All PoCs
subscribe (RSS)All proof-of-concept entries in the archive.
Entries
745
in the archive
CISA KEV
116
exploited in the wild
Ransomware
33
known campaign use
Unpatched
300
no vendor fix
Critical
367
49% of listed
Severity
Exploitation signals
Patch status
Date range
745 result(s)
- CVE-2026-21508 binary HIGH 7.8
Windows Media Player DLL Hijack -- Local Privilege Escalation (CVE-2026-21508)
CVE-2026-21508 is a DLL hijacking vulnerability that achieves Session 0 privilege escalation on Windows 11. WUDFHost.exe loads CrossDevice.Streaming.Source.dll from the user-writable path C:\ProgramData\CrossDevice\. By planting a malicious DLL and…
Patched 2026-08-16 - CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 network CRITICAL 10 KEV EPSS 87%
UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
CVE-2026-34910 is an unauthenticated command injection vulnerability in Ubiquiti UniFi OS Server, rated CVSS 10.0 and listed in CISA KEV. The nginx auth layer treats any request whose raw URI starts with /api/auth/validate-sso/ as public, but routes by the…
Patched 2026-08-16 - CVE-2026-68398 binary HIGH 7.8
Ubuntu Linux Kernel PPPoL2TP Use-After-Free Local Privilege Escalation (CVE-2026-68398)
CVE-2026-68398 is a use-after-free race condition between PPPoL2TP receive processing and destruction of a bound-but-unattached PPP channel in the Linux kernel. The PPPoX socket and its embedded pppchannel are RCU-safe, but the internal struct channel used by…
Patched 2026-08-16 - CVE-2026-17544 / GHSA-x692-q9x7-8c3f web CRITICAL 9.8
PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 is an out-of-bounds write vulnerability in the PHP bcmath extension, specifically in the bcstr2num() function in ext/bcmath/libbcmath/src/str2num.c. When the manual scale is smaller than the auto scale, the fraction is truncated and a…
Unverified 2026-08-16 - CVE-2026-42533 web CRITICAL 9.8
nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 is a heap buffer overflow in nginx triggered by PCRE regex capture variable handling. When two map directives share the same capture group name, a length/value mismatch occurs in the internal variable copy code (ngxhttpscriptcopycapturecode and…
Unverified 2026-08-16 - CVE-2026-23111 binary HIGH 7.8
Linux nf_tables Catchall Set Element UAF -- Local Privilege Escalation (CVE-2026-23111)
CVE-2026-23111 is a use-after-free in the Linux nftables subsystem caused by an inverted genmask check in nftmapcatchallactivate(). During transaction abort, the handler skips inactive catchall elements that need reactivation and processes active ones that do…
Unverified 2026-08-16 - CVE-2026-53361 binary CRITICAL 9.8
Linux AF_UNIX GC vs MSG_PEEK Use-After-Free Container Escape (CVE-2026-53361)
CVE-2026-53361 is a use-after-free in the Linux AFUNIX socket garbage collector triggered via a MSGPEEK race. The GC reclaims in-flight sockets forming unreachable reference cycles, but a concurrent MSGPEEK can take a reference the GC census never counts. The…
Unverified 2026-08-16 - CVE-2026-2764 / MFSA 2026-13 binary HIGH 8.8
Firefox SpiderMonkey JIT Miscompilation and Use-After-Free (CVE-2026-2764)
CVE-2026-2764 is a JIT miscompilation vulnerability in Firefox SpiderMonkey (IonMonkey/Baseline) that leads to type confusion and use-after-free. On new Ctor(...arr) / Reflect.construct with a Proxy as newTarget, the proxy get trap fires while the engine is…
Unverified 2026-08-16 - CVE-2026-8452 network CRITICAL 9.8
Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)
CVE-2026-8452 is a pre-authentication heap buffer overflow in the Citrix NetScaler ADC and Gateway SAML authentication handler. The vulnerability exists in the XML Signature Canonicalization (C14N) processing of the PrefixList attribute within SAML responses.…
Patched 2026-08-16 - CVE-2026-20200 / NSIDE-SA-2026-003 network CRITICAL 9.9
Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)
CVE-2026-20200 is an argument injection vulnerability in Cisco IMC that allows an authenticated user to achieve root-level RCE. The Redfish API SSH key upload handler (ManagerAccount.UploadSSHKey) passes the KeyURI parameter to curl without sanitization. An…
Patched 2026-08-16 - CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web CRITICAL 10
Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 is an internal metadata spoofing vulnerability in Apache Traffic Server. ATS uses @-prefixed headers (e.g., @Ats-Internal, @ICAP-Status, @TCPInfo) as internal metadata that lives in the in-memory header structure but is never serialized on the…
Unverified 2026-08-16 - CVE-2026-47301 network CRITICAL 9.8
Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
CVE-2026-47301 is a remote code execution vulnerability in Microsoft Configuration Manager (SCCM) that chains four weaknesses: broken access control on the AdminService UploadExtensionInChunks endpoint (any domain user, no RBAC check), CAB extraction…
Unverified 2026-08-15 - CVE-2026-64564 binary HIGH 7.8
Linux Kernel — SCTPhantom: SCTP ASCONF DEL-IP Use-After-Free Local Privilege Escalation (CVE-2026-64564)
CVE-2026-64564 is a use-after-free vulnerability in the Linux kernel SCTP ASCONF DEL-IP processing. When a multihomed SCTP association processes an ASCONF chunk that deletes an IP address, the associated transport structure is freed but a dangling pointer…
Unverified 2026-08-15 - CVE-2026-68138 binary HIGH 7.8
Linux Kernel — qdisc Rate-Table Race Condition Local Privilege Escalation (CVE-2026-68138)
CVE-2026-68138 is a race condition in the Linux kernel traffic-control rate-table code that leads to a use-after-free or double-free of struct qdiscratetable. The flower classifier sets TCFPROTOOPSDOITUNLOCKED, allowing RTMNEWTFILTER requests to reach…
Patched 2026-08-15 - CVE-2026-64531 binary HIGH 7.8
Linux Kernel — OVSwrap: Open vSwitch Conntrack Local Privilege Escalation (CVE-2026-64531)
CVE-2026-64531 is a memory corruption vulnerability in the Linux kernel Open vSwitch (OVS) conntrack subsystem. The exploit, named OVSwrap, uses OVS Generic Netlink operations to corrupt conntrack timeout and labels carrier objects, establishing kernel read…
Unverified 2026-08-15 - CVE-2026-17106 binary CRITICAL 9.8
Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
CVE-2026-17106, nicknamed CopyEscape, is a race condition in Docker's docker cp command that allows a malicious running container to escape and write arbitrary files on the Docker host. The vulnerability exists in how Docker's archive producer walks the…
Unverified 2026-08-15 - CVE-2026-27912 network HIGH 8
Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)
CVE-2026-27912, nicknamed ResetNightmare by Semperis, is a validation flaw in the Kerberos Change Password protocol that allows an attacker to reset the password of any user or computer account in Active Directory — including Domain Admins, the krbtgt…
Unverified 2026-08-11 - Bypass of CVE-2026-50656 binary HIGH 7.8 EPSS 11%
Windows Defender — ShieldBreak: RoguePlanet (CVE-2026-50656) Patch Bypass via Cloud Files Rehydration + Object Manager Symlinks
ShieldBreak is a 0-day local privilege escalation exploit that bypasses the patch for CVE-2026-50656 (RoguePlanet), achieving SYSTEM-level code execution from an unprivileged user on fully patched Windows 11 and Server 2025 systems. The exploit was released…
Unpatched 2026-08-11 - CVE-2026-25177 network HIGH 8.8
Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)
CVE-2026-25177 is a privilege escalation vulnerability in Active Directory Domain Services caused by improper restriction of Unicode characters in Service Principal Names (SPNs). An authenticated user with write-SPN permissions can inject Unicode zero-width…
Patched 2026-08-11 - CVE-2026-64561 binary HIGH 8.8
Zapscape — KVM/x86 Shadow-MMU Recursive-Zap Guest-to-Host Escape (CVE-2026-64561)
Zapscape (CVE-2026-64561) is a use-after-free in the KVM/x86 shadow MMU that lets a guest which uses nested virtualization escape to the host and run commands as the host kernel (root). Using guest-side actions alone, an attacker makes KVM recursively zap a…
Patched 2026-08-09 - CVE-2026-64638 web HIGH 8.9
WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")
CVE-2026-64638 — nicknamed XSS2Shell by its discoverers at pwn.ai — is a pre-authentication reflected XSS in the WordPress login page that chains through five to seven stages into full remote code execution on the server. It is one of the most impactful…
Unverified 2026-08-09 - CVE-2026-63077 web CRITICAL 9.8 KEV
TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077)
CVE-2026-63077 is an unauthenticated remote code execution vulnerability in JetBrains TeamCity. The agent polling subsystem accepts XML payloads from unregistered agents and deserializes them with XStream without any authentication or sanitization. An…
Patched 2026-08-09 - CVE-2025-61882 web CRITICAL 9.8 KEV Ransomware EPSS 100%
Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)
CVE-2025-61882 is an unauthenticated remote code execution chain in Oracle E-Business Suite 12.2.3 through 12.2.14. An attacker POSTs an XML document to the unauthenticated /OAHTML/configurator/UiServlet endpoint; the servlet extracts a returnurl element from…
Patched 2026-08-09 - MDEV-40328 binary CRITICAL 8.8
MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free
This PoC chains two MariaDB memory-safety bugs to achieve remote code execution as the mariadbd process from a low-privilege database account — no special grants, no filesystem access, no administrative role:
Unpatched 2026-08-09 - CVE-2023-35078 network CRITICAL 9.8 KEV Ransomware EPSS 100%
Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)
Ivanti Endpoint Manager Mobile (EPMM, formerly MobileIron Core) fails to enforce authentication on specific paths beneath its /mifs/aad/api/ administrative API. An unauthenticated remote attacker can issue a plain GET…
Unverified 2026-08-09 - CVE-2025-22457 network CRITICAL 9 KEV Ransomware EPSS 100%
Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)
CVE-2025-22457 is a remote, pre-authentication stack-based buffer overflow (CWE-121) in the HTTPS request-handling path of Ivanti Connect Secure and sibling appliances. A single oversized X-Forwarded-For request header overflows a fixed-size stack buffer in…
Unpatched 2026-08-09 - CVE-2021-22205 web CRITICAL 10 KEV Ransomware EPSS 100%
GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)
GitLab Workhorse intercepts multipart file uploads and strips image metadata by shelling out to ExifTool before the request is routed to Rails and therefore before any authentication or authorization decision is made. ExifTool in turn contained…
Patched 2026-08-09 - CVE-2026-60004 web HIGH 8.8
Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)
CVE-2026-60004 is an authenticated remote code execution vulnerability in the Gitea diffpatch API. The endpoint applies a supplied patch with git apply --cached, which should only update the index and never write files to disk. However, by sending the same…
Patched 2026-08-09 - CVE-2026-18718 misc HIGH 7.5
Ghidra — Swift Demangler Arbitrary Code Execution via Shared Project Files (CVE-2026-18718)
Opening someone else's Ghidra project is enough to execute their code — with no prompt, no signature check, and no integrity verification.
Patched 2026-08-09 - CVE-2024-51378 web CRITICAL 10 KEV Ransomware EPSS 95%
CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)
CyberPanel exposes two DNS/FTP reset-status endpoints, /dns/getresetstatus and /ftp/getresetstatus, whose handlers read a JSON statusfile property straight out of the request body and concatenate it into a shell command executed with sudo. Neither handler…
Patched 2026-08-09 - CVE-2026-16232 network CRITICAL 9.1 KEV EPSS 71%
Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)
CVE-2026-16232 is an unauthenticated authentication bypass (CWE-287) in the Check Point SmartConsole login path on Security Management and Multi-Domain Management servers. During the legacy SIC/CPMI bootstrap the management server volunteers its own SIC…
Patched 2026-08-09 - CVE-2026-64640 cloud HIGH 8.1
Apache Polaris — Cross-Tenant Credential Vending Before Location Validation in Iceberg REST Register (CVE-2026-64640)
CVE-2026-64640 is a confused-deputy vulnerability in Apache Polaris: the Iceberg REST register endpoints mint cloud storage credentials for a caller-supplied path and read that path server-side before checking it against the catalog's allowedLocations. A…
Patched 2026-08-09 - NotCVE-2026-0010 binary HIGH
Barrier 2.4.0 — barrierd.exe Unauthenticated IPC → SYSTEM Privilege Escalation (NotCVE-2026-0010)
Barrier 2.4.0 ships a Windows service daemon (barrierd.exe) that runs as LocalSystem and binds a TCP IPC control server on 127.0.0.1:24801 with no authentication. Any local process, regardless of privilege level, can connect to that port and send a…
Unverified 2026-08-01 - CVE-2026-65694 web HIGH 7.5
Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
Microweber CMS exposes an unauthenticated GET /userfiles/{path} route intended to serve files from its userfiles/ upload directory. The controller reads the path via $request->path — a Laravel magic-property accessor that falls back to the request's…
Patched 2026-07-31 - CVE-2026-9198 web CRITICAL 9.8 KEV EPSS 17%
IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)
IBM Langflow OSS ships an /api/v1/autologin endpoint that, when the deployment has LANGFLOWAUTOLOGIN enabled (a common/default posture), will mint and hand back a fully-privileged SUPERUSER JWT access token to any caller — no credentials, no session, nothing.…
Patched 2026-07-31 - CVE-2022-40684 network CRITICAL 9.8 KEV Ransomware EPSS 100%
CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)
CVE-2022-40684 is an authentication-bypass vulnerability in the web management interface of FortiOS, FortiProxy, and FortiSwitchManager that allows an unauthenticated remote attacker to access the administrative REST API. The affected firmware fails to…
Unverified 2026-07-31 - CVE-2025-32432 web CRITICAL 10 KEV EPSS 100%
Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)
Craft CMS shipped an incomplete patch for the earlier CVE-2023-41892 deserialization RCE, leaving a critical, pre-auth code-injection chain exploitable through the assets/generate-transform action. An unauthenticated attacker first poisons the server-side PHP…
Patched 2026-07-31 - CVE-2025-54988 web CRITICAL 9.8
Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)
Apache Tika's PDF parser processes an embedded XFA (XML Forms Architecture) form's XML content with external entity resolution enabled. A crafted PDF whose AcroForm dictionary contains an /XFA key pointing to a stream object holding malicious XFA XML can…
Patched 2026-07-31 - CVE-2026-16723 web CRITICAL 9
Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723)
CVE-2026-16723 is a critical, unauthenticated remote code execution vulnerability in Alibaba Fastjson 1.2.68 through 1.2.83, actively exploited in the wild against Spring Boot fat-JAR deployments. Under Fastjson stock defaults (AutoType disabled, SafeMode…
Unpatched 2026-07-31 - CVE-2026-49176 binary HIGH 7.8
Windows WalletService Known-Folder Redirection → ESE Persisted-Callback DLL Load Local Privilege Escalation (CVE-2026-49176)
Windows WalletService — which runs as LocalSystem — resolves the caller's FOLDERIDDocuments known folder while impersonating the calling user, then reverts to the LocalSystem token before opening <Documents>\Wallet\wallet.db. Because the folder resolution…
Patched 2026-07-27 - CVE-2026-54992 network HIGH 8.4
Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)
MSMQ's Queue Manager processes RStartReceive/RStartTransactionalReceive responses from the MS-MQRR RPC interface as a set of SectionBuffer structures, each carrying its own SectionSizeAlloc. When a remote-read response is split into multiple sections,…
Patched 2026-07-27 - CVE-2026-66066 web CRITICAL 9.5
Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)
Rails Active Storage hands untrusted, attacker-supplied image uploads directly to libvips for variant/representation generation without disabling libvips' "unfuzzed" (i.e. not hardened against malicious input) loaders, specifically the MATLAB/HDF5 matload…
Patched 2026-07-27 - CVE-2026-56423 web HIGH 8.8
MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports & Sharing Groups (CVE-2026-56423)
MISP's bulk-deletion endpoints for Event Reports (/eventReports/deleteSelection) and Sharing Groups (/sharingGroups/deleteSelection) authorize each selected item using a checkModifyCallback that discards the item id and instead returns the acting user's…
Patched 2026-07-27 - CVE-2026-50522 web CRITICAL 9.8 KEV EPSS 77%
Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)
SharePoint's WS-Federation passive sign-in endpoint (/trust/default.aspx) accepts a wresult parameter containing a WS-Trust RequestSecurityTokenResponse that can carry a SecurityContextToken with an embedded Cookie value. Windows Identity Foundation's…
Patched 2026-07-27 - CVE-2026-57830 web CRITICAL 9.1
Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
Helix Ultimate's plugins/system/helixultimate/src/Platform/Media.php exposes deleteMedia() and getFolders() through the Joomla comajax dispatch hook (onAfterRoute()), reachable via option=comajax&helix=ultimate&action=delete-media/view-media. These methods…
Patched 2026-07-27 - CVE-2026-56291 web CRITICAL 9.8 KEV EPSS 76%
Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)
Balbooa Forms is a popular drag-and-drop form builder extension for Joomla!. Its form.uploadAttachmentFile task — reachable via the unauthenticated combaforms component entry point — accepts multipart file uploads for form attachments but performs neither a…
Unverified 2026-07-27 - CVE-2026-46316 binary CRITICAL 9.3
ITScape — KVM/arm64 vGIC-ITS Guest-to-Host VM Escape (CVE-2026-46316)
ITScape (CVE-2026-46316) is a use-after-free in the KVM/arm64 in-kernel vGIC-ITS (Interrupt Translation Service) emulation that lets an unprivileged-but-rooted guest VM escape to the host and execute code as the host kernel (i.e., as root on the host), on any…
Patched 2026-07-27 - N/A binary HIGH
GreatXML — WinRE / Defender Offline-Scan Trust-Boundary Abuse → BitLocker Bypass (No CVE)
GreatXML abuses the trust boundary around Microsoft Defender's Offline Scan feature, which reboots a Windows machine into WinRE (Windows PE) and runs OfflineScannerShell.exe with elevated, pre-BitLocker-unlock trust. The ReAgent.xml recovery-configuration…
Unpatched 2026-07-27 - N/A web CRITICAL
GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
GitLab renders diffs for Jupyter notebooks by passing repository-controlled JSON through Oj, a native (C-extension) Ruby JSON parser, in the Puma worker process. The researcher (Yuhang Wu, depthfirst.com) found and chained two distinct memory-corruption bugs…
Unverified 2026-07-27 - CVE-2026-53753 web CRITICAL 9.8
Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
Crawl4AI's JsonCssExtractionStrategy supports "computed fields" — small Python expressions evaluated against each extracted item via safeevalexpression(). That function tries to sandbox the expression with an AST allow-list (rejecting only…
Patched 2026-07-27 - N/A social-engineering HIGH
ClickFix Social-Engineering Technique — Fortinet-Branded Multi-Stage Lure (Fake File-Access Page + Fake CAPTCHA + Clipboard Injection)
This entry documents a second ClickFix-style social-engineering demo, distinct from other ClickFix variants in this archive: a multi-stage lure that opens with a Fortinet-branded fake "Secure File Access" page (index.html) requesting a work email, then…
Unverified 2026-07-27 - N/A social-engineering HIGH
ClickFix Social Engineering Technique — Fake Cloudflare Turnstile Just a Moment Verification Lure
ClickFix is a widely reported in-the-wild social-engineering technique in which a fake CAPTCHA or "verification" page tricks a victim into copying an attacker-controlled command (silently injected into the clipboard by the page) and pasting/executing it…
Unverified 2026-07-27 - N/A social-engineering HIGH
ClickFix Fake-CAPTCHA Social-Engineering Kit with IP Fencing and 19-Language Localization
This is a fork of 0x204/ClickFix-Turnstile that adds two enhancements: real IP allow/block fencing at the Cloudflare Worker edge (checking the cf-connecting-ip request header against a hardcoded ALLOWEDIPS[] array before serving content), and genuine…
Unverified 2026-07-27 - N/A social-engineering HIGH
ClickFix Fake reCAPTCHA to mshta/HTA Execution Chain
This is a reference implementation of ClickFix, a widely used real-world social-engineering technique (reported by Unit42, Huntress, and Orange CyberDefense as used by numerous threat actors since roughly 2024, including in LummaStealer and Emmenhtal malware…
Unverified 2026-07-27 - CVE-2026-54350 web CRITICAL 10
Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
Budibase queries interpolate user-supplied parameters directly into a query's raw JSON body via Handlebars, then JSON.parse the result. The only input filter blocks Handlebars markers ({{/}}) but does not block ", \, } or $ — so a parameter value containing a…
Patched 2026-07-27 - CVE-2026-49230 web CRITICAL 9.1
Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
The jwe-decrypt plugin is an auth-type APISIX plugin that decrypts an incoming JWE token with a per-consumer AES-256-GCM secret and forwards the plaintext upstream as proof of authentication. Its internal helper jwedecryptwithobj() returns only the decrypted…
Patched 2026-07-27 - CVE-2026-54121 network HIGH 8.8
AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)
CertiGhost (CVE-2026-54121) abuses a "chase" mechanism in AD CS certificate enrollment: when a certificate request carries a cdc (chase domain controller) attribute pointing at an attacker-controlled IP alongside an rmd (remote machine DNS) attribute naming a…
Patched 2026-07-27 - CVE-2026-63030 web CRITICAL 9.1 KEV EPSS 96%
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
A two-bug chain in stock WordPress core — no plugins, no misconfiguration, no special DB privileges required — that goes from a single unauthenticated HTTP request to a new administrator account and remote code execution. The always-true primitive is…
Patched 2026-07-19 - CVE-2026-14431 binary HIGH 8.8
V8 Array Iterator Maglev Type Confusion — addrof/fakeobj Primitives (CVE-2026-14431)
Array.prototypeSymbol.iterator.next() is miscompiled by V8's Maglev JIT tier: ArrayIteratorPrototypeNext fails to re-check the map (elements kind) of an inlined array after a side effect can change it mid-call, leading to a type confusion between…
Unpatched 2026-07-19 - CVE-2026-48558 web CRITICAL 10 KEV EPSS 11%
SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)
When OIDC (OpenID Connect) authentication is configured on a SimpleHelp server, the server accepts identity tokens (JWTs) submitted during login without verifying their cryptographic signature. A remote, unauthenticated attacker can forge a token containing…
Patched 2026-07-19 - CVE-2026-58116 web CRITICAL 9.8
LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
LLaMA-Factory's WebUI hardcodes trustremotecode=True whenever it loads a model (src/llamafactory/webui/chatter.py:139 and runner.py:175,320). The "Model path" field — fully attacker/user-controlled — flows unvalidated into AutoTokenizer.frompretrained() /…
Patched 2026-07-19 - binary HIGH
LegacyHive - Windows user profile service arbitrary hive load elevation of privileges vulnerability
LegacyHive demonstrates a local privilege-escalation path in Windows user profile hive handling where a low-privileged user can influence how another user's hive is loaded. The PoC modifies hive data and abuses object manager links and an oplock timing window…
Patched 2026-07-19 - CVE-2026-55255 web HIGH 8.4 KEV EPSS 29%
Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)
Langflow's OpenAI-compatible Responses API (POST /api/v1/responses) accepts a model field that Langflow interprets as a flow ID to execute. The endpoint fails to verify that the API key making the request actually owns the flow ID supplied — so any…
Patched 2026-07-19 - CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%
Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)
Cisco Unified Communications Manager's WebDialer service, when enabled, contains an improper-input-validation flaw that allows an unauthenticated remote attacker to conduct server-side request forgery (SSRF) attacks by sending crafted HTTP requests.…
Patched 2026-07-19 - CVE-2026-48282 web CRITICAL 10 KEV EPSS 99%
Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)
Adobe ColdFusion's Remote Development Service (RDS), a legacy feature that lets IDEs like Dreamweaver remotely browse, read, and write files on a ColdFusion server, is reachable via the /CFIDE/main/ide.cfm endpoint using a simple length-prefixed text…
Patched 2026-07-19 - CVE-2026-15409 network CRITICAL 10 KEV Ransomware EPSS 78%
SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)
The SMA1000 WorkPlace interface exposes a websocket-based remote-access proxy (wsproxy) that lets an authenticated remote-access session request a proxied connection to a destination host/port/service combination (e.g. SSH, TELNET). The proxy does not…
Patched 2026-07-15 - network HIGH
OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)
OpenSSH's ssh-agent supports being locked with a password, during which it is supposed to refuse essentially all requests — including the session-bind@openssh.com extension that a forwarded agent connection uses to record which remote session it belongs to.…
Unpatched 2026-07-12 - CVE-2026-56271 web CRITICAL 9.8
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
Flowise's enterprise passport authentication middleware signs and verifies JWTs using values pulled from environment variables (JWTAUTHTOKENSECRET, JWTREFRESHTOKENSECRET, JWTAUDIENCE, JWTISSUER). When an operator doesn't set these — an easy oversight in a…
Patched 2026-07-12 - CVE-2026-56260 web CRITICAL 9.1
Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
Crawl4AI's Docker API server exposes /screenshot and /pdf endpoints that accept an outputpath parameter specifying where the rendered output should be saved. The parameter is passed straight into a file-write call with no validation whatsoever — no check for…
Patched 2026-07-12 - CVE-2023-38950 web HIGH 7.5 KEV EPSS 85%
ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)
ZKTeco BioTime v8.5.5 exposes the iclock device-communication API endpoint (/iclock/file) without authentication. The url query parameter, which is meant to reference firmware/log filenames pulled by physical biometric terminals, is concatenated into a…
Patched 2026-07-11 - CVE-2026-48939 web CRITICAL 9.8 KEV EPSS 83%
Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)
iCagenda's frontend event-registration form includes an optional file-attachment field. The "Registered Only" access restriction meant to gate that field is enforced only in the view layer that decides whether to render the form — the registration.submit…
Patched 2026-07-11 - CVE-2021-42237 web CRITICAL 9.8 KEV Ransomware EPSS 98%
Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)
Sitecore Experience Platform ships a legacy, unused reporting handler at /sitecore/shell/ClientBin/Reporting/Report.ashx that is reachable without authentication. The handler deserializes an attacker-supplied XML <parameters> block using…
Patched 2026-07-11 - CVE-2021-25296 web HIGH 8.8 KEV EPSS 72%
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)
Nagios XI's "Windows WMI" configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php) builds a WMI-check shell command using several attacker-supplied HTTP parameters, including pluginoutputlen. The value is never…
Patched 2026-07-11 - CVE-2021-25297 web HIGH 8.8 KEV EPSS 56%
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)
Nagios XI's "Switch" configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php) generates an MRTG configuration snippet for the monitored switch and writes it into an MRTG config file using a shell sed command built from…
Patched 2026-07-11 - CVE-2021-25298 web HIGH 8.8 KEV EPSS 75%
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)
Nagios XI's "Cloud/VM" configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php) performs a reachability check against an attacker-supplied host address by shelling out to ping. The address parameter is concatenated…
Patched 2026-07-11 - CVE-2026-42208 web CRITICAL 9.8 KEV EPSS 89%
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
LiteLLM Proxy authenticates API requests by checking that the Authorization: Bearer token starts with sk-. When a caller sends a token that does not start with sk-, that assertion fails — but instead of simply rejecting the request, the raw, unhashed token is…
Patched 2026-07-11 - CVE-2026-20896 web CRITICAL 9.8 EPSS 32%
Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
Gitea supports reverse-proxy authentication: put it behind a proxy that sets an X-WEBAUTH-USER header, and Gitea trusts that header for the username, gated by REVERSEPROXYTRUSTEDPROXIES — an IP allowlist meant to ensure only the actual proxy can set that…
Patched 2026-07-11 - CVE-2022-26258 network CRITICAL 9.8 KEV EPSS 80%
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
D-Link DIR-820L firmware 1.05B03 contains an OS command injection (CWE-78) in the router's /getset.ccp LAN-configuration handler. The lanHostCfgDeviceName1.1.1.0 parameter (submitted from the "Device Name" field on the lan.asp LAN setup page) is filtered by…
Unverified 2026-07-11 - network CRITICAL
XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
XRING is a remote, unauthenticated crash in XQUIC (Alibaba's QUIC/HTTP-3 library) triggered by fully spec-compliant QPACK dynamic-table encoder-stream instructions. A single incorrect variable in xqcringmemresize() (src/common/utils/ringmem/xqcringmem.c)…
Unpatched 2026-07-08 - CVE-2026-43499 binary HIGH 7.8
Linux Kernel rtmutex Priority-Inheritance Stack-UAF — "GhostLock" (CVE-2026-43499, Nebula Security weaponized variant)
Nebula Security independently discovered and weaponized a use-after-free in the Linux kernel's rtmutex priority-inheritance cleanup logic, naming it "GhostLock." They describe it as a stack-UAF reachable via ordinary threading/futex calls from any…
Patched 2026-07-08 - CVE-2025-24893 web CRITICAL 9.8 KEV EPSS 100%
XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki, caused by the built-in SolrSearch macro (Main.SolrSearch) passing user-supplied search input into a Groovy evaluation context without sanitization. By crafting a GET…
Patched 2026-07-06 - CVE-2025-54322 network CRITICAL 10 EPSS 14%
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
XSpeeder SXZOS firmware exposes a Django-based web endpoint that passes a base64-decoded, attacker-controlled chkid query parameter into Python's eval(). Because there is no authentication check on this endpoint and no sanitization of the decoded payload, an…
Unpatched 2026-07-06 - CVE-2025-65856 hardware CRITICAL 9.8
Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 is a critical authentication bypass in the ONVIF implementation shipped on Xiongmai XM530-based IP cameras. The device's deviceservice and mediaservice ONVIF SOAP endpoints accept and fully process requests such as GetDeviceInformation,…
Unverified 2026-07-06 - CVE-2025-11170 web CRITICAL 9.8
WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
The "WP移行専用プラグイン for CPI" WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to missing file type validation in the CpiwmImportController::import function, present in all versions up to and including 1.0.2. The plugin registers an…
Unpatched 2026-07-06 - CVE-2025-13390 web CRITICAL 10
WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
WP Directory Kit implements a one-click "auto-login" feature via wdkgenerateautologinlink() that mints a login token from weak, predictable inputs (derived from the target user ID) rather than a cryptographically random secret. Because the token can be…
Patched 2026-07-06 - CVE-2025-39401 web CRITICAL 10
WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
The WPAMS WordPress plugin (<= 44.0) contains an Unrestricted Upload of File with Dangerous Type vulnerability (CWE-434): its public "apartment management member registration" form accepts an avatar/upload field (amgtuseravatar) without validating the file's…
Unverified 2026-07-06 - CVE-2025-49901 web CRITICAL 9.8
WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
The Simple Link Directory plugin's qc-opd (password reset) AJAX/form handler accepts a username and a new password and applies it to the corresponding WordPress account without verifying the requester's identity via any token tied to the user, email…
Patched 2026-07-06 - CVE-2025-5947 web CRITICAL 9.8
WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
The Service Finder Bookings WordPress plugin implements a "switch back to original user" feature (intended for admin-to-user account switching) via the servicefinderswitchback() AJAX handler, registered under the servicefinderswitchback action. This handler…
Unverified 2026-07-06 - CVE-2025-68860 web CRITICAL 9.8
WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
The WordPress "Mobile Builder" plugin (<= 1.4.2) implements its own JWT-based authentication scheme for its REST API integration but signs/validates tokens using a static, publicly known secret (examplekey) rather than a per-site secret. Because the signing…
Unpatched 2026-07-06 - CVE-2025-6440 web CRITICAL 9.8 EPSS 31%
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
The WooCommerce Dynamic Pricing & Discounts plugin (installed under the wc-designer-pro plugin folder) exposes an unauthenticated AJAX action, wcdpsavecanvasdesignajax, used by its product "canvas design" feature to save user-uploaded artwork. The handler…
Unverified 2026-07-06 - CVE-2025-47812 web CRITICAL 10 KEV EPSS 95%
Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)
Wing FTP Server's authentication routine cCheckUser() truncates the supplied username at the first NULL byte (%00) when validating credentials, but the code path that subsequently writes the session file persists the full, unsanitized username — including…
Patched 2026-07-06 - CVE-2025-29009 web CRITICAL 10
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
The Webkul Medical Prescription Attachment plugin for WooCommerce exposes an AJAX action, wkwcpahandleprescriptionsession, that lets storefront visitors upload a "prescription" file attachment without validating the uploaded file's extension or MIME type on…
