Tag
Flowise Unauthenticated RCE via Environment Variable Bypass
6 rules 11 TTPs 2 CVEsFlowise v3.1.2 and earlier are vulnerable to unauthenticated remote code execution because the CVE-2025-8943 patch relies on an incomplete environment variable blocklist, allowing attackers to inject configuration variables that force arbitrary package installation.
SQL Injection in Sequelize Oracle Dialect
1 TTPSequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.
Cross-Site Scripting Vulnerability in Angular Server-Side Rendering
1 TTP 1 CVEA Cross-Site Scripting (XSS) vulnerability in @angular/platform-server (CVE-2026-69149) allows script injection via improper serialization of fallback raw-content elements during server-side rendering.
SQL Injection in SiYuan fullTextSearchAssetContent Endpoint
3 rules 2 TTPs 1 CVESiYuan versions before 3.7.3 contain a critical SQL injection vulnerability in the fullTextSearchAssetContent endpoint, allowing unauthenticated attackers to execute arbitrary SQL commands on the backend asset-content database.
Authorization Bypass in @better-auth/stripe
1 CVEAn authorization bypass vulnerability in @better-auth/stripe allows authenticated users to perform unauthorized subscription actions and access billing data of other organizations via ID parameter confusion.
Remote Code Execution in Kali Forms WordPress Plugin
1 rule 2 TTPs 1 CVEUnauthenticated attackers can achieve remote code execution in Kali Forms versions up to 2.4.20 by exploiting insufficient validation of the thisPermalink field within the _save_data function.
Unauthenticated Remote Execution in dynatrace-mcp-server HTTP Transport
1 ruleThe dynatrace-mcp-server package v1.8.5 contains a critical authentication bypass vulnerability in its HTTP transport mode that allows unauthenticated, network-reachable attackers to invoke sensitive Model Context Protocol tools.
Leantime Authenticated LFI and SSRF via Blueprints
1 TTP 1 CVELeantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.
Authentication Bypass in FTC E-Commerce Management Panel
1 CVEA missing authentication vulnerability in FTC E-Commerce Management Panel versions prior to 1.0.2 allows unauthenticated remote attackers to bypass security controls and gain unauthorized access.
Reflected XSS in IBM Tivoli System Automation and WebSphere Application Server
1 rule 1 CVEIBM Tivoli System Automation Application Manager 4.1 and WebSphere Application Server are affected by a reflected cross-site scripting vulnerability in the administrative console login page that allows unauthenticated attackers to execute arbitrary JavaScript.
BuddyPress Insecure Deserialization Vulnerability
1 TTPAn insecure deserialization vulnerability in the BuddyPress WordPress plugin allows authenticated attackers to inject arbitrary PHP objects, potentially leading to remote code execution.
Multiple Vulnerabilities in Apache Traffic Server
2 TTPsMultiple vulnerabilities in Apache Traffic Server can be exploited by a remote, anonymous attacker to bypass security measures, disclose or manipulate data, trigger a denial-of-service, and potentially achieve code execution.
CVE-2026-16597 - GTM4WP WordPress Plugin Vulnerable to Stored XSS via WooCommerce Billing Fields
1 rule 1 TTP 1 CVEThe GTM4WP (Google Tag Manager) plugin for WordPress, in versions up to and including 1.22.3, is vulnerable to stored cross-site scripting (XSS) via CVE-2026-16597, allowing unauthenticated attackers to inject arbitrary web scripts through WooCommerce billing fields during a guest checkout, which execute when a user accesses the compromised page.
Authentication Bypass in Advanced Responsive Video Embedder WordPress Plugin
1 rule 3 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.
WordPress Wholesale for WooCommerce Plugin Privilege Escalation (CVE-2026-12144)
1 TTP 1 CVEThe Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation due to insufficient validation and capability checks in `save_requests_meta()` function, allowing authenticated attackers with author-level access or higher to escalate their privileges to administrator by supplying 'administrator' as the `user_role_set` value in a crafted request.
IBM WebSphere Application Server Authentication Bypass Vulnerability (CVE-2026-16184)
5 TTPs 7 CVEs 5 IOCsA remote attacker can bypass authentication in IBM WebSphere Application Server versions 9.0 and 8.5 by sending a crafted unauthenticated request, potentially leading to unauthorized access and impact on confidentiality, integrity, and availability.
WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)
1 rule 1 TTP 1 CVEThe WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.
Null Pointer Dereference Vulnerability in TinyWeb
1 TTP 1 CVEA null pointer dereference vulnerability, CVE-2026-67184, in TinyWeb through version 0.0.8 allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string, leading to a denial of service.
Poweradmin Vulnerable to Host Header Injection in Authentication Redirects
3 TTPs 1 CVE 1 IOCPoweradmin versions earlier than 4.2.4 and from 4.3.0 up to, but not including, 4.3.3 are vulnerable to CVE-2026-54588, a critical Host Header Injection flaw in OIDC, SAML, and logout authentication flows that allows an unauthenticated attacker to manipulate the HTTP_HOST header, poisoning callback URLs to redirect authorization codes to an attacker-controlled server, leading to full account takeover and potential full DNS zone control.
Rouille HTTP Server Framework Vulnerable to Request Smuggling (CVE-2026-67181)
1 rule 1 TTP 1 CVERouille HTTP server framework versions 0.3.3 through 3.6.2 are vulnerable to an HTTP request smuggling attack, CVE-2026-67181, allowing remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation, leading to potential bypassing of security controls or unauthorized access.
TrueBooker WordPress Plugin SQL Injection Vulnerability (CVE-2026-13161)
1 rule 2 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-13161, a generic SQL Injection vulnerability in the TrueBooker - Appointment Booking and Scheduler System plugin for WordPress affecting versions up to and including 1.2.2, by manipulating the 'alldata[truebooker_user]' parameter in POST requests, allowing the extraction of sensitive database information.
CVE-2026-12741: Unauthenticated SQL Injection in WP Fast Total Search WordPress Plugin
1 rule 2 TTPs 1 CVEAn SQL injection vulnerability (CVE-2026-12741) exists in the WP Fast Total Search - The Power of Indexed Search plugin for WordPress, affecting all versions up to and including 1.80.280. The flaw, located in the 'form_data[s]' parameter, is due to insufficient input escaping and poor SQL query preparation, allowing unauthenticated attackers to inject malicious SQL queries and extract sensitive information from the underlying database.
Arbitrary File Deletion Vulnerability in WordPress Better Messages Plugin
1 rule 2 TTPs 1 CVEA path traversal vulnerability, CVE-2026-16585, in the Better Messages - Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress allows authenticated administrators to delete arbitrary files on the server by bypassing file path validation, potentially leading to remote code execution.
The Demi WordPress Plugin Vulnerable to Arbitrary Directory Deletion (CVE-2026-14490)
2 TTPs 1 CVEUnauthenticated attackers can exploit CVE-2026-14490 in The Demi - One Click Demo Import, WP Backup & Site Migration WordPress plugin (versions up to and including 0.0.7) to achieve arbitrary directory deletion by retrieving a publicly exposed HMAC signing key and forging valid requests to a vulnerable AJAX handler.
Denial-of-Service Vulnerability in facil.io HTTP/1.1 Chunked Transfer Encoding Parser (CVE-2026-66731)
1 TTP 1 CVEAn unauthenticated remote denial-of-service vulnerability exists in facil.io versions 0.7.5 through 0.7.6, allowing attackers to crash the server by sending a POST request with a 'Transfer-Encoding: chunked' header containing a negative chunk size value, which corrupts internal state and leads to a fault.
Critical Eval Injection Vulnerability in vBulletin Allows Remote Code Execution (CVE-2026-61511)
1 rule 2 TTPs 3 CVEs 4 IOCsAn eval injection vulnerability, identified as CVE-2026-61511, exists in vBulletin versions 5.x through 5.7.5 and 6.x through 6.2.1, specifically within the vB5_Template_Runtime::runMaths() method, allowing unauthenticated remote attackers to achieve arbitrary PHP code execution by manipulating the pagenav[pagenumber] parameter through the unauthenticated ajax/render template route with phpfuck-style encoding.
WPForms Pro Plugin Arbitrary File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 IOCThe WPForms Pro plugin for WordPress, in versions up to and including 1.10.1.1, is vulnerable to arbitrary file upload via the ajax_chunk_upload_finalize function, allowing unauthenticated attackers to upload executable files due to improper file type validation occurring after file contents are written to disk, which can lead to remote code execution on the affected server.
Multiple High-Severity Vulnerabilities in OmniFaces Library
6 TTPs 1 CVEMultiple vulnerabilities in OmniFaces versions prior to 1.14.3, 2.7.33, 3.14.23, 4.7.12, and 5.4.2 allow attackers to exploit forged combined-resource IDs leading to server-side request forgery (SSRF)-like behavior or information disclosure, achieve client-side arbitrary code execution via cross-site scripting (XSS) in `o:hashParam`, bypass session authentication for push channels resulting in unauthorized message interception, and cause denial-of-service (DoS) via unbounded caches.
Budibase Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
3 TTPs 4 IOCsAn unauthenticated attacker can steal REST datasource credentials, including Bearer/Basic tokens and static headers, from Budibase applications due to a critical cross-origin authentication leak (GHSA-mqhr-6j6h-74p5) where the application attaches stored credentials to outgoing requests without validating the destination host, allowing exfiltration to an attacker-controlled server.
Budibase MongoDB Datasource Vulnerability Allows Server Filesystem Existence/Read Oracle
2 rules 6 TTPs 2 IOCsA vulnerability in Budibase's MongoDB datasource configuration allows authenticated attackers to specify arbitrary absolute server-side file paths for `tlsCertificateKeyFile` and `tlsCAFile`, enabling the `/api/datasources/verify` endpoint to act as an arbitrary-path existence/read oracle on the underlying multi-tenant server, distinguishing between existing and non-existing files and potentially exfiltrating certificate content.
SQL Injection Vulnerability in Budibase MySQL Integration
1 rule 7 TTPsA critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.
Cloudreve OAuth Admin.Read Scope Bypass for OneDrive Storage Policy Credential Update (CVE-2026-55502)
1 rule 1 TTPAn authorization bypass vulnerability (CVE-2026-55502) in Cloudreve 4.16.1 allows an attacker with an `Admin.Read` OAuth token to modify the OneDrive storage policy credentials via a POST request to `/api/v4/admin/policy/oauth/signin`, despite lacking `Admin.Write` scope, which can break the storage backend and redirect future OAuth setups.
Open WebUI: Cross-User Code-Interpreter and Tool Execution via Unvalidated Socket.IO Session ID
1 rule 3 TTPs 1 CVEAn authenticated low-privilege user can exploit CVE-2026-59216 in Open WebUI versions prior to 0.10.0 to execute arbitrary Python code or tools within another user's authenticated session by supplying an unvalidated `session_id`, which, if targeting an administrator, leads to remote code execution on the server as the root process.
