web PoCs
subscribe (RSS)Proof-of-concept research filed under the web category.
Entries
431
in web
CISA KEV
63
exploited in the wild
Ransomware
20
known campaign use
Unpatched
155
no vendor fix
Critical
244
57% of listed
Severity
Exploitation signals
Patch status
Date range
431 result(s)
- CVE-2026-17544 / GHSA-x692-q9x7-8c3f web CRITICAL 9.8
PHP bcmath bccomp() Out-of-Bounds Write (CVE-2026-17544)
CVE-2026-17544 is an out-of-bounds write vulnerability in the PHP bcmath extension, specifically in the bcstr2num() function in ext/bcmath/libbcmath/src/str2num.c. When the manual scale is smaller than the auto scale, the fraction is truncated and a…
Unverified 2026-08-16 - CVE-2026-42533 web CRITICAL 9.8
nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 is a heap buffer overflow in nginx triggered by PCRE regex capture variable handling. When two map directives share the same capture group name, a length/value mismatch occurs in the internal variable copy code (ngxhttpscriptcopycapturecode and…
Unverified 2026-08-16 - CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web CRITICAL 10
Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 is an internal metadata spoofing vulnerability in Apache Traffic Server. ATS uses @-prefixed headers (e.g., @Ats-Internal, @ICAP-Status, @TCPInfo) as internal metadata that lives in the in-memory header structure but is never serialized on the…
Unverified 2026-08-16 - CVE-2026-64638 web HIGH 8.9
WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")
CVE-2026-64638 — nicknamed XSS2Shell by its discoverers at pwn.ai — is a pre-authentication reflected XSS in the WordPress login page that chains through five to seven stages into full remote code execution on the server. It is one of the most impactful…
Unverified 2026-08-09 - CVE-2026-63077 web CRITICAL 9.8 KEV
TeamCity — Unauthenticated RCE via Agent Polling Deserialization (CVE-2026-63077)
CVE-2026-63077 is an unauthenticated remote code execution vulnerability in JetBrains TeamCity. The agent polling subsystem accepts XML payloads from unregistered agents and deserializes them with XStream without any authentication or sanitization. An…
Patched 2026-08-09 - CVE-2025-61882 web CRITICAL 9.8 KEV Ransomware EPSS 100%
Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)
CVE-2025-61882 is an unauthenticated remote code execution chain in Oracle E-Business Suite 12.2.3 through 12.2.14. An attacker POSTs an XML document to the unauthenticated /OAHTML/configurator/UiServlet endpoint; the servlet extracts a returnurl element from…
Patched 2026-08-09 - CVE-2021-22205 web CRITICAL 10 KEV Ransomware EPSS 100%
GitLab Unauthenticated RCE via Workhorse Pre-Auth Upload into ExifTool DjVu Injection (CVE-2021-22205)
GitLab Workhorse intercepts multipart file uploads and strips image metadata by shelling out to ExifTool before the request is routed to Rails and therefore before any authentication or authorization decision is made. ExifTool in turn contained…
Patched 2026-08-09 - CVE-2026-60004 web HIGH 8.8
Gitea — diffpatch API Git Hook Remote Code Execution (CVE-2026-60004)
CVE-2026-60004 is an authenticated remote code execution vulnerability in the Gitea diffpatch API. The endpoint applies a supplied patch with git apply --cached, which should only update the index and never write files to disk. However, by sending the same…
Patched 2026-08-09 - CVE-2024-51378 web CRITICAL 10 KEV Ransomware EPSS 95%
CyberPanel Pre-Auth Remote Code Execution via getresetstatus Command Injection (CVE-2024-51378)
CyberPanel exposes two DNS/FTP reset-status endpoints, /dns/getresetstatus and /ftp/getresetstatus, whose handlers read a JSON statusfile property straight out of the request body and concatenate it into a shell command executed with sudo. Neither handler…
Patched 2026-08-09 - CVE-2026-65694 web HIGH 7.5
Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
Microweber CMS exposes an unauthenticated GET /userfiles/{path} route intended to serve files from its userfiles/ upload directory. The controller reads the path via $request->path — a Laravel magic-property accessor that falls back to the request's…
Patched 2026-07-31 - CVE-2026-9198 web CRITICAL 9.8 KEV EPSS 17%
IBM Langflow OSS Unauthenticated RCE via Auto-Login + validate/code Chain (CVE-2026-9198)
IBM Langflow OSS ships an /api/v1/autologin endpoint that, when the deployment has LANGFLOWAUTOLOGIN enabled (a common/default posture), will mint and hand back a fully-privileged SUPERUSER JWT access token to any caller — no credentials, no session, nothing.…
Patched 2026-07-31 - CVE-2025-32432 web CRITICAL 10 KEV EPSS 100%
Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)
Craft CMS shipped an incomplete patch for the earlier CVE-2023-41892 deserialization RCE, leaving a critical, pre-auth code-injection chain exploitable through the assets/generate-transform action. An unauthenticated attacker first poisons the server-side PHP…
Patched 2026-07-31 - CVE-2025-54988 web CRITICAL 9.8
Apache Tika PDF Parser XXE via Crafted XFA Form (CVE-2025-54988)
Apache Tika's PDF parser processes an embedded XFA (XML Forms Architecture) form's XML content with external entity resolution enabled. A crafted PDF whose AcroForm dictionary contains an /XFA key pointing to a stream object holding malicious XFA XML can…
Patched 2026-07-31 - CVE-2026-16723 web CRITICAL 9
Alibaba Fastjson 1.x checkAutoType Bypass to Remote Code Execution via jar:http SSRF and fd-Reread Trick (CVE-2026-16723)
CVE-2026-16723 is a critical, unauthenticated remote code execution vulnerability in Alibaba Fastjson 1.2.68 through 1.2.83, actively exploited in the wild against Spring Boot fat-JAR deployments. Under Fastjson stock defaults (AutoType disabled, SafeMode…
Unpatched 2026-07-31 - CVE-2026-66066 web CRITICAL 9.5
Rails Active Storage Arbitrary File Read to RCE via libvips Unfuzzed Loaders (CVE-2026-66066)
Rails Active Storage hands untrusted, attacker-supplied image uploads directly to libvips for variant/representation generation without disabling libvips' "unfuzzed" (i.e. not hardened against malicious input) loaders, specifically the MATLAB/HDF5 matload…
Patched 2026-07-27 - CVE-2026-56423 web HIGH 8.8
MISP Core `deleteSelection` Broken Access Control — Bulk Deletion of Foreign Event Reports & Sharing Groups (CVE-2026-56423)
MISP's bulk-deletion endpoints for Event Reports (/eventReports/deleteSelection) and Sharing Groups (/sharingGroups/deleteSelection) authorize each selected item using a checkModifyCallback that discards the item id and instead returns the acting user's…
Patched 2026-07-27 - CVE-2026-50522 web CRITICAL 9.8 KEV EPSS 77%
Microsoft SharePoint Server WS-Federation SecurityContextToken Deserialization → Unauthenticated RCE (CVE-2026-50522)
SharePoint's WS-Federation passive sign-in endpoint (/trust/default.aspx) accepts a wresult parameter containing a WS-Trust RequestSecurityTokenResponse that can carry a SecurityContextToken with an embedded Cookie value. Windows Identity Foundation's…
Patched 2026-07-27 - CVE-2026-57830 web CRITICAL 9.1
Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)
Helix Ultimate's plugins/system/helixultimate/src/Platform/Media.php exposes deleteMedia() and getFolders() through the Joomla comajax dispatch hook (onAfterRoute()), reachable via option=comajax&helix=ultimate&action=delete-media/view-media. These methods…
Patched 2026-07-27 - CVE-2026-56291 web CRITICAL 9.8 KEV EPSS 76%
Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)
Balbooa Forms is a popular drag-and-drop form builder extension for Joomla!. Its form.uploadAttachmentFile task — reachable via the unauthenticated combaforms component entry point — accepts multipart file uploads for form attachments but performs neither a…
Unverified 2026-07-27 - N/A web CRITICAL
GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)
GitLab renders diffs for Jupyter notebooks by passing repository-controlled JSON through Oj, a native (C-extension) Ruby JSON parser, in the Puma worker process. The researcher (Yuhang Wu, depthfirst.com) found and chained two distinct memory-corruption bugs…
Unverified 2026-07-27 - CVE-2026-53753 web CRITICAL 9.8
Crawl4AI JsonCssExtractionStrategy AST Sandbox Escape → Unauthenticated RCE (CVE-2026-53753)
Crawl4AI's JsonCssExtractionStrategy supports "computed fields" — small Python expressions evaluated against each extracted item via safeevalexpression(). That function tries to sandbox the expression with an AST allow-list (rejecting only…
Patched 2026-07-27 - CVE-2026-54350 web CRITICAL 10
Budibase Unauthenticated NoSQL Operator Injection (CVE-2026-54350)
Budibase queries interpolate user-supplied parameters directly into a query's raw JSON body via Handlebars, then JSON.parse the result. The only input filter blocks Handlebars markers ({{/}}) but does not block ", \, } or $ — so a parameter value containing a…
Patched 2026-07-27 - CVE-2026-49230 web CRITICAL 9.1
Apache APISIX `jwe-decrypt` Integrity-Check Bypass → Unauthenticated Gateway Auth Bypass (CVE-2026-49230)
The jwe-decrypt plugin is an auth-type APISIX plugin that decrypts an incoming JWE token with a per-consumer AES-256-GCM secret and forwards the plaintext upstream as proof of authentication. Its internal helper jwedecryptwithobj() returns only the decrypted…
Patched 2026-07-27 - CVE-2026-63030 web CRITICAL 9.1 KEV EPSS 96%
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
A two-bug chain in stock WordPress core — no plugins, no misconfiguration, no special DB privileges required — that goes from a single unauthenticated HTTP request to a new administrator account and remote code execution. The always-true primitive is…
Patched 2026-07-19 - CVE-2026-48558 web CRITICAL 10 KEV EPSS 11%
SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)
When OIDC (OpenID Connect) authentication is configured on a SimpleHelp server, the server accepts identity tokens (JWTs) submitted during login without verifying their cryptographic signature. A remote, unauthenticated attacker can forge a token containing…
Patched 2026-07-19 - CVE-2026-58116 web CRITICAL 9.8
LLaMA-Factory WebUI Remote Code Execution via Hardcoded `trust_remote_code` (CVE-2026-58116)
LLaMA-Factory's WebUI hardcodes trustremotecode=True whenever it loads a model (src/llamafactory/webui/chatter.py:139 and runner.py:175,320). The "Model path" field — fully attacker/user-controlled — flows unvalidated into AutoTokenizer.frompretrained() /…
Patched 2026-07-19 - CVE-2026-55255 web HIGH 8.4 KEV EPSS 29%
Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)
Langflow's OpenAI-compatible Responses API (POST /api/v1/responses) accepts a model field that Langflow interprets as a flow ID to execute. The endpoint fails to verify that the API key making the request actually owns the flow ID supplied — so any…
Patched 2026-07-19 - CVE-2026-48282 web CRITICAL 10 KEV EPSS 99%
Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)
Adobe ColdFusion's Remote Development Service (RDS), a legacy feature that lets IDEs like Dreamweaver remotely browse, read, and write files on a ColdFusion server, is reachable via the /CFIDE/main/ide.cfm endpoint using a simple length-prefixed text…
Patched 2026-07-19 - CVE-2026-56271 web CRITICAL 9.8
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
Flowise's enterprise passport authentication middleware signs and verifies JWTs using values pulled from environment variables (JWTAUTHTOKENSECRET, JWTREFRESHTOKENSECRET, JWTAUDIENCE, JWTISSUER). When an operator doesn't set these — an easy oversight in a…
Patched 2026-07-12 - CVE-2026-56260 web CRITICAL 9.1
Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
Crawl4AI's Docker API server exposes /screenshot and /pdf endpoints that accept an outputpath parameter specifying where the rendered output should be saved. The parameter is passed straight into a file-write call with no validation whatsoever — no check for…
Patched 2026-07-12 - CVE-2023-38950 web HIGH 7.5 KEV EPSS 85%
ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)
ZKTeco BioTime v8.5.5 exposes the iclock device-communication API endpoint (/iclock/file) without authentication. The url query parameter, which is meant to reference firmware/log filenames pulled by physical biometric terminals, is concatenated into a…
Patched 2026-07-11 - CVE-2026-48939 web CRITICAL 9.8 KEV EPSS 83%
Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)
iCagenda's frontend event-registration form includes an optional file-attachment field. The "Registered Only" access restriction meant to gate that field is enforced only in the view layer that decides whether to render the form — the registration.submit…
Patched 2026-07-11 - CVE-2021-42237 web CRITICAL 9.8 KEV Ransomware EPSS 98%
Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)
Sitecore Experience Platform ships a legacy, unused reporting handler at /sitecore/shell/ClientBin/Reporting/Report.ashx that is reachable without authentication. The handler deserializes an attacker-supplied XML <parameters> block using…
Patched 2026-07-11 - CVE-2021-25296 web HIGH 8.8 KEV EPSS 72%
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)
Nagios XI's "Windows WMI" configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php) builds a WMI-check shell command using several attacker-supplied HTTP parameters, including pluginoutputlen. The value is never…
Patched 2026-07-11 - CVE-2021-25297 web HIGH 8.8 KEV EPSS 56%
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)
Nagios XI's "Switch" configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php) generates an MRTG configuration snippet for the monitored switch and writes it into an MRTG config file using a shell sed command built from…
Patched 2026-07-11 - CVE-2021-25298 web HIGH 8.8 KEV EPSS 75%
Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)
Nagios XI's "Cloud/VM" configuration wizard (/usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php) performs a reachability check against an attacker-supplied host address by shelling out to ping. The address parameter is concatenated…
Patched 2026-07-11 - CVE-2026-42208 web CRITICAL 9.8 KEV EPSS 89%
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
LiteLLM Proxy authenticates API requests by checking that the Authorization: Bearer token starts with sk-. When a caller sends a token that does not start with sk-, that assertion fails — but instead of simply rejecting the request, the raw, unhashed token is…
Patched 2026-07-11 - CVE-2026-20896 web CRITICAL 9.8 EPSS 32%
Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
Gitea supports reverse-proxy authentication: put it behind a proxy that sets an X-WEBAUTH-USER header, and Gitea trusts that header for the username, gated by REVERSEPROXYTRUSTEDPROXIES — an IP allowlist meant to ensure only the actual proxy can set that…
Patched 2026-07-11 - CVE-2025-24893 web CRITICAL 9.8 KEV EPSS 100%
XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)
CVE-2025-24893 is a critical unauthenticated remote code execution vulnerability in XWiki, caused by the built-in SolrSearch macro (Main.SolrSearch) passing user-supplied search input into a Groovy evaluation context without sanitization. By crafting a GET…
Patched 2026-07-06 - CVE-2025-11170 web CRITICAL 9.8
WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
The "WP移行専用プラグイン for CPI" WordPress plugin is vulnerable to unauthenticated arbitrary file upload due to missing file type validation in the CpiwmImportController::import function, present in all versions up to and including 1.0.2. The plugin registers an…
Unpatched 2026-07-06 - CVE-2025-13390 web CRITICAL 10
WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
WP Directory Kit implements a one-click "auto-login" feature via wdkgenerateautologinlink() that mints a login token from weak, predictable inputs (derived from the target user ID) rather than a cryptographically random secret. Because the token can be…
Patched 2026-07-06 - CVE-2025-39401 web CRITICAL 10
WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
The WPAMS WordPress plugin (<= 44.0) contains an Unrestricted Upload of File with Dangerous Type vulnerability (CWE-434): its public "apartment management member registration" form accepts an avatar/upload field (amgtuseravatar) without validating the file's…
Unverified 2026-07-06 - CVE-2025-49901 web CRITICAL 9.8
WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
The Simple Link Directory plugin's qc-opd (password reset) AJAX/form handler accepts a username and a new password and applies it to the corresponding WordPress account without verifying the requester's identity via any token tied to the user, email…
Patched 2026-07-06 - CVE-2025-5947 web CRITICAL 9.8
WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
The Service Finder Bookings WordPress plugin implements a "switch back to original user" feature (intended for admin-to-user account switching) via the servicefinderswitchback() AJAX handler, registered under the servicefinderswitchback action. This handler…
Unverified 2026-07-06 - CVE-2025-68860 web CRITICAL 9.8
WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
The WordPress "Mobile Builder" plugin (<= 1.4.2) implements its own JWT-based authentication scheme for its REST API integration but signs/validates tokens using a static, publicly known secret (examplekey) rather than a per-site secret. Because the signing…
Unpatched 2026-07-06 - CVE-2025-6440 web CRITICAL 9.8 EPSS 31%
WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)
The WooCommerce Dynamic Pricing & Discounts plugin (installed under the wc-designer-pro plugin folder) exposes an unauthenticated AJAX action, wcdpsavecanvasdesignajax, used by its product "canvas design" feature to save user-uploaded artwork. The handler…
Unverified 2026-07-06 - CVE-2025-47812 web CRITICAL 10 KEV EPSS 95%
Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)
Wing FTP Server's authentication routine cCheckUser() truncates the supplied username at the first NULL byte (%00) when validating credentials, but the code path that subsequently writes the session file persists the full, unsanitized username — including…
Patched 2026-07-06 - CVE-2025-29009 web CRITICAL 10
Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
The Webkul Medical Prescription Attachment plugin for WooCommerce exposes an AJAX action, wkwcpahandleprescriptionsession, that lets storefront visitors upload a "prescription" file attachment without validating the uploaded file's extension or MIME type on…
Patched 2026-07-06 - CVE-2025-12057 web CRITICAL 9.8
WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
WavePlayer, a WordPress audio player plugin, exposes an AJAX action (wvpl-ajax=createlocalcopy) that lets an unauthenticated visitor instruct the server to fetch a remote URL and save it as a local "track" file inside the uploads directory, without validating…
Unverified 2026-07-06 - CVE-2025-12539 web CRITICAL 10
TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
TNC Toolbox: Web Performance is a WordPress plugin that integrates with cPanel to manage caching/performance settings, and stores the cPanel API credentials (hostname, username, API key) it needs for that integration in plaintext files under a predictable,…
Patched 2026-07-06 - CVE-2025-63888 web CRITICAL 9.8
ThinkPHP 5.0.24 File Inclusion Leading to Remote Code Execution (CVE-2025-63888)
ThinkPHP 5.0.24's read() method in thinkphp/library/think/template/driver/File.php fails to validate the template path derived from user-controlled input passed to the framework's view() function. By submitting a crafted template parameter (e.g. a…
Unverified 2026-07-06 - CVE-2025-34282 web CRITICAL 9.1
ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
ThingsBoard versions before 4.2.1 are vulnerable to Server-Side Request Forgery (CWE-918) through its Image Upload Gallery feature. A Tenant Admin can upload a crafted SVG file whose <image xlink:href="..."> (or <pattern>/<image>) element references an…
Patched 2026-07-06 - CVE-2025-7441 web CRITICAL 9.8 EPSS 39%
StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)
The StoryChief WordPress plugin exposes an unauthenticated REST webhook endpoint (/wp-json/storychief/webhook) that accepts a JSON payload describing a "published" story, including a data.featuredimage.data.sizes.full field containing a URL. The plugin…