Patched 2026-07-06 - CVE-2025-12057 web CRITICAL 9.8
WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
WavePlayer, a WordPress audio player plugin, exposes an AJAX action (wvpl-ajax=createlocalcopy) that lets an unauthenticated visitor instruct the server to fetch a remote URL and save it as a local "track" file inside the uploads directory, without validating…
Unverified 2026-07-06 - CVE-2025-13315 network CRITICAL 9.8 EPSS 33%
Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass & Admin Credential Log Leak (CVE-2025-13315)
CVE-2025-13315 is a critical access-control flaw in Twonky Server 8.5.2 discovered by Rapid7: an earlier fix restricted unauthenticated access to the /rpc/ endpoint prefix, but the equivalent /nmc/rpc/ routing path was left unprotected, so privileged RPC…
Unpatched 2026-07-06 - CVE-2025-12539 web CRITICAL 10
TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
TNC Toolbox: Web Performance is a WordPress plugin that integrates with cPanel to manage caching/performance settings, and stores the cPanel API credentials (hostname, username, API key) it needs for that integration in plaintext files under a predictable,…
Patched 2026-07-06 - CVE-2025-54416 cloud CRITICAL 9.1
tj-actions/branch-names GitHub Actions Command Injection (CVE-2025-54416)
CVE-2025-54416 is a command injection vulnerability in tj-actions/branch-names, a popular GitHub Action used to extract branch/tag names into workflow outputs, affecting over 5,000 public repositories. The root cause is the action's internal use of eval…
Patched 2026-07-06 - CVE-2025-63888 web CRITICAL 9.8
ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
ThinkPHP 5.0.24's read() method in thinkphp/library/think/template/driver/File.php fails to validate the template path derived from user-controlled input passed to the framework's view() function. By submitting a crafted template parameter (e.g. a…
Unverified 2026-07-06 - CVE-2025-34282 web CRITICAL 9.1
ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
ThingsBoard versions before 4.2.1 are vulnerable to Server-Side Request Forgery (CWE-918) through its Image Upload Gallery feature. A Tenant Admin can upload a crafted SVG file whose <image xlink:href="..."> (or <pattern>/<image>) element references an…
Patched 2026-07-06 - CVE-2025-29384 network CRITICAL 9.8
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 is a critical stack-based buffer overflow in the Tenda AC9 router's web management interface, specifically in the handling of the wanMTU POST parameter sent to the /goform/AdvSetMacMtuWan endpoint. The root cause is a lack of bounds checking…
Unpatched 2026-07-06 - CVE-2025-32463 binary CRITICAL 9.3 KEV EPSS 56%
Sudo `chroot` Option Local Privilege Escalation (CVE-2025-32463)
Sudo's -R/--chroot option allowed an unprivileged local user to make sudo chroot() into a directory the user controls before sudo resolves and loads NSS (Name Service Switch) configuration and modules. Because sudo continues to consult /etc/nsswitch.conf and…
Patched 2026-07-06 - CVE-2025-7441 web CRITICAL 9.8 EPSS 39%
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
The StoryChief WordPress plugin exposes an unauthenticated REST webhook endpoint (/wp-json/storychief/webhook) that accepts a JSON payload describing a "published" story, including a data.featuredimage.data.sizes.full field containing a URL. The plugin…
Unpatched 2026-07-06 - CVE-2025-48148 web CRITICAL 9.8 EPSS 16%
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
The StoreKeeper for WooCommerce plugin exposes an admin-ajax.php action (uploadproductimage) that fails to validate the type/extension of uploaded files, in all versions up to and including 14.4.4. An unauthenticated attacker can extract a public AJAX nonce…
Unverified 2026-07-06 - CVE-2025-62168 network CRITICAL 10 EPSS 63%
Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168)
When Squid is configured with emailerrdata enabled (including in default configurations), it embeds diagnostic details about a failed request — including the original client's HTTP request headers — into the auto-generated error page it returns. Specifically,…
Patched 2026-07-06 - CVE-2025-41243 web CRITICAL 10
Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243 concerns a SpEL (Spring Expression Language) injection vulnerability in Spring Cloud Gateway that leads to remote code execution when the Actuator gateway management endpoint is exposed. The root cause is that Actuator's gateway routes API…
Unpatched 2026-07-06 - CVE-2025-6389 web CRITICAL 9.8 EPSS 73%
Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)
The Sneeit Framework plugin for WordPress registers an unauthenticated AJAX action, sneeitarticlespagination, whose callback function sneeitarticlespaginationcallback() takes a function name and a JSON-encoded argument list straight from $POST['callback'] and…
Unverified 2026-07-06 - CVE-2025-52691 web CRITICAL 10 KEV Ransomware EPSS 85%
SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)
This PoC chains two SmarterMail vulnerabilities into a single pre-authentication-to-RCE exploit. First (WT-2026-0001), the /api/v1/auth/force-reset-password endpoint accepts a password-reset request that sets a new password for an arbitrary (including…
Patched 2026-07-06 - CVE-2025-4334 web CRITICAL 9.8
Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
The "Simple User Registration" WordPress plugin (versions <= 6.3) exposes a front-end registration form whose submission handler (wprsubmitform, invoked via admin-ajax.php) accepts a role field directly from the submitted form data without server-side…
Unverified 2026-07-06 - CVE-2025-53580 web CRITICAL 9.8
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
The Simple Business Directory Pro plugin for WordPress exposes a front-end password-restore feature (qcpd-restore-pwd) that accepts a numeric WordPress user ID (qcpd-uid) and a new plaintext password (pass) via a simple POST request, without requiring any…
Patched 2026-07-06 - CVE-2025-31324 web CRITICAL 10 KEV Ransomware EPSS 100%
SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)
CVE-2025-31324 is an unrestricted file upload vulnerability in the Metadata Uploader servlet of SAP NetWeaver Visual Composer (VCFRAMEWORK), which is exposed unauthenticated on the /developmentserver/metadatauploader endpoint. The root cause is that this…
Patched 2026-07-06 - CVE-2025-4632 web CRITICAL 9.8 KEV EPSS 24%
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
Samsung MagicINFO 9 Server's SWUpdateFileUploader servlet, which handles firmware/content update uploads from signage devices, fails to properly sanitize the fileName parameter, allowing directory traversal sequences (../../) to break out of the intended…
Patched 2026-07-06 - CVE-2025-12735 misc CRITICAL 9.8
safe-expr-eval: Mitigation Library for the expr-eval Unsafe eval() RCE (CVE-2025-12735)
CVE-2025-12735 is a critical arbitrary code execution vulnerability in the expr-eval npm package: instead of tokenizing and walking expressions through a restricted interpreter, expr-eval's evaluation path ultimately reaches JavaScript's eval()/Function()…
Patched 2026-07-06 - CVE-2025-68926 cloud CRITICAL 9.8 EPSS 29%
RustFS Hardcoded gRPC Authentication Token Leading to Full Node Compromise (CVE-2025-68926)
RustFS's internal cluster/node gRPC service (nodeservice.NodeService) authenticates peer-to-peer RPC calls using a fixed, hardcoded bearer token — the literal string "rustfs rpc" — which is compiled into every RustFS build and cannot be rotated or configured…
Patched 2026-07-06 - CVE-2025-49113 web CRITICAL 9.9 KEV EPSS 98%
Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)
Roundcube Webmail versions up to and including 1.6.10 are vulnerable to a post-authentication PHP object deserialization vulnerability in the file upload handler, which passes a client-supplied attachment filename through a deserialization path without…
Patched 2026-07-06 - CVE-2025-9209 web CRITICAL 9.8
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
RestroPress, a WordPress food-ordering plugin, exposes user account metadata through the default wp-json/wp/v2/users REST endpoint, including private fields such as rpapiuserprivatekey, rpapiuserpublickey, and rpapiusertokenkey. These values are sensitive…
Unpatched 2026-07-06 - CVE-2025-49844 binary CRITICAL 9.9 EPSS 87%
RediShell: Redis Lua Scripting Use-After-Free Leading to JOP-Chained Remote Code Execution (CVE-2025-49844)
CVE-2025-49844 ("RediShell") is a use-after-free vulnerability in Redis's embedded Lua scripting engine: a crafted Lua script can manipulate the Lua garbage collector so that a Proto (function prototype) object is freed while a reference to it is still…
Patched 2026-07-06 - CVE-2025-6758 web CRITICAL 9.8
Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 is a critical privilege-escalation vulnerability in the Real Spaces WordPress Properties Directory Theme (versions <= 3.6), reachable through the theme's imicagentregister AJAX registration handler. The handler accepts a client-supplied role…
Unverified 2026-07-06 - CVE-2025-55182 web CRITICAL 10 KEV Ransomware EPSS 100%
React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182)
CVE-2025-55182, dubbed "React2Shell", is a critical unauthenticated remote code execution vulnerability in React Server Components' Flight protocol deserialization. The Flight protocol serializes/deserializes component data exchanged between client and…
Patched 2026-07-06 - CVE-2025-11953 network CRITICAL 9.8 KEV EPSS 94%
React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)
The Metro Development Server started by the React Native Community CLI binds to external network interfaces by default and exposes an /open-url HTTP endpoint (implemented by openURLMiddleware in @react-native-community/cli-server-api) that is intended to open…
Patched 2026-07-06 - CVE-2025-4517 misc CRITICAL 9.4
Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
Python's tarfile module added extraction filters (filter="data"/"tar", PEP 706, enabled by default since Python 3.12 and backported) specifically to prevent unsafe archive extraction — path traversal, symlink escapes, and writes outside the destination…
Patched 2026-07-06 - CVE-2025-49132 web CRITICAL 10 EPSS 41%
Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)
Pterodactyl Panel prior to version 1.11.11 exposes a /locales/locale.json endpoint that accepts attacker-controlled locale and namespace query parameters without a required integrity/hash check, allowing an unauthenticated attacker to traverse outside the…
Patched 2026-07-06 - CVE-2025-61922 web CRITICAL 9.1
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
The PrestaShop Checkout module exposes an ExpressCheckout endpoint (/module/pscheckout/ExpressCheckout) that is meant to handle PayPal Express Checkout order confirmation callbacks. Versions of the module prior to 5.0.5 fail to properly verify that the caller…
Patched 2026-07-06 - CVE-2025-11391 web CRITICAL 9.8
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
The "PPOM for WooCommerce" plugin (WooCommerce Product Addon / PPOM Fields) is vulnerable to an unauthenticated time-based blind SQL injection in its getproductmeta() function, present in versions up to and including 33.0.15. The function concatenates a…
Patched 2026-07-06 - CVE-2025-10147 web CRITICAL 9.8
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the moveasoriginalfile function, present in all versions up to and including 4.2.6. The plugin's image-caching route accepts an…
Unverified 2026-07-06 - CVE-2025-13780 web CRITICAL 9.1
pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
pgAdmin 4's database Restore feature attempts to block dangerous psql meta-commands — which begin with a backslash (\) and can execute arbitrary shell commands via \! — using the regular expression (^|\n)[ \t]\\. This regex only matches a backslash that…
Unverified 2026-07-06 - CVE-2025-2945 web CRITICAL 9.9 EPSS 47%
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)
pgAdmin 4's Query Tool "download" endpoint accepts a querycommited parameter and passes it directly to Python's built-in eval() without any sanitization, allowing an authenticated attacker to run arbitrary Python code under the pgAdmin service account. The…
Patched 2026-07-06 - CVE-2025-61757 web CRITICAL 9.8 KEV EPSS 88%
Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)
Oracle Identity Manager's SecurityFilter fails to correctly normalize request URIs before applying its authentication check. By appending a ;.wadl matrix-parameter suffix to the path of the groovyscriptstatus endpoint, an unauthenticated attacker can bypass…
Unpatched 2026-07-06 - CVE-2025-6934 web CRITICAL 9.8 EPSS 24%
Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934)
The Opal Estate Pro plugin (<= 1.7.5) exposes a public-facing user self-registration AJAX action, opalestateregisterform, handled by an onregisteruser function that fails to restrict which role value a registering visitor may request. A registration request…
Unverified 2026-07-06 - CVE-2025-34299 network CRITICAL 9.8 EPSS 73%
Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)
Monsta FTP versions up to and including 2.11.2 contain a pre-authentication, unrestricted arbitrary file upload vulnerability (CWE-434) in the downloadFile action of its /mftp/application/api/api.php endpoint. The endpoint accepts a user-supplied FTP…
Patched 2026-07-06 - CVE-2025-23061 web CRITICAL 9
Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 is an incomplete-fix bypass of CVE-2024-53900, a NoSQL/command injection vulnerability in the Mongoose ODM for Node.js. The original fix blocked $where operators submitted directly inside a populate() match filter, but failed to sanitize $where…
Patched 2026-07-06 - CVE-2025-52913 network CRITICAL 9.8
Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
Mitel MiCollab fails to properly normalize URL paths before applying access-control checks on its NPM (Network Protocol Manager) web endpoints. By appending crafted traversal sequences such as ..;/..;/ after seemingly-legitimate, unauthenticated-facing…
Unverified 2026-07-06 - CVE-2025-54068 web CRITICAL 9.8 KEV EPSS 96%
Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068)
Laravel Livewire serializes component state into a wire:snapshot HTML attribute and protects it with an HMAC-SHA256 checksum keyed on the application's APPKEY. If an attacker obtains the APPKEY (leaked .env, default/demo key, weak secret, etc.), they can…
Patched 2026-07-06 - CVE-2025-27515 web CRITICAL 9.8
Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 is a file upload validation bypass (CWE-20: Improper Input Validation) affecting Laravel applications that validate array-based file uploads with wildcard rules such as files.. The root cause is that Laravel's mimes: validation rule inspects…
Patched 2026-07-06 - CVE-2026-27966 web CRITICAL 9.8 EPSS 34%
Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966)
Langflow versions prior to 1.8.0 hardcode allowdangerouscode=True in the CSV Agent component, exposing LangChain's pythonreplast tool to prompt injection. Independently, several Langflow REST API endpoints (customcomponent, build/{uuid}/vertices,…
Patched 2026-07-06 - CVE-2025-2294 web CRITICAL 9.8 EPSS 78%
Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)
The Kubio AI Page Builder plugin for WordPress, in all versions up to and including 2.5.1, is vulnerable to Local File Inclusion via the kubiohybridthemeloadtemplate function. The root cause is that a template path supplied through a query-string parameter is…
Unverified 2026-07-06 - CVE-2025-12674 web CRITICAL 9.8
KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
KiotViet Sync is a WordPress plugin that synchronizes products between the KiotViet retail/POS platform and a WooCommerce store via a custom REST route. Its createmedia() function, invoked when syncing a product's image, accepts a remote rawimageid URL and…
Unverified 2026-07-06 - CVE-2025-14440 web CRITICAL 9.8
JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
The JAY Login & Register plugin implements a "switch back" feature — presumably intended for admins who impersonate another user to later switch back to their own account — via the jayloginregisterprocessswitchback handler. This handler trusts the…
Unverified 2026-07-06 - CVE-2025-47916 web CRITICAL 10 EPSS 85%
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)
Invision Community's theme editor exposes a customCss() action on the front-end themeeditor controller (/applications/core/modules/front/system/themeeditor.php) that is reachable without authentication and passes the attacker-supplied content request…
Patched 2026-07-06 - CVE-2025-1974 cloud CRITICAL 9.8 EPSS 100%
IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)
The ingress-nginx admission controller validates incoming Ingress objects by rendering a temporary NGINX configuration and running nginx -t against it — but the validation webhook itself has no authentication and accepts attacker-controlled configuration…
Unverified 2026-07-06 - CVE-2025-37164 network CRITICAL 10 KEV EPSS 90%
HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)
HPE OneView exposes a REST endpoint, /rest/id-pools/executeCommand, that accepts a JSON body containing a cmd field and executes it as an OS command on the appliance. The root cause is that the endpoint passes attacker-supplied input from the cmd field…
Unpatched 2026-07-06 - CVE-2025-54123 web CRITICAL 9.8 EPSS 11%
Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)
Hoverfly exposes a middleware configuration API (/api/v2/hoverfly/middleware) that lets an authenticated admin register an external "middleware" process to pre/post-process simulated HTTP traffic, specified as a binary (interpreter/executable) plus a script…
Patched 2026-07-06 - CVE-2025-41115 web CRITICAL 10 EPSS 17%
Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115)
Grafana Enterprise/Cloud's SCIM provisioning feature (enabled via the enableSCIM feature flag together with usersyncenabled) fails to properly validate the externalId supplied when a SCIM client creates a user via POST /api/scim/v2/Users. This lets a caller…
Patched 2026-07-06 - CVE-2025-14611 web CRITICAL 9.8 KEV EPSS 53%
Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)
CentreStack and Triofox protect file-download "access tickets" with AES-256-CBC, but the encryption key and IV are not generated per-installation — they are static byte strings hardcoded in GladCtrl64.dll's .data section and returned verbatim by the…
Unverified 2026-07-06 - CVE-2025-22777 web CRITICAL 9.8
GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 is an unauthenticated PHP Object Injection (CWE-502, Deserialization of Untrusted Data) vulnerability in the GiveWP WordPress donation plugin. GiveWP stores certain donor-supplied form field values as serialized PHP meta in the database and…
Patched 2026-07-06 - CVE-2025-13342 web CRITICAL 9.8
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 is a critical, fully unauthenticated privilege-escalation vulnerability in the Frontend Admin plugin for WordPress (<= 3.28.20). The plugin's ACF-powered frontend registration/form-submission handler accepts user-controlled acff[user][field]…
Patched 2026-07-06 - CVE-2025-57819 web CRITICAL 9.8 KEV EPSS 88%
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
CVE-2025-57819 is an unauthenticated SQL injection in FreePBX's admin/ajax.php endpoint handler for the endpoint module, where the brand parameter is concatenated into a backend SQL query without sanitization. The PoC first confirms the injection with an…
Patched 2026-07-06 - CVE-2025-66039 network CRITICAL 9.8
FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039 is a critical authentication bypass in the FreePBX framework module that occurs when the system's "Authorization Type" (AUTHTYPE) is configured to webserver — in this mode FreePBX trusts an externally-supplied Authorization header (intended for…
Patched 2026-07-06 - CVE-2025-14156 web CRITICAL 9.8
Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
Fox LMS exposes a REST API endpoint, /wp-json/fox-lms/v1/payments/create-order, intended to register a new user as part of a course-purchase flow. The endpoint accepts a role field in the JSON body but does not validate or restrict it to safe values (e.g.…
Unverified 2026-07-06 - CVE-2025-64446 network CRITICAL 9.8 KEV EPSS 92%
FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)
FortiWeb exposes an internal CGI handler (cgi-bin/fwbcgi) that is reachable through the authenticated cmdb REST API path by appending a relative path-traversal sequence (../) after a request to a nonexistent object (admin%3f). Because path handling for the…
Unverified 2026-07-06 - CVE-2025-59718 network CRITICAL 9.8 KEV EPSS 63%
FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)
CVE-2025-59718 is an improper verification of a cryptographic signature in Fortinet's FortiCloud SSO admin-login flow across FortiOS, FortiProxy, FortiSwitchManager, and FortiWeb, allowing authentication bypass when admin-forticloud-sso-login is enabled on a…
Patched 2026-07-06 - CVE-2025-49071 web CRITICAL 9.8
Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
The Flozen Theme for WordPress (versions up to and including 1.5.1) registers a wphandleupload-routed AJAX action (backed by the theme's flozenaddnewcustomfont() function) that accepts a ZIP file upload without checking authentication or validating its…
Unverified 2026-07-06 - CVE-2025-58434 web CRITICAL 9.8 EPSS 50%
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
CVE-2025-58434 is an authentication-bypass vulnerability in FlowiseAI's password-reset flow: the forgot-password endpoint returns the password-reset tempToken directly in its JSON response body instead of only delivering it out-of-band (e.g., via email), and…
Patched 2026-07-06 - CVE-2025-59528 web CRITICAL 10 EPSS 90%
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
Flowise exposes a CustomMCP node whose loadMethod handler (/api/v1/node-load-method/customMCP) accepts a user-supplied mcpServerConfig string. On the backend, this string is passed straight into a Function() constructor inside the convertToValidJSONString…
Patched 2026-07-06 - CVE-2025-63353 / GHSA-cg2x-c25f-6327 network CRITICAL 9.8
FiberHome HG6145F1 Predictable Default Wi-Fi PSK Derived from Broadcast SSID (CVE-2025-63353)
The FiberHome HG6145F1 GPON ONT broadcasts a factory-default SSID of the form fh<hexa>, where <hexa> is a six-character lowercase hex string. The factory-default WPA2 pre-shared key printed on the device label is a deterministic function of that same value:…
Patched 2026-07-06 - CVE-2025-54957 binary CRITICAL 9.8
Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957 is a critical out-of-bounds write vulnerability in Dolby's DDPlus Unified Decoder, triggered while processing "evolution" data in an AC-3/EC-3 (Dolby Digital Plus) bitstream. An integer overflow in the length calculation for evolution-data…
Unverified 2026-07-06 - CVE-2025-64459 web CRITICAL 9.1 EPSS 19%
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)
This is a SQL injection vulnerability in Django's QuerySet/Q object construction: when application code builds a Q(kwargs) filter directly from user-controlled input (such as a raw request.GET QueryDict) without allow-listing keys, an attacker can supply the…
Patched 2026-07-06 - CVE-2025-49002 web CRITICAL 9.8 EPSS 45%
DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002)
DataEase's /de2api/datasource/validate endpoint lets a client submit an arbitrary JDBC connection string when testing/validating a new datasource. By choosing datasource type: h2 and supplying a base64-encoded H2 JDBC URL that includes INIT=RUNSCRIPT FROM…
Patched 2026-07-06 - CVE-2025-60854 network CRITICAL 9.8
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
The D-Link AX1500 web management interface exposes a SetDeviceSettings SOAP action (reached via the /DHMAPI/ HNAP-style endpoint) that lets a client update the router's DeviceName. The vulnerable firmware function (identified in the binary as…
Patched 2026-07-06 - CVE-2025-54309 web CRITICAL 9 KEV EPSS 94%
CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309)
CrushFTP's web interface trusts the presence of the HTTP headers X-DMZ-Proxy: disabled and X-AS2-Version: 1.0 (plus a matching User-Agent) as proof that a request originates from an already-authenticated AS2 (Applicability Statement 2 / EDI-over-HTTP) proxy…
Patched 2026-07-06 - CVE-2025-14700 web CRITICAL 9.9
Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
Crafty Controller's server Webhook configuration accepts a user-controlled "body" template that is rendered server-side with Jinja2 without sandboxing. An authenticated user can set the webhook body to a Jinja2 expression that escapes the sandbox via…
Unverified 2026-07-06 - CVE-2025-11492 network CRITICAL 9.6
ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)
The ConnectWise Automate RMM agent can be configured with an http:// fallback Server Address (observed as default/common configuration at multiple MSPs); an attacker with AiTM network position can force a fallback from HTTPS to HTTP, then serve a forged…
Patched 2026-07-06 - CVE-2025-20393 network CRITICAL 10 KEV EPSS 30%
Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393)
CVE-2025-20393 is an unauthenticated remote code execution vulnerability in Cisco AsyncOS's Spam Quarantine service, which listens on TCP/6025. This repository provides a detection-only tool that (1) checks whether TCP/6025 is reachable on a target Secure…
Unverified 2026-07-06 - CVE-2025-20333 network CRITICAL 9.9 KEV EPSS 40%
Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)
CVE-2025-20333 is a critical heap-based buffer overflow in the WebVPN file-upload handler of Cisco Secure ASA and FTD devices, which can lead to remote code execution as root when successfully exploited (typically after first bypassing authentication via the…
Unverified 2026-07-06 - CVE-2025-13595 web CRITICAL 9.8
Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
The Cibeles AI plugin ships a debug/update helper, actualizadorgit.php, directly inside its plugin directory. The file is missing the standard WordPress ABSPATH guard, so it is reachable over plain HTTP without any authentication, and it implements a "GitHub…
Unverified 2026-07-06 - CVE-2026-33453 web CRITICAL 9.8
camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
Apache Camel's camel-coap component copies CoAP request URI query parameters directly into Camel Exchange headers inside CamelCoapResource.handleRequest(), without applying any HeaderFilterStrategy. Because CoAPEndpoint extends DefaultEndpoint (not…
Unverified 2026-07-06 - CVE-2025-55315 network CRITICAL 9.9 EPSS 66%
ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315)
CVE-2025-55315 is an HTTP request-smuggling vulnerability in the Kestrel web server used by ASP.NET Core, caused by Kestrel's chunked-transfer-encoding parser accepting a lone \n in a chunk-size line where the HTTP/1.1 spec requires \r\n. When Kestrel sits…
Patched 2026-07-06 - CVE-2025-30065 misc CRITICAL 9.8 EPSS 41%
Apache Parquet-Avro Schema Deserialization RCE/SSRF — Incomplete-Fix Bypass (CVE-2025-30065)
CVE-2025-30065 is an unsafe class-instantiation vulnerability in Apache Parquet Java's parquet-avro module: crafted Avro schema metadata embedded in a Parquet file can force the reading JVM to load and instantiate attacker-named classes. The official 1.15.1…
Patched 2026-07-06 - CVE-2025-23048 web CRITICAL 9.1
Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)
CVE-2025-23048 is a client certificate authentication bypass in Apache HTTP Server's modssl that occurs when TLS 1.3 session resumption (session tickets/PSK) is used across virtual hosts configured with different SSLCACertificateFile directives. The root…
Patched 2026-07-06 - CVE-2025-59390 crypto CRITICAL 9.8
Apache Druid Kerberos Cookie-Signing Secret Recovery via ThreadLocalRandom Seed Inversion (CVE-2025-59390)
When Apache Druid's Kerberos authenticator is deployed without an explicit druid.auth.authenticator.kerberos.cookieSignatureSecret, Druid falls back to generating that secret using Java's ThreadLocalRandom, which is not cryptographically secure. Because…
Patched 2026-07-06 - CVE-2026-27172 web CRITICAL 9.8
Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
Apache Camel's camel-consul component uses a Consul key/value store as a Camel bean registry (ConsulRegistry). When a bean is looked up by name, ConsulRegistryUtils.deserialize() Base64-decodes the stored KV value and deserializes it with a raw…
Patched 2026-07-06 - CVE-2025-13597 web CRITICAL 9.8
AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
AI Feeds ships the same vulnerable actualizadorgit.php "GitHub mirror updater" helper found in the vendor's other plugin, Cibeles AI (CVE-2025-13595) — it is directly reachable over HTTP (no ABSPATH guard, no authentication) and blindly downloads and mirrors…
Unverified 2026-07-06 - CVE-2025-11749 web CRITICAL 9.8 EPSS 75%
AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749)
AI Engine's built-in Model Context Protocol (MCP) server, exposed via WordPress REST routes under /wp-json/mcp/v1/, discloses a per-site MCP access token directly in the unauthenticated route listing when the plugin's MCP feature (or a "No-Auth URL"-style…
Unverified 2026-07-06 - CVE-2025-54236 web CRITICAL 9.1 KEV EPSS 97%
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)
Magento's customer address form exposes a file-upload field (customattributes[countryid]) at customer/addressfile/upload that is intended to accept a small file attachment (e.g. a document tied to a custom address attribute), guarded only by a per-request…
Patched 2026-07-06 - CVE-2025-54253 web CRITICAL 10 KEV EPSS 88%
Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253)
AEM Forms exposes several form-submission endpoints (e.g. /content/forms/af/submit, /services/SubmitForm, /bin/receive, /lc/submit) that parse attacker-supplied XML without disabling external entity resolution. The root cause is an XML parser configured to…
Unverified 2026-07-06 - CVE-2025-13486 web CRITICAL 9.8 EPSS 74%
ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)
The ACF Extended (ACFE) plugin's front-end form-rendering AJAX handler (wpajaxnoprivacfe/form/renderformajax) resolves user-controlled form configuration through prepareform(), which ultimately passes attacker-supplied data into calluserfuncarray() without…
Unverified 2026-07-06 - CVE-2025-65354 web CRITICAL 9.8
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
The target is a PHP "Grocery" web application whose product-search endpoint, Grocery/searchproductsitname.php, takes a sitemname parameter that is concatenated into a backend SQL query without parameterization or escaping. This allows classic boolean-based…
Unpatched 2026-07-06 - CVE-2026-1459 network HIGH
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
The router's web management interface exposes a TR369Certificates CGI endpoint whose name parameter, used during a certificate "download" action, is passed unsanitized into a shell command executed as root. An authenticated administrator (or attacker with…
Unverified 2026-07-05 - CVE-2026-40003 hardware HIGH
ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)
The ZX297520V3 BootROM falls back to a USB download mode when it cannot load or verify a valid image from flash, entering a handshake loop that accepts a stage-1 image over USB for device recovery. The BootROM's image-load command does not validate the…
Unverified 2026-07-05 - CVE-2026-34474 network HIGH EPSS 25%
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
CVE-2026-34474 is an unauthenticated information disclosure in the web management interface of ZTE ZXHN H298A and H108N router firmware. A crafted GET request to getpage.lua?pid=1000ÐCheat=1 returns HTML containing the live administrator password, WLAN…
Unverified 2026-07-05 - CVE-2026-34472 network CRITICAL
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472 is an authentication bypass in ZTE ZXHN H188A V6 routers caused by unauthenticated access to pre-login "wizard" handlers. Root-path routing trusts attacker-controlled type/tag parameters, and the QuickSetupEnable gate that should block this…
Unverified 2026-07-05 - CVE-2026-34473 network HIGH
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473 is an unauthenticated denial-of-service condition in ZTE H-series routers' web management interface, rooted in how the cgilua/post.lua pre-auth request-body parser handles oversized application/x-www-form-urlencoded POST bodies. Sending a…
Unverified 2026-07-05 - CVE-2026-27470 web HIGH 8.8
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
ZoneMinder's event-rename functionality (web/ajax/event.php) safely stores a user-supplied event name using a parameterized query, giving no indication anything is wrong. However, the "near events" lookup (web/ajax/status.php, getNearEvents()) later reads…
Patched 2026-07-05 - CVE-2026-28286 web CRITICAL
ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
ZimaOS exposes a file-management REST API endpoint (/v21/files/file) that accepts a user-supplied file path without canonicalizing it or restricting it to a base directory. Because this is a web-facing REST API rather than a local system call, an attacker…
Unverified 2026-07-05 - CVE-2026-25807 network CRITICAL
ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)
ZAI-Shell exposes a peer-to-peer terminal-sharing feature that listens on a TCP socket and accepts a simple JSON-line protocol (hello / command messages). When the host starts a sharing session with --no-ai (noaimode), commands received over this P2P channel…
Patched 2026-07-05 - CVE-2026-1937 web HIGH 7.2
YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
The YayMail WooCommerce Email Customizer plugin registers an AJAX action, yaymailimportstate, that lets users import a saved settings ZIP file without any server-side capability check. An authenticated attacker holding only the WooCommerce Shop Manager role…
Unverified 2026-07-05 - CVE-2026-44595 / GHSA-p2rj-mrmc-9w29 web MEDIUM 4.3
YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
The YAMCS IAM REST API endpoints (listUsers, getUser, listGroups, getGroup) fail to enforce the required SystemPrivilege.ControlAccess authorization check. Any authenticated user, including one with no assigned privileges, can call these endpoints directly…