Fastify/static Vulnerable to Route Guard Bypass via Path Traversal
1 rule 3 TTPs 1 CVEThe @fastify/static package is vulnerable to a route guard bypass via path traversal using non-leading '..' or '%2E%2E' path segments, allowing attackers to circumvent route-based middleware and access protected files that are served by the static plugin.
React Router Denial of Service via Inefficient Route Matching (CVE-2026-55685)
1 TTPAn unauthenticated attacker can exploit CVE-2026-55685 in React Router versions 7.0.0 through 7.17.x, when used in Framework Mode applications, to cause a denial-of-service condition by repeatedly accessing the manifest endpoint, leading to heavy server load and slow response times.
VikBooking Hotel Booking Engine & PMS Plugin Vulnerable to Stored Cross-Site Scripting (CVE-2026-15401)
1 rule 2 TTPs 1 CVEThe VikBooking Hotel Booking Engine & PMS plugin for WordPress versions up to and including 1.8.13 is vulnerable to Stored Cross-Site Scripting (XSS) via the 'vbfX' parameter, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an infected page.
Wpify Woo Plugin Privilege Escalation Vulnerability (CVE-2026-12736)
1 rule 2 TTPs 1 CVEA privilege escalation vulnerability (CVE-2026-12736) in the Wpify Woo plugin for WordPress, affecting versions up to and including 5.4.16, allows authenticated attackers with 'Shop Manager' capabilities or higher to gain Administrator privileges by exploiting a REST route that overwrites arbitrary WordPress options.
Microweber CMS Path Traversal Vulnerability (CVE-2026-65694)
1 rule 2 TTPs 1 CVE 2 IOCsAn unauthenticated path traversal vulnerability (CVE-2026-65694) in the static file controller of Microweber CMS, affecting versions through 2.0.20, allows remote attackers to read arbitrary files by supplying directory traversal sequences in the 'path' query parameter via a single unauthenticated HTTP GET request, potentially disclosing sensitive information like environment configuration files containing credentials or system files.
Cal.com Stored Cross-Site Scripting Vulnerability (CVE-2024-58355)
1 TTP 1 CVEA stored cross-site scripting (XSS) vulnerability, CVE-2024-58355, affects Cal.com (calcom/cal.diy) versions through 4.7.15, allowing an attacker to inject arbitrary HTML/JavaScript into a booking-question label that executes in a victim's browser when they view a crafted booking URL, potentially leading to session hijacking, data theft, or defacement.
CVE-2024-58353: Cal.com Cross-Site Scripting Vulnerability
1 TTP 1 CVECVE-2024-58353 describes a cross-site scripting (XSS) vulnerability in Cal.com (repository calcom/cal.diy) versions up to and including 4.7.15, where an attacker can inject malicious HTML/JavaScript into booking question labels that is then executed via React's dangerouslySetInnerHTML when a victim visits a publicly accessible single booking view, allowing for arbitrary client-side code execution, particularly impacting self-hosted instances with open registration.
WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)
2 TTPs 1 CVE 2 IOCsA critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.
h2oGPT Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2026-65700)
1 rule 3 TTPs 1 CVEh2oGPT through version 0.2.1 contains a critical path traversal vulnerability (CVE-2026-65700) in its OpenAI-compatible files API, allowing unauthenticated remote attackers to achieve arbitrary file read, write, and delete, and ultimately remote code execution, by injecting traversal sequences into the bearer token.
CVE-2026-65919 Unauthenticated Arbitrary File Read in Meshery
1 rule 1 TTP 1 CVEMeshery versions prior to 1.0.57 are vulnerable to an unauthenticated arbitrary file read due to a path traversal flaw in the /api/system/fileView and /api/system/fileDownload API endpoints, allowing attackers to read arbitrary files from the host filesystem without authentication by supplying path traversal sequences.
CyberPanel Missing Authorization Vulnerability Allows Cross-Tenant Backup Manipulation
1 rule 2 TTPs 1 CVEA missing authorization vulnerability, identified as CVE-2026-65916, in CyberPanel through version 1.9.1 allows authenticated users to manipulate and destroy other tenants' backups by sending crafted POST requests to the `cancelBackupCreation` handler.
Auth.js Email Normalizer Vulnerability Allows Homoglyph Bypass Leading to Account Takeover
2 TTPsA critical vulnerability in Auth.js libraries (next-auth and @auth/core) affects the email/magic-link sign-in flow, allowing an attacker to craft an email address with a homoglyph character that bypasses validation before Unicode normalization, leading to magic links being misrouted to attacker-controlled mailboxes and enabling account takeover without victim interaction.
CVE-2026-65898: DOMPurify Vulnerability Leads to Stored Cross-Site Scripting
2 TTPs 1 CVE 2 IOCsA vulnerability in DOMPurify before version 3.4.11 allows attackers to achieve stored Cross-Site Scripting (XSS) by manipulating the `ALLOWED_ATTR` allowlist through an `uponSanitizeAttribute` hook, leading to client-side code execution.
Bold Reports Standalone Report Designer Path Traversal Vulnerability (CVE-2026-65687)
1 rule 2 TTPs 2 CVEsCVE-2026-65687 describes a path traversal vulnerability in Bold Reports Standalone Report Designer prior to version 14.1.12, allowing an unauthenticated attacker to read arbitrary files from the server filesystem by exploiting a missing filepath validation flaw in the SVG processing feature, potentially leading to full unauthorized access via disclosure of sensitive server files like authentication credentials.
CVE-2026-9713: Lumise Product Designer for WooCommerce Plugin SQL Injection
1 rule 2 TTPs 1 CVEThe Lumise Product Designer for WooCommerce plugin for WordPress, in versions up to and including 2.1.1, is vulnerable to SQL Injection via the 'id' and 'table' parameters within an uploaded cart JSON file processed by the checkout AJAX action, allowing unauthenticated attackers to extract sensitive database information.
SUMO Reward Points WordPress Plugin Vulnerable to Unauthenticated Stored XSS via REST API (CVE-2026-7534)
1 rule 2 TTPs 1 CVEThe SUMO Reward Points plugin for WordPress, versions up to and including 32.7.0, is vulnerable to CVE-2026-7534, an Unauthenticated Stored Cross-Site Scripting flaw that allows attackers to inject arbitrary web scripts into the reward points log via the `/wp-json/wc-srp/v1/earning` REST API endpoint, executing when an administrator accesses specific admin pages.
Next.js App Router Middleware/Proxy Bypass Vulnerability (CVE-2026-64642)
2 TTPsA high-severity vulnerability, CVE-2026-64642, in Next.js App Router applications built with Turbopack and configured with a single locale entry allows attackers to bypass middleware and proxy-based authentication mechanisms through specially crafted HTTP requests, leading to unauthorized access to protected resources.
Next.js Server-Side Request Forgery and Open Redirect Vulnerability (CVE-2026-64645)
2 rules 3 TTPsA vulnerability (CVE-2026-64645) in Next.js allows Server-Side Request Forgery (SSRF) and Open Redirect when `rewrites()` or `redirects()` rules in `next.config.js` use attacker-controlled input to construct external destination hostnames, enabling attackers to manipulate dynamic segments from the path or `has` captures to point the rewrite to an arbitrary hostname, potentially leading to internal network access, information disclosure, or redirection of users to malicious sites, affecting Next.js versions from 12.0.0 up to, but not including, 15.5.21, and versions from 16.0.0 up to, but not including, 16.2.11.
Eclipse Jetty Digest Authentication Bypass via ISO-8859-1 Encoding Flaw (CVE-2026-10050)
1 TTPA vulnerability, CVE-2026-10050, in Eclipse Jetty's HTTP client `DigestAuthentication.apply()` method allows an authentication bypass by an attacker who can exploit the lossy ISO-8859-1 character encoding to forge Digest authentication response hashes for users with non-Latin-1 passwords.
LiteLLM MCP Authentication Bypass via OAuth2 Passthrough Fallback
1 TTP 1 CVEAn authentication bypass vulnerability (CVE-2026-59822) exists in LiteLLM's MCP Streamable HTTP endpoint, affecting versions prior to 1.84.0, allowing an unauthenticated attacker to exploit a fallback path that replaces failed key validation with an empty authentication object, leading to the establishment of an authenticated MCP session using arbitrary Bearer tokens, enabling access to configured MCP tools and connected services.
Grav Login Plugin Privilege Escalation (CVE-2026-65603)
2 TTPs 1 CVEA critical privilege escalation vulnerability, CVE-2026-65603, exists in the Grav Login plugin (grav-plugin-login) versions up to and including 3.8.11, allowing an authenticated low-privilege user to exploit a flaw in the `processUserProfile()` handler to bypass privilege stripping and escalate to super-admin, enabling admin panel access, remote code execution, and Twig evaluation.
CVE-2026-65057 Server-Side Request Forgery in Keep Healthcheck Endpoint
1 rule 2 TTPs 1 CVEAn unauthenticated server-side request forgery (SSRF) vulnerability in Keep (commit 91c75e0) allows attackers to exploit an unprotected healthcheck endpoint by supplying crafted JSON payloads with malicious host values, forcing the backend to issue arbitrary HTTP requests to internal services or cloud metadata endpoints for internal network reconnaissance and theft of cloud credentials.
Gitea Server-Side Request Forgery Vulnerabilities
1 rule 3 TTPs 1 IOCTwo Server-Side Request Forgery (SSRF) vulnerabilities in Gitea version 1.26.2 and earlier allow authenticated users to bypass IP filtering for webhooks and repository migrations by targeting CGNAT and IPv6 transition prefixes, and unauthenticated users to trigger arbitrary GET requests against internal hosts via the OpenID sign-in form, potentially leading to internal network discovery and data exposure.
SVGO removeScripts Plugin Bypass Leads to Cross-Site Scripting
2 TTPsA vulnerability in the SVGO library's `removeScripts` plugin, affecting versions prior to 2.8.3, 3.3.4, and 4.0.2, allowed namespaced script elements and case-insensitive JavaScript URIs to bypass sanitization, potentially leading to Cross-Site Scripting (XSS) in web applications serving untrusted SVGs.
Gitea Repository Migration SSRF and Internal Git Repository Exfiltration
2 rules 9 TTPs 1 CVEA critical vulnerability in Gitea allows an authenticated, low-privileged user to exfiltrate internal Git repositories by exploiting a validation bypass, where Gitea's initial URL validation for repository migration is circumvented by the Git command-line client's default behavior of following HTTP redirects to otherwise blocked internal IP addresses, leading to server-side request forgery (SSRF) and the theft of sensitive code, credentials, and configuration into an attacker-controlled repository, with persistent exfiltration possible through pull mirrors.