Unpatched 2026-07-06 - CVE-2025-48148 web CRITICAL 9.8 EPSS 16%
StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)
The StoreKeeper for WooCommerce plugin exposes an admin-ajax.php action (uploadproductimage) that fails to validate the type/extension of uploaded files, in all versions up to and including 14.4.4. An unauthenticated attacker can extract a public AJAX nonce…
Unverified 2026-07-06 - CVE-2025-41243 web CRITICAL 10
Spring Cloud Gateway Actuator RCE — Vulnerable Environment Lab (CVE-2025-41243)
CVE-2025-41243 concerns a SpEL (Spring Expression Language) injection vulnerability in Spring Cloud Gateway that leads to remote code execution when the Actuator gateway management endpoint is exposed. The root cause is that Actuator's gateway routes API…
Unpatched 2026-07-06 - CVE-2025-6389 web CRITICAL 9.8 EPSS 73%
Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)
The Sneeit Framework plugin for WordPress registers an unauthenticated AJAX action, sneeitarticlespagination, whose callback function sneeitarticlespaginationcallback() takes a function name and a JSON-encoded argument list straight from $POST['callback'] and…
Unverified 2026-07-06 - CVE-2025-52691 web CRITICAL 10 KEV Ransomware EPSS 85%
SmarterMail Auth Bypass via Password Reset to Pre-Auth RCE (CVE-2025-52691 / WT-2026-0001)
This PoC chains two SmarterMail vulnerabilities into a single pre-authentication-to-RCE exploit. First (WT-2026-0001), the /api/v1/auth/force-reset-password endpoint accepts a password-reset request that sets a new password for an arbitrary (including…
Patched 2026-07-06 - CVE-2025-4334 web CRITICAL 9.8
Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
The "Simple User Registration" WordPress plugin (versions <= 6.3) exposes a front-end registration form whose submission handler (wprsubmitform, invoked via admin-ajax.php) accepts a role field directly from the submitted form data without server-side…
Unverified 2026-07-06 - CVE-2025-53580 web CRITICAL 9.8
Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
The Simple Business Directory Pro plugin for WordPress exposes a front-end password-restore feature (qcpd-restore-pwd) that accepts a numeric WordPress user ID (qcpd-uid) and a new plaintext password (pass) via a simple POST request, without requiring any…
Patched 2026-07-06 - CVE-2025-31324 web CRITICAL 10 KEV Ransomware EPSS 100%
SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)
CVE-2025-31324 is an unrestricted file upload vulnerability in the Metadata Uploader servlet of SAP NetWeaver Visual Composer (VCFRAMEWORK), which is exposed unauthenticated on the /developmentserver/metadatauploader endpoint. The root cause is that this…
Patched 2026-07-06 - CVE-2025-4632 web CRITICAL 9.8 KEV EPSS 24%
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
Samsung MagicINFO 9 Server's SWUpdateFileUploader servlet, which handles firmware/content update uploads from signage devices, fails to properly sanitize the fileName parameter, allowing directory traversal sequences (../../) to break out of the intended…
Patched 2026-07-06 - CVE-2025-49113 web CRITICAL 9.9 KEV EPSS 98%
Roundcube Webmail Post-Auth RCE via PHP Object Deserialization (CVE-2025-49113)
Roundcube Webmail versions up to and including 1.6.10 are vulnerable to a post-authentication PHP object deserialization vulnerability in the file upload handler, which passes a client-supplied attachment filename through a deserialization path without…
Patched 2026-07-06 - CVE-2025-9209 web CRITICAL 9.8
RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
RestroPress, a WordPress food-ordering plugin, exposes user account metadata through the default wp-json/wp/v2/users REST endpoint, including private fields such as rpapiuserprivatekey, rpapiuserpublickey, and rpapiusertokenkey. These values are sensitive…
Unpatched 2026-07-06 - CVE-2025-6758 web CRITICAL 9.8
Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 is a critical privilege-escalation vulnerability in the Real Spaces WordPress Properties Directory Theme (versions <= 3.6), reachable through the theme's imicagentregister AJAX registration handler. The handler accepts a client-supplied role…
Unverified 2026-07-06 - CVE-2025-55182 web CRITICAL 10 KEV Ransomware EPSS 100%
React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182)
CVE-2025-55182, dubbed "React2Shell", is a critical unauthenticated remote code execution vulnerability in React Server Components' Flight protocol deserialization. The Flight protocol serializes/deserializes component data exchanged between client and…
Patched 2026-07-06 - CVE-2025-49132 web CRITICAL 10 EPSS 41%
Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)
Pterodactyl Panel prior to version 1.11.11 exposes a /locales/locale.json endpoint that accepts attacker-controlled locale and namespace query parameters without a required integrity/hash check, allowing an unauthenticated attacker to traverse outside the…
Patched 2026-07-06 - CVE-2025-61922 web CRITICAL 9.1
PrestaShop Checkout Zero-Click Account Takeover via ExpressCheckout Endpoint (CVE-2025-61922)
The PrestaShop Checkout module exposes an ExpressCheckout endpoint (/module/pscheckout/ExpressCheckout) that is meant to handle PayPal Express Checkout order confirmation callbacks. Versions of the module prior to 5.0.5 fail to properly verify that the caller…
Patched 2026-07-06 - CVE-2025-11391 web CRITICAL 9.8
PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
The "PPOM for WooCommerce" plugin (WooCommerce Product Addon / PPOM Fields) is vulnerable to an unauthenticated time-based blind SQL injection in its getproductmeta() function, present in versions up to and including 33.0.15. The function concatenates a…
Patched 2026-07-06 - CVE-2025-10147 web CRITICAL 9.8
Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the moveasoriginalfile function, present in all versions up to and including 4.2.6. The plugin's image-caching route accepts an…
Unverified 2026-07-06 - CVE-2025-13780 web CRITICAL 9.1
pgAdmin 4 Restore Feature Regex-Bypass Command Injection RCE (CVE-2025-13780)
pgAdmin 4's database Restore feature attempts to block dangerous psql meta-commands — which begin with a backslash (\) and can execute arbitrary shell commands via \! — using the regular expression (^|\n)[ \t]\\. This regex only matches a backslash that…
Unverified 2026-07-06 - CVE-2025-2945 web CRITICAL 9.9 EPSS 47%
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)
pgAdmin 4's Query Tool "download" endpoint accepts a querycommited parameter and passes it directly to Python's built-in eval() without any sanitization, allowing an authenticated attacker to run arbitrary Python code under the pgAdmin service account. The…
Patched 2026-07-06 - CVE-2025-61757 web CRITICAL 9.8 KEV EPSS 88%
Oracle Identity Manager `;.wadl` Authentication Bypass + Groovy Script RCE (CVE-2025-61757)
Oracle Identity Manager's SecurityFilter fails to correctly normalize request URIs before applying its authentication check. By appending a ;.wadl matrix-parameter suffix to the path of the groovyscriptstatus endpoint, an unauthenticated attacker can bypass…
Unpatched 2026-07-06 - CVE-2025-6934 web CRITICAL 9.8 EPSS 24%
Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934)
The Opal Estate Pro plugin (<= 1.7.5) exposes a public-facing user self-registration AJAX action, opalestateregisterform, handled by an onregisteruser function that fails to restrict which role value a registering visitor may request. A registration request…
Unverified 2026-07-06 - CVE-2025-23061 web CRITICAL 9
Mongoose `populate()` Match `$where` Bypass Command Injection (CVE-2025-23061)
CVE-2025-23061 is an incomplete-fix bypass of CVE-2024-53900, a NoSQL/command injection vulnerability in the Mongoose ODM for Node.js. The original fix blocked $where operators submitted directly inside a populate() match filter, but failed to sanitize $where…
Patched 2026-07-06 - CVE-2025-54068 web CRITICAL 9.8 KEV EPSS 96%
Laravel Livewire Remote Code Execution via Known APP_KEY (CVE-2025-54068)
Laravel Livewire serializes component state into a wire:snapshot HTML attribute and protects it with an HMAC-SHA256 checksum keyed on the application's APPKEY. If an attacker obtains the APPKEY (leaked .env, default/demo key, weak secret, etc.), they can…
Patched 2026-07-06 - CVE-2025-27515 web CRITICAL 9.8
Laravel `files.*` Wildcard Validation Bypass via Polyglot JPEG+PHP Upload (CVE-2025-27515)
CVE-2025-27515 is a file upload validation bypass (CWE-20: Improper Input Validation) affecting Laravel applications that validate array-based file uploads with wildcard rules such as files.. The root cause is that Laravel's mimes: validation rule inspects…
Patched 2026-07-06 - CVE-2026-27966 web CRITICAL 9.8 EPSS 34%
Langflow Pre-Auth RCE Mass Scanner (CVE-2026-27966)
Langflow versions prior to 1.8.0 hardcode allowdangerouscode=True in the CSV Agent component, exposing LangChain's pythonreplast tool to prompt injection. Independently, several Langflow REST API endpoints (customcomponent, build/{uuid}/vertices,…
Patched 2026-07-06 - CVE-2025-2294 web CRITICAL 9.8 EPSS 78%
Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)
The Kubio AI Page Builder plugin for WordPress, in all versions up to and including 2.5.1, is vulnerable to Local File Inclusion via the kubiohybridthemeloadtemplate function. The root cause is that a template path supplied through a query-string parameter is…
Unverified 2026-07-06 - CVE-2025-12674 web CRITICAL 9.8
KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
KiotViet Sync is a WordPress plugin that synchronizes products between the KiotViet retail/POS platform and a WooCommerce store via a custom REST route. Its createmedia() function, invoked when syncing a product's image, accepts a remote rawimageid URL and…
Unverified 2026-07-06 - CVE-2025-14440 web CRITICAL 9.8
JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
The JAY Login & Register plugin implements a "switch back" feature — presumably intended for admins who impersonate another user to later switch back to their own account — via the jayloginregisterprocessswitchback handler. This handler trusts the…
Unverified 2026-07-06 - CVE-2025-47916 web CRITICAL 10 EPSS 85%
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)
Invision Community's theme editor exposes a customCss() action on the front-end themeeditor controller (/applications/core/modules/front/system/themeeditor.php) that is reachable without authentication and passes the attacker-supplied content request…
Patched 2026-07-06 - CVE-2025-54123 web CRITICAL 9.8 EPSS 11%
Hoverfly Middleware Command Injection to RCE (CVE-2025-54123)
Hoverfly exposes a middleware configuration API (/api/v2/hoverfly/middleware) that lets an authenticated admin register an external "middleware" process to pre/post-process simulated HTTP traffic, specified as a binary (interpreter/executable) plus a script…
Patched 2026-07-06 - CVE-2025-41115 web CRITICAL 10 EPSS 17%
Grafana Enterprise SCIM User ID Collision / Impersonation (CVE-2025-41115)
Grafana Enterprise/Cloud's SCIM provisioning feature (enabled via the enableSCIM feature flag together with usersyncenabled) fails to properly validate the externalId supplied when a SCIM client creates a user via POST /api/scim/v2/Users. This lets a caller…
Patched 2026-07-06 - CVE-2025-14611 web CRITICAL 9.8 KEV EPSS 53%
Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)
CentreStack and Triofox protect file-download "access tickets" with AES-256-CBC, but the encryption key and IV are not generated per-installation — they are static byte strings hardcoded in GladCtrl64.dll's .data section and returned verbatim by the…
Unverified 2026-07-06 - CVE-2025-22777 web CRITICAL 9.8
GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 is an unauthenticated PHP Object Injection (CWE-502, Deserialization of Untrusted Data) vulnerability in the GiveWP WordPress donation plugin. GiveWP stores certain donor-supplied form field values as serialized PHP meta in the database and…
Patched 2026-07-06 - CVE-2025-13342 web CRITICAL 9.8
Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 is a critical, fully unauthenticated privilege-escalation vulnerability in the Frontend Admin plugin for WordPress (<= 3.28.20). The plugin's ACF-powered frontend registration/form-submission handler accepts user-controlled acff[user][field]…
Patched 2026-07-06 - CVE-2025-57819 web CRITICAL 9.8 KEV EPSS 88%
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
CVE-2025-57819 is an unauthenticated SQL injection in FreePBX's admin/ajax.php endpoint handler for the endpoint module, where the brand parameter is concatenated into a backend SQL query without sanitization. The PoC first confirms the injection with an…
Patched 2026-07-06 - CVE-2025-14156 web CRITICAL 9.8
Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
Fox LMS exposes a REST API endpoint, /wp-json/fox-lms/v1/payments/create-order, intended to register a new user as part of a course-purchase flow. The endpoint accepts a role field in the JSON body but does not validate or restrict it to safe values (e.g.…
Unverified 2026-07-06 - CVE-2025-49071 web CRITICAL 9.8
Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
The Flozen Theme for WordPress (versions up to and including 1.5.1) registers a wphandleupload-routed AJAX action (backed by the theme's flozenaddnewcustomfont() function) that accepts a ZIP file upload without checking authentication or validating its…
Unverified 2026-07-06 - CVE-2025-58434 web CRITICAL 9.8 EPSS 50%
FlowiseAI Account-Takeover via Forgot-Password Token Leak (CVE-2025-58434)
CVE-2025-58434 is an authentication-bypass vulnerability in FlowiseAI's password-reset flow: the forgot-password endpoint returns the password-reset tempToken directly in its JSON response body instead of only delivering it out-of-band (e.g., via email), and…
Patched 2026-07-06 - CVE-2025-59528 web CRITICAL 10 EPSS 90%
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
Flowise exposes a CustomMCP node whose loadMethod handler (/api/v1/node-load-method/customMCP) accepts a user-supplied mcpServerConfig string. On the backend, this string is passed straight into a Function() constructor inside the convertToValidJSONString…
Patched 2026-07-06 - CVE-2025-64459 web CRITICAL 9.1 EPSS 19%
Django QuerySet/Q Object SQL Injection via `_connector` Kwarg (CVE-2025-64459)
This is a SQL injection vulnerability in Django's QuerySet/Q object construction: when application code builds a Q(kwargs) filter directly from user-controlled input (such as a raw request.GET QueryDict) without allow-listing keys, an attacker can supply the…
Patched 2026-07-06 - CVE-2025-49002 web CRITICAL 9.8 EPSS 45%
DataEase PostgreSQL JDBC Datasource-Validation Bypass to Remote Code Execution (CVE-2025-49002)
DataEase's /de2api/datasource/validate endpoint lets a client submit an arbitrary JDBC connection string when testing/validating a new datasource. By choosing datasource type: h2 and supplying a base64-encoded H2 JDBC URL that includes INIT=RUNSCRIPT FROM…
Patched 2026-07-06 - CVE-2025-54309 web CRITICAL 9 KEV EPSS 94%
CrushFTP AS2 Header Authentication Bypass (CVE-2025-54309)
CrushFTP's web interface trusts the presence of the HTTP headers X-DMZ-Proxy: disabled and X-AS2-Version: 1.0 (plus a matching User-Agent) as proof that a request originates from an already-authenticated AS2 (Applicability Statement 2 / EDI-over-HTTP) proxy…
Patched 2026-07-06 - CVE-2025-14700 web CRITICAL 9.9
Crafty Controller Webhook Jinja2 Server-Side Template Injection RCE (CVE-2025-14700)
Crafty Controller's server Webhook configuration accepts a user-controlled "body" template that is rendered server-side with Jinja2 without sandboxing. An authenticated user can set the webhook body to a Jinja2 expression that escapes the sandbox via…
Unverified 2026-07-06 - CVE-2025-13595 web CRITICAL 9.8
Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
The Cibeles AI plugin ships a debug/update helper, actualizadorgit.php, directly inside its plugin directory. The file is missing the standard WordPress ABSPATH guard, so it is reachable over plain HTTP without any authentication, and it implements a "GitHub…
Unverified 2026-07-06 - CVE-2026-33453 web CRITICAL 9.8
camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)
Apache Camel's camel-coap component copies CoAP request URI query parameters directly into Camel Exchange headers inside CamelCoapResource.handleRequest(), without applying any HeaderFilterStrategy. Because CoAPEndpoint extends DefaultEndpoint (not…
Unverified 2026-07-06 - CVE-2025-23048 web CRITICAL 9.1
Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)
CVE-2025-23048 is a client certificate authentication bypass in Apache HTTP Server's modssl that occurs when TLS 1.3 session resumption (session tickets/PSK) is used across virtual hosts configured with different SSLCACertificateFile directives. The root…
Patched 2026-07-06 - CVE-2026-27172 web CRITICAL 9.8
Apache Camel `camel-consul` ConsulRegistry Deserialization RCE (CVE-2026-27172)
Apache Camel's camel-consul component uses a Consul key/value store as a Camel bean registry (ConsulRegistry). When a bean is looked up by name, ConsulRegistryUtils.deserialize() Base64-decodes the stored KV value and deserializes it with a raw…
Patched 2026-07-06 - CVE-2025-13597 web CRITICAL 9.8
AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
AI Feeds ships the same vulnerable actualizadorgit.php "GitHub mirror updater" helper found in the vendor's other plugin, Cibeles AI (CVE-2025-13595) — it is directly reachable over HTTP (no ABSPATH guard, no authentication) and blindly downloads and mirrors…
Unverified 2026-07-06 - CVE-2025-11749 web CRITICAL 9.8 EPSS 75%
AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749)
AI Engine's built-in Model Context Protocol (MCP) server, exposed via WordPress REST routes under /wp-json/mcp/v1/, discloses a per-site MCP access token directly in the unauthenticated route listing when the plugin's MCP feature (or a "No-Auth URL"-style…
Unverified 2026-07-06 - CVE-2025-54236 web CRITICAL 9.1 KEV EPSS 97%
Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)
Magento's customer address form exposes a file-upload field (customattributes[countryid]) at customer/addressfile/upload that is intended to accept a small file attachment (e.g. a document tied to a custom address attribute), guarded only by a per-request…
Patched 2026-07-06 - CVE-2025-54253 web CRITICAL 10 KEV EPSS 88%
Adobe Experience Manager Forms XXE to JNDI RCE Scanner (CVE-2025-54253)
AEM Forms exposes several form-submission endpoints (e.g. /content/forms/af/submit, /services/SubmitForm, /bin/receive, /lc/submit) that parse attacker-supplied XML without disabling external entity resolution. The root cause is an XML parser configured to…
Unverified 2026-07-06 - CVE-2025-13486 web CRITICAL 9.8 EPSS 74%
ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)
The ACF Extended (ACFE) plugin's front-end form-rendering AJAX handler (wpajaxnoprivacfe/form/renderformajax) resolves user-controlled form configuration through prepareform(), which ultimately passes attacker-supplied data into calluserfuncarray() without…
Unverified 2026-07-06 - CVE-2025-65354 web CRITICAL 9.8
"Grocery" PHP Application `search_products_itname.php` `sitem_name` Boolean-Based SQL Injection (CVE-2025-65354)
The target is a PHP "Grocery" web application whose product-search endpoint, Grocery/searchproductsitname.php, takes a sitemname parameter that is concatenated into a backend SQL query without parameterization or escaping. This allows classic boolean-based…
Unpatched 2026-07-06 - CVE-2026-27470 web HIGH 8.8
ZoneMinder — Second-Order SQL Injection via Event Rename (CVE-2026-27470)
ZoneMinder's event-rename functionality (web/ajax/event.php) safely stores a user-supplied event name using a parameterized query, giving no indication anything is wrong. However, the "near events" lookup (web/ajax/status.php, getNearEvents()) later reads…
Patched 2026-07-05 - CVE-2026-28286 web CRITICAL
ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
