tag
Unauthenticated-Rce
Critical
Wing FTP Server NULL-Byte Lua Injection Unauthenticated RCE (CVE-2025-47812)
CVE-2025-47812·
Wing FTP Server, web administration/login interface (loginok.html, session mechanism)
patched
Critical
Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
CVE-2025-4632·
Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet
unpatched
Critical
React Server Components Flight-Protocol Prototype Pollution RCE — "React2Shell" (CVE-2025-55182)
CVE-2025-55182·
React Server Components (RSC) packages using the Flight protocol (commonly deployed via Next.js)
unpatched
Critical
Invision Community Theme Editor Template Injection Unauthenticated RCE (CVE-2025-47916)
CVE-2025-47916·
Invision Community, themeeditor front controller (IPS\core\modules\front\system\themeeditor::customCss())
patched
Critical
Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure & IOC Scanner (CVE-2025-20393)
CVE-2025-20393·
Cisco AsyncOS for Secure Email Gateway (ESA) / Security Management Appliance (SMA)
unpatched
Critical
ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)
CVE-2025-13486·
Advanced Custom Fields: Extended (ACFE) — WordPress plugin
unpatched
Critical
WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555·
WebStack theme for WordPress
unpatched
Critical
SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)
CVE-2026-48909 (GHSA-gf8c-xmwj-whrh)·
JoomShaper SP LMS (com_splms) Joomla Learning Management System extension
patched
Critical (per vendor advisory)
FortiAuthenticator Unauthenticated RCE Endpoint Probe (CVE-2026-44277)
CVE-2026-44277·
Fortinet FortiAuthenticator
patched
Critical
Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)
CVE-2026-4631 (GHSA-m4gv-x78h-3427)·
Cockpit (Linux web-based server admin console)
patched