CVE-2026-3055
Citrix NetScaler Out-of-Bounds Read Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures reveal 17 critical vulnerabilities spanning WordPress, FastGPT, NocoBase, and multiple AI/developer tooling platforms. Critical CVEs rose 21% from the prior day while high-priority vulnerabilities saw a sharp 47% increase to 100. CVE-2026-34162 in FastGPT carries a perfect CVSS 10.0 score, CVE-2026-34156 in NocoBase rates 9.9, and CVE-2026-3300 affects WordPress at 9.8. Attack patterns are dominated by remote code execution and authentication bypass across web application frameworks, content management systems, and healthcare interoperability standards (HL7 HAPI FHIR). No patches are currently available for disclosed vulnerabilities, and 8 CVEs have confirmed active exploitation including Citrix NetScaler, Apple products, Craft CMS, and Laravel Livewire.
Immediate action: Prioritize risk assessment for FastGPT, NocoBase, WordPress, and Citrix NetScaler deployments, applying network-level mitigations such as WAF rules and access restrictions where patches are unavailable. Monitor vendor advisories closely for patch releases across all 117 CVEs, as 0% currently have fixes available, and verify that actively exploited components including Apple products, Craft CMS, and Laravel Livewire are isolated or updated as remediation becomes available.
Citrix NetScaler Out-of-Bounds Read Vulnerability - Active in CISA KEV catalog.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
Laravel Livewire Code Injection Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Improper Locking Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Classic Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Aquasecurity Trivy Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Everest Forms Pro is vulnerable to unauthenticated Remote Code Execution via PHP Code Injection in its Calculation Addon, allowing attackers to execute code through unsanitized form fields.
SciTokens is vulnerable to SQL Injection in its KeyCache class due to the unsafe use of Python's str.format() for query construction, allowing attackers to execute arbitrary SQL commands.
NocoBase Workflow Script Node allows authenticated sandbox escape to Remote Code Execution as root via prototype chain traversal of console objects. This flaw is patched in version 2.0.28.
SiYuan desktop application is vulnerable to Remote Code Execution via a permissive CORS policy. A malicious website can inject JavaScript into the Electron Node.js context without user interaction.
FastGPT exposes an unauthenticated HTTP tools testing endpoint that functions as a full HTTP proxy, enabling Server-Side Request Forgery (SSRF) and internal network scanning.
HAPI FHIR's Validator service contains an unauthenticated SSRF vulnerability in the "/loadIG" endpoint that allows attackers to steal sensitive authentication tokens from the server.
baserCMS contains an OS command injection vulnerability in its core update functionality, allowing authenticated administrators to execute arbitrary commands on the server.
SiYuan is vulnerable to a stored XSS-to-RCE chain in its Attribute View. Malicious URLs in the mAsse field trigger JavaScript execution with full OS access in the Electron client.
The wenxian GitHub Actions workflow is vulnerable to command injection via untrusted user input in issue comments, allowing arbitrary code execution on the GitHub runner.
OpenClaw contains a remote command injection vulnerability in the iMessage attachment staging flow. Unsanitized SCP paths allow attackers to execute commands on remote hosts.
OpenClaw versions before 2026.3.11 contain an unauthenticated authorization bypass allowing remote attackers to execute privileged gateway actions via synthetic operator clients.
MLflow is vulnerable to command injection when serving models with `enable_mlserver=True`. Shell metacharacters in the `model_uri` allow for arbitrary code execution via `bash -c`.
The MAVLink protocol used in PX4 systems lacks default cryptographic authentication. Unauthenticated attackers can send `SERIAL_CONTROL` messages to gain interactive shell access to the drone or vehicle.
XenForo versions prior to 2.3.7 contain a critical security flaw in Passkey-based authentication that could allow attackers to compromise user accounts.
baserCMS contains an OS command injection vulnerability within its update functionality. Authenticated administrators can exploit this flaw to execute arbitrary commands with server-level privileges.
The Business::OnlinePayment::StoredTransaction Perl module uses an insecure MD5 hash of a predictable random number to generate secret keys for encrypting credit card data.
UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 is vulnerable to an arbitrary file overwrite during the import process, leading to code execution or data exposure.
The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2
Symantec Data Loss Prevention Windows Endpoint, prior to 25
Nginx UI is a web user interface for the Nginx web server
The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1
HAPI FHIR, a Java-based HL7 FHIR implementation, contains a high-severity vulnerability that impacts the security of healthcare data interoperability.
Core FTP/SFTP Server 1
JOSE is a Javascript Object Signing and Encryption (JOSE) library
The Query Monitor â The developer tools panel for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the â$_SERVER['REQUEST_URI']â parameter in all versions up to, and including, 3
FastGPT, an AI Agent building platform, contains a security vulnerability that could lead to unauthorized access or manipulation of AI agent configurations.
Admidio is an open-source user management solution
WWBN AVideo is an open source video platform
A security vulnerability has been detected in code-projects Accounting System 1
A vulnerability was determined in code-projects Student Membership System 1
A security flaw has been discovered in itsourcecode Payroll Management System 1
A weakness has been identified in itsourcecode Payroll Management System 1
A flaw has been found in code-projects Simple Laundry System 1
A vulnerability has been found in code-projects Simple Laundry System 1
baserCMS is a website development framework
OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication
A flaw has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205
A vulnerability has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205
A vulnerability was determined in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205
WWBN AVideo is an open source video platform
Invoice Ninja v5
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data
A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1
A flaw has been found in SourceCodester Simple Doctors Appointment System 1
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data
A vulnerability was detected in Tenda CH22 1
A vulnerability has been found in Tenda CH22 1
A vulnerability was found in Tenda CH22 1
A vulnerability was determined in Tenda CH22 1
A vulnerability was determined in Tenda CH22 1
The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default
A cross-session information disclosure vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19)
act is a project which allows for local running of github actions
The application's update service, when checking for updates, loads certain system libraries from a search path that includes directories writable by lowâprivileged users and is not strictly restricted to trusted system locations
NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments
IBM Storage Protect Server 8
OpenClaw before 2026
Unauthenticated credential disclosure in the wizard interface in ZTE ZXHN H188A V6
FreeRDP, an open-source Remote Desktop Protocol implementation, contains a security vulnerability. This flaw could potentially allow remote attackers to compromise RDP sessions or execute unauthorized actions.
FreeRDP is affected by a security vulnerability that could lead to unauthorized access or data compromise. This issue resides within the protocol implementation and affects various versions of the software.
FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol
SQL Injection vulnerability in SchemaHero 0
SQL Injection vulnerability in SchemaHero 0
Moby is an open source container framework
XenForo before 2
XenForo before 2
XenForo before 2
baserCMS is a website development