access or server-side request forgery.
Stored XSS in parallax filament-comments
1 TTPCVE-2026-90943 is a stored cross-site scripting vulnerability in filament-comments <= 3.0.0, allowing authenticated users to inject malicious scripts into comment bodies for execution in the browsers of other users.
SQL Injection in itsourcecode Leave Management System
1 rule 1 TTP 1 CVEThe itsourcecode Leave Management System version 1.0 is vulnerable to remote SQL injection via the user_email parameter in login.php, enabling potential authentication bypass or unauthorized database access.
Improper Privilege Management in Soarkey StudentManagement
1 TTP 1 CVEThe RegisterServlet component in Soarkey StudentManagement is vulnerable to improper privilege management, allowing remote attackers to manipulate user account levels during registration via the 'level' argument.
SSRF Vulnerability in tarzan-cms Theme Download Function
1 TTP 1 CVEAn unauthenticated remote SSRF vulnerability exists in the Theme Download Function of tarzan-cms 1.0.0 due to insecure handling of the httpUrl parameter.
Authorization Bypass in Shopper Framework CollectionProducts Component
2 TTPsAn authorization bypass vulnerability in the Shopper framework allows authenticated users with limited privileges to perform unauthorized product deletions across any collection in the database.
MoguBlog XML External Entity Injection in WeChat Callback
1 rule 2 TTPs 1 CVEMoguBlog versions through 6.2 are vulnerable to unauthenticated XML External Entity (XXE) injection via the WeChat callback handler, allowing arbitrary file read and outbound SSRF.
Authorization Bypass in Dolibarr Document Storage
1 rule 1 TTP 1 CVEAn unauthenticated authorization bypass vulnerability in Dolibarr allows remote attackers to access arbitrary sensitive files via the document storage endpoints.
Universal XSS in UC Browser for Android via ucapi Bridge
1 TTP 1 CVEA Universal Cross-Site Scripting (UXSS) vulnerability, CVE-2026-78997, allows attackers to bypass the Same-Origin Policy in UC Browser for Android by exploiting a flaw in the ucapi login callback mechanism.
XXE Vulnerability in IBM webMethods Integration Server
1 TTP 1 CVEIBM webMethods Integration Server 11.1 is vulnerable to an XML External Entity (XXE) injection flaw that allows unauthenticated attackers to exfiltrate sensitive files or trigger denial of service via memory exhaustion.
OS Command Injection in FileRun
2 TTPs 1 CVEFileRun versions prior to 2026.3.0 contain an OS command injection vulnerability via an improper redefinition of escapeshellcmd() that allows unauthenticated or authenticated users to execute arbitrary commands.
Open WebUI Same-Origin XSS via Terminal Port Preview
3 rules 5 TTPs 1 CVEAn insecure sandbox configuration in the Open WebUI terminal port preview feature allows authenticated users to execute arbitrary JavaScript in the application's origin, leading to session token theft and account takeover.
Domain-Restriction Bypass in n8n OpenAI Chat Model Node
3 TTPs 2 CVEsAn unauthenticated credential access vulnerability in n8n allows users to bypass domain restrictions in the OpenAI Chat Model node via the model-search endpoint, leading to unauthorized credential exposure.
Stored Cross-Site Scripting in Sidebar Manager Light Plugin
1 TTP 1 CVEThe Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to insufficient input sanitization of the sbm_description parameter, allowing unauthenticated attackers to execute arbitrary scripts in victim browsers.
Unauthenticated Category Addition in Rizwan17 inventory-management-system
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in the AJAX backend of Rizwan17 inventory-management-system allows remote attackers to execute unauthorized category additions via the userid parameter.
CVE-2026-0308 Stored XSS in PAN-OS Web Interface
4 TTPsA stored cross-site scripting (XSS) vulnerability in the PAN-OS web interface allows an authenticated administrator to execute arbitrary JavaScript within the context of the management interface.
Path Traversal and Arbitrary Deletion in Chainlit
1 rule 1 TTP 1 CVEChainlit versions 2.12.0 and earlier are vulnerable to an unauthenticated path traversal attack via the socket.io sessionId parameter, enabling arbitrary directory deletion.
Stored XSS in Repeater Fields for Gravity Forms Plugin
1 CVEThe Repeater Fields for Gravity Forms plugin for WordPress is vulnerable to Stored XSS due to improper sanitization of multi-input sub-fields, allowing unauthenticated attackers to execute arbitrary JavaScript.
Arbitrary Command Execution in Snipe-IT Backup Restoration
1 rule 14 TTPs 1 CVESnipe-IT versions prior to 8.7.0 are vulnerable to OS command injection when a superadministrator restores a crafted backup archive, allowing arbitrary command execution via the MySQL client.
Authorization Bypass in iWebShop via Update Controller
1 CVEA missing authorization vulnerability in the iWebShop Update::index function allows unauthenticated remote attackers to access restricted administrative functions in versions up to 5.15.
Authentication Bypass in knowns Management API
2 rules 2 TTPs 1 CVEThe knowns application before version 0.30.0 exposes an unauthenticated management API on all network interfaces, allowing attackers to provision unauthorized tunnels via the /api/tunnel/start endpoint.
Arbitrary File Upload and RCE in Lara Dashboard
3 rules 2 TTPs 1 CVELara Dashboard versions prior to 1.3.2 are vulnerable to arbitrary file upload via the core-upgrades endpoint, allowing unauthorized administrators to achieve remote code execution.
Authentication Bypass in SourceCodester Simple Traffic Offense System
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in SourceCodester Simple Traffic Offense System 1.0 allows remote, unauthenticated attackers to manipulate user creation via the saveuser.php script.
SQL Injection in Inventory Management System
1 rule 1 TTP 1 CVEA SQL injection vulnerability in the login component of inventory-management-system 1.0.0 allows remote attackers to execute arbitrary database queries via the username and password parameters.
SQL Injection in SourceCodester Online Voting System
3 rules 1 TTP 1 CVESourceCodester Online Voting System 1.0 is vulnerable to remote SQL injection via the 'id' parameter in the '/ajax.php?action=save_user' endpoint, enabling unauthenticated attackers to manipulate database queries.
Stored XSS in Contact Form by Supsystic
1 rule 2 TTPs 1 CVEThe Contact Form by Supsystic WordPress plugin is vulnerable to unauthenticated Stored Cross-Site Scripting due to insufficient sanitization of X-Forwarded-For headers.
Privilege Escalation in Abandoned Cart Pro for WooCommerce
1 rule 1 TTP 1 CVEThe Abandoned Cart Pro for WooCommerce plugin is vulnerable to privilege escalation allowing authenticated subscribers to hijack administrative accounts by intercepting SMTP settings and email recovery tokens.
Stored XSS in CleanTalk WordPress Plugin
1 TTP 1 CVEThe Spam protection, Honeypot, Anti-Spam by CleanTalk plugin for WordPress is vulnerable to stored cross-site scripting via insufficient input sanitization in the comment content aria-label placeholder, allowing attackers to execute arbitrary scripts in the browsers of site visitors.
Stored Cross-Site Scripting in iubenda WordPress Plugin
2 TTPs 1 CVEThe iubenda All-in-one Compliance for GDPR / CCPA Cookie Consent plugin for WordPress contains a stored XSS vulnerability in versions 3.13.4 and earlier, allowing unauthenticated attackers to inject malicious scripts when the Secondary parser engine is enabled.
Librarian PDF Save Endpoint SSRF Vulnerability (CVE-2024-54819)
1 rule 2 TTPs 1 CVEAn authenticated Server-Side Request Forgery (SSRF) vulnerability in the Librarian PDF save endpoint allows attackers to perform unauthorized requests against internal network resources.
SSRF Vulnerability in Jina AI Reader via Incomplete Redirect Validation
2 TTPs 1 CVEJina AI reader is vulnerable to Server-Side Request Forgery (SSRF) due to improper URL validation during HTTP redirects, allowing access to internal network or cloud metadata services.
Server-Side Request Forgery in ms-swift
1 rule 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability in ms-swift version 4.5.2 allows attackers to perform unauthorized requests to internal network services and cloud metadata endpoints.
Account Footprinting Vulnerability in GastroMenum Web Panel
1 TTP 1 CVEGastroMenum Web Panel versions prior to 31.08.2026 contain an observable response discrepancy vulnerability enabling unauthorized account footprinting and user reconnaissance.
SQL Injection in Vehicle Management System
1 rule 1 TTP 1 CVEVehicle Management System version 1.0 contains an SQL injection vulnerability in the busid parameter of /busprofile.php, allowing unauthenticated remote attackers to execute arbitrary SQL queries.
Unauthenticated SSRF in Openpanel Site Checker
1 rule 8 TTPs 1 CVEOpenpanel versions before 2.3.0 are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw in the /tools/site-checker endpoint that allows internal network probing and cloud metadata access.
Stored Cross-Site Scripting in Grav Shortcode Core
2 TTPs 1 CVEGrav Shortcode Core versions prior to 6.2.5 are vulnerable to stored cross-site scripting (XSS) due to improper input sanitization in the [lorem] and [details] tags.
SQL Injection Vulnerability in DreamMaker
1 TTP 1 CVEAuthenticated remote attackers can exploit a SQL injection vulnerability in Interinfo's DreamMaker software to execute arbitrary database queries, leading to unauthorized data exfiltration or destruction.
Semaphore UI Cross-Site Request Forgery Vulnerability
2 TTPs 1 CVESemaphore UI is vulnerable to a CSRF attack via the password change endpoint, enabling unauthenticated attackers to hijack user accounts, including administrator accounts, by inducing an authenticated user to visit a malicious webpage.
Information Disclosure in SiYuan Kernel Enabling Offline Password Cracking
4 rules 8 TTPs 1 CVEAn information disclosure vulnerability in SiYuan's API allows unauthorized remote readers to retrieve cryptographic material necessary for offline, unthrottled GPU-based cracking of encrypted notebook master passwords.
SQL Injection in Doctor Appointment System 1.0
2 rules 1 TTP 1 CVEAn SQL injection vulnerability in the email parameter of the patient_login.php file allows unauthenticated remote attackers to execute arbitrary SQL commands in Doctor Appointment System 1.0.
CVE-2026-85388 SQL Injection in Worklenz
1 TTP 2 CVEsAuthenticated attackers can exploit improper validation of the sort-field parameter in Worklenz <= 3.0.0 to perform blind SQL injection against PostgreSQL backends.
Authentication Bypass in vhr PUT /hr/pass Endpoint
1 TTP 1 CVEAn authentication flaw in the vhr application through commit 03abbd3 allows authenticated attackers to perform unauthorized password changes for arbitrary accounts by manipulating the account ID in PUT requests.
Stored XSS in DPCalendar Free via Event Location Manipulation
1 rule 1 TTP 1 CVEDPCalendar Free versions 10.11.2 and earlier contain a stored XSS vulnerability in the location title field, allowing an Author-role user to bypass content moderation and execute arbitrary JavaScript in the browsers of site visitors.
SSRF and Response Disclosure in @platejs/docx-io
1 CVEThe @platejs/docx-io library is vulnerable to Server-Side Request Forgery (SSRF) and response disclosure, allowing attackers to probe internal networks via malicious HTML image embeddings.
Authorization Bypass in Craft CMS assets/move-asset Endpoint
2 rules 4 TTPs 1 CVECraft CMS versions prior to 5.10.11 contain an authorization bypass in the assets/move-asset endpoint, allowing authenticated users with insufficient permissions to move and delete arbitrary assets by supplying the force=1 parameter.
Unauthenticated SQL Injection in Micahblu Rsvp Me WordPress Plugin (CVE-2024-50491)
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability in the Micahblu Rsvp Me plugin for WordPress (<= 1.9.9) allows remote attackers to extract sensitive database information via the 'id' parameter.
Stored XSS via Attribute Filter Bypass in league/commonmark
3 TTPs 1 CVEAn XSS vulnerability in league/commonmark allows attackers to execute arbitrary JavaScript by prepending a U+000C form feed character to malicious attribute names, bypassing security filters in the AttributesExtension.
PHP Object Injection in Cypht
2 TTPs 1 CVECypht versions before 2.12.2 contain a PHP object injection vulnerability in the logout handler, allowing authenticated attackers to achieve remote code execution via serialized payloads.
SSRF Vulnerability in Wyoming API
1 rule 1 TTP 1 CVEWyoming versions prior to 1.10.2 contain a server-side request forgery (SSRF) vulnerability that allows unauthenticated remote attackers to redirect outbound API connections to arbitrary network targets.
SQL Injection Vulnerability in TRtek Products's Store
1 TTP 1 CVECVE-2026-18210 is a critical SQL injection vulnerability in the TRtek Products's Store application, allowing unauthenticated attackers to manipulate backend database queries.
Stored Cross-Site Scripting in Welcart e-Commerce Plugin
1 rule 1 TTP 1 CVEAn unauthenticated stored XSS vulnerability in the Welcart e-Commerce WordPress plugin (CVE-2026-19914) allows attackers to inject malicious scripts that execute in the context of administrative sessions.
Stored XSS Vulnerability in Listdom WordPress Plugin
2 TTPs 1 CVEAn unauthenticated stored XSS vulnerability in the Listdom WordPress plugin allows attackers to inject arbitrary scripts when specific premium add-ons are enabled.