Unauthenticated Input Validation Bypass in Ninja Forms WordPress Plugin (CVE-2026-65052)
1 TTP 1 CVEAn improper input validation vulnerability, identified as CVE-2026-65052, in Ninja Forms WordPress plugin versions 3.14.8 and prior allows unauthenticated attackers to tamper with form submission payloads to the ajax submit endpoint, injecting arbitrary numeric values into form calculations and payment totals, thereby bypassing admin-configured pricing logic and potentially reducing payment amounts to zero.
WordPress Easy Form Builder Plugin Vulnerable to Unauthenticated Administrator Privilege Escalation (CVE-2026-13439)
1 rule 2 TTPs 1 CVEAn unauthenticated privilege escalation vulnerability exists in the Easy Form Builder by WhiteStudio plugin for WordPress, affecting versions up to and including 4.0.11, allowing attackers to exploit a flaw in the password recovery process by using a publicly visible session identifier ('sid') as a reset token, combined with a publicly accessible nonce refresh endpoint, to set an arbitrary new password for any WordPress user, including administrators, to gain full control.
CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability
4 rules 4 TTPs 2 IOCsA high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.
CVE-2026-16324: Metasoft MetaCRM Unrestricted File Upload Vulnerability
1 rule 2 TTPs 1 CVEA high-severity vulnerability, CVE-2026-16324, exists in Metasoft MetaCRM up to version 6.4.0 Beta06, allowing remote attackers to perform unrestricted file uploads by manipulating the 'File' argument within the `/business/qnaire/upload.jsp` component, which can lead to webshell deployment and remote code execution; a public exploit is available, increasing the risk of attack.
Astro Authorization Bypass via Iterative Decode Limit and Canonicalization Mismatch
1 rule 2 TTPs 1 CVEAn authorization bypass vulnerability exists in Astro versions >= 6.4.7 and < 6.4.8, caused by a mismatch in URL path canonicalization, allowing an unauthenticated attacker to bypass middleware protections and access protected routes if the application relies on pathname-based authorization and uses rewrite behavior that performs route matching after middleware execution.
LightRAG CORS Misconfiguration Allows Credentialed Cross-Origin Requests (CVE-2026-61736)
2 TTPs 1 CVEThe LightRAG application, specifically the 'lightrag-hku' package, contains a critical vulnerability (CVE-2026-61736) due to its default Cross-Origin Resource Sharing (CORS) configuration, enabling any malicious website to perform authenticated API calls on behalf of a logged-in LightRAG user, leading to unauthorized data exfiltration or destructive actions.
CVE-2026-63766: Unauthenticated OS Command Injection in GPT-SoVITS webui.py
1 rule 2 TTPs 1 CVE 2 IOCsAn unauthenticated OS command injection vulnerability (CVE-2026-63766) in GPT-SoVITS through version 20250606v2pro's webui.py allows attackers to execute arbitrary operating system commands via shell metacharacters in Gradio textbox inputs, leading to remote code execution.
Adminer Cookie Injection Vulnerability via X-Forwarded-Prefix Header (CVE-2026-63771)
1 rule 1 TTP 1 CVEAdminer versions prior to 5.4.3 are vulnerable to a cookie injection flaw, which allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header, enabling cross-origin authenticated requests and bypassing cookie security controls.
Server-Side Request Forgery in Huginn (CVE-2026-63769)
1 rule 2 TTPs 1 CVEA server-side request forgery vulnerability, CVE-2026-63769, in Huginn through version 2022.08.18 allows authenticated users to make arbitrary HTTP requests via crafted URLs, leading to internal network probing, port enumeration, and potential credential theft from cloud metadata endpoints.
Roo Code Command Injection Vulnerability (CVE-2026-63108)
1 rule 1 TTP 1 CVEA command injection vulnerability in Roo Code versions through 3.54.0 allows attackers to bypass allowlist/denylist enforcement in the auto-approve execute feature. By nesting command substitutions inside parameter expansion defaults, the command parser in parse-command.ts fails to detect the dangerous payloads, leading to their auto-approval and subsequent arbitrary command execution via the shell through execa.
Tornado Quadratic DoS via Repeated HTTP Header Coalescing (CVE-2025-67725)
1 TTP 1 CVEA quadratic Denial of Service (DoS) vulnerability exists in Tornado's `HTTPHeaders.add` method due to inefficient string concatenation for repeated header names, which, when processing a maliciously crafted HTTP request with numerous repeated headers, can block the server's single event loop for an extended period, leading to a high severity DoS if `max_header_size` is increased from its default 64KB.
Tenda AC10 Buffer Overflow Vulnerability (CVE-2026-16248)
2 TTPs 1 CVE 6 IOCsA stack-based buffer overflow vulnerability (CVE-2026-16248) has been identified in Tenda AC10 firmware version 16.03.10.09_multi_TDE01, residing in the fromAdvSetLanip function of the /goform/AdvSetLanip file within the httpd/netctrl component, which can be remotely exploited by manipulating the GetValue/SetValue argument, with a public exploit now available.
Web Server Local File Inclusion Activity
1 rule 4 TTPs 1 IOCThis brief details how attackers exploit Local File Inclusion (LFI) vulnerabilities on web servers such as Nginx, Apache, IIS, and Traefik, by using directory traversal or direct sensitive file path requests to disclose system information, credentials, and configuration files, potentially leading to remote code execution and system compromise.
Shibboleth Service Provider SQL Injection Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a SQL Injection vulnerability within the Shibboleth Service Provider software, allowing them to perform unauthorized database queries and potentially extract or manipulate sensitive data.
QueryWeaver Authentication Bypass via Signup Request (CVE-2026-10130)
3 TTPs 1 CVECVE-2026-10130 describes an authentication bypass vulnerability in QueryWeaver, enabling unauthenticated attackers to obtain valid session tokens for existing user accounts by submitting a crafted signup request with a known victim's email address, leveraging a Cypher MERGE operation that unconditionally links a new token before checking for existing accounts.
CVE-2024-58368: SurrealDB Denial-of-Service via Malformed HTTP Headers
1 TTP 1 CVEUnauthenticated attackers can exploit CVE-2024-58368 in SurrealDB versions prior to 1.1.0 by sending crafted HTTP REST API requests with malformed ID, DB, or NS headers, leading to an uncaught exception and server crash, resulting in denial of service.
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
Authenticated Full-Read SSRF in CloudTAK /api/esri* Routes
1 rule 3 TTPs 2 IOCsAn authenticated Server-Side Request Forgery (SSRF) vulnerability exists in CloudTAK's `/api/esri*` routes, allowing any authenticated user to compel the server to make arbitrary outbound HTTP requests to internal network resources, enabling attackers to access sensitive cloud instance metadata, enumerate internal services, and exfiltrate data by reflecting the response bodies.
IBM Langflow OSS Remote Code Execution via Deserialization
1 rule 5 TTPs 7 CVEs 1 IOCIBM Langflow OSS versions 1.0.0 through 1.10.0 contain a critical deserialization vulnerability (CVE-2026-8476) in its disk-based caching mechanism, which uses Python's unsafe `pickle.loads()` function without proper validation, allowing attackers to process malicious pickle payloads and achieve arbitrary code execution with the privileges of the Langflow server process, leading to complete system compromise.
IBM Engineering AI Hub Cross-site Scripting Vulnerability (CVE-2026-15091)
2 TTPs 1 CVEA critical cross-site scripting (XSS) vulnerability, identified as CVE-2026-15091 with a CVSS v3.1 score of 9.3, affects IBM Engineering AI Hub versions 1.0.0, 1.1.0, and 1.2.0, allowing a remote attacker to execute arbitrary scripts due to improper input neutralization during web page generation.
Flask-Reuploaded Extension Denylist Bypass via Case-Folding Asymmetry
3 TTPs 1 CVEAn incomplete fix for CVE-2026-27641 in Flask-Reuploaded versions up to and including 1.5.0 allows attackers to bypass extension denylists through case-folding asymmetry, enabling the upload of malicious files with dangerous extensions (e.g., shell.PHP) that can lead to remote code execution on case-insensitive execution environments.
meta-ads-mcp Authentication Bypass via X-Pipeboard-Token Header
3 TTPsAn authentication bypass vulnerability in `meta-ads-mcp` version 1.0.113 allows unauthenticated network callers to gain unauthorized access by sending an arbitrary value in the `X-Pipeboard-Token` HTTP header, leading to the reuse of the server operator's `META_ACCESS_TOKEN` for full read and write access to Meta Ads data.
IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)
1 rule 3 TTPs 3 CVEs 2 IOCsUnauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.
FreePBX Modules Vulnerable to Unauthenticated RCE and SQL Injection
2 rules 5 TTPsMultiple critical vulnerabilities have been identified in FreePBX modules, including unauthenticated remote code execution (RCE) in the UCP module, unauthenticated SQL injection in the missedcall module leading to administrator takeover, authenticated command injection in the TTS module, and authenticated RCE in the music module. These flaws affect specific versions of these modules across FreePBX 16 and 17, allowing attackers to execute arbitrary commands, bypass authentication, and gain administrative control.
Vulnerability in poco-ai poco-claw Leads to Server-Side Request Forgery (CVE-2026-16016)
1 rule 2 TTPs 1 CVEA high-severity server-side request forgery (SSRF) vulnerability, identified as CVE-2026-16016, exists in poco-ai's poco-claw software up to version 0.5.4, allowing remote attackers to manipulate the `callback_url` argument in the `run_task` function to force the server to make arbitrary requests, with a public exploit available posing an immediate risk.
Kali Forms WordPress Plugin Vulnerable to Stored Cross-Site Scripting via digitalSignature Field
1 rule 6 TTPs 1 CVEThe Kali Forms - Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'digitalSignature' field in versions up to and including 2.4.18, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user accesses an affected page.
Grav API Plugin Vulnerable to CORS Misconfiguration Allowing Data Exposure and Unauthorized Operations
1 rule 3 TTPs 1 CVEThe Grav API plugin before version 1.0.0-rc.16 contains a CORS misconfiguration that sets `Access-Control-Allow-Origin: *` by default, enabling an attacker to perform authenticated cross-origin requests from a malicious website after obtaining a valid API token, leading to sensitive data exfiltration and unauthorized write operations.
Grav .htaccess Case-Insensitivity Bypass for Sensitive File Access
1 rule 3 TTPs 1 CVEAn unauthenticated attacker can exploit a flaw in Grav prior to version 2.0.4 where the default .htaccess file's rules for blocking access to sensitive file types are case-sensitive, allowing bypass on case-insensitive filesystems (Windows, macOS, or Docker volume mounts) by requesting sensitive configuration files (e.g., .yaml, .php, .json) using uppercase or mixed-case extensions, leading to unauthorized reading of files that may contain API keys and credentials.