Patched 2026-07-05 - CVE-2026-44596 / GHSA-w5r6-mcgq-7pq4 web MEDIUM 5.3
YAMCS Missing Rate Limiting on Authentication Endpoint (CVE-2026-44596)
The POST /auth/token authentication endpoint in yamcs-core accepts unlimited granttype=password login attempts with no rate limiting, account lockout, or failed-attempt throttling. An unauthenticated remote attacker with network access can brute-force…
Patched 2026-07-05 - CVE-2026-42568 / GHSA-cqh3-jg8p-336j network MEDIUM
YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)
YAMCS's LdapAuthModule builds LDAP search filters by directly substituting the user-supplied username into a filter template (e.g. (uid={0})) without RFC 4515 escaping. An attacker can supply LDAP metacharacters in the username field to alter the filter's…
Patched 2026-07-05 - CVE-2026-33137 web CRITICAL 9.3
XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
XWiki's REST endpoint POST /wikis/{wikiName} imports a XAR (XWiki Archive, a ZIP-based export/import format) directly into the wiki without verifying that the requester has administrative rights on the target. Because the endpoint performs no authorization…
Patched 2026-07-05 - CVE-2026-20698 binary HIGH
XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)
XNU's routing socket implementation processes RTMGET messages carrying an RTAGENMASK sockaddr through rnaddmask(), which copies the supplied genmask into a fixed, address-family-dependent radix-tree node buffer without validating that the attacker-controlled…
Patched 2026-07-05 - CVE-2026-3609 binary HIGH
XIGNCODE3 Anti-Cheat Driver PPL-Bypass LSASS Credential Dump (CVE-2026-3609)
Wellbia's XIGNCODE3 anti-cheat kernel driver xhunter1.sys exposes an IRPMJWRITE command interface that calls ObOpenObjectByPointer with AccessMode = KernelMode and without the OBJKERNELHANDLE flag, handing a kernel-minted PROCESSALLACCESS handle straight into…
Patched 2026-07-05 - CVE-2026-39912 web CRITICAL 9.1
Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
Both V2Board and its fork Xboard implement a "login with mail link" (magic link) feature. Their loginWithMailLink endpoint (AuthController.php in V2Board, MailLinkService.php in Xboard) generates the one-time login link and is supposed to only deliver it via…
Patched 2026-07-05 - CVE-2026-38698 network CRITICAL
Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
The tutkpacketalloc function inside the TUTK SDK's tutkavserver component, used by Wyze Cam Pan v3 and other TUTK-integrated IoT cameras, allocates a buffer for incoming AV packets based on an attacker-influenced size field without adequate bounds validation.…
Unverified 2026-07-05 - CVE-2026-1357 web CRITICAL EPSS 33%
WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)
The WPvivid Backup & Migration plugin's remote migration/"send to site" feature decrypts an incoming session key with opensslprivatedecrypt(). When decryption fails, the function returns boolean false instead of the code aborting, and that false is passed…
Unverified 2026-07-05 - CVE-2026-49105 web HIGH 8.1
WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
This PoC targets the WP Zendesk for Contact Form 7 plugin, whose cf7-zendesk.php calls maybeunserialize() on user-supplied Contact Form 7 field values without validation. An unauthenticated attacker can locate a site's CF7 forms via the CF7 REST API (or by…
Unverified 2026-07-05 - CVE-2026-40791 web HIGH 7.2
WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
The public booking form of the WP Time Slots Booking Form plugin parses a submitted appointment field by splitting on a literal space character, then stores the resulting substring as the booking's time-slot value. Because HTML treats a tab character as valid…
Patched 2026-07-05 - CVE-2026-6379 web CRITICAL 8.6
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
WP Photo Album Plus's wppagetphotos() function (in wppa-functions.php) parses the wppa-supersearch request parameter as a comma-separated value list. When the search "type" is o (Owner), the resulting DATA field is concatenated directly into a SQL query…
Patched 2026-07-05 - CVE-2026-49085 web HIGH 8.1
WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
This PoC targets the WP Insightly plugin, which calls PHP's maybeunserialize() on user-supplied form field values without validating the input. An unauthenticated attacker can submit a crafted PHP serialized object as a form field value through the plugin's…
Unverified 2026-07-05 - CVE-2026-5415 web HIGH 8.8
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 is an authentication bypass in the WP Captcha PRO WordPress plugin that lets an authenticated Subscriber-level user escalate to any other account, including Administrators. The plugin's AJAX handler for creating temporary login links relies on a…
Unverified 2026-07-05 - CVE-2026-54806 web CRITICAL 9.8
WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
WP Activity Log logs the User-Agent header on any request that generates a loggable event (such as a failed login), and stores that value in the database without treating it as untrusted input. The stored value is later deserialized (via PHP's native…
Patched 2026-07-05 - CVE-2026-0745 web MEDIUM
WordPress User Language Switch Plugin SSRF — CVE-2026-0745
The User Language Switch WordPress plugin exposes an ulsdownloadlanguage AJAX action that accepts a caller-supplied URL (infolanguage) and fetches it server-side to download a language file. The endpoint does not validate or restrict the destination, allowing…
Unverified 2026-07-05 - CVE-2026-12416, CVE-2026-12417 web CRITICAL 9.8
WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
Both plugins register a password-reset AJAX handler (pravelchangepassword for SignUp & SignIn, pravelinvoicechangepassword for Invoice Generator) as wpajaxnopriv, meaning it is reachable without authentication. Neither handler validates a WordPress nonce or…
Unverified 2026-07-05 - CVE-2026-0740 web HIGH EPSS 58%
WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740
Ninja Forms exposes a file-upload field feature reachable via WordPress's admin-ajax.php endpoint. The PoC script first requests a fresh nonce through the nffugetnewnonce action, then uses that nonce to submit a file via the nffuupload action. Because the…
Unverified 2026-07-05 - CVE-2026-4106 web HIGH
WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
The HT Mega plugin registers several wpajaxnopriv AJAX action hooks (e.g. wcsalespurchasedproducts, htmegauserlistajax) used to power dynamic widget content, but these handlers omit both authentication (checkajaxreferer) and authorization (currentusercan)…
Unverified 2026-07-05 - CVE-2026-39676 web MEDIUM
WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
The Download Manager WordPress plugin (<= 3.3.5.2) is missing a capability check on its file-serving and media-access endpoints. An unauthenticated attacker can directly reference internal object/file identifiers to bypass access restrictions and retrieve…
Unverified 2026-07-05 - CVE-2026-3180 web HIGH
WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
The Contest Gallery WordPress plugin passes the cglmaili parameter through WordPress's sanitizeemail() function, which preserves the single-quote character (') in the local part of an email address. Because the sanitized value is subsequently used to build a…
Unverified 2026-07-05 - CVE-2026-3844 web CRITICAL EPSS 37%
WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)
The Breeze Cache WordPress plugin (<= 2.4.4) exposes a gravatar-caching feature that writes attacker-supplied remote content directly into the plugin's cache directory without verifying that the fetched content is actually image data. An unauthenticated…
Unverified 2026-07-05 - CVE-2026-0594 web MEDIUM
WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
The "List Site Contributors" WordPress plugin reflects the alpha query parameter into page output without sanitization, allowing an attacker to inject arbitrary HTML/JavaScript that executes in a victim's browser when they visit a crafted link. The included…
Unverified 2026-07-05 - CVE-2026-3629 web CRITICAL
WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
The "Import and Export Users and Customers" WordPress plugin contains a privilege-escalation flaw that allows a low-privileged authenticated user to escalate to a higher-privileged role (e.g. administrator) through the plugin's user import/export…
Unverified 2026-07-05 - CVE-2026-3359 web CRITICAL
WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
The WordPress "Form Maker" plugin (up to version 1.15.42) passes attacker-controlled input from a crafted inputs[2|typecheckbox|all] field on the admin-ajax.php?action=fmreloadinput endpoint into a SQL query without adequate sanitization, allowing…
Unverified 2026-07-05 - CVE-2026-5364 web HIGH 8.1
WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
The plugin determines an uploaded file's extension via pathinfo() on the raw, attacker-supplied filename before that filename is passed through WordPress's sanitizefilename(). By uploading a file named e.g. shell.php$, pathinfo() reports the extension as php$…
Unverified 2026-07-05 - CVE-2026-27542 web CRITICAL 9.8
WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
The WWLC WordPress plugin ships two unauthenticated AJAX handlers that are exploited together in this tool. CVE-2026-27542 abuses wwlccreateuser, which fails to sanitize role-related fields, letting an unauthenticated attacker inject…
Unverified 2026-07-05 - CVE-2026-54807 web INFO
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
The vulnerable plugin's frontend user-registration form accepts a userroles parameter directly from the unauthenticated registration POST request and trusts it when creating the new WordPress account, instead of forcing a safe default role (e.g. subscriber or…
Unverified 2026-07-05 - CVE-2026-44403 web HIGH
Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
Wing FTP Server's WebAdmin session mechanism serializes session values as executable Lua source using [[...]] long-string literals. Because bracket-sanitization code that would strip [/] characters from session values was commented out, a value containing ]]…
Patched 2026-07-05 - CVE-2026-21510 social-engineering HIGH KEV EPSS 26%
Windows ShellLink (.lnk) Remote Code Execution — CVE-2026-21510 LNK-Stomping Generator
This is a standalone Python generator (lnkstomperpoint.py) that builds malicious Windows .lnk shortcut files exploiting CVE-2026-21510, a ShellLink remote-code-execution issue in how Windows resolves and launches shortcut targets. The tool assembles a…
Unverified 2026-07-05 - CVE-2026-32202 binary HIGH KEV EPSS 64%
Windows Shell LNK _IDCONTROLW Zero-Click SMB Coercion Builder — CVE-2026-32202
This repository documents a reverse-engineered, undocumented IDCONTROLW structure used internally by shell32.dll to represent Control Panel applet items inside a .lnk file's LinkTargetIDList, based on the researcher's own IDA Pro static analysis and…
Unverified 2026-07-05 - CVE-2026-24294 network CRITICAL
Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)
Windows 11 24H2 / Server 2025 introduced an SMB client capability allowing connections to arbitrary TCP ports via net use \\host\share /tcpport:PORT. Combined with SMB2 session multiplexing, this enables a local NTLM reflection attack: a low-privileged local…
Patched 2026-07-05 - CVE-2026-26179 / ZDI-26-276 binary HIGH
Windows Secure Kernel (VTL1/VSM) Memory Corruption PoC (CVE-2026-26179 / ZDI-26-276)
CVE-2026-26179 is a vulnerability discovered by the author within the Windows Secure Kernel — the isolated, more privileged execution environment (VTL1) that underlies Virtualization Based Security (VBS) features such as Credential Guard and HVCI. The author…
Unverified 2026-07-05 - CVE-2026-42978 binary HIGH 7.8
Windows Push Notification Service Use-After-Free Race (CVE-2026-42978)
CVE-2026-42978 is a use-after-free race condition (CWE-362) in wpncore.dll's PresentationEndpointFacade class, which backs the WpnService Windows Push Notification service running as NT AUTHORITY\SYSTEM. Facade methods (e.g. ToastUnblockAll) fetch a pointer…
Unverified 2026-07-05 - CVE-2026-29923 binary CRITICAL
Windows pstrip64.sys BYOVD Physical Memory Local Privilege Escalation — CVE-2026-29923
pstrip64.sys is a legacy signed kernel driver bundled with EnTech Taiwan PowerStrip that exposes an IOCTL (0x80002008) allowing a calling process to map arbitrary physical memory into its own address space via ZwMapViewOfSection against…
Unverified 2026-07-05 - CVE-2026-40369 binary HIGH
Windows Kernel Local Privilege Escalation via SeDebugPrivilege Bit Corruption (CVE-2026-40369)
This exploit is a local privilege escalation chain against the Windows kernel that abuses a low-level primitive reachable through NtQuerySystemInformation to corrupt a bit near the process's SeDebugPrivilege state in kernel memory, without requiring the…
Unverified 2026-07-05 - CVE-2026-26128 network CRITICAL
Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)
CVE-2026-26128 is a Kerberos relay vulnerability rooted in a mismatch between how two different Windows components normalize Unicode characters when resolving Service Principal Names. The client-side DnsCache service uses CompareStringW with NORMIGNORECASE,…
Unverified 2026-07-05 - CVE-2026-33824 network CRITICAL EPSS 56%
Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824
This repository is an in-progress C/C++ exploit prototype targeting a double-free vulnerability in Windows' ikeext.dll, the kernel driver that handles IKEv2 IPsec negotiation over UDP port 500. The exploit constructs and sends fragmented (SKF) IKEv2 packets…
Patched 2026-07-05 - CVE-2026-49160 binary HIGH EPSS 54%
Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)
This PoC targets a memory-safety bug in the Windows HTTP.sys kernel driver's request header parsing path (HTTP!UlpParseNextRequest / HTTP!UlpHandleRequest). The included http2bomb.py script establishes a TLS/HTTP2 connection to a target IIS/HTTP.sys-backed…
Patched 2026-07-05 - CVE-2026-20817 binary HIGH
Windows Error Reporting Service ALPC Local Privilege Escalation (CVE-2026-20817)
CVE-2026-20817 abuses an ALPC-based elevation primitive in the Windows Error Reporting Service. WerSvc listens on the \WindowsErrorReportingServicePort ALPC port and, upon receiving a specially crafted WERSVCMSG request with the SvcElevatedLaunch message flag…
Unverified 2026-07-05 - CVE-2026-2636 binary MEDIUM
Windows CLFS.sys Unrecoverable State / BSoD via ReadFile on Log File Handle (CVE-2026-2636)
CVE-2026-2636 is a denial-of-service vulnerability in the Windows Common Log File System driver (CLFS.sys). An unprivileged local user can crash the system simply by calling the ReadFile Win32 API on a handle obtained via CreateLogFile — a call sequence CLFS…
Patched 2026-07-05 - CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp web HIGH
WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
WeGIA's control.php endpoint (AtendidoocorrenciaControle::listarTodosComAnexo) is vulnerable to authenticated error-based SQL injection through the idmemorando parameter. This helper script automates the tedious part of exploitation: it attempts login against…
Patched 2026-07-05 - CVE-2026-1555 web CRITICAL 9.8
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
The WebStack WordPress theme registers an imgupload AJAX action via wpajaxnopriv, exposing it to unauthenticated visitors, and the handler function ioimgupload() performs no file type or extension validation before saving the uploaded file into a publicly…
Unverified 2026-07-05 - CVE-2026-27778 web MEDIUM
WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)
This repository is a hands-on simulator for CVE-2026-27778 (CWE-307: Improper Restriction of Excessive Authentication Attempts) built around a small Node.js/Express server that accepts WebSocket AUTHREQ messages containing a password guess and replies with…
Patched 2026-07-05 - CVE-2026-24126 web HIGH 6.5
Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
Weblate's SSH host-key management feature (weblate/ssh/views.py, addhostkey()) passes the administrator-supplied host field straight into an ssh-keyscan subprocess invocation with no sanitization and no -- argument terminator. Because ssh-keyscan supports a…
Patched 2026-07-05 - CVE-2026-43700 web HIGH
WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
WebKit's GPUDevice.importExternalTexture({ source: HTMLVideoElement }) imports the current frame of a <video> element as a GPU-sampleable GPUExternalTexture. Prior to the fix, WebKit did not check the video element's taintsOrigin (cross-origin CORS-tainted)…
Unverified 2026-07-05 - CVE-2026-20643 web MEDIUM
WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)
The Navigation API's navigate event exposes an event.canIntercept flag that browsers must set to false for navigations that cross a security boundary the page is not allowed to intercept — including navigations to a different port on the same host. This PoC…
Unverified 2026-07-05 - CVE-2026-43735 web HIGH
WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)
CVE-2026-43735 is a WebKit Navigation API bug where, when a parent page uses a named <a target="iframeName"> link to trigger a fragment navigation inside a cross-origin <iframe>, the NavigateEvent.sourceElement delivered to the iframe's navigate event…
Unverified 2026-07-05 - CVE-2026-5615 web HIGH 8.5
VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
VvvebJs versions <= 2.0.5 allow uploading SVG files without sanitizing their contents. Because SVG is XML that can embed <script>-equivalent event handlers (e.g. onload), an attacker can upload an SVG containing JavaScript, which is stored server-side and…
Patched 2026-07-05 - CVE-2026-37748 web HIGH 7.2
Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
Visitor Management System 1.0 calls moveuploadedfile() in vms/php/adminuserinsert.php and vms/php/update1.php without validating the uploaded file's MIME type, extension, or content. An authenticated admin user can upload a PHP webshell disguised as a profile…
Unverified 2026-07-05 - CVE-2026-35250 binary LOW 2.3
VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)
VirtualBox's DevVGAVBVA.cpp dimension-validation check uses a logical OR where an AND is required, letting a malicious guest supply width=0x80000001, height=16 and pass the bounds check. The resulting pointer-data size calculation (cbPointerData) then…
Unverified 2026-07-05 - CVE-2026-44656 binary HIGH
Vim Modeline `path` Option Backtick-Expansion Command Injection (CVE-2026-44656)
Vim's modeline processing allows a file to set the path option, which can itself contain a backtick ( ) expansion expression. When a user triggers path/file completion via the :find command and presses Tab, Vim evaluates the path option's embedded backtick…
Patched 2026-07-05 - CVE-2026-37064 web MEDIUM
Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
Veno File Manager Project 4.4.9's /vfm-admin/ajax/usr-check.php endpoint allows an unauthenticated attacker to enumerate application users by sending a specially crafted POST request with a chosen username parameter and observing whether the response…
Unverified 2026-07-05 - CVE-2026-37066 web HIGH
Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
Veno File Manager Project 4.4.9 contains a path traversal vulnerability in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php that allows an authenticated attacker with the superadmin role to disclose sensitive information via two specially crafted HTTP…
Unverified 2026-07-05 - CVE-2026-37067 web MEDIUM
Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a chosen date forward via a specially crafted POST request.
Unverified 2026-07-05 - CVE-2026-37068 web CRITICAL
Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the superadmin role to overwrite any PHP file in the application via a specially crafted POST request,…
Unverified 2026-07-05 - CVE-2026-37065 web HIGH
Veno File Manager Arbitrary File Deletion (CVE-2026-37065)
Veno File Manager Project 4.4.9 is vulnerable to arbitrary file deletion. An authenticated attacker with the superadmin role can send a specially crafted POST request using the remove URL parameter to control which file gets deleted, with no further…
Unverified 2026-07-05 - CVE-2026-37069 web LOW
Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
Absolute path disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to learn the system directory in which the application code is running by sending a GET…
Unverified 2026-07-05 - CVE-2026-37072 web CRITICAL
Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
admin-head-updates.php in Veno File Manager 4.4.9 is vulnerable to Local File Inclusion via the unsanitized lang GET parameter. An unauthenticated attacker can send a crafted POST request with a path-traversal payload in lang that corrupts the application's…
Unverified 2026-07-05 - CVE-2026-37073 web MEDIUM
Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
The /vfm-admin/ajax/sendfiles.php endpoint in Veno File Manager 4.4.9 lacks any access control, allowing an unauthenticated attacker to send arbitrary emails through the application's configured SMTP server. By supplying attacker-controlled destination,…
Unverified 2026-07-05 - CVE-2026-37070 web MEDIUM
Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
Veno File Manager 4.4.9 exposes the /vfm-admin/ajax/streamvid.php endpoint without properly restricting which files a session-authenticated user may request. A user who is only supposed to have access to their own assigned directory can instead read any…
Unverified 2026-07-05 - CVE-2026-37071 web HIGH
Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
Veno File Manager 4.4.9's Actions::renameFile() function fails to restrict which files an authenticated user with rename permission can rename. By renaming the application's own vfm-admin/config.php file, an attacker triggers the application into believing it…
Unverified 2026-07-05 - CVE-2026-25050 web MEDIUM
Vendure GraphQL Admin API Authentication Timing Attack / User Enumeration (CVE-2026-25050)
Vendure's NativeAuthenticationStrategy.authenticate() method looks up a user by email and returns immediately (in roughly 1-5ms) when no matching account exists, but performs a costly bcrypt password verification (roughly 200-400ms) when the account does…
Patched 2026-07-05 - CVE-2026-26012 web MEDIUM 6.5
Vaultwarden Organization Collection Permissions Bypass & Cipher Enumeration (CVE-2026-26012)
CVE-2026-26012 is a broken access control vulnerability in Vaultwarden's organization cipher endpoint. The /api/ciphers/organization-details endpoint is reachable by any organization member regardless of their assigned collection permissions, and internally…
Patched 2026-07-05 - CVE-2026-6307 binary CRITICAL
V8 JavaScript Engine Exploit — "Longinus" Kit (CVE-2026-6307)
A full V8 exploit kit targeting CVE-2026-6307, comprising a JavaScript trigger/exploit (poc.js), Python generation and validation tooling (gen.py, val.py) for producing and testing exploit payload variants, and a YARA detection rule for the resulting…
Unverified 2026-07-05 - CVE-2026-4882 web CRITICAL 9.8
User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
The User Registration Advanced Fields plugin (<= 1.6.20) leaks a valid AJAX nonce via wplocalizescript() on any page containing a registration form. Its urafprofilepictureuploadmethodupload AJAX action normally validates uploaded file extensions, but passing…
Unverified 2026-07-05 - CVE-2026-1492 web CRITICAL 9.8 EPSS 24%
User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492)
The plugin's userregistrationmembershipregistermember AJAX handler accepts a client-supplied role field inside the membersdata JSON payload during membership registration, without enforcing a server-side allowlist or capability check. An unauthenticated…
Unverified 2026-07-05 - CVE-2026-6145 web MEDIUM 5.3
User Registration & Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)
The isadmincreationprocess() method in the User Registration & Membership plugin determines whether a new registration should be auto-approved and have its admin notification suppressed, based solely on whether $REQUEST['action'] equals createuser — with no…
Unverified 2026-07-05 - CVE-2026-10795 web CRITICAL
UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
UpdraftPlus ships a remote-management RPC channel (UpdraftCentral) reachable via admin-ajax.php that authenticates requests using an AES-encrypted message keyed to one of several well-known "keyname" identifiers (e.g. migrator.updraftplus.com). When a site…
Unverified 2026-07-05 - CVE-2026-36851 misc HIGH 7.5
UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
UnPoller supports a file:// prefix convention for its UniFi controller password configuration value, intended to read the password from a file on disk. However, the path following the file:// prefix is not restricted, allowing path traversal to read arbitrary…
Unverified 2026-07-05 - CVE-2026-35037 web HIGH
Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
Ech0's GET /api/website/title endpoint fetches a URL supplied by the (unauthenticated) caller to extract a website's title, without restricting the target to safe, external hosts. This allows an unauthenticated attacker to force the Ech0 server to make…
Patched 2026-07-05 - CVE-2026-36522 network CRITICAL 9.1
Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)
ArduPilot ArduPlane's GCSMAVLink::handleparamset() does not validate that a parameter value supplied via a MAVLink PARAMSET message is a well-formed floating-point number. An unauthenticated party able to send MAVLink messages to the vehicle can inject a NaN…
Unverified 2026-07-05 - CVE-2026-27621 web MEDIUM
TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
TypiCMS Core allows users with file-upload permission to upload SVG files, validating only the MIME type without sanitizing the SVG's internal content. Because SVG is an XML-based format that can embed <script> tags, an attacker can upload a malicious SVG…
Patched 2026-07-05 - CVE-2026-33712 web HIGH
Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
Typebot's preview-chat feature lets a caller submit an arbitrary typebot definition, including server-side "Code" blocks that execute inside an isolated-vm sandbox. In vulnerable versions, the fetch() function exposed to that sandbox called Node's native…
Patched 2026-07-05 - CVE-2026-0651 network CRITICAL
TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
This PoC chains three vulnerabilities in the TP-Link Tapo C260 camera to go from unauthenticated (or guest-level) access to root command execution. First, a path traversal flaw in the HTTP GET handler allows arbitrary local file disclosure. Second, a…
Unverified 2026-07-05 - CVE-2026-11834 network CRITICAL
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
TP-Link router firmware processes DHCP Option 66 ("TFTP Server Name") from a lease it acquires on its WAN interface by concatenating the value unsanitized into a tftp shell command inside libcmm.so, which is ultimately passed to system() via utilexecSystem().…
Unverified 2026-07-05 - CVE-2026-8697 network CRITICAL 9.3
TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)
The TP-Link Archer C64 exposes a residual debug SSH service (port 22) that does not grant a shell — it simply closes the connection once a password is entered — but validates the password against the same credential used by the router's web admin interface,…
Unverified 2026-07-05 - CVE-2026-7671 web MEDIUM
Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
The Tornet Scooter mobile application's /TwoFactor backend endpoint does not implement rate limiting or account lockout on one-time-password (OTP) verification attempts. Because the OTP is a 4-digit numeric code (0000-9999), an attacker can brute-force the…
Unverified 2026-07-05 - CVE-2026-41901 web CRITICAL
Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
The PoC reproduces a Spring Expression Language (SpEL) injection in a Thymeleaf-rendered template where user-controlled input is reflected into a template expression context without sanitization. By submitting a crafted SpEL payload such as…
Patched 2026-07-05 - CVE-2026-49772 web CRITICAL 9.3
The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772.py is a full-featured blind SQL injection tool targeting an unauthenticated, unsanitized order parameter on The Events Calendar's experimental REST endpoint GET /wp-json/tec/v1/events. A broken REST parameter validator (validatecallback returns…
Patched 2026-07-05 - CVE-2026-22804 web HIGH
Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)
Termix's built-in File Manager renders SVG files opened from a connected host using dangerouslySetInnerHTML, without stripping active content such as <foreignObject>/<img onerror=...>. An attacker who can place a crafted SVG on a filesystem reachable via…
Patched 2026-07-05 - CVE-2026-11499 network HIGH
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499 is a stack-based buffer overflow (CWE-121) in the web-management formDOMAINBLK handler of Tenda HG7/HG9/HG10 router firmware. The vulnerable code path copies the attacker-supplied blkDomain form parameter into a fixed-size stack buffer without…
Unverified 2026-07-05 - CVE-2026-38426 network CRITICAL 9.8
Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
The fetchjpg() function's initial-connection handling (case 0) in Tasmota's scripter driver extracts the MJPEG multipart boundary string from the HTTP Content-Type response header and copies it into a fixed 40-byte boundary[40] field of the JPGTASK struct…
Patched 2026-07-05 - CVE-2026-38427 network CRITICAL 9.8
Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
When fetching subsequent MJPEG frames (case 2) in Tasmota's scripter driver, fetchjpg() reads the Content-Length header value via atoi() into a uint16t variable. Values above 65535 silently wrap around (e.g. 65537 becomes 1), causing the device to allocate a…
Patched 2026-07-05 - CVE-2026-38422 network CRITICAL 9.8
Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
Tasmota's scripter driver (xdrv10scripter.ino) implements an MJPEG client via fetchjpg() that contains two compounding memory-corruption bugs: a strcpy() overflow of a fixed 40-byte boundary[] buffer when parsing the Content-Type boundary string…
Patched 2026-07-05 - CVE-2026-26903 web MEDIUM
TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)
TanStack Query's internal replaceEqualDeep function recursively performs deep-equality comparisons between old and new query cache data so that unchanged object references can be preserved across re-renders. The recursive implementation has no depth limit or…
Patched 2026-07-05 - CVE-2026-25964 web MEDIUM 4.9
Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 is a path traversal / arbitrary file read vulnerability in Tandoor Recipes' recipe-import workflow. The /api/recipe-import/ endpoint lets an authenticated user set an arbitrary filepath and storage backend on a RecipeImport object without…
Patched 2026-07-05 - CVE-2026-11417 cloud HIGH 3.1
Supply Chain Command Injection in AWS CDK's NodejsFunction — CVE-2026-11417
The AWS CDK NodejsFunction construct bundles Lambda handlers with esbuild during cdk synth, and prior to 2.245.0 it built the esbuild invocation by directly interpolating several user/construct-controlled properties (externalModules, loader, define, inject,…
Patched 2026-07-05 - CVE-2026-35333 network MEDIUM
strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)
strongSwan's attributeenumerate() in src/libradius/radiusmessage.c accepts RADIUS attributes whose length byte is smaller than sizeof(rattrt) (2 bytes). When length == 0, the remaining-data counter underflows to a huge value and the loop's decrement condition…
Unverified 2026-07-05 - CVE-2026-35330 network HIGH
strongSwan EAP-SIM/EAP-AKA Pre-Auth Heap Buffer Overflow via Integer Underflow (CVE-2026-35330)
strongSwan's parseattributes() in src/libsimaka/simakamessage.c reads TLV attribute headers whose length byte counts 4-byte words. For the ATRAND/ATENCRDATA branches, a crafted small length value causes an integer underflow in the computed remaining-data…
Unverified 2026-07-05 - CVE-2026-27886 web CRITICAL
Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
Strapi's Content API allows unauthenticated query-parameter filtering on collection endpoints (e.g. /api/articles) that leaks internal relation data through a boolean oracle. The PoC abuses a where-style filter bypass to enumerate the admin user's email…
Patched 2026-07-05 - CVE-2026-22732 web CRITICAL 9.1
Spring Security Lazy Header Writing Security Header Bypass (CVE-2026-22732)
CVE-2026-22732 affects Spring Security's default "lazy" header-writing mechanism, which normally injects security-related response headers (X-Frame-Options, X-Content-Type-Options, Cache-Control, Strict-Transport-Security, etc.) just before the HTTP response…
Patched 2026-07-05 - CVE-2026-22738 web CRITICAL 9.8
Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
SimpleVectorStore.similaritySearch() builds a filter expression by concatenating a caller-supplied filterKey parameter directly into a Spring Expression Language (SpEL) string that is then evaluated by a full-featured StandardEvaluationContext. Because that…
Patched 2026-07-05 - CVE-2026-20251 web HIGH 8.8 EPSS 19%
Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251)
Splunk Secure Gateway lets mobile clients fetch alert data that is stored in the App Key Value Store and later reconstructed into Python objects using the jsonpickle library. A low-privileged authenticated user can write a crafted document to the mobilealerts…
Unverified 2026-07-05 - CVE-2026-32604 cloud CRITICAL 10
Spinnaker Clouddriver — Git Clone Shell Injection RCE (CVE-2026-32604)
Spinnaker's Clouddriver service exposes an artifact-fetch endpoint (PUT /artifacts/fetch) that, when configured for HTTP-based git authentication, passes a user-supplied branch name unsanitized into a sh -c shell command. Because Clouddriver is the Spinnaker…
Patched 2026-07-05 - CVE-2026-7465 web CRITICAL 8.8
Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
The Spectra Gutenberg blocks plugin registers custom uagb/ block types whose rendering is driven by a rendercallback value that can be influenced by attacker-controlled block content embedded in a post. An authenticated user with Contributor-level privileges…