Stored Cross-Site Scripting Vulnerability in Affiliate Super Assistent WordPress Plugin
2 TTPs 1 CVEThe Affiliate Super Assistent plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability via the doCommentShortcode function, allowing unauthenticated attackers to execute arbitrary scripts in the context of a victim's session.
CSRF Vulnerability in PHPJabbers Cinema Booking System
1 TTP 1 CVECVE-2024-57429 is a Cross-Site Request Forgery (CSRF) vulnerability in the pjActionUpdate function of PHPJabbers Cinema Booking System v2.0, allowing attackers to perform administrative account takeover via malicious web requests.
Unrestricted File Upload Vulnerability in ShopEx ECShop
2 rules 2 TTPs 1 CVEShopEx ECShop versions up to 2.5.1 contain an unrestricted file upload vulnerability in the check_img_type function that allows unauthenticated remote attackers to upload malicious files via the pack_img argument.
Critical SQL Injection in Customer Support System 1.0
1 rule 1 TTP 1 CVECVE-2023-49970 is a critical SQL injection vulnerability in the Customer Support System version 1.0 allowing unauthenticated attackers to execute arbitrary database commands via the 'subject' parameter.
Improper Access Control in MegaEase EaseProbe
1 rule 1 TTP 1 CVEMegaEase EaseProbe versions up to 2.3.0 are vulnerable to remote access control bypass via manipulation of HTTP headers including X-Forwarded-For, X-Real-IP, and True-Client-IP.
SQL Injection Vulnerability in Ankara Hosting Site Management Panel (CVE-2026-5956)
1 TTP 1 CVEAn improper neutralization of special elements in the Ankara Hosting Site Management Panel allows unauthenticated remote attackers to perform SQL injection attacks, potentially leading to unauthorized data exfiltration or system compromise.
SSRF Vulnerability in PowerJob Transport Endpoint
1 TTP 1 CVEPowerJob versions up to 5.1.2 contain a server-side request forgery vulnerability in the MuConnectionManager component that allows remote, unauthenticated attackers to perform unauthorized network requests.
SQL Injection in Online Medicine Delivery System
3 rules 1 TTP 1 CVEOnline Medicine Delivery System 1.0 contains a SQL injection vulnerability in the login interface, allowing remote unauthenticated attackers to bypass authentication or access database contents.
Remote Code Injection in SeaCMS Template Engine
2 rules 2 TTPs 1 CVESeaCMS versions 13.6 and earlier contain a code injection vulnerability in the search.php file, allowing remote attackers to execute arbitrary code via the searchtype parameter.
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
7 rules 15 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
Directory Traversal Vulnerability in Cloud Commander
1 CVECloud Commander versions prior to 19.20.2 are vulnerable to a directory traversal flaw in REST file-operation and markdown endpoints, allowing unauthenticated attackers to read or write arbitrary files.
Omnivore API Authentication Bypass via JWT Algorithm Confusion
1 TTP 1 CVEThe Omnivore API improperly validates Apple sign-in tokens, allowing attackers to perform algorithm confusion attacks to bypass authentication and impersonate users.
Stored XSS Vulnerability in Phpgurukul Teachers Record Management System
1 rule 2 TTPs 1 CVEA stored cross-site scripting (XSS) vulnerability in Phpgurukul Teachers Record Management System version 1.0 allows authenticated administrators to execute arbitrary JavaScript in the context of other users.
CVE-2026-82287: CORS Misconfiguration in Rybbit
1 TTP 1 CVEA CORS misconfiguration in Rybbit versions prior to 2.7.0 allows unauthorized cross-origin requests to read sensitive data and perform authenticated actions.
Remote Code Execution in BISHENG Workflow API
2 rules 3 TTPs 1 CVEAuthenticated users can achieve remote code execution in BISHENG versions prior to 2.6.0 by submitting crafted Python payloads to the /api/v1/workflow/run_once endpoint.
Unauthenticated Directory Traversal in Yamcs
2 rules 3 TTPs 1 CVEYamcs versions prior to 5.11.13 contain an unauthenticated directory traversal vulnerability in the HTTP request handling components that allows remote attackers to read arbitrary files from the underlying host.
9router Authentication Bypass and SSRF via Host Header Spoofing
2 rules 2 TTPs 1 CVEAn authentication bypass in 9router 0.4.80 and earlier allows remote attackers to spoof the 'Host' header, gaining unauthorized access to API proxy endpoints, enabling quota theft via AI relay and server-side request forgery (SSRF).
SSRF Vulnerability in SiYuan via DNS Rebinding
2 rules 6 TTPs 1 CVESiYuan versions prior to 3.8.1 are vulnerable to server-side request forgery through a DNS rebinding attack, enabling unauthorized access to cloud metadata services and internal network resources.
Stored XSS Vulnerability in Forminator Forms WordPress Plugin
1 TTP 1 CVEThe Forminator Forms WordPress plugin (up to v1.57.0.1) is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) via the Rich-Text Textarea field, allowing malicious script execution in the context of victim browsers.
Cross-Site Scripting Vulnerability in Element maps-ng
1 CVEA stored cross-site scripting (XSS) vulnerability in the si-map component of Element maps-ng allows unauthenticated attackers to execute arbitrary scripts in a victim's browser via crafted map pin tooltips.
Unauthenticated SQL Injection in WooCommerce Lottery Plugin
1 rule 1 TTP 1 CVEThe WooCommerce Lottery plugin for WordPress is vulnerable to unauthenticated time-based SQL injection via the 'orderby' and 'order' GET parameters, allowing attackers to extract sensitive database information.
Unauthenticated Configuration Manipulation in NebulaGraph
1 rule 1 TTP 1 CVENebulaGraph versions 3.8.0 and earlier contain an authentication bypass in the internal HTTP web service that allows unauthenticated remote attackers to read sensitive configuration and modify daemon behavior at runtime.
Unauthenticated Remote Command Execution in Next.js on Windows
1 rule 2 TTPs 1 CVEA critical path traversal vulnerability (CVE-2026-75604) in the Next.js FileSystemCache on Windows allows unauthenticated attackers to steal Server Action encryption keys and execute arbitrary commands.
Reflected Cross-Site Scripting Vulnerability in 2ClickPortal
1 rule 1 TTP 1 CVECVE-2024-5961 is a reflected cross-site scripting (XSS) vulnerability in 2ClickPortal versions 7.2.31 through 7.6.4, enabling arbitrary script execution via the search function parameter.
SQL Injection Vulnerability in SililaWijesinghe Food Ordering System
1 TTP 1 CVEA SQL injection vulnerability in the search_box argument of search.php allows remote attackers to perform unauthorized database operations on the SililaWijesinghe Food Ordering System.
Local File Inclusion Vulnerability in Shuffle WordPress Theme
1 rule 1 TTP 1 CVEThe Shuffle WordPress theme (<= 1.8) contains a Local File Inclusion vulnerability (CVE-2026-78566) that allows unauthenticated remote attackers to execute arbitrary PHP code on the host server.
Remote Code Execution in Adminer via PDO DSN Injection
3 rules 2 TTPs 4 CVEsAdminer versions prior to 5.4.3 are vulnerable to unauthenticated remote code execution via DSN injection, allowing attackers to write arbitrary PHP files to the web root.
Dolibarr Members REST API Improper Authorization Vulnerability
2 rules 2 TTPs 1 CVEAn improper authorization vulnerability (CVE-2026-71504) in Dolibarr prior to version 24.0.0 allows authenticated users to overwrite the credentials of any account via the Members REST API.
SSRF and Credential Leakage in AWX Notification Backends
3 TTPs 1 CVECVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.
Unrestricted File Upload Vulnerability in itsourcecode Online Pharmacy System
1 rule 2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-78245) exists in itsourcecode Online Pharmacy System 1.0 due to improper file validation within the user registration process.
SQL Injection in Real Estate Management System
1 rule 2 TTPs 1 CVEThe itsourcecode Real Estate Management System 1.0 contains an SQL injection vulnerability in search.php that allows unauthenticated remote attackers to execute arbitrary database queries.
Stored Cross-Site Scripting Vulnerability in Heptabase
2 TTPs 1 CVEHeptabase contains a stored cross-site scripting (XSS) vulnerability allowing authenticated remote attackers to execute arbitrary JavaScript in the context of other users.
Authentication Bypass in AVideo via Parameter Manipulation
7 rules 13 TTPs 1 CVEAn authentication bypass vulnerability in AVideo (CVE-2026-59808) allows attackers with upload access to hijack administrative sessions via improper video ownership verification.
Stored XSS in J2Commerce via Guest Checkout Filter Bypass
1 rule 2 TTPs 1 CVEJ2Commerce versions 4.1.5 and earlier are vulnerable to stored XSS via guest checkout, allowing unauthenticated attackers to execute malicious JavaScript in the administrator's browser upon order review.
Stored XSS in YOURLS via Referer Header
2 TTPs 1 CVEThe YOURLS URL shortener is vulnerable to stored cross-site scripting (XSS) via the Referer header, allowing unauthenticated attackers to execute arbitrary JavaScript in an administrator's browser context.
Remote Code Execution in Paperclip via DNS Rebinding
2 TTPs 1 CVEPaperclip versions prior to 0.3.1 are vulnerable to remote code execution due to improper Host header validation when running in 'local_trusted' mode, allowing attackers to leverage DNS rebinding to execute arbitrary commands.
Path Traversal Vulnerability in Dockge (CVE-2026-73040)
1 CVEDockge fails to validate stack names in read and delete operations, allowing authenticated or unauthenticated attackers to perform arbitrary file reads or recursive directory deletion via path traversal.
Unauthenticated Remote Code Execution in Elementor Pro
1 rule 2 TTPsElementor Pro versions 4.2.1 and below contain a critical file upload vulnerability (CVE-2026-32475) that allows unauthenticated attackers to achieve remote code execution by bypassing extension validation.
Information Exposure in phpMyFAQ Password Reset Mechanism
2 rules 4 TTPs 1 CVEVersions of phpMyFAQ prior to 4.1.7 store password reset tokens in a publicly accessible file when user tracking is enabled, allowing unauthenticated attackers to hijack accounts.
Cross-Site Scripting Vulnerability in IBM App Connect Enterprise
1 TTP 1 CVEIBM App Connect Enterprise contains a vulnerability, identified as CVE-2024-44280, that allows a remote, anonymous attacker to execute Cross-Site Scripting (XSS) attacks within the context of the affected application.
SQL Injection in Simple Online Food Ordering System
2 rules 1 TTP 1 CVESourceCodester Simple Online Food Ordering System 1.0 is vulnerable to unauthenticated SQL injection via the admin login endpoint, allowing remote attackers to execute arbitrary SQL commands.
Remote Code Execution in LibreNMS Signal Alert Transport Module
3 TTPsAn authenticated administrator can execute arbitrary code on LibreNMS servers by injecting commands into the Signal Alert Transport configuration fields, triggering unsafe system exec calls.
SQL Injection in PHPGurukul Complaint Management System
1 rule 1 TTP 1 CVEPHPGurukul Complaint Management System 1.0 contains an unauthenticated SQL injection vulnerability in the user/check_availability.php file, allowing remote attackers to execute arbitrary database commands.
MLflow Tracking Server Unauthenticated Full-Read SSRF via Webhook Delivery
1 rule 2 TTPs 2 CVEsMLflow Tracking Server versions prior to 3.15.0 are vulnerable to an unauthenticated full-read SSRF attack because the webhook delivery mechanism follows unvalidated HTTP redirects, allowing attackers to exfiltrate internal data or interact with local services.
Path Traversal in SWE-agent Trajectory Inspector
1 rule 2 TTPs 1 CVEThe SWE-agent trajectory inspector version 1.1.0 is vulnerable to unauthenticated path traversal via the /trajectory/ handler, allowing attackers to read JSON-formatted sensitive files.
Stored XSS Vulnerability in Platnosci Online Blue Media Plugin
2 TTPs 1 CVEAn unauthenticated stored Cross-Site Scripting vulnerability in the Platnosci Online Blue Media WordPress plugin allows attackers to inject malicious scripts into the checkout page.
CVE-2026-15162: Unauthenticated SQL Injection in Object Sync for Salesforce Plugin
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability in the Object Sync for Salesforce WordPress plugin allows remote attackers to execute arbitrary SQL queries via the REST API.
Stored XSS in Online Booking & Scheduling Calendar for WordPress by vcita
1 rule 1 TTP 1 CVEA stored cross-site scripting (XSS) vulnerability in the vcita WordPress plugin up to version 4.6.0 allows unauthenticated attackers to inject arbitrary scripts via the 'business_id' parameter.
Datavane TIS XXE Vulnerability CVE-2026-69101
1 rule 1 TTP 1 CVEDatavane TIS v5.0.0 is vulnerable to XML external entity injection in the doEditWorkflow endpoint, allowing authenticated attackers to perform SSRF and exfiltrate sensitive local files.
Privilege Escalation via Improper API Scope Validation in Grav Plugin
1 TTP 1 CVEThe grav-plugin-api plugin for Grav fails to validate API key scope hierarchy, allowing low-privileged users to mint unrestricted administrative keys via the createApiKey endpoint.
Authentication Scope Bypass in Grav API Plugin Leading to RCE
1 rule 3 TTPs 1 CVEAn API key scope-cap bypass in the Grav API plugin allows attackers with restricted keys to execute server-side templates via Server-Side Template Injection.