Pheditor Hardcoded Admin Password Leads to Remote Code Execution (CVE-2026-55579)
1 rule 5 TTPsPheditor contains a critical vulnerability (CVE-2026-55579) where a hardcoded default password 'admin' with no forced change mechanism upon first login allows an unauthenticated attacker to gain full administrative access, enabling arbitrary file read/write and remote code execution through the application's terminal feature, leading to complete server compromise.
Pheditor Authenticated Command Whitelist Bypass via Shell Command Substitution
1 rule 1 TTPPheditor 2.0.4 contains an authenticated command injection vulnerability, CVE-2026-54540, allowing a user with `terminal` permissions to bypass the `TERMINAL_COMMANDS` whitelist by leveraging shell command substitution to execute arbitrary shell commands as the web server user.
AVideo OS Command Injection Vulnerability (CVE-2026-63304)
1 rule 1 TTP 1 CVE 2 IOCsAVideo versions up to and including 29.0 are vulnerable to an OS command injection (CVE-2026-63304) in the `listFFmpegProcesses()` function within `plugin/API/standAlone/functions.php`, allowing attackers to craft an encrypted `codeToExec` payload to bypass single-quote escaping and execute arbitrary operating system commands as the web-server user, leading to remote code execution.
Vulnerability in Ruby on Rails Allows Remote Indirect Code Injection (XSS)
1 TTP 1 IOCA cross-site scripting (XSS) vulnerability has been discovered in Ruby on Rails versions prior to 1.7.1, enabling a remote attacker to perform an indirect remote code injection, allowing malicious scripts to be executed in the client's browser.
WordPress Digits Plugin Privilege Escalation via Missing Authorization
1 rule 1 TTP 1 CVEThe Digits: WordPress Mobile Number Signup and Login plugin is vulnerable to privilege escalation, allowing authenticated attackers with Subscriber-level access to elevate privileges to Administrator by submitting a forged `digits_reg_userrole` value during profile update, impacting WordPress sites configured with the built-in DIGITS User Role field.
RPB Chessboard WordPress Plugin Vulnerable to Stored Cross-Site Scripting
1 TTP 1 CVEThe RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its comment content functionality, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a user views the affected page, bypassing WordPress's default kses sanitization.
SQL Injection Vulnerability in WordPress WooCommerce Advanced Product Search Plugin (CVE-2026-12753)
1 rule 2 TTPs 1 CVEA SQL Injection vulnerability, CVE-2026-12753, has been identified in the Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress, affecting all versions up to and including 1.4.4. The flaw, caused by insufficient input sanitization of the 's' and 'match' parameters and inadequate SQL query preparation, allows unauthenticated attackers to append arbitrary SQL queries. This enables them to extract sensitive information directly from the database.
SQL Injection Vulnerability in H3C SecPath F1000-C8300 (CVE-2026-15907)
1 rule 1 TTP 1 CVE 5 IOCsA SQL injection vulnerability, CVE-2026-15907, exists in H3C SecPath F1000-C8300 appliances up to version 20260522, allowing remote attackers to manipulate the 'subject' argument in the '/webui/?g=log_fw_nbc_mail_jsondata' endpoint to execute arbitrary SQL commands, potentially leading to unauthorized data access or system compromise, with a publicly available exploit.
TensorZero Gateway Arbitrary File Read and SSRF Vulnerability
1 rule 3 TTPsA high-severity vulnerability (CVE-2026-54457) in the TensorZero Gateway's `/internal/object_storage` endpoint allows attackers to achieve arbitrary file reading from the gateway filesystem and Server-Side Request Forgery (SSRF) by manipulating the `storage_path` parameter, potentially leading to credential exposure and internal network reconnaissance.
Gravity Forms Directory Traversal Vulnerability (CVE-2026-12997)
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit a Directory Traversal vulnerability (CVE-2026-12997) in the Gravity Forms plugin for WordPress, affecting all versions up to and including 2.10.4, to read arbitrary files on the server and receive their contents as an email attachment, potentially exfiltrating sensitive information.
MantisBT Reflected XSS Vulnerabilities in admin/install.php (CVE-2026-52847)
1 rule 4 TTPsMantisBT versions 2.28.3 and earlier are vulnerable to six reflected XSS injection points in the `/admin/install.php` script, which attackers can exploit without authentication to perform credential phishing, open redirects, and UI manipulation due to an incomplete Content Security Policy.
Kanboard Vulnerability CVE-2026-58660 Allows Cross-Project Task Manipulation
3 TTPs 1 CVEA high-severity vulnerability, CVE-2026-58660, in Kanboard versions up to 1.2.52 allows any authenticated user to enumerate, move, corrupt, or hide tasks belonging to any project on the same instance, including private projects, due to improper validation in the BoardAjaxController save() method.
Splunk Enterprise and Cloud Platform CSRF Vulnerability Leading to Arbitrary SPL Execution (CVE-2026-20296)
4 TTPs 3 CVEsA Cross-Site Request Forgery (CSRF) vulnerability, identified as CVE-2026-20296, in Splunk Enterprise and Splunk Cloud Platform allows an attacker to trick a user with the `list_deployment_server` capability into executing arbitrary Search Processing Language (SPL) searches as the highly privileged `splunk-system-user`, potentially leading to unauthorized access of stored credentials and indexed data due to a lack of CSRF token validation and improper input neutralization.
MantisBT Remote Code Execution via Class Hoisting (CVE-2026-49273)
1 rule 1 TTPA high-severity remote code execution vulnerability, CVE-2026-49273, affects MantisBT versions 2.28.3 and earlier, allowing an authenticated administrator to achieve arbitrary code execution as the web server user by leveraging PHP's class hoisting during the processing of non-string configuration values in `adm_config_set.php`.
MantisBT SOAP API Authentication Bypass and Privilege Escalation (CVE-2026-47156)
2 TTPsA critical authentication bypass vulnerability, CVE-2026-47156, exists in the SOAP API's mci_check_login() function of MantisBT versions 2.28.3 and earlier, allowing an unauthenticated attacker to impersonate any user, including an administrator, by knowing a valid cookie_string and the target username, without needing the target's password, which can lead to full administrator access, extensive data exfiltration, and destructive operations when default self-registration is enabled.
MantisBT SQL Injection via history_order Configuration Value
2 rules 8 TTPsMantisBT versions 2.28.3 and earlier are vulnerable to a SQL injection within the `history_order` configuration value in `core/history_api.php`, allowing an authenticated administrator to inject malicious SQL via the web UI or REST API, which then executes whenever any user views a bug with history entries, leading to sensitive data extraction and potential Remote Code Execution (RCE) via webshell if the MySQL FILE privilege is enabled.
Grav Form Plugin Arbitrary File Write Vulnerability (CVE-2026-61873)
1 rule 3 TTPs 1 CVEGrav before version 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, allowing attackers to bypass path traversal validation via Twig template processing and write PHP webshells for remote code execution.
Grav API Plugin File Upload Extension Bypass Leading to RCE
1 rule 3 TTPs 1 CVEA vulnerability (CVE-2026-61457) in the Grav API plugin before version 1.0.3 allows an authenticated attacker with `api.media.write` permissions to bypass file upload extension validation using double extensions, which can lead to remote code execution on the web server.
PraisonAI MCP HTTP-Stream Authentication Bypass (CVE-2026-61427)
1 rule 3 TTPs 1 CVEPraisonAI versions prior to 4.6.78 contain an authentication bypass vulnerability, CVE-2026-61427, in the MCP HTTP-stream transport, allowing unauthenticated clients to establish sessions, enumerate tools, and invoke tools, potentially leading to remote code execution if the server is bound to a network-accessible address.
Grav Flex Objects Plugin Stored Template Injection Leading to RCE
1 rule 1 TTP 1 CVEA stored server-side template injection vulnerability, identified as CVE-2026-58655, exists in the Grav Flex Objects plugin before version 1.4.0, allowing an attacker to achieve arbitrary Twig execution and remote command execution by injecting malicious code into user-controlled title frontmatter that bypasses sanitization.
Open WebUI Stored Cross-Site Scripting Vulnerability (CVE-2026-56398)
2 TTPs 1 CVEOpen WebUI before version 0.9.5 contains a high-severity stored cross-site scripting (XSS) vulnerability, CVE-2026-56398, in its OAuth authentication flow that allows an authenticated attacker to bypass profile image validation by uploading malicious SVG files, leading to script execution, authentication token theft, and ultimately account takeover for other authenticated users.
CVE-2026-61451: Unauthenticated Account Takeover in Grav API Plugin via Password Reset Vulnerability
1 rule 3 TTPs 1 CVEAn unauthenticated attacker can exploit CVE-2026-61451 in Grav API plugin versions prior to 1.0.4, leveraging improper URL validation in the password reset functionality to specify an arbitrary host in the reset link, thereby disclosing valid reset tokens to an attacker-controlled server and enabling full account takeover.
Zhinianboke Xianyu-Auto-Reply Missing Authorization Vulnerability (CVE-2026-15752)
1 TTP 1 CVEA missing authorization vulnerability (CVE-2026-15752) exists in the /api/v1/users/ endpoint of zhinianboke xianyu-auto-reply, affecting versions up to commit dcb445ad97816ad65299a7580ee0c8c8f929da84, allowing a remote attacker to bypass authentication or authorization checks. An exploit for this vulnerability has been made public, and organizations using this product should apply the patch named 19fc3282a1bb78a05c34945c088525d20e081cbd to mitigate the risk.
CAI Content Credentials Server-Side Request Forgery Leads to Arbitrary Code Execution
2 TTPs 1 CVECAI Content Credentials is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-48290, which an attacker can exploit to achieve arbitrary code execution and potentially gain elevated access by injecting malicious scripts into a web page, requiring user interaction to succeed.
Unauthenticated API Key Use in NetLicensing-MCP HTTP Mode
5 TTPsAn unauthenticated vulnerability exists in netlicensing-mcp (version 0.1.5 and earlier) when operating in HTTP transport mode, where the ApiKeyMiddleware fails to enforce authentication for requests lacking a client API key, causing the application to fall back to the server's NETLICENSING_API_KEY environment variable for upstream calls, allowing an unauthenticated network attacker to invoke any MCP tool under the server operator's identity and account quota.
Command Injection in Sustainable Irrigation Platform cli_control Plugin
3 TTPs 3 CVEsA critical command injection vulnerability (CVE-2026-58479) exists in the optional cli_control plugin of Sustainable Irrigation Platform (SIP) versions up to 5.2.16, allowing unauthenticated or CSRF attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating an associated irrigation station.
Apache ActiveMQ Cross-Site Scripting Vulnerability
1 TTPA remote, authenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in Apache ActiveMQ to execute malicious scripts within a victim's browser.
