tag
Code-Injection
Critical
XWiki SolrSearch Macro Unauthenticated Groovy RCE (CVE-2025-24893)
CVE-2025-24893·
XWiki (SolrSearch macro, Main.SolrSearch)
unpatched
Critical
pgAdmin 4 Query Tool Authenticated eval() RCE (CVE-2025-2945)
CVE-2025-2945·
pgAdmin 4 (web-based PostgreSQL administration tool)
patched
High
Shopware Twig Rendered-View Code Injection Regression (CVE-2026-23498)
CVE-2026-23498·
Shopware (shopware/shopware, shopware/core)
patched
Critical
PbootCMS Authenticated RCE via sitecopyright Field (CVE-2026-36239)
CVE-2026-36239·
PbootCMS
unpatched
High
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj)·
OpenWebUI (self-hosted LLM web interface)
unpatched
Critical
Node.js protobufjs Dynamic Type Compilation RCE (CVE-2026-41242)
CVE-2026-41242·
Node.js application using protobufjs (Root.fromJSON + dynamic decode)
unpatched
Critical
DbGate Unauthenticated RCE via JSON Script Runner (CVE-2026-47668)
CVE-2026-47668·
DbGate (dbgate-serve — web-based database management tool)
patched
High
DbGate `loadReader` `functionName` Injection RCE (CVE-2026-48017)
CVE-2026-48017 / GHSA-hv83-ggc4-v385·
DbGate (dbgate-api), a web-based database management GUI
patched
Critical
Apache NiFi 2.8.0 — EXECUTE_CODE Permission Bypass to Groovy RCE (CVE-2026-39816)
CVE-2026-39816·
Apache NiFi (with the optional graph bundle / nifi-other-graph-services-nar)
patched