ZimaOS exposes a file-management REST API endpoint (/v21/files/file) that accepts a user-supplied file path without canonicalizing it or restricting it to a base directory. Because this is a web-facing REST API rather than a local system call, an attacker…
Unverified 2026-07-05 - CVE-2026-1937 web HIGH 7.2
YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
The YayMail WooCommerce Email Customizer plugin registers an AJAX action, yaymailimportstate, that lets users import a saved settings ZIP file without any server-side capability check. An authenticated attacker holding only the WooCommerce Shop Manager role…
Unverified 2026-07-05 - CVE-2026-44595 / GHSA-p2rj-mrmc-9w29 web MEDIUM 4.3
YAMCS Unauthorized User Enumeration via IAM API (CVE-2026-44595)
The YAMCS IAM REST API endpoints (listUsers, getUser, listGroups, getGroup) fail to enforce the required SystemPrivilege.ControlAccess authorization check. Any authenticated user, including one with no assigned privileges, can call these endpoints directly…
Patched 2026-07-05 - CVE-2026-44596 / GHSA-w5r6-mcgq-7pq4 web MEDIUM 5.3
YAMCS Missing Rate Limiting on Authentication Endpoint (CVE-2026-44596)
The POST /auth/token authentication endpoint in yamcs-core accepts unlimited granttype=password login attempts with no rate limiting, account lockout, or failed-attempt throttling. An unauthenticated remote attacker with network access can brute-force…
Patched 2026-07-05 - CVE-2026-33137 web CRITICAL 9.3
XWiki Unauthenticated XAR Import Leading to RCE — CVE-2026-33137
XWiki's REST endpoint POST /wikis/{wikiName} imports a XAR (XWiki Archive, a ZIP-based export/import format) directly into the wiki without verifying that the requester has administrative rights on the target. Because the endpoint performs no authorization…
Patched 2026-07-05 - CVE-2026-39912 web CRITICAL 9.1
Xboard / V2Board — Magic Link Token Leak Unauth Account Takeover (CVE-2026-39912)
Both V2Board and its fork Xboard implement a "login with mail link" (magic link) feature. Their loginWithMailLink endpoint (AuthController.php in V2Board, MailLinkService.php in Xboard) generates the one-time login link and is supposed to only deliver it via…
Patched 2026-07-05 - CVE-2026-1357 web CRITICAL EPSS 33%
WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)
The WPvivid Backup & Migration plugin's remote migration/"send to site" feature decrypts an incoming session key with opensslprivatedecrypt(). When decryption fails, the function returns boolean false instead of the code aborting, and that false is passed…
Unverified 2026-07-05 - CVE-2026-49105 web HIGH 8.1
WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
This PoC targets the WP Zendesk for Contact Form 7 plugin, whose cf7-zendesk.php calls maybeunserialize() on user-supplied Contact Form 7 field values without validation. An unauthenticated attacker can locate a site's CF7 forms via the CF7 REST API (or by…
Unverified 2026-07-05 - CVE-2026-40791 web HIGH 7.2
WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
The public booking form of the WP Time Slots Booking Form plugin parses a submitted appointment field by splitting on a literal space character, then stores the resulting substring as the booking's time-slot value. Because HTML treats a tab character as valid…
Patched 2026-07-05 - CVE-2026-6379 web CRITICAL 8.6
WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
WP Photo Album Plus's wppagetphotos() function (in wppa-functions.php) parses the wppa-supersearch request parameter as a comma-separated value list. When the search "type" is o (Owner), the resulting DATA field is concatenated directly into a SQL query…
Patched 2026-07-05 - CVE-2026-49085 web HIGH 8.1
WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
This PoC targets the WP Insightly plugin, which calls PHP's maybeunserialize() on user-supplied form field values without validating the input. An unauthenticated attacker can submit a crafted PHP serialized object as a form field value through the plugin's…
Unverified 2026-07-05 - CVE-2026-5415 web HIGH 8.8
WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 is an authentication bypass in the WP Captcha PRO WordPress plugin that lets an authenticated Subscriber-level user escalate to any other account, including Administrators. The plugin's AJAX handler for creating temporary login links relies on a…
Unverified 2026-07-05 - CVE-2026-54806 web CRITICAL 9.8
WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
WP Activity Log logs the User-Agent header on any request that generates a loggable event (such as a failed login), and stores that value in the database without treating it as untrusted input. The stored value is later deserialized (via PHP's native…
Patched 2026-07-05 - CVE-2026-0745 web MEDIUM
WordPress User Language Switch Plugin SSRF — CVE-2026-0745
The User Language Switch WordPress plugin exposes an ulsdownloadlanguage AJAX action that accepts a caller-supplied URL (infolanguage) and fetches it server-side to download a language file. The endpoint does not validate or restrict the destination, allowing…
Unverified 2026-07-05 - CVE-2026-12416, CVE-2026-12417 web CRITICAL 9.8
WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
Both plugins register a password-reset AJAX handler (pravelchangepassword for SignUp & SignIn, pravelinvoicechangepassword for Invoice Generator) as wpajaxnopriv, meaning it is reachable without authentication. Neither handler validates a WordPress nonce or…
Unverified 2026-07-05 - CVE-2026-0740 web HIGH EPSS 58%
WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740
Ninja Forms exposes a file-upload field feature reachable via WordPress's admin-ajax.php endpoint. The PoC script first requests a fresh nonce through the nffugetnewnonce action, then uses that nonce to submit a file via the nffuupload action. Because the…
Unverified 2026-07-05 - CVE-2026-4106 web HIGH
WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
The HT Mega plugin registers several wpajaxnopriv AJAX action hooks (e.g. wcsalespurchasedproducts, htmegauserlistajax) used to power dynamic widget content, but these handlers omit both authentication (checkajaxreferer) and authorization (currentusercan)…
Unverified 2026-07-05 - CVE-2026-39676 web MEDIUM
WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
The Download Manager WordPress plugin (<= 3.3.5.2) is missing a capability check on its file-serving and media-access endpoints. An unauthenticated attacker can directly reference internal object/file identifiers to bypass access restrictions and retrieve…
Unverified 2026-07-05 - CVE-2026-3180 web HIGH
WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
The Contest Gallery WordPress plugin passes the cglmaili parameter through WordPress's sanitizeemail() function, which preserves the single-quote character (') in the local part of an email address. Because the sanitized value is subsequently used to build a…
Unverified 2026-07-05 - CVE-2026-3844 web CRITICAL EPSS 37%
WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)
The Breeze Cache WordPress plugin (<= 2.4.4) exposes a gravatar-caching feature that writes attacker-supplied remote content directly into the plugin's cache directory without verifying that the fetched content is actually image data. An unauthenticated…
Unverified 2026-07-05 - CVE-2026-0594 web MEDIUM
WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
The "List Site Contributors" WordPress plugin reflects the alpha query parameter into page output without sanitization, allowing an attacker to inject arbitrary HTML/JavaScript that executes in a victim's browser when they visit a crafted link. The included…
Unverified 2026-07-05 - CVE-2026-3629 web CRITICAL
WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
The "Import and Export Users and Customers" WordPress plugin contains a privilege-escalation flaw that allows a low-privileged authenticated user to escalate to a higher-privileged role (e.g. administrator) through the plugin's user import/export…
Unverified 2026-07-05 - CVE-2026-3359 web CRITICAL
WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
The WordPress "Form Maker" plugin (up to version 1.15.42) passes attacker-controlled input from a crafted inputs[2|typecheckbox|all] field on the admin-ajax.php?action=fmreloadinput endpoint into a SQL query without adequate sanitization, allowing…
Unverified 2026-07-05 - CVE-2026-5364 web HIGH 8.1
WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
The plugin determines an uploaded file's extension via pathinfo() on the raw, attacker-supplied filename before that filename is passed through WordPress's sanitizefilename(). By uploading a file named e.g. shell.php$, pathinfo() reports the extension as php$…
Unverified 2026-07-05 - CVE-2026-27542 web CRITICAL 9.8
WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
The WWLC WordPress plugin ships two unauthenticated AJAX handlers that are exploited together in this tool. CVE-2026-27542 abuses wwlccreateuser, which fails to sanitize role-related fields, letting an unauthenticated attacker inject…
Unverified 2026-07-05 - CVE-2026-54807 web INFO
WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
The vulnerable plugin's frontend user-registration form accepts a userroles parameter directly from the unauthenticated registration POST request and trusts it when creating the new WordPress account, instead of forcing a safe default role (e.g. subscriber or…
Unverified 2026-07-05 - CVE-2026-44403 web HIGH
Wing FTP Server Admin Session Poisoning via Lua loadfile() RCE (CVE-2026-44403)
Wing FTP Server's WebAdmin session mechanism serializes session values as executable Lua source using [[...]] long-string literals. Because bracket-sanitization code that would strip [/] characters from session values was commented out, a value containing ]]…
Patched 2026-07-05 - CVE-2026-23723 / GHSA-xfmp-2hf9-gfjp web HIGH
WeGIA Authenticated Error-Based SQL Injection Exploitation Helper (CVE-2026-23723)
WeGIA's control.php endpoint (AtendidoocorrenciaControle::listarTodosComAnexo) is vulnerable to authenticated error-based SQL injection through the idmemorando parameter. This helper script automates the tedious part of exploitation: it attempts login against…
Patched 2026-07-05 - CVE-2026-1555 web CRITICAL 9.8
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
The WebStack WordPress theme registers an imgupload AJAX action via wpajaxnopriv, exposing it to unauthenticated visitors, and the handler function ioimgupload() performs no file type or extension validation before saving the uploaded file into a publicly…
Unverified 2026-07-05 - CVE-2026-27778 web MEDIUM
WebSocket Authentication Brute-Force via Missing Rate Limiting (CVE-2026-27778)
This repository is a hands-on simulator for CVE-2026-27778 (CWE-307: Improper Restriction of Excessive Authentication Attempts) built around a small Node.js/Express server that accepts WebSocket AUTHREQ messages containing a password guess and replies with…
Patched 2026-07-05 - CVE-2026-24126 web HIGH 6.5
Weblate Arbitrary File Read via ssh-keyscan Host Argument Injection — CVE-2026-24126
Weblate's SSH host-key management feature (weblate/ssh/views.py, addhostkey()) passes the administrator-supplied host field straight into an ssh-keyscan subprocess invocation with no sanitization and no -- argument terminator. Because ssh-keyscan supports a…
Patched 2026-07-05 - CVE-2026-43700 web HIGH
WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
WebKit's GPUDevice.importExternalTexture({ source: HTMLVideoElement }) imports the current frame of a <video> element as a GPU-sampleable GPUExternalTexture. Prior to the fix, WebKit did not check the video element's taintsOrigin (cross-origin CORS-tainted)…
Unverified 2026-07-05 - CVE-2026-20643 web MEDIUM
WebKit Navigation API Cross-Port canIntercept Bypass (CVE-2026-20643)
The Navigation API's navigate event exposes an event.canIntercept flag that browsers must set to false for navigations that cross a security boundary the page is not allowed to intercept — including navigations to a different port on the same host. This PoC…
Unverified 2026-07-05 - CVE-2026-43735 web HIGH
WebKit Navigation API `NavigateEvent.sourceElement` Cross-Origin DOM Leak (CVE-2026-43735)
CVE-2026-43735 is a WebKit Navigation API bug where, when a parent page uses a named <a target="iframeName"> link to trigger a fragment navigation inside a cross-origin <iframe>, the NavigateEvent.sourceElement delivered to the iframe's navigate event…
Unverified 2026-07-05 - CVE-2026-5615 web HIGH 8.5
VvvebJs SVG Upload Stored Cross-Site Scripting — CVE-2026-5615
VvvebJs versions <= 2.0.5 allow uploading SVG files without sanitizing their contents. Because SVG is XML that can embed <script>-equivalent event handlers (e.g. onload), an attacker can upload an SVG containing JavaScript, which is stored server-side and…
Patched 2026-07-05 - CVE-2026-37748 web HIGH 7.2
Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)
Visitor Management System 1.0 calls moveuploadedfile() in vms/php/adminuserinsert.php and vms/php/update1.php without validating the uploaded file's MIME type, extension, or content. An authenticated admin user can upload a PHP webshell disguised as a profile…
Unverified 2026-07-05 - CVE-2026-37064 web MEDIUM
Veno File Manager Unauthenticated User Enumeration (CVE-2026-37064)
Veno File Manager Project 4.4.9's /vfm-admin/ajax/usr-check.php endpoint allows an unauthenticated attacker to enumerate application users by sending a specially crafted POST request with a chosen username parameter and observing whether the response…
Unverified 2026-07-05 - CVE-2026-37066 web HIGH
Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
Veno File Manager Project 4.4.9 contains a path traversal vulnerability in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php that allows an authenticated attacker with the superadmin role to disclose sensitive information via two specially crafted HTTP…
Unverified 2026-07-05 - CVE-2026-37067 web MEDIUM
Veno File Manager Incorrect Access Control — Application Log Extraction (CVE-2026-37067)
Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a chosen date forward via a specially crafted POST request.
Unverified 2026-07-05 - CVE-2026-37068 web CRITICAL
Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)
Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the superadmin role to overwrite any PHP file in the application via a specially crafted POST request,…
Unverified 2026-07-05 - CVE-2026-37065 web HIGH
Veno File Manager Arbitrary File Deletion (CVE-2026-37065)
Veno File Manager Project 4.4.9 is vulnerable to arbitrary file deletion. An authenticated attacker with the superadmin role can send a specially crafted POST request using the remove URL parameter to control which file gets deleted, with no further…
Unverified 2026-07-05 - CVE-2026-37069 web LOW
Veno File Manager Absolute Path Disclosure (CVE-2026-37069)
Absolute path disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to learn the system directory in which the application code is running by sending a GET…
Unverified 2026-07-05 - CVE-2026-37072 web CRITICAL
Veno File Manager 4.4.9 — Unauthenticated LFI to Superadmin Takeover (CVE-2026-37072)
admin-head-updates.php in Veno File Manager 4.4.9 is vulnerable to Local File Inclusion via the unsanitized lang GET parameter. An unauthenticated attacker can send a crafted POST request with a path-traversal payload in lang that corrupts the application's…
Unverified 2026-07-05 - CVE-2026-37073 web MEDIUM
Veno File Manager 4.4.9 — Unauthenticated Email Hijack via SMTP Relay (CVE-2026-37073)
The /vfm-admin/ajax/sendfiles.php endpoint in Veno File Manager 4.4.9 lacks any access control, allowing an unauthenticated attacker to send arbitrary emails through the application's configured SMTP server. By supplying attacker-controlled destination,…
Unverified 2026-07-05 - CVE-2026-37070 web MEDIUM
Veno File Manager 4.4.9 — Authenticated Arbitrary File Read (CVE-2026-37070)
Veno File Manager 4.4.9 exposes the /vfm-admin/ajax/streamvid.php endpoint without properly restricting which files a session-authenticated user may request. A user who is only supposed to have access to their own assigned directory can instead read any…
Unverified 2026-07-05 - CVE-2026-37071 web HIGH
Veno File Manager 4.4.9 — Arbitrary File Rename to Privilege Escalation (CVE-2026-37071)
Veno File Manager 4.4.9's Actions::renameFile() function fails to restrict which files an authenticated user with rename permission can rename. By renaming the application's own vfm-admin/config.php file, an attacker triggers the application into believing it…
Unverified 2026-07-05 - CVE-2026-25050 web MEDIUM
Vendure GraphQL Admin API Authentication Timing Attack / User Enumeration (CVE-2026-25050)
Vendure's NativeAuthenticationStrategy.authenticate() method looks up a user by email and returns immediately (in roughly 1-5ms) when no matching account exists, but performs a costly bcrypt password verification (roughly 200-400ms) when the account does…
Patched 2026-07-05 - CVE-2026-26012 web MEDIUM 6.5
Vaultwarden Organization Collection Permissions Bypass & Cipher Enumeration (CVE-2026-26012)
CVE-2026-26012 is a broken access control vulnerability in Vaultwarden's organization cipher endpoint. The /api/ciphers/organization-details endpoint is reachable by any organization member regardless of their assigned collection permissions, and internally…
Patched 2026-07-05 - CVE-2026-4882 web CRITICAL 9.8
User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
The User Registration Advanced Fields plugin (<= 1.6.20) leaks a valid AJAX nonce via wplocalizescript() on any page containing a registration form. Its urafprofilepictureuploadmethodupload AJAX action normally validates uploaded file extensions, but passing…
Unverified 2026-07-05 - CVE-2026-1492 web CRITICAL 9.8 EPSS 24%
User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492)
The plugin's userregistrationmembershipregistermember AJAX handler accepts a client-supplied role field inside the membersdata JSON payload during membership registration, without enforcing a server-side allowlist or capability check. An unauthenticated…
Unverified 2026-07-05 - CVE-2026-6145 web MEDIUM 5.3
User Registration & Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)
The isadmincreationprocess() method in the User Registration & Membership plugin determines whether a new registration should be auto-approved and have its admin notification suppressed, based solely on whether $REQUEST['action'] equals createuser — with no…
Unverified 2026-07-05 - CVE-2026-10795 web CRITICAL
UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
UpdraftPlus ships a remote-management RPC channel (UpdraftCentral) reachable via admin-ajax.php that authenticates requests using an AES-encrypted message keyed to one of several well-known "keyname" identifiers (e.g. migrator.updraftplus.com). When a site…
Unverified 2026-07-05 - CVE-2026-35037 web HIGH
Unauthenticated SSRF in Ech0 via /api/website/title (CVE-2026-35037)
Ech0's GET /api/website/title endpoint fetches a URL supplied by the (unauthenticated) caller to extract a website's title, without restricting the target to safe, external hosts. This allows an unauthenticated attacker to force the Ech0 server to make…
Patched 2026-07-05 - CVE-2026-27621 web MEDIUM
TypiCMS Core — Stored XSS via Unsanitized SVG File Upload (CVE-2026-27621)
TypiCMS Core allows users with file-upload permission to upload SVG files, validating only the MIME type without sanitizing the SVG's internal content. Because SVG is an XML-based format that can embed <script> tags, an attacker can upload a malicious SVG…
Patched 2026-07-05 - CVE-2026-33712 web HIGH
Typebot Unauthenticated Preview-Chat SSRF — CVE-2026-33712
Typebot's preview-chat feature lets a caller submit an arbitrary typebot definition, including server-side "Code" blocks that execute inside an isolated-vm sandbox. In vulnerable versions, the fetch() function exposed to that sandbox called Node's native…
Patched 2026-07-05 - CVE-2026-7671 web MEDIUM
Tornet Scooter Mobile App OTP Brute Force via Missing Rate Limiting (CVE-2026-7671)
The Tornet Scooter mobile application's /TwoFactor backend endpoint does not implement rate limiting or account lockout on one-time-password (OTP) verification attempts. Because the OTP is a 4-digit numeric code (0000-9999), an attacker can brute-force the…