Remote SQL Injection Vulnerability in code-projects Online Job Portal (CVE-2026-15676)
1 rule 2 TTPs 1 CVEA high-severity SQL injection vulnerability, CVE-2026-15676, exists in code-projects Online Job Portal up to version 1.0, allowing remote unauthenticated attackers to manipulate the database via the /Admin/DeleteUser.php file with a publicly available exploit.
CVE-2026-44752: SAP NetWeaver Application Server Java Cross-Site Scripting Vulnerability
3 TTPs 1 CVEAn unauthenticated attacker can exploit a cross-site scripting (XSS) vulnerability (CVE-2026-44752) in SAP NetWeaver Application Server Java by injecting malicious JavaScript through crafted URLs, leading to client-side script execution, access to sensitive session information, and modification of non-sensitive data, resulting in high confidentiality impact and low integrity impact.
CVE-2026-61462 - mcp-gitlab Path Traversal Vulnerability Leading to Unauthorized API Access
1 rule 2 TTPs 1 CVEA path traversal vulnerability, CVE-2026-61462, in the job_id parameter of build/index.js within mcp-gitlab allows attackers to redirect GitLab API requests to arbitrary endpoints by escaping the intended path prefix, leveraging the operator's personal access token for unauthorized access.
Rejetto HFS Vulnerability Allows Remote Code Execution via Session Forgery (CVE-2026-61500)
4 TTPs 1 CVEA remote attacker can exploit a critical vulnerability, CVE-2026-61500, in Rejetto HFS versions 3.0.0 through 3.2.0 by recovering the session-cookie signing key due to poor randomness, forging an administrator session, and achieving remote code execution.
NukeViet Server-Side Request Forgery via X-Forwarded-Host (CVE-2026-55372)
2 TTPsAn unauthenticated attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability in NukeViet by spoofing the X-Forwarded-Host and X-Forwarded-Proto HTTP headers, allowing the server to make a cURL request to an attacker-controlled host without validation for internal host/port discovery and cache poisoning. The vulnerability affects NukeViet versions prior to 4.6.00.
NukeViet Multiple Anti-XSS Filter Bypasses Leading to Stored XSS
2 TTPsTwo filter-bypass techniques in NukeViet\Core\Request allow a low-privileged user with news-posting permission to store and execute arbitrary JavaScript in the browsers of any visitor to an affected page, leading to session cookie theft, credential harvesting, defacement, and further privilege escalation via CVE-2026-54064.
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
1 rule 2 TTPsAn authenticated administrator in NukeViet is vulnerable to a path traversal flaw (CVE-2026-54065) in the Edit Comment admin function, allowing an attacker to inject a crafted `attach` parameter which, upon comment deletion, leads to arbitrary file deletion within the application root, causing a full application outage and exposing the install wizard.
NukeViet CMS Stored Cross-Site Scripting Vulnerability
1 rule 2 TTPsA stored cross-site scripting (XSS) vulnerability, CVE-2026-49259, exists in NukeViet CMS versions 4.x through 4.5.08, including the 'composer/nukeviet/nukeviet' package prior to version 4.5.09, which allows a low-privileged authenticated user to inject JavaScript into their profile's display name fields that executes in the browser of any visitor, including administrators, who clicks the 'Reply' link on a comment posted by the attacker, leading to arbitrary JavaScript execution, administrative session hijacking, credential phishing, and data exfiltration.
Decidim Vulnerability Allows Unauthorized Access to Identity Documents via Reusable Signed URLs
1 rule 1 TTPA high-severity vulnerability (CVE-2026-45378) in Decidim's identity document verification workflow allows unauthorized access to sensitive identity documents. Signed `/rails/active_storage/disk/` URLs, which are generated for administrator review, can be harvested and replayed by unauthenticated users for up to seven days, enabling attackers to bypass authentication and download highly sensitive personal information if these URLs are leaked through various channels.
CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0
1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.
Drupal AlternativeCommerce (Basket) Module Vulnerability Allows Code Execution
2 TTPsA critical vulnerability in the Drupal 'AlternativeCommerce' (Basket) module allows a remote, unauthenticated attacker to execute arbitrary program code. This can lead to full compromise of the affected web application.
Metasoft MetaCRM SQL Injection Vulnerability (CVE-2026-15514)
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-15514) in Metasoft MetaCRM up to version 6.4.0 Beta06 allows remote attackers to exploit the RPCService.query function via the phprpc_args argument in /customizemt/xkq/rpc.jsp, leading to unauthorized database access and manipulation, with a public exploit available.
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)
1 TTP 1 CVELuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.
CVE-2026-61875: Stored Cross-Site Scripting in OpenWrt luci-app-upnp
2 TTPs 1 CVECVE-2026-61875 details a stored cross-site scripting vulnerability in OpenWrt's luci-app-upnp that allows unauthenticated LAN clients to inject malicious JavaScript into UPnP IGD AddPortMapping SOAP requests, leading to client-side code execution in an administrator's browser when viewing specific web interface pages.
CVE-2026-15489: SQL Injection in RafyMrX TOKO-ONLINE-ROTI login.php
2 rules 4 TTPs 1 CVEA critical SQL injection vulnerability (CVE-2026-15489) exists in RafyMrX TOKO-ONLINE-ROTI, allowing remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument in the 'proses/login.php' file, with a public exploit available.
SQL Injection Vulnerability in Aster Telecom Azcall (CVE-2026-15482)
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability, tracked as CVE-2026-15482, exists in Aster Telecom Azcall 10/11 within the HTTP Handler component, where manipulating the 'nome/perfil/status' argument when accessing '/azcall/adm/gestao_loja/sis.php?t=consultar' can lead to remote SQL injection, with a publicly available exploit allowing unauthenticated attackers to potentially access or modify sensitive data.
WP CTA Plugin Vulnerable to Unauthenticated Time-Based Blind SQL Injection (CVE-2026-4661)
1 rule 2 TTPs 1 CVEThe WP CTA - Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in versions up to and including 2.2.2. This vulnerability is due to insufficient escaping of user-supplied column names and lack of preparation in database queries. Unauthenticated attackers can exploit this by injecting arbitrary SQL queries to extract sensitive information, including administrator password hashes, from the database.
The Swiss Toolkit For WP Plugin Vulnerable to Arbitrary File Upload Leading to RCE (CVE-2026-2354)
1 rule 3 TTPs 1 CVEA critical arbitrary file upload vulnerability (CVE-2026-2354) exists in The Swiss Toolkit For WP plugin for WordPress, affecting all versions up to and including 1.4.6. The flaw, located in the `upload_extension_files()` function, allows authenticated attackers with Author-level access or higher to bypass file type validation due to an improper `strpos()` check, enabling the upload of arbitrary files, including PHP scripts, which can lead to remote code execution on the server if the "Enhanced Multi-Format Image Support" feature is active with at least one configured extension.
WordPress Booking Package Plugin Vulnerable to Unauthenticated SQL Injection
1 TTP 1 CVEThe Booking Package plugin for WordPress is vulnerable to unauthenticated generic SQL Injection via the 'email' form parameter in versions up to and including 1.7.20, allowing attackers to extract sensitive information from the database.
SiYuan Stored XSS via Malicious Bazaar Package README
5 TTPs 1 CVEA stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-54070, affects SiYuan versions up to 3.6.5, allowing a malicious third-party package author to embed JavaScript in package READMEs via an incomplete HTML sanitizer's blocklist, which executes in an Administrator's authenticated browser session upon viewing and interacting with the crafted README in the Bazaar marketplace, leading to API token theft and potential full workspace control.
SiYuan Unauthenticated Admin API Access via Chrome Extension Allowlist
1 rule 6 TTPs 1 CVE 1 IOCA critical vulnerability (CVE-2026-54069) in SiYuan Note kernel's HTTP server allows any Chrome/Chromium browser extension to gain unauthenticated RoleAdministrator access, enabling data exfiltration, stored XSS injection, and configuration tampering for SiYuan desktop users, including via compromised legitimate extensions.
FileBrowser Authentication Bypass via Forged Proxy Authentication Header
1 rule 3 TTPsAn unauthenticated attacker can impersonate any user, including administrators, or automatically create new user accounts in FileBrowser by forging the `X-Remote-User` HTTP header when the server is configured for proxy authentication and is directly reachable, leading to full administrative control and unauthorized access to data.
SiYuan Path Traversal Vulnerability (CVE-2026-54066) via Double URL Encoding
1 rule 3 TTPs 2 CVEs 1 IOCAn incomplete fix for CVE-2026-41894 in SiYuan's 'publish mode' allows unauthenticated remote attackers to perform path traversal by double URL-encoding '..' segments in requests to the '/assets/*path' route, leading to the read of arbitrary files within the 'WorkspaceDir'.
Dify MyScale Backend SQL Injection Vulnerability (CVE-2026-61461)
1 rule 4 TTPs 1 CVEA high-severity SQL injection vulnerability, CVE-2026-61461, exists in the MyScale vector store backend of Dify versions prior to 1.16.0-rc1, allowing attackers with low privileges to execute arbitrary SQL commands via unsanitized search parameters, leading to unauthorized data manipulation in the underlying ClickHouse database.
CVE-2026-56291: Balbooa Forms Unrestricted File Upload Vulnerability Leading to RCE
1 rule 2 TTPs 1 CVEA critical unrestricted file upload vulnerability, CVE-2026-56291, in Balbooa Forms allows an unauthenticated attacker to upload executable files, potentially leading to arbitrary code execution on the server.
Crawl4AI Server-Side Request Forgery Vulnerability (CVE-2026-56261)
2 TTPs 1 CVECrawl4AI versions before 0.8.7 contain a server-side request forgery (SSRF) vulnerability, CVE-2026-56261, in its Docker API server's webhook endpoints, allowing an attacker to coerce the server into making requests to internal services and potentially expose cloud metadata.
Lucee CFML Server Reflected XSS Vulnerability (CVE-2026-29519)
1 rule 2 TTPs 1 CVELucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines are vulnerable to a reflected cross-site scripting (XSS) flaw in URL path parsing, allowing unauthenticated remote attackers to embed arbitrary HTML or JavaScript payloads within the request path which, when visited by a victim, enables the execution of arbitrary JavaScript in the victim's browser for purposes such as session hijacking or unauthorized actions against the Lucee administrative interface.
CVE-2026-15330: zhayujie CowAgent Server-Side Request Forgery
1 rule 1 TTP 1 CVEA critical server-side request forgery (SSRF) vulnerability, CVE-2026-15330, exists in zhayujie CowAgent up to version 2.1.1, allowing remote attackers to manipulate the 'image' argument in the Vision Tool component's `_build_image_content` or `_download_to_data_url` functions to access internal resources or conduct port scanning.
