tag
Cwe-863
Critical
Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758·
Real Spaces - Properties Directory Theme for WordPress (imic_agent_register AJAX handler)
unpatched
Critical
FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)
CVE-2025-66039·
FreePBX (Sangoma) framework module — web-based administration panel for Asterisk-based VoIP/PBX systems
patched
High
LiteLLM Proxy Privilege Escalation via `/user/update` (CVE-2026-47102)
CVE-2026-47102·
LiteLLM (LLM API proxy / gateway)
patched
High
LiteLLM /config/update Broken Access Control (CVE-2026-35029)
CVE-2026-35029·
LiteLLM proxy
patched
High
Kanboard — Missing Access Control on Plugin Installation Leads to Administrative RCE via Webshell Plugin (CVE-2026-25924)
CVE-2026-25924 / GHSA-grch-p7vf-vc4f·
Kanboard (project management application)
patched
High
Gitea OAuth2 Scope Enforcement Bypass via HTTP Basic Auth — CVE-2026-28699
CVE-2026-28699·
Gitea (code.gitea.io/gitea)
patched