Unverified 2026-07-05 - CVE-2026-41901 web CRITICAL
Thymeleaf SpEL Injection Remote Code Execution (CVE-2026-41901)
The PoC reproduces a Spring Expression Language (SpEL) injection in a Thymeleaf-rendered template where user-controlled input is reflected into a template expression context without sanitization. By submitting a crafted SpEL payload such as…
Patched 2026-07-05 - CVE-2026-49772 web CRITICAL 9.3
The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772.py is a full-featured blind SQL injection tool targeting an unauthenticated, unsanitized order parameter on The Events Calendar's experimental REST endpoint GET /wp-json/tec/v1/events. A broken REST parameter validator (validatecallback returns…
Patched 2026-07-05 - CVE-2026-22804 web HIGH
Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)
Termix's built-in File Manager renders SVG files opened from a connected host using dangerouslySetInnerHTML, without stripping active content such as <foreignObject>/<img onerror=...>. An attacker who can place a crafted SVG on a filesystem reachable via…
Patched 2026-07-05 - CVE-2026-26903 web MEDIUM
TanStack Query — Unbounded Recursion Denial of Service in `replaceEqualDeep` (CVE-2026-26903)
TanStack Query's internal replaceEqualDeep function recursively performs deep-equality comparisons between old and new query cache data so that unchanged object references can be preserved across re-renders. The recursive implementation has no depth limit or…
Patched 2026-07-05 - CVE-2026-25964 web MEDIUM 4.9
Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
CVE-2026-25964 is a path traversal / arbitrary file read vulnerability in Tandoor Recipes' recipe-import workflow. The /api/recipe-import/ endpoint lets an authenticated user set an arbitrary filepath and storage backend on a RecipeImport object without…
Patched 2026-07-05 - CVE-2026-27886 web CRITICAL
Strapi CMS Admin Account Takeover via Query Filter Bypass — CVE-2026-27886
Strapi's Content API allows unauthenticated query-parameter filtering on collection endpoints (e.g. /api/articles) that leaks internal relation data through a boolean oracle. The PoC abuses a where-style filter bypass to enumerate the admin user's email…
Patched 2026-07-05 - CVE-2026-22732 web CRITICAL 9.1
Spring Security Lazy Header Writing Security Header Bypass (CVE-2026-22732)
CVE-2026-22732 affects Spring Security's default "lazy" header-writing mechanism, which normally injects security-related response headers (X-Frame-Options, X-Content-Type-Options, Cache-Control, Strict-Transport-Security, etc.) just before the HTTP response…
Patched 2026-07-05 - CVE-2026-22738 web CRITICAL 9.8
Spring AI SimpleVectorStore SpEL Injection RCE (CVE-2026-22738)
SimpleVectorStore.similaritySearch() builds a filter expression by concatenating a caller-supplied filterKey parameter directly into a Spring Expression Language (SpEL) string that is then evaluated by a full-featured StandardEvaluationContext. Because that…
Patched 2026-07-05 - CVE-2026-20251 web HIGH 8.8 EPSS 19%
Splunk Secure Gateway jsonpickle Deserialization RCE (CVE-2026-20251)
Splunk Secure Gateway lets mobile clients fetch alert data that is stored in the App Key Value Store and later reconstructed into Python objects using the jsonpickle library. A low-privileged authenticated user can write a crafted document to the mobilealerts…
Unverified 2026-07-05 - CVE-2026-7465 web CRITICAL 8.8
Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
The Spectra Gutenberg blocks plugin registers custom uagb/ block types whose rendering is driven by a rendercallback value that can be influenced by attacker-controlled block content embedded in a post. An authenticated user with Contributor-level privileges…
Unverified 2026-07-05 - CVE-2026-48909 web CRITICAL 9.5
SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
SP LMS's cart model (components/comsplms/models/cart.php) reads the lmsOrders cookie, base64-decodes it, and passes the result directly to PHP's unserialize() with no validation, giving an unauthenticated attacker full control over the deserialized object…
Patched 2026-07-05 - CVE-2026-1056 web CRITICAL EPSS 12%
Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)
Snow Monkey Forms' REST API route handler (SnowMonkey\Plugin\Forms\App\Rest\Route\View.php) contains a logic flaw where supplying method=input causes the handler to skip its CSRF token validation entirely and jump straight to the send() cleanup routine. That…
Unverified 2026-07-05 - CVE-2026-0001 web CRITICAL 9
SmarterMail Unauthenticated Admin Password Reset (CVE-2026-0001 / WT-2026-0001)
SmarterMail exposes an /api/v1/auth/force-reset-password endpoint intended for authenticated self-service password resets, but the handler fails to validate the caller's identity when the request body sets IsSysAdmin to true. Sending a crafted JSON payload…
Patched 2026-07-05 - CVE-2026-24423 web CRITICAL KEV Ransomware EPSS 88%
SmarterMail ConnectToHub Unauthenticated SSRF Leading to Remote Command Execution — CVE-2026-24423
SmarterMail's node-clustering feature allows an administrator to point a node at a "hub" server via the connect-to-hub API. The vulnerability is that the admin-level /api/v1/settings/sysadmin/connect-to-hub endpoint requires no authentication, and the server…
Unverified 2026-07-05 - CVE-2026-23760 web CRITICAL 9.3 KEV Ransomware EPSS 96%
SmarterMail Admin Password-Reset Authentication Bypass (CVE-2026-23760)
SmarterMail's force-reset-password API endpoint accepts anonymous requests and never validates the caller's existing password or a reset token before changing the password of a system administrator account. By POSTing a JSON body that names an existing admin…
Patched 2026-07-05 - CVE-2026-34227 web HIGH
Sliver C2 MCP Server Unauthenticated CORS/Preflight Bypass (CVE-2026-34227)
Sliver's MCP server exposes an unauthenticated Server-Sent Events (SSE) interface on 127.0.0.1:8080 and responds to every request with Access-Control-Allow-Origin: . Because the underlying mcp-go library does not validate the request's Content-Type, a…
Unverified 2026-07-05 - CVE-2026-48558 web CRITICAL 9.8 KEV EPSS 11%
SimpleHelp OIDC Authentication Bypass (CVE-2026-48558)
When OIDC authentication is enabled, SimpleHelp accepts identity tokens (ID Tokens/JWTs) at its OIDC callback endpoint without verifying their cryptographic signature — including tokens using alg: none. A remote, unauthenticated attacker can forge a JWT with…
Patched 2026-07-05 - CVE-2026-7459 web HIGH 7.5
Simple History Missing Authorization Account Takeover — CVE-2026-7459
Simple History exposes a REST "reaction" endpoint (/wp-json/simple-history/v1/events/{id}/react) that is missing proper authorization checks when the plugin's experimental features are enabled. A low-privileged, authenticated Subscriber can call this endpoint…
Unverified 2026-07-05 - CVE-2026-11912 web HIGH 7.5
Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
The Simple File List plugin registers its simplefilelisteditjob AJAX action on both the wpajax and wpajaxnopriv hooks, meaning it is reachable by unauthenticated visitors. The authorization check inside eeSFLFileEditor() relies on isadmin(), which always…
Patched 2026-07-05 - CVE-2026-23498 web HIGH
Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
Shopware previously fixed CVE-2023-2017 by restricting Twig filters so that only allow-listed functions could be invoked from templates. CVE-2026-23498 is a regression of that fix: the allow-list check was not applied to array- and closure-crafted values…
Patched 2026-07-05 - CVE-2026-30951 web HIGH
Sequelize ORM JSON Cast SQL Injection — CVE-2026-30951
Sequelize v6's JSON/JSONB where-clause processing treats the portion of a JSON path key following a :: delimiter as a SQL cast type, inserting it into the generated SQL query without validation. If an application allows attacker-controlled JSON object keys to…
Patched 2026-07-05 - CVE-2026-37750 web MEDIUM 6.1
School Management System 1.0 — Reflected XSS in register.php (CVE-2026-37750)
register.php in School Management System 1.0 reflects the type request parameter into the page's HTML twice — once inside an <h1> tag via ucfirst($REQUEST['type']) and once inside a form action attribute — without applying htmlspecialchars() or any output…
Unverified 2026-07-05 - CVE-2026-9067 web HIGH 8.1
Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
The plugin's saswprfformimageupload AJAX handler does not validate the requesting user's capability nor properly validate the uploaded file's type, allowing an unauthenticated attacker to upload arbitrary files (with a spoofed MIME type/extension) to the…
Unverified 2026-07-05 - CVE-2026-46490 / GHSA-34r5-q4jw-r36m web HIGH 8.8
samlify SAML AttributeValue XML Injection → Privilege Escalation (CVE-2026-46490)
samlify's template substitution engine (replaceTagsByValue / escapeTag in src/libsaml.ts) only XML-escapes values that are substituted into XML attribute contexts; values substituted into element text context (such as…
Patched 2026-07-05 - CVE-2026-23499 web HIGH
Saleor Stored XSS via Unrestricted File Upload (CVE-2026-23499)
Saleor allowed authenticated staff users or Apps to upload arbitrary file types through its media-upload functionality, including HTML and SVG files containing embedded JavaScript. In deployments where uploaded media is served from the same origin as the…
Patched 2026-07-05 - CVE-2026-22849 web HIGH
Saleor Rich Text (EditorJS) Field Stored XSS (CVE-2026-22849)
Saleor stores rich text content (page bodies, product descriptions, etc.) as EditorJS block JSON, and is supposed to run this content through a server-side HTML cleaner before persisting and rendering it. In the affected versions that cleaning step was not…
Patched 2026-07-05 - CVE-2026-24136 web HIGH 7.5
Saleor GraphQL IDOR — Unauthenticated Order PII Exfiltration (CVE-2026-24136)
Saleor exposes a GraphQL order(id: $id) query used to fetch detailed order information by its global Relay ID. In affected versions this resolver performs no authorization check, so any unauthenticated caller who obtains (or guesses) an order's global ID can…
Patched 2026-07-05 - CVE-2026-29198 web CRITICAL
Rocket.Chat OAuth2 NoSQL Injection Privilege Escalation — CVE-2026-29198
Rocket.Chat's OAuth2 authentication flow builds a MongoDB query from attacker-influenced OAuth2 profile/identity fields without sufficient sanitization, allowing NoSQL injection operators to be smuggled into the user lookup query. By crafting a malicious…
Patched 2026-07-05 - CVE-2026-39023 web CRITICAL
Responsive Filemanager 9.14.0 — Unauthenticated RCE via Duplicate File (CVE-2026-39023)
Responsive Filemanager 9.14.0 allows an unauthenticated attacker to abuse its "duplicate file" functionality to create a new file with an attacker-chosen name and PHP extension containing arbitrary content. By duplicating an existing file into a .php file…
Unpatched 2026-07-05 - CVE-2026-4802 web HIGH
Red Hat Cockpit `logsJournal.jsx` Shell Injection RCE (CVE-2026-4802)
Cockpit's systemd logs page builds a journalctl invocation from URL-fragment-derived filter parameters (such as --since=) inside loadServiceFilters(). The resulting argument array is joined into a single shell string with only whitespace escaping and then…
Unpatched 2026-07-05 - CVE-2026-27579 web HIGH 7.4
Realtime Collaboration Platform — CORS Misconfiguration Leading to Authenticated Data Exposure (CVE-2026-27579)
The realtime-collaboration-platform project configured its Appwrite backend to allow arbitrary cross-origin requests while also enabling Access-Control-Allow-Credentials: true. Because the origin allow-list was effectively unrestricted, an attacker-controlled…
Unverified 2026-07-05 - CVE-2026-41179 web CRITICAL 9.8
rclone RC API Unauthenticated Remote Code Execution (CVE-2026-41179)
rclone's built-in Remote Control (rcd) HTTP API exposes an /operations/fsinfo endpoint that accepts an attacker-controlled fs= connection-string parameter used to instantiate a storage backend. When the string selects the WebDAV backend, rclone recognizes an…
Patched 2026-07-05 - CVE-2026-39324 / GHSA-33qg-7wpp-89cq web CRITICAL
Rack::Session::Cookie Decrypt-Failure Fallback to Unencrypted Cookies (CVE-2026-39324)
Rack::Session::Cookie, when configured with the secrets: option for encrypted session cookies, is supposed to reject any cookie that fails decryption. Instead, when all configured encryptors fail to decrypt a cookie, the code silently falls through to the…
Patched 2026-07-05 - CVE-2026-41462 web CRITICAL 9.8
ProjeQtor Unauthenticated Login SQL Injection (CVE-2026-41462)
ProjeQtor's login.php endpoint concatenates the login POST parameter directly into a SQL query without sanitization, allowing an unauthenticated attacker to inject stacked SQL statements. The included exploit crafts a login value that terminates the original…
Patched 2026-07-05 - CVE-2026-0926 web HIGH
Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
Prodigy Commerce exposes an AJAX action, prodigy-render-my-account-widget, that renders a "My Account" widget template chosen via the parameters[templatename] POST parameter. The plugin fails to sanitize or restrict this parameter to an allow-list of…
Unverified 2026-07-05 - CVE-2026-5366 web HIGH
Prefect GitRepository Git Argument Injection RCE via `commit_sha` — CVE-2026-5366
CVE-2026-5366 is a git argument-injection vulnerability in Prefect's GitRepository storage class (src/prefect/runner/storage.py). The commitsha parameter is stored verbatim with no validation beyond a branch/commitsha mutual-exclusion check, then passed…
Patched 2026-07-05 - CVE-2026-44338 / [GHSA-6rmh-7xcm-cpxj] web HIGH EPSS 29%
PraisonAI API Server Missing Authentication (CVE-2026-44338)
PraisonAI's apiserver.py exposes HTTP endpoints (e.g. /agents, /chat) that trigger execution of configured AI agent workflows, but ships with authentication disabled by default and no token/Authorization-header requirement. Any network-reachable client can…
Patched 2026-07-05 - CVE-2026-40487 / GHSA-44wg-r34q-hvfx web HIGH 8.9
Postiz Arbitrary File Upload to Stored XSS / Account Takeover (CVE-2026-40487)
Postiz accepts file uploads for post media and validates the file type solely from the client-supplied Content-Type header, with no inspection of the actual file bytes. An attacker can upload an SVG (or HTML) file containing embedded JavaScript while…
Patched 2026-07-05 - CVE-2026-25126 web MEDIUM
PolarLearn Forum Vote Count Manipulation (CVE-2026-25126)
CVE-2026-25126 is a business logic flaw in PolarLearn's forum voting API. The POST /api/v1/forum/vote endpoint declares a TypeScript type for the direction field but never validates it at runtime, so the server accepts arbitrary string values instead of only…
Patched 2026-07-05 - CVE-2026-44166 / [GHSA-pq7p-mc74-g65w] web MEDIUM 6.1
PocketBase OAuth2 Account Pre-Hijacking (CVE-2026-44166)
PocketBase's auth-with-oauth2 endpoint accepts a client-supplied createData object when provisioning a new user record during OAuth2 sign-up, but never validates the email field inside it against the email address actually verified by the OAuth2 provider. An…
Patched 2026-07-05 - CVE-2026-4885 web CRITICAL
Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
Piotnet Addons for Elementor Pro (<= 7.1.70) exposes a form-builder file-upload AJAX action (pafeajaxformbuilder) that insufficiently validates uploaded file extensions, allowing unauthenticated attackers to upload PHP files disguised with alternate…
Unverified 2026-07-05 - CVE-2026-42569 web CRITICAL
phpVMS Unauthenticated Legacy Importer Database Wipe (CVE-2026-42569)
phpVMS ships legacy data-import endpoints (/importer, /importer/index, /import, /legacy/importer) that were intended to be restricted but remain reachable without authentication in versions ≤ 7.0.5. These endpoints accept import/action parameters capable of…
Patched 2026-07-05 - CVE-2026-55584 / GHSA-786w-p5pm-cvgh web HIGH 7.5
phpSysInfo IP Allowlist Bypass via X-Forwarded-For Spoofing — CVE-2026-55584
phpSysInfo's PSIALLOWED IP allowlist feature determines the client IP by checking the attacker-controlled X-Forwarded-For header first, then Client-IP, and only falls back to the trustworthy REMOTEADDR socket address last. Because there is no concept of a…
Patched 2026-07-05 - CVE-2026-4350 web HIGH 8.1
Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 is a path traversal vulnerability in the Perfmatters WordPress performance plugin that allows arbitrary file deletion. The plugin's perfmattersdelete AJAX action (reachable via wp-admin/admin-ajax.php) takes a delete parameter and passes it to a…
Unverified 2026-07-05 - CVE-2026-25212 web CRITICAL 9.9
Percona PMM Authenticated RCE via PostgreSQL COPY TO PROGRAM (CVE-2026-25212)
CVE-2026-25212 arises because PMM's internal PostgreSQL user retains SUPERUSER privileges instead of being restricted. An attacker authenticated with only pmm-admin rights can use Grafana's "Add data source" feature to register an arbitrary PostgreSQL data…
Patched 2026-07-05 - CVE-2026-26801 web HIGH
pdfmake Server-Side Request Forgery via Unvalidated Document URLs (CVE-2026-26801)
CVE-2026-26801 is a Server-Side Request Forgery vulnerability in pdfmake, a popular Node.js PDF generation library. When a document definition (docDefinition) references remote resources in fields such as images, attachments, or files, pdfmake's…
Patched 2026-07-05 - CVE-2026-36239 web CRITICAL
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
PbootCMS's decodestring() function in apps/home/controller/ParserController.php sequentially applies stripcslashes() then htmlspecialcharsdecode() to the "Footer Information" (sitecopyright) admin field, which effectively reverses HTML-entity encoding and…
Unverified 2026-07-05 - CVE-2026-29000 web CRITICAL 9.8
pac4j JWT Authentication Bypass via Unsigned Token in JWE Wrapper — CVE-2026-29000
A vulnerable pac4j JWT configuration accepts unsigned JWTs (alg: "none") and, when JWE encryption is used to wrap tokens, decrypts the outer JWE and trusts the inner JWT's claims without independently verifying that the inner token is signed. The PoC builds…
Patched 2026-07-05 - CVE-2026-21876 web CRITICAL EPSS 13%
OWASP CoreRuleSet Multipart Charset WAF Bypass (CVE-2026-21876)
CVE-2026-21876 is a bypass in the OWASP Core Rule Set (CRS) rule 922110, which is meant to block multipart/form-data parts that declare a forbidden (non-ASCII-safe) character set such as IBM037/EBCDIC. The rule only inspects the charset of the last part in a…
Patched 2026-07-05 - CVE-2026-33331 web HIGH
oRPC OpenAPI Reference Plugin Stored XSS via Unescaped Spec Embedding (CVE-2026-33331)
oRPC's OpenAPI reference plugin renders the generated API docs page by embedding the OpenAPI spec directly into an inline <script id="spec" type="application/json"> block using JSON.stringify(spec), with no HTML-context encoding. Because JSON.stringify() does…
Patched 2026-07-05 - CVE-2026-26198 web CRITICAL 9.8
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 is a SQL injection vulnerability in the Ormar async ORM's min() and max() aggregate query methods. While the sibling sum() and avg() methods validate that the supplied "column" parameter refers to an actual numeric field on the model, min() and…
Patched 2026-07-05 - CVE-2026-45777 web CRITICAL
OpenXDMoD `user_interface.php` Report Title Command Injection (CVE-2026-45777)
Open XDMoD's controllers/userinterface.php endpoint accepts a report title parameter as part of a PDF report generation request. The PoC demonstrates that this value is passed unsanitized into a server-side command execution context (used during PDF/report…
Patched 2026-07-05 - CVE-2026-0766 web HIGH 8.8 EPSS 27%
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
OpenWebUI lets users extend LLM functionality by creating "Tools" containing user-submitted Python code. That code is loaded via loadtoolmodulebyid() in backend/openwebui/utils/plugin.py, which calls exec(content, module.dict) on the submitted source with…
Unverified 2026-07-05 - CVE-2026-24418 web HIGH 8.8
OpenSTAManager Scadenzario Bulk Operations Error-Based SQL Injection — CVE-2026-24418