CVE-2026-15290: Ultimate Member Plugin Blind SQL Injection
1 rule 2 TTPs 2 CVEsThe Ultimate Member plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to and including 2.10.1, due to insufficient escaping of user-supplied input and inadequate preparation of existing SQL queries, allowing unauthenticated attackers to append additional SQL queries and extract sensitive information from the database.
CVE-2026-13430: WordPress Post Export Import with Media Plugin Arbitrary File Upload Leading to RCE
1 rule 2 TTPs 1 CVEA high-severity arbitrary file upload vulnerability, CVE-2026-13430, exists in all versions up to 1.13.1 of the Post Export Import with Media plugin for WordPress, allowing authenticated administrators to upload executable web shells via a trailing-dot filename bypass, leading to remote code execution.
CVE-2026-58122: Hermes WebUI Authentication Bypass via Spoofed X-Forwarded-For Header
1 rule 4 TTPs 1 CVECVE-2026-58122 describes an authentication bypass vulnerability in Hermes WebUI before version 0.51.307, allowing unauthenticated remote attackers to bypass local-origin IP restrictions on onboarding endpoints by spoofing the X-Forwarded-For header with a loopback address, leading to server-side request forgery (SSRF), API key overwrites, and persistent access token acquisition.
YesWiki Unauthenticated ActivityPub Signature-Verification Bypass (CVE-2026-52767)
1 rule 3 TTPsA critical vulnerability, CVE-2026-52767, in YesWiki's `HttpSignatureService::verifySignature()` allows unauthenticated attackers to bypass ActivityPub signature verification due to a loose boolean negation (`!openssl_verify(...)`) accepting `int(-1)` from PHP's `openssl_verify()` under specific conditions, enabling arbitrary Create, Update, and Delete operations on ActivityPub-enabled forms leading to defacement and content manipulation.
YesWiki Unauthenticated SSRF via ActivityPub Signature.keyId (CVE-2026-52769)
1 rule 3 TTPs 1 IOCAn unauthenticated Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-52769, exists in YesWiki's `POST /api/forms/{formId}/actor/inbox` route when ActivityPub is enabled, allowing attackers to force arbitrary outbound HTTP GET requests to internal or external hosts and potentially exfiltrate sensitive information via timing and error messages.
CVE-2026-9253: WordPress E&P Forms Plugin Stored Cross-Site Scripting
2 TTPs 1 CVEAn unauthenticated attacker can inject arbitrary web scripts into WordPress sites running the 'WP Cost Estimation & Payment Forms Builder' plugin version 10.5.97 and earlier by exploiting CVE-2026-9253, a Stored Cross-Site Scripting vulnerability via the 'customerInfos' parameter, leading to script execution in users' browsers and potential session hijacking or data theft.
EventPrime WordPress Plugin Stored XSS (CVE-2026-13441)
1 rule 2 TTPs 1 CVEA critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-13441, exists in all versions up to 4.3.4.2 of the EventPrime - Events Calendar, Bookings and Tickets plugin for WordPress, allowing authenticated attackers with custom-level access (or unauthenticated attackers if 'Guest Submissions' is enabled) to inject malicious web scripts via the new_event_type_background_color parameter that execute whenever a user accesses an affected page, potentially leading to session hijacking, defacement, or further compromise.
CVE-2026-5955: Critical SQL Injection in Inrove BiEticaret
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-5955) in Inrove Software and Internet Services BiEticaret, affecting versions before v3.3.57, allows unauthenticated attackers to execute arbitrary SQL commands, potentially leading to data exfiltration and full system compromise.
CVE-2026-38969: Ruby WEBrick Request Smuggling Vulnerability
2 TTPs 1 CVEA high-severity vulnerability, CVE-2026-38969, exists in Ruby WEBrick versions up to v1.9.2 due to improper re-parsing of the 'trailer Content-Length' header, enabling HTTP request smuggling that attackers can exploit to bypass security controls and gain unauthorized access or execute arbitrary requests.
Joomla: Multiple Vulnerabilities Allowing XSS and Data Modification
1 TTPMultiple vulnerabilities in Joomla allow a remote, unauthenticated or authenticated attacker to display false information, launch Cross-Site Scripting (XSS) attacks, and modify data, potentially leading to integrity compromises and further client-side exploitation.
Gradio Open Redirect and Server-Side Request Forgery (SSRF) Vulnerability (CVE-2026-59806)
1 rule 2 TTPs 1 CVEGradio versions before 6.20.0 contain an open redirect and server-side request forgery (SSRF) vulnerability, CVE-2026-59806, allowing attackers to redirect users or perform client-side SSRF by supplying unvalidated HTTP/HTTPS URLs to the `/gradio_api/file=` endpoint, potentially leading to the retrieval of sensitive credentials, such as EC2 IAM role credentials.
Unauthenticated SQL Injection in IBM API Connect (CVE-2026-9074)
1 rule 3 TTPs 1 CVEIBM API Connect versions 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 are vulnerable to an unauthenticated SQL injection (CVE-2026-9074) in the password reset functionality, potentially leading to unauthorized data access or authentication bypass.
CVE-2026-59703: repomix Local File Inclusion Vulnerability
1 rule 2 TTPs 1 CVErepomix contains a local file inclusion vulnerability (CVE-2026-59703) in its git clone endpoint, allowing unauthenticated attackers to read arbitrary local git repositories and server filesystem contents by bypassing validation with crafted file:// URLs.
CVE-2026-58656 - Grav API Plugin Cross-Origin Authentication Bypass and Account Takeover
1 rule 3 TTPs 1 CVEA critical vulnerability, CVE-2026-58656, in the Grav API plugin before v1.0.0-rc.16 allows unauthenticated attackers to perform fully authenticated cross-origin API requests by leveraging leaked JWT tokens via the `?token=` URL query parameter and the `Access-Control-Allow-Origin: *` response header, potentially leading to persistent backdoor super-admin accounts and sensitive data exfiltration.
Multiple Vulnerabilities Discovered in Joomla! CMS
4 TTPs 5 CVEs 24 IOCsMultiple vulnerabilities, including several Cross-Site Scripting (XSS) flaws and incorrect access control issues, have been discovered in Joomla! versions 6.x prior to 6.1.2 and 5.x prior to 5.4.7, which could allow an attacker to bypass security policies, compromise data confidentiality and integrity, and perform remote indirect code injection.
CVE-2026-6818: VikBooking WordPress Plugin Stored XSS Vulnerability
1 rule 5 TTPs 1 CVEA stored cross-site scripting vulnerability (CVE-2026-6818) exists in the VikBooking Hotel Booking Engine & PMS plugin for WordPress, affecting versions up to and including 1.8.8, caused by insufficient input sanitization of the 'special_requests' parameter, enabling unauthenticated attackers to inject arbitrary web scripts that execute whenever a user accesses an affected page, potentially leading to unauthorized data access, session hijacking, or defacement.
CVE-2026-14489: WHMCS Bridge Plugin Arbitrary File Upload Leads to RCE
3 TTPs 1 CVEAuthenticated attackers with Custom-level access or higher can exploit CVE-2026-14489, a missing file type validation vulnerability (CWE-434) in the `connect()` function of the WHMCS Bridge plugin for WordPress versions up to and including 6.9, to upload arbitrary files, potentially leading to remote code execution.
Critical OS Command Injection in 9Router (CVE-2026-59800)
1 rule 2 TTPs 1 CVEA critical OS command injection vulnerability (CVE-2026-59800) affects 9Router versions prior to 0.4.44, allowing unauthenticated remote attackers to execute arbitrary OS commands as root via a crafted POST request to the /api/tunnel/tailscale-install endpoint, leading to full system compromise with active exploitation observed.
XWiki Platform Old Core Path Traversal via /skin/ Endpoint (CVE-2026-34151)
1 rule 3 TTPs 2 IOCsAn attacker can exploit CVE-2026-34151, a path traversal vulnerability in XWiki Platform Old Core through the `/skin/` action endpoint when hosted on Jetty 12+. This allows unauthenticated users to craft URLs to access and download arbitrary files on the server, such as `/etc/passwd` or sensitive XWiki configuration files (e.g., `xwiki.cfg`), potentially leading to information disclosure and further system compromise.
EGroupware Authenticated RCE via Malicious eTemplate Upload (CVE-2026-40187)
1 rule 2 TTPs 3 IOCsAn authenticated EGroupware administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) containing unescaped backtick characters that lead to shell command execution within a PHP `eval()` call during template processing (CVE-2026-40187), impacting non-Docker or non-hardened EGroupware deployments.
EGroupware Critical RCE Vulnerability (CVE-2026-27823)
2 rules 4 TTPsA critical remote code execution vulnerability (CVE-2026-27823) in EGroupware allows an authenticated attacker, or an unauthenticated attacker if self-registration is enabled, to execute arbitrary commands on the server by combining an authorization bypass, arbitrary file write via path traversal, and arbitrary file read, leading to full system compromise.
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
1 TTP 1 CVE 1 IOCAn attacker with only a GitHub account can plant a malicious JavaScript payload in a GitHub issue title, leading to a DOM Cross-Site Scripting (XSS) vulnerability (CVE-2026-55790) that executes in a Craft CMS administrator's control panel session when they use the CraftSupport widget and retrieve the poisoned issue, allowing for arbitrary JavaScript execution and potential unauthorized actions.
Critical Unauthenticated API Vulnerabilities in 9Router Leading to Data Leak and RCE Risk
3 rules 5 TTPsMultiple critical unauthenticated API vulnerabilities in 9Router versions up to 0.4.41 allow an attacker to perform full CRUD operations on provider connections, leak plaintext API keys, and access sensitive conversation history, posing risks of data exfiltration and denial of service.
CVE-2026-59712: Leantime JSON-RPC API Authorization Bypass Leads to Credential Disclosure
3 TTPs 1 CVE 3 IOCsAn authenticated user can exploit CVE-2026-59712, an authorization bypass vulnerability in Leantime's JSON-RPC API `Users::getUser` method, to retrieve sensitive user credential information including password hashes, TOTP secrets, and session tokens for any user, leading to account enumeration, offline password cracking, 2FA bypass, and session hijacking.
Coder User-Admin Role Can Reset Owner Account Password (CVE-2026-55077)
1 TTPA critical vulnerability, CVE-2026-55077, in the Coder platform allowed a user with the `user-admin` role to reset the password of an `owner` account without needing the current password via the `PUT /api/v2/users/{user}/password` endpoint, leading to privilege escalation and full deployment control.
CVE-2026-9181: Unauthenticated Directory Traversal in ArcGIS Server
2 TTPs 1 IOCAn unauthenticated attacker can exploit CVE-2026-9181, a critical directory traversal vulnerability in ArcGIS Server versions 12.0 and prior, by sending crafted path parameters to access sensitive files, leading to unauthorized information disclosure.