Unverified 2026-07-05 - CVE-2026-42096 network CRITICAL
Sparx Enterprise Architect / Pro Cloud Server Unauthenticated Binary-Protocol SQL Injection (CVE-2026-42096)
Sparx Pro Cloud Server exposes a SparxCloudLink.sseap endpoint that accepts a proprietary binary protocol used by the Enterprise Architect desktop client to query the underlying repository database. Commands (including raw SQL query strings) are obfuscated…
Unverified 2026-07-05 - CVE-2026-48909 web CRITICAL 9.5
SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
SP LMS's cart model (components/comsplms/models/cart.php) reads the lmsOrders cookie, base64-decodes it, and passes the result directly to PHP's unserialize() with no validation, giving an unauthenticated attacker full control over the deserialized object…
Patched 2026-07-05 - CVE-2026-4112 network HIGH 7.2
SonicWall SMA 8200v Cross-Parameter Blind SQL Injection to Root (CVE-2026-4112)
The SonicWall SMA 8200v management console contains a post-authentication blind SQL injection in the /activeUsers.action endpoint, reachable by any authenticated user regardless of role — including a read-only monitoring account. The application's safeParam()…
Unverified 2026-07-05 - CVE-2026-1056 web CRITICAL EPSS 12%
Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)
Snow Monkey Forms' REST API route handler (SnowMonkey\Plugin\Forms\App\Rest\Route\View.php) contains a logic flaw where supplying method=input causes the handler to skip its CSRF token validation entirely and jump straight to the send() cleanup routine. That…
Unverified 2026-07-05 - CVE-2026-3888 binary HIGH
snapd snap-confine / systemd-tmpfiles Race Condition LPE (CVE-2026-3888)
snap-confine's writable-mimic setup performs a directory swap while constructing a snap's mount namespace, and races with systemd-tmpfiles during this window. A local attacker can exploit this race to poison the namespace being constructed for a privileged…
Patched 2026-07-05 - CVE-2026-0001 web CRITICAL 9
SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
SmarterMail exposes an /api/v1/auth/force-reset-password endpoint intended for authenticated self-service password resets, but the handler fails to validate the caller's identity when the request body sets IsSysAdmin to true. Sending a crafted JSON payload…
Patched 2026-07-05 - CVE-2026-24423 web CRITICAL KEV Ransomware EPSS 88%
SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423
SmarterMail's node-clustering feature allows an administrator to point a node at a "hub" server via the connect-to-hub API. The vulnerability is that the admin-level /api/v1/settings/sysadmin/connect-to-hub endpoint requires no authentication, and the server…
Unverified 2026-07-05 - CVE-2026-23760 web CRITICAL 9.3 KEV Ransomware EPSS 96%
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)
SmarterMail's force-reset-password API endpoint accepts anonymous requests and never validates the caller's existing password or a reset token before changing the password of a system administrator account. By POSTing a JSON body that names an existing admin…
Patched 2026-07-05 - CVE-2026-29781 network HIGH
Sliver C2 Server mTLS Nil-Pointer Panic / Infrastructure Kill-Switch — CVE-2026-29781
Sliver C2's transport-layer protobuf handlers (mTLS, WireGuard, DNS) lack consistent nil-pointer validation and lack a recover() mechanism around packet processing. A party in possession of a captured implant's mTLS certificate, private key, and Age secret…
Unverified 2026-07-05 - CVE-2026-34227 web HIGH
Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
Sliver's MCP server exposes an unauthenticated Server-Sent Events (SSE) interface on 127.0.0.1:8080 and responds to every request with Access-Control-Allow-Origin: . Because the underlying mcp-go library does not validate the request's Content-Type, a…
Unverified 2026-07-05 - CVE-2026-48558 web CRITICAL 9.8 KEV EPSS 11%
SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)
When OIDC authentication is enabled, SimpleHelp accepts identity tokens (ID Tokens/JWTs) at its OIDC callback endpoint without verifying their cryptographic signature — including tokens using alg: none. A remote, unauthenticated attacker can forge a JWT with…
Patched 2026-07-05 - CVE-2026-7459 web HIGH 7.5
Simple History Missing Authorization Account Takeover — CVE-2026-7459
Simple History exposes a REST "reaction" endpoint (/wp-json/simple-history/v1/events/{id}/react) that is missing proper authorization checks when the plugin's experimental features are enabled. A low-privileged, authenticated Subscriber can call this endpoint…
Unverified 2026-07-05 - CVE-2026-11912 web HIGH 7.5
Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
The Simple File List plugin registers its simplefilelisteditjob AJAX action on both the wpajax and wpajaxnopriv hooks, meaning it is reachable by unauthenticated visitors. The authorization check inside eeSFLFileEditor() relies on isadmin(), which always…
Patched 2026-07-05 - CVE-2026-23498 web HIGH
Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
Shopware previously fixed CVE-2023-2017 by restricting Twig filters so that only allow-listed functions could be invoked from templates. CVE-2026-23498 is a regression of that fix: the allow-list check was not applied to array- and closure-crafted values…
Patched 2026-07-05 - CVE-2026-44590 cloud CRITICAL 9.3
Sherlock CI `pull_request_target` Command Injection → GitHub Actions Secret Exfiltration (CVE-2026-44590)
The validatemodifiedtargets.yml GitHub Actions workflow in sherlock-project/sherlock uses the dangerous pullrequesttarget trigger and processes attacker-controlled pull request data (a JSON entry key) in a shell context without sanitization, resulting in…
Patched 2026-07-05 - CVE-2026-30951 web HIGH
Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951
Sequelize v6's JSON/JSONB where-clause processing treats the portion of a JSON path key following a :: delimiter as a SQL cast type, inserting it into the generated SQL query without validation. If an application allows attacker-controlled JSON object keys to…
Patched 2026-07-05 - CVE-2026-45091 crypto HIGH
sealed-env Unseal Token TOTP/Enterprise Secret Disclosure (CVE-2026-45091)
sealed-env's "unseal token" is structured like a JWT (header.payload.signature) but its payload embeds sensitive material — specifically a totpSecret / enterpriseSecret field — in plain base64url-encoded JSON with no additional protection beyond the…
Patched 2026-07-05 - CVE-2026-37750 web MEDIUM 6.1
School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
register.php in School Management System 1.0 reflects the type request parameter into the page's HTML twice — once inside an <h1> tag via ucfirst($REQUEST['type']) and once inside a form action attribute — without applying htmlspecialchars() or any output…
Unverified 2026-07-05 - CVE-2026-9067 web HIGH 8.1
Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
The plugin's saswprfformimageupload AJAX handler does not validate the requesting user's capability nor properly validate the uploaded file's type, allowing an unauthenticated attacker to upload arbitrary files (with a spoofed MIME type/extension) to the…
Unverified 2026-07-05 - CVE-2026-21018 binary HIGH
Samsung SveService Native Out-of-Bounds Write (CVE-2026-21018)
CVE-2026-21018 is an out-of-bounds write in the Samsung system service SveService, which runs as system (UID 1000) and is registered directly via ServiceManager.addService() — bypassing Android's normal signatureOrSystem permission enforcement, so it is…
Unverified 2026-07-05 - CVE-2026-20980 binary CRITICAL
Samsung Android AT-Command Filter Bypass to system_server Code Execution (CVE-2026-20980)
CVE-2026-20980 is the first stage of a three-bug exploit chain against Samsung's AP AT-command handling. The atdistributor daemon filters "protected" AT commands via libpacmclient.so's pacmcheckatcmds, which rejects multi-command payloads by checking for the…
Unverified 2026-07-05 - CVE-2026-46490 / GHSA-34r5-q4jw-r36m web HIGH 8.8
samlify SAML AttributeValue XML Injection → Privilege Escalation (CVE-2026-46490)
samlify's template substitution engine (replaceTagsByValue / escapeTag in src/libsaml.ts) only XML-escapes values that are substituted into XML attribute contexts; values substituted into element text context (such as…
Patched 2026-07-05 - CVE-2026-4480 network CRITICAL EPSS 14%
Samba spoolss Print Job Command Injection RCE (CVE-2026-4480)
This PoC targets a flaw in Samba's spoolss print spooler RPC interface where a submitted print job's document name/content is not safely handled, allowing an attacker who can open a writable printer/share to inject a shell command that gets executed on the…
Patched 2026-07-05 - CVE-2026-23499 web HIGH
Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)
Saleor allowed authenticated staff users or Apps to upload arbitrary file types through its media-upload functionality, including HTML and SVG files containing embedded JavaScript. In deployments where uploaded media is served from the same origin as the…
Patched 2026-07-05 - CVE-2026-22849 web HIGH
Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)
Saleor stores rich text content (page bodies, product descriptions, etc.) as EditorJS block JSON, and is supposed to run this content through a server-side HTML cleaner before persisting and rendering it. In the affected versions that cleaning step was not…
Patched 2026-07-05 - CVE-2026-24136 web HIGH 7.5
Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
Saleor exposes a GraphQL order(id: $id) query used to fetch detailed order information by its global Relay ID. In affected versions this resolver performs no authorization check, so any unauthenticated caller who obtains (or guesses) an order's global ID can…
Patched 2026-07-05 - CVE-2026-27607 cloud HIGH
RustFS — Presigned POST Policy Condition Bypass (CVE-2026-27607)
RustFS is an S3-compatible object storage server. This PoC demonstrates that RustFS fails to properly enforce the conditions embedded in S3 presigned POST policies. Presigned POST is normally used by applications to let clients upload directly to storage…
Patched 2026-07-05 - CVE-2026-21514, CVE-2026-21510 social-engineering HIGH KEV
RTF Protected-View Bypass (CVE-2026-21514) Chained with ShellLink RCE (CVE-2026-21510) — Builder Scripts
This repository contains two small builder scripts used to research a document-based attack chain: genrtf.py assembles a malicious RTF file containing an embedded OLE object whose payload is a hex-encoded UNC path (\\127.0.0.1@80\final.lnk) to a remotely…
Unverified 2026-07-05 - CVE-2026-29198 web CRITICAL
Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
Rocket.Chat's OAuth2 authentication flow builds a MongoDB query from attacker-influenced OAuth2 profile/identity fields without sufficient sanitization, allowing NoSQL injection operators to be smuggled into the user lookup query. By crafting a malicious…
Patched 2026-07-05 - CVE-2026-27831 binary MEDIUM
rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)
rldns is an open-source DNS server for Linux, FreeBSD, and NetBSD. Version 1.3 contains a heap-based out-of-bounds read that can be triggered remotely by sending a specially crafted, malformed DNS-like UDP packet, causing the server process to crash and…
Patched 2026-07-05 - CVE-2026-39023 web CRITICAL
Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
Responsive Filemanager 9.14.0 allows an unauthenticated attacker to abuse its "duplicate file" functionality to create a new file with an attacker-chosen name and PHP extension containing arbitrary content. By duplicating an existing file into a .php file…
Unpatched 2026-07-05 - CVE-2026-4802 web HIGH
Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
Cockpit's systemd logs page builds a journalctl invocation from URL-fragment-derived filter parameters (such as --since=) inside loadServiceFilters(). The resulting argument array is joined into a single shell string with only whitespace escaping and then…
Unpatched 2026-07-05 - CVE-2026-27579 web HIGH 7.4
Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
The realtime-collaboration-platform project configured its Appwrite backend to allow arbitrary cross-origin requests while also enabling Access-Control-Allow-Credentials: true. Because the origin allow-list was effectively unrestricted, an attacker-controlled…
Unverified 2026-07-05 - CVE-2026-36355 network CRITICAL
Realtek rtl819x Jungle SDK Unauthenticated Kernel Memory R/W via Debug IOCTLs (CVE-2026-36355)
The rtl8192cd Wi-Fi kernel driver in Realtek's out-of-tree rtl819x "Jungle SDK" exposes two IOCTLs — writemem (0x89F5) and readmem (0x89F6) — with no access-control checks. These debug handlers are gated only by a macro (IOCTLDEBUGCMD) that is defined…
Unverified 2026-07-05 - CVE-2026-41179 web CRITICAL 9.8
rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
rclone's built-in Remote Control (rcd) HTTP API exposes an /operations/fsinfo endpoint that accepts an attacker-controlled fs= connection-string parameter used to instantiate a storage backend. When the string selects the WebDAV backend, rclone recognizes an…
Patched 2026-07-05 - CVE-2026-1814 misc HIGH
Rapid7 Nexpose Weak Keystore Entropy Credential Decryption — CVE-2026-1814
Rapid7 Nexpose stores site/scan credentials in an exported XML file, with each <credentials> element holding a hex-encoded salt, RSA-wrapped AES key, and AES-CBC-encrypted blob. The private key needed to unwrap the AES key lives in a PKCS12 keystore whose…
Unverified 2026-07-05 - CVE-2026-39324 / GHSA-33qg-7wpp-89cq web CRITICAL
Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)
Rack::Session::Cookie, when configured with the secrets: option for encrypted session cookies, is supposed to reject any cookie that fails decryption. Instead, when all configured encryptors fail to decrypt a cookie, the code silently falls through to the…
Patched 2026-07-05 - CVE-2026-24688 misc HIGH
pypdf Circular Outline Reference Infinite-Loop DoS (CVE-2026-24688)
pypdf's outline (bookmark) parser walks the linked list of outline entries via the /Next pointer without any cycle detection or iteration cap. A PDF crafted with a circular outline reference (an entry whose /Next chain loops back on itself) causes…
Patched 2026-07-05 - CVE-2026-32707 hardware HIGH 7.5
PX4-Autopilot tattu_can Driver — CAN Bus Stack Buffer Overflow DoS (CVE-2026-32707)
The tattucan driver in PX4-Autopilot reassembles multi-frame Tattu12SBatteryMessage telemetry from the battery's CAN bus into a fixed 48-byte stack buffer, but performs the per-frame memcpy() without checking the cumulative write offset against the buffer…
Patched 2026-07-05 - CVE-2026-32743 hardware MEDIUM 6.5
PX4 Autopilot MAVLink FTP Stack Buffer Overflow (CVE-2026-32743)
PX4 Autopilot's MAVLink FTP log-handling code (MavlinkLogHandler / MAVLink FTP directory listing path) copies an attacker-supplied directory path into a fixed-size stack buffer without validating its length. Sending a MAVLink FTP request (e.g. via…
Patched 2026-07-05 - CVE-2026-31900 misc HIGH 8.7
psf/black GitHub Action RCE via Insecure Regex Version Validation — CVE-2026-31900
The psf/black GitHub Action's usepyproject: true option reads the Black version to install from the repository's pyproject.toml. The regex used to validate that version string (^black([^A-Z0-9.\-]+.)$ with re.IGNORECASE) is overly permissive, allowing…
Patched 2026-07-05 - CVE-2026-41462 web CRITICAL 9.8
ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
ProjeQtor's login.php endpoint concatenates the login POST parameter directly into a SQL query without sanitization, allowing an unauthenticated attacker to inject stacked SQL statements. The included exploit crafts a login value that terminates the original…
Patched 2026-07-05 - CVE-2026-42167 network HIGH 8.1
ProFTPD mod_sql Pre-Auth SQL Injection Leading to RCE (CVE-2026-42167)
CVE-2026-42167 is a pre-authentication SQL injection in ProFTPD's modsql logging support. The module's isescapedtext() sanitizer fails to properly neutralize input used to populate logging variables (such as %U), which are substituted into SQL statements…
Patched 2026-07-05 - CVE-2026-0926 web HIGH
Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
Prodigy Commerce exposes an AJAX action, prodigy-render-my-account-widget, that renders a "My Account" widget template chosen via the parameters[templatename] POST parameter. The plugin fails to sanitize or restrict this parameter to an allow-list of…
Unverified 2026-07-05 - CVE-2026-5366 web HIGH
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 is a git argument-injection vulnerability in Prefect's GitRepository storage class (src/prefect/runner/storage.py). The commitsha parameter is stored verbatim with no validation beyond a branch/commitsha mutual-exclusion check, then passed…
Patched 2026-07-05 - CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj] web HIGH EPSS 29%
PraisonAI API Server Missing Authentication (CVE-2026-44338)
PraisonAI's apiserver.py exposes HTTP endpoints (e.g. /agents, /chat) that trigger execution of configured AI agent workflows, but ships with authentication disabled by default and no token/Authorization-header requirement. Any network-reachable client can…
Patched 2026-07-05 - CVE-2026-40487 / GHSA-44wg-r34q-hvfx web HIGH 8.9
Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
Postiz accepts file uploads for post media and validates the file type solely from the client-supplied Content-Type header, with no inspection of the actual file bytes. An attacker can upload an SVG (or HTML) file containing embedded JavaScript while…
Patched 2026-07-05 - CVE-2026-2005 binary CRITICAL
PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
The pgcrypto extension's PGP session-key parsing contains a heap-based buffer overflow that corrupts MBuf structure headers used internally to track ciphertext/plaintext buffers. By crafting malicious PGP messages passed to pgcrypto decryption functions, a…
Unverified 2026-07-05 - CVE-2026-3437 binary HIGH
Portwell Engineering Toolkits Driver Arbitrary Physical Memory R/W LPE (CVE-2026-3437)
portwell.sys, a legitimately signed driver shipped with Portwell Engineering Toolkits v4.8.2, exposes IOCTL handlers that let any local user-mode process read and write arbitrary physical memory via MmMapIoSpace, with no validation of the caller-supplied…
Unverified 2026-07-05 - CVE-2026-25126 web MEDIUM
PolarLearn Forum Vote Count Manipulation (CVE-2026-25126)
CVE-2026-25126 is a business logic flaw in PolarLearn's forum voting API. The POST /api/v1/forum/vote endpoint declares a TypeScript type for the direction field but never validates it at runtime, so the server accepts arbitrary string values instead of only…
Patched 2026-07-05 - CVE-2026-44166 / [GHSA-pq7p-mc74-g65w] web MEDIUM 6.1
PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
PocketBase's auth-with-oauth2 endpoint accepts a client-supplied createData object when provisioning a new user record during OAuth2 sign-up, but never validates the email field inside it against the email address actually verified by the OAuth2 provider. An…
Patched 2026-07-05 - CVE-2026-32096 cloud CRITICAL 9.3
Plunk SSRF via Unvalidated AWS SNS SubscriptionConfirmation — CVE-2026-32096
Plunk's POST /webhooks/sns endpoint is meant to handle AWS SNS subscription confirmation callbacks, but it fetches the attacker-supplied SubscribeURL field directly via fetch() without ever verifying the AWS SNS message signature. Because the endpoint…
Patched 2026-07-05 - CVE-2026-32945 network MEDIUM
PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)
getnamelen() and getname() in pjproject's pjlib-util/src/pjlib-util/dns.c read a 2-byte DNS message-compression pointer via pjmemcpy(&offset, p, 2) without verifying that both bytes fall within the received packet buffer. If the compression-pointer marker…
Patched 2026-07-05 - CVE-2026-25994 network HIGH
PJSIP / PJNATH ICE Session Stack Buffer Overflow via SDP ice-ufrag (CVE-2026-25994)
CVE-2026-25994 is a stack-based buffer overflow in PJNATH's ICE (Interactive Connectivity Establishment) session handling, specifically in pjicesesscreatechecklist() in pjnath/src/pjnath/icesession.c. When constructing the ICE username, the code copies the…
Patched 2026-07-05 - CVE-2026-4885 web CRITICAL
Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
Piotnet Addons for Elementor Pro (<= 7.1.70) exposes a form-builder file-upload AJAX action (pafeajaxformbuilder) that insufficiently validates uploaded file extensions, allowing unauthenticated attackers to upload PHP files disguised with alternate…
Unverified 2026-07-05 - CVE-2026-43494 binary HIGH
PinTheft: RDS zcopy Refcount-Steal Double-Free LPE — Pure NASM Rewrite (CVE-2026-43494)
This is a hand-written, dependency-free x86-64 NASM rewrite of the "PinTheft" Linux local privilege escalation exploit (originally published as PinTheft-go). It targets a refcount double-drop in the RDS zerocopy send path (rdsmessagezcopyfromuser()), which is…
Patched 2026-07-05 - CVE-2026-42569 web CRITICAL
phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
phpVMS ships legacy data-import endpoints (/importer, /importer/index, /import, /legacy/importer) that were intended to be restricted but remain reachable without authentication in versions ≤ 7.0.5. These endpoints accept import/action parameters capable of…
Patched 2026-07-05 - CVE-2026-55584 / GHSA-786w-p5pm-cvgh web HIGH 7.5
phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584
phpSysInfo's PSIALLOWED IP allowlist feature determines the client IP by checking the attacker-controlled X-Forwarded-For header first, then Client-IP, and only falls back to the trustworthy REMOTEADDR socket address last. Because there is no concept of a…
Patched 2026-07-05 - CVE-2026-6664 network HIGH
PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664
PgBouncer's mbufgetbytes() bounds check (lib/usual/mbuf.h) computes buf->readpos + len > buf->writepos using 32-bit unsigned arithmetic, which wraps around when a client supplies a very large length value in a SASLInitialResponse ('p') message, silently…
Patched 2026-07-05 - CVE-2026-4350 web HIGH 8.1
Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 is a path traversal vulnerability in the Perfmatters WordPress performance plugin that allows arbitrary file deletion. The plugin's perfmattersdelete AJAX action (reachable via wp-admin/admin-ajax.php) takes a delete parameter and passes it to a…
Unverified 2026-07-05 - CVE-2026-25212 web CRITICAL 9.9
Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 arises because PMM's internal PostgreSQL user retains SUPERUSER privileges instead of being restricted. An attacker authenticated with only pmm-admin rights can use Grafana's "Add data source" feature to register an arbitrary PostgreSQL data…
Patched 2026-07-05 - CVE-2026-26801 web HIGH
pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 is a Server-Side Request Forgery vulnerability in pdfmake, a popular Node.js PDF generation library. When a document definition (docDefinition) references remote resources in fields such as images, attachments, or files, pdfmake's…
Patched 2026-07-05 - CVE-2026-36239 web CRITICAL
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
PbootCMS's decodestring() function in apps/home/controller/ParserController.php sequentially applies stripcslashes() then htmlspecialcharsdecode() to the "Footer Information" (sitecopyright) admin field, which effectively reverses HTML-entity encoding and…
Unverified 2026-07-05 - CVE-2026-14459 binary HIGH 8.8
Pardus Software Center Local Privilege Escalation via APT Option Injection (CVE-2026-14459 / CVE-2026-14460)
Two local privilege-escalation flaws affect the pardus-software package that powers the Pardus Software Center's PolicyKit-mediated install/update helpers. CVE-2026-14459 (CWE-88, argument injection) arises because the privileged Actions.py helper splits its…
Patched 2026-07-05 - CVE-2026-41651 binary HIGH
PackageKit TOCTOU Local Privilege Escalation (CVE-2026-41651)
PackageKit's transaction handling in src/pk-transaction.c contains a set of logic flaws that combine into a TOCTOU (time-of-check to time-of-use) race condition, nicknamed "Pack2TheRoot" by the researcher. InstallFiles() overwrites cached transaction…
Patched 2026-07-05 - CVE-2026-29000 web CRITICAL 9.8
pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
A vulnerable pac4j JWT configuration accepts unsigned JWTs (alg: "none") and, when JWE encryption is used to wrap tokens, decrypts the outer JWE and trusts the inner JWT's claims without independently verifying that the inner token is signed. The PoC builds…
Patched 2026-07-05 - CVE-2026-21876 web CRITICAL EPSS 13%
OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876)
CVE-2026-21876 is a bypass in the OWASP Core Rule Set (CRS) rule 922110, which is meant to block multipart/form-data parts that declare a forbidden (non-ASCII-safe) character set such as IBM037/EBCDIC. The rule only inspects the charset of the last part in a…
Patched 2026-07-05 - CVE-2026-34940 cloud HIGH 8.7
OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
KubeAI constructs a Kubernetes startup probe shell script by interpolating Model CRD URL components (ref, modelParam) into a bash -c command via Go's fmt.Sprintf. Shell metacharacters in these fields are not sanitized, so any user holding only Model CRD…
Patched 2026-07-05 - CVE-2026-23947 misc HIGH
Orval OpenAPI Codegen Arbitrary Code Execution via Malicious Spec (CVE-2026-23947)
Orval generates TypeScript client code from OpenAPI specifications, and it copies certain vendor-extension fields — specifically x-enumDescriptions and x-enumNames — directly into generated source as comments/string literals without escaping. By crafting an…
Patched 2026-07-05 - CVE-2026-33331 web HIGH
oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)
oRPC's OpenAPI reference plugin renders the generated API docs page by embedding the OpenAPI spec directly into an inline <script id="spec" type="application/json"> block using JSON.stringify(spec), with no HTML-context encoding. Because JSON.stringify() does…
Patched 2026-07-05 - CVE-2026-26198 web CRITICAL 9.8
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 is a SQL injection vulnerability in the Ormar async ORM's min() and max() aggregate query methods. While the sibling sum() and avg() methods validate that the supplied "column" parameter refers to an actual numeric field on the model, min() and…
Patched 2026-07-05 - CVE-2026-21986 binary MEDIUM 7.1
Oracle VirtualBox Shared Folders Kernel Memory Exhaustion DoS (CVE-2026-21986)
CVE-2026-21986 is a denial-of-service vulnerability in the VirtualBox Shared Folders driver interface exposed to Windows guests as the device \\.\VBoxMiniRdrDN. The driver's IOCTLMRXVBOXADDCONN handler accepts user-controlled connection-string buffers and…
Patched 2026-07-05 - CVE-2026-45777 web CRITICAL
OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
Open XDMoD's controllers/userinterface.php endpoint accepts a report title parameter as part of a PDF report generation request. The PoC demonstrates that this value is passed unsanitized into a server-side command execution context (used during PDF/report…
Patched 2026-07-05 - CVE-2026-0766 web HIGH 8.8 EPSS 27%
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
OpenWebUI lets users extend LLM functionality by creating "Tools" containing user-submitted Python code. That code is loaded via loadtoolmodulebyid() in backend/openwebui/utils/plugin.py, which calls exec(content, module.dict) on the submitted source with…
Unverified 2026-07-05 - CVE-2026-24418 web HIGH 8.8
OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
OpenSTAManager's bulk-operations handler for the Scadenzario (payment schedule) module accepts an idrecords[] array via POST at /actions.php?idmodule=18. The arrayclean() helper only strips empty values and never validates that elements are integers, so…
Patched 2026-07-05 - CVE-2026-24415 web MEDIUM
OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)
OpenSTAManager fails to sanitize the righe GET parameter before reflecting it into a hidden HTML input's value attribute across six modificaiva.php modal files (contracts, quotes, invoices, DDT, orders, and interventions modules). Because the parameter is…
Patched 2026-07-05 - CVE-2026-24419 web HIGH
OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
The Prima Nota (journal entry) module's add.php reads the iddocumenti GET parameter, splits it on commas with explode(), but never validates that the resulting elements are integers before imploding them back into a SQL IN() clause used to look up…
Patched 2026-07-05 - CVE-2026-24417 web HIGH
OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
OpenSTAManager's global search AJAX endpoint (/ajaxsearch.php) dispatches the user-supplied term parameter to more than ten module-specific search handlers (Articoli, Ordini, DDT, Fatture, Preventivi, Anagrafiche, Impianti, and others), each of which…
Patched 2026-07-05 - CVE-2026-24416 web HIGH
OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
OpenSTAManager's article pricing AJAX handler (/ajaxcomplete.php?op=getprezzi) builds a UNION SQL query to pull pricing history from invoices and delivery notes. The developer correctly wrapped the idarticolo parameter in the framework's prepare() sanitizer…
Patched 2026-07-05 - CVE-2026-39842 / GHSA-7mqr-33rv-p3mp web CRITICAL 10
OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
OpenRemote's Rules Engine evaluates user-supplied JavaScript rule expressions using the Java Nashorn scripting engine with no sandboxing, SecurityManager, or ClassFilter restrictions. While the API layer explicitly blocks non-superusers from creating Groovy…
Patched 2026-07-05 - CVE-2026-31156 hardware HIGH
OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156
gluegenerator.cpp is a code-generation utility used in the OpenPLCv3 build pipeline to parse a variable-definition header file and emit corresponding glue-code source. The tool accepts input and output file paths as command-line arguments without validating…
Unverified 2026-07-05 - CVE-2026-41900 cloud HIGH 8.6
OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)
OpenLearnX's /api/compiler/execute endpoint runs untrusted user-submitted code inside a sibling Docker container, but the blueprint carries no authentication decorator, so any unauthenticated request can trigger it. The pre-patch executeincontainer() function…
Patched 2026-07-05 - CVE-2026-24849 web CRITICAL 6.5
OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
OpenEMR's Fax/SMS module ships an EtherFax integration whose disposeDoc() handler (in EtherFaxActions.php) takes an attacker-controlled filepath request parameter, checks only that the file exists, and passes it directly to readfile() with no canonicalization…
Patched 2026-07-05 - CVE-2026-22812 web HIGH 8.8 EPSS 17%
OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812)
OpenCode versions before 1.0.216 automatically start a local HTTP server that accepts session-creation and shell-execution requests without any authentication, and does so with permissive CORS behavior. This means any local process, malicious browser tab, or…
Patched 2026-07-05 - CVE-2026-28466 network CRITICAL
OpenClaw Gateway WebSocket Authentication Bypass RCE — CVE-2026-28466
OpenClaw exposes a WebSocket control-plane gateway (/ws) used to manage connected nodes/agents. The gateway's connect handshake accepts a client-supplied auth token and role/scope set without properly validating that the presented token is bound to the…
Patched 2026-07-05 - CVE-2026-41285 network HIGH
OpenBSD slaacd/rad Infinite Loop via Malformed ND Option (CVE-2026-41285)
slaacd and rad each contain their own userland parser for ICMPv6 Neighbor Discovery (ND) options, separate from the kernel's already-correct nd6options() validation. Their parsing loop computes optlen = ndoptlen 8 - 2, and when an attacker sends an ND option…
Patched 2026-07-05 - CVE-2026-33439 web CRITICAL 9.8 EPSS 10%
OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439)
OpenAM's unauthenticated Password Reset pages accept a jato.clientSession parameter that is passed to Encoder.deserialize() without any class allowlist/filtering, allowing an attacker to submit an arbitrary serialized Java object graph. The PoC builds a…
Patched 2026-07-05 - CVE-2026-45401 web HIGH
Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)
Open WebUI v0.9.4 validates user-supplied URLs with a validateurl() function before the server fetches them, intended to block requests to internal/private hosts. However, the validation only checks the initial hostname supplied by the client; when the…
Patched 2026-07-05 - CVE-2026-33317 binary HIGH 8.7
OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)
CVE-2026-33317 is missing bounds validation in entrygetattributevalue() in the OP-TEE PKCS#11 Trusted Application, reachable via the PKCS11CMDGETATTRIBUTEVALUE command. The TA does not verify that each attribute header and its associated data region lie fully…
Patched 2026-07-05 - CVE-2026-7482 misc MEDIUM
Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482
Ollama versions prior to 0.17.1 do not validate that a GGUF model file's declared tensor size matches the actual bytes present in the file. By crafting a GGUF file whose tensor metadata declares a much larger shape than the data actually written, and then…
Patched 2026-07-05 - CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web CRITICAL 9.9
OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
OliveTin lets administrators expose predefined shell commands ("Actions") to end users via a web UI or webhooks, relying on checkShellArgumentSafety() to sanitize user-supplied argument values before they are templated into a command string and passed to sh…
Unverified 2026-07-05 - CVE-2026-24207 network CRITICAL 9.8
NVIDIA Triton Inference Server SageMaker Auth Bypass to Unauthenticated RCE (CVE-2026-24207)
NVIDIA Triton Inference Server exposes separate HTTP endpoints for SageMaker and Vertex AI multi-model integration. These endpoints bypass the operator-configured --http-restricted-api access control, meaning the model-management surface…
Patched 2026-07-05 - CVE-2026-2395 misc MEDIUM
npm `tar` Package Unicode-Normalization Race Condition / File Collision (CVE-2026-2395)
The tar npm package's parallel-extraction mode (jobs > 1) is vulnerable to a race condition rooted in Unicode normalization differences: filenames like collisionss and collisionß can be treated as the same target path due to case/normalization handling, even…
