| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-12569 | Cri | 0.84 | 9.8 | 0.46 | KEV | Jun 18, 2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified… | |
| CVE-2026-48768 | Cri | 0.60 | 9.3 | 0.00 | Jun 18, 2026 | TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a… | ||
| CVE-2026-54388 | Cri | 0.52 | 9.1 | 0.01 | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote… | ||
| CVE-2026-54387 | Cri | 0.52 | 9.1 | 0.01 | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can… | ||
| CVE-2026-48814 | Cri | 0.52 | 9.1 | 0.01 | Jun 17, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing… | ||
| CVE-2026-55196 | Cri | 0.52 | 9.1 | 0.01 | Jun 17, 2026 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST… | ||
| CVE-2026-53805 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without… | ||
| CVE-2026-3894 | Cri | 0.59 | 9.1 | 0.00 | Jun 17, 2026 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from… | ||
| CVE-2026-30803 | Cri | 0.59 | 9.1 | 0.01 | Jun 17, 2026 | Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers. This issue affects Connext Micro: from 4.0.0 before 4.3.0. | ||
| CVE-2026-20266 | Cri | 0.59 | 9.1 | 0.01 | Jun 17, 2026 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration… | ||
| CVE-2026-53874 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle files that evades detection but executes… | ||
| CVE-2026-53873 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling… | ||
| CVE-2026-3490 | Cri | 0.58 | 10.0 | 0.01 | Jun 17, 2026 | picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call… | ||
| CVE-2026-36418 | Cri | 0.59 | 9.1 | 0.01 | Jun 17, 2026 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing… | ||
| CVE-2026-20181 | Cri | 0.60 | 9.1 | 0.09 | Jun 17, 2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This… | ||
| CVE-2025-71325 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at… | ||
| CVE-2025-71323 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary… | ||
| CVE-2025-71321 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of… | ||
| CVE-2025-71320 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary… | ||
| CVE-2026-55743 | Cri | 0.55 | 9.6 | 0.01 | Jun 17, 2026 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user. | ||
| CVE-2026-54812 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109. | ||
| CVE-2026-47103 | Cri | 0.57 | 9.8 | 0.01 | Jun 17, 2026 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `` attributes evaluated unsafely. The SCXMLProcessor passes… | ||
| CVE-2026-54819 | Cri | 0.00 | 9.3 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0. | ||
| CVE-2026-54815 | Cri | 0.00 | 9.3 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6. | ||
| CVE-2026-54809 | Cri | 0.00 | 9.3 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10. | ||
| CVE-2026-54808 | Cri | 0.00 | 9.3 | 0.00 | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4. | ||
| CVE-2026-49268 | Cri | 0.59 | 9.1 | 0.01 | Jun 17, 2026 | A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an… | ||
| CVE-2026-49108 | Cri | 0.00 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Moderno < 1.43 versions. | ||
| CVE-2025-69127 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. | ||
| CVE-2025-69111 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. | ||
| CVE-2025-60236 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. | ||
| CVE-2025-60231 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1. | ||
| CVE-2025-60230 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9. | ||
| CVE-2025-60229 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. | ||
| CVE-2025-59554 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. | ||
| CVE-2026-54811 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. | ||
| CVE-2026-54807 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. | ||
| CVE-2026-54806 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. | ||
| CVE-2026-54803 | Cri | 0.64 | 9.8 | 0.00 | Jun 17, 2026 | Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. | ||
| CVE-2026-54194 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. | ||
| CVE-2026-54187 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. | ||
| CVE-2026-54186 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. | ||
| CVE-2026-52706 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. | ||
| CVE-2026-52705 | Cri | 0.59 | 9.0 | 0.00 | Jun 17, 2026 | Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. | ||
| CVE-2026-50203 | Cri | 0.52 | 9.1 | 0.01 | Jun 17, 2026 | A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is… | ||
| CVE-2026-49767 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. | ||
| CVE-2026-49107 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2026 | Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. | ||
| CVE-2026-49084 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. | ||
| CVE-2026-49080 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. | ||
| CVE-2026-49079 | Cri | 0.60 | 9.3 | 0.00 | Jun 17, 2026 | Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. |
- risk 0.84cvss 9.8epss 0.46
A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified…
- risk 0.60cvss 9.3epss 0.00
TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is unauthenticated and uses unsanitized fileName input to construct public/ S3 object keys, while issuing presigned PUT URLs that do not bind Content-Type. As a…
- risk 0.52cvss 9.1epss 0.01
Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote…
- risk 0.52cvss 9.1epss 0.01
Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can…
- risk 0.52cvss 9.1epss 0.01
Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows unauthenticated cross-origin MCP tool invocation due to an empty default secret. This issue was partially addressed by CVE-2026-46701 in version 5.4.5 by closing…
- risk 0.52cvss 9.1epss 0.01
Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST…
- risk 0.57cvss 9.8epss 0.01
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without…
- risk 0.59cvss 9.1epss 0.00
Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from…
- risk 0.59cvss 9.1epss 0.01
Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers. This issue affects Connext Micro: from 4.0.0 before 4.3.0.