OpenSTAManager's bulk-operations handler for the Scadenzario (payment schedule) module accepts an idrecords[] array via POST at /actions.php?idmodule=18. The arrayclean() helper only strips empty values and never validates that elements are integers, so…
Patched 2026-07-05 - CVE-2026-24415 web MEDIUM
OpenSTAManager Reflected XSS via `righe` Parameter (CVE-2026-24415)
OpenSTAManager fails to sanitize the righe GET parameter before reflecting it into a hidden HTML input's value attribute across six modificaiva.php modal files (contracts, quotes, invoices, DDT, orders, and interventions modules). Because the parameter is…
Patched 2026-07-05 - CVE-2026-24419 web HIGH
OpenSTAManager Prima Nota Error-Based SQL Injection — CVE-2026-24419
The Prima Nota (journal entry) module's add.php reads the iddocumenti GET parameter, splits it on commas with explode(), but never validates that the resulting elements are integers before imploding them back into a SQL IN() clause used to look up…
Patched 2026-07-05 - CVE-2026-24417 web HIGH
OpenSTAManager Global Search Amplified Time-Based Blind SQL Injection — CVE-2026-24417
OpenSTAManager's global search AJAX endpoint (/ajaxsearch.php) dispatches the user-supplied term parameter to more than ten module-specific search handlers (Articoli, Ordini, DDT, Fatture, Preventivi, Anagrafiche, Impianti, and others), each of which…
Patched 2026-07-05 - CVE-2026-24416 web HIGH
OpenSTAManager Article Pricing Time-Based Blind SQL Injection — CVE-2026-24416
OpenSTAManager's article pricing AJAX handler (/ajaxcomplete.php?op=getprezzi) builds a UNION SQL query to pull pricing history from invoices and delivery notes. The developer correctly wrapped the idarticolo parameter in the framework's prepare() sanitizer…
Patched 2026-07-05 - CVE-2026-39842 / GHSA-7mqr-33rv-p3mp web CRITICAL 10
OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
OpenRemote's Rules Engine evaluates user-supplied JavaScript rule expressions using the Java Nashorn scripting engine with no sandboxing, SecurityManager, or ClassFilter restrictions. While the API layer explicitly blocks non-superusers from creating Groovy…
Patched 2026-07-05 - CVE-2026-24849 web CRITICAL 6.5
OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
OpenEMR's Fax/SMS module ships an EtherFax integration whose disposeDoc() handler (in EtherFaxActions.php) takes an attacker-controlled filepath request parameter, checks only that the file exists, and passes it directly to readfile() with no canonicalization…
Patched 2026-07-05 - CVE-2026-22812 web HIGH 8.8 EPSS 17%
OpenCode Unauthenticated Local HTTP Server -> Remote Code Execution (CVE-2026-22812)
OpenCode versions before 1.0.216 automatically start a local HTTP server that accepts session-creation and shell-execution requests without any authentication, and does so with permissive CORS behavior. This means any local process, malicious browser tab, or…
Patched 2026-07-05 - CVE-2026-33439 web CRITICAL 9.8 EPSS 10%
OpenAM Pre-Authentication RCE via `jato.clientSession` Deserialization (CVE-2026-33439)
OpenAM's unauthenticated Password Reset pages accept a jato.clientSession parameter that is passed to Encoder.deserialize() without any class allowlist/filtering, allowing an attacker to submit an arbitrary serialized Java object graph. The PoC builds a…
Patched 2026-07-05 - CVE-2026-45401 web HIGH
Open WebUI SSRF via HTTP Redirect Bypass of validate_url() (CVE-2026-45401)
Open WebUI v0.9.4 validates user-supplied URLs with a validateurl() function before the server fetches them, intended to block requests to internal/private hosts. However, the validation only checks the initial hostname supplied by the client; when the…
Patched 2026-07-05 - CVE-2026-27626 / GHSA-49gm-hh7w-wfvf web CRITICAL 9.9
OliveTin OS Command Injection via Shell Mode Arguments (CVE-2026-27626)
OliveTin lets administrators expose predefined shell commands ("Actions") to end users via a web UI or webhooks, relying on checkShellArgumentSafety() to sanitize user-supplied argument values before they are templated into a command string and passed to sh…
Unverified 2026-07-05 - CVE-2026-41242 web CRITICAL
Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
The demo Express service accepts a JSON protobuf descriptor from an HTTP request body and passes it straight to protobuf.Root.fromJSON(), then looks up and decodes a message type from that attacker-controlled descriptor. Because protobufjs compiles field/type…
Patched 2026-07-05 - CVE-2026-34200 web CRITICAL 9.6
Nhost Local MCP Server Unauthenticated CORS Bypass Leading to Full Project Takeover (CVE-2026-34200)
The Nhost CLI's local MCP server, used to let AI agents/tools manage a developer's Nhost project, has no inbound authentication and inherits a permissive Access-Control-Allow-Origin: CORS policy from the underlying mcp-go library. Because the server does not…
Patched 2026-07-05 - CVE-2026-40701 web MEDIUM 6.3
nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)
nginx's resolver contains a use-after-free that is reachable when a server is configured with sslstapling on;, sslstaplingverify on;, and a resolver directive — the combination that causes nginx to perform DNS resolution of the OCSP responder hostname on the…
Patched 2026-07-05 - CVE-2026-0211 web HIGH
Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
This repository is a university penetration-testing course project that models a hypothetical heap buffer overflow in Nginx's QUIC (HTTP/3) packet parser, where the Destination Connection ID (DCID) length field is not properly bounds-checked before being used…
Unverified 2026-07-05 - CVE-2026-9256 web CRITICAL EPSS 10%
nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
This PoC chains two nginx rewrite-engine bugs that share the same root cause — a two-pass mismatch in how isargs/$args length is computed — into a single ASLR-independent remote system() call on a stock, unmodified nginx:1.30.0 Docker image, with no hardcoded…
Unverified 2026-07-05 - CVE-2026-42926 web HIGH
NGINX HTTP/2 Frame Injection via Vulnerable Upstream Proxying (CVE-2026-42926)
CVE-2026-42926 is an HTTP/2 frame injection issue in NGINX that occurs when a specific vulnerable proxy configuration is used — proxying to an upstream over HTTP/2 (proxyhttpversion 2) while forwarding a client-controlled request body via a variable…
Patched 2026-07-05 - CVE-2026-53519 web INFO
Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
The Nezha Dashboard improperly normalizes its routing paths, allowing a crafted request such as /dashboard../data/config.yaml to escape the intended static-file root and read arbitrary files served by the dashboard process. The PoC uses this path traversal…
Patched 2026-07-05 - CVE-2026-3228 web MEDIUM 6.4
NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
The NextScripts Social Networks Auto-Poster plugin for WordPress fails to sanitize or escape the snapFB post-meta value that backs its [nxsfbembed] shortcode. A user with Contributor-level access (or higher) can store arbitrary JavaScript in this field when…
Unverified 2026-07-05 - CVE-2026-45156 web HIGH 8.1
Nextcloud user_oidc ID4me JWT Signature Bypass (CVE-2026-45156)
Nextcloud's useroidc app processes JWT idtoken values received from ID4me identity providers by splitting the token on . and calling base64decode() on the header and payload segments — but never validates the cryptographic signature (Id4meController.php lines…
Patched 2026-07-05 - CVE-2026-33671 web HIGH
Next.js Vendored picomatch Vulnerable Dependency — CVE-2026-33671
Next.js 16.2.4 vendors a copy of the picomatch glob-matching library inside its own compiled output at nodemodules/next/dist/compiled/picomatch/, pinned to version 4.0.3, which is affected by CVE-2026-33671. Because the vendored copy has its package.json…
Patched 2026-07-05 - CVE-2026-21858, CVE-2025-68613 web CRITICAL 10 EPSS 73%
n8n Unauthenticated Arbitrary File Read to RCE Full Chain — CVE-2026-21858 + CVE-2025-68613
This PoC chains two n8n vulnerabilities into full unauthenticated remote code execution. First, CVE-2026-21858 is a Content-Type confusion bug in n8n's binary file handling: sending Content-Type: application/json instead of multipart/form-data to a form…
Patched 2026-07-05 - CVE-2026-44789 / GHSA-c8xv-5998-g76h web CRITICAL 9.4
n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)
The n8n HTTP Request node's pagination feature (updateAParameterInEachRequest mode) allows an attacker-controlled parameter.type value of proto, causing paginationData.request[parameter.type][parameterName] = parameterValue to write directly onto…
Patched 2026-07-05 - CVE-2026-3304 web HIGH 8.7
Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304
Multer versions before 2.1.0 can leave temporary uploaded files permanently on disk when a multipart request is malformed in a specific way while using an asynchronous fileFilter callback (e.g., one deferred via setImmediate). When a valid file part is…
Patched 2026-07-05 - CVE-2026-0596 web CRITICAL 9.6
MLflow / MLServer Insecure Pickle Deserialization RCE — CVE-2026-0596
MLflow can serve models through Seldon's MLServer runtime, which loads model artifacts using Python's native pickle format. While the REST API's string parameters are handled safely and are not vulnerable to classic OS command injection, the underlying…
Unverified 2026-07-05 - CVE-2026-27483 web CRITICAL EPSS 11%
MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)
MindsDB exposes a /api/handlers/ endpoint that lists available integration handlers, some of which are registered but not actually installed. By selecting one of these available-but-uninstalled handler names, an attacker can abuse a path traversal flaw in the…
Patched 2026-07-05 - CVE-2026-34220 web HIGH
MikroORM Custom Type Raw SQL Injection (CVE-2026-34220)
CVE-2026-34220 is a SQL injection vulnerability in MikroORM's handling of Custom Type columns. When a client-supplied JSON value contains a raw property, MikroORM's internal isRaw() check treats it as a trusted, framework-generated Raw SQL expression rather…
Patched 2026-07-05 - CVE-2026-1306 web CRITICAL 9.8
midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
The midi-Synth plugin's export AJAX action insufficiently validates the file type/extension of uploaded MIDI conversion payloads (CWE-434). The handler writes the attacker-supplied, Base64-encoded file content into the plugin's…
Unverified 2026-07-05 - CVE-2026-45504 web HIGH
Microsoft Exchange Authenticated Arbitrary File Read via EWS Reference Attachment (CVE-2026-45504)
CVE-2026-45504 is an authenticated arbitrary file read vulnerability in Microsoft Exchange Server. An attacker with valid mailbox credentials authenticates to OWA and, via the Exchange Web Services (EWS) CreateItem/CreateAttachment SOAP calls, creates a…
Patched 2026-07-05 - CVE-2026-49345 web CRITICAL
Mercator Configuration SSRF Chained to Internal Redis RCE (CVE-2026-49345)
This repository contains two Python PoCs that abuse an unvalidated provider URL parameter in Mercator's ConfigurationController::testProvider endpoint, which the server fetches with libcurl. ssrf2scan.py uses the telnet:// scheme to turn the SSRF into a blind…
Unverified 2026-07-05 - CVE-2026-23744 web CRITICAL EPSS 45%
MCPJam Inspector Unauthenticated Command Injection RCE (CVE-2026-23744)
This repository is a German-language Hack The Box "DevHub" walkthrough that documents a full attack chain, one step of which is a genuine, directly reusable RCE against MCPJam Inspector v1.4.2 (CVE-2026-23744). The vulnerable /api/mcp/connect endpoint accepts…
Patched 2026-07-05 - CVE-2026-23520 web CRITICAL
MCPJam Inspector / Arcane MCP Connect Command Injection RCE via Host-Header Vhost Routing (CVE-2026-23520)
The Model Context Protocol (MCP) connect endpoint /api/mcp/connect accepts a JSON body describing a new server connection, including a command and args array that get executed on the host without sanitization. In many deployments the vulnerable component sits…
Patched 2026-07-05 - CVE-2026-27825 web CRITICAL 9.3
mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)
The confluenceuploadattachment MCP tool in mcp-atlassian passes its filepath argument straight into open(filepath, "rb") with no path validation, letting an attacker read arbitrary files on the server's filesystem and exfiltrate them via a multipart upload to…
Patched 2026-07-05 - CVE-2026-40897 web CRITICAL
Math.js Expression Parser Sandbox Bypass RCE (CVE-2026-40897)
Math.js exposes an expression-evaluation API (math.evaluate) intended to run untrusted mathematical expressions inside a restricted sandbox that blocks access to dangerous properties such as constructor. The isSafeProperty guard only inspects direct property…
Patched 2026-07-05 - CVE-2026-4484 web HIGH 8.8
Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
The Masteriyo LMS WordPress plugin's InstructorsController::prepareobjectfordatabase REST API handler fails to verify that the requesting user holds the editusers/promoteusers capability before persisting an arbitrary roles value submitted in the request…
Unverified 2026-07-05 - CVE-2026-30849 web HIGH
MantisBT SOAP `mc_issue_add` Authentication Bypass (Type Juggling) — CVE-2026-30849
MantisBT's legacy SOAP API is affected by a PHP loose-comparison ("type juggling") flaw in password verification reachable via the mcissueadd SOAP operation, allowing an attacker to authenticate without knowing a valid password by supplying a specially…
Patched 2026-07-05 - CVE-2026-42281 web CRITICAL 9.2
MagicMirror² Unauthenticated SSRF via `/cors` Endpoint (CVE-2026-42281)
MagicMirror²'s /cors endpoint is designed to proxy cross-origin requests on behalf of the browser, but it performs no validation or allowlisting of the target URL and forwards attacker-controlled headers in both directions. This turns the endpoint into a…
Patched 2026-07-05 - CVE-2026-49468 web CRITICAL 9.8
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
exploit.py demonstrates a pre-authentication bypass in the LiteLLM proxy caused by a single crafted Host header (Host: evil/?). LiteLLM's getrequestroute() derives the route used for auth decisions from request.url.path, which Starlette reconstructs from the…
Patched 2026-07-05 - CVE-2026-47102 web HIGH 8.8
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
LiteLLM's /user/update endpoint is meant to let a user update their own account attributes (name, email, metadata). The authorization check canusercalluserupdate() only verifies which user record the caller may modify (their own, or any if they are already…
Patched 2026-07-05 - CVE-2026-40217 web CRITICAL 8.8
LiteLLM Guardrail Custom-Code Sandbox Escape to Root RCE (CVE-2026-40217)
LiteLLM's guardrail-testing endpoint lets authenticated users submit custom Python code that is checked with a regex-based source-code filter meant to block dangerous identifiers such as globals, builtins, and import. Because the filter only inspects source…
Patched 2026-07-05 - CVE-2026-35030 web CRITICAL 9.1
LiteLLM Authentication Bypass via OIDC Userinfo Cache Key Collision (CVE-2026-35030)
LiteLLM's OIDC userinfo cache uses only the first 20 characters of the presented JWT (token[:20]) as its cache key. Two different, validly-signed JWTs can be crafted to share identical first-20-character prefixes, allowing an unauthenticated attacker to forge…
Patched 2026-07-05 - CVE-2026-35029 web HIGH 8.8 EPSS 26%
LiteLLM /config/update Broken Access Control (CVE-2026-35029)
LiteLLM's /config/update endpoint does not check the caller's role — any authenticated user holding a valid API key, not just a proxyadmin, can modify the proxy's runtime configuration. This allows registering a malicious pass-through endpoint that can be…
Patched 2026-07-05 - CVE-2026-30368 web HIGH
Lightspeed Classroom Management Weak Authentication / Device Takeover — CVE-2026-30368
Lightspeed Classroom Management is a Chrome extension used by schools to monitor and remotely control student Chromebooks. The extension's service worker (running classroom.wasm) generates a JWT used to obtain a token for Lightspeed's Ably real-time channel,…
Unverified 2026-07-05 - CVE-2026-49083 web HIGH 8.8
LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
This PoC exploits insufficient role validation in LatePoint's customer-to-WordPress-user linking logic. An authenticated attacker holding only a low-privileged "Contributor" WordPress account can create a LatePoint customer record using the email address of…
Unverified 2026-07-05 - CVE-2026-6741 web HIGH 8.8
LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
LatePoint 5.3.0+ registers a WordPress Abilities API ability, latepoint/connect-customer-to-wp-user, that links a LatePoint customer record to an arbitrary WordPress user ID. The ability's permission check only verifies that the calling user holds the…
Patched 2026-07-05 - CVE-2026-0770 web CRITICAL KEV EPSS 56%
Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770)
Langflow exposes an API endpoint (/api/v1/validate/code) that is meant to validate user-submitted Python "component" code before it runs inside a workflow. The endpoint evaluates the submitted code using exec() with an execglobals context that is not…
Patched 2026-07-05 - CVE-2026-27966 web CRITICAL 9.8 EPSS 34%
Langflow Remote Code Execution — CVE-2026-27966
Langflow is a low-code platform for building LLM/agent pipelines ("flows") that can include arbitrary code-execution components. This tool detects exposed Langflow instances, and where no existing flow exists, automatically creates one containing a…
Patched 2026-07-05 - CVE-2026-42048 web HIGH
Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
Langflow's DELETE /api/v1/knowledgebases bulk-delete endpoint accepts a list of kbnames values and builds a filesystem path for each by joining it onto the current user's Knowledge Base directory, without normalizing or validating that the resulting path…
Patched 2026-07-05 - CVE-2026-33017 web CRITICAL KEV EPSS 100%
Langflow Custom Component Remote Code Execution — CVE-2026-33017
Langflow exposes a REST API endpoint that builds and runs a "flow" — a graph of nodes describing a data/LLM pipeline. One of the supported node types is a generic custom component whose code field is arbitrary Python that Langflow imports and executes…
Patched 2026-07-05 - CVE-2026-0920 web CRITICAL 9.8
LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
LA-Studio Element Kit for Elementor registers an unauthenticated AJAX action (wpajaxnoprivlakitajax) that handles front-end user registration requests. The handler builds a wpinsertuser() call directly from attacker-supplied POST data, including a lakitbkrole…
Unverified 2026-07-05 - CVE-2026-38526 web CRITICAL
Krayin CRM — TinyMCE Upload Unrestricted File Upload to RCE (CVE-2026-38526)
Krayin CRM's TinyMCE rich-text editor upload endpoint (/admin/tinymce/upload) fails to properly restrict uploaded file types, allowing an authenticated user to bypass the upload filter using a double-extension technique and upload a PHP webshell. Once…
Unverified 2026-07-05 - CVE-2026-5426 web CRITICAL
KnowledgeDeliver ASP.NET ViewState Deserialization RCE via Hardcoded Machine Keys — CVE-2026-5426
CVE-2026-5426 stems from KnowledgeDeliver shipping with hardcoded, publicly known decryptionKey/validationKey values in its web.config <machineKey> element. Because ASP.NET Web Forms uses these keys to encrypt and HMAC-sign the VIEWSTATE field, anyone who…
Unverified 2026-07-05 - CVE-2026-8206 web CRITICAL 9.8
Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
The Kirki plugin's CompLibFormHandler REST API endpoint, used by a Kirki-rendered "forgot password" form, does not properly bind the password-reset request to the account that initiated it. This allows an unauthenticated attacker to redirect the…
Unverified 2026-07-05 - CVE-2026-1529 web CRITICAL
Keycloak Unauthorized Organization Registration via Invitation Token Flaw — CVE-2026-1529
Keycloak's organization invitation flow accepts a JWT invitation token to scope a new user's registration to a specific organization, but the server does not properly validate that the token's claims (notably the organization ID) have not been tampered with…
Unverified 2026-07-05 - CVE-2026-25924 / GHSA-grch-p7vf-vc4f web HIGH 8.4