Path Traversal Vulnerability in Budibase
1 rule 4 TTPs 1 CVEBudibase versions before 3.40.0 are vulnerable to path traversal via maliciously crafted S3 object keys, allowing authenticated builders to perform arbitrary file writes during workspace export.
Cross-Site Request Forgery in phpList Administrator Deletion
1 CVEA CSRF vulnerability in phpList versions prior to 3.7.0-RC5 allows authenticated administrators to be tricked into deleting other administrator accounts via a crafted GET request.
Stored XSS Vulnerability in Johnson Controls Metasys
1 rule 1 TTPA stored Cross-Site Scripting (XSS) vulnerability (CVE-2026-34491) in Johnson Controls Metasys allows low-privileged users to execute arbitrary scripts in the context of other users' sessions, potentially leading to session hijacking.
SQL Injection in Pimcore via ClassDefinition UID
1 rule 1 TTPAn improper input validation in Pimcore's ClassDefinition UID and unsanitized SQL query construction allow authenticated users to perform UNION-based SQL injection and exfiltrate database contents.
NoSQL Injection in Budibase Server
1 TTP 1 CVEBudibase Server versions before 3.40.0 contain a NoSQL injection vulnerability in the MongoDB query execution endpoint, enabling authenticated attackers to bypass filters and perform unauthorized database operations.
NoSQL Injection Vulnerability in Budibase MongoDB Integration
1 rule 3 TTPs 5 CVEsBudibase versions prior to 3.40.0 are vulnerable to NoSQL injection in the MongoDB datasource due to improper handling of user-supplied parameters, allowing unauthorized data access and potential server-side execution.
Authentication Bypass in SiYuan Publish API
7 rules 19 TTPs 5 CVEsSiYuan versions prior to 3.7.4 contain an authentication bypass vulnerability allowing unauthenticated remote attackers to retrieve decrypted content from encrypted notebooks.
Path Traversal Vulnerability in Joomla com_joomlaupdate
1 TTP 1 CVEJoomla version 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension allowing a Super User to be manipulated into extracting malicious ZIP files, leading to arbitrary file write and remote code execution.
Pre-Authentication XXE Vulnerability in SimpleSAMLphp
1 TTP 2 CVEsA proof-of-concept exploit has been published for a pre-authentication XML External Entity (XXE) vulnerability in SimpleSAMLphp and the Saml2 Library, enabling arbitrary file read by unauthenticated remote attackers.
Unauthenticated Arbitrary File Write in AVideo
2 rules 3 TTPs 1 CVEAn unauthenticated arbitrary file write vulnerability (CVE-2026-72748) in the AVideo aVideoEncoderChunk.json.php endpoint allows remote attackers to upload arbitrary content to the server, potentially leading to remote code execution.
SQL Injection Vulnerability in MingSoft MCMS
1 rule 1 TTP 1 CVEMingSoft MCMS versions up to 3.0.6 contain a remote SQL injection vulnerability in the ms-mdiy component, allowing unauthenticated attackers to manipulate the formFields argument to execute arbitrary database queries.
Improper Authentication in code-projects Task Management System
1 rule 2 TTPs 3 CVEsA vulnerability in code-projects Task Management System 1.0 allows remote attackers to bypass authentication via manipulation of the password argument in the login component.
SQL Injection in CodeIgniter4 Query Builder deleteBatch Method
1 TTP 1 CVEA SQL injection vulnerability in CodeIgniter4 (CVE-2026-63221) allows unauthenticated attackers to execute arbitrary SQL via improperly handled where() clauses when using the deleteBatch() method.
Unauthenticated Remote Code Execution in OpenChamber
2 rules 4 TTPs 3 CVEsOpenChamber 1.11.7 contains a critical unauthenticated RCE vulnerability in the /api/fs/exec endpoint due to improper command input validation and flawed authentication middleware.
SQL Injection Vulnerability in Loca Software CMS
1 rule 1 TTP 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2026-5134) in Loca Software CMS allows remote attackers to execute arbitrary database commands.
CVE-2026-19000 Server-Side Request Forgery in JeecgBoot
1 rule 1 TTP 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability in the JeecgBoot 'Anonymous Chat Attachment Parser' allows remote attackers to perform unauthorized requests via the /airag/chat/send endpoint.
Stored XSS in FluentSMTP WordPress Plugin via Email Logs
2 TTPs 1 CVEAn unauthenticated stored cross-site scripting vulnerability in the FluentSMTP WordPress plugin allows attackers to inject malicious scripts into email logs that execute in an administrator session.
Password Reset Token Expiry Bypass in Flarum
1 TTP 1 CVEFlarum versions prior to 1.8.16 are vulnerable to an unauthenticated password reset token expiry bypass, allowing attackers to reuse expired tokens to gain unauthorized account access.
CVE-2026-9273 Password Reset Poisoning in Kadence Memberships
1 rule 1 TTP 1 CVEThe Kadence Memberships plugin for WordPress is vulnerable to password reset link poisoning, allowing unauthenticated attackers to hijack accounts by redirecting users to malicious hosts to harvest reset tokens.
Cross-Site Scripting Vulnerability in Ghost ActivityPub Client
1 TTP 1 CVEAn XSS vulnerability in the @tryghost/activitypub package (CVE-2026-53950) allows attackers to inject arbitrary JavaScript via malicious ActivityPub server posts.
SSRF Vulnerability in Open WebUI via NAT64-encoded URLs
2 rules 6 TTPs 1 CVEAuthenticated users can bypass SSRF protection in Open WebUI by wrapping internal IPv4 addresses in NAT64 IPv6 transition prefixes, allowing unauthorized access to cloud metadata and internal network services.
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 8 CVEs 2 IOCsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
SQL Injection in Sequelize Oracle Dialect
1 TTPSequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.
Cross-Site Scripting Vulnerability in Angular Server-Side Rendering
1 TTP 1 CVEA Cross-Site Scripting (XSS) vulnerability in @angular/platform-server (CVE-2026-69149) allows script injection via improper serialization of fallback raw-content elements during server-side rendering.
Path Traversal Vulnerability in Grav CMS ImageMedium Class
1 rule 2 TTPs 1 CVEGrav CMS 2.0.10 is vulnerable to path traversal in the ImageMedium::watermark() method, allowing unauthenticated attackers to disclose arbitrary image files by traversing outside the media sandbox.
Authorization Bypass in @better-auth/stripe
1 CVEAn authorization bypass vulnerability in @better-auth/stripe allows authenticated users to perform unauthorized subscription actions and access billing data of other organizations via ID parameter confusion.
Remote Code Execution in Kali Forms WordPress Plugin
1 rule 2 TTPs 1 CVEUnauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.
Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport
1 ruleThe dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.
Leantime Authenticated LFI and SSRF via Blueprints
1 TTP 1 CVELeantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.
Authentication Bypass in FTC E-Commerce Management Panel
1 CVEA missing authentication vulnerability in FTC E-Commerce Management Panel versions prior to 1.0.2 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access.
Reflected XSS in IBM Tivoli System Automation and WebSphere Application Server
1 rule 1 CVEIBM Tivoli System Automation Application Manager 4.1 and WebSphere Application Server are affected by a reflected cross-site scripting vulnerability in the administrative console login page that allows unauthenticated attackers to execute arbitrary JavaScript.
BuddyPress Insecure Deserialization Vulnerability
1 TTPAn insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.
Multiple Vulnerabilities in Apache Traffic Server
2 TTPsMultiple vulnerabilities in Apache Traffic Server can be exploited by a remote, anonymous attacker to bypass security measures, disclose or manipulate data, trigger a denial-of-service, and potentially achieve code execution.
CVE-2026-16597 - GTM4WP WordPress Plugin Vulnerable to Stored XSS via WooCommerce Billing Fields
1 rule 1 TTP 1 CVEThe GTM4WP (Google Tag Manager) plugin for WordPress, in versions up to and including 1.22.3, is vulnerable to stored cross-site scripting (XSS) via CVE-2026-16597, allowing unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields during a guest checkout, which execute when a user accesses the compromised page.
Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin
1 rule 3 TTPs 1 IOCA critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.
WordPress Wholesale for WooCommerce Plugin Privilege Escalation (CVE-2026-12144)
1 TTP 1 CVEThe Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation due to insufficient validation and capability checks in `save_requests_meta()` function, allowing authenticated attackers with author-level access or higher to escalate their privileges to administrator by supplying 'administrator' as the `user_role_set` value in a crafted request.
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)
1 rule 1 TTP 1 CVEThe WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.
Null Pointer Dereference Vulnerability in TinyWeb
1 TTP 1 CVEA null pointer dereference vulnerability, CVE-2026-67184, in TinyWeb through version 0.0.8 allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string, leading to a denial of service.
Poweradmin Vulnerable to Host Header Injection in Authentication Redirects
3 TTPs 1 CVE 1 IOCPoweradmin versions earlier than 4.2.4 and from 4.3.0 up to, but not including, 4.3.3 are vulnerable to CVE-2026-54588, a critical Host Header Injection flaw in OIDC, SAML, and logout authentication flows that allows an unauthenticated attacker to manipulate the HTTP_HOST header, poisoning callback URLs to redirect authorization codes to an attacker-controlled server, leading to full account takeover and potential full DNS zone control.
Rouille HTTP Server Framework Vulnerable to Request Smuggling (CVE-2026-67181)
1 rule 1 TTP 1 CVERouille HTTP server framework versions 0.3.3 through 3.6.2 are vulnerable to an HTTP request smuggling attack, CVE-2026-67181, allowing remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation, leading to potential bypassing of security controls or unauthorized access.
TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.
CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin
1 rule 2 TTPs 1 CVEAn SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.
Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin
1 rule 2 TTPs 1 CVEA path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.
The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)
2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.
Denial-of-Service Vulnerability in facil.io HTTP/1.1 Chunked Transfer Encoding Parser (CVE-2026-66731)
1 TTP 1 CVEAn unauthenticated remote denial-of-service vulnerability exists in facil.io versions 0.7.5 through 0.7.6, allowing attackers to crash the server by sending a POST request with a 'Transfer-Encoding: chunked' header containing a negative chunk size value, which corrupts internal state and leads to a fault.
Critical Eval Injection Vulnerability in vBulletin Allows Remote Code Execution (CVE-2026-61511)
1 rule 2 TTPs 3 CVEs 4 IOCsAn eval injection vulnerability, identified as CVE-2026-61511, exists in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, specifically within the vB5_Template_Runtime::runMaths() method, allowing unauthenticated remote attackers to achieve arbitrary PHP code execution by manipulating the pagenav[pagenumber] parameter through the unauthenticated ajax/render template route with phpfuck-style encoding.
WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 IOCThe WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.
Multiple High-Severity Vulnerabilities in OmniFaces Library
6 TTPs 1 CVEMultiple vulnerabilities in OmniFaces versions prior to 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2 allow attackers to exploit forged combined-resource IDs leading to server-side request forgery (SSRF)-like behavior or information disclosure, achieve client-side arbitrary code execution via cross-site scripting (XSS) in `o:hashParam`, bypass session authentication for push channels resulting in unauthorized message interception, and cause denial-of-service (DoS) via unbounded caches.
Budibase Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
3 TTPs 4 IOCsAn unauthenticated attacker can steal REST datasource credentials, including Bearer/Basic tokens and static headers, from Budibase applications due to a critical cross-origin authentication leak (GHSA-mqhr-6j6h-74p5) where the application attaches stored credentials to outgoing requests without validating the destination host, allowing exfiltration to an attacker-controlled server.
Budibase MongoDB Datasource Vulnerability Allows Server Filesystem Existence/Read Oracle
2 rules 6 TTPs 2 IOCsA vulnerability in Budibase's MongoDB datasource configuration allows authenticated attackers to specify arbitrary absolute server-side file paths for `tlsCertificateKeyFile` and `tlsCAFile`, enabling the `/api/datasources/verify` endpoint to act as an arbitrary-path existence/read oracle on the underlying multi-tenant server, distinguishing between existing and non-existing files and potentially exfiltrating certificate content.
SQL Injection Vulnerability in Budibase MySQL Integration
1 rule 7 TTPsA critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.
Cloudreve OAuth Admin.Read Scope Bypass for OneDrive Storage Policy Credential Update (CVE-2026-55502)
1 rule 1 TTPAn authorization bypass vulnerability (CVE-2026-55502) in Cloudreve 4.16.1 allows an attacker with an `Admin.Read` OAuth token to modify the OneDrive storage policy credentials via a POST request to `/api/v4/admin/policy/oauth/signin`, despite lacking `Admin.Write` scope, which can break the storage backend and redirect future OAuth setups.
Open WebUI: Cross-User Code-Interpreter and Tool Execution via Unvalidated Socket.IO Session ID
1 rule 3 TTPs 1 CVEAn authenticated low-privilege user can exploit CVE-2026-59216 in Open WebUI versions prior to 0.10.0 to execute arbitrary Python code or tools within another user's authenticated session by supplying an unvalidated `session_id`, which, if targeting an administrator, leads to remote code execution on the server as the root process.