- risk 0.59cvss 9.1epss 0.01
In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration…
- risk 0.57cvss 9.8epss 0.01
picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbitrary code by hiding eval calls nested under callable objects via getattr. Attackers can embed malicious code in pickle files that evades detection but executes…
- risk 0.57cvss 9.8epss 0.01
picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run() function, allowing attackers to achieve arbitrary code execution via exec(). Attackers can craft malicious pickle files calling…
- risk 0.58cvss 10.0epss 0.01
picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolving any dangerous function through indirect REDUCE calls. Remote attackers can invoke any blocked function such as os.system, builtins.exec, or subprocess.call…
- risk 0.59cvss 9.1epss 0.01
JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing…
- risk 0.60cvss 9.1epss 0.09
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This…
- risk 0.57cvss 9.8epss 0.01
picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes, failing to track arguments in the correct range and allowing malicious pickle files to bypass detection. Attackers can craft pickle files with arguments at…
- risk 0.57cvss 9.8epss 0.01
picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary…
- risk 0.57cvss 9.8epss 0.01
picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous blocklist by using distutils.file_util.write_file. Attackers can construct malicious pickle objects to overwrite critical system files and achieve denial of…
- risk 0.57cvss 9.8epss 0.01
picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using these unblocked functions to achieve arbitrary…
- risk 0.55cvss 9.6epss 0.01
The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed to execute arbitrary OS commands with the privileges of the desktop user.
- risk 0.60cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors motors-car-dealership-classified-listings allows Blind SQL Injection.This issue affects Motors: from n/a through 1.4.109.
- risk 0.57cvss 9.8epss 0.01
Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `` attributes evaluated unsafely. The SCXMLProcessor passes…
- risk 0.00cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection. This issue affects Listdom: from n/a through 5.4.0.
- risk 0.00cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerce allows Blind SQL Injection. This issue affects Cargo Shipping Location for WooCommerce: from n/a through 5.6.
- risk 0.00cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. This issue affects GIFT4U: from n/a through 1.0.10.
- risk 0.00cvss 9.3epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Blind SQL Injection. This issue affects WP Travel Gutenberg Blocks: from n/a through 3.9.4.
- risk 0.59cvss 9.1epss 0.01
A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an…
- risk 0.00cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Moderno < 1.43 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
- risk 0.64cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5.
- risk 0.64cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a through 1.8.1.
- risk 0.64cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a through 1.9.
- risk 0.64cvss 9.8epss 0.00
Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in WP eMember < v10.9.4 versions.
- risk 0.64cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- risk 0.64cvss 9.8epss 0.00
Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions.
- risk 0.64cvss 9.8epss 0.01
Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions.
- risk 0.59cvss 9.0epss 0.00
Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions.
- risk 0.52cvss 9.1epss 0.01
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is…
- risk 0.64cvss 9.8epss 0.01
Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.