Unverified 2026-07-05 - CVE-2026-3008 binary MEDIUM
Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008
Notepad++'s Find Results panel initializer (sub1400916C0) retrieves the localized find-result-hits string from nativeLang.xml and passes it directly as the format string argument to wsprintfW, with no accompanying variadic data arguments and no validation of…
Unverified 2026-07-05 - CVE-2026-41242 web CRITICAL
Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
The demo Express service accepts a JSON protobuf descriptor from an HTTP request body and passes it straight to protobuf.Root.fromJSON(), then looks up and decodes a message type from that attacker-controlled descriptor. Because protobufjs compiles field/type…
Patched 2026-07-05 - CVE-2026-29786 misc HIGH
Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
The tar package's extraction engine does not sufficiently validate destination paths when an archive entry is of type symlink. An attacker can craft a tarball containing a symlink entry that points outside the intended extraction directory (e.g. to…
Patched 2026-07-05 - CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 misc HIGH
node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
node-tar fails to sanitize absolute paths supplied in the linkpath field of hardlink and symlink tar entries. In src/unpack.ts, the library resolves the link target with path.resolve(this.cwd, String(entry.linkpath)), but path.resolve() ignores the base cwd…
Patched 2026-07-05 - CVE-2026-34200 web CRITICAL 9.6
Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
The Nhost CLI's local MCP server, used to let AI agents/tools manage a developer's Nhost project, has no inbound authentication and inherits a permissive Access-Control-Allow-Origin: CORS policy from the underlying mcp-go library. Because the server does not…
Patched 2026-07-05 - CVE-2026-40701 web MEDIUM 6.3
nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
nginx's resolver contains a use-after-free that is reachable when a server is configured with sslstapling on;, sslstaplingverify on;, and a resolver directive — the combination that causes nginx to perform DNS resolution of the OCSP responder hostname on the…
Patched 2026-07-05 - CVE-2026-0211 web HIGH
Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
This repository is a university penetration-testing course project that models a hypothetical heap buffer overflow in Nginx's QUIC (HTTP/3) packet parser, where the Destination Connection ID (DCID) length field is not properly bounds-checked before being used…
Unverified 2026-07-05 - CVE-2026-9256 web CRITICAL EPSS 10%
nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
This PoC chains two nginx rewrite-engine bugs that share the same root cause — a two-pass mismatch in how isargs/$args length is computed — into a single ASLR-independent remote system() call on a stock, unmodified nginx:1.30.0 Docker image, with no hardcoded…
Unverified 2026-07-05 - CVE-2026-42926 web HIGH
NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926 is an HTTP/2 frame injection issue in NGINX that occurs when a specific vulnerable proxy configuration is used — proxying to an upstream over HTTP/2 (proxyhttpversion 2) while forwarding a client-controlled request body via a variable…
Patched 2026-07-05 - CVE-2026-53519 web INFO
Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
The Nezha Dashboard improperly normalizes its routing paths, allowing a crafted request such as /dashboard../data/config.yaml to escape the intended static-file root and read arbitrary files served by the dashboard process. The PoC uses this path traversal…
Patched 2026-07-05 - CVE-2026-3228 web MEDIUM 6.4
NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
The NextScripts Social Networks Auto-Poster plugin for WordPress fails to sanitize or escape the snapFB post-meta value that backs its [nxsfbembed] shortcode. A user with Contributor-level access (or higher) can store arbitrary JavaScript in this field when…
Unverified 2026-07-05 - CVE-2026-45156 web HIGH 8.1
Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)
Nextcloud's useroidc app processes JWT idtoken values received from ID4me identity providers by splitting the token on . and calling base64decode() on the header and payload segments — but never validates the cryptographic signature (Id4meController.php lines…
Patched 2026-07-05 - CVE-2026-33671 web HIGH
Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
Next.js 16.2.4 vendors a copy of the picomatch glob-matching library inside its own compiled output at nodemodules/next/dist/compiled/picomatch/, pinned to version 4.0.3, which is affected by CVE-2026-33671. Because the vendored copy has its package.json…
Patched 2026-07-05 - CVE-2026-58138 misc CRITICAL 9.8
Netflix Conductor Unauthenticated RCE via INLINE GraalVM Evaluator — CVE-2026-58138
Conductor evaluates user-supplied JavaScript (and Python) expressions in INLINE (and related LAMBDA/DOWHILE/SWITCH) workflow tasks using a GraalVM polyglot context built with full host access (HostAccess.ALL / allowAllAccess(true)). Because the community REST…
Patched 2026-07-05 - CVE-2026-1337 network LOW
Neo4j Bolt Transaction Metadata Log Injection (CVE-2026-1337)
Neo4j writes the transaction metadata field supplied over the Bolt protocol directly into query.log without escaping control characters such as newlines. An authenticated user can therefore embed a crafted metadata value containing full fake log lines, which…
Unverified 2026-07-05 - CVE-2026-21858, CVE-2025-68613 web CRITICAL 10 EPSS 73%
n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613
This PoC chains two n8n vulnerabilities into full unauthenticated remote code execution. First, CVE-2026-21858 is a Content-Type confusion bug in n8n's binary file handling: sending Content-Type: application/json instead of multipart/form-data to a form…
Patched 2026-07-05 - CVE-2026-44789 / GHSA-c8xv-5998-g76h web CRITICAL 9.4
n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
The n8n HTTP Request node's pagination feature (updateAParameterInEachRequest mode) allows an attacker-controlled parameter.type value of proto, causing paginationData.request[parameter.type][parameterName] = parameterValue to write directly onto…
Patched 2026-07-05 - CVE-2026-8161 / GHSA-qxch-whhj-8956 misc MEDIUM
Multiparty Denial of Service via Prototype-Pollution Field Name (CVE-2026-8161)
multiparty@4.2.3 and earlier store parsed multipart field names and files in plain JavaScript objects and rely on ordinary property lookup (fields[name], files[name]) to detect whether a field has been seen before. Because plain-object lookups traverse the…
Patched 2026-07-05 - CVE-2026-3304 web HIGH 8.7
Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
Multer versions before 2.1.0 can leave temporary uploaded files permanently on disk when a multipart request is malformed in a specific way while using an asynchronous fileFilter callback (e.g., one deferred via setImmediate). When a valid file part is…
Patched 2026-07-05 - CVE-2026-6992 network HIGH
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
MR9600 routers with Bluetooth management capability expose a vulnerable JNAP request path that allows command injection via the Bluetooth PIN configuration flow, enabling an attacker to execute arbitrary commands on the router. The PoC reverses the original…
Unverified 2026-07-05 - CVE-2026-0596 web CRITICAL 9.6
MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
MLflow can serve models through Seldon's MLServer runtime, which loads model artifacts using Python's native pickle format. While the REST API's string parameters are handled safely and are not vulnerable to classic OS command injection, the underlying…
Unverified 2026-07-05 - CVE-2026-1668 binary CRITICAL
MIPS-Based Managed Switch Firmware Pre-Auth Kernel RCE — CVE-2026-1668
The switch's embedded web management HTTP server contains a memory-corruption flaw reachable via a crafted request to the /data/login.json endpoint, exploitable before the device's first legitimate HTTP request after boot. The PoC builds a raw MIPS shellcode…
Unverified 2026-07-05 - CVE-2026-36981 binary HIGH
MiniTool pwdrvio.sys Kernel Write-What-Where — Local Privilege Escalation Primitive (CVE-2026-36981)
MiniTool's pwdrvio.sys kernel driver exposes a write-what-where condition through its IOCTL interface, allowing an unprivileged local attacker to write attacker-controlled data to an attacker-controlled kernel address. The included PoC demonstrates a…
Patched 2026-07-05 - CVE-2026-36980 binary MEDIUM
MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)
MiniTool's pwdrvio.sys kernel driver contains a buffer overflow in its IOCTL handler. An unprivileged local attacker can send a crafted IOCTL request that corrupts kernel pool memory, triggering an immediate system crash (BSOD) — a local denial-of-service…
Patched 2026-07-05 - CVE-2026-27483 web CRITICAL EPSS 11%
MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)
MindsDB exposes a /api/handlers/ endpoint that lists available integration handlers, some of which are registered but not actually installed. By selecting one of these available-but-uninstalled handler names, an attacker can abuse a path traversal flaw in the…
Patched 2026-07-05 - CVE-2026-34220 web HIGH
MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220 is a SQL injection vulnerability in MikroORM's handling of Custom Type columns. When a client-supplied JSON value contains a raw property, MikroORM's internal isRaw() check treats it as a trusted, framework-generated Raw SQL expression rather…
Patched 2026-07-05 - CVE-2026-1306 web CRITICAL 9.8
midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
The midi-Synth plugin's export AJAX action insufficiently validates the file type/extension of uploaded MIDI conversion payloads (CWE-434). The handler writes the attacker-supplied, Base64-encoded file content into the plugin's…
Unverified 2026-07-05 - CVE-2026-26030 misc CRITICAL
Microsoft Semantic Kernel In-Memory Vector Store Filter eval() Sandbox Bypass RCE (CVE-2026-26030)
CVE-2026-26030 is a sandbox-bypass remote code execution vulnerability in Semantic Kernel's in-memory vector store search filter evaluation. Agents that expose a search/query tool backed by InMemoryCollection let the LLM emit a filter expression string (e.g.…
Patched 2026-07-05 - CVE-2026-45504 web HIGH
Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 is an authenticated arbitrary file read vulnerability in Microsoft Exchange Server. An attacker with valid mailbox credentials authenticates to OWA and, via the Exchange Web Services (EWS) CreateItem/CreateAttachment SOAP calls, creates a…
Patched 2026-07-05 - CVE-2026-41091 binary HIGH 7.8 KEV
Microsoft Defender Link Following Local Privilege Escalation (CVE-2026-41091)
CVE-2026-41091 is a local privilege escalation vulnerability in Microsoft Defender caused by improper link resolution (CWE-59) during file operations performed with SYSTEM privileges. By racing a Defender-triggered scan against filesystem oplocks, and then…
Unpatched 2026-07-05 - CVE-2026-49345 web CRITICAL
Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
This repository contains two Python PoCs that abuse an unvalidated provider URL parameter in Mercator's ConfigurationController::testProvider endpoint, which the server fetches with libcurl. ssrf2scan.py uses the telnet:// scheme to turn the SSRF into a blind…
Unverified 2026-07-05 - CVE-2026-36356 network CRITICAL EPSS 14%
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
The GoAhead web server bundled with MeiG Smart FORGESLT711 4G LTE CPE devices exposes an unauthenticated HTTP endpoint, /action/SetRemoteAccessCfg, that interpolates user-controlled JSON input into a shell command without sanitization. A single…
Unverified 2026-07-05 - CVE-2026-23744 web CRITICAL EPSS 45%
MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744)
This repository is a German-language Hack The Box "DevHub" walkthrough that documents a full attack chain, one step of which is a genuine, directly reusable RCE against MCPJam Inspector v1.4.2 (CVE-2026-23744). The vulnerable /api/mcp/connect endpoint accepts…
Patched 2026-07-05 - CVE-2026-23520 web CRITICAL
MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
The Model Context Protocol (MCP) connect endpoint /api/mcp/connect accepts a JSON body describing a new server connection, including a command and args array that get executed on the host without sanitization. In many deployments the vulnerable component sits…
Patched 2026-07-05 - CVE-2026-27825 web CRITICAL 9.3
mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)
The confluenceuploadattachment MCP tool in mcp-atlassian passes its filepath argument straight into open(filepath, "rb") with no path validation, letting an attacker read arbitrary files on the server's filesystem and exfiltrate them via a multipart upload to…
Patched 2026-07-05 - CVE-2026-40897 web CRITICAL
Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
Math.js exposes an expression-evaluation API (math.evaluate) intended to run untrusted mathematical expressions inside a restricted sandbox that blocks access to dangerous properties such as constructor. The isSafeProperty guard only inspects direct property…
Patched 2026-07-05 - CVE-2026-4484 web HIGH 8.8
Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
The Masteriyo LMS WordPress plugin's InstructorsController::prepareobjectfordatabase REST API handler fails to verify that the requesting user holds the editusers/promoteusers capability before persisting an arbitrary roles value submitted in the request…
Unverified 2026-07-05 - CVE-2026-56111 hardware HIGH 8.3
Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111
Marlin's M421 G-code handler, used to set Mesh Bed Leveling (MBL) grid points, validates only that the supplied I/J grid indices are non-negative and never checks the upper bound against the actual mesh grid size. The underlying setz() function then writes…
Patched 2026-07-05 - CVE-2026-3494 network MEDIUM
MariaDB server_audit Plugin Logging Bypass via Inline Comments (CVE-2026-3494)
CVE-2026-3494 is a logging-omission regression in MariaDB's serveraudit plugin. When serveraudit is configured with filters such as QUERYDCL, QUERYDDL, and QUERYDML, certain queries containing inline # or -- comments — including queries that trigger error…
Patched 2026-07-05 - CVE-2026-32710 binary CRITICAL
MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
MariaDB's jsongetnormalizedstring() (used by JSONSCHEMAVALID(), sql/jsonschemahelper.cc:91) performs an unbounded strncpy of up to 192 bytes into a 128-byte DYNAMICSTRING buffer, producing a heap out-of-bounds write. The included exploit chains this overflow…
Patched 2026-07-05 - CVE-2026-30849 web HIGH
MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
MantisBT's legacy SOAP API is affected by a PHP loose-comparison ("type juggling") flaw in password verification reachable via the mcissueadd SOAP operation, allowing an attacker to authenticate without knowing a valid password by supplying a specially…
Patched 2026-07-05 - CVE-2026-21509 misc HIGH KEV EPSS 72%
Malicious DOCX/OLE CLSID Object Embedding Builder (CVE-2026-21509)
CVE-2026-21509 concerns Microsoft Word's handling of embedded OLE objects referencing attacker-chosen COM CLSIDs inside a .docx package. The included PoC is a pure-Python builder that assembles a syntactically valid OOXML .docx package containing a minimal…
Unverified 2026-07-05 - CVE-2026-42281 web CRITICAL 9.2
MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
MagicMirror²'s /cors endpoint is designed to proxy cross-origin requests on behalf of the browser, but it performs no validation or allowlisting of the target URL and forwards attacker-controlled headers in both directions. This turns the endpoint into a…
Patched 2026-07-05 - CVE-2026-8836 network CRITICAL 9.8
lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)
lwIP's SNMPv3 User-based Security Model (USM) handler contains a stack-based buffer overflow in snmpparseinboundframe(). A commented-out bounds check combined with an incorrect buffer-size parameter passed to snmpasn1decraw() allows an oversized…
Patched 2026-07-05 - CVE-2026-6130 misc MEDIUM
local-mcp exec Tool Sandbox/Restriction Bypass (CVE-2026-6130)
This is not a standalone PoC script but the actual local-mcp MCP server codebase, whose exec tool contains the real CVE-2026-6130 bypass: a workaround using a generated batch file plus base64 encoding that circumvents intended command-execution restrictions…
Unverified 2026-07-05 - CVE-2026-54420 network HIGH 8.5 KEV
LiteSpeed cPanel/WHM Plugin Symlink Privilege Escalation — CVE-2026-54420
LiteSpeed's cPanel and WHM plugins mishandle user-supplied symbolic links on shared hosting servers isolated with CloudLinux/CageFS. A tenant with FTP or web shell access to their own account can create a symlink (via SITE SYMLINK, rename-based tricks, or…
Unverified 2026-07-05 - CVE-2026-49468 web CRITICAL 9.8
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
exploit.py demonstrates a pre-authentication bypass in the LiteLLM proxy caused by a single crafted Host header (Host: evil/?). LiteLLM's getrequestroute() derives the route used for auth decisions from request.url.path, which Starlette reconstructs from the…
Patched 2026-07-05 - CVE-2026-47102 web HIGH 8.8
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
LiteLLM's /user/update endpoint is meant to let a user update their own account attributes (name, email, metadata). The authorization check canusercalluserupdate() only verifies which user record the caller may modify (their own, or any if they are already…
Patched 2026-07-05 - CVE-2026-40217 web CRITICAL 8.8
LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)
LiteLLM's guardrail-testing endpoint lets authenticated users submit custom Python code that is checked with a regex-based source-code filter meant to block dangerous identifiers such as globals, builtins, and import. Because the filter only inspects source…
Patched 2026-07-05 - CVE-2026-35030 web CRITICAL 9.1
LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
LiteLLM's OIDC userinfo cache uses only the first 20 characters of the presented JWT (token[:20]) as its cache key. Two different, validly-signed JWTs can be crafted to share identical first-20-character prefixes, allowing an unauthenticated attacker to forge…
Patched 2026-07-05 - CVE-2026-35029 web HIGH 8.8 EPSS 26%
LiteLLM /config/update Broken Access Control (CVE-2026-35029)
LiteLLM's /config/update endpoint does not check the caller's role — any authenticated user holding a valid API key, not just a proxyadmin, can modify the proxy's runtime configuration. This allows registering a malicious pass-through endpoint that can be…
Patched 2026-07-05 - CVE-2026-30952 misc HIGH 8.7
LiquidJS Template Engine Path Traversal — CVE-2026-30952
LiquidJS's layout, render, and include tags can resolve absolute file paths even when a root directory restriction is configured, because the library's fallback path-resolution logic does not properly verify that the resolved path stays within the configured…
Patched 2026-07-05 - CVE-2026-53075 binary INFO
Linux Kernel PPP Unprivileged User-Namespace Precondition Probe — CVE-2026-53075
This is a small local diagnostic probe, not a full weaponized exploit. It checks whether the preconditions for CVE-2026-53075 (an unprivileged-user attack path against the kernel ppp driver) are present on the running kernel: it creates an unprivileged…
Patched 2026-07-05 - CVE-2026-23416 binary MEDIUM
Linux Kernel mm/mseal VMA-Merge Stale-Bound Bug (CVE-2026-23416)
CVE-2026-23416 is a logic bug in the kernel's mseal(2) implementation. msealapply() iterates over the target VMAs and advances its cursor by copying a previously-captured vmend value, but the underlying vmamodifyflags() call can merge adjacent VMAs…
Patched 2026-07-05 - CVE-2026-31429 binary MEDIUM
Linux Kernel KFENCE Cross-Cache Free of SKB Head via bpf_prog_test_run_skb — CVE-2026-31429
Linux's skbkfreehead() decides which slab cache to free an SKB's head buffer back to based solely on whether endoffset equals SKBSMALLHEADHEADROOM, relying on the fact that SKBSMALLHEADCACHESIZE is a non-power-of-2 value that normally never collides with a…
Patched 2026-07-05 - CVE-2026-23398 network HIGH
Linux Kernel ICMP Fragmentation-Needed NULL Pointer Dereference (CVE-2026-23398)
CVE-2026-23398 is a NULL pointer dereference in the Linux kernel's ICMP handling path, reachable when a host has net.ipv4.ipnopmtudisc set to 3 (a hardened Path MTU Discovery mode) and receives a crafted ICMP "Fragmentation Needed" (type 3, code 4) packet.…
Patched 2026-07-05 - CVE-2026-43499 binary HIGH 7.8
Linux Kernel Futex-PI rtmutex remove_waiter() Use-After-Free (CVE-2026-43499)
CVE-2026-43499 is a use-after-free in the Linux kernel's removewaiter() function (kernel/locking/rtmutex.c), which is shared between the ordinary rtmutex slow-unlock path and the futex priority-inheritance (PI) proxy-lock rollback path invoked from…
Patched 2026-07-05 - CVE-2026-31694 binary HIGH
Linux FUSE Readdir Cache Out-of-Bounds Write to Root LPE — CVE-2026-31694
fuseadddirenttocache() is missing a bounds check when copying a FUSE server-supplied directory entry into the kernel's readdir page-cache. A malicious (or attacker-controlled) FUSE server can return a dirent with namelen = 4095, which serializes to a…
Patched 2026-07-05 - CVE-2026-31413 binary CRITICAL
Linux BPF Verifier Scalar-Forking Soundness Bug to Container Escape — CVE-2026-31413
The Linux BPF verifier's maybeforkscalars() forks verifier state when it sees an ARSH followed by AND/OR with a constant. The forked ("pushed") path is generated via pushstack(env, env->insnidx + 1, ...), which skips the ALU instruction on that path and…
Patched 2026-07-05 - CVE-2026-30368 web HIGH
Lightspeed Classroom Management Weak Authentication / Device Takeover — CVE-2026-30368
Lightspeed Classroom Management is a Chrome extension used by schools to monitor and remotely control student Chromebooks. The extension's service worker (running classroom.wasm) generates a JWT used to obtain a token for Lightspeed's Ably real-time channel,…
Unverified 2026-07-05 - CVE-2026-36834 binary MEDIUM 6.5
LibRaw pana8.cpp GetDBit() Out-of-Bounds Array Read (CVE-2026-36834)
LibRaw's GetDBit() function, used when decoding Panasonic RW2 raw image files, can return the value 17 when no Huffman table match is found. However, the huffcoeff[] array is declared with only 17 elements (valid indices 0-16), so this out-of-bounds return…
Unverified 2026-07-05 - CVE-2026-0006 binary CRITICAL 9.8
libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
The APV decoder in libopenapv parses two different structures — an AUINFO PBU (Payload Byte Unit) and the actual FRAME PBU — to determine frame dimensions, but oapvdinfo() and oapvddecode() read those dimensions from different sources without cross-validating…
Unverified 2026-07-05 - CVE-2026-0827 binary HIGH
Lenovo LDE (LdeApi.Server.exe) Unimpersonated Junction-Based Arbitrary File Write to SYSTEM (CVE-2026-0827)
The Lenovo LDE service process LdeApi.Server.exe runs as SYSTEM and periodically writes a file named MP27AM7Westimation.json into C:\ProgramData\Lenovo\LDE\SYSTEM without impersonating the calling user and without verifying the target path is a real directory…
Unverified 2026-07-05 - CVE-2026-49083 web HIGH 8.8
LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
This PoC exploits insufficient role validation in LatePoint's customer-to-WordPress-user linking logic. An authenticated attacker holding only a low-privileged "Contributor" WordPress account can create a LatePoint customer record using the email address of…
Unverified 2026-07-05 - CVE-2026-6741 web HIGH 8.8
LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
LatePoint 5.3.0+ registers a WordPress Abilities API ability, latepoint/connect-customer-to-wp-user, that links a LatePoint customer record to an arbitrary WordPress user ID. The ability's permission check only verifies that the calling user holds the…
Patched 2026-07-05 - CVE-2026-39031 crypto HIGH
Lansweeper lsrunase 2.0 / lsencrypt 2.0 — RC4 Password Recovery (CVE-2026-39031)
Lansweeper's lsrunase and lsencrypt 2.0 tools implement a reversible password "encryption" scheme built on RC4 with a key derived from an 8-character cleartext prefix (stored alongside the ciphertext) concatenated with a fixed 142-byte suffix hardcoded into…
Unverified 2026-07-05 - CVE-2026-0770 web CRITICAL KEV EPSS 56%
Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770)
Langflow exposes an API endpoint (/api/v1/validate/code) that is meant to validate user-submitted Python "component" code before it runs inside a workflow. The endpoint evaluates the submitted code using exec() with an execglobals context that is not…
Patched 2026-07-05 - CVE-2026-27966 web CRITICAL 9.8 EPSS 34%
Langflow Remote Code Execution — CVE-2026-27966
Langflow is a low-code platform for building LLM/agent pipelines ("flows") that can include arbitrary code-execution components. This tool detects exposed Langflow instances, and where no existing flow exists, automatically creates one containing a…
Patched 2026-07-05 - CVE-2026-42048 web HIGH
Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
Langflow's DELETE /api/v1/knowledgebases bulk-delete endpoint accepts a list of kbnames values and builds a filesystem path for each by joining it onto the current user's Knowledge Base directory, without normalizing or validating that the resulting path…
Patched 2026-07-05 - CVE-2026-33017 web CRITICAL KEV EPSS 100%
Langflow Custom Component Remote Code Execution — CVE-2026-33017
Langflow exposes a REST API endpoint that builds and runs a "flow" — a graph of nodes describing a data/LLM pipeline. One of the supported node types is a generic custom component whose code field is arbitrary Python that Langflow imports and executes…
Patched 2026-07-05 - CVE-2026-0920 web CRITICAL 9.8
LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
LA-Studio Element Kit for Elementor registers an unauthenticated AJAX action (wpajaxnoprivlakitajax) that handles front-end user registration requests. The handler builds a wpinsertuser() call directly from attacker-supplied POST data, including a lakitbkrole…
Unverified 2026-07-05 - CVE-2026-53360 binary HIGH
KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360
KVM's SEV-SNP Page State Change (PSC) handler trusts a guest-supplied entry count against a fixed protocol constant (VMGEXITPSCMAXCOUNT = 253) instead of validating it against the actual size of the buffer the host allocated for the request. When a guest…
Patched 2026-07-05 - CVE-2026-46680 cloud HIGH
Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
Kubernetes' securityContext.runAsNonRoot: true admission check is meant to prevent Pods from running as UID 0 (root). This PoC demonstrates that a crafted container image with a numeric UID value that overflows the integer type used internally by the…
Patched 2026-07-05 - CVE-2026-38526 web CRITICAL
Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)
Krayin CRM's TinyMCE rich-text editor upload endpoint (/admin/tinymce/upload) fails to properly restrict uploaded file types, allowing an authenticated user to bypass the upload filter using a double-extension technique and upload a PHP webshell. Once…
Unverified 2026-07-05 - CVE-2026-5426 web CRITICAL
KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 stems from KnowledgeDeliver shipping with hardcoded, publicly known decryptionKey/validationKey values in its web.config <machineKey> element. Because ASP.NET Web Forms uses these keys to encrypt and HMAC-sign the VIEWSTATE field, anyone who…
Unverified 2026-07-05 - CVE-2026-8206 web CRITICAL 9.8
Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
The Kirki plugin's CompLibFormHandler REST API endpoint, used by a Kirki-rendered "forgot password" form, does not properly bind the password-reset request to the account that initiated it. This allows an unauthenticated attacker to redirect the…
Unverified 2026-07-05 - CVE-2026-0828 binary HIGH
KillChain — Vulnerable Kernel Driver IOCTL Protected-Process Termination (CVE-2026-0828)
KillChain is a fully-built "Bring Your Own Vulnerable Driver" (BYOVD) tool that embeds a vulnerable kernel driver, ProcessMonitorDriver.sys, directly inside its executable as a raw byte array. At runtime it extracts the driver to a temp path, registers it as…
Unverified 2026-07-05 - CVE-2026-1529 web CRITICAL
Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529
Keycloak's organization invitation flow accepts a JWT invitation token to scope a new user's registration to a specific organization, but the server does not properly validate that the token's claims (notably the organization ID) have not been tampered with…
Unverified 2026-07-05 - CVE-2026-25924 / GHSA-grch-p7vf-vc4f web HIGH 8.4
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
Kanboard defines a PLUGININSTALLER security constant (default disabled) that is meant to prevent installing plugins from remote URLs. The UI correctly hides the plugin-install controls when this constant is off, using Installer::isConfigured() checks in…
Patched 2026-07-05 - CVE-2026-32255 web HIGH 8.6 EPSS 10%
Kan SSRF via Attachment Download Endpoint — CVE-2026-32255
Kan's attachment download proxy endpoint, GET /api/download/attatchment, is intended to stream S3-hosted attachments to clients but instead takes a fully attacker-controlled url query parameter and passes it directly to fetch() on the server with no…
Patched 2026-07-05 - CVE-2026-40864 web MEDIUM
JupyterHub Cross-Origin Form POST XSRF Bypass (CVE-2026-40864)
JupyterHub's XSRF protection, reworked in 4.1.0, uses the browser-supplied Sec-Fetch-Mode header as an origin oracle to decide whether a request is same-origin and therefore exempt from token validation. The implementation incorrectly treats Sec-Fetch-Mode:…
Patched 2026-07-05 - CVE-2026-56290 web CRITICAL 9.8 KEV EPSS 83%
Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290
The Joomla extension Page Builder CK exposes a controller method, browse.ajaxAddPicture, that accepts file uploads with a user-controlled destination path parameter (path) that is only passed through trim() — no whitelist, extension check, or…
Patched 2026-07-05 - CVE-2026-21627 web CRITICAL 9.5
Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
The ajaxTaskInclude() method of the nrframework Joomla plugin is explicitly whitelisted for unauthenticated frontend AJAX access and accepts attacker-controlled path, file, and class parameters. The path parameter uses Joomla's RAW input filter (no…
Patched 2026-07-05 - CVE-2026-49048 web CRITICAL 8.7
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
JoomCCK's custom MVC dispatcher (MControllerBase::execute()) invokes controller tasks without any CSRF token check or ACL/authorization check — its authorise() method is a no-op that always returns true. This makes the tags.save task, whose model method…
Unpatched 2026-07-05 - CVE-2026-25526 web CRITICAL
Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 is a sandbox-escape vulnerability in Jinjava, the Java template engine used by many JVM web applications for user-influenced templating. The PoC shows that Jinjava's rendering context exposes an internal interpreter object (int3rpr3t3r) whose…
Patched 2026-07-05 - CVE-2026-49079 web HIGH 7.5
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
JetSearch's AJAX handlers (invoked via WordPress's admin-ajax.php) fail to properly escape/parameterize user-supplied search parameters, allowing an unauthenticated attacker to perform SQL injection against the underlying WordPress database. The PoC…
Unverified 2026-07-05 - CVE-2026-53435 web HIGH 9.1 EPSS 19%
Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435
Jenkins restricts deserialization via a custom ClassFilter that only allows types defined in Jenkins core or installed plugins. CVE-2026-53435 shows this whitelist is insufficient: an attacker who can POST a view's config.xml can get Jenkins to deserialize a…
Patched 2026-07-05 - CVE-2026-8196 web HIGH
JeecgBoot mLogin Endpoint CAPTCHA Bypass Enabling Credential Brute Force (CVE-2026-8196)
JeecgBoot exposes a secondary login endpoint, /sys/mLogin, that accepts the same username/password credentials as the standard /sys/login endpoint but — unlike /sys/login — does not enforce a CAPTCHA challenge and applies no rate limiting or account lockout.…
Unverified 2026-07-05 - CVE-2026-1281, CVE-2026-1340 network CRITICAL KEV EPSS 82%
Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion (CVE-2026-1281 / CVE-2026-1340)
This is a self-contained Docker/Nginx lab that reproduces the vulnerable Bash logic behind Ivanti EPMM's pre-auth RCE (as documented by watchTowr Labs). The map-appstore-url CGI script parses comma-separated key=value pairs from a crafted appstore URL in a…
Patched 2026-07-05 - CVE-2026-54597 web HIGH
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
ITFlow's agent/ajax.php endpoint accepts an expires parameter that is used unsanitized in a SQL query, enabling a time-based blind SQL injection. An authenticated user can extract arbitrary database values (admin password hash, SMTP credentials, DB version)…
Unverified 2026-07-05 - CVE-2026-54596 web HIGH
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
ITFlow's recurring-invoice handling accepts an unsanitized recurringinvoicefrequency parameter that is placed directly into a SQL query. An authenticated technician-level user with access to an invoice can inject arbitrary SQL, extracting sensitive data…
Unverified 2026-07-05 - CVE-2026-28995 misc HIGH
iOS App Intents Path Traversal — CVE-2026-28995
Apple's App Intents framework insufficiently validates file paths supplied to an intent's handler, allowing a malicious app to read arbitrary files outside its normal app sandbox. The PoC defines an AppIntent whose readCve(path:) function prepends a long…
Patched 2026-07-05 - CVE-2026-23491 web CRITICAL
InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
InvoicePlane v1.6.3's Guest module exposes a getfile controller action that serves uploaded customer files. The action urldecode()s the requested filename and concatenates it directly onto a fixed base directory (uploads/customerfiles/) before passing the…
Patched 2026-07-05 - CVE-2026-49104 web HIGH 8.1
Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