Fastify/static Vulnerable to Route Guard Bypass via Path Traversal
1 rule 3 TTPs 1 CVEThe @fastify/static package is vulnerable to a route guard bypass via path traversal using non-leading '..' or '%2E%2E' path segments, allowing attackers to circumvent route-based middleware and access protected files that are served by the static plugin.
React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)
1 TTPAn unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.
VikBooking Hotel Booking Engine & PMS Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-15401)
1 rule 2 TTPs 1 CVEThe VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to and including 1.8.13 is vulnerable to Stored Cross-Site Scripting (XSS) via the 'vbfX' parameter, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an infected page.
Wpify Woo Plugin Privilege Escalation Vulnerability (CVE-2026-12736)
1 rule 2 TTPs 1 CVEA privilege escalation vulnerability (CVE-2026-12736) in the Wpify Woo plugin for WordPress, affecting versions up to and including 5.4.16, allows authenticated attackers with 'Shop Manager' capabilities or higher to gain Administrator privileges by exploiting a REST route that overwrites arbitrary WordPress options.
Microweber CMS Path Traversal Vulnerability (CVE-2026-65694)
1 rule 2 TTPs 1 CVE 2 IOCsAn unauthenticated path traversal vulnerability (CVE-2026-65694) in the static file controller of Microweber CMS, affecting versions through 2.0.20, allows remote attackers to read arbitrary files by supplying directory traversal sequences in the 'path' query parameter via a single unauthenticated HTTP GET request, potentially disclosing sensitive information like environment configuration files containing credentials or system files.
Cal.com Stored Cross-Site Scripting Vulnerability (CVE-2024-58355)
1 TTP 1 CVEA stored cross-site scripting (XSS) vulnerability, CVE-2024-58355, affects Cal.com (calcom/cal.diy) versions through 4.7.15, allowing an attacker to inject arbitrary HTML/JavaScript into a booking-question label that executes in a victim's browser when they view a crafted booking URL, potentially leading to session hijacking, data theft, or defacement.
CVE-2024-58353: Cal.com Cross-Site Scripting Vulnerability
1 TTP 1 CVECVE-2024-58353 describes a cross-site scripting (XSS) vulnerability in Cal.com (repository calcom/cal.diy) versions up to and including 4.7.15, where an attacker can inject malicious HTML/JavaScript into booking question labels that is then executed via React's dangerouslySetInnerHTML when a victim visits a publicly accessible single booking view, allowing for arbitrary client-side code execution, particularly impacting self-hosted instances with open registration.
WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)
2 TTPs 2 CVEs 2 IOCsA critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.
h2oGPT Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2026-65700)
1 rule 3 TTPs 1 CVEh2oGPT through version 0.2.1 contains a critical path traversal vulnerability (CVE-2026-65700) in its OpenAI-compatible files API, allowing unauthenticated remote attackers to achieve arbitrary file read, write, and delete, and ultimately remote code execution, by injecting traversal sequences into the bearer token.
CVE-2026-65919 Unauthenticated Arbitrary File Read in Meshery
1 rule 1 TTP 1 CVEMeshery versions prior to 1.0.57 are vulnerable to an unauthenticated arbitrary file read due to a path traversal flaw in the /api/system/fileView and /api/system/fileDownload API endpoints, allowing attackers to read arbitrary files from the host filesystem without authentication by supplying path traversal sequences.
CyberPanel Missing Authorization Vulnerability Allows Cross-Tenant Backup Manipulation
1 rule 2 TTPs 1 CVEA missing authorization vulnerability, identified as CVE-2026-65916, in CyberPanel through version 1.9.1 allows authenticated users to manipulate and destroy other tenants' backups by sending crafted POST requests to the `cancelBackupCreation` handler.
Auth.js Email Normalizer Vulnerability Allows Homoglyph Bypass Leading to Account Takeover
2 TTPsA critical vulnerability in Auth.js libraries (next-auth and @auth/core) affects the email/magic-link sign-in flow, allowing an attacker to craft an email address with a homoglyph character that bypasses validation before Unicode normalization, leading to magic links being misrouted to attacker-controlled mailboxes and enabling account takeover without victim interaction.
CVE-2026-65898: DOMPurify Vulnerability Leads to Stored Cross-Site Scripting
2 TTPs 1 CVE 2 IOCsA vulnerability in DOMPurify before version 3.4.11 allows attackers to achieve stored Cross-Site Scripting (XSS) by manipulating the `ALLOWED_ATTR` allowlist through an `uponSanitizeAttribute` hook, leading to client-side code execution.
Bold Reports Standalone Report Designer Path Traversal Vulnerability (CVE-2026-65687)
1 rule 2 TTPs 2 CVEsCVE-2026-65687 describes a path traversal vulnerability in Bold Reports Standalone Report Designer prior to version 14.1.12, allowing an unauthenticated attacker to read arbitrary files from the server filesystem by exploiting a missing filepath validation flaw in the SVG processing feature, potentially leading to full unauthorized access via disclosure of sensitive server files like authentication credentials.
CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection
1 rule 2 TTPs 1 CVEThe Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.
SUMO Reward Points WordPress Plugin Vulnerable to Unauthenticated Stored XSS via REST API (CVE-2026-7534)
1 rule 2 TTPs 1 CVEThe SUMO Reward Points plugin for WordPress, versions up to and including 32.7.0, is vulnerable to CVE-2026-7534, an Unauthenticated Stored Cross-Site Scripting flaw that allows attackers to inject arbitrary web scripts into the reward points log via the `/wp-json/wc-srp/v1/earning` REST API endpoint, executing when an administrator accesses specific admin pages.
Next.js App Router Middleware/Proxy Bypass Vulnerability (CVE-2026-64642)
2 TTPsA high-severity vulnerability, CVE-2026-64642, in Next.js App Router applications built with Turbopack and configured with a single locale entry allows attackers to bypass middleware and proxy-based authentication mechanisms through specially crafted HTTP requests, leading to unauthorized access to protected resources.
Next.js Server-Side Request Forgery and Open Redirect Vulnerability (CVE-2026-64645)
2 rules 3 TTPsA vulnerability (CVE-2026-64645) in Next.js allows Server-Side Request Forgery (SSRF) and Open Redirect when `rewrites()` or `redirects()` rules in `next.config.js` use attacker-controlled input to construct external destination hostnames, enabling attackers to manipulate dynamic segments from the path or `has` captures to point the rewrite to an arbitrary hostname, potentially leading to internal network access, information disclosure, or redirection of users to malicious sites, affecting Next.js versions from 12.0.0 up to, but not including, 15.5.21, and versions from 16.0.0 up to, but not including, 16.2.11.
Eclipse Jetty Digest Authentication Bypass via ISO-8859-1 Encoding Flaw (CVE-2026-10050)
1 TTPA vulnerability, CVE-2026-10050, in Eclipse Jetty's HTTP client `DigestAuthentication.apply()` method allows an authentication bypass by an attacker who can exploit the lossy ISO-8859-1 character encoding to forge Digest authentication response hashes for users with non-Latin-1 passwords.
LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback
1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.
Grav Login Plugin Privilege Escalation (CVE-2026-65603)
2 TTPs 1 CVEA critical privilege escalation vulnerability, CVE-2026-65603, exists in the Grav Login plugin (grav-plugin-login) versions up to and including 3.8.11, allowing an authenticated low-privilege user to exploit a flaw in the `processUserProfile()` handler to bypass privilege stripping and escalate to super-admin, enabling admin panel access, remote code execution, and Twig evaluation.
CVE-2026-65057 Server-Side Request Forgery in Keep Healthcheck Endpoint
1 rule 2 TTPs 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability in Keep (commit 91c75e0) allows attackers to exploit an unprotected healthcheck endpoint by supplying crafted JSON payloads with malicious host values, forcing the backend to issue arbitrary HTTP requests to internal services or cloud metadata endpoints for internal network reconnaissance and theft of cloud credentials.
Gitea Server-Side Request Forgery Vulnerabilities
1 rule 3 TTPs 1 IOCTwo Server-Side Request Forgery (SSRF) vulnerabilities in Gitea version 1.26.2 and earlier allow authenticated users to bypass IP filtering for webhooks and repository migrations by targeting CGNAT and IPv6 transition prefixes, and unauthenticated users to trigger arbitrary GET requests against internal hosts via the OpenID sign-in form, potentially leading to internal network discovery and data exposure.
SVGO removeScripts Plugin Bypass Leads to Cross-Site Scripting
2 TTPsA vulnerability in the SVGO library's `removeScripts` plugin, affecting versions prior to 2.8.3, 3.3.4, and 4.0.2, allowed namespaced script elements and case-insensitive JavaScript URIs to bypass sanitization, potentially leading to Cross-Site Scripting (XSS) in web applications serving untrusted SVGs.
Gitea Repository Migration SSRF and Internal Git Repository Exfiltration
2 rules 9 TTPs 1 CVEA critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.
Unauthenticated Input Validation Bypass in Ninja Forms WordPress Plugin (CVE-2026-65052)
1 TTP 1 CVEAn improper input validation vulnerability, identified as CVE-2026-65052, in Ninja Forms WordPress plugin versions 3.14.8 and prior allows unauthenticated attackers to tamper with form submission payloads to the ajax submit endpoint, injecting arbitrary numeric values into form calculations and payment totals, thereby bypassing admin-configured pricing logic and potentially reducing payment amounts to zero.
WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)
1 rule 2 TTPs 1 CVEAn unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.
CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability
4 rules 4 TTPs 2 IOCsA high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.
CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability
1 rule 2 TTPs 1 CVEA high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.
Astro Authorization Bypass via Iterative Decode Limit and Canonicalization Mismatch
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability exists in Astro versions >= 6.4.7 and < 6.4.8, caused by a mismatch in URL path canonicalization, allowing an unauthenticated attacker to bypass middleware protections and access protected routes if the application relies on pathname-based authorization and uses rewrite behavior that performs route matching after middleware execution.
LightRAG CORS Misconfiguration Allows Credentialed Cross-Origin Requests (CVE-2026-61736)
2 TTPs 1 CVEThe LightRAG application, specifically the 'lightrag-hku' package, contains a critical vulnerability (CVE-2026-61736) due to its default Cross-Origin Resource Sharing (CORS) configuration, enabling any malicious website to perform authenticated API calls on behalf of a logged-in LightRAG user, leading to unauthorized data exfiltration or destructive actions.
CVE-2026-63766: Unauthenticated OS Command Injection in GPT-SoVITS webui.py
1 rule 2 TTPs 1 CVE 2 IOCsAn unauthenticated OS command injection vulnerability (CVE-2026-63766) in GPT-SoVITS through version 20250606v2pro's webui.py allows attackers to execute arbitrary operating system commands via shell metacharacters in Gradio textbox inputs, leading to remote code execution.
Adminer Cookie Injection Vulnerability via X-Forwarded-Prefix Header (CVE-2026-63771)
1 rule 1 TTP 1 CVEAdminer versions prior to 5.4.3 are vulnerable to a cookie injection flaw, which allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header, enabling cross-origin authenticated requests and bypassing cookie security controls.
Server-Side Request Forgery in Huginn (CVE-2026-63769)
1 rule 2 TTPs 1 CVEA server-side request forgery vulnerability, CVE-2026-63769, in Huginn through version 2022.08.18 allows authenticated users to make arbitrary HTTP requests via crafted URLs, leading to internal network probing, port enumeration, and potential credential theft from cloud metadata endpoints.
Roo Code Command Injection Vulnerability (CVE-2026-63108)
1 rule 1 TTP 1 CVEA command injection vulnerability in Roo Code versions through 3.54.0 allows attackers to bypass allowlist/denylist enforcement in the auto-approve execute feature. By nesting command substitutions inside parameter expansion defaults, the command parser in parse-command.ts fails to detect the dangerous payloads, leading to their auto-approval and subsequent arbitrary command execution via the shell through execa.
Tornado Quadratic DoS via Repeated HTTP Header Coalescing (CVE-2025-67725)
1 TTP 1 CVEA quadratic Denial of Service (DoS) vulnerability exists in Tornado's `HTTPHeaders.add` method due to inefficient string concatenation for repeated header names, which, when processing a maliciously crafted HTTP request with numerous repeated headers, can block the server's single event loop for an extended period, leading to a high severity DoS if `max_header_size` is increased from its default 64KB.
Tenda AC10 Buffer Overflow Vulnerability (CVE-2026-16248)
2 TTPs 1 CVE 6 IOCsA stack-based buffer overflow vulnerability (CVE-2026-16248) has been identified in Tenda AC10 firmware version 16.03.10.09_multi_TDE01, residing in the fromAdvSetLanip function of the /goform/AdvSetLanip file within the httpd/netctrl component, which can be remotely exploited by manipulating the GetValue/SetValue argument, with a public exploit now available.
Web Server Local File Inclusion Activity
1 rule 4 TTPs 1 IOCThis brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.
Shibboleth Service Provider SQL Injection Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a SQL Injection vulnerability within the Shibboleth Service Provider software, allowing them to perform unauthorized database queries and potentially extract or manipulate sensitive data.
QueryWeaver Authentication Bypass via Signup Request (CVE-2026-10130)
3 TTPs 1 CVECVE-2026-10130 describes an authentication bypass vulnerability in QueryWeaver, enabling unauthenticated attackers to obtain valid session tokens for existing user accounts by submitting a crafted signup request with a known victim's email address, leveraging a Cypher MERGE operation that unconditionally links a new token before checking for existing accounts.