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
Kanboard defines a PLUGININSTALLER security constant (default disabled) that is meant to prevent installing plugins from remote URLs. The UI correctly hides the plugin-install controls when this constant is off, using Installer::isConfigured() checks in…
Patched 2026-07-05 - CVE-2026-32255 web HIGH 8.6 EPSS 10%
Kan SSRF via Attachment Download Endpoint — CVE-2026-32255
Kan's attachment download proxy endpoint, GET /api/download/attatchment, is intended to stream S3-hosted attachments to clients but instead takes a fully attacker-controlled url query parameter and passes it directly to fetch() on the server with no…
Patched 2026-07-05 - CVE-2026-40864 web MEDIUM
JupyterHub Cross-Origin Form POST XSRF Bypass (CVE-2026-40864)
JupyterHub's XSRF protection, reworked in 4.1.0, uses the browser-supplied Sec-Fetch-Mode header as an origin oracle to decide whether a request is same-origin and therefore exempt from token validation. The implementation incorrectly treats Sec-Fetch-Mode:…
Patched 2026-07-05 - CVE-2026-56290 web CRITICAL 9.8 KEV EPSS 83%
Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290
The Joomla extension Page Builder CK exposes a controller method, browse.ajaxAddPicture, that accepts file uploads with a user-controlled destination path parameter (path) that is only passed through trim() — no whitelist, extension check, or…
Patched 2026-07-05 - CVE-2026-21627 web CRITICAL 9.5
Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627
The ajaxTaskInclude() method of the nrframework Joomla plugin is explicitly whitelisted for unauthenticated frontend AJAX access and accepts attacker-controlled path, file, and class parameters. The path parameter uses Joomla's RAW input filter (no…
Patched 2026-07-05 - CVE-2026-49048 web CRITICAL 8.7
JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)
JoomCCK's custom MVC dispatcher (MControllerBase::execute()) invokes controller tasks without any CSRF token check or ACL/authorization check — its authorise() method is a no-op that always returns true. This makes the tags.save task, whose model method…
Unpatched 2026-07-05 - CVE-2026-25526 web CRITICAL
Jinjava Server-Side Template Injection to RCE via Jackson ObjectMapper (CVE-2026-25526)
CVE-2026-25526 is a sandbox-escape vulnerability in Jinjava, the Java template engine used by many JVM web applications for user-influenced templating. The PoC shows that Jinjava's rendering context exposes an internal interpreter object (int3rpr3t3r) whose…
Patched 2026-07-05 - CVE-2026-49079 web HIGH 7.5
JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
JetSearch's AJAX handlers (invoked via WordPress's admin-ajax.php) fail to properly escape/parameterize user-supplied search parameters, allowing an unauthenticated attacker to perform SQL injection against the underlying WordPress database. The PoC…
Unverified 2026-07-05 - CVE-2026-53435 web HIGH 9.1 EPSS 19%
Jenkins ClassFilter Deserialization Bypass → Arbitrary File Read — CVE-2026-53435
Jenkins restricts deserialization via a custom ClassFilter that only allows types defined in Jenkins core or installed plugins. CVE-2026-53435 shows this whitelist is insufficient: an attacker who can POST a view's config.xml can get Jenkins to deserialize a…
Patched 2026-07-05 - CVE-2026-8196 web HIGH
JeecgBoot mLogin Endpoint CAPTCHA Bypass Enabling Credential Brute Force (CVE-2026-8196)
JeecgBoot exposes a secondary login endpoint, /sys/mLogin, that accepts the same username/password credentials as the standard /sys/login endpoint but — unlike /sys/login — does not enforce a CAPTCHA challenge and applies no rate limiting or account lockout.…
Unverified 2026-07-05 - CVE-2026-54597 web HIGH
ITFlow Time-Based Blind SQL Injection via agent/ajax.php expires Parameter (CVE-2026-54597)
ITFlow's agent/ajax.php endpoint accepts an expires parameter that is used unsanitized in a SQL query, enabling a time-based blind SQL injection. An authenticated user can extract arbitrary database values (admin password hash, SMTP credentials, DB version)…
Unverified 2026-07-05 - CVE-2026-54596 web HIGH
ITFlow SQL Injection via recurring_invoice_frequency (CVE-2026-54596)
ITFlow's recurring-invoice handling accepts an unsanitized recurringinvoicefrequency parameter that is placed directly into a SQL query. An authenticated technician-level user with access to an invoice can inject arbitrary SQL, extracting sensitive data…
Unverified 2026-07-05 - CVE-2026-23491 web CRITICAL
InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
InvoicePlane v1.6.3's Guest module exposes a getfile controller action that serves uploaded customer files. The action urldecode()s the requested filename and concatenates it directly onto a fixed base directory (uploads/customerfiles/) before passing the…
Patched 2026-07-05 - CVE-2026-49104 web HIGH 8.1
Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
This PoC targets the "Integration for Keap/Infusionsoft" WordPress plugin, whose cf7-infusionsoft.php file calls maybeunserialize() on user-supplied form field values without validation. An unauthenticated attacker can submit a crafted PHP serialized object…
Unverified 2026-07-05 - CVE-2026-9691 web HIGH 8.1
Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
The plugin's cf7-active-campaign.php component calls PHP's maybeunserialize() on user-supplied form field values without validation before forwarding them to ActiveCampaign. An unauthenticated attacker can submit a crafted, serialized PHP object as a form…
Unpatched 2026-07-05 - CVE-2026-35455 web HIGH
Immich Stored XSS to API Key Exfiltration and Account Hijacking (CVE-2026-35455)
A stored XSS vulnerability in Immich allows an attacker to inject a malicious script (via a photo/asset field) that executes in a victim's authenticated session. The included demo automates generation of a new API key from within the hijacked session and…
Patched 2026-07-05 - CVE-2026-0911 web HIGH
Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
The Hustle WordPress plugin's module-import feature (actionimportmodule()) calls WordPress's core wphandleupload() with testtype => false, which disables strict file-type validation during upload. If the subsequently-imported module JSON fails validation, the…
Unverified 2026-07-05 - CVE-2026-10580 web CRITICAL 9.8
Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
The Hippoo Mobile App for WooCommerce plugin registers a REST API endpoint (wc-hippoo/v1/ext/wp/v2/users/<id>) that proxies to WordPress's user-management REST routes but fails to properly enforce the underlying capability checks, conflating its own…
Unverified 2026-07-05 - CVE-2026-46395 web CRITICAL 9.8
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
The hmacBase64() function in HAXcms's Node.js backend contains two cryptographic flaws: it signs data with the hard-coded literal key "0" instead of the real signing key, and then appends the real key (privateKey + salt) in plaintext onto the returned token.…
Patched 2026-07-05 - CVE-2026-46394 web HIGH 7.2
HAXcms Git.php OS Command Injection (CVE-2026-46394)
HAXcms's Git.php library builds shell command strings by concatenating unsanitized parameters and executes them via procopen(). Of the 17 functions that shell out, only commit() escapes its input with escapeshellarg() — the remaining 15, including…
Patched 2026-07-05 - CVE-2026-33937 web CRITICAL
Handlebars AST Injection Remote Code Execution — CVE-2026-33937
Handlebars' Handlebars.compile() accepts either a plain template string or a pre-parsed AST object; when given an AST object directly, the normal template-parsing phase (which would otherwise escape/validate literal values) is skipped entirely. Inside the…
Patched 2026-07-05 - CVE-2026-25512 web CRITICAL 9.4 EPSS 19%
Group-Office TNEF Attachment Handler OS Command Injection (CVE-2026-25512)
CVE-2026-25512 is an OS command injection in Group-Office's TNEF (winmail.dat) attachment handler. The email/message/tnefAttachmentFromTempFile endpoint takes a user-controlled tmpfile parameter and concatenates it, unescaped, directly into a shell exec()…
Patched 2026-07-05 - CVE-2026-34838 web CRITICAL
Group-Office PHP Deserialization Remote Code Execution (CVE-2026-34838)
CVE-2026-34838 is a PHP object deserialization vulnerability in Group-Office. The AbstractSettingsCollection::loadData() method calls unserialize() on a stored setting value prefixed with serialized:, without validating the object type. By storing a crafted…
Patched 2026-07-05 - CVE-2026-4406 web MEDIUM 6.1
Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
The Gravity Forms WordPress plugin (<= 2.9.28) reflects the formids array values from the args parameter of the gformgetconfig AJAX action verbatim into its HTTP response, which is served with Content-Type: text/html; charset=UTF-8. Because the value is…
Patched 2026-07-05 - CVE-2026-48866 web CRITICAL 9.6
Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
Gravity Forms stores the URL of uploaded files in a form entry via the gformuploadedfiles parameter without stripping ../ sequences (escurlraw() and isvalidurl() both accept path-traversal payloads). When an entry containing such a URL is later deleted —…
Patched 2026-07-05 - CVE-2026-32247 web HIGH 8.1
graphiti-core Cypher Injection via Unsanitized node_labels — CVE-2026-32247
graphiti-core builds Cypher WHERE clauses for its searchnodes functionality by joining caller-supplied node label strings with | and concatenating the result directly into a raw query string, with no parameterization or input validation anywhere in the call…
Patched 2026-07-05 - CVE-2026-21721 web HIGH
Grafana Dashboard Permissions Broken Access Control — Editor-to-Admin Privilege Escalation (CVE-2026-21721)
This PoC demonstrates a broken-access-control flaw in Grafana's per-dashboard permissions API: an authenticated user holding only the Editor role can read and rewrite the ACL (/api/dashboards/uid/{uid}/permissions) for dashboards they do not own, and use it…
Patched 2026-07-05 - CVE-2026-42589 web CRITICAL 9.8
Gotenberg 8.29.1 Unauthenticated ExifTool Metadata Key Injection RCE (CVE-2026-42589)
CVE-2026-42589 is an unauthenticated remote code execution vulnerability in Gotenberg 8.29.1's metadata-writing endpoint. Gotenberg forwards user-supplied metadata JSON keys to ExifTool without rejecting control characters; a metadata key containing…
Patched 2026-07-05 - CVE-2026-24135 web HIGH 7.5
Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
Gogs, a self-hosted Git service written in Go, contains a path traversal flaw in the updateWikiPage function used when editing wiki pages. The function sanitizes the new page title before writing the updated file but never sanitizes the previous ("old") title…
Patched 2026-07-05 - CVE-2026-52813 web INFO
Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
Gogs fails to properly sanitize the organization name supplied at organization-creation time, allowing an authenticated attacker to embed path-traversal sequences (../../...) in the name so that it resolves outside the intended organization directory and into…
Patched 2026-07-05 - CVE-2026-5173 web HIGH
GitLab WebSocket GraphqlChannel Unauthorized Method Enumeration — CVE-2026-5173
CVE-2026-5173 allows a low-privileged authenticated GitLab user to invoke backend GraphQL methods over the /-/cable ActionCable WebSocket endpoint via the GraphqlChannel, methods that should otherwise be gated by normal GraphQL authorization checks. The PoC…
Patched 2026-07-05 - CVE-2026-28699 web HIGH
Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
Gitea lets an OAuth2 application obtain an access token restricted to a subset of a user's permissions (e.g. read:user only), and enforces that restriction through a tokenRequiresScopes middleware. The middleware relies on an ApiTokenScope value that is…
Patched 2026-07-05 - CVE-2026-27771 web CRITICAL EPSS 43%
Gitea Container Registry Anonymous Auth Bypass (CVE-2026-27771)
Gitea's OCI Distribution Spec API (/v2/<name>/manifests/<ref>, /v2/<name>/blobs/<digest>) serves container image content to anonymous/ghost users without ever checking the package owner's configured visibility (private, limited, or public). The…
Patched 2026-07-05 - CVE-2026-29053 web HIGH
Ghost CMS Theme JSONPath Remote Code Execution — CVE-2026-29053
Ghost CMS uses the jsonpath package, which internally relies on static-eval to interpret JSONPath filter expressions embedded in Handlebars theme templates. static-eval is explicitly documented upstream as unsafe for untrusted input, yet Ghost passes…
Patched 2026-07-05 - CVE-2026-26980 web CRITICAL EPSS 69%
Ghost CMS Content API — Unauthenticated Blind SQL Injection (CVE-2026-26980)
Ghost CMS's Content API filter parser (slug-filter-order.js) builds a raw SQL ORDER BY ... CASE WHEN slug IN (...) clause by directly interpolating user-supplied slug values from the filter=slug:[...] query parameter instead of using parameterized query…
Patched 2026-07-05 - CVE-2026-25895 web CRITICAL 9.8
FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)
FUXA's POST /api/upload endpoint (server/api/projects/index.js:193) is registered without the middleware chain applied to every other project-management route, so it bypasses both the JWT/API-key check and the admin permission gate — even when the…
Patched 2026-07-05 - CVE-2026-1208 web MEDIUM 4.3
Friendly Functions for Welcart WordPress Plugin CSRF (CVE-2026-1208)
The Friendly Functions for Welcart plugin's settings page fails to validate a nonce or verify request origin when processing settings updates, exposing a classic CSRF flaw. An unauthenticated attacker can craft an auto-submitting HTML form targeting the…
Patched 2026-07-05 - CVE-2026-28289 web CRITICAL 10 EPSS 31%
FreeScout Zero-Click RCE via Email Attachment Filename Sanitization Bypass ("Mail2Shell") — CVE-2026-28289
FreeScout automatically saves incoming email attachments to a predictable, web-accessible storage path, and attempts to block dangerous filenames such as .htaccess. This PoC bypasses that filter by prepending a zero-width Unicode character to the .htaccess…
Patched 2026-07-05 - CVE-2026-46376 web CRITICAL 9.1
FreePBX Unauthenticated UCP Access via Hard-Coded Credentials (CVE-2026-46376)
FreePBX's optional UCP generic template setup feature (available since 2021) creates a system user named FreePBXUCPTemplateCreator with a hard-coded, static password (1a2b3c@fd48jshs03123ld) embedded in Userman.class.php. If an administrator runs this setup…
Patched 2026-07-05 - CVE-2026-53647 web MEDIUM 6.9
FOSSBilling Unauthenticated API Key Config Disclosure & Password Reset Token Reuse — CVE-2026-53647
CVE-2026-53647 is an unauthenticated information disclosure vulnerability in FOSSBilling's guest API. The endpoint /api/guest/serviceapikey/getinfo returns the full service configuration — including custom fields, API credentials, internal hostnames, and…
Patched 2026-07-05 - CVE-2026-44277 web CRITICAL
FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277 is described by the vendor/advisory as an unauthenticated remote code execution vulnerability in Fortinet FortiAuthenticator, caused by improper access control on specific API endpoints. The included script is a reconnaissance/detection tool…
Patched 2026-07-05 - CVE-2026-5229 web CRITICAL 9.8
Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
The Form Notify WordPress plugin's LINE Login OAuth callback resolves the local WordPress account to log into purely by matching an email address, without ever verifying that the connecting LINE account was previously linked to that WordPress user. In…
Patched 2026-07-05 - CVE-2026-30824 web CRITICAL 9.8 EPSS 36%
Flowise NVIDIA NIM Endpoint Authentication Bypass — CVE-2026-30824
Flowise's global authentication middleware whitelists the /api/v1/nvidia-nim/ path, exposing NVIDIA NIM container management and API token generation endpoints to unauthenticated remote access (CWE-306: Missing Authentication for Critical Function). An…
Patched 2026-07-05 - CVE-2026-54337 web INFO
Fireshare Unauthenticated Arbitrary File Write/Overwrite — CVE-2026-54337
Fireshare's public upload endpoint (/api/upload/public) accepts multipart form fields (file, filename, folder) that are passed largely unsanitized into a downstream ffmpeg invocation used to process the uploaded video. By embedding extra ffmpeg-style…
Unverified 2026-07-05 - CVE-2026-3296 web CRITICAL 9.8
Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
Everest Forms saves submitted form field values into the wpevfentrymeta table using maybeserialize(), and its sanitization routine (sanitizetextfield()) strips HTML/null bytes but does not strip PHP serialization control characters, so an attacker can submit…
Patched 2026-07-05 - CVE-2026-3300 web CRITICAL EPSS 41%
Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300)
Everest Forms Pro's Calculation Addon evaluates form field expressions server-side without properly sandboxing attacker-controlled input, allowing an unauthenticated visitor to break out of the expression context and inject arbitrary PHP that gets executed by…
Unverified 2026-07-05 - CVE-2026-1657 web MEDIUM
EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
The EventPrime WordPress plugin registers an AJAX action epuploadfilemedia with nopriv support, meaning any unauthenticated visitor can reach it. The handler uploadfilemedia() in includes/class-ep-ajax.php neither checks a user capability (currentusercan())…
Patched 2026-07-05 - CVE-2026-40776 / Patchstack PSID 85de025d71e7 web HIGH 7.5
Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
The Eventin WordPress plugin (10,000+ active installs) exposes a public REST endpoint, /wp-json/eventin/v1/nonce, that hands a valid wprest nonce to any unauthenticated visitor. Three separate REST controllers then treat possession of that nonce as sufficient…
Patched 2026-07-05 - CVE-2026-33656 web CRITICAL
EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
EspoCRM's Formula scripting engine (Formula/action/run) can be abused by an admin-authenticated user to bypass access controls and directly rewrite the sourceId field of an Attachment record, redirecting where uploaded chunk data is written on disk via path…
Patched 2026-07-05 - CVE-2026-33657 web MEDIUM
EspoCRM 9.3.3 Stored HTML Injection in Email Notifications — CVE-2026-33657
EspoCRM 9.3.3 renders stream-post notification emails by converting a Note's Markdown body to HTML and inserting the result into the email template using an unescaped triple-brace placeholder ({{{post}}}), which skips HTML entity escaping normally applied by…
Patched 2026-07-05 - CVE-2026-33534 web MEDIUM
EspoCRM 9.3.3 Authenticated SSRF via Alternative IPv4 Loopback Notation — CVE-2026-33534
EspoCRM 9.3.3 blocks direct requests to http://127.0.0.1/... in its /api/v1/Attachment/fromImageUrl endpoint, but the underlying fetch logic does not normalize alternative IPv4 representations of the loopback address (octal, hex, decimal-dword, and…
Patched 2026-07-05 - CVE-2026-2600 web MEDIUM 6.4
ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 is a stored cross-site scripting vulnerability in the ElementsKit Elementor Addons plugin's Simple Tab widget. The widget renders tab titles (ekittabtitle) with echo and no output escaping in widgets/tab/tab.php. While Elementor's page-builder…
Patched 2026-07-05 - CVE-2026-22243 web CRITICAL
EGroupware Nextmatch Filter Authenticated SQL Injection (CVE-2026-22243)
CVE-2026-22243 is a critical authenticated SQL injection in EGroupware's Nextmatch widget filter processing (used across modules such as InfoLog and Address Book). The application's database layer (Api\Db, Api\Storage\Base, infologso) treats array keys of the…
Patched 2026-07-05 - CVE-2026-26897 web MEDIUM 6.3
EcoOnline EHS Android App — Deep Link Validation Bypass to WebView Open Redirect (CVE-2026-26897)
EcoOnline EHS for Android is a WebView wrapper app that loads its content from a trusted domain and enforces a host allow-list (isInternalHost) whenever it restores or navigates URLs. The app also registers an exported, scheme-only custom URL handler…
Patched 2026-07-05 - CVE-2026-9018 web HIGH 8.8
Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