This PoC targets the "Integration for Keap/Infusionsoft" WordPress plugin, whose cf7-infusionsoft.php file calls maybeunserialize() on user-supplied form field values without validation. An unauthenticated attacker can submit a crafted PHP serialized object…
Unverified 2026-07-05 - CVE-2026-9691 web HIGH 8.1
Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
The plugin's cf7-active-campaign.php component calls PHP's maybeunserialize() on user-supplied form field values without validation before forwarding them to ActiveCampaign. An unauthenticated attacker can submit a crafted, serialized PHP object as a form…
Unpatched 2026-07-05 - CVE-2026-35455 web HIGH
Immich Stored XSS to API Key Exfiltration and Account Hijacking (CVE-2026-35455)
A stored XSS vulnerability in Immich allows an attacker to inject a malicious script (via a photo/asset field) that executes in a victim's authenticated session. The included demo automates generation of a new API key from within the hijacked session and…
Patched 2026-07-05 - CVE-2026-0911 web HIGH
Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
The Hustle WordPress plugin's module-import feature (actionimportmodule()) calls WordPress's core wphandleupload() with testtype => false, which disables strict file-type validation during upload. If the subsequently-imported module JSON fails validation, the…
Unverified 2026-07-05 - CVE-2026-23813 network CRITICAL 9.8
HPE Aruba AOS-CX Pre-Auth REST API Bypass via nginx Version Smuggling (CVE-2026-23813)
AOS-CX fronts its management REST API with nginx, which uses an over-permissive regular expression to route requests by API version/login path. By smuggling a login-flavored token into the request path, an unauthenticated attacker can reach REST endpoints…
Patched 2026-07-05 - CVE-2026-10580 web CRITICAL 9.8
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
The Hippoo Mobile App for WooCommerce plugin registers a REST API endpoint (wc-hippoo/v1/ext/wp/v2/users/<id>) that proxies to WordPress's user-management REST routes but fails to properly enforce the underlying capability checks, conflating its own…
Unverified 2026-07-05 - CVE-2026-46395 web CRITICAL 9.8
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
The hmacBase64() function in HAXcms's Node.js backend contains two cryptographic flaws: it signs data with the hard-coded literal key "0" instead of the real signing key, and then appends the real key (privateKey + salt) in plaintext onto the returned token.…
Patched 2026-07-05 - CVE-2026-46394 web HIGH 7.2
HAXcms Git.php OS Command Injection (CVE-2026-46394)
HAXcms's Git.php library builds shell command strings by concatenating unsanitized parameters and executes them via procopen(). Of the 17 functions that shell out, only commit() escapes its input with escapeshellarg() — the remaining 15, including…
Patched 2026-07-05 - CVE-2026-4660 / HCSEC-2026-04 cloud HIGH 7.5
HashiCorp go-getter Git Pathspec Arbitrary File Read (CVE-2026-4660)
go-getter resolves Terraform/Nomad/Packer/Waypoint module sources with ref query parameters passed straight through to git checkout. An attacker can publish a module whose ref is set to a git option such as --pathspec-from-file=/path/to/file instead of a real…
Patched 2026-07-05 - CVE-2026-33555 network HIGH
HAProxy HTTP/3 (QUIC) Standalone FIN Body Validation Bypass Leading to Request Smuggling — CVE-2026-33555
HAProxy's HTTP/3 frontend does not validate that a request's declared Content-Length matches the number of body bytes actually delivered over the QUIC stream before the stream is closed (a "standalone FIN"). When HAProxy translates such a malformed HTTP/3…
Patched 2026-07-05 - CVE-2026-33937 web CRITICAL
Handlebars AST Injection Remote Code Execution — CVE-2026-33937
Handlebars' Handlebars.compile() accepts either a plain template string or a pre-parsed AST object; when given an AST object directly, the normal template-parsing phase (which would otherwise escape/validate literal values) is skipped entirely. Inside the…
Patched 2026-07-05 - CVE-2026-33186 network HIGH
gRPC-Go RBAC Authorization Bypass via Missing Leading Slash in `:path` (CVE-2026-33186)
gRPC-Go's authz package implements RBAC using deny/allow rules matched against the HTTP/2 :path pseudo-header (e.g. /Service/Method). The HTTP/2 server transport stores the raw, pre-normalization :path value in context, but the routing layer (handleStream)…
Patched 2026-07-05 - CVE-2026-25512 web CRITICAL 9.4 EPSS 19%
Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512)
CVE-2026-25512 is an OS command injection in Group-Office's TNEF (winmail.dat) attachment handler. The email/message/tnefAttachmentFromTempFile endpoint takes a user-controlled tmpfile parameter and concatenates it, unescaped, directly into a shell exec()…
Patched 2026-07-05 - CVE-2026-34838 web CRITICAL
Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 is a PHP object deserialization vulnerability in Group-Office. The AbstractSettingsCollection::loadData() method calls unserialize() on a stored setting value prefixed with serialized:, without validating the object type. By storing a crafted…
Patched 2026-07-05 - CVE-2026-4406 web MEDIUM 6.1
Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
The Gravity Forms WordPress plugin (<= 2.9.28) reflects the formids array values from the args parameter of the gformgetconfig AJAX action verbatim into its HTTP response, which is served with Content-Type: text/html; charset=UTF-8. Because the value is…
Patched 2026-07-05 - CVE-2026-48866 web CRITICAL 9.6
Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
Gravity Forms stores the URL of uploaded files in a form entry via the gformuploadedfiles parameter without stripping ../ sequences (escurlraw() and isvalidurl() both accept path-traversal payloads). When an entry containing such a URL is later deleted —…
Patched 2026-07-05 - CVE-2026-6807 network HIGH
GRASSMARLIN XML External Entity (XXE) Out-of-Band File Exfiltration (CVE-2026-6807)
GRASSMARLIN's handling of XML files ingested when opening stored sessions is vulnerable to XML External Entity (XXE) injection. A crafted session XML referencing an external DTD/entity allows out-of-band exfiltration of arbitrary local files from the…
Unverified 2026-07-05 - CVE-2026-32247 web HIGH 8.1
graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
graphiti-core builds Cypher WHERE clauses for its searchnodes functionality by joining caller-supplied node label strings with | and concatenating the result directly into a raw query string, with no parameterization or input validation anywhere in the call…
Patched 2026-07-05 - CVE-2026-21721 web HIGH
Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
This PoC demonstrates a broken-access-control flaw in Grafana's per-dashboard permissions API: an authenticated user holding only the Editor role can read and rewrite the ACL (/api/dashboards/uid/{uid}/permissions) for dashboards they do not own, and use it…
Patched 2026-07-05 - CVE-2026-42589 web CRITICAL 9.8
Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 is an unauthenticated remote code execution vulnerability in Gotenberg 8.29.1's metadata-writing endpoint. Gotenberg forwards user-supplied metadata JSON keys to ExifTool without rejecting control characters; a metadata key containing…
Patched 2026-07-05 - CVE-2026-24135 web HIGH 7.5
Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
Gogs, a self-hosted Git service written in Go, contains a path traversal flaw in the updateWikiPage function used when editing wiki pages. The function sanitizes the new page title before writing the updated file but never sanitizes the previous ("old") title…
Patched 2026-07-05 - CVE-2026-52813 web INFO
Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
Gogs fails to properly sanitize the organization name supplied at organization-creation time, allowing an authenticated attacker to embed path-traversal sequences (../../...) in the name so that it resolves outside the intended organization directory and into…
Patched 2026-07-05 - CVE-2026-28372 binary HIGH 7.4
GNU inetutils telnetd Local Privilege Escalation via NEW-ENVIRON Injection — CVE-2026-28372
GNU inetutils telnetd forwards client-controlled environment variables — negotiated via the Telnet NEW-ENVIRON option — to the login(1) process it spawns without adequately sanitizing them. On systems where the installed login (from util-linux) supports a…
Patched 2026-07-05 - CVE-2026-32746 network CRITICAL 9.8 EPSS 24%
GNU InetUtils telnetd LINEMODE SLC Pre-Auth Buffer Overflow (CVE-2026-32746)
GNU InetUtils telnetd's addslc() function in telnetd/slc.c appends 3 bytes per SLC (Set Local Characters) triplet into a fixed 108-byte buffer (slcbuf) with no bounds checking. During telnet option negotiation, before any login prompt is shown, an…
Unverified 2026-07-05 - CVE-2026-5173 web HIGH
GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173 allows a low-privileged authenticated GitLab user to invoke backend GraphQL methods over the /-/cable ActionCable WebSocket endpoint via the GraphqlChannel, methods that should otherwise be gated by normal GraphQL authorization checks. The PoC…
Patched 2026-07-05 - CVE-2026-28699 web HIGH
Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
Gitea lets an OAuth2 application obtain an access token restricted to a subset of a user's permissions (e.g. read:user only), and enforces that restriction through a tokenRequiresScopes middleware. The middleware relies on an ApiTokenScope value that is…
Patched 2026-07-05 - CVE-2026-27771 web CRITICAL EPSS 43%
Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
Gitea's OCI Distribution Spec API (/v2/<name>/manifests/<ref>, /v2/<name>/blobs/<digest>) serves container image content to anonymous/ghost users without ever checking the package owner's configured visibility (private, limited, or public). The…
Patched 2026-07-05 - CVE-2026-29053 web HIGH
Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053
Ghost CMS uses the jsonpath package, which internally relies on static-eval to interpret JSONPath filter expressions embedded in Handlebars theme templates. static-eval is explicitly documented upstream as unsafe for untrusted input, yet Ghost passes…
Patched 2026-07-05 - CVE-2026-26980 web CRITICAL EPSS 69%
Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980)
Ghost CMS's Content API filter parser (slug-filter-order.js) builds a raw SQL ORDER BY ... CASE WHEN slug IN (...) clause by directly interpolating user-supplied slug values from the filter=slug:[...] query parameter instead of using parameterized query…
Patched 2026-07-05 - CVE-2026-5201 binary HIGH 7.5
gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201
gdk-pixbuf's direct JPEG loading path (gdkpixbufjpegimageload / gdkpixbufrealjpegimageload in io-jpeg.c) allocates the output pixel buffer based on the expected number of color components (3 for RGB, 4 for CMYK) without validating that libjpeg's actual…
Patched 2026-07-05 - CVE-2026-25895 web CRITICAL 9.8
FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)
FUXA's POST /api/upload endpoint (server/api/projects/index.js:193) is registered without the middleware chain applied to every other project-management route, so it bypasses both the JWT/API-key check and the admin permission gate — even when the…
Patched 2026-07-05 - CVE-2026-1208 web MEDIUM 4.3
Friendly Functions for Welcart WordPress Plugin CSRF (CVE-2026-1208)
The Friendly Functions for Welcart plugin's settings page fails to validate a nonce or verify request origin when processing settings updates, exposing a classic CSRF flaw. An unauthenticated attacker can craft an auto-submitting HTML form targeting the…
Patched 2026-07-05 - CVE-2026-28289 web CRITICAL 10 EPSS 31%
FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289
FreeScout automatically saves incoming email attachments to a predictable, web-accessible storage path, and attempts to block dangerous filenames such as .htaccess. This PoC bypasses that filter by prepending a zero-width Unicode character to the .htaccess…
Patched 2026-07-05 - CVE-2026-46376 web CRITICAL 9.1
FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)
FreePBX's optional UCP generic template setup feature (available since 2021) creates a system user named FreePBXUCPTemplateCreator with a hard-coded, static password (1a2b3c@fd48jshs03123ld) embedded in Userman.class.php. If an administrator runs this setup…
Patched 2026-07-05 - CVE-2026-45250 binary CRITICAL
FreeBSD setcred(2) Kernel Stack Buffer Overflow — Local Privilege Escalation (CVE-2026-45250)
kernsetcredcopyinsuppgroups() in sys/kern/kernprot.c uses sizeof(groups) where groups is declared as gidt , so the size expression evaluates to 8 bytes (pointer size) instead of the intended 4 bytes (sizeof(gidt)). When the supplementary-groups count is small…
Unverified 2026-07-05 - CVE-2026-49417 binary HIGH
FreeBSD OSS /dev/dsp Stale Kernel-Stack Buffer Local Privilege Escalation (CVE-2026-49417)
exp.c is a local FreeBSD kernel privilege-escalation exploit built around /dev/dsp (the OSS sound driver). It sprays hundreds of pthreads that call nanosleep() with distinctively tagged tvnsec values so their kernel stacks/return addresses are recognizable,…
Unverified 2026-07-05 - CVE-2026-49413 binary HIGH
FreeBSD Linuxulator AT_SECURE=0 Local Privilege Escalation via LD_PRELOAD (CVE-2026-49413)
exploit.c is a local privilege-escalation PoC targeting FreeBSD's Linux compatibility subsystem. It detects whether the Linuxulator is loaded and glibc's dynamic linker is present under /compat/linux/, locates a setuid-root Linux binary within that tree, and…
Unverified 2026-07-05 - CVE-2026-7270 binary CRITICAL
FreeBSD exec_args_adjust_args() Out-of-Bounds memmove — Local Privilege Escalation via sshd Race (CVE-2026-7270)
An operator-precedence bug in FreeBSD's execargsadjustargs() (present since 2013) computes a memmove size using + consume instead of - consume, causing the copy length to be roughly double the correct value. With a ~265KB argv[0] supplied via a shebang exec,…
Unverified 2026-07-05 - CVE-2026-45258 binary CRITICAL
FreeBSD /dev/dsp (OSS) Negative-Offset mmap Kernel Memory Corruption LPE (CVE-2026-45258)
This PoC targets a FreeBSD kernel local privilege escalation reachable through the OSS /dev/dsp audio device driver. By configuring device fragment sizes via ioctl(SNDCTLDSPSETFRAGMENT, ...) and then mmap-ing the device with a crafted negative file offset,…
Unverified 2026-07-05 - CVE-2026-53647 web MEDIUM 6.9
FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 is an unauthenticated information disclosure vulnerability in FOSSBilling's guest API. The endpoint /api/guest/serviceapikey/getinfo returns the full service configuration — including custom fields, API credentials, internal hostnames, and…
Patched 2026-07-05 - CVE-2026-39808 network CRITICAL 9.8 KEV EPSS 91%
FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)
FortiSandbox versions 4.4.0 through 4.4.8 contain a critical OS command injection vulnerability in the tracer-behavior API endpoint (job-detail/tracer-behavior), reachable via the jid request parameter. Improper neutralization of special shell characters…
Unverified 2026-07-05 - CVE-2026-25089 network CRITICAL 9.8 KEV EPSS 74%
Fortinet FortiSandbox "Start VNC" OS Command Injection (CVE-2026-25089)
FortiSandbox's Web UI "start VNC" feature passes a caller-supplied virtual machine name into an OS command without proper neutralization of shell metacharacters, allowing an unauthenticated attacker to inject arbitrary commands executed on the underlying…
Patched 2026-07-05 - CVE-2026-24018 binary HIGH
Fortinet FortiClientLinux VPN Config Symlink/Shared-Object Loading LPE — CVE-2026-24018
FortiClientLinux allows a VPN connection profile to reference a custom pre/post-connect shared object (.so) file path that gets loaded by a component of the client running with elevated privileges. Because the path is followed without validating…
Unverified 2026-07-05 - CVE-2026-44277 web CRITICAL
FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277 is described by the vendor/advisory as an unauthenticated remote code execution vulnerability in Fortinet FortiAuthenticator, caused by improper access control on specific API endpoints. The included script is a reconnaissance/detection tool…
Patched 2026-07-05 - CVE-2026-5229 web CRITICAL 9.8
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
The Form Notify WordPress plugin's LINE Login OAuth callback resolves the local WordPress account to log into purely by matching an email address, without ever verifying that the connecting LINE account was previously linked to that WordPress user. In…
Patched 2026-07-05 - CVE-2026-30824 web CRITICAL 9.8 EPSS 36%
Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824
Flowise's global authentication middleware whitelists the /api/v1/nvidia-nim/ path, exposing NVIDIA NIM container management and API token generation endpoints to unauthenticated remote access (CWE-306: Missing Authentication for Critical Function). An…
Patched 2026-07-05 - CVE-2026-54337 web INFO
Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
Fireshare's public upload endpoint (/api/upload/public) accepts multipart form fields (file, filename, folder) that are passed largely unsanitized into a downstream ffmpeg invocation used to process the uploaded video. By embedding extra ffmpeg-style…
Unverified 2026-07-05 - CVE-2026-6770 binary MEDIUM
Firefox/Tor Browser IndexedDB Ordering Fingerprint — CVE-2026-6770
Prior to the fix, Firefox's indexedDB.databases() API returned database names in an implementation-specific (non-alphabetically-sorted) internal order rather than a canonical sorted order. Because this ordering can vary based on subtle…
Unverified 2026-07-05 - CVE-2026-56121 misc CRITICAL 9.8
Feast Registry gRPC Unauthenticated RCE via dill.loads — CVE-2026-56121
Feast's registry gRPC server deserializes the user-defined function (UDF) body of an OnDemandFeatureView with dill.loads() (a pickle superset) the moment a spec is received via the ApplyFeatureView RPC — before any permission check runs. Because the default…
Patched 2026-07-05 - CVE-2026-43893 / GHSA-cw26-7653-2rp5 misc HIGH 8.2
exiftool-vendored.js Argument Injection via Newline-Delimited Tag Names (CVE-2026-43893)
exiftool-vendored sends caller-supplied strings (tag names in the object passed to exiftool.write(), filenames, and other options) to the underlying ExifTool process via stdin, one argument per line, without filtering embedded newline/carriage-return/NUL…
Patched 2026-07-05 - CVE-2026-3102 binary HIGH
ExifTool Metadata Field Command Injection (macOS) — CVE-2026-3102
The PoC demonstrates a command-injection pattern in ExifTool's metadata tag-copy workflow: a crafted DateTimeOriginal value containing shell metacharacters is written into an image's metadata, and when the image is later processed with -tagsFromFile ...…
Patched 2026-07-05 - CVE-2026-3296 web CRITICAL 9.8
Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
Everest Forms saves submitted form field values into the wpevfentrymeta table using maybeserialize(), and its sanitization routine (sanitizetextfield()) strips HTML/null bytes but does not strip PHP serialization control characters, so an attacker can submit…
Patched 2026-07-05 - CVE-2026-3300 web CRITICAL EPSS 41%
Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300)
Everest Forms Pro's Calculation Addon evaluates form field expressions server-side without properly sandboxing attacker-controlled input, allowing an unauthenticated visitor to break out of the expression context and inject arbitrary PHP that gets executed by…
Unverified 2026-07-05 - CVE-2026-1657 web MEDIUM
EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
The EventPrime WordPress plugin registers an AJAX action epuploadfilemedia with nopriv support, meaning any unauthenticated visitor can reach it. The handler uploadfilemedia() in includes/class-ep-ajax.php neither checks a user capability (currentusercan())…
Patched 2026-07-05 - CVE-2026-40776 / Patchstack PSID 85de025d71e7 web HIGH 7.5
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
The Eventin WordPress plugin (10,000+ active installs) exposes a public REST endpoint, /wp-json/eventin/v1/nonce, that hands a valid wprest nonce to any unauthenticated visitor. Three separate REST controllers then treat possession of that nonce as sufficient…
Patched 2026-07-05 - CVE-2026-33656 web CRITICAL
EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
EspoCRM's Formula scripting engine (Formula/action/run) can be abused by an admin-authenticated user to bypass access controls and directly rewrite the sourceId field of an Attachment record, redirecting where uploaded chunk data is written on disk via path…
Patched 2026-07-05 - CVE-2026-33657 web MEDIUM
EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
EspoCRM 9.3.3 renders stream-post notification emails by converting a Note's Markdown body to HTML and inserting the result into the email template using an unescaped triple-brace placeholder ({{{post}}}), which skips HTML entity escaping normally applied by…
Patched 2026-07-05 - CVE-2026-33534 web MEDIUM
EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
EspoCRM 9.3.3 blocks direct requests to http://127.0.0.1/... in its /api/v1/Attachment/fromImageUrl endpoint, but the underlying fetch logic does not normalize alternative IPv4 representations of the loopback address (octal, hex, decimal-dword, and…
Patched 2026-07-05 - CVE-2026-2600 web MEDIUM 6.4
ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 is a stored cross-site scripting vulnerability in the ElementsKit Elementor Addons plugin's Simple Tab widget. The widget renders tab titles (ekittabtitle) with echo and no output escaping in widgets/tab/tab.php. While Elementor's page-builder…
Patched 2026-07-05 - CVE-2026-22243 web CRITICAL
EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)
CVE-2026-22243 is a critical authenticated SQL injection in EGroupware's Nextmatch widget filter processing (used across modules such as InfoLog and Address Book). The application's database layer (Api\Db, Api\Storage\Base, infologso) treats array keys of the…
Patched 2026-07-05 - CVE-2026-26897 web MEDIUM 6.3
EcoOnline EHS Android App — Deep Link Validation Bypass to WebView Open Redirect (CVE-2026-26897)
EcoOnline EHS for Android is a WebView wrapper app that loads its content from a trusted domain and enforces a host allow-list (isInternalHost) whenever it restores or navigates URLs. The app also registers an exported, scheme-only custom URL handler…
Patched 2026-07-05 - CVE-2026-9018 web HIGH 8.8
Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
The easyelhandleregister() function, exposed via the unauthenticated wpajaxnopriveelregister AJAX action, passes attacker-controlled custommeta POST array values directly into updateusermeta() without any key whitelist. Because WordPress stores a user's…
Patched 2026-07-05 - CVE-2026-34036 web MEDIUM
Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
Dolibarr's core/ajax/selectobject.php endpoint, used to power object-picker autocomplete widgets in the UI, accepts an objectdesc parameter that is used to build a path to a local file. An authenticated user can craft an objectdesc value (in the form…
Patched 2026-07-05 - CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web CRITICAL
Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
Dolibarr's ODT-to-PDF document conversion feature builds a shell command by concatenating the admin-configurable MAINODTASPDF global setting with a sanitized filename before passing it to PHP's exec(). While the filename argument is escaped with…
Patched 2026-07-05 - CVE-2026-24009 misc HIGH
docling-core Unsafe YAML Deserialization Leading to Code Execution — CVE-2026-24009
docling-core's DoclingDocument.loadfromyaml() deserializes YAML using yaml.load(f, Loader=yaml.FullLoader) rather than a safe loader. When paired with a vulnerable PyYAML version (< 5.4, related to CVE-2020-14343), a crafted YAML document can trigger code…
Patched 2026-07-05 - CVE-2026-5172 network INFO
dnsmasq extract_addresses() RDLEN/RDATA Buffer Overflow — CVE-2026-5172
The PoC targets extractaddresses() in dnsmasq, which parses resource records (RRs) returned by an upstream DNS server. The function is reported to trust the RR's declared RDLENGTH field without properly validating it against the actual RDATA bytes present in…
Patched 2026-07-05 - CVE-2026-4893 network MEDIUM
dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)
This PoC demonstrates that dnsmasq, when configured with EDNS Client Subnet (ECS, RFC 7871) via add-subnet, will accept an upstream DNS response carrying an ECS option whose subnet does not match the subnet dnsmasq originally sent in the query. The included…
Patched 2026-07-05 - CVE-2026-33033 web MEDIUM
Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
Django's multipart form parser has a special path for file parts declared with Content-Transfer-Encoding: base64. When the stripped chunk length isn't a multiple of 4, the parser calls fieldstream.read(1) in a loop to pull additional bytes for alignment. If…
Patched 2026-07-05 - CVE-2026-1207 web HIGH EPSS 13%
Django GIS RasterField SQL Injection (CVE-2026-1207)
The reproduction project demonstrates a SQL injection flaw in GeoDjango's raster query handling. When a view builds a RasterField lookup such as rastcontains=(rast, band), the band value taken directly from an HTTP query parameter is concatenated into the…
Patched 2026-07-05 - CVE-2026-5118 web CRITICAL 9.8
Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
Divi Form Builder <= 5.1.2's createuser() logic (in FormSubmissionHandler.php) reads a role value directly from submitted form POST data and only checks that the role exists in WordPress (e.g. administrator is a valid role name) rather than checking that it…
Unverified 2026-07-05 - CVE-2026-38934 web HIGH 8.8
diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)
public/settingsprocess.php in diskover-community (<= 2.3.5) accepts sensitive configuration-changing POST requests without validating any CSRF token. An attacker can craft a self-submitting HTML form that, when opened by an authenticated administrator,…
Unverified 2026-07-05 - CVE-2026-49952 web CRITICAL
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
This is a multi-stage, pre-auth-to-RCE exploit chain against Discuz! X5.0 that combines several bugs: an authcode-based DB export/import feature is abused to leak the admin's username and MD5 password hash from a database backup; the exploit then registers a…
Unverified 2026-07-05 - CVE-2026-0776 binary HIGH 7.3
Discord Desktop Client Uncontrolled Search Path Element / Local Code Execution (CVE-2026-0776)
CVE-2026-0776 is an Uncontrolled Search Path Element (CWE-427) issue in the Discord Desktop Client on Windows: under certain conditions the Electron/Node.js runtime resolves and loads native/JS modules from a filesystem location that a local, unprivileged…
Unverified 2026-07-05 - CVE-2026-31635 binary HIGH
DirtyDecrypt-Go — RxRPC rxgk Page-Cache Overwrite LPE (Go Port) — CVE-2026-31635
This is a Go re-implementation ("port") of the original C dirtydecrypt PoC, now tracked as its own CVE (CVE-2026-31635). The bug is a missing skbcowdata() call in rxgkdecryptskb(): the krb5enc AEAD used by RxRPC's rxgk security class decrypts skb payload data…
Patched 2026-07-05 - CVE-2026-44262 / [GHSA-4rm2-28vj-fj39] web CRITICAL
dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
dedoc/scramble generates OpenAPI documentation for Laravel APIs by statically analyzing controller code, including validation rules. Its NodeRulesEvaluator::doEvaluateExpression() routine calls PHP's extract($variables) immediately before eval("return…
Patched 2026-07-05 - CVE-2026-47668 web CRITICAL 3.1
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
DbGate's dbgate-serve component exposes a JSON "script runner" (POST /runners/start) that dynamically builds and executes JavaScript in a Node.js child process based on user-supplied fields. Two of these fields, functionName and variableName, are embedded…
Patched 2026-07-05 - CVE-2026-48017 / GHSA-hv83-ggc4-v385 web HIGH 8.8
DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
DbGate's POST /runners/load-reader endpoint takes a functionName parameter and concatenates it directly into a JavaScript template string that is later executed in a forked runner process, without sanitization or validation. An authenticated attacker can…
Patched 2026-07-05 - CVE-2026-41490 web HIGH
Dagster Database I/O Manager SQL Injection via Dynamic Partition Keys (CVE-2026-41490)
All five Dagster database I/O-manager packages share a copy-pasted helper, staticwhereclause, that builds SQL WHERE/DELETE clauses by f-string-interpolating partition key values with no escaping. For statically defined partitions this is safe because the…
Patched 2026-07-05 - CVE-2026-3805 network HIGH
curl SMB Connection-Reuse Use-After-Free (CVE-2026-3805)
libcurl's SMB protocol handler stores a request-scoped req->path pointer that points into memory owned by a temporary "needle" connection object used during connection-cache lookup (smbc->share). When a second SMB transfer to the same server reuses an…
Patched 2026-07-05 - CVE-2026-34975 web HIGH 8.5
CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
Plunk's POST /v1/send endpoint builds a raw MIME email message by interpolating user-supplied fields (from.name, subject, custom headers, attachment filenames) directly into a template string without sanitizing CRLF (\r\n) sequences. An authenticated API user…
Patched 2026-07-05 - CVE-2026-34038 web CRITICAL 10
Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
Coolify builds shell commands for application deployment by interpolating user-supplied configuration fields — notably dockerfilelocation and predeploymentcommand — directly into shell strings executed inside the build/deploy container, without adequate…
Patched 2026-07-05 - CVE-2026-57517 web CRITICAL 9.8
Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517
Control Web Panel versions <= 0.9.8.1224 contain a pre-authentication blind SQL injection in the userRes POST parameter of the user panel endpoint (/{username}/). The backend query runs with MySQL root privileges, which hold the global FILE privilege,…
Patched 2026-07-05 - CVE-2026-4257 web CRITICAL EPSS 41%
Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257)
CVE-2026-4257 is an unauthenticated Server-Side Template Injection (SSTI) vulnerability in the "Contact Form by Supsystic" WordPress plugin's prefill functionality (cfsPreFill parameter). A form field value is rendered through the Twig template engine without…
Unverified 2026-07-05 - CVE-2026-37749 web CRITICAL 9.8
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
The login form in index.php of CodeAstro Simple Attendance Management System 1.0 concatenates the username POST parameter directly into a MySQL query with no sanitization or prepared statements. An unauthenticated attacker can submit a classic SQL injection…
Unverified 2026-07-05 - CVE-2026-4631 web CRITICAL 9.8 EPSS 15%
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
Cockpit's remote-login feature passes attacker-controlled hostnames (from the URL path) and usernames (from the Authorization: Basic header) directly to the OpenSSH ssh client without validation or a -- end-of-options separator. Because both values are used…
Patched 2026-07-05 - CVE-2026-54316 misc MEDIUM
Claude Code WebFetch Hardcoded HuggingFace Bare-Hostname Allow-List Bypass — CVE-2026-54316
CVE-2026-54316 (GHSA-fg94-h982-f3mm) is a permission-prompt bypass in Claude Code's WebFetch tool: versions from 0.2.54 up to (but not including) 2.1.163 hardcoded huggingface.co as a bare, pre-approved hostname, so any path on that domain — including…
Patched 2026-07-05 - CVE-2026-20182 network CRITICAL 10 KEV EPSS 90%
Cisco Catalyst SD-WAN Peering Authentication Bypass — CVE-2026-20182
Cisco Catalyst SD-WAN Controller and Manager rely on a peering authentication handshake between fabric control-plane devices over DTLS on UDP port 12346, handled by the vdaemon process. A flaw in how this control-connection handshake enforces peering…
Patched 2026-07-05 - CVE-2026-23842 misc HIGH 7.5
ChatterBot Denial of Service via SQLAlchemy Connection Pool Exhaustion (CVE-2026-23842)
ChatterBot's default SQLAlchemy storage adapter uses an unbounded/default QueuePool configuration with no concurrency throttling, request rate limiting, or explicit session lifecycle management. When many threads call getresponse() concurrently, each checks…
Patched 2026-07-05 - CVE-2026-33715 / GHSA-mxc9-9335-45mc web HIGH 7.5
Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
Chamilo LMS ships an installation-wizard AJAX endpoint, public/main/inc/ajax/install.ajax.php, that unlike every other AJAX endpoint in the codebase never includes global.inc.php — the file responsible for enforcing session/authentication checks — and remains…
Unverified 2026-07-05 - CVE-2026-29041 web HIGH 8.8
Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
Chamilo LMS's ckuploadimage AJAX endpoint (main/inc/ajax/document.ajax.php?a=ckuploadimage) validates uploaded files solely by inspecting magic bytes via PHP's mimecontenttype(), without checking the file extension or sanitizing the stored filename. An…
Patched 2026-07-05 - CVE-2026-2749 web CRITICAL
Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
This repository bundles three distinct, authenticated vulnerabilities in Centreon that were disclosed together. CVE-2026-2749 is a path traversal flaw in the Open Tickets upload feature that allows arbitrary file write, which can be escalated to remote code…
Patched 2026-07-05 - CVE-2026-6815 web HIGH
Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
Casdoor's Local File System storage provider fails to properly sanitize the pathPrefix configuration and fullFilePath parameter during resource uploads. An authenticated administrator (or equivalent privileged user) can use directory traversal sequences to…
Unverified 2026-07-05 - CVE-2026-39949 web HIGH
Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
Cacti substitutes user-controlled host metadata — specifically the device "notes" field — into RRDtool command-line arguments through its variable replacement engine without sanitizing shell metacharacters. An authenticated attacker who can create devices and…
Patched 2026-07-05 - CVE-2026-2576 web HIGH 7.5
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