CVE-2024-58368: SurrealDB Denial-of-Service via Malformed HTTP Headers
1 TTP 1 CVEUnauthenticated attackers can exploit CVE-2024-58368 in SurrealDB versions prior to 1.1.0 by sending crafted HTTP REST API requests with malformed ID, DB, or NS headers, leading to an uncaught exception and server crash, resulting in denial of service.
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
Authenticated Full-Read SSRF in CloudTAK /api/esri* Routes
1 rule 3 TTPs 2 IOCsAn authenticated Server-Side Request Forgery (SSRF) vulnerability exists in CloudTAK's `/api/esri*` routes, allowing any authenticated user to compel the server to make arbitrary outbound HTTP requests to internal network resources, enabling attackers to access sensitive cloud instance metadata, enumerate internal services, and exfiltrate data by reflecting the response bodies.
IBM Langflow OSS Remote Code Execution via Deserialization
1 rule 5 TTPs 7 CVEs 1 IOCIBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.
IBM Engineering AI Hub Cross-site Scripting Vulnerability (CVE-2026-15091)
2 TTPs 1 CVEA critical cross-site scripting (XSS) vulnerability, identified as CVE-2026-15091 with a CVSS v3.1 score of 9.3, affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, allowing a remote attacker to execute arbitrary scripts due to improper input neutralization during web page generation.
Flask-Reuploaded Extension Denylist Bypass via Case-Folding Asymmetry
3 TTPs 1 CVEAn incomplete fix for CVE-2026-27641 in Flask-Reuploaded versions up to and including 1.5.0 allows attackers to bypass extension denylists through case-folding asymmetry, enabling the upload of malicious files with dangerous extensions (e.g., shell.PHP) that can lead to remote code execution on case-insensitive execution environments.
meta-ads-mcp Authentication Bypass via X-Pipeboard-Token Header
3 TTPsAn authentication bypass vulnerability in `meta-ads-mcp` version 1.0.113 allows unauthenticated network callers to gain unauthorized access by sending an arbitrary value in the `X-Pipeboard-Token` HTTP header, leading to the reuse of the server operator's `META_ACCESS_TOKEN` for full read and write access to Meta Ads data.
IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)
1 rule 3 TTPs 11 CVEs 2 IOCsUnauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.
FreePBX Modules Vulnerable to Unauthenticated RCE and SQL Injection
2 rules 5 TTPsMultiple critical vulnerabilities have been identified in FreePBX modules, including unauthenticated remote code execution (RCE) in the UCP module, unauthenticated SQL injection in the missedcall module leading to administrator takeover, authenticated command injection in the TTS module, and authenticated RCE in the music module. These flaws affect specific versions of these modules across FreePBX 16 and 17, allowing attackers to execute arbitrary commands, bypass authentication, and gain administrative control.
Vulnerability in poco-ai poco-claw Leads to Server-Side Request Forgery (CVE-2026-16016)
1 rule 2 TTPs 1 CVEA high-severity server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16016, exists in poco-ai's poco-claw software up to version 0.5.4, allowing remote attackers to manipulate the `callback_url` argument in the `run_task` function to force the server to make arbitrary requests, with a public exploit available posing an immediate risk.
Kali Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via digitalSignature Field
1 rule 6 TTPs 1 CVEThe Kali Forms - Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'digitalSignature' field in versions up to and including 2.4.18, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an affected page.
Grav API Plugin Vulnerable to CORS Misconfiguration Allowing Data Exposure and Unauthorized Operations
1 rule 3 TTPs 1 CVEThe Grav API plugin before version 1.0.0-rc.16 contains a CORS misconfiguration that sets `Access-Control-Allow-Origin: *` by default, enabling an attacker to perform authenticated cross-origin requests from a malicious website after obtaining a valid API token, leading to sensitive data exfiltration and unauthorized write operations.
Grav .htaccess Case-Insensitivity Bypass for Sensitive File Access
1 rule 3 TTPs 1 CVEAn unauthenticated attacker can exploit a flaw in Grav prior to version 2.0.4 where the default .htaccess file's rules for blocking access to sensitive file types are case-sensitive, allowing bypass on case-insensitive filesystems (Windows, macOS, or Docker volume mounts) by requesting sensitive configuration files (e.g., .yaml, .php, .json) using uppercase or mixed-case extensions, leading to unauthorized reading of files that may contain API keys and credentials.
Pheditor Hardcoded Admin Password Leads to Remote Code Execution (CVE-2026-55579)
1 rule 5 TTPsPheditor contains a critical vulnerability (CVE-2026-55579) where a hardcoded default password 'admin' with no forced change mechanism upon first login allows an unauthenticated attacker to gain full administrative access, enabling arbitrary file read/write and remote code execution through the application's terminal feature, leading to complete server compromise.
Pheditor Authenticated Command Whitelist Bypass via Shell Command Substitution
1 rule 1 TTPPheditor 2.0.4 contains an authenticated command injection vulnerability, CVE-2026-54540, allowing a user with `terminal` permissions to bypass the `TERMINAL_COMMANDS` whitelist by leveraging shell command substitution to execute arbitrary shell commands as the web server user.
AVideo OS Command Injection Vulnerability (CVE-2026-63304)
1 rule 1 TTP 1 CVE 2 IOCsAVideo versions up to and including 29.0 are vulnerable to an OS command injection (CVE-2026-63304) in the `listFFmpegProcesses()` function within `plugin/API/standAlone/functions.php`, allowing attackers to craft an encrypted `codeToExec` payload to bypass single-quote escaping and execute arbitrary operating system commands as the web-server user, leading to remote code execution.
Vulnerability in Ruby on Rails Allows Remote Indirect Code Injection (XSS)
1 TTP 1 IOCA cross-site scripting (XSS) vulnerability has been discovered in Ruby on Rails versions prior to 1.7.1, enabling a remote attacker to perform an indirect remote code injection, allowing malicious scripts to be executed in the client's browser.
WordPress Digits Plugin Privilege Escalation via Missing Authorization
1 rule 1 TTP 1 CVEThe Digits: WordPress Mobile Number Signup and Login plugin is vulnerable to privilege escalation, allowing authenticated attackers with Subscriber-level access to elevate privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, impacting WordPress sites configured with the built-in DIGITS User Role field.
RPB Chessboard WordPress Plugin Vulnerable to Stored Cross-Site Scripting
1 TTP 1 CVEThe RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its comment content functionality, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user views the affected page, bypassing WordPress's default kses sanitization.
SQL Injection Vulnerability in WordPress WooCommerce Advanced Product Search Plugin (CVE-2026-12753)
1 rule 2 TTPs 1 CVEA SQL Injection vulnerability, CVE-2026-12753, has been identified in the Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress, affecting all versions up to and including 1.4.4. The flaw, caused by insufficient input sanitization of the 's' and 'match' parameters and inadequate SQL query preparation, allows unauthenticated attackers to append arbitrary SQL queries. This enables them to extract sensitive information directly from the database.
SQL Injection Vulnerability in H3C SecPath F1000-C8300 (CVE-2026-15907)
1 rule 1 TTP 1 CVE 5 IOCsA SQL injection vulnerability, CVE-2026-15907, exists in H3C SecPath F1000-C8300 appliances up to version 20260522, allowing remote attackers to manipulate the 'subject' argument in the '/webui/?g=log_fw_nbc_mail_jsondata' endpoint to execute arbitrary SQL commands, potentially leading to unauthorized data access or system compromise, with a publicly available exploit.
TensorZero Gateway Arbitrary File Read and SSRF Vulnerability
1 rule 3 TTPsA high-severity vulnerability (CVE-2026-54457) in the TensorZero Gateway's `/internal/object_storage` endpoint allows attackers to achieve arbitrary file reading from the gateway filesystem and Server-Side Request Forgery (SSRF) by manipulating the `storage_path` parameter, potentially leading to credential exposure and internal network reconnaissance.
Gravity Forms Directory Traversal Vulnerability (CVE-2026-12997)
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a Directory Traversal vulnerability (CVE-2026-12997) in the Gravity Forms plugin for WordPress, affecting all versions up to and including 2.10.4, to read arbitrary files on the server and receive their contents as an email attachment, potentially exfiltrating sensitive information.
MantisBT Reflected XSS Vulnerabilities in admin/install.php (CVE-2026-52847)
1 rule 4 TTPsMantisBT versions 2.28.3 and earlier are vulnerable to six reflected XSS injection points in the `/admin/install.php` script, which attackers can exploit without authentication to perform credential phishing, open redirects, and UI manipulation due to an incomplete Content Security Policy.
Kanboard Vulnerability CVE-2026-58660 Allows Cross-Project Task Manipulation
3 TTPs 1 CVEA high-severity vulnerability, CVE-2026-58660, in Kanboard versions up to 1.2.52 allows any authenticated user to enumerate, move, corrupt, or hide tasks belonging to any project on the same instance, including private projects, due to improper validation in the BoardAjaxController save() method.
Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)
4 TTPs 3 CVEsA Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.
MantisBT Remote Code Execution via Class Hoisting (CVE-2026-49273)
1 rule 1 TTPA high-severity remote code execution vulnerability, CVE-2026-49273, affects MantisBT versions 2.28.3 and earlier, allowing an authenticated administrator to achieve arbitrary code execution as the web server user by leveraging PHP's class hoisting during the processing of non-string configuration values in `adm_config_set.php`.
MantisBT SOAP API Authentication Bypass and Privilege Escalation (CVE-2026-47156)
2 TTPsA critical authentication bypass vulnerability, CVE-2026-47156, exists in the SOAP API's mci_check_login() function of MantisBT versions 2.28.3 and earlier, allowing an unauthenticated attacker to impersonate any user, including an administrator, by knowing a valid cookie_string and the target username, without needing the target's password, which can lead to full administrator access, extensive data exfiltration, and destructive operations when default self-registration is enabled.
MantisBT SQL Injection via history_order Configuration Value
2 rules 8 TTPsMantisBT versions 2.28.3 and earlier are vulnerable to a SQL injection within the `history_order` configuration value in `core/history_api.php`, allowing an authenticated administrator to inject malicious SQL via the web UI or REST API, which then executes whenever any user views a bug with history entries, leading to sensitive data extraction and potential Remote Code Execution (RCE) via webshell if the MySQL FILE privilege is enabled.
Grav Form Plugin Arbitrary File Write Vulnerability (CVE-2026-61873)
1 rule 3 TTPs 1 CVEGrav before version 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, allowing attackers to bypass path traversal validation via Twig template processing and write PHP webshells for remote code execution.
Grav API Plugin File Upload Extension Bypass Leading to RCE
1 rule 3 TTPs 1 CVEA vulnerability (CVE-2026-61457) in the Grav API plugin before version 1.0.3 allows an authenticated attacker with `api.media.write` permissions to bypass file upload extension validation using double extensions, which can lead to remote code execution on the web server.
PraisonAI MCP HTTP-Stream Authentication Bypass (CVE-2026-61427)
1 rule 3 TTPs 1 CVEPraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability, CVE-2026-61427, in the MCP HTTP-stream transport, allowing unauthenticated clients to establish sessions, enumerate tools, and invoke tools, potentially leading to remote code execution if the server is bound to a network-accessible address.
Grav Flex Objects Plugin Stored Template Injection Leading to RCE
1 rule 1 TTP 1 CVEA stored server-side template injection vulnerability, identified as CVE-2026-58655, exists in the Grav Flex Objects plugin before version 1.4.0, allowing an attacker to achieve arbitrary Twig execution and remote command execution by injecting malicious code into user-controlled title frontmatter that bypasses sanitization.
Open WebUI Stored Cross-Site Scripting Vulnerability (CVE-2026-56398)
2 TTPs 1 CVEOpen WebUI before version 0.9.5 contains a high-severity stored cross-site scripting (XSS) vulnerability, CVE-2026-56398, in its OAuth authentication flow that allows an authenticated attacker to bypass profile image validation by uploading malicious SVG files, leading to script execution, authentication token theft, and ultimately account takeover for other authenticated users.
CVE-2026-61451: Unauthenticated Account Takeover in Grav API Plugin via Password Reset Vulnerability
1 rule 3 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-61451 in Grav API plugin versions prior to 1.0.4, leveraging improper URL validation in the password reset functionality to specify an arbitrary host in the reset link, thereby disclosing valid reset tokens to an attacker-controlled server and enabling full account takeover.
Zhinianboke Xianyu-Auto-Reply Missing Authorization Vulnerability (CVE-2026-15752)
1 TTP 1 CVEA missing authorization vulnerability (CVE-2026-15752) exists in the /api/v1/users/ endpoint of zhinianboke xianyu-auto-reply, affecting versions up to commit dcb445ad97816ad65299a7580ee0c8c8f929da84, allowing a remote attacker to bypass authentication or authorization checks. An exploit for this vulnerability has been made public, and organizations using this product should apply the patch named 19fc3282a1bb78a05c34945c088525d20e081cbd to mitigate the risk.
CAI Content Credentials Server-Side Request Forgery Leads to Arbitrary Code Execution
2 TTPs 1 CVECAI Content Credentials is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-48290, which an attacker can exploit to achieve arbitrary code execution and potentially gain elevated access by injecting malicious scripts into a web page, requiring user interaction to succeed.
