Tag
Krayin CRM v2.2.x Authenticated Remote Code Execution Exploit
1 TTPA public exploit (EDB-52629) has been released for Krayin CRM v2.2.x, demonstrating an authenticated remote code execution vulnerability that allows an authenticated attacker to execute arbitrary code on the underlying system, significantly increasing the risk for unpatched deployments of the web application.
Joomla Page Builder CK Arbitrary File Upload (EDB-52626)
3 TTPsA public exploit has been released for an arbitrary file upload vulnerability in Joomla Page Builder CK version 3.5.10, which allows an unauthenticated attacker to upload malicious files to the server, potentially leading to remote code execution and full system compromise.
Public Exploit for MCPJam Inspector Remote Code Execution (EDB-52625)
2 TTPsA public exploit (EDB-52625) has been published for the web application MCPJam Inspector, demonstrating a Remote Code Execution vulnerability, significantly elevating the risk for unpatched systems and allowing attackers to execute arbitrary code.
Flowise 3.1.3 Arbitrary Code Execution Exploit Published
2 TTPsA critical arbitrary code execution vulnerability in Flowise version 3.1.3 and earlier has been publicly disclosed on Exploit-DB, enabling unauthenticated attackers to execute arbitrary commands on unpatched web application instances, leading to full system compromise.
WordPress Bricks Builder Theme - Unauthenticated RCE (CVE-2024-25600)
1 rule 2 TTPs 1 CVE 4 IOCsAn unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2024-25600) exists in the WordPress Bricks Builder Theme up to version 1.9.6, allowing attackers to exploit the 'render_element' endpoint by first extracting a nonce from the page source, then injecting PHP code to execute arbitrary operating system commands on the underlying web server, with a public exploit now available.
JoomShaper SP LMS PHP Object Injection Leads to RCE (CVE-2026-48909)
1 rule 3 TTPs 1 CVEA critical PHP object injection vulnerability (CVE-2026-48909) in JoomShaper SP LMS versions <= 4.1.3 allows unauthenticated attackers to achieve remote code execution (RCE) via a crafted 'lmsOrders' cookie, leading to webshell deployment on vulnerable Joomla installations (< 5.2.2).
KeepInMind 0.8.4.2 - Stored XSS Public Exploit
1 TTPA public exploit has been published for a Stored XSS vulnerability in KeepInMind version 0.8.4.2, significantly increasing the risk for unpatched installations.
WordPress WPZOOM Portfolio Plugin XSS Vulnerability (CVE-2026-49069)
1 rule 2 TTPs 1 CVE 2 IOCsA critical reflected cross-site scripting (XSS) vulnerability, CVE-2026-49069, affects the WPZOOM Portfolio plugin (version 1.4.21 and earlier) for WordPress, enabling unauthenticated attackers to inject malicious JavaScript into web pages via the `wpzoom_load_more_items` AJAX action, leading to client-side script execution in victims' browsers.
Langflow 1.3.0 Remote Code Execution Vulnerability
1 rule 1 TTP 5 IOCsLangflow 1.3.0 contains a remote code execution vulnerability (CVE-2026-0770) due to untrusted input in the exec_globals parameter at the validate endpoint, allowing remote attackers to execute arbitrary code as root without authentication, as demonstrated by a public exploit.
MixPHP Framework 2.2.17 Unsafe Deserialization Remote Code Execution
2 rules 1 TTPMixPHP Framework 2.2.17 is vulnerable to remote code execution due to unsafe deserialization, with a public exploit available, increasing the risk for unpatched systems.
EspoCRM 9.3.3 SSRF Vulnerability (CVE-2026-33534)
2 rules 1 TTP 1 CVEA public exploit is available for EspoCRM 9.3.3, exploiting a Server-Side Request Forgery (SSRF) vulnerability (CVE-2026-33534) allowing authenticated attackers to potentially access internal resources.
Casdoor 3.54.1 Arbitrary File Write via Path Traversal
2 rules 1 TTPCasdoor version 3.54.1 is vulnerable to a path traversal attack, allowing arbitrary file writes on the system, with a public exploit available.
OpenCATS 0.9.7.4 SQL Injection Vulnerability
2 rules 1 TTPA SQL Injection vulnerability exists in OpenCATS 0.9.7.4, with a published exploit that allows for database version and user extraction on unpatched systems.
WordPress Temporary Login Plugin Authentication Bypass Vulnerability
2 rules 1 TTPA public exploit is available for WordPress Temporary Login Plugin version 1.0.0, which demonstrates an authentication bypass vulnerability that can lead to account takeover, increasing the risk for unpatched systems.
SolarEdge CSRF and Out-of-Band Injection Vulnerability
2 rules 1 TTP 1 IOCA CSRF-OOB-Injection vulnerability exists in SolarEdge Monitoring Platform's `/solaredge-web/p/initClient` endpoint due to improper validation of session parameters, allowing attackers to manipulate headers to initiate requests to attacker-controlled domains, potentially leading to session compromise and unauthorized system control.
BookStack 25.12.1 Denial-of-Service Vulnerability
2 rules 1 TTPA denial-of-service vulnerability exists in BookStack version 25.12.1, and a public exploit (EDB-52571) is available, increasing the risk to unpatched systems.
Cockpit 359 Remote Code Execution Vulnerability
2 rules 1 TTPCockpit version 359 is vulnerable to remote code execution, and a public exploit is available on Exploit-DB, increasing the risk for unpatched systems.
ePati Antikor NGFW 2.0.1301 Authentication Bypass Vulnerability
1 rule 1 TTPA public exploit has been published for ePati Antikor NGFW 2.0.1301, exploiting an authentication bypass vulnerability, increasing the risk to unpatched systems.
Apache HertzBeat 1.8.0 Remote Code Execution Vulnerability
2 rules 1 TTPApache HertzBeat 1.8.0 is vulnerable to remote code execution due to a newly published exploit, posing a significant risk to unpatched systems.
Bludit CMS 3.18.4 Remote Code Execution Vulnerability
2 rules 1 TTPA remote code execution vulnerability exists in Bludit CMS 3.18.4, for which a public exploit has been published, increasing the risk to unpatched systems.
LuaJIT 2.1.1774638290 Arbitrary Code Execution Vulnerability
2 rules 1 TTPA public exploit has been published for LuaJIT version 2.1.1774638290, enabling arbitrary code execution on vulnerable web applications.
Ghost CMS 6.19.0 SQL Injection Vulnerability
2 rules 1 TTPA SQL injection vulnerability exists in Ghost CMS 6.19.0, and a public exploit (EDB-52555) is available, increasing the risk to unpatched systems.