The Business Directory Plugin's ORM query builder (class-db-query-set.php) safely parameterizes scalar filter values with $wpdb->prepare(), but falls back to raw string concatenation whenever a filter value is an array. The plugin's checkout controller reads…
Patched 2026-07-05 - CVE-2026-8181 web CRITICAL 9.8 EPSS 15%
Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)
Burst Statistics' ismainwpauthenticated() function (in class-mainwp-proxy.php) checks whether wpauthenticateapplicationpassword() returned a WPError, but does not verify that it returned an actual WPUser. When the call is made outside WordPress's normal REST…
Patched 2026-07-05 - CVE-2026-31816 web CRITICAL EPSS 15%
Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816
Budibase exposes an integrations/webhooks-related endpoint pattern (/api/integrations?/webhooks/trigger) that can be reached without authentication, and a plugin-upload endpoint (/api/plugin/upload?/webhooks/trigger) that shares the same bypass pattern. By…
Unverified 2026-07-05 - CVE-2026-11551 web CRITICAL 9.8
Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
Branda's signup-password.php registers a preinsertuserdata() hook that fires on every wpinsertuser()/wpupdateuser() call, but is missing the standard if ($update) return $data; guard used to distinguish new-user creation from existing-user updates. As a…
Patched 2026-07-05 - CVE-2026-5513 web HIGH 7.2
Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
Bookly reads the bookly-customer-full-name cookie value and renders it directly into the booking form's HTML value attribute without sanitizing or escaping it, when the plugin's "Remember personal information in cookies" option is enabled. An unauthenticated…
Patched 2026-07-05 - CVE-2026-6960 web CRITICAL 9.8
BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
BookingPress Pro's bookingpressbookappointmentbooking AJAX handler processes a signature-type custom field value as a data URI. The plugin extracts the file extension from the MIME-type portion of the URI via regex and passes it directly to fileputcontents()…
Unverified 2026-07-05 - CVE-2026-39387 web HIGH
BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
BoidCMS (<= 2.1.2) combines two weaknesses to reach remote code execution from an authenticated admin account. First, its media upload endpoint only checks the declared MIME type (e.g. image/gif) rather than actual file contents, allowing PHP code embedded in…
Patched 2026-07-05 - CVE-2026-25099 web HIGH
Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
Bludit CMS's POST /api/files/<page-key> endpoint lets any holder of a valid API token upload files to a page without validating file extension or content, so a PHP file can be uploaded and dropped directly under the web-accessible uploads directory. Once…
Patched 2026-07-05 - CVE-2026-49943 network HIGH 3.1
BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)
This repository documents a stack-based buffer overflow in BIRD's BGP ASPATH mask matching code (aspathmatch() in nest/a-path.c). The function uses a fixed-size stack array of 2048 + 1 pmpos entries, but parsepath() expands ASPATH segments from a received BGP…
Patched 2026-07-05 - CVE-2026-7515 web CRITICAL 9.8
BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
BetterDocs Pro <= 3.8.0 passes the unauthenticated docstyle POST parameter from its loadmoredocssection/loadmoredocs AJAX actions (registered via wpajaxnopriv) directly into a file-include/view-loading sink (views->get("layouts/encyclopedia/$docstyle")),…
Unverified 2026-07-05 - CVE-2026-41653 web CRITICAL
BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)
BentoPDF's Markdown-to-PDF tool renders user-supplied Markdown through markdown-it with html: true enabled and injects the resulting HTML directly into the DOM via innerHTML, with no sanitizer (e.g. DOMPurify) in between. A crafted .md file containing an <img…
Patched 2026-07-05 - CVE-2026-30332 binary HIGH
Balena Etcher Windows TOCTOU Privilege Escalation — CVE-2026-30332
Balena Etcher for Windows writes a temporary .cmd script (containing environment variables and the command to launch etcher-util.exe) to a user-writable temp directory and then executes it with elevated privileges via a UAC prompt. Because there is a time gap…
Unverified 2026-07-05 - CVE-2026-54415 web HIGH 3.1
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
Before Azuriom 1.2.11, the admin panel's server-management routes (/admin/servers/) had no dedicated permission gate — any admin-panel user with just the base admin.access permission could reach them, since the admin.servers permission did not exist yet.…
Patched 2026-07-05 - CVE-2026-6279 web CRITICAL
Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
Avada Builder's wpajaxnoprivfusiongetwidgetmarkup AJAX handler processes a base64-encoded JSON renderlogics payload. Within its getvalue() method, the wpconditionaltags case passes an attacker-controlled function name directly to PHP's calluserfunc() with no…
Unverified 2026-07-05 - CVE-2026-30950 web HIGH 7.1
AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
The AutoGPT Platform's chat-session API exposes a PATCH /sessions/{sessionid}/assign-user route that lets an authenticated user attach their own account to a chat session record, but the route performs no check that the caller currently owns the session being…
Patched 2026-07-05 - CVE-2026-6643 binary CRITICAL
ASUSTOR ADM vpnupload.cgi Format String / Stack Buffer Overflow RCE — CVE-2026-6643
The ASUSTOR ADM NAS operating system's WireGuard config upload handler (vpnupload.cgi, uploadwireguard action) contains two chained memory-safety bugs. First, it JSON-encodes the parsed config and passes the result directly as the format string to printf(),…
Unverified 2026-07-05 - CVE-2026-1880 binary MEDIUM
ASUS DriverHub Update TOCTOU Local Privilege Escalation — CVE-2026-1880
ASUS DriverHub updates drivers by downloading a package, extracting it to C:\ProgramData\ASUS\AsusDriverHub\SupportTemp\<drivername>, and later launching setup.exe from that directory via ShellExecuteExW. Because the driver folder name can be predicted from…
Patched 2026-07-05 - CVE-2026-5076 web CRITICAL 9.8
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
ARMember Premium <= 7.3.1 stores password-reset keys (armresetpasswordkey user meta) in plaintext, and the plugin's member-directory AJAX endpoint (armdirectorypagingaction) is vulnerable to unauthenticated SQL injection via the order parameter. The included…
Patched 2026-07-05 - CVE-2026-7473 network MEDIUM 5.8 KEV
Arista EOS Tunnel Decapsulation Protocol-Type Bypass — CVE-2026-7473
Arista EOS switches configured as a tunnel decapsulation endpoint (for VXLAN, GRE, or generic ip decap-group/GUE/IP-in-IP profiles) incorrectly decapsulate and forward tunneled packets of an unexpected/non-configured protocol type as long as the outer…
Unverified 2026-07-05 - CVE-2026-30862 web CRITICAL 9.1
Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862
Appsmith's TableWidgetV2 component (BasicCell.tsx) fails to sanitize user-supplied cell values when the column type is URL or Plain Text, rendering raw HTML/attributes directly as React children and allowing stored XSS. Because Appsmith's XSRF-TOKEN cookie is…
Patched 2026-07-05 - CVE-2026-20637 binary HIGH
AppleSEPKeyStore IOKit Use-After-Free (CVE-2026-20637)
The AppleSEPKeyStore kernel driver exposes an IOKit user client (AppleKeyStore) whose command gate can be freed while still being accessed, producing a use-after-free. The PoC opens repeated IOServiceOpen connections while separate threads race…
Patched 2026-07-05 - CVE-2026-43655 binary HIGH
AppleM2ScalerCSCDriver Shared Scheduler Use-After-Free (CVE-2026-43655)
CVE-2026-43655 is a use-after-free in the AppleM2ScalerCSCDriver kernel driver's shared scaler-operation scheduler, reachable from a default-sandboxed iOS/iPadOS/macOS app with no special entitlements (only get-task-allow, no jailbreak or private…
Unverified 2026-07-05 - CVE-2026-20687 binary HIGH
AppleJPEGDriver startDecoder Timeout Use-After-Free (CVE-2026-20687)
AppleJPEGDriver's synchronous decode path (startDecodersync) can time out while a decode request is still referenced by a per-codec queue-node vector; on timeout the driver frees the request object but fails to remove its embedded queue-node pointer from that…
Patched 2026-07-05 - CVE-2026-32731 web HIGH
ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
ApostropheCMS supports importing a site/content archive (.tar.gz) containing aposDocs.json and aposAttachments.json metadata files. The import handler does not validate that entries extracted from the archive stay within the intended extraction directory,…
Patched 2026-07-05 - CVE-2026-39973 misc HIGH
Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
Apktool decodes an APK's resources.arsc to reconstruct resource file paths during decompilation, and a security regression (commit e10a045, PR #4041) removed the BrutIO.detectPossibleDirectoryTraversal() check that previously validated the fully-built output…
Patched 2026-07-05 - CVE-2026-34486 web CRITICAL KEV EPSS 81%
Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486)
CVE-2026-34486 is a fail-open flaw in Apache Tomcat's Tribes clustering EncryptInterceptor, which is meant to require encrypted, authenticated membership traffic between cluster nodes. Due to the bypass, an attacker can send an unencrypted, crafted message…
Patched 2026-07-05 - CVE-2026-43515 web HIGH
Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
CVE-2026-43515 is a security constraint evaluation bug in Apache Tomcat's RealmBase.findSecurityConstraints(). When a single <security-constraint> defines multiple <web-resource-collection> blocks that share the same URL pattern (e.g. .html) but each declare…
Patched 2026-07-05 - CVE-2026-29145 web CRITICAL 9.1
Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
When Tomcat is configured to use Mutual TLS (CLIENTCERT) authentication together with OCSP revocation checking in hard-fail mode, it is expected to reject any client certificate whose revocation status cannot be confirmed. This PoC demonstrates that when the…
Patched 2026-07-05 - CVE-2026-25854 web MEDIUM 6.1
Apache Tomcat LoadBalancerDrainingValve — Cross-System Open Redirect / Session Fixation (CVE-2026-25854)
When a Tomcat cluster node is marked disabled/draining, its LoadBalancerDrainingValve invalidates the invalid/stale session and constructs a redirect using the raw, attacker-supplied request URI. If that URI begins with //, Tomcat preserves the double slash,…
Patched 2026-07-05 - CVE-2026-23980 web MEDIUM 6.5
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
Apache Superset versions before 6.0.0 are vulnerable to an authenticated, error-based SQL injection reachable through the sqlExpression (adhoc column) or extras.where parameters of the /api/v1/chart/data REST endpoint. Superset's validateadhocsubquery()…
Patched 2026-07-05 - CVE-2026-44825 web CRITICAL 9.8
Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
Apache Solr bundles the Apache Velocity template engine as an optional response writer. Solr's VelocityResponseWriter renders user-supplied Velocity templates passed via the wt=velocity query parameter without adequately restricting access to Java reflection…
Patched 2026-07-05 - CVE-2026-22444 web CRITICAL
Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)
CVE-2026-22444 affects Apache Solr's "create core" admin API on Windows deployments running in standalone mode. Path validation (assertPathAllowed()) is only performed after the CoreDescriptor constructor has already triggered filesystem/network operations…
Patched 2026-07-05 - CVE-2026-39816 web CRITICAL
Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
Apache NiFi restricts all of its 16 dedicated script-execution processors behind an EXECUTECODE permission, enforced via a @Restricted annotation. However, the optional graph bundle's TinkerpopClientService — used by the ExecuteGraphQuery /…
Patched 2026-07-05 - CVE-2026-42779 network CRITICAL 9.8
Apache MINA acceptMatchers Deserialization Filter Bypass to RCE (CVE-2026-42779)
CVE-2026-42779 is a deserialization filter bypass in Apache MINA's AbstractIoBuffer.resolveClass(). Applications configure an acceptMatchers allowlist to restrict which Java classes ObjectSerializationCodecFactory may deserialize, but the allowlist check is…
Patched 2026-07-05 - CVE-2026-24072 web MEDIUM
Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
Apache HTTP Server's apexpr expression evaluation engine exposes filesystem-introspection functions (file(), filesize(), and tests like -f, -d, -e, -s, -L, -h, -x) that are meant to be restricted when expressions are parsed from a .htaccess file rather than…
Patched 2026-07-05 - CVE-2026-33006 web MEDIUM 4.8
Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006
Apache's modauthdigest module is vulnerable to a timing side-channel during HTTP Digest authentication: because the response verification does not run in constant time, an attacker can measure subtle differences in server response latency to infer whether a…
Patched 2026-07-05 - CVE-2026-49975 network HIGH EPSS 28%
Apache HTTP Server HTTP/2 HPACK Cookie-Merging Memory Bomb (CVE-2026-49975)
CVE-2026-49975 is a denial-of-service vulnerability in Apache HTTP Server's HTTP/2 request handling. A small HPACK-encoded HTTP/2 header block can reference the HPACK dynamic-table entry for the cookie header many times (up to the request field limit), which…
Unverified 2026-07-05 - CVE-2026-40564 cloud HIGH
Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
The Apache Flink Kubernetes Operator reconciles FlinkSessionJob (and FlinkDeployment) custom resources by fetching the JAR referenced in spec.job.jarURI from inside its own pod, without validating the URI's scheme, host, or resolved IP address. Any user…
Patched 2026-07-05 - CVE-2026-33453 web CRITICAL 10
Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
Apache Camel's camel-coap component maps CoAP URI query parameters directly into Camel Exchange headers via setHeader() inside CamelCoapResource.handleRequest(), without applying any HeaderFilterStrategy. Because CoAPEndpoint extends DefaultEndpoint rather…
Patched 2026-07-05 - CVE-2026-31908 web CRITICAL 10
Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
Apache APISIX's forward-auth plugin fails to sanitize CRLF (\r\n) sequences in inbound request headers before forwarding an authentication check upstream. By injecting CRLF sequences into headers such as Authorization, X-Forwarded-For, or Host, an…
Patched 2026-07-05 - CVE-2026-25604 web HIGH
Apache Airflow AWS Auth Manager SAML Host Header Injection (CVE-2026-25604)
CVE-2026-25604 is a CWE-346 origin validation error in Apache Airflow's AWS Auth Manager. When building the SAML AssertionConsumerService (ACS) callback URL for a login request, the code reads the HTTP Host header directly from the incoming request instead of…
Patched 2026-07-05 - CVE-2026-42588 web HIGH 8.1
Apache ActiveMQ Jolokia addNetworkConnector Spring Bean RCE (CVE-2026-42588)
CVE-2026-42588 is a code injection / improper input validation vulnerability in Apache ActiveMQ's Jolokia JMX-HTTP bridge. An attacker able to reach the addNetworkConnector MBean operation via Jolokia can supply a crafted broker configuration URI (xbean:…
Patched 2026-07-05 - CVE-2026-34197 network CRITICAL KEV EPSS 97%
Apache ActiveMQ Classic Jolokia addNetworkConnector Xbean Spring-XML RCE (CVE-2026-34197)
Apache ActiveMQ Classic exposes broker management via Jolokia, a JMX-over-HTTP bridge. The BrokerView.addNetworkConnector(uri) MBean operation accepts a discovery URI that can specify an inner vm:// transport with a brokerConfig=xbean:<url> parameter. This…
Patched 2026-07-05 - CVE-2026-0047 binary CRITICAL 8.4
Android ActivityManagerService dumpBitmapsProto() Missing Permission Check (CVE-2026-0047)
ActivityManagerService.dumpBitmapsProto() is missing an enforceCallingOrSelfPermission(DUMP) check that should gate access to a system-wide UI bitmap dump used for debugging. Because the method body executes fully before any permission is verified, any…
Unpatched 2026-07-05 - CVE-2026-7791 cloud HIGH
Amazon WorkSpaces Skylight Workspace Config Service Local Privilege Escalation (CVE-2026-7791)
The Skylight Workspace Config Service on Amazon WorkSpaces runs as SYSTEM and performs scheduled log rotation under C:\ProgramData\Amazon. Permissive ACLs on this directory, a ROTATE directory junction, absence of file-type checks, and a ~1-10 ms TOCTOU…
Unverified 2026-07-05 - CVE-2026-6042 network HIGH 7.5
Algorithmic Complexity DoS in musl libc `iconv` GB18030 Decoder — CVE-2026-6042
musl libc's GB18030 4-byte decoder (src/locale/iconv.c) contains a gap-skipping loop that, for each decoded character, iterates the entire 23,940-entry gb18030[126][190] lookup table to resolve a linear index to a Unicode codepoint. A crafted 4-byte sequence…
Unverified 2026-07-05 - CVE-2026-22807 misc HIGH
AI Model-Loader `trust_remote_code` Order-of-Operations RCE Simulation (CVE-2026-22807)
This repository is a small, self-contained Python testbed (vulnerablelib.py) that reproduces a class of AI supply-chain vulnerability found in model-loading frameworks: when a loader resolves a model's Python class via a config.json's automap field, it can…
Patched 2026-07-05 - CVE-2026-33980 web HIGH 8.8
adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
adx-mcp-server is a Model Context Protocol server that exposes tools letting an AI agent query an Azure Data Explorer (Kusto/KQL) cluster. Three "safe" metadata tools — gettableschema, sampletabledata, and gettabledetails — build their KQL queries by directly…
Patched 2026-07-05 - CVE-2026-8809 web CRITICAL 9.8
Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
ACF Extended's aftervalidatesavepost() function trusts the attacker-controlled POST parameter acfpostid without any validation or authentication check. By manipulating this parameter, an attacker causes the function to take a cleanup code path that silently…
Unverified 2026-07-05 - CVE-2026-21440 web CRITICAL 9.2
AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 is a path-traversal vulnerability in @adonisjs/bodyparser's MultipartFile.move() method. When an application calls file.move(location) without explicitly supplying a sanitized name option, the library falls back to the client-supplied original…
Patched 2026-07-05 - CVE-2026-3462 misc CRITICAL
Adobe Acrobat/Reader PDF Exploit Generator — Claimed Prototype Pollution (CVE-2026-3462)
This repository is titled and described as a PoC for "Acrobat Reader Improperly Controlled Modification of Object Prototype Attributes (Prototype Pollution)" under CVE-2026-3462, but the actual shipped code (poc.py / cve202634621advanced.py, both identical)…
Patched 2026-07-05 - CVE-2026-30498 web HIGH
AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
AdminPanel 4.0's delete.php endpoint performs a sensitive file-deletion action (deleting verifyPanel.php) via a simple GET request, with no CSRF token, no Origin/Referer validation, and no confirmation of user intent. An attacker can host a page that…
Unverified 2026-07-05 - CVE-2026-1729 web CRITICAL
AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
The AdForest WordPress theme implements a one-time-password (OTP) login flow via the sbloginuserwithotpfun AJAX handler, but the handler does not actually verify the submitted OTP code against a server-issued value before authenticating the requested user. As…
Unverified 2026-07-05 - CVE-2026-46391 web HIGH
@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)
The cacheAddress endpoint in @haxtheweb/open-apis (/api/services/website/cacheAddress) performs a server-side fetch of a URL supplied by the caller without adequately restricting the destination, resulting in a Server-Side Request Forgery (SSRF)…
Unverified 2026-07-05 - None assigned as of 2026-07-04 network HIGH
PostgreSQL Referential-Integrity Owner-Switched Implicit Cast RCE
This PoC demonstrates that PostgreSQL's referential-integrity (RI) enforcement for foreign keys switches its effective role to the referenced table's owner before invoking any implicit cast needed to compare the foreign-key value against the primary-key type.…
Unverified 2026-07-04 - None assigned as of 2026-07-03 binary MEDIUM
VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash
VLC 3.0.23's bundled FFmpeg VP9 decoder tracks per-frame slice-thread progress in an entries array sized from the superblock row count (sbrows) of the current frame. A crafted two-frame VP9 IVF file — a 64x64 first frame followed by a 64x8192 second frame…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary HIGH
System Informer phsvc Trusted-Host Confused Deputy LPE
System Informer's privileged helper process phsvc exposes an ALPC API port (\BaseNamedObjects\SiSvcApiPort) with a connect ACL open to Everyone, and authorizes connecting clients purely by checking whether the client's process image is generically…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
RustDesk Relay Session Downgrade and FileTransfer Authorization Scope Bypass
This entry covers two related but distinct RustDesk findings. First, RustDesk's client can fail open on secure-session setup: when the signed peer key material from the rendezvous/relay path is missing or invalid, the client requests a non-secure relay and…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network CRITICAL
Redis Vector Set Duplicate HNSW Node ID RCE
Redis Vector Set RDB/RESTORE deserialization accepts serialized HNSW graph nodes that reuse the same node ID, but the ID-lookup table only tracks one node per ID while the element dictionary tracks nodes by name, so link validation ends up trusting IDs…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary CRITICAL
QEMU CXL Type-3 Mailbox Guest-to-Host Escape
QEMU's CXL Type-3 mailbox command handling contains two related out-of-bounds issues: the GETLOG handler validates offset + length as a byte range but then uses offset as an array index into cci->cellog, and the SETFEATURE rank-sparing handler copies…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary HIGH
Pillow ImageCms Mutable output_mode Heap OOB Write
Pillow's ImageCms.buildTransform() creates a reusable LittleCMS-backed transform object and stores mutable inputmode/outputmode attributes on the Python wrapper. ImageCmsTransform.apply() trusts these mutable attributes both to validate image modes and to…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web CRITICAL
PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
This PoC demonstrates a full memory-corruption-to-RCE chain in PHP 8.5.7 built from three engine/extension behaviors chained together: ArrayIterator can mutate normally-protected internal object properties (bypassing typed-property/visibility/readonly…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
OpenVPN Connect Server-Pushed Option Current-User Command Execution
A malicious OpenVPN server can push an echo option to a connected OpenVPN Connect for Windows client that decodes into the internal script.win.user.disconnect script key. OpenVPN Connect then executes that pushed command when the client disconnects, even…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary MEDIUM
objdump DLX ELF Backend Out-of-Bounds Write (Crash-to-Calc)
objdump -g (debug-info dumping) against a crafted ELF/DLX object file triggers an out-of-bounds write in the DLX ELF backend's relocation-processing code, writing outside the intended debug section buffer. The researcher shapes the crafted relocation data so…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
NodeBB ActivityPub attributedTo Local UID Spoof
NodeBB's ActivityPub inbox authenticates the top-level signed actor of an incoming activity via HTTP Signatures, but never checks that the embedded Note.attributedTo field — used later as the internal local user id for chat message and post authorship —…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network LOW
Nmap IPv6 Extension-Header Length Wrap
The Nmap IPv6 extension-header parser in libnetutil/netutil.cc advances a payload pointer by an attacker-declared extension-header length without first checking that the advanced pointer stays within the bounds of the captured packet. When a crafted,…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
nghttpx HTTP/1.1 Upgrade Request Body Response Queue Poisoning
nghttpx, the reverse proxy shipped with nghttp2, incorrectly accepts an HTTP/1.1 Upgrade request that also carries a Content-Length header, then forwards both the Upgrade headers and the body bytes unmodified to a keep-alive HTTP/1.1 backend connection. If…
Patched 2026-07-03 - None assigned as of 2026-07-03 cloud HIGH
Nextcloud Federated Share OCM Bearer Token Scope Escalation to Sender WebDAV Access
When a Nextcloud user creates a normal federated file share, the sender instance generates a permanent authentication token that is also stored as the federated share's secret; that token is created without an explicit narrow scope, so it defaults to full…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Next.js unstable_cache Object-Argument Cache-Key Collision
Next.js's unstablecache() API derives its cache key by running JSON.stringify() over the arguments passed to the cached function. When a route handler passes a stock request-wrapper object — a Request, URLSearchParams, or FormData instance — directly into…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
A non-super Admin CP account that has only the user-management permission (user-users = 1) can use the standard Admin CP "add user" form to create a brand-new account directly in the Administrator group (gid=4), because the underlying user data handler's…
Unpatched 2026-07-03 - None assigned as of 2026-07-03 binary CRITICAL 3.1
Lunar Client Modrinth Explore Raw-HTML to Local Launcher Execution Chain
The chain begins with Lunar Client's Explore feature rendering attacker-controlled Modrinth project Markdown (project body and version changelog) through ReactMarkdown with the rehypeRaw plugin and no observed HTML sanitizer, allowing raw HTML/script-capable…
Unverified 2026-07-03 - CVE-2026-55200 network CRITICAL
libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200 is an unchecked packetlength condition in libssh2's ssh2transportread() transport-parsing path. The vulnerable code accepts an attacker-controlled decrypted SSH packetlength field and only rejects values less than 1, then computes an allocation…
Patched 2026-07-03 - None assigned as of 2026-07-03 network CRITICAL
libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
libssh2publickeylistfetch() parses a stream of publickey-subsystem response packets and grows an array of libssh2publickeylist entries as responses arrive, but the parser has two distinct memory-safety defects depending on target architecture. On 32-bit…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary MEDIUM
libarchive ZIP Declared-Size Boundary Bypass via debuginfod
The PoC builds a stored ZIP64 archive entry whose declared uncompressed size field is 109 bytes while the actual inflated stream is 4 GiB + 109 bytes — crafted so the low 32 bits of the true length equal the advertised value (0x100000004 mod 2^32 == 4, offset…
Unverified 2026-07-03 - CVE-2025-3248 web CRITICAL 9.8 KEV Ransomware EPSS 100%
Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)
CVE-2025-3248 is a missing-authentication vulnerability in Langflow's code-validation API. The /api/v1/validate/code endpoint accepts and executes arbitrary Python code submitted by any client, with no authentication check on the route, allowing an…
Patched 2026-07-03 - None assigned as of 2026-07-03 web CRITICAL
Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
The PoC targets a lifetime bug in Ladybird's WebAssembly ESM import path: WebAssemblyModule.cpp builds a Wasm::FunctionType as a stack-local value and passes it by reference into createhostfunction(), so the resulting long-lived JS host callback retains a…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary HIGH
ImageMagick Ghostscript Delegate Search Path Hijack
When ImageMagick converts PDF/PS/EPS-family inputs on Windows and cannot resolve a full path to Ghostscript, it falls back to invoking the bare executable name gswin64c.exe and launches it through the Windows process API with the application name left unset —…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web CRITICAL
Gogs Admin User Edit CSRF to Git Hook RCE
Gogs' admin user-edit route (POST /admin/users/:userid) performs the state-changing grant of IsAdmin/AllowGitHook without a CSRF token, so an authenticated site administrator can be induced (e.g., via a cross-site form submission) to grant those rights to an…
Unverified 2026-07-03 - None assigned as of 2026-07-03 cloud HIGH
Gitea act_runner container.options Host Namespace Escape
Gitea's actrunner allows workflow YAML to append Docker options via jobs.<job>.container.options. When the runner configuration disables privileged mode, actrunner forces Privileged back to false and sanitizes bind mounts, but it preserves every other Docker…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary MEDIUM
Ghidra 12.1.2 Conditional Swift Demangler ACE (plus TraceRMI RCE and SevenZipJBinding Reachability)
This entry packages three conditional, defensively-scoped findings against Ghidra 12.1.2 rather than a single unconditional exploit. First, the Swift demangler analyzer builds and launches a swift-demangle executable from a program/analyzer-controlled tool…
Unverified 2026-07-03 - CVE-2026-35616 network CRITICAL 9.1 KEV EPSS 89%
Fortinet FortiClient EMS Pre-Auth Bypass — "FortiBleed" (CVE-2026-35616)
CVE-2026-35616 is a pre-authentication bypass in Fortinet FortiClient EMS's certificate-chain authentication handler (certchainauth.py), which trusts the X-SSL-CLIENT-VERIFY header directly without performing real cryptographic validation of the presented…
Patched 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Flowise Custom MCP Environment Variable Case Bypass
Flowise's Custom MCP stdio node validates configured environment variables against a denylist (PATH, LDLIBRARYPATH, DYLDLIBRARYPATH, NODEOPTIONS) using exact, case-sensitive string comparison. Windows, however, treats environment variable names…
Unverified 2026-07-03 - None assigned as of 2026-07-03 cloud CRITICAL
Floci API Gateway VTL RCE + IAM Scope Bypass
Floci evaluates user-controlled API Gateway integration response templates with an unrestricted Apache Velocity engine that exposes $util, allowing template code to reach java.lang.ProcessBuilder via reflection and execute arbitrary OS commands in the Floci…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Firefox Smart Window Private URL Exfiltration
Firefox's Smart Window assistant exposes getopentabs and searchbrowsinghistory tools that return private tab/history URLs to the model and mark the conversation as containing privateData, but they never mark it as containing untrustedInput even though the…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary CRITICAL
FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write
FFmpeg's RASC decoder (decodedlta() in libavcodec/rasc.c) tracks a row cursor and only checks whether it has reached the end of the current row after certain operations, rather than before. Several DLTA run types (4, 7, 12, 13) perform 32-bit reads/writes at…
Unpatched 2026-07-03 - None assigned as of 2026-07-03 cloud MEDIUM
Docker cp Copy-Out Destination Escape via Symlink Race
docker cp copy-out operations are vulnerable to a time-of-check/time-of-use race: the daemon walks the container's source path with filepath.WalkDir and builds a tar stream, but if a container process changes a directory entry (e.g., swaps it for a symlink)…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Discourse Scoped API Key Pre-Route Authorization Bypass
Discourse's overload-protection middleware authenticates API requests before Rails routing has resolved the actual HTTP verb, and its scoped API key matcher (lib/routematcher.rb) calls Rails.application.routes.recognizepath(request.pathinfo) without passing…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network MEDIUM
curl SMTP EXPN Recipient CRLF Command Injection
Stock curl does not reject CR/LF sequences in the recipient operand used with SMTP EXPN/VRFY custom requests (CURLOPTMAILRCPT), allowing an attacker who controls that operand to inject arbitrary additional SMTP protocol lines into the same authenticated…
Unverified 2026-07-03 - CVE-2026-8451 network HIGH 7.5 EPSS 16%
Citrix NetScaler ADC/Gateway Pre-Auth SAML Memory Overread — "CitrixBleed"-style Leak (CVE-2026-8451)
CVE-2026-8451 is a pre-authentication out-of-bounds memory read in Citrix NetScaler ADC/Gateway's SAML request parser, in the same vulnerability class as the infamous 2023 "CitrixBleed" (CVE-2023-4966). By posting a specially-sized, malformed SAMLRequest to…
Unverified 2026-07-03 - None assigned as of 2026-07-03 network HIGH
c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
c-ares's aresgetaddrinfo() path over DNS-over-TCP with EDNS enabled contains a use-after-free reachable when a malicious or compromised DNS server sends two responses for the same query ID in a single TCP read — the first a FORMERR without OPT data…
Unverified 2026-07-03 - None assigned as of 2026-07-03 binary HIGH
AnyDesk Printer Pipe COM Impersonation Local Privilege Escalation
AnyDesk's local printer IPC worker creates a named pipe (\\.\pipe\adprinterpipe) with an ACL that grants access to Everyone, then accepts a message containing attacker-controlled COM marshaling bytes, unmarshals it into an IUnknown, queries for IStream, and…
Unverified 2026-07-03 - None assigned as of 2026-07-03 misc HIGH
7-Zip RAR5 Mark-of-the-Web / ADS Full-Chain Bypass
7-Zip 26.01 on Windows mishandles RAR5 archives that contain crafted STM (stream) service records alongside a normal file entry. By naming one stream ::$DATA and another :Zone.Identifier:$DATA, an attacker can make the archive-provided data silently override…
Unverified 2026-07-03 - CVE-2025-8088 misc HIGH 8.4 KEV Ransomware EPSS 95%
WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)
CVE-2025-8088 is a path traversal vulnerability in the Windows version of WinRAR. A specially crafted RAR archive abuses NTFS Alternate Data Streams (ADS) combined with ..\ traversal sequences so that, when opened or extracted by a vulnerable WinRAR build,…
Patched 2026-07-01 - CVE-2026-45247 web CRITICAL 9.3 KEV EPSS 28%
Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)