Unauthenticated API Key Use in NetLicensing-MCP HTTP Mode
5 TTPsAn unauthenticated vulnerability exists in netlicensing-mcp (version 0.1.5 and earlier) when operating in HTTP transport mode, where the ApiKeyMiddleware fails to enforce authentication for requests lacking a client API key, causing the application to fall back to the server's NETLICENSING_API_KEY environment variable for upstream calls, allowing an unauthenticated network attacker to invoke any MCP tool under the server operator's identity and account quota.
Command Injection in Sustainable Irrigation Platform cli_control Plugin
3 TTPs 3 CVEsA critical command injection vulnerability (CVE-2026-58479) exists in the optional cli_control plugin of Sustainable Irrigation Platform (SIP) versions up to 5.2.16, allowing unauthenticated or CSRF attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating an associated irrigation station.
Apache ActiveMQ Cross-Site Scripting Vulnerability
1 TTPA remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Apache ActiveMQ to execute malicious scripts within a victim's browser.
Remote SQL Injection Vulnerability in code-projects Online Job Portal (CVE-2026-15676)
1 rule 2 TTPs 1 CVEA high-severity SQL injection vulnerability, CVE-2026-15676, exists in code-projects Online Job Portal up to version 1.0, allowing remote unauthenticated attackers to manipulate the database via the /Admin/DeleteUser.php file with a publicly available exploit.
CVE-2026-44752: SAP NetWeaver Application Server Java Cross-Site Scripting Vulnerability
3 TTPs 1 CVEAn unauthenticated attacker can exploit a cross-site scripting (XSS) vulnerability (CVE-2026-44752) in SAP NetWeaver Application Server Java by injecting malicious JavaScript through crafted URLs, leading to client-side script execution, access to sensitive session information, and modification of non-sensitive data, resulting in high confidentiality impact and low integrity impact.
CVE-2026-61462 - mcp-gitlab Path Traversal Vulnerability Leading to Unauthorized API Access
1 rule 2 TTPs 1 CVEA path traversal vulnerability, CVE-2026-61462, in the job_id parameter of build/index.js within mcp-gitlab allows attackers to redirect GitLab API requests to arbitrary endpoints by escaping the intended path prefix, leveraging the operator's personal access token for unauthorized access.
Rejetto HFS Vulnerability Allows Remote Code Execution via Session Forgery (CVE-2026-61500)
4 TTPs 1 CVEA remote attacker can exploit a critical vulnerability, CVE-2026-61500, in Rejetto HFS versions 3.0.0 through 3.2.0 by recovering the session-cookie signing key due to poor randomness, forging an administrator session, and achieving remote code execution.
NukeViet Server-Side Request Forgery via X-Forwarded-Host (CVE-2026-55372)
2 TTPsAn unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in NukeViet by spoofing the X-Forwarded-Host and X-Forwarded-Proto HTTP headers, allowing the server to make a cURL request to an attacker-controlled host without validation for internal host/port discovery and cache poisoning. The vulnerability affects NukeViet versions prior to 4.6.00.
NukeViet Multiple Anti-XSS Filter Bypasses Leading to Stored XSS
2 TTPsTwo filter-bypass techniques in NukeViet\Core\Request allow a low-privileged user with news-posting permission to store and execute arbitrary JavaScript in the browsers of any visitor to an affected page, leading to session cookie theft, credential harvesting, defacement, and further privilege escalation via CVE-2026-54064.
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
1 rule 2 TTPsAn authenticated administrator in NukeViet is vulnerable to a path traversal flaw (CVE-2026-54065) in the Edit Comment admin function, allowing an attacker to inject a crafted `attach` parameter which, upon comment deletion, leads to arbitrary file deletion within the application root, causing a full application outage and exposing the install wizard.
NukeViet CMS Stored Cross-Site Scripting Vulnerability
1 rule 2 TTPsA stored cross-site scripting (XSS) vulnerability, CVE-2026-49259, exists in NukeViet CMS versions 4.x through 4.5.08, including the 'composer/nukeviet/nukeviet' package prior to version 4.5.09, which allows a low-privileged authenticated user to inject JavaScript into their profile's display name fields that executes in the browser of any visitor, including administrators, who clicks the 'Reply' link on a comment posted by the attacker, leading to arbitrary JavaScript execution, administrative session hijacking, credential phishing, and data exfiltration.
Decidim Vulnerability Allows Unauthorized Access to Identity Documents via Reusable Signed URLs
1 rule 1 TTPA high-severity vulnerability (CVE-2026-45378) in Decidim's identity document verification workflow allows unauthorized access to sensitive identity documents. Signed `/rails/active_storage/disk/` URLs, which are generated for administrator review, can be harvested and replayed by unauthenticated users for up to seven days, enabling attackers to bypass authentication and download highly sensitive personal information if these URLs are leaked through various channels.
CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0
1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.
Drupal AlternativeCommerce (Basket) Module Vulnerability Allows Code Execution
2 TTPsA critical vulnerability in the Drupal 'AlternativeCommerce' (Basket) module allows a remote, unauthenticated attacker to execute arbitrary program code. This can lead to full compromise of the affected web application.
Metasoft MetaCRM SQL Injection Vulnerability (CVE-2026-15514)
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-15514) in Metasoft MetaCRM up to version 6.4.0 Beta06 allows remote attackers to exploit the RPCService.query function via the phprpc_args argument in /customizemt/xkq/rpc.jsp, leading to unauthorized database access and manipulation, with a public exploit available.
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)
1 TTP 1 CVELuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.
CVE-2026-61875: Stored Cross-Site Scripting in OpenWrt luci-app-upnp
2 TTPs 1 CVECVE-2026-61875 details a stored cross-site scripting vulnerability in OpenWrt's luci-app-upnp that allows unauthenticated LAN clients to inject malicious JavaScript into UPnP IGD AddPortMapping SOAP requests, leading to client-side code execution in an administrator's browser when viewing specific web interface pages.
CVE-2026-15489: SQL Injection in RafyMrX TOKO-ONLINE-ROTI login.php
2 rules 4 TTPs 1 CVEA critical SQL injection vulnerability (CVE-2026-15489) exists in RafyMrX TOKO-ONLINE-ROTI, allowing remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument in the 'proses/login.php' file, with a public exploit available.
SQL Injection Vulnerability in Aster Telecom Azcall (CVE-2026-15482)
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability, tracked as CVE-2026-15482, exists in Aster Telecom Azcall 10/11 within the HTTP Handler component, where manipulating the 'nome/perfil/status' argument when accessing '/azcall/adm/gestao_loja/sis.php?t=consultar' can lead to remote SQL injection, with a publicly available exploit allowing unauthenticated attackers to potentially access or modify sensitive data.
WP CTA Plugin Vulnerable to Unauthenticated Time-Based Blind SQL Injection (CVE-2026-4661)
1 rule 2 TTPs 1 CVEThe WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in versions up to and including 2.2.2. This vulnerability is due to insufficient escaping of user-supplied column names and lack of preparation in database queries. Unauthenticated attackers can exploit this by injecting arbitrary SQL queries to extract sensitive information, including administrator password hashes, from the database.
The Swiss Toolkit For WP Plugin Vulnerable to Arbitrary File Upload Leading to RCE (CVE-2026-2354)
1 rule 3 TTPs 1 CVEA critical arbitrary file upload vulnerability (CVE-2026-2354) exists in The Swiss Toolkit For WP plugin for WordPress, affecting all versions up to and including 1.4.6. The flaw, located in the `upload_extension_files()` function, allows authenticated attackers with Author-level access or higher to bypass file type validation due to an improper `strpos()` check, enabling the upload of arbitrary files, including PHP scripts, which can lead to remote code execution on the server if the "Enhanced Multi-Format Image Support" feature is active with at least one configured extension.
WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection
1 TTP 1 CVEThe Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.
SiYuan Stored XSS via Malicious Bazaar Package README
5 TTPs 1 CVEA stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-54070, affects SiYuan versions up to 3.6.5, allowing a malicious third-party package author to embed JavaScript in package READMEs via an incomplete HTML sanitizer's blocklist, which executes in an Administrator's authenticated browser session upon viewing and interacting with the crafted README in the Bazaar marketplace, leading to API token theft and potential full workspace control.
SiYuan Unauthenticated Admin API Access via Chrome Extension Allowlist
1 rule 6 TTPs 1 CVE 1 IOCA critical vulnerability (CVE-2026-54069) in SiYuan Note kernel's HTTP server allows any Chrome/Chromium browser extension to gain unauthenticated RoleAdministrator access, enabling data exfiltration, stored XSS injection, and configuration tampering for SiYuan desktop users, including via compromised legitimate extensions.
FileBrowser Authentication Bypass via Forged Proxy Authentication Header
1 rule 3 TTPsAn unauthenticated attacker can impersonate any user, including administrators, or automatically create new user accounts in FileBrowser by forging the `X-Remote-User` HTTP header when the server is configured for proxy authentication and is directly reachable, leading to full administrative control and unauthorized access to data.
SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding
1 rule 3 TTPs 2 CVEs 1 IOCAn incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.
Dify MyScale Backend SQL Injection Vulnerability (CVE-2026-61461)
1 rule 4 TTPs 1 CVEA high-severity SQL injection vulnerability, CVE-2026-61461, exists in the MyScale vector store backend of Dify versions prior to 1.16.0-rc1, allowing attackers with low privileges to execute arbitrary SQL commands via unsanitized search parameters, leading to unauthorized data manipulation in the underlying ClickHouse database.
CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 CVEA critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.
Crawl4AI Server-Side Request Forgery Vulnerability (CVE-2026-56261)
2 TTPs 1 CVECrawl4AI versions before 0.8.7 contain a server-side request forgery (SSRF) vulnerability, CVE-2026-56261, in its Docker API server's webhook endpoints, allowing an attacker to coerce the server into making requests to internal services and potentially expose cloud metadata.
Lucee CFML Server Reflected XSS Vulnerability (CVE-2026-29519)
1 rule 2 TTPs 1 CVELucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines are vulnerable to a reflected cross-site scripting (XSS) flaw in URL path parsing, allowing unauthenticated remote attackers to embed arbitrary HTML or JavaScript payloads within the request path which, when visited by a victim, enables the execution of arbitrary JavaScript in the victim's browser for purposes such as session hijacking or unauthorized actions against the Lucee administrative interface.
CVE-2026-15330: zhayujie CowAgent Server-Side Request Forgery
1 rule 1 TTP 1 CVEA critical server-side request forgery (SSRF) vulnerability, CVE-2026-15330, exists in zhayujie CowAgent up to version 2.1.1, allowing remote attackers to manipulate the 'image' argument in the Vision Tool component's `_build_image_content` or `_download_to_data_url` functions to access internal resources or conduct port scanning.
CVE-2026-15290: Ultimate Member Plugin Blind SQL Injection
1 rule 2 TTPs 2 CVEsThe Ultimate Member plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to and including 2.10.1, due to insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-13430: WordPress Post Export Import with Media Plugin Arbitrary File Upload Leading to RCE
1 rule 2 TTPs 1 CVEA high-severity arbitrary file upload vulnerability, CVE-2026-13430, exists in all versions up to 1.13.1 of the Post Export Import with Media plugin for WordPress, allowing authenticated administrators to upload executable web shells via a trailing-dot filename bypass, leading to remote code execution.
CVE-2026-58122: Hermes WebUI Authentication Bypass via Spoofed X-Forwarded-For Header
1 rule 4 TTPs 1 CVECVE-2026-58122 describes an authentication bypass vulnerability in Hermes WebUI before version 0.51.307, allowing unauthenticated remote attackers to bypass local-origin IP restrictions on onboarding endpoints by spoofing the X-Forwarded-For header with a loopback address, leading to server-side request forgery (SSRF), API key overwrites, and persistent access token acquisition.
YesWiki Unauthenticated ActivityPub Signature-Verification Bypass (CVE-2026-52767)
1 rule 3 TTPsA critical vulnerability, CVE-2026-52767, in YesWiki's `HttpSignatureService::verifySignature()` allows unauthenticated attackers to bypass ActivityPub signature verification due to a loose boolean negation (`!openssl_verify(...)`) accepting `int(-1)` from PHP's `openssl_verify()` under specific conditions, enabling arbitrary Create, Update, and Delete operations on ActivityPub-enabled forms leading to defacement and content manipulation.
YesWiki Unauthenticated SSRF via ActivityPub Signature.keyId (CVE-2026-52769)
1 rule 3 TTPs 1 IOCAn unauthenticated Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52769, exists in YesWiki's `POST /api/forms/{formId}/actor/inbox` route when ActivityPub is enabled, allowing attackers to force arbitrary outbound HTTP GET requests to internal or external hosts and potentially exfiltrate sensitive information via timing and error messages.
CVE-2026-9253: WordPress E&P Forms Plugin Stored Cross-Site Scripting
2 TTPs 1 CVEAn unauthenticated attacker can inject arbitrary web scripts into WordPress sites running the 'WP Cost Estimation & Payment Forms Builder' plugin version 10.5.97 and earlier by exploiting CVE-2026-9253, a Stored Cross-Site Scripting vulnerability via the 'customerInfos' parameter, leading to script execution in users' browsers and potential session hijacking or data theft.