The easyelhandleregister() function, exposed via the unauthenticated wpajaxnopriveelregister AJAX action, passes attacker-controlled custommeta POST array values directly into updateusermeta() without any key whitelist. Because WordPress stores a user's…
Patched 2026-07-05 - CVE-2026-34036 web MEDIUM
Dolibarr selectobject.php Authenticated Local File Inclusion (CVE-2026-34036)
Dolibarr's core/ajax/selectobject.php endpoint, used to power object-picker autocomplete widgets in the UI, accepts an objectdesc parameter that is used to build a path to a local file. An authenticated user can craft an objectdesc value (in the form…
Patched 2026-07-05 - CVE-2026-23500 / GHSA-w5j3-8fcr-h87w web CRITICAL
Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)
Dolibarr's ODT-to-PDF document conversion feature builds a shell command by concatenating the admin-configurable MAINODTASPDF global setting with a sanitized filename before passing it to PHP's exec(). While the filename argument is escaped with…
Patched 2026-07-05 - CVE-2026-33033 web MEDIUM
Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033
Django's multipart form parser has a special path for file parts declared with Content-Transfer-Encoding: base64. When the stripped chunk length isn't a multiple of 4, the parser calls fieldstream.read(1) in a loop to pull additional bytes for alignment. If…
Patched 2026-07-05 - CVE-2026-1207 web HIGH EPSS 13%
Django GIS RasterField SQL Injection (CVE-2026-1207)
The reproduction project demonstrates a SQL injection flaw in GeoDjango's raster query handling. When a view builds a RasterField lookup such as rastcontains=(rast, band), the band value taken directly from an HTTP query parameter is concatenated into the…
Patched 2026-07-05 - CVE-2026-5118 web CRITICAL 9.8
Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
Divi Form Builder <= 5.1.2's createuser() logic (in FormSubmissionHandler.php) reads a role value directly from submitted form POST data and only checks that the role exists in WordPress (e.g. administrator is a valid role name) rather than checking that it…
Unverified 2026-07-05 - CVE-2026-38934 web HIGH 8.8
diskover-community — CSRF Leading to Authentication Bypass (CVE-2026-38934)
public/settingsprocess.php in diskover-community (<= 2.3.5) accepts sensitive configuration-changing POST requests without validating any CSRF token. An attacker can craft a self-submitting HTML form that, when opened by an authenticated administrator,…
Unverified 2026-07-05 - CVE-2026-49952 web CRITICAL
Discuz! X5.0 Race Condition + CAPTCHA-Solving Pre-Auth to RCE Chain (CVE-2026-49952)
This is a multi-stage, pre-auth-to-RCE exploit chain against Discuz! X5.0 that combines several bugs: an authcode-based DB export/import feature is abused to leak the admin's username and MD5 password hash from a database backup; the exploit then registers a…
Unverified 2026-07-05 - CVE-2026-44262 / [GHSA-4rm2-28vj-fj39] web CRITICAL
dedoc/scramble Laravel API-Doc Generator Unauthenticated eval() RCE (CVE-2026-44262)
dedoc/scramble generates OpenAPI documentation for Laravel APIs by statically analyzing controller code, including validation rules. Its NodeRulesEvaluator::doEvaluateExpression() routine calls PHP's extract($variables) immediately before eval("return…
Patched 2026-07-05 - CVE-2026-47668 web CRITICAL 3.1
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
DbGate's dbgate-serve component exposes a JSON "script runner" (POST /runners/start) that dynamically builds and executes JavaScript in a Node.js child process based on user-supplied fields. Two of these fields, functionName and variableName, are embedded…
Patched 2026-07-05 - CVE-2026-48017 / GHSA-hv83-ggc4-v385 web HIGH 8.8
DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
DbGate's POST /runners/load-reader endpoint takes a functionName parameter and concatenates it directly into a JavaScript template string that is later executed in a forked runner process, without sanitization or validation. An authenticated attacker can…
Patched 2026-07-05 - CVE-2026-41490 web HIGH
Dagster Database I/O Manager SQL Injection via Dynamic Partition Keys (CVE-2026-41490)
All five Dagster database I/O-manager packages share a copy-pasted helper, staticwhereclause, that builds SQL WHERE/DELETE clauses by f-string-interpolating partition key values with no escaping. For statically defined partitions this is safe because the…
Patched 2026-07-05 - CVE-2026-34975 web HIGH 8.5
CRLF Email Header Injection in Plunk via Raw MIME Construction (CVE-2026-34975)
Plunk's POST /v1/send endpoint builds a raw MIME email message by interpolating user-supplied fields (from.name, subject, custom headers, attachment filenames) directly into a template string without sanitizing CRLF (\r\n) sequences. An authenticated API user…
Patched 2026-07-05 - CVE-2026-34038 web CRITICAL 10
Coolify Authenticated Remote Command Injection via Deployment Config (CVE-2026-34038)
Coolify builds shell commands for application deployment by interpolating user-supplied configuration fields — notably dockerfilelocation and predeploymentcommand — directly into shell strings executed inside the build/deploy container, without adequate…
Patched 2026-07-05 - CVE-2026-57517 web CRITICAL 9.8
Control Web Panel Pre-Auth Blind SQL Injection to RCE — CVE-2026-57517
Control Web Panel versions <= 0.9.8.1224 contain a pre-authentication blind SQL injection in the userRes POST parameter of the user panel endpoint (/{username}/). The backend query runs with MySQL root privileges, which hold the global FILE privilege,…
Patched 2026-07-05 - CVE-2026-4257 web CRITICAL EPSS 41%
Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257)
CVE-2026-4257 is an unauthenticated Server-Side Template Injection (SSTI) vulnerability in the "Contact Form by Supsystic" WordPress plugin's prefill functionality (cfsPreFill parameter). A form field value is rendered through the Twig template engine without…
Unverified 2026-07-05 - CVE-2026-37749 web CRITICAL 9.8
CodeAstro Simple Attendance Management System 1.0 — SQL Injection Auth Bypass (CVE-2026-37749)
The login form in index.php of CodeAstro Simple Attendance Management System 1.0 concatenates the username POST parameter directly into a MySQL query with no sanitization or prepared statements. An unauthenticated attacker can submit a classic SQL injection…
Unverified 2026-07-05 - CVE-2026-4631 web CRITICAL 9.8 EPSS 15%
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
Cockpit's remote-login feature passes attacker-controlled hostnames (from the URL path) and usernames (from the Authorization: Basic header) directly to the OpenSSH ssh client without validation or a -- end-of-options separator. Because both values are used…
Patched 2026-07-05 - CVE-2026-33715 / GHSA-mxc9-9335-45mc web HIGH 7.5
Chamilo LMS Unauthenticated install.ajax.php SSRF + Open Mail Relay — CVE-2026-33715
Chamilo LMS ships an installation-wizard AJAX endpoint, public/main/inc/ajax/install.ajax.php, that unlike every other AJAX endpoint in the codebase never includes global.inc.php — the file responsible for enforcing session/authentication checks — and remains…
Unverified 2026-07-05 - CVE-2026-29041 web HIGH 8.8
Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041
Chamilo LMS's ckuploadimage AJAX endpoint (main/inc/ajax/document.ajax.php?a=ckuploadimage) validates uploaded files solely by inspecting magic bytes via PHP's mimecontenttype(), without checking the file extension or sanitizing the stored filename. An…
Patched 2026-07-05 - CVE-2026-2749 web CRITICAL
Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
This repository bundles three distinct, authenticated vulnerabilities in Centreon that were disclosed together. CVE-2026-2749 is a path traversal flaw in the Open Tickets upload feature that allows arbitrary file write, which can be escalated to remote code…
Patched 2026-07-05 - CVE-2026-6815 web HIGH
Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
Casdoor's Local File System storage provider fails to properly sanitize the pathPrefix configuration and fullFilePath parameter during resource uploads. An authenticated administrator (or equivalent privileged user) can use directory traversal sequences to…
Unverified 2026-07-05 - CVE-2026-39949 web HIGH
Cacti Authenticated OS Command Injection via Host Notes Variable (CVE-2026-39949)
Cacti substitutes user-controlled host metadata — specifically the device "notes" field — into RRDtool command-line arguments through its variable replacement engine without sanitizing shell metacharacters. An authenticated attacker who can create devices and…
Patched 2026-07-05 - CVE-2026-2576 web HIGH 7.5
Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
The Business Directory Plugin's ORM query builder (class-db-query-set.php) safely parameterizes scalar filter values with $wpdb->prepare(), but falls back to raw string concatenation whenever a filter value is an array. The plugin's checkout controller reads…
Patched 2026-07-05 - CVE-2026-8181 web CRITICAL 9.8 EPSS 15%
Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181)
Burst Statistics' ismainwpauthenticated() function (in class-mainwp-proxy.php) checks whether wpauthenticateapplicationpassword() returned a WPError, but does not verify that it returned an actual WPUser. When the call is made outside WordPress's normal REST…
Patched 2026-07-05 - CVE-2026-31816 web CRITICAL EPSS 15%
Budibase Authentication Bypass to Plugin-Upload Reverse Shell — CVE-2026-31816
Budibase exposes an integrations/webhooks-related endpoint pattern (/api/integrations?/webhooks/trigger) that can be reached without authentication, and a plugin-upload endpoint (/api/plugin/upload?/webhooks/trigger) that shares the same bypass pattern. By…
Unverified 2026-07-05 - CVE-2026-11551 web CRITICAL 9.8
Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
Branda's signup-password.php registers a preinsertuserdata() hook that fires on every wpinsertuser()/wpupdateuser() call, but is missing the standard if ($update) return $data; guard used to distinguish new-user creation from existing-user updates. As a…
Patched 2026-07-05 - CVE-2026-5513 web HIGH 7.2
Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
Bookly reads the bookly-customer-full-name cookie value and renders it directly into the booking form's HTML value attribute without sanitizing or escaping it, when the plugin's "Remember personal information in cookies" option is enabled. An unauthenticated…
Patched 2026-07-05 - CVE-2026-6960 web CRITICAL 9.8
BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
BookingPress Pro's bookingpressbookappointmentbooking AJAX handler processes a signature-type custom field value as a data URI. The plugin extracts the file extension from the MIME-type portion of the URI via regex and passes it directly to fileputcontents()…
Unverified 2026-07-05 - CVE-2026-39387 web HIGH
BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
BoidCMS (<= 2.1.2) combines two weaknesses to reach remote code execution from an authenticated admin account. First, its media upload endpoint only checks the declared MIME type (e.g. image/gif) rather than actual file contents, allowing PHP code embedded in…
Patched 2026-07-05 - CVE-2026-25099 web HIGH
Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)
Bludit CMS's POST /api/files/<page-key> endpoint lets any holder of a valid API token upload files to a page without validating file extension or content, so a PHP file can be uploaded and dropped directly under the web-accessible uploads directory. Once…
Patched 2026-07-05 - CVE-2026-7515 web CRITICAL 9.8
BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
BetterDocs Pro <= 3.8.0 passes the unauthenticated docstyle POST parameter from its loadmoredocssection/loadmoredocs AJAX actions (registered via wpajaxnopriv) directly into a file-include/view-loading sink (views->get("layouts/encyclopedia/$docstyle")),…
Unverified 2026-07-05 - CVE-2026-41653 web CRITICAL
BentoPDF Stored XSS to File Exfiltration (CVE-2026-41653)
BentoPDF's Markdown-to-PDF tool renders user-supplied Markdown through markdown-it with html: true enabled and injects the resulting HTML directly into the DOM via innerHTML, with no sanitizer (e.g. DOMPurify) in between. A crafted .md file containing an <img…
Patched 2026-07-05 - CVE-2026-54415 web HIGH 3.1
Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415
Before Azuriom 1.2.11, the admin panel's server-management routes (/admin/servers/) had no dedicated permission gate — any admin-panel user with just the base admin.access permission could reach them, since the admin.servers permission did not exist yet.…
Patched 2026-07-05 - CVE-2026-6279 web CRITICAL
Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
Avada Builder's wpajaxnoprivfusiongetwidgetmarkup AJAX handler processes a base64-encoded JSON renderlogics payload. Within its getvalue() method, the wpconditionaltags case passes an attacker-controlled function name directly to PHP's calluserfunc() with no…
Unverified 2026-07-05 - CVE-2026-30950 web HIGH 7.1
AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
The AutoGPT Platform's chat-session API exposes a PATCH /sessions/{sessionid}/assign-user route that lets an authenticated user attach their own account to a chat session record, but the route performs no check that the caller currently owns the session being…
Patched 2026-07-05 - CVE-2026-5076 web CRITICAL 9.8
ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
ARMember Premium <= 7.3.1 stores password-reset keys (armresetpasswordkey user meta) in plaintext, and the plugin's member-directory AJAX endpoint (armdirectorypagingaction) is vulnerable to unauthenticated SQL injection via the order parameter. The included…
Patched 2026-07-05 - CVE-2026-30862 web CRITICAL 9.1
Appsmith Table Widget Stored XSS to Admin Account Takeover — CVE-2026-30862
Appsmith's TableWidgetV2 component (BasicCell.tsx) fails to sanitize user-supplied cell values when the column type is URL or Plain Text, rendering raw HTML/attributes directly as React children and allowing stored XSS. Because Appsmith's XSRF-TOKEN cookie is…
Patched 2026-07-05 - CVE-2026-32731 web HIGH
ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
ApostropheCMS supports importing a site/content archive (.tar.gz) containing aposDocs.json and aposAttachments.json metadata files. The import handler does not validate that entries extracted from the archive stay within the intended extraction directory,…
Patched 2026-07-05 - CVE-2026-34486 web CRITICAL KEV EPSS 81%
Apache Tomcat Tribes EncryptInterceptor Fail-Open Unauthenticated RCE (CVE-2026-34486)
CVE-2026-34486 is a fail-open flaw in Apache Tomcat's Tribes clustering EncryptInterceptor, which is meant to require encrypted, authenticated membership traffic between cluster nodes. Due to the bypass, an attacker can send an unencrypted, crafted message…
Patched 2026-07-05 - CVE-2026-43515 web HIGH
Apache Tomcat Split-Collection Security Constraint Bypass (CVE-2026-43515)
CVE-2026-43515 is a security constraint evaluation bug in Apache Tomcat's RealmBase.findSecurityConstraints(). When a single <security-constraint> defines multiple <web-resource-collection> blocks that share the same URL pattern (e.g. .html) but each declare…
Patched 2026-07-05 - CVE-2026-29145 web CRITICAL 9.1
Apache Tomcat Mutual TLS OCSP Soft-Fail Authentication Bypass — CVE-2026-29145
When Tomcat is configured to use Mutual TLS (CLIENTCERT) authentication together with OCSP revocation checking in hard-fail mode, it is expected to reject any client certificate whose revocation status cannot be confirmed. This PoC demonstrates that when the…
Patched 2026-07-05 - CVE-2026-25854 web MEDIUM 6.1
Apache Tomcat LoadBalancerDrainingValve — Cross-System Open Redirect / Session Fixation (CVE-2026-25854)
When a Tomcat cluster node is marked disabled/draining, its LoadBalancerDrainingValve invalidates the invalid/stale session and constructs a redirect using the raw, attacker-supplied request URI. If that URI begins with //, Tomcat preserves the double slash,…
Patched 2026-07-05 - CVE-2026-23980 web MEDIUM 6.5
Apache Superset Authenticated SQL Injection via sqlExpression/where Bypass — CVE-2026-23980
Apache Superset versions before 6.0.0 are vulnerable to an authenticated, error-based SQL injection reachable through the sqlExpression (adhoc column) or extras.where parameters of the /api/v1/chart/data REST endpoint. Superset's validateadhocsubquery()…
Patched 2026-07-05 - CVE-2026-44825 web CRITICAL 9.8
Apache Solr Velocity Template Injection RCE (CVE-2026-44825)
Apache Solr bundles the Apache Velocity template engine as an optional response writer. Solr's VelocityResponseWriter renders user-supplied Velocity templates passed via the wt=velocity query parameter without adequately restricting access to Java reflection…
Patched 2026-07-05 - CVE-2026-22444 web CRITICAL
Apache Solr UNC Path Validation Bypass to RCE (CVE-2026-22444)
CVE-2026-22444 affects Apache Solr's "create core" admin API on Windows deployments running in standalone mode. Path validation (assertPathAllowed()) is only performed after the CoreDescriptor constructor has already triggered filesystem/network operations…
Patched 2026-07-05 - CVE-2026-39816 web CRITICAL
Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
Apache NiFi restricts all of its 16 dedicated script-execution processors behind an EXECUTECODE permission, enforced via a @Restricted annotation. However, the optional graph bundle's TinkerpopClientService — used by the ExecuteGraphQuery /…
Patched 2026-07-05 - CVE-2026-24072 web MEDIUM
Apache HTTP Server mod_rewrite/mod_setenvif/mod_proxy_fcgi ap_expr Local File Read — CVE-2026-24072
Apache HTTP Server's apexpr expression evaluation engine exposes filesystem-introspection functions (file(), filesize(), and tests like -f, -d, -e, -s, -L, -h, -x) that are meant to be restricted when expressions are parsed from a .htaccess file rather than…
Patched 2026-07-05 - CVE-2026-33006 web MEDIUM 4.8
Apache HTTP Server mod_auth_digest Timing Attack — CVE-2026-33006
Apache's modauthdigest module is vulnerable to a timing side-channel during HTTP Digest authentication: because the response verification does not run in constant time, an attacker can measure subtle differences in server response latency to infer whether a…
Patched 2026-07-05 - CVE-2026-33453 web CRITICAL 10
Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)
Apache Camel's camel-coap component maps CoAP URI query parameters directly into Camel Exchange headers via setHeader() inside CamelCoapResource.handleRequest(), without applying any HeaderFilterStrategy. Because CoAPEndpoint extends DefaultEndpoint rather…
Patched 2026-07-05 - CVE-2026-31908 web CRITICAL 10
Apache APISIX forward-auth CRLF Header Injection — CVE-2026-31908
Apache APISIX's forward-auth plugin fails to sanitize CRLF (\r\n) sequences in inbound request headers before forwarding an authentication check upstream. By injecting CRLF sequences into headers such as Authorization, X-Forwarded-For, or Host, an…
Patched 2026-07-05 - CVE-2026-25604 web HIGH
Apache Airflow AWS Auth Manager SAML Host Header Injection (CVE-2026-25604)
CVE-2026-25604 is a CWE-346 origin validation error in Apache Airflow's AWS Auth Manager. When building the SAML AssertionConsumerService (ACS) callback URL for a login request, the code reads the HTTP Host header directly from the incoming request instead of…
Patched 2026-07-05 - CVE-2026-42588 web HIGH 8.1
Apache ActiveMQ Jolokia addNetworkConnector Spring Bean RCE (CVE-2026-42588)
CVE-2026-42588 is a code injection / improper input validation vulnerability in Apache ActiveMQ's Jolokia JMX-HTTP bridge. An attacker able to reach the addNetworkConnector MBean operation via Jolokia can supply a crafted broker configuration URI (xbean:…
Patched 2026-07-05 - CVE-2026-33980 web HIGH 8.8
adx-mcp-server KQL Injection via table_name Parameter (CVE-2026-33980)
adx-mcp-server is a Model Context Protocol server that exposes tools letting an AI agent query an Azure Data Explorer (Kusto/KQL) cluster. Three "safe" metadata tools — gettableschema, sampletabledata, and gettabledetails — build their KQL queries by directly…
Patched 2026-07-05 - CVE-2026-8809 web CRITICAL 9.8
Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
ACF Extended's aftervalidatesavepost() function trusts the attacker-controlled POST parameter acfpostid without any validation or authentication check. By manipulating this parameter, an attacker causes the function to take a cleanup code path that silently…
Unverified 2026-07-05 - CVE-2026-21440 web CRITICAL 9.2
AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
CVE-2026-21440 is a path-traversal vulnerability in @adonisjs/bodyparser's MultipartFile.move() method. When an application calls file.move(location) without explicitly supplying a sanitized name option, the library falls back to the client-supplied original…
Patched 2026-07-05 - CVE-2026-30498 web HIGH
AdminPanel 4.0 CSRF File Deletion / Setup-Mode Reset — CVE-2026-30498
AdminPanel 4.0's delete.php endpoint performs a sensitive file-deletion action (deleting verifyPanel.php) via a simple GET request, with no CSRF token, no Origin/Referer validation, and no confirmation of user intent. An attacker can host a page that…
Unverified 2026-07-05 - CVE-2026-1729 web CRITICAL
AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
The AdForest WordPress theme implements a one-time-password (OTP) login flow via the sbloginuserwithotpfun AJAX handler, but the handler does not actually verify the submitted OTP code against a server-issued value before authenticating the requested user. As…
Unverified 2026-07-05 - CVE-2026-46391 web HIGH
@haxtheweb/open-apis Credential Exposure via SSRF in cacheAddress Endpoint (CVE-2026-46391)
The cacheAddress endpoint in @haxtheweb/open-apis (/api/services/website/cacheAddress) performs a server-side fetch of a URL supplied by the caller without adequately restricting the destination, resulting in a Server-Side Request Forgery (SSRF)…
Unverified 2026-07-05 - None assigned as of 2026-07-03 web CRITICAL
PHP 8.5.7 StreamBucket-to-SOAP Numeric Cookie Remote Code Execution
This PoC demonstrates a full memory-corruption-to-RCE chain in PHP 8.5.7 built from three engine/extension behaviors chained together: ArrayIterator can mutate normally-protected internal object properties (bypassing typed-property/visibility/readonly…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
NodeBB ActivityPub attributedTo Local UID Spoof
NodeBB's ActivityPub inbox authenticates the top-level signed actor of an incoming activity via HTTP Signatures, but never checks that the embedded Note.attributedTo field — used later as the internal local user id for chat message and post authorship —…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Next.js unstable_cache Object-Argument Cache-Key Collision
Next.js's unstablecache() API derives its cache key by running JSON.stringify() over the arguments passed to the cached function. When a route handler passes a stock request-wrapper object — a Request, URLSearchParams, or FormData instance — directly into…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
MyBB 1.8.40 Limited Admin CP User-Manager to Full Administrator Privilege Escalation
A non-super Admin CP account that has only the user-management permission (user-users = 1) can use the standard Admin CP "add user" form to create a brand-new account directly in the Administrator group (gid=4), because the underlying user data handler's…
Unpatched 2026-07-03 - CVE-2025-3248 web CRITICAL 9.8 KEV Ransomware EPSS 100%
Langflow Missing-Authentication Remote Code Execution (CVE-2025-3248)
CVE-2025-3248 is a missing-authentication vulnerability in Langflow's code-validation API. The /api/v1/validate/code endpoint accepts and executes arbitrary Python code submitted by any client, with no authentication check on the route, allowing an…
Patched 2026-07-03 - None assigned as of 2026-07-03 web CRITICAL
Ladybird Browser WebAssembly ESM Host-Function Use-After-Free RCE
The PoC targets a lifetime bug in Ladybird's WebAssembly ESM import path: WebAssemblyModule.cpp builds a Wasm::FunctionType as a stack-local value and passes it by reference into createhostfunction(), so the resulting long-lived JS host callback retains a…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web CRITICAL
Gogs Admin User Edit CSRF to Git Hook RCE
Gogs' admin user-edit route (POST /admin/users/:userid) performs the state-changing grant of IsAdmin/AllowGitHook without a CSRF token, so an authenticated site administrator can be induced (e.g., via a cross-site form submission) to grant those rights to an…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Flowise Custom MCP Environment Variable Case Bypass
Flowise's Custom MCP stdio node validates configured environment variables against a denylist (PATH, LDLIBRARYPATH, DYLDLIBRARYPATH, NODEOPTIONS) using exact, case-sensitive string comparison. Windows, however, treats environment variable names…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Firefox Smart Window Private URL Exfiltration
Firefox's Smart Window assistant exposes getopentabs and searchbrowsinghistory tools that return private tab/history URLs to the model and mark the conversation as containing privateData, but they never mark it as containing untrustedInput even though the…
Unverified 2026-07-03 - None assigned as of 2026-07-03 web HIGH
Discourse Scoped API Key Pre-Route Authorization Bypass
Discourse's overload-protection middleware authenticates API requests before Rails routing has resolved the actual HTTP verb, and its scoped API key matcher (lib/routematcher.rb) calls Rails.application.routes.recognizepath(request.pathinfo) without passing…
Unverified 2026-07-03 - CVE-2026-45247 web CRITICAL 9.3 KEV EPSS 28%
Unauthenticated RCE in Mirasvit Full Page Cache Warmer for Magento 2 (CVE-2026-45247)
CVE-2026-45247 is a PHP object injection / insecure deserialization vulnerability in Mirasvit's Full Page Cache Warmer extension for Magento 2. The extension processes attacker-controlled data from the CacheWarmer cookie and passes it directly to PHP's native…
Unverified 2026-07-01 - CVE-2026-48907 web CRITICAL 10 KEV EPSS 56%
Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)
CVE-2026-48907 is a critical improper access control vulnerability in the JCE extension for Joomla. The profile import workflow (index.php?option=comjce&task=profiles.import) is missing sufficient authorization checks, letting unauthenticated users create new…
Patched 2026-07-01 - CVE-2026-0257 web HIGH 7.8 KEV Ransomware EPSS 94%
PAN-OS GlobalProtect Authentication Bypass via Forged Cookie (CVE-2026-0257)
CVE-2026-0257 is an authentication bypass in the GlobalProtect portal and gateway components of PAN-OS. In configurations where the same TLS certificate is reused for both the HTTPS service and the authentication-override cookie's encryption/decryption, an…
Unverified 2026-07-01 - CVE-2026-11645 web HIGH 8.8 KEV
Google Chromium V8 Out-of-Bounds Read/Write — Crash PoC (CVE-2026-11645)
CVE-2026-11645 is a high-severity out-of-bounds read/write vulnerability in V8, the JavaScript/WebAssembly engine used by Chrome and other Chromium-based browsers. The bug is rooted in V8's TurboFan optimizer: incorrect range analysis for loop-modified or…
Unverified 2026-07-01 - CVE-2026-42271 web HIGH 8.7 KEV EPSS 83%
Authenticated Command Injection in LiteLLM MCP Test Endpoints (CVE-2026-42271)
CVE-2026-42271 is a command injection vulnerability in BerriAI LiteLLM's MCP preview/test endpoints — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list. These endpoints accept a full MCP server configuration in the request body, including…
Patched 2026-07-01 - CVE-2026-48908 web CRITICAL 10 KEV EPSS 88%
SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)
CVE-2026-48908 is a CVSS 10.0 unauthenticated remote code execution vulnerability in SP Page Builder, one of the most widely used Joomla page-builder extensions (joomshaper.net). The asset.uploadCustomIcon endpoint enforces no authentication, no…
Patched 2026-06-30 - CVE-2026-20253 web CRITICAL KEV EPSS 97%
Splunk Enterprise Pre-Auth RCE via PostgreSQL Sidecar (CVE-2026-20253)
CVE-2026-20253 is a critical unauthenticated RCE vulnerability in Splunk Enterprise arising from a missing authentication check on the PostgreSQL sidecar service endpoint /v1/postgres/recovery/backup. An unauthenticated attacker can reach this endpoint and…
Patched 2026-06-28 - web CRITICAL 9.3
FirefUXSS: Universal XSS in Firefox Focus for iOS via Redirect-Scheme Validation Race Condition
FirefUXSS is a universal XSS issue in Firefox Focus for iOS where redirect-scheme validation can be bypassed via a race condition. A burst of benign redirects can desynchronize validation from navigation commit, allowing a final javascript: redirect to…
Unpatched 2026-06-08 - CVE-2026-48172 web HIGH KEV EPSS 19%
LiteSpeed User-End cPanel Plugin Local Privilege Escalation (CVE-2026-48172)
CVE-2026-48172 is a local privilege-escalation flaw in LiteSpeed cPanel Plugin v6.5.0 and earlier. The plugin installation flow does not sufficiently validate package ownership/permissions and can be abused with symlinked install targets. A normal cPanel user…
Unverified 2026-05-30 - CVE-2026-9082 / SA-CORE-2026-004 web CRITICAL KEV EPSS 88%
Drupal Core PostgreSQL SQL Injection (CVE-2026-9082)
CVE-2026-9082 is an unauthenticated SQL injection in Drupal Core's PostgreSQL entity-query handling for JSON:API filters. User-controlled array keys are used to build SQL placeholder names without proper sanitization, enabling injection into generated SQL. On…
Patched 2026-05-30 - CVE-2026-5281 web HIGH 8.8 KEV
Chrome WebGPU Use-After-Free (CVE-2026-5281)
CVE-2026-5281 is a reported WebGPU use-after-free condition in Chrome's Dawn backend. The upstream toolkit provides an aggressive payload generator, scanner, and automated browser runner to reproduce crash-like GPU-failure signals and compare vulnerable vs…
Unverified 2026-05-18 - CVE-2025-53770, CVE-2025-53771, CVE-2025-49704, CVE-2025-49706 web CRITICAL KEV Ransomware EPSS 100%
ToolShell - SharePoint Unauthenticated RCE Chain
CVE-2025-53770 ("ToolShell") is a full unauthenticated remote code execution chain against Microsoft SharePoint Server. The chain combines an authentication bypass in the ToolPane.aspx endpoint (CVE-2025-49706 / patch bypass CVE-2025-53771) with an unsafe…
Patched 2026-05-17 - CVE-2025-55182 web CRITICAL 10 KEV Ransomware EPSS 100%
React2Shell - Next.js RSC Unauthenticated RCE
CVE-2025-55182 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Next.js applications using React Server Components (RSC) with the App Router. The exploit abuses unsafe deserialization of the RSC wire format: a crafted multipart POST…
Patched 2026-05-17 - CVE-2024-3400 web CRITICAL 10 KEV Ransomware EPSS 100%
Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)
CVE-2024-3400 is an unauthenticated command injection vulnerability in PAN-OS GlobalProtect that can be reached over the network when specific features are enabled. Public reporting showed chained abuse via arbitrary file creation and command execution as…
Patched 2026-05-17 - CVE-2026-44572 web LOW 3.1
Next.js x-nextjs-data Cache Poisoning (CVE-2026-44572)
CVE-2026-44572 is a cache poisoning vulnerability in Next.js Pages Router redirect handling. Pre-patch, any external client could set the internal x-nextjs-data: 1 header on a request to a redirecting URL, causing the server to return a 200 OK with…
Patched 2026-05-17 - CVE-2026-44578 web HIGH 8.6 EPSS 39%
Next.js WebSocket Upgrade SSRF (Self-Hosted) (CVE-2026-44578)
CVE-2026-44578 is a server-side request forgery (SSRF) vulnerability in self-hosted Next.js WebSocket upgrade handling. A crafted HTTP request with Upgrade: websocket can coerce vulnerable versions into proxying to attacker-chosen internal targets on port 80…
Patched 2026-05-17 - CVE-2026-23870 web HIGH 7.5
Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)
CVE-2026-23870 is a pre-authentication Denial of Service against any Next.js deployment using the App Router. An attacker sends crafted HTTP POST requests to any App Router server function endpoint with a deeply-cyclic or wide fan-out React Flight protocol…
Patched 2026-05-17 - CVE-2026-44576 web MEDIUM 5.4
Next.js RSC Response Cache Poisoning (CVE-2026-44576)
CVE-2026-44576 is a cache poisoning issue in Next.js RSC response handling. In vulnerable versions, RSC and HTML response variants can be mis-partitioned by shared caches when request/response variants are not keyed correctly, allowing attacker-controlled…
Patched 2026-05-17 - CVE-2026-44582 web LOW 3.7
Next.js RSC Cache-Busting Weak Hash Collision (CVE-2026-44582)
Next.js used a weak cache-busting hash for the rsc query parameter in vulnerable versions. Because this hash had practical collision resistance limits, an attacker could generate alternative header/state tuples that map to the same rsc token as a victim route…
Patched 2026-05-17 - CVE-2026-44577 web MEDIUM 5.9
Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)
CVE-2026-44577 is a denial-of-service issue in Next.js Image Optimization on self-hosted deployments. In vulnerable builds, /next/image can fetch very large local assets into memory without an effective size cap and then perform expensive image…
Patched 2026-05-17 - CVE-2026-44573 web HIGH 7.5
Next.js i18n Middleware Bypass (CVE-2026-44573)
CVE-2026-44573 is an authorization bypass in Next.js Pages Router applications that use the i18n configuration. The middleware matcher regex's i18n branch does not correctly cover all locale-prefix permutations of next/data/<buildId>/<page>.json URLs. As a…
Patched 2026-05-17 - CVE-2026-44574 web HIGH 8.1
Next.js Dynamic Route Injection Auth Bypass (CVE-2026-44574)
CVE-2026-44574 is an authentication bypass in Next.js App Router applications that use middleware to protect dynamic route pages. Specially crafted query parameters (nxtP / nxtI internal Next.js route params) injected on a public URL cause the App Router…
Patched 2026-05-17 - CVE-2026-44581 web MEDIUM 4.7
Next.js CSP Nonce Cache-Poisoned XSS (CVE-2026-44581)
CVE-2026-44581 is a reflected XSS issue in Next.js App Router nonce handling. Malformed nonce values from a Content-Security-Policy request header can be reflected into rendered HTML script attributes without safe attribute-context escaping. In caching…
Patched 2026-05-17 - CVE-2026-44579 web HIGH 7.5
Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)
CVE-2026-44579 is a denial-of-service issue in Next.js Cache Components (PPR) request handling. Before the fix, a crafted client request could force the server into the next-resume flow and trigger expensive request-body processing and resume rendering work.…
Patched 2026-05-17 - CVE-2026-44580 web MEDIUM 6.1
Next.js beforeInteractive Script XSS (CVE-2026-44580)
CVE-2026-44580 is an XSS vulnerability in Next.js next/script rendering for beforeInteractive scripts. Vulnerable versions serialize script props with JSON.stringify and inject them into inline HTML via dangerouslySetInnerHTML without safe HTML escaping for…
Patched 2026-05-17 - CVE-2026-44575 web HIGH 7.5
Next.js App Router Segment-Prefetch Middleware Bypass (CVE-2026-44575)
CVE-2026-44575 is an authorization bypass in Next.js App Router middleware matching. Vulnerable versions compile middleware matchers for canonical paths and legacy Pages Router data routes, but omit the App Router transport variants used for .rsc and…
Patched 2026-05-17 - CVE-2024-23897 web CRITICAL 9.8 KEV Ransomware EPSS 100%
Jenkins CLI Arbitrary File Read to RCE (CVE-2024-23897)
CVE-2024-23897 is an arbitrary file read vulnerability in the Jenkins CLI command parser. The parser expands arguments that start with @ and can disclose controller-local files to unauthenticated attackers in common deployments. This disclosure can expose…
Patched 2026-05-17 - CVE-2023-22527 web CRITICAL 10 KEV Ransomware EPSS 100%
Confluence SSTI RCE - CVE-2023-22527
CVE-2023-22527 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server. The vulnerability is a Server-Side Template Injection (SSTI) in the Velocity/Freemarker template engine, reachable via the…
Patched 2026-05-17 - CVE-2024-21683 web HIGH 8.3 EPSS 88%
Confluence Post-Auth RCE - CVE-2024-21683
CVE-2024-21683 is an authenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server affecting the "Add a New Language" feature in the Code Macro plugin. An authenticated Confluence administrator can upload a malicious .js…
Unverified 2026-05-17 - CVE-2026-23918 web CRITICAL EPSS 50%
Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918
CVE-2026-23918 is a pre-authentication double-free vulnerability in Apache httpd's modhttp2 stream cleanup path. Under affected configurations, a remote attacker can trigger memory corruption over HTTP/2 before authentication. The upstream PoC demonstrates…
Patched 2026-05-17 - CVE-2025-0108 web CRITICAL 9.1 KEV EPSS 98%
Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
CVE-2025-0108 is an authentication bypass in the PAN-OS management interface that can allow unauthorized administrative access. The PoC uses a crafted path traversal style request to reach sensitive management functionality without a valid login session.…
Patched 2026-05-16 - CVE-2024-21762 web CRITICAL 9.6 KEV Ransomware EPSS 84%
Fortinet FortiOS SSL VPN Unauthenticated RCE (CVE-2024-21762)
CVE-2024-21762 is a critical out-of-bounds write in FortiOS sslvpnd reachable through the SSL VPN web interface. A remote unauthenticated attacker can send crafted HTTP requests to corrupt memory and potentially achieve remote code execution. Public reporting…
Patched 2026-05-16 - CVE-2024-55591 web CRITICAL 9.6 KEV Ransomware EPSS 98%
Fortinet FortiOS / FortiProxy Authentication Bypass (CVE-2024-55591)
CVE-2024-55591 is an authentication bypass in Fortinet management interfaces that can be abused over a crafted WebSocket workflow. The public PoC demonstrates racing WebSocket login-context traffic to gain effective super-admin CLI access without valid…
Unverified 2026-05-16 - CVE-2026-41940 web CRITICAL 10 KEV Ransomware EPSS 98%
cPanel & WHM Authentication Bypass via Session-File CRLF Injection (CVE-2026-41940)
CVE-2026-41940 is a critical unauthenticated authentication bypass in cPanel & WHM. The vulnerable session handling flow writes attacker-controlled Authorization: Basic data to the session file before sanitization, allowing CRLF injection of trusted session…
Patched 2026-05-16 - CVE-2025-5777 web CRITICAL 9.3 KEV Ransomware EPSS 100%
Citrix NetScaler CitrixBleed 2 Session Token Disclosure (CVE-2025-5777)
CVE-2025-5777 ("CitrixBleed 2") is an unauthenticated out-of-bounds memory disclosure in Citrix NetScaler ADC/Gateway authentication processing. A crafted request can leak chunks of process memory that may contain active session tokens and credentials.…
Patched 2026-05-16 - CVE-2026-2441 web HIGH 8.8 KEV EPSS 22%
Chrome CSSFontFeatureValuesMap Use-After-Free (CVE-2026-2441)
CVE-2026-2441 is a Blink use-after-free vulnerability in CSSFontFeatureValuesMap iteration logic. A crafted web page mutates a styleset map while iterating through entries, which can invalidate internal structures and trigger renderer memory safety failure on…
Unpatched 2026-05-16 - CVE-2025-29927 web CRITICAL 9.1 EPSS 99%
Next.js Corrupt Middleware Auth Bypass (CVE-2025-29927)
CVE-2025-29927 is a critical authentication bypass in Next.js middleware. By sending a crafted x-middleware-subrequest HTTP header, an unauthenticated remote attacker can cause the Next.js middleware layer to skip execution entirely — bypassing authentication…
Patched 2026-05-15 - CVE-2026-42897 web MEDIUM 5.3 KEV EPSS 70%
Exchange Health Checker Outbound Rule Blind Spot (CVE-2026-42897)
CVE-2026-42897 describes a diagnostic blind spot in Exchange Health Checker. The analyzer only enumerates inbound IIS URL Rewrite rules and ignores outbound rules. The EOMT mitigation for this CVE installs an outbound Content-Security-Policy rewrite rule…
Unverified 2026-05-15 - CVE-2026-42945 web CRITICAL 9.8 EPSS 66%
NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945)
CVE-2026-42945 is a critical heap buffer overflow in NGINX's ngxhttprewritemodule that has existed since 2008. When a server configuration combines a rewrite rule containing ? with a set directive, NGINX's two-pass script engine allocates an undersized buffer…
Unverified 2026-05-14