CVE-2026-45247 is a PHP object injection / insecure deserialization vulnerability in Mirasvit's Full Page Cache Warmer extension for Magento 2. The extension processes attacker-controlled data from the CacheWarmer cookie and passes it directly to PHP's native…
Unverified 2026-07-01 - CVE-2026-48907 web CRITICAL 10 KEV EPSS 56%
Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)
CVE-2026-48907 is a critical improper access control vulnerability in the JCE extension for Joomla. The profile import workflow (index.php?option=comjce&task=profiles.import) is missing sufficient authorization checks, letting unauthenticated users create new…
Patched 2026-07-01 - CVE-2026-47729 network MEDIUM
Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729, dubbed "Squidbleed," is an out-of-bounds heap read in Squid Proxy's FTP gateway and FTP directory-listing parser. The bug stems from legacy FTP parsing logic (originally written in 1997 for NetWare-style listings) in FtpGateway.cc, where…
Patched 2026-07-01 - CVE-2026-0257 web HIGH 7.8 KEV Ransomware EPSS 94%
PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of PAN-OS. In configurations where the same TLS certificate is reused for both the HTTPS service and the authentication-override cookie's encryption/decryption, an…
Unverified 2026-07-01 - CVE-2026-11645 web HIGH 8.8 KEV
Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645)
CVE-2026-11645 is a high-severity out-of-bounds read/write vulnerability in V8, the JavaScript/WebAssembly engine used by Chrome and other Chromium-based browsers. The bug is rooted in V8's TurboFan optimizer: incorrect range analysis for loop-modified or…
Unverified 2026-07-01 - CVE-2026-20230 network CRITICAL 8.6 KEV EPSS 83%
Cisco Unified CM WebDialer SSRF to Arbitrary File Write / RCE (CVE-2026-20230)
CVE-2026-20230 is a critical server-side request forgery vulnerability in Cisco Unified CM / Unified CM SME caused by improper input validation of HTTP requests processed by the WebDialer component. A remote unauthenticated attacker can chain unauthenticated…
Unverified 2026-07-01 - CVE-2026-20262 network MEDIUM 6.5 KEV EPSS 28%
Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)
CVE-2026-20262 is an authenticated remote arbitrary file write vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. Improper validation of user-supplied input during a file upload process enables path traversal, letting an authenticated attacker…
Unverified 2026-07-01 - CVE-2026-42271 web HIGH 8.7 KEV EPSS 83%
Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271)
CVE-2026-42271 is a command injection vulnerability in BerriAI LiteLLM's MCP preview/test endpoints — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list. These endpoints accept a full MCP server configuration in the request body, including…
Patched 2026-07-01 - CVE-2026-48908 web CRITICAL 10 KEV EPSS 88%
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
CVE-2026-48908 is a CVSS 10.0 unauthenticated remote code execution vulnerability in SP Page Builder, one of the most widely used Joomla page-builder extensions (joomshaper.net). The asset.uploadCustomIcon endpoint enforces no authentication, no…
Patched 2026-06-30 - CVE-2026-46331 binary HIGH 7.8
Linux Kernel act_pedit Partial COW Page-Cache LPE (CVE-2026-46331)
CVE-2026-46331 is a local privilege escalation in the Linux kernel's net/sched/actpedit subsystem. The vulnerable function tcfpeditact() computes the writable Copy-on-Write (COW) region using a pre-calculated maximum hint (tcfpoffmaxhint) before the actual…
Patched 2026-06-30 - CVE-2026-55200 network CRITICAL 9.8
libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 is a critical heap out-of-bounds write in libssh2's SSH transport layer (ssh2transportread() in src/transport.c). The function validates that packetlength is greater than zero but performs no upper-bound check, allowing an attacker-controlled…
Patched 2026-06-30 - CVE-2026-8932 network LOW
libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)
CVE-2026-8932 is a Low-severity authentication bypass in libcurl's TLS connection reuse logic. Certain mTLS private-key configuration parameters (key file path, key type, key password) were omitted from the connection-matching comparison performed when…
Patched 2026-06-30 - CVE-2026-24061 network CRITICAL 9.8 KEV EPSS 98%
GNU Inetutils telnetd Unauthenticated Root RCE via NEW-ENVIRON (CVE-2026-24061)
CVE-2026-24061 is a critical authentication bypass in GNU Inetutils telnetd that grants an unauthenticated network attacker an immediate root shell. The NEW-ENVIRON Telnet option handler passes the USER environment variable unsanitised to /bin/login. Setting…
Patched 2026-06-30 - CVE-2026-12485 network CRITICAL 10
GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 is a CVSS 10.0 unauthenticated stack-based buffer overflow in the GeoVision GV-I/O Box 4E, a Linux-based smart I/O device used in physical security and building automation. The DVRSearch service listens on UDP port 10001 and handles CMDIPSET…
Patched 2026-06-30 - CVE-2026-8461 binary HIGH 8.8
FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 (codename PixelSmash) is a High-severity out-of-bounds heap write in FFmpeg's MagicYUV decoder (libavcodec). Improper bounds validation during frame decoding allows a specially crafted video file with an odd slice height to trigger a heap buffer…
Patched 2026-06-30 - CVE-2026-7574 binary HIGH 8.7
Claude Desktop Cowork VM Image Integrity Bypass / Local Persistence (CVE-2026-7574)
CVE-2026-7574 is a VM image integrity bypass in Anthropic's Claude Desktop Cowork feature (macOS). Before booting the Cowork virtual machine, the application validates only the presence of rootfs.img and its associated version marker (.rootfs.img.origin); it…
Unverified 2026-06-30 - CVE-2026-45586 binary HIGH 7.8
Windows CTFMON Arbitrary Section Object EoP — GreenPlasma (CVE-2026-45586)
CVE-2026-45586 (GreenPlasma) is a Windows CTFMON Elevation of Privilege vulnerability exploiting an arbitrary named section object creation primitive. A standard unprivileged user can create a section object in any directory object writable by SYSTEM, abusing…
Patched 2026-06-28 - CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 network CRITICAL 10 KEV EPSS 62%
Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)
A three-CVE unauthenticated RCE chain in Ubiquiti UniFi OS Server ≤ 5.0.6 allows a remote attacker to achieve root-level command execution with no credentials. CVE-2026-34908 and CVE-2026-34909 (improper access control + path traversal) are chained to bypass…
Patched 2026-06-28 - CVE-2026-20253 web CRITICAL KEV EPSS 97%
Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)
CVE-2026-20253 is a critical unauthenticated RCE vulnerability in Splunk Enterprise arising from a missing authentication check on the PostgreSQL sidecar service endpoint /v1/postgres/recovery/backup. An unauthenticated attacker can reach this endpoint and…
Patched 2026-06-28 - CVE-2026-10520, CVE-2026-10523 network CRITICAL 10 KEV EPSS 100%
Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)
Two critical vulnerabilities in Ivanti Sentry enable unauthenticated root-level RCE and arbitrary admin account creation. CVE-2026-10520 is an OS command injection in the MICS API at /mics/api/v2/sentry/mics-config/handleMessage (CVSS 10.0). CVE-2026-10523 is…
Patched 2026-06-28 - CVE-2026-43503 binary HIGH 8.8
DirtyClone — Linux Kernel LPE via Cloned Packet Page-Cache Overwrite (CVE-2026-43503)
DirtyClone (CVE-2026-43503, CVSS 8.8) is the fourth member of the DirtyFrag family of Linux kernel local privilege escalation vulnerabilities. Each member shares the same root failure: file-backed page-cache memory is exposed to network packet operations, and…
Patched 2026-06-28 - CVE-2026-20245 network HIGH 7.8 KEV EPSS 25%
Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)
CVE-2026-20245 is the seventh Cisco SD-WAN zero-day exploited in 2026. An authenticated attacker with netadmin privileges on Cisco Catalyst SD-WAN Manager can upload a specially crafted file to the CLI subsystem, triggering insufficient input validation and…
Unpatched 2026-06-28 - CVE-2026-50751 network CRITICAL 9.3 KEV Ransomware EPSS 83%
Check Point Remote Access VPN IKEv1 Auth Bypass (CVE-2026-50751)
CVE-2026-50751 is a critical authentication bypass in Check Point Remote Access VPN affecting gateways configured for the legacy IKEv1 protocol. A remote unauthenticated attacker can complete the deprecated IKEv1 phase-1 exchange and be authenticated as a…
Patched 2026-06-28 - CVE-2026-45585 misc MEDIUM 6.1
YellowKey — BitLocker Bypass via WinRE autofstx.exe (CVE-2026-45585)
CVE-2026-45585 (YellowKey) is a zero-day physical-access vulnerability discovered in May 2026 that allows an attacker with physical access to a Windows 11 device to fully bypass BitLocker disk encryption without the PIN, password, or recovery key. The…
Patched 2026-06-26 - CVE-2026-50656 binary HIGH 7.8 EPSS 11%
CVE-2026-50656 RoguePlanet — Safe Vulnerability Checker (Resurface)
CVE-2026-50656 is a High-severity Elevation of Privilege vulnerability in the Microsoft Malware Protection Engine, publicly referred to as RoguePlanet. It stems from improper link resolution before file access (CWE-59) — the engine follows attacker-controlled…
Patched 2026-06-26 - CVE-2026-50656 binary HIGH 7.8 EPSS 11%
RoguePlanet — Windows Defender LPE via ISO Mount + Task Scheduler Race Condition
RoguePlanet is a local privilege escalation exploit for Windows 10 and 11 that abuses a race condition in Windows Defender's scan pipeline. The exploit mounts an attacker-controlled ISO image via the VirtualDisk API, plants an EICAR-like trigger file inside…
Unpatched 2026-06-10 - web CRITICAL 9.3
FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition
FirefUXSS is a universal XSS issue in Firefox Focus for iOS where redirect-scheme validation can be bypassed via a race condition. A burst of benign redirects can desynchronize validation from navigation commit, allowing a final javascript: redirect to…
Unpatched 2026-06-08 - CVE-2026-46333 binary HIGH
ssh-keysign-pwn: pidfd_getfd FD Theft via mm-NULL Exit Window (CVE-2026-46333)
ssh-keysign-pwn demonstrates a local file-descriptor theft primitive on vulnerable Linux kernels. During process exit, a race window appears after exitmm() but before file descriptors are closed; in that state pidfdgetfd(2) can bypass expected dumpable checks…
Patched 2026-06-05 - CVE-2026-41089 network CRITICAL 9.8 EPSS 80%
Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089)
This PoC targets CVE-2026-41089, a stack-based buffer overflow in the Windows Netlogon CLDAP handling path. A crafted UDP/389 CLDAP ping containing an oversized User value can overrun a stack buffer in the LSASS/Netlogon flow and crash the domain controller.…
Patched 2026-06-04 - CVE-2026-48172 web HIGH KEV EPSS 19%
LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172)
CVE-2026-48172 is a local privilege-escalation flaw in LiteSpeed cPanel Plugin v6.5.0 and earlier. The plugin installation flow does not sufficiently validate package ownership/permissions and can be abused with symlinked install targets. A normal cPanel user…
Unverified 2026-05-30 - CVE-2026-9082 / SA-CORE-2026-004 web CRITICAL KEV EPSS 88%
Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)
CVE-2026-9082 is an unauthenticated SQL injection in Drupal Core's PostgreSQL entity-query handling for JSON:API filters. User-controlled array keys are used to build SQL placeholder names without proper sanitization, enabling injection into generated SQL. On…
Patched 2026-05-30 - CVE-2026-48770, CVE-2026-48778, CVE-2026-48800 binary HIGH 5
Notepad++ <= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)
This PoC set covers three Notepad++ vulnerabilities affecting versions up to 8.9.6. CVE-2026-48770 demonstrates an out-of-bounds read crash by sending malformed WMCOPYDATA data to a running Notepad++ process. CVE-2026-48778 and CVE-2026-48800 demonstrate…
Patched 2026-05-28 - binary HIGH
PinTheft: RDS Double-Free → LPE
PinTheft is a Linux local privilege escalation exploit targeting a double-free in the RDS zerocopy send path (rdsmessagezcopyfromuser()). When a multi-page zerocopy send faults on a later page, the error path drops already-pinned pages, but RDS message…
Unverified 2026-05-20 - N/A network CRITICAL
TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE
TossUp is a pair of bugs against TerraMaster TOS NAS devices. The primary issue is that Redis 4.0.10 runs as root and listens on 0.0.0.0:6379 with no authentication — despite /etc/redis.conf containing bind 127.0.0.1, the init script starts Redis as…
Unpatched 2026-05-18 - N/A binary HIGH
DirtyDecrypt / DirtyCBC — rxgk Page-Cache Write (Dirty Pipe Variant)
DirtyDecrypt (also called DirtyCBC) is a variant of the CopyFail / DirtyFrag / Fragnesia bug class. rxgkdecryptskb() in net/rxrpc/rxgkcommon.h calls skbtosgvec() followed by cryptokrb5decrypt() without first calling skbcowdata(). The krb5enc AEAD template…
Unverified 2026-05-18 - CVE-2026-5281 web HIGH 8.8 KEV
Chrome WebGPU Use-After-Free (CVE-2026-5281)
CVE-2026-5281 is a reported WebGPU use-after-free condition in Chrome's Dawn backend. The upstream toolkit provides an aggressive payload generator, scanner, and automated browser runner to reproduce crash-like GPU-failure signals and compare vulnerable vs…
Unverified 2026-05-18 - CVE-2025-24054 binary MEDIUM 6.5 KEV EPSS 59%
Windows NTLM Hash Disclosure via File Explorer - CVE-2025-24054
CVE-2025-24054 is a zero-click NTLMv2-SSP hash disclosure vulnerability in Windows File Explorer. When a user opens a ZIP archive containing a crafted .searchConnector-ms file, Windows Explorer automatically resolves an embedded UNC path during file preview,…
Unverified 2026-05-17 - CVE-2025-26633 binary HIGH KEV Ransomware EPSS 30%
Windows MMC MSC EvilTwin - CVE-2025-26633
CVE-2025-26633 is a zero-day vulnerability in Microsoft Management Console (MMC) that was exploited in the wild by Russian APT group Water Gamayun (EncryptHub/Larva-208). An attacker crafts a malicious .msc file that abuses the MUIPath resolution mechanism:…
Unverified 2026-05-17 - CVE-2025-62215 binary HIGH 7 KEV
Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)
CVE-2025-62215 is a Windows Kernel Elevation of Privilege vulnerability disclosed and patched in November 2025, confirmed to have been actively exploited as a zero-day in the wild prior to patching. The bug combines a race condition in kernel resource…
Patched 2026-05-17 - CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web CRITICAL KEV Ransomware EPSS 100%
ToolShell - SharePoint Unauthenticated RCE Chain
CVE-2025-53770 ("ToolShell") is a full unauthenticated remote code execution chain against Microsoft SharePoint Server. The chain combines an authentication bypass in the ToolPane.aspx endpoint (CVE-2025-49706 / patch bypass CVE-2025-53771) with an unsafe…
Patched 2026-05-17 - CVE-2025-55182 web CRITICAL 10 KEV Ransomware EPSS 100%
React2Shell - Next.js RSC Unauthenticated RCE
CVE-2025-55182 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Next.js applications using React Server Components (RSC) with the App Router. The exploit abuses unsafe deserialization of the RSC wire format: a crafted multipart POST…
Patched 2026-05-17 - CVE-2024-3400 web CRITICAL 10 KEV Ransomware EPSS 100%
Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)
CVE-2024-3400 is an unauthenticated command injection vulnerability in PAN-OS GlobalProtect that can be reached over the network when specific features are enabled. Public reporting showed chained abuse via arbitrary file creation and command execution as…
Patched 2026-05-17 - CVE-2026-44572 web LOW 3.1
Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572 is a cache poisoning vulnerability in Next.js Pages Router redirect handling. Pre-patch, any external client could set the internal x-nextjs-data: 1 header on a request to a redirecting URL, causing the server to return a 200 OK with…
Patched 2026-05-17 - CVE-2026-44578 web HIGH 8.6 EPSS 39%
Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)
CVE-2026-44578 is a server-side request forgery (SSRF) vulnerability in self-hosted Next.js WebSocket upgrade handling. A crafted HTTP request with Upgrade: websocket can coerce vulnerable versions into proxying to attacker-chosen internal targets on port 80…
Patched 2026-05-17 - CVE-2026-23870 web HIGH 7.5
Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 is a pre-authentication Denial of Service against any Next.js deployment using the App Router. An attacker sends crafted HTTP POST requests to any App Router server function endpoint with a deeply-cyclic or wide fan-out React Flight protocol…
Patched 2026-05-17 - CVE-2026-44576 web MEDIUM 5.4
Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576 is a cache poisoning issue in Next.js RSC response handling. In vulnerable versions, RSC and HTML response variants can be mis-partitioned by shared caches when request/response variants are not keyed correctly, allowing attacker-controlled…
Patched 2026-05-17 - CVE-2026-44582 web LOW 3.7
Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
Next.js used a weak cache-busting hash for the rsc query parameter in vulnerable versions. Because this hash had practical collision resistance limits, an attacker could generate alternative header/state tuples that map to the same rsc token as a victim route…
Patched 2026-05-17 - CVE-2026-44577 web MEDIUM 5.9
Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
CVE-2026-44577 is a denial-of-service issue in Next.js Image Optimization on self-hosted deployments. In vulnerable builds, /next/image can fetch very large local assets into memory without an effective size cap and then perform expensive image…
Patched 2026-05-17 - CVE-2026-44573 web HIGH 7.5
Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 is an authorization bypass in Next.js Pages Router applications that use the i18n configuration. The middleware matcher regex's i18n branch does not correctly cover all locale-prefix permutations of next/data/<buildId>/<page>.json URLs. As a…
Patched 2026-05-17 - CVE-2026-44574 web HIGH 8.1
Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574 is an authentication bypass in Next.js App Router applications that use middleware to protect dynamic route pages. Specially crafted query parameters (nxtP / nxtI internal Next.js route params) injected on a public URL cause the App Router…
Patched 2026-05-17 - CVE-2026-44581 web MEDIUM 4.7
Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
CVE-2026-44581 is a reflected XSS issue in Next.js App Router nonce handling. Malformed nonce values from a Content-Security-Policy request header can be reflected into rendered HTML script attributes without safe attribute-context escaping. In caching…
Patched 2026-05-17 - CVE-2026-44579 web HIGH 7.5
Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
CVE-2026-44579 is a denial-of-service issue in Next.js Cache Components (PPR) request handling. Before the fix, a crafted client request could force the server into the next-resume flow and trigger expensive request-body processing and resume rendering work.…
Patched 2026-05-17 - CVE-2026-44580 web MEDIUM 6.1
Next.js beforeInteractive Script XSS (CVE-2026-44580)
CVE-2026-44580 is an XSS vulnerability in Next.js next/script rendering for beforeInteractive scripts. Vulnerable versions serialize script props with JSON.stringify and inject them into inline HTML via dangerouslySetInnerHTML without safe HTML escaping for…
Patched 2026-05-17 - CVE-2026-44575 web HIGH 7.5
Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575 is an authorization bypass in Next.js App Router middleware matching. Vulnerable versions compile middleware matchers for canonical paths and legacy Pages Router data routes, but omit the App Router transport variants used for .rsc and…
Patched 2026-05-17 - CVE-2025-21756 binary HIGH 7.8
Linux vsock Use-After-Free VM Escape (CVE-2025-21756)
CVE-2025-21756 is a use-after-free vulnerability in the Linux kernel's vsock (virtual socket) subsystem. An attacker with code execution inside a virtual machine can exploit this bug to escape the VM boundary and gain root-level code execution on the…
Patched 2026-05-17 - CVE-2024-1086 binary HIGH 7.8 KEV Ransomware EPSS 28%
Linux nf_tables Use-After-Free Local Privilege Escalation (CVE-2024-1086)
CVE-2024-1086 is a use-after-free vulnerability in the Linux kernel's netfilter nftables subsystem that allows an unprivileged local user to escalate privileges to root. The exploit achieves a 99.4% success rate on KernelCTF images and works universally…
Patched 2026-05-17 - CVE-2024-23897 web CRITICAL 9.8 KEV Ransomware EPSS 100%
Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)
CVE-2024-23897 is an arbitrary file read vulnerability in the Jenkins CLI command parser. The parser expands arguments that start with @ and can disclose controller-local files to unauthenticated attackers in common deployments. This disclosure can expose…
Patched 2026-05-17 - CVE-2025-0282 network CRITICAL 9 KEV Ransomware EPSS 100%
Ivanti Connect Secure Pre-Auth RCE (Stack Overflow)
CVE-2025-0282 is a pre-authentication stack-based buffer overflow in the IFT (IF-T) TLS protocol handling code of Ivanti Connect Secure VPN appliances. Discovered and disclosed by Sina Kheirkhah of watchTowr Labs, this zero-day was confirmed by Mandiant as…
Unverified 2026-05-17 - CVE-2025-1974 cloud CRITICAL 9.8 EPSS 100%
IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE
IngressNightmare is a chain of critical vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) in the Kubernetes Ingress-NGINX admission controller. Discovered by Wiz Research, the vulnerabilities allow an unauthenticated attacker…
Unverified 2026-05-17 - CVE-2024-47575 network CRITICAL 9.8 KEV EPSS 95%
Fortinet FortiManager FortiJump Unauthenticated RCE (CVE-2024-47575)
CVE-2024-47575 (FortiJump) is a missing-authentication flaw in FortiManager's fgfmd daemon that lets a remote unauthenticated attacker execute arbitrary commands. Public exploit code demonstrates vulnerability detection and command execution primitives over…
Unverified 2026-05-17 - CVE-2025-59718, CVE-2025-59719 network CRITICAL 9.8 KEV EPSS 63%
Fortinet FortiCloud SSO Authentication Bypass
CVE-2025-59718 and CVE-2025-59719 are closely related authentication-bypass vulnerabilities (CWE-347: Improper Verification of Cryptographic Signature) in Fortinet products that use the FortiCloud SSO login feature. Both were disclosed by Fortinet on 9…
Unverified 2026-05-17 - CVE-2025-32433 network CRITICAL 10 KEV EPSS 99%
Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433
CVE-2025-32433 is a critical pre-authentication remote code execution vulnerability in the Erlang/OTP SSH server with a CVSS score of 10.0. An attacker with network access to any service built on Erlang/OTP's SSH daemon can execute arbitrary OS commands…
Patched 2026-05-17 - CVE-2026-31431 binary HIGH KEV EPSS 100%
Copy Fail Linux Kernel Local Privilege Escalation (CVE-2026-31431)
Copy Fail (CVE-2026-31431) is a Linux kernel local privilege-escalation vulnerability published by Theori (Xint Code). The provided PoC abuses AFALG AEAD socket operations with crafted parameters and splice() writes to patch privileged executable bytes and…
Patched 2026-05-17 - CVE-2023-22527 web CRITICAL 10 KEV Ransomware EPSS 100%
Confluence SSTI RCE - CVE-2023-22527
CVE-2023-22527 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server. The vulnerability is a Server-Side Template Injection (SSTI) in the Velocity/Freemarker template engine, reachable via the…
Patched 2026-05-17 - CVE-2024-21683 web HIGH 8.3 EPSS 88%
Confluence Post-Auth RCE - CVE-2024-21683
CVE-2024-21683 is an authenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server affecting the "Add a New Language" feature in the Code Macro plugin. An authenticated Confluence administrator can upload a malicious .js…
Unverified 2026-05-17 - CVE-2025-54914 cloud CRITICAL 10
Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914 is a critical privilege escalation vulnerability (CVSS 10.0) in Microsoft Azure Networking. Discovered by Mark Mallia and disclosed on September 4, 2025, the flaw arises from a missing authorization check in the GetRouteTable API code path. A…
Patched 2026-05-17 - CVE-2026-23918 web CRITICAL EPSS 50%
Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918
CVE-2026-23918 is a pre-authentication double-free vulnerability in Apache httpd's modhttp2 stream cleanup path. Under affected configurations, a remote attacker can trigger memory corruption over HTTP/2 before authentication. The upstream PoC demonstrates…
Patched 2026-05-17 - CVE-2025-21298 binary CRITICAL 9.8 EPSS 81%
Windows OLE Zero-Click RCE via Outlook RTF (CVE-2025-21298)
CVE-2025-21298 is a critical Windows OLE memory-corruption vulnerability in ole32.dll that can be triggered through malicious RTF content. In Outlook scenarios, preview-pane rendering is sufficient to trigger the vulnerable parsing flow, making this…
Patched 2026-05-16 - CVE-2024-37079 network CRITICAL 9.8 KEV EPSS 22%
VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)
CVE-2024-37079 is a critical heap overflow condition in a vCenter Server DCE/RPC network-handling path. A crafted network packet can trigger memory corruption pre-authentication and potentially lead to remote code execution. Public reporting indicates patch…
Patched 2026-05-16 - CVE-2024-37085 network MEDIUM 6.8 KEV Ransomware EPSS 26%
VMware ESXi Active Directory Authentication Bypass (CVE-2024-37085)
CVE-2024-37085 is an authentication bypass in domain-joined VMware ESXi environments where AD group membership manipulation can grant administrator-level ESXi access without valid local ESXi credentials. Public reporting links this issue to real-world…
Patched 2026-05-16 - binary CRITICAL
QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain
QEMUtiny is a memory corruption exploit chain in QEMU CXL Type-3 emulation that combines an out-of-bounds read (GETLOG) with an out-of-bounds write (SETFEATURE). The PoC leaks QEMU process pointers and then corrupts CXL device-adjacent state to steer…
Unverified 2026-05-16 - CVE-2025-0108 web CRITICAL 9.1 KEV EPSS 98%
Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
CVE-2025-0108 is an authentication bypass in the PAN-OS management interface that can allow unauthorized administrative access. The PoC uses a crafted path traversal style request to reach sensitive management functionality without a valid login session.…
Patched 2026-05-16 - CVE-2024-6387 network HIGH 8.1 EPSS 100%
OpenSSH regreSSHion Signal-Handler Race Unauthenticated RCE (CVE-2024-6387)
CVE-2024-6387 (regreSSHion) is a signal-handler race condition in OpenSSH sshd that reintroduced a previously fixed bug class and can allow unauthenticated remote code execution as root on glibc-based Linux systems. The issue is triggered around…
Patched 2026-05-16 - CVE-2024-21762 web CRITICAL 9.6 KEV Ransomware EPSS 84%
Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)
CVE-2024-21762 is a critical out-of-bounds write in FortiOS sslvpnd reachable through the SSL VPN web interface. A remote unauthenticated attacker can send crafted HTTP requests to corrupt memory and potentially achieve remote code execution. Public reporting…
Patched 2026-05-16 - CVE-2024-55591 web CRITICAL 9.6 KEV Ransomware EPSS 98%
Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)
CVE-2024-55591 is an authentication bypass in Fortinet management interfaces that can be abused over a crafted WebSocket workflow. The public PoC demonstrates racing WebSocket login-context traffic to gain effective super-admin CLI access without valid…
Unverified 2026-05-16 - CVE-2026-41940 web CRITICAL 10 KEV Ransomware EPSS 98%
cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)
CVE-2026-41940 is a critical unauthenticated authentication bypass in cPanel & WHM. The vulnerable session handling flow writes attacker-controlled Authorization: Basic data to the session file before sanitization, allowing CRLF injection of trusted session…
Patched 2026-05-16 - CVE-2025-5777 web CRITICAL 9.3 KEV Ransomware EPSS 100%
Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777)
CVE-2025-5777 ("CitrixBleed 2") is an unauthenticated out-of-bounds memory disclosure in Citrix NetScaler ADC/Gateway authentication processing. A crafted request can leak chunks of process memory that may contain active session tokens and credentials.…
Patched 2026-05-16 - CVE-2026-2441 web HIGH 8.8 KEV EPSS 22%
Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441)
CVE-2026-2441 is a Blink use-after-free vulnerability in CSSFontFeatureValuesMap iteration logic. A crafted web page mutates a styleset map while iterating through entries, which can invalidate internal structures and trigger renderer memory safety failure on…
Unpatched 2026-05-16 - CVE-2025-30065 misc CRITICAL 10 EPSS 41%
Apache Parquet Java Unsafe Deserialization RCE (CVE-2025-30065)
CVE-2025-30065 is an unsafe deserialization issue in Apache Parquet Java schema handling that can instantiate attacker-controlled classes while parsing malicious Parquet/Avro metadata. The provided PoC demonstrates two practical outcomes: arbitrary command…
Patched 2026-05-16 - CVE-2026-34621 binary CRITICAL 9.8 KEV
Adobe Acrobat/Reader Prototype Pollution Sandbox Escape (CVE-2026-34621)
This repository contains a Python-based exploit generator for CVE-2026-34621, described as a prototype pollution vulnerability in Adobe Acrobat and Reader that can break JavaScript trust boundaries. The generated PDF embeds JavaScript intended to escalate…
Unverified 2026-05-16 - CVE-2025-6218 misc HIGH KEV EPSS 89%
WinRAR Archive Extraction Path Traversal (CVE-2025-6218)
This PoC demonstrates CVE-2025-6218 in WinRAR, where a crafted archive extraction path can place files outside the intended destination directory. The provided batch script builds a ZIP archive that writes a .bat file into the current user's Startup folder.…
Unverified 2026-05-15 - CVE-2026-33825 binary HIGH 7.8 KEV Ransomware
RedSun Privileged File Write (CVE-2026-33825)
RedSun documents a local privilege-escalation technique where Defender's handling of a cloud-tagged malicious file can be abused as a privileged file write primitive. The PoC orchestrates file operations so the antimalware rewrite path lands on a high-value…
Patched 2026-05-15 - CVE-2025-29927 web CRITICAL 9.1 EPSS 99%
Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)
CVE-2025-29927 is a critical authentication bypass in Next.js middleware. By sending a crafted x-middleware-subrequest HTTP header, an unauthenticated remote attacker can cause the Next.js middleware layer to skip execution entirely — bypassing authentication…
Patched 2026-05-15 - CVE-2020-17103 binary HIGH 7.8 EPSS 27%
MiniPlasma - Windows Cloud Files Mini Filter Driver LPE (CVE-2020-17103)
MiniPlasma is a fully weaponized Windows LPE that exploits a race condition in cldflrt!HsmOsBlockPlaceholderAccess inside cldflt.sys — the same vulnerability originally discovered by James Forshaw (Google Project Zero) and reported as CVE-2020-17103 in 2020.…
Patched 2026-05-15 - CVE-2024-49113 network CRITICAL EPSS 83%
LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)
LDAP Nightmare is a public PoC for CVE-2024-49113, a critical vulnerability in Windows LDAP client behavior that can be reached through Netlogon workflow interactions. The PoC starts a malicious LDAP service and triggers victim-side LDAP resolution via…
Patched 2026-05-15 - CVE-2021-31166 network CRITICAL 9.8 KEV EPSS 100%
HTTP Protocol Stack Remote Code Execution Vulnerability (CVE-2021-31166)
CVE-2021-31166 is a remote use-after-free vulnerability in the Windows HTTP Protocol Stack (http.sys) that is reachable via crafted HTTP headers. The public PoC sends a malformed Accept-Encoding header to trigger unsafe list handling in the kernel HTTP parser…
Patched 2026-05-15 - CVE-2026-42897 web MEDIUM 5.3 KEV EPSS 70%
Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897)
CVE-2026-42897 describes a diagnostic blind spot in Exchange Health Checker. The analyzer only enumerates inbound IIS URL Rewrite rules and ignores outbound rules. The EOMT mitigation for this CVE installs an outbound Content-Security-Policy rewrite rule…
Unverified 2026-05-15 - CVE-2024-21338 binary HIGH 7.8 KEV Ransomware EPSS 60%
CVE-2024-21338 — Local Privilege Escalation from Admin to Kernel
This PoC targets CVE-2024-21338, a Windows local privilege-escalation issue that enables escalation from local administrator context toward kernel-level control. The exploit chain performs token impersonation and then abuses an AppLocker IOCTL handler with…
Patched 2026-05-15 - CVE-2026-33825 binary HIGH 7.8 KEV Ransomware
BlueHammer Defender Local Privilege Escalation (CVE-2026-33825)
BlueHammer is a Windows local privilege-escalation PoC targeting Defender-associated update and scanning behavior. The exploit orchestrates object-manager symbolic links, directory change notifications, oplocks, RPC-triggered Defender activity, and…
Patched 2026-05-15 - CVE-2023-45866 network HIGH 8.8
BlueDucky — Unauthenticated Peering Leading to Code Execution (CVE-2023-45866)
BlueDucky is a practical PoC implementation for CVE-2023-45866. It automates Bluetooth device discovery/selection and then emulates HID keyboard input to inject attacker-controlled DuckyScript payloads on vulnerable nearby targets. Because the pairing…
Patched 2026-05-15 - CVE-2026-42945 web CRITICAL 9.8 EPSS 66%
NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945)
CVE-2026-42945 is a critical heap buffer overflow in NGINX's ngxhttprewritemodule that has existed since 2008. When a server configuration combines a rewrite rule containing ? with a set directive, NGINX's two-pass script engine allocates an undersized buffer…
Unverified 2026-05-14 - CVE-2026-46300 binary HIGH 7.8
Linux XFRM ESP-in-TCP Local Privilege Escalation (Fragnesia)
CVE-2026-46300 ("Fragnesia") is a universal Linux local privilege escalation vulnerability in the XFRM ESP-in-TCP subsystem. It is a member of the Dirty Frag vulnerability class — a separate bug from the original dirtyfrag — that abuses a logic flaw where the…
Patched 2026-05-14 - CVE-2026-43500, CVE-2026-43284 binary CRITICAL 7.8 EPSS 93%
Dirty Frag: Linux XFRM/RxRPC Page Cache Write Chain LPE
Dirty Frag is a universal Linux Local Privilege Escalation (LPE) vulnerability class discovered by Hyunwoo Kim (@v4bel) that chains two Page Cache Write primitives: the xfrm-ESP Page-Cache Write (CVE-2026-43284) and the RxRPC Page-Cache Write…
Patched 2026-05-14