EventPrime WordPress Plugin Stored XSS (CVE-2026-13441)
1 rule 2 TTPs 1 CVEA critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-13441, exists in all versions up to 4.3.4.2 of the EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress, allowing authenticated attackers with custom-level access (or unauthenticated attackers if 'Guest Submissions' is enabled) to inject malicious web scripts via the new_event_type_background_color parameter that execute whenever a user accesses an affected page, potentially leading to session hijacking, defacement, or further compromise.
CVE-2026-5955: Critical SQL Injection in Inrove BiEticaret
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-5955) in Inrove Software and Internet Services BiEticaret, affecting versions before v3.3.57, allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to data exfiltration and full system compromise.
CVE-2026-38969: Ruby WEBrick Request Smuggling Vulnerability
2 TTPs 1 CVEA high-severity vulnerability, CVE-2026-38969, exists in Ruby WEBrick versions up to v1.9.2 due to improper re-parsing of the 'trailer Content-Length' header, enabling HTTP request smuggling that attackers can exploit to bypass security controls and gain unauthorized access or execute arbitrary requests.
Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification
1 TTPMultiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.
Gradio Open Redirect and Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-59806)
1 rule 2 TTPs 1 CVEGradio versions before 6.20.0 contain an open redirect and server-side request forgery (SSRF) vulnerability, CVE-2026-59806, allowing attackers to redirect users or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the `/gradio_api/file=` endpoint, potentially leading to the retrieval of sensitive credentials, such as EC2 IAM role credentials.
Unauthenticated SQL Injection in IBM API Connect (CVE-2026-9074)
1 rule 3 TTPs 1 CVEIBM API Connect versions 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 are vulnerable to an unauthenticated SQL injection (CVE-2026-9074) in the password reset functionality, potentially leading to unauthorized data access or authentication bypass.
CVE-2026-59703: repomix Local File Inclusion Vulnerability
1 rule 2 TTPs 1 CVErepomix contains a local file inclusion vulnerability (CVE-2026-59703) in its git clone endpoint, allowing unauthenticated attackers to read arbitrary local git repositories and server filesystem contents by bypassing validation with crafted file:// URLs.
CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover
1 rule 3 TTPs 1 CVEA critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.
Multiple Vulnerabilities Discovered in Joomla! CMS
4 TTPs 5 CVEs 24 IOCsMultiple vulnerabilities, including several Cross-Site Scripting (XSS) flaws and incorrect access control issues, have been discovered in Joomla! versions 6.x prior to 6.1.2 and 5.x prior to 5.4.7, which could allow an attacker to bypass security policies, compromise data confidentiality and integrity, and perform remote indirect code injection.
CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability
1 rule 5 TTPs 1 CVEA stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.
CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE
3 TTPs 1 CVEAuthenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.
Critical OS Command Injection in 9Router (CVE-2026-59800)
1 rule 2 TTPs 1 CVEA critical OS command injection vulnerability (CVE-2026-59800) affects 9Router versions prior to 0.4.44, allowing unauthenticated remote attackers to execute arbitrary OS commands as root via a crafted POST request to the /api/tunnel/tailscale-install endpoint, leading to full system compromise with active exploitation observed.
XWiki Platform Old Core Path Traversal via /skin/ Endpoint (CVE-2026-34151)
1 rule 3 TTPs 2 IOCsAn attacker can exploit CVE-2026-34151, a path traversal vulnerability in XWiki Platform Old Core through the `/skin/` action endpoint when hosted on Jetty 12+. This allows unauthenticated users to craft URLs to access and download arbitrary files on the server, such as `/etc/passwd` or sensitive XWiki configuration files (e.g., `xwiki.cfg`), potentially leading to information disclosure and further system compromise.
EGroupware Authenticated RCE via Malicious eTemplate Upload (CVE-2026-40187)
1 rule 2 TTPs 3 IOCsAn authenticated EGroupware administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) containing unescaped backtick characters that lead to shell command execution within a PHP `eval()` call during template processing (CVE-2026-40187), impacting non-Docker or non-hardened EGroupware deployments.
EGroupware Critical RCE Vulnerability (CVE-2026-27823)
2 rules 4 TTPsA critical remote code execution vulnerability (CVE-2026-27823) in EGroupware allows an authenticated attacker, or an unauthenticated attacker if self-registration is enabled, to execute arbitrary commands on the server by combining an authorization bypass, arbitrary file write via path traversal, and arbitrary file read, leading to full system compromise.
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
1 TTP 1 CVE 1 IOCAn attacker with only a GitHub account can plant a malicious JavaScript payload in a GitHub issue title, leading to a DOM Cross-Site Scripting (XSS) vulnerability (CVE-2026-55790) that executes in a Craft CMS administrator's control panel session when they use the CraftSupport widget and retrieve the poisoned issue, allowing for arbitrary JavaScript execution and potential unauthorized actions.
Critical Unauthenticated API Vulnerabilities in 9Router Leading to Data Leak and RCE Risk
3 rules 5 TTPsMultiple critical unauthenticated API vulnerabilities in 9Router versions up to 0.4.41 allow an attacker to perform full CRUD operations on provider connections, leak plaintext API keys, and access sensitive conversation history, posing risks of data exfiltration and denial of service.
CVE-2026-59712: Leantime JSON-RPC API Authorization Bypass Leads to Credential Disclosure
3 TTPs 1 CVE 3 IOCsAn authenticated user can exploit CVE-2026-59712, an authorization bypass vulnerability in Leantime's JSON-RPC API `Users::getUser` method, to retrieve sensitive user credential information including password hashes, TOTP secrets, and session tokens for any user, leading to account enumeration, offline password cracking, 2FA bypass, and session hijacking.
Coder User-Admin Role Can Reset Owner Account Password (CVE-2026-55077)
1 TTPA critical vulnerability, CVE-2026-55077, in the Coder platform allowed a user with the `user-admin` role to reset the password of an `owner` account without needing the current password via the `PUT /api/v2/users/{user}/password` endpoint, leading to privilege escalation and full deployment control.
CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server
2 TTPs 1 IOCAn unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.
Formie Hidden Field SSTI Vulnerability (CVE-2026-52889)
1 rule 2 TTPsFormie Hidden fields in versions prior to 3.1.27 are vulnerable to Server-Side Template Injection (SSTI), allowing an unauthenticated attacker to inject Twig syntax into request-derived default values, potentially leading to remote code execution, sensitive information disclosure, or application state modification.
CVE-2026-14808 — Prog Management System Sensitive Information Exposure
2 TTPs 1 CVE 2 IOCsA critical vulnerability, CVE-2026-14808, in the Prog Management System developed by PROG MIS allows unauthenticated remote attackers to view a specific web page and obtain sensitive database account credentials, including the username and password, with high impact on confidentiality, integrity, and availability.
CVE-2026-14778: Improper Authorization in SourceCodester Onlne Examination & Learning Management System
1 CVEA high-severity improper authorization vulnerability (CVE-2026-14778) exists in SourceCodester Onlne Examination & Learning Management System version 1.0, allowing remote attackers to bypass authorization checks by manipulating the `student_id`, `schedule_id`, or `action` arguments in `/ajax_enroll.php`, potentially leading to unauthorized access or actions.
CVE-2026-14769 — SQL Injection in code-projects Real State Services 1.0
1 rule 3 TTPs 1 CVE 6 IOCsA critical security vulnerability, CVE-2026-14769, allows for remote SQL Injection in code-projects Real State Services 1.0 via the 'Bankname' argument in the '/pay.php' file, with a publicly disclosed exploit enabling information disclosure and potential data manipulation.
CVE-2026-14768: Remote SQL Injection in code-projects Real State Services 1.0
1 rule 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-14768) has been identified in code-projects Real State Services 1.0, allowing attackers to exploit the 'loc' argument in '/builderHome.php' for arbitrary SQL command execution, with a public exploit available.
CVE-2026-14764: SQL Injection in code-projects Hotel and Tourism Reservation
1 rule 3 TTPs 1 CVEAn unauthenticated attacker can remotely exploit CVE-2026-14764, an SQL injection vulnerability in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_event.php` component via the `fdetails` argument, to manipulate database queries and compromise sensitive data, with public exploit disclosure increasing the risk of active exploitation.
CVE-2026-14755: Remote SQL Injection in code-projects Hotel and Tourism Reservation
1 rule 2 TTPs 1 CVE 2 IOCsA critical remote unauthenticated SQL injection vulnerability (CVE-2026-14755) in code-projects Hotel and Tourism Reservation version 1.0, specifically within the '/admin/reservations.php' file's 'delete' argument, allows attackers to manipulate backend database queries, leading to data exposure and manipulation with a publicly disclosed exploit.
CVE-2026-14749: mjperpinosa stumasy Code Injection Vulnerability
1 rule 2 TTPs 1 CVEA code injection vulnerability (CVE-2026-14749) was identified in mjperpinosa stumasy, affecting versions up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, which allows remote attackers to execute arbitrary code by manipulating the 'mathematical_sentence' argument in the 'eval' function of 'application/pages/imba_calculator/calculate.php', with a public exploit available and no vendor response.
CVE-2026-14746: SQL Injection in code-projects Real State Services
1 rule 1 TTP 1 CVEA high-severity SQL injection vulnerability (CVE-2026-14746) exists in code-projects Real State Services 1.0, specifically in the `/addprojectrent.php` file, where the `amen` argument can be manipulated to execute arbitrary SQL commands, enabling remote attackers to achieve unauthorized data access or modification, with public exploit disclosure increasing the risk of active exploitation.
CVE-2026-14745: SQL Injection in code-projects Real State Services
1 rule 3 TTPs 1 CVEA critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.
CVE-2026-14713 — SQL Injection in SourceCodester Pizzafy E-Commerce System
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14713) exists in SourceCodester Pizzafy E-Commerce System version 1.0, allowing unauthenticated remote attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the `/admin/ajax.php?action=confirm_order` endpoint, potentially leading to data exfiltration or modification, with a public exploit available.
CVE-2026-14695: SourceCodester Multi-Vendor Online Grocery Management System SQL Injection
1 TTP 1 CVEA high-severity SQL injection vulnerability, CVE-2026-14695, exists in SourceCodester Multi-Vendor Online Grocery Management System 1.0, allowing remote attackers to manipulate the 'Name' argument within the `save_client` function of `classes/Users.php` to execute arbitrary SQL commands, with a public exploit available.
CVE-2026-14688: Remote SQL Injection in itsourcecode Online Hotel Management System
1 rule 1 TTP 1 CVE 3 IOCsA high-severity SQL injection vulnerability, CVE-2026-14688, exists in itsourcecode Online Hotel Management System 1.0 within the `/admin/login.php` file via the `email` argument, allowing remote unauthenticated attackers to bypass authentication and potentially exfiltrate data, with a publicly available exploit.
CVE-2026-14654: Remote SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 1 TTP 1 CVE 7 IOCsA remote, unauthenticated SQL injection vulnerability (CVE-2026-14654) in SourceCodester Simple and Nice Shopping Cart Script 1.0 allows attackers to manipulate the `user_id` argument via `/admin/girlsproductdeletequery.php`, leading to database compromise, data exfiltration, or unauthorized access, with an exploit publicly available.
CVE-2026-14652: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14652) exists in the Admin Login component of SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing an unauthenticated attacker to remotely exploit it by manipulating the 'Username' argument in the /admin/login.php file, potentially leading to unauthorized access, information disclosure, or data manipulation, with a public exploit available.
CVE-2026-14637: Critical Deserialization Vulnerability in kirilkirkov Ecommerce-CodeIgniter-Bootstrap
2 TTPs 1 CVEA high-severity deserialization vulnerability, CVE-2026-14637, exists in the `getCartItems` function of `application/libraries/ShoppingCart.php` in kirilkirkov Ecommerce-CodeIgniter-Bootstrap versions up to commit `13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7`, allowing remote attackers to achieve arbitrary code execution by manipulating the `shopping_cart` argument, with public exploit disclosure raising immediate risk.
CVE-2026-14622 — Jairiidriss restaurant-website-php-mysql Authentication Bypass
1 rule 1 TTP 1 CVEA high-severity authentication bypass vulnerability (CVE-2026-14622) exists in the jairiidriss restaurant-website-php-mysql web application's AJAX Endpoint, specifically affecting the /admin/ajax_files component, allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionalities, with public exploit code increasing immediate risk.
Incomplete Fix for CVE-2026-25754 in @adonisjs/bodyparser Leads to CVE-2026-48795
3 TTPs 1 CVEAn incomplete fix for CVE-2026-25754 in the `@adonisjs/bodyparser` package, tracked as CVE-2026-48795, allows remote unauthenticated attackers to bypass security measures via nested prototype pollution payloads in `multipart/form-data` requests, potentially leading to authorization bypasses or remote code execution.
GeoNetwork Reflected XSS through Client-Side Template Injection (CVE-2026-39379)
1 rule 4 TTPsA reflected Cross-Site Scripting (XSS) vulnerability, CVE-2026-39379, exists in GeoNetwork due to client-side template injection within error pages, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript to execute in their browser in the context of their authenticated session.
GeoNetwork ACL Bypass in Elasticsearch Search (CVE-2026-46487)
3 TTPsA high-severity authorization bypass vulnerability, CVE-2026-46487, in GeoNetwork's Elasticsearch-backed search API allows unauthenticated attackers to retrieve restricted metadata records by bypassing access control and visibility filters when the request body omits the 'query' field, leading to sensitive information disclosure.
