tag
Remote
Critical
wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf·
WordPress core (REST API /batch/v1, WP_Query::author__not_in)
patched
Critical
SimpleHelp OIDC Authentication Bypass via Unverified JWT Signature (CVE-2026-48558)
CVE-2026-48558·
SimpleHelp — remote support / RMM (remote monitoring and management) platform, OIDC authentication flow
patched
High
Langflow Responses API IDOR — Execute Another User's Flow (CVE-2026-55255)
CVE-2026-55255 (GHSA-qrpv-q767-xqq2)·
Langflow — open-source platform for building and deploying AI-powered agents and workflows (langflow-ai/langflow), OpenAI-compatible Responses API
patched
Critical (per Ciscos own Security Impact Rating, despite a High numeric CVSS)
Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)
CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW)·
Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service
patched
Critical
Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)
CVE-2026-48282 (Adobe APSB26-68)·
Adobe ColdFusion — Remote Development Service (RDS), /CFIDE/main/ide.cfm
patched
Critical
SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)
CVE-2026-15409 (SNWLID-2026-0008)·
SonicWall SMA1000 Appliance — WorkPlace interface (websocket proxy service)
unpatched
Critical
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8)·
Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware)
patched
Critical
Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
CVE-2026-56260 (GHSA-365w-hqf6-vxfg)·
Crawl4AI — open-source LLM-friendly web crawler/scraper (unclecode/crawl4ai), Docker API server mode
patched
High
ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)
CVE-2023-38950·
ZKTeco BioTime (web-based time & attendance / access control management platform)
patched
Critical
Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)
CVE-2026-48939·
iCagenda — events/calendar extension (component) for Joomla
patched
Critical
Sitecore XP Report.ashx Insecure Deserialization RCE (CVE-2021-42237)
CVE-2021-42237 (Sitecore advisory SC2021-003-499266)·
Sitecore Experience Platform (XP)
unpatched
Critical
LiteLLM Proxy Pre-Authentication SQL Injection via Error-Handling Callback (CVE-2026-42208)
CVE-2026-42208 (GHSA-r75f-5x8p-qvmc)·
LiteLLM Proxy — open-source LLM/AI gateway (22,000+ GitHub stars) fronting OpenAI, Anthropic, and other model provider APIs
patched
Critical
Gitea Docker Image Reverse-Proxy Authentication Bypass — "One Header, Any User" (CVE-2026-20896)
CVE-2026-20896 (GHSA-f75j-4cw6-rmx4)·
Gitea — official Docker images (gitea/gitea), both root and rootless variants
patched
Critical
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
CVE-2022-26258·
D-Link DIR-820L wireless router, all hardware revisions
unpatched
Critical
XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)
[alibaba/xquic](https://github.com/alibaba/xquic) — QUIC/HTTP-3 library, used by Tengine and reportedly across Alibaba's cloud/CDN infrastructure (Taobao, AliPay)
unpatched