Formie Hidden Field SSTI Vulnerability (CVE-2026-52889)
1 rule 2 TTPsFormie Hidden fields in versions prior to 3.1.27 are vulnerable to Server-Side Template Injection (SSTI), allowing an unauthenticated attacker to inject Twig syntax into request-derived default values, potentially leading to remote code execution, sensitive information disclosure, or application state modification.
CVE-2026-14808 — Prog Management System Sensitive Information Exposure
2 TTPs 1 CVE 2 IOCsA critical vulnerability, CVE-2026-14808, in the Prog Management System developed by PROG MIS allows unauthenticated remote attackers to view a specific web page and obtain sensitive database account credentials, including the username and password, with high impact on confidentiality, integrity, and availability.
CVE-2026-14778: Improper Authorization in SourceCodester Onlne Examination & Learning Management System
1 CVEA high-severity improper authorization vulnerability (CVE-2026-14778) exists in SourceCodester Onlne Examination & Learning Management System version 1.0, allowing remote attackers to bypass authorization checks by manipulating the `student_id`, `schedule_id`, or `action` arguments in `/ajax_enroll.php`, potentially leading to unauthorized access or actions.
CVE-2026-14769 — SQL Injection in code-projects Real State Services 1.0
1 rule 3 TTPs 1 CVE 6 IOCsA critical security vulnerability, CVE-2026-14769, allows for remote SQL Injection in code-projects Real State Services 1.0 via the 'Bankname' argument in the '/pay.php' file, with a publicly disclosed exploit enabling information disclosure and potential data manipulation.
CVE-2026-14768: Remote SQL Injection in code-projects Real State Services 1.0
1 rule 1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-14768) has been identified in code-projects Real State Services 1.0, allowing attackers to exploit the 'loc' argument in '/builderHome.php' for arbitrary SQL command execution, with a public exploit available.
CVE-2026-14764: SQL Injection in code-projects Hotel and Tourism Reservation
1 rule 3 TTPs 1 CVEAn unauthenticated attacker can remotely exploit CVE-2026-14764, an SQL injection vulnerability in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_event.php` component via the `fdetails` argument, to manipulate database queries and compromise sensitive data, with public exploit disclosure increasing the risk of active exploitation.
CVE-2026-14755: Remote SQL Injection in code-projects Hotel and Tourism Reservation
1 rule 2 TTPs 1 CVE 2 IOCsA critical remote unauthenticated SQL injection vulnerability (CVE-2026-14755) in code-projects Hotel and Tourism Reservation version 1.0, specifically within the '/admin/reservations.php' file's 'delete' argument, allows attackers to manipulate backend database queries, leading to data exposure and manipulation with a publicly disclosed exploit.
CVE-2026-14749: mjperpinosa stumasy Code Injection Vulnerability
1 rule 2 TTPs 1 CVEA code injection vulnerability (CVE-2026-14749) was identified in mjperpinosa stumasy, affecting versions up to commit 327d1b0f2915ba79d7ef8ebb74553e987609d9be, which allows remote attackers to execute arbitrary code by manipulating the 'mathematical_sentence' argument in the 'eval' function of 'application/pages/imba_calculator/calculate.php', with a public exploit available and no vendor response.
CVE-2026-14746: SQL Injection in code-projects Real State Services
1 rule 1 TTP 1 CVEA high-severity SQL injection vulnerability (CVE-2026-14746) exists in code-projects Real State Services 1.0, specifically in the `/addprojectrent.php` file, where the `amen` argument can be manipulated to execute arbitrary SQL commands, enabling remote attackers to achieve unauthorized data access or modification, with public exploit disclosure increasing the risk of active exploitation.
CVE-2026-14745: SQL Injection in code-projects Real State Services
1 rule 3 TTPs 1 CVEA critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.
CVE-2026-14713 — SQL Injection in SourceCodester Pizzafy E-Commerce System
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14713) exists in SourceCodester Pizzafy E-Commerce System version 1.0, allowing unauthenticated remote attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the `/admin/ajax.php?action=confirm_order` endpoint, potentially leading to data exfiltration or modification, with a public exploit available.
CVE-2026-14695: SourceCodester Multi-Vendor Online Grocery Management System SQL Injection
1 TTP 1 CVEA high-severity SQL injection vulnerability, CVE-2026-14695, exists in SourceCodester Multi-Vendor Online Grocery Management System 1.0, allowing remote attackers to manipulate the 'Name' argument within the `save_client` function of `classes/Users.php` to execute arbitrary SQL commands, with a public exploit available.
CVE-2026-14688: Remote SQL Injection in itsourcecode Online Hotel Management System
1 rule 1 TTP 1 CVE 3 IOCsA high-severity SQL injection vulnerability, CVE-2026-14688, exists in itsourcecode Online Hotel Management System 1.0 within the `/admin/login.php` file via the `email` argument, allowing remote unauthenticated attackers to bypass authentication and potentially exfiltrate data, with a publicly available exploit.
CVE-2026-14654: Remote SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 1 TTP 1 CVE 7 IOCsA remote, unauthenticated SQL injection vulnerability (CVE-2026-14654) in SourceCodester Simple and Nice Shopping Cart Script 1.0 allows attackers to manipulate the `user_id` argument via `/admin/girlsproductdeletequery.php`, leading to database compromise, data exfiltration, or unauthorized access, with an exploit publicly available.
CVE-2026-14652: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14652) exists in the Admin Login component of SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing an unauthenticated attacker to remotely exploit it by manipulating the 'Username' argument in the /admin/login.php file, potentially leading to unauthorized access, information disclosure, or data manipulation, with a public exploit available.
CVE-2026-14637: Critical Deserialization Vulnerability in kirilkirkov Ecommerce-CodeIgniter-Bootstrap
2 TTPs 1 CVEA high-severity deserialization vulnerability, CVE-2026-14637, exists in the `getCartItems` function of `application/libraries/ShoppingCart.php` in kirilkirkov Ecommerce-CodeIgniter-Bootstrap versions up to commit `13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7`, allowing remote attackers to achieve arbitrary code execution by manipulating the `shopping_cart` argument, with public exploit disclosure raising immediate risk.
CVE-2026-14622 — Jairiidriss restaurant-website-php-mysql Authentication Bypass
1 rule 1 TTP 1 CVEA high-severity authentication bypass vulnerability (CVE-2026-14622) exists in the jairiidriss restaurant-website-php-mysql web application's AJAX Endpoint, specifically affecting the /admin/ajax_files component, allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionalities, with public exploit code increasing immediate risk.
Incomplete Fix for CVE-2026-25754 in @adonisjs/bodyparser Leads to CVE-2026-48795
3 TTPs 1 CVEAn incomplete fix for CVE-2026-25754 in the `@adonisjs/bodyparser` package, tracked as CVE-2026-48795, allows remote unauthenticated attackers to bypass security measures via nested prototype pollution payloads in `multipart/form-data` requests, potentially leading to authorization bypasses or remote code execution.
GeoNetwork Reflected XSS through Client-Side Template Injection (CVE-2026-39379)
1 rule 4 TTPsA reflected Cross-Site Scripting (XSS) vulnerability, CVE-2026-39379, exists in GeoNetwork due to client-side template injection within error pages, allowing an attacker to craft a URL that, when visited by a victim, causes arbitrary JavaScript to execute in their browser in the context of their authenticated session.
GeoNetwork ACL Bypass in Elasticsearch Search (CVE-2026-46487)
3 TTPsA high-severity authorization bypass vulnerability, CVE-2026-46487, in GeoNetwork's Elasticsearch-backed search API allows unauthenticated attackers to retrieve restricted metadata records by bypassing access control and visibility filters when the request body omits the 'query' field, leading to sensitive information disclosure.
MediaWiki Maps Stored XSS via display_map `overlays` Parameter (CVE-2026-52854)
1 rule 2 TTPsA high-severity stored cross-site scripting (XSS) vulnerability, CVE-2026-52854, exists in the MediaWiki Maps extension (versions prior to 12.1.3), allowing any authenticated user with edit permissions to inject malicious JavaScript into the `overlays` parameter of the `display_map` parser function, leading to arbitrary client-side code execution in a victim's browser.
Unauthenticated SQL Execution Vulnerability in Recce OSS Server (CVE-2026-49360)
1 rule 3 TTPsRecce OSS server deployments are vulnerable to unauthenticated SQL execution via the query run API when configured with a DuckDB-backed project, allowing attackers to use DuckDB filesystem primitives to read and write arbitrary files accessible to the server process, potentially leading to data disclosure, tampering, or stored XSS.
OpenAM Pre-Authentication Reflected XSS via OAuth2/OIDC state parameter (CVE-2026-44203)
1 rule 2 TTPsA critical pre-authentication reflected Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-44203, in OpenIdentityPlatform OpenAM's `openam-oauth2` component allows an unauthenticated attacker to inject malicious scripts into a victim's browser context by manipulating the `state` parameter in OAuth2/OIDC `form_post` responses, leading to session hijacking or credential theft.
Budibase Arbitrary File Read Vulnerability via PWA-zip Symlink Upload (CVE-2026-54352)
4 TTPs 1 CVE 3 IOCsA critical vulnerability, CVE-2026-54352, in Budibase server allows an authenticated workspace builder to perform arbitrary file reads on the host system by uploading a crafted PWA zip file containing a symbolic link, leading to credential compromise and privilege escalation, potentially enabling a full global administrator takeover.
i18next-http-middleware Prototype Pollution via missingKeyHandler (CVE-2026-48714)
1 rule 2 TTPs 1 CVEA critical prototype pollution vulnerability (CVE-2026-48714) exists in `i18next-http-middleware` versions up to 3.9.6, where the `missingKeyHandler` fails to adequately sanitize dotted key segments, allowing attackers to manipulate `Object.prototype` when exposed to untrusted input and used with vulnerable `i18next-fs-backend` versions up to 2.6.5, potentially leading to configuration poisoning, security bypasses, crashes, or remote code execution.
CVE-2024-58351: Flowise Remote Code Execution via Configuration Injection
2 rules 7 TTPsFlowise versions before 2.1.4 are critically vulnerable to configuration injection (CVE-2024-58351) via the `overrideConfig` option in both its frontend web integration and backend Prediction API, which, due to a bypassable `vm2` sandbox, allows attackers to achieve remote code execution, sandbox escape, denial of service, server-side request forgery, prompt injection, and server variable/data exfiltration.
Faraday: Uncontrolled Recursion in NestedParamsEncoder Allows Stack Exhaustion DoS
2 rules 1 TTPAn unauthenticated attacker can trigger a denial-of-service condition in applications using the Faraday Ruby library by sending deeply nested query parameters (CVE-2026-54297), leading to `SystemStackError` and application crashes due to uncontrolled recursion.