MediaWiki Maps Stored XSS via display_map `overlays` Parameter (CVE-2026-52854)
1 rule 2 TTPsA high-severity stored cross-site scripting (XSS) vulnerability, CVE-2026-52854, exists in the MediaWiki Maps extension (versions prior to 12.1.3), allowing any authenticated user with edit permissions to inject malicious JavaScript into the `overlays` parameter of the `display_map` parser function, leading to arbitrary client-side code execution in a victim's browser.
Unauthenticated SQL Execution Vulnerability in Recce OSS Server (CVE-2026-49360)
1 rule 3 TTPsRecce OSS server deployments are vulnerable to unauthenticated SQL execution via the query run API when configured with a DuckDB-backed project, allowing attackers to use DuckDB filesystem primitives to read and write arbitrary files accessible to the server process, potentially leading to data disclosure, tampering, or stored XSS.
OpenAM Pre-Authentication Reflected XSS via OAuth2/OIDC state parameter (CVE-2026-44203)
1 rule 2 TTPsA critical pre-authentication reflected Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-44203, in OpenIdentityPlatform OpenAM's `openam-oauth2` component allows an unauthenticated attacker to inject malicious scripts into a victim's browser context by manipulating the `state` parameter in OAuth2/OIDC `form_post` responses, leading to session hijacking or credential theft.
Budibase Arbitrary File Read Vulnerability via PWA-zip Symlink Upload (CVE-2026-54352)
4 TTPs 1 CVE 3 IOCsA critical vulnerability, CVE-2026-54352, in Budibase server allows an authenticated workspace builder to perform arbitrary file reads on the host system by uploading a crafted PWA zip file containing a symbolic link, leading to credential compromise and privilege escalation, potentially enabling a full global administrator takeover.
i18next-http-middleware Prototype Pollution via missingKeyHandler (CVE-2026-48714)
1 rule 2 TTPs 1 CVEA critical prototype pollution vulnerability (CVE-2026-48714) exists in `i18next-http-middleware` versions up to 3.9.6, where the `missingKeyHandler` fails to adequately sanitize dotted key segments, allowing attackers to manipulate `Object.prototype` when exposed to untrusted input and used with vulnerable `i18next-fs-backend` versions up to 2.6.5, potentially leading to configuration poisoning, security bypasses, crashes, or remote code execution.
CVE-2024-58351: Flowise Remote Code Execution via Configuration Injection
2 rules 7 TTPsFlowise versions before 2.1.4 are critically vulnerable to configuration injection (CVE-2024-58351) via the `overrideConfig` option in both its frontend web integration and backend Prediction API, which, due to a bypassable `vm2` sandbox, allows attackers to achieve remote code execution, sandbox escape, denial of service, server-side request forgery, prompt injection, and server variable/data exfiltration.
Faraday: Uncontrolled Recursion in NestedParamsEncoder Allows Stack Exhaustion DoS
2 rules 1 TTPAn unauthenticated attacker can trigger a denial-of-service condition in applications using the Faraday Ruby library by sending deeply nested query parameters (CVE-2026-54297), leading to `SystemStackError` and application crashes due to uncontrolled recursion.
JupyterLab Git Extension Stored XSS to RCE (CVE-2026-54527)
2 rules 6 TTPsA stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-54527, in the `jupyterlab-git` JupyterLab extension (versions >= 0.30.0b3, < 0.54.0a1), specifically in `PlainTextDiff.ts`, allows an adversary with Git commit access to execute arbitrary JavaScript in a victim's browser and achieve Remote Code Execution (RCE) on the JupyterLab server by crafting a malicious filename in a Git commit that, when viewed as a rename diff, triggers the XSS payload to steal `_xsrf` cookies, open a terminal, and execute arbitrary shell commands to exfiltrate data.
JupyterLab-Git excluded_paths Case-Sensitivity Bypass (CVE-2026-54528)
2 rules 4 TTPsAn authenticated user can bypass the admin-configured `excluded_paths` security control in `jupyterlab-git` versions up to 0.53.0 by exploiting a case-sensitivity flaw on case-insensitive filesystems (e.g., macOS APFS, Windows NTFS), allowing unauthorized read access to git history and file content in explicitly excluded directories.
Joomla com_booking Information Disclosure (CVE-2023-54357)
1 rule 2 TTPsAn unauthenticated information disclosure vulnerability (CVE-2023-54357) in the Joomla com_booking component version 2.4.9 allows attackers to enumerate user accounts, including names, usernames, and email addresses, by exploiting the getUserData function via specific GET requests.
AlchemyCMS: Unauthenticated Nested Page API Leaks Restricted & Unpublished Content
2 rulesAn unauthenticated API endpoint, `GET /api/pages/nested`, in Alchemy CMS versions up to 8.2.5 (including all 8.x versions prior to a fix and all 7.x versions up to 7.4.14), fails to enforce authorization and scoping checks, allowing any anonymous user to retrieve the complete page tree, encompassing restricted and unpublished pages, and, with `?elements=true`, the full content of these sensitive pages, completely bypassing intended access controls and leading to unauthorized information disclosure.
Joomla! Calendar Planner 1.0.1 SQL Injection (CVE-2017-20267)
1 rule 1 TTPAn unauthenticated attacker can exploit CVE-2017-20267, an SQL injection vulnerability in Joomla! Component Calendar Planner 1.0.1, by sending malicious GET requests to the 'events' view via the 'category_id' parameter, allowing for sensitive database information extraction.
Joomla! Component Flip Wall SQL Injection (CVE-2017-20265)
2 rules 3 TTPsAn SQL injection vulnerability, CVE-2017-20265, in Joomla! Component Flip Wall 8.0 allows unauthenticated attackers to execute arbitrary SQL queries via malicious GET requests to the `wallid` parameter, enabling the extraction of sensitive database information.
Joomla! FocalPoint Pro/Free SQL Injection (CVE-2017-20263)
1 rule 3 TTPs 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2017-20263) in Joomla! Component FocalPoint Pro/Free version 1.2.3 allows attackers to execute arbitrary SQL queries via a crafted 'id' parameter in GET requests, leading to sensitive database information disclosure.
CVE-2017-20262 — Joomla! Component Ajax Quiz SQL Injection
1 rule 3 TTPsAn unauthenticated SQL injection vulnerability, CVE-2017-20262, in Joomla! Component Ajax Quiz version 1.8 allows attackers to execute arbitrary SQL queries by injecting malicious code through the `cid` parameter in GET requests to `index.php` with `option=com_ajaxquiz` and `view=ajaxquiz`, leading to extraction of sensitive database information.
Joomla OSDownloads SQL Injection (CVE-2017-20259)
2 rules 3 TTPs 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2017-20259) in Joomla OSDownloads version 1.7.4 allows attackers to execute arbitrary SQL queries via a crafted GET request to index.php, extracting sensitive database information like credentials and configuration data.
Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection (CVE-2017-20258)
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit an SQL injection vulnerability (CVE-2017-20258) in Joomla! Component RPC Responsive Portfolio 1.6.1 by injecting malicious code through the 'id' parameter in GET requests, allowing the execution of arbitrary SQL queries and extraction of sensitive database information.
Joomla! Component JB Visa 1.0 SQL Injection (CVE-2017-20255)
2 rules 2 TTPsAn unauthenticated SQL injection vulnerability (CVE-2017-20255) in Joomla! Component JB Visa 1.0 allows attackers to execute arbitrary SQL queries by injecting malicious code via the 'visatype' parameter in GET requests to 'index.php?option=com_bookpro&view=popup', leading to the extraction of sensitive database information including credentials.
Joomla! User Bench Component SQL Injection (CVE-2017-20254)
1 rule 3 TTPsAn unauthenticated attacker can exploit CVE-2017-20254, an SQL injection vulnerability in the Joomla! Component User Bench 1.0, by sending crafted HTTP GET requests to extract sensitive database information including credentials and configuration data.
CVE-2017-20252: Joomla NextGen Editor SQL Injection
2 rules 4 TTPsJoomla NextGen Editor 2.1.0 contains an SQL injection vulnerability (CVE-2017-20252) that allows unauthenticated attackers to execute arbitrary SQL commands through the `plname` parameter in crafted GET requests to `index.php?option=com_nge&view=config`, leading to the extraction of sensitive database information.
Tilt: Cross-site WebSocket Hijacking Vulnerability (CVE-2026-55883)
3 rules 3 TTPsAn attacker can exploit CVE-2026-55883, a Cross-site WebSocket Hijacking vulnerability in Tilt versions 0.24.0 through 0.37.3, by acquiring an unauthenticated CSRF token or bypassing Origin header checks, to establish a WebSocket connection to a network-exposed Tilt HUD and exfiltrate sensitive developer session state, Tiltfile contents, and resource statuses.
gemini-mcp-tool Vulnerable to OS Command Injection and File Exfiltration (CVE-2026-0755)
2 rules 3 TTPsA critical vulnerability, CVE-2026-0755, in npm's gemini-mcp-tool package allows for OS command injection on Windows systems due to improper handling of unquoted cmd.exe metacharacters, and arbitrary local file exfiltration via the @file parser when processing untrusted prompt input, leading to potential remote code execution and sensitive data compromise.
Crawl4AI Unauthenticated RCE via Chromium Launch-Argument Injection
3 rules 2 TTPsAn attacker can achieve unauthenticated remote code execution (RCE) in Crawl4AI Docker deployments by injecting malicious Chromium launch arguments, such as `--utility-cmd-prefix` and `--no-zygote`, into the `browser_config.extra_args` field of the API request, allowing for arbitrary command execution as the container's runtime user.
Kirby: Self cross-site scripting (self-XSS) in the writer field (CVE-2026-49276)
2 rules 3 TTPsKirby CMS versions prior to 4.9.4 and between 5.0.0-alpha.1 and 5.4.3 are vulnerable to a self-cross-site scripting (self-XSS) flaw, CVE-2026-49276, in the writer field, allowing an attacker to inject malicious JavaScript as the target of a link or email link which, if clicked by an authenticated user before saving, will execute in their browser context, potentially making API requests with their permissions, while Panel plugins using the `<k-writer>` component may be vulnerable to stored XSS if they don't sanitize HTML.
Jupyter Server Stored XSS via Missing CSP Sandbox (CVE-2026-44727)
2 rules 4 TTPsA critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-44727, exists in `jupyter_server` versions up to 2.19.0 due to a missing `sandbox` directive in Content-Security-Policy (CSP) headers, allowing authenticated attackers to craft malicious notebooks that exfiltrate victim tokens and achieve kernel Remote Code Execution (RCE) when viewed.
Critical Kirby CMS Vulnerability Allows Remote Admin Account Creation via Reverse Proxy Headers (CVE-2026-54003)
2 rules 2 TTPsA critical external initialization vulnerability (CVE-2026-54003) in Kirby CMS allows unauthenticated attackers to create an initial admin account on sites running behind a reverse proxy, specifically when the proxy utilizes `Forwarded: for=...`, `X-Client-IP`, or `X-Real-IP` headers, bypassing Kirby's `isLocal` check and enabling remote Panel installation with full administrative access.
PraisonAI Authentication Bypass via PRAISONAI_CALL_AUTH=disabled
2 rules 7 TTPsA high-severity authentication bypass vulnerability in PraisonAI versions prior to 4.6.61 allows unauthenticated attackers to invoke any registered agent by setting the `PRAISONAI_CALL_AUTH=disabled` environment variable, potentially leading to arbitrary code execution or system compromise.
CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability
2 rules 1 TTP 5 CVEs 2 IOCsAn injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.
CVE-2026-49952: Discuz! X5.0 Authentication Bypass Leading to Database Access
2 rules 6 TTPs 1 CVE 1 IOCCVE-2026-49952 is an authentication bypass vulnerability in Discuz! X5.0 versions 20260320 through 20260501, allowing unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key, leading to potential data exfiltration and user impersonation.
Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)
2 rules 1 TTP 1 CVE 3 IOCsA high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.
CVE-2026-53787: Unauthenticated Arbitrary File Upload in Amasty Order Attributes for Magento 2
2 rules 4 TTPs 1 CVE 1 IOCAn unauthenticated arbitrary file upload vulnerability in Amasty Order Attributes for Magento 2 (versions before 4.0.0) allows attackers to upload files of any type to the store's media directory, which can lead to remote code execution (RCE) on misconfigured servers by uploading PHP files, enable malware hosting, facilitate stored cross-site scripting (XSS) via HTML/SVG uploads, or achieve path traversal to write files outside the intended directory.
Multiple Vulnerabilities in Typo3 Leading to RCE, Privilege Escalation, and Data Compromise
3 rules 6 TTPs 5 CVEs 20 IOCsMultiple vulnerabilities discovered in Typo3 allow an attacker to achieve remote arbitrary code execution, privilege escalation, data confidentiality compromise, data integrity compromise, security policy bypass, remote indirect code injection (XSS), and SQL injection (SQLi).
Path Traversal Vulnerability in WilliamCloudQi matlab-mcp-server
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in WilliamCloudQi matlab-mcp-server up to version ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca, allowing a remote attacker to manipulate the scriptPath argument in the generate_matlab_code/execute_matlab_code function to access arbitrary files.