| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-73355 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | ||
| CVE-2026-73343 | Cri | 0.65 | 10.0 | 0.01 | Aug 18, 2026 | Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions. | ||
| CVE-2026-73341 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions. | ||
| CVE-2026-73339 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | ||
| CVE-2026-73187 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | ||
| CVE-2026-66627 | Cri | 0.64 | 9.9 | 0.00 | Aug 18, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5. | ||
| CVE-2026-59940 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without… | ||
| CVE-2026-32474 | Cri | 0.64 | 9.9 | 0.00 | Aug 18, 2026 | Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions. | ||
| CVE-2026-32470 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions. | ||
| CVE-2026-32463 | Cri | 0.64 | 9.9 | 0.00 | Aug 18, 2026 | Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions. | ||
| CVE-2026-32444 | Cri | 0.64 | 9.9 | 0.01 | Aug 18, 2026 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | ||
| CVE-2026-28192 | Cri | 0.62 | 9.6 | 0.00 | Aug 18, 2026 | Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions. | ||
| CVE-2026-75874 | Cri | 0.65 | 10.0 | 0.00 | Aug 18, 2026 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. | ||
| CVE-2026-75783 | Cri | 0.62 | 9.6 | 0.01 | Aug 18, 2026 | A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be… | ||
| CVE-2026-74990 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This… | ||
| CVE-2026-74989 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and… | ||
| CVE-2026-74988 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in… | ||
| CVE-2026-74987 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This… | ||
| CVE-2026-74986 | Cri | 0.59 | 9.1 | 0.01 | Aug 18, 2026 | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74985 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74979 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74964 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||
| CVE-2026-74961 | Cri | 0.59 | 9.1 | 0.00 | Aug 18, 2026 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74959 | Cri | 0.59 | 9.1 | 0.00 | Aug 18, 2026 | Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||
| CVE-2026-74956 | Cri | 0.59 | 9.1 | 0.01 | Aug 18, 2026 | Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74944 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||
| CVE-2026-74943 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||
| CVE-2026-74940 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||
| CVE-2026-74938 | Cri | 0.59 | 9.1 | 0.00 | Aug 18, 2026 | Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | ||
| CVE-2026-74936 | Cri | 0.64 | 9.8 | 0.01 | Aug 18, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | ||
| CVE-2026-23933 | Cri | 0.59 | 9.1 | 0.00 | Aug 18, 2026 | In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used… | ||
| CVE-2026-75854 | Cri | 0.57 | 9.8 | 0.01 | Aug 18, 2026 | ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on… | ||
| CVE-2026-75852 | Cri | 0.57 | 9.8 | 0.01 | Aug 18, 2026 | ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials. | ||
| CVE-2026-75851 | Cri | 0.64 | 9.9 | 0.00 | Aug 18, 2026 | ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext… | ||
| CVE-2026-75843 | Cri | 0.57 | 9.9 | 0.00 | Aug 18, 2026 | ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a… | ||
| CVE-2026-75837 | Cri | 0.52 | 9.1 | 0.00 | Aug 18, 2026 | Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation… | ||
| CVE-2026-75627 | Cri | 0.57 | 9.8 | 0.01 | Aug 18, 2026 | Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings,… | ||
| CVE-2026-75626 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the… | ||
| CVE-2026-34884 | Cri | 0.57 | 9.8 | 0.01 | Aug 18, 2026 | SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | ||
| CVE-2026-15748 | Cri | 0.64 | 9.8 | 0.06 | Aug 18, 2026 | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist… | ||
| CVE-2026-75094 | Cri | 0.59 | 9.1 | 0.03 | Aug 18, 2026 | A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the… | ||
| CVE-2026-67919 | Cri | 0.57 | 9.8 | 0.01 | Aug 17, 2026 | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components | ||
| CVE-2026-42164 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section. | ||
| CVE-2026-42162 | Cri | 0.59 | 9.1 | 0.01 | Aug 17, 2026 | Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated. | ||
| CVE-2026-38165 | Cri | 0.57 | 9.8 | 0.01 | Aug 17, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression. | ||
| CVE-2026-71424 | Cri | 0.55 | 9.6 | 0.00 | Aug 17, 2026 | Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info… | ||
| CVE-2026-67960 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components | ||
| CVE-2026-67868 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code. | ||
| CVE-2026-67854 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code | ||
| CVE-2026-64849 | Cri | 0.66 | 9.3 | 0.10 | KEV | Aug 17, 2026 | MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in… |
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
- risk 0.65cvss 10.0epss 0.01
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
- risk 0.64cvss 9.9epss 0.00
Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.
- risk 0.64cvss 9.8epss 0.01
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…
- risk 0.64cvss 9.9epss 0.00
Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.
- risk 0.64cvss 9.8epss 0.01
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
- risk 0.64cvss 9.9epss 0.00
Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.
- risk 0.64cvss 9.9epss 0.01
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
- risk 0.62cvss 9.6epss 0.00
Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.
- risk 0.65cvss 10.0epss 0.00
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
- risk 0.62cvss 9.6epss 0.01
A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be…
- risk 0.64cvss 9.8epss 0.01
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…
- risk 0.64cvss 9.8epss 0.01
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and…
- risk 0.64cvss 9.8epss 0.01
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in…
- risk 0.64cvss 9.8epss 0.01
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…
- risk 0.59cvss 9.1epss 0.01
Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.00
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.01
Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.00
Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- risk 0.64cvss 9.8epss 0.01
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- risk 0.59cvss 9.1epss 0.00
In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used…
- risk 0.57cvss 9.8epss 0.01
ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on…
- risk 0.57cvss 9.8epss 0.01
ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.
- risk 0.64cvss 9.9epss 0.00
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext…
- risk 0.57cvss 9.9epss 0.00
ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a…
- risk 0.52cvss 9.1epss 0.00
Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation…
- risk 0.57cvss 9.8epss 0.01
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings,…
- risk 0.60cvss 9.3epss 0.00
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the…
- risk 0.57cvss 9.8epss 0.01
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.
- risk 0.64cvss 9.8epss 0.06
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist…
- risk 0.59cvss 9.1epss 0.03
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET§ion=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the…
- risk 0.57cvss 9.8epss 0.01
An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components
- risk 0.64cvss 9.8epss 0.01
Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.
- risk 0.59cvss 9.1epss 0.01
Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.
- risk 0.57cvss 9.8epss 0.01
A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.
- risk 0.55cvss 9.6epss 0.00
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info…
- risk 0.64cvss 9.8epss 0.01
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
- risk 0.64cvss 9.8epss 0.01
A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code
- risk 0.66cvss 9.3epss 0.10
MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in…