JupyterLab Git Extension Stored XSS to RCE (CVE-2026-54527)
2 rules 6 TTPsA stored cross-site scripting (XSS) vulnerability, identified as CVE-2026-54527, in the `jupyterlab-git` JupyterLab extension (versions >= 0.30.0b3, < 0.54.0a1), specifically in `PlainTextDiff.ts`, allows an adversary with Git commit access to execute arbitrary JavaScript in a victim's browser and achieve Remote Code Execution (RCE) on the JupyterLab server by crafting a malicious filename in a Git commit that, when viewed as a rename diff, triggers the XSS payload to steal `_xsrf` cookies, open a terminal, and execute arbitrary shell commands to exfiltrate data.
JupyterLab-Git excluded_paths Case-Sensitivity Bypass (CVE-2026-54528)
2 rules 4 TTPsAn authenticated user can bypass the admin-configured `excluded_paths` security control in `jupyterlab-git` versions up to 0.53.0 by exploiting a case-sensitivity flaw on case-insensitive filesystems (e.g., macOS APFS, Windows NTFS), allowing unauthorized read access to git history and file content in explicitly excluded directories.
Joomla com_booking Information Disclosure (CVE-2023-54357)
1 rule 2 TTPsAn unauthenticated information disclosure vulnerability (CVE-2023-54357) in the Joomla com_booking component version 2.4.9 allows attackers to enumerate user accounts, including names, usernames, and email addresses, by exploiting the getUserData function via specific GET requests.
AlchemyCMS: Unauthenticated Nested Page API Leaks Restricted & Unpublished Content
2 rulesAn unauthenticated API endpoint, `GET /api/pages/nested`, in Alchemy CMS versions up to 8.2.5 (including all 8.x versions prior to a fix and all 7.x versions up to 7.4.14), fails to enforce authorization and scoping checks, allowing any anonymous user to retrieve the complete page tree, encompassing restricted and unpublished pages, and, with `?elements=true`, the full content of these sensitive pages, completely bypassing intended access controls and leading to unauthorized information disclosure.
Joomla! Calendar Planner 1.0.1 SQL Injection (CVE-2017-20267)
1 rule 1 TTPAn unauthenticated attacker can exploit CVE-2017-20267, an SQL injection vulnerability in Joomla! Component Calendar Planner 1.0.1, by sending malicious GET requests to the 'events' view via the 'category_id' parameter, allowing for sensitive database information extraction.
Joomla! Component Flip Wall SQL Injection (CVE-2017-20265)
2 rules 3 TTPsAn SQL injection vulnerability, CVE-2017-20265, in Joomla! Component Flip Wall 8.0 allows unauthenticated attackers to execute arbitrary SQL queries via malicious GET requests to the `wallid` parameter, enabling the extraction of sensitive database information.
Joomla! FocalPoint Pro/Free SQL Injection (CVE-2017-20263)
1 rule 3 TTPs 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2017-20263) in Joomla! Component FocalPoint Pro/Free version 1.2.3 allows attackers to execute arbitrary SQL queries via a crafted 'id' parameter in GET requests, leading to sensitive database information disclosure.
CVE-2017-20262 — Joomla! Component Ajax Quiz SQL Injection
1 rule 3 TTPsAn unauthenticated SQL injection vulnerability, CVE-2017-20262, in Joomla! Component Ajax Quiz version 1.8 allows attackers to execute arbitrary SQL queries by injecting malicious code through the `cid` parameter in GET requests to `index.php` with `option=com_ajaxquiz` and `view=ajaxquiz`, leading to extraction of sensitive database information.
Joomla OSDownloads SQL Injection (CVE-2017-20259)
2 rules 3 TTPs 1 CVEAn unauthenticated SQL injection vulnerability (CVE-2017-20259) in Joomla OSDownloads version 1.7.4 allows attackers to execute arbitrary SQL queries via a crafted GET request to index.php, extracting sensitive database information like credentials and configuration data.
Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection (CVE-2017-20258)
1 rule 2 TTPs 1 CVEUnauthenticated attackers can exploit an SQL injection vulnerability (CVE-2017-20258) in Joomla! Component RPC Responsive Portfolio 1.6.1 by injecting malicious code through the 'id' parameter in GET requests, allowing the execution of arbitrary SQL queries and extraction of sensitive database information.
Joomla! Component JB Visa 1.0 SQL Injection (CVE-2017-20255)
2 rules 2 TTPsAn unauthenticated SQL injection vulnerability (CVE-2017-20255) in Joomla! Component JB Visa 1.0 allows attackers to execute arbitrary SQL queries by injecting malicious code via the 'visatype' parameter in GET requests to 'index.php?option=com_bookpro&view=popup', leading to the extraction of sensitive database information including credentials.
Joomla! User Bench Component SQL Injection (CVE-2017-20254)
1 rule 3 TTPsAn unauthenticated attacker can exploit CVE-2017-20254, an SQL injection vulnerability in the Joomla! Component User Bench 1.0, by sending crafted HTTP GET requests to extract sensitive database information including credentials and configuration data.
CVE-2017-20252: Joomla NextGen Editor SQL Injection
2 rules 4 TTPsJoomla NextGen Editor 2.1.0 contains an SQL injection vulnerability (CVE-2017-20252) that allows unauthenticated attackers to execute arbitrary SQL commands through the `plname` parameter in crafted GET requests to `index.php?option=com_nge&view=config`, leading to the extraction of sensitive database information.
Tilt: Cross-site WebSocket Hijacking Vulnerability (CVE-2026-55883)
3 rules 3 TTPsAn attacker can exploit CVE-2026-55883, a Cross-site WebSocket Hijacking vulnerability in Tilt versions 0.24.0 through 0.37.3, by acquiring an unauthenticated CSRF token or bypassing Origin header checks, to establish a WebSocket connection to a network-exposed Tilt HUD and exfiltrate sensitive developer session state, Tiltfile contents, and resource statuses.
gemini-mcp-tool Vulnerable to OS Command Injection and File Exfiltration (CVE-2026-0755)
2 rules 3 TTPsA critical vulnerability, CVE-2026-0755, in npm's gemini-mcp-tool package allows for OS command injection on Windows systems due to improper handling of unquoted cmd.exe metacharacters, and arbitrary local file exfiltration via the @file parser when processing untrusted prompt input, leading to potential remote code execution and sensitive data compromise.
Crawl4AI Unauthenticated RCE via Chromium Launch-Argument Injection
3 rules 2 TTPsAn attacker can achieve unauthenticated remote code execution (RCE) in Crawl4AI Docker deployments by injecting malicious Chromium launch arguments, such as `--utility-cmd-prefix` and `--no-zygote`, into the `browser_config.extra_args` field of the API request, allowing for arbitrary command execution as the container's runtime user.
Kirby: Self cross-site scripting (self-XSS) in the writer field (CVE-2026-49276)
2 rules 3 TTPsKirby CMS versions prior to 4.9.4 and between 5.0.0-alpha.1 and 5.4.3 are vulnerable to a self-cross-site scripting (self-XSS) flaw, CVE-2026-49276, in the writer field, allowing an attacker to inject malicious JavaScript as the target of a link or email link which, if clicked by an authenticated user before saving, will execute in their browser context, potentially making API requests with their permissions, while Panel plugins using the `<k-writer>` component may be vulnerable to stored XSS if they don't sanitize HTML.
Jupyter Server Stored XSS via Missing CSP Sandbox (CVE-2026-44727)
2 rules 4 TTPsA critical stored Cross-Site Scripting (XSS) vulnerability, CVE-2026-44727, exists in `jupyter_server` versions up to 2.19.0 due to a missing `sandbox` directive in Content-Security-Policy (CSP) headers, allowing authenticated attackers to craft malicious notebooks that exfiltrate victim tokens and achieve kernel Remote Code Execution (RCE) when viewed.
Critical Kirby CMS Vulnerability Allows Remote Admin Account Creation via Reverse Proxy Headers (CVE-2026-54003)
2 rules 2 TTPsA critical external initialization vulnerability (CVE-2026-54003) in Kirby CMS allows unauthenticated attackers to create an initial admin account on sites running behind a reverse proxy, specifically when the proxy utilizes `Forwarded: for=...`, `X-Client-IP`, or `X-Real-IP` headers, bypassing Kirby's `isLocal` check and enabling remote Panel installation with full administrative access.
PraisonAI Authentication Bypass via PRAISONAI_CALL_AUTH=disabled
2 rules 7 TTPsA high-severity authentication bypass vulnerability in PraisonAI versions prior to 4.6.61 allows unauthenticated attackers to invoke any registered agent by setting the `PRAISONAI_CALL_AUTH=disabled` environment variable, potentially leading to arbitrary code execution or system compromise.
CVE-2026-50107: NGINX Gateway Fabric Configuration Injection Vulnerability
2 rules 1 TTP 5 CVEs 2 IOCsAn injection vulnerability, CVE-2026-50107, exists in the NGINX configuration generator component of NGINX Gateway Fabric when configured with NGINX Plus or NGINX Open Source as the data plane, allowing authenticated attackers with CRD modification permissions to inject arbitrary NGINX configuration directives via unsanitized user-supplied string values in the access log format setting, leading to control plane compromise and potential defense evasion or system impact.
CVE-2026-49952: Discuz! X5.0 Authentication Bypass Leading to Database Access
2 rules 6 TTPs 1 CVE 1 IOCCVE-2026-49952 is an authentication bypass vulnerability in Discuz! X5.0 versions 20260320 through 20260501, allowing unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key, leading to potential data exfiltration and user impersonation.
Vite Dev Server `server.fs.deny` Bypass on Windows (CVE-2026-53571)
2 rules 1 TTP 1 CVE 3 IOCsA high-severity vulnerability (CVE-2026-53571) in the Vite development server on Windows allows threat actors to bypass `server.fs.deny` restrictions, leading to information disclosure of sensitive files like `.env` or `tls.pem` via crafted HTTP requests utilizing NTFS Alternate Data Streams or 8.3 short names, impacting applications that expose the dev server to the network.
Multiple Vulnerabilities in Typo3 Leading to RCE, Privilege Escalation, and Data Compromise
3 rules 6 TTPs 5 CVEs 20 IOCsMultiple vulnerabilities discovered in Typo3 allow an attacker to achieve remote arbitrary code execution, privilege escalation, data confidentiality compromise, data integrity compromise, security policy bypass, remote indirect code injection (XSS), and SQL injection (SQLi).
Path Traversal Vulnerability in WilliamCloudQi matlab-mcp-server
2 rules 1 TTP 1 CVEA path traversal vulnerability exists in WilliamCloudQi matlab-mcp-server up to version ab88f6b9bf5f36f725e8628029f7f6dd0d9913ca, allowing a remote attacker to manipulate the scriptPath argument in the generate_matlab_code/execute_matlab_code function to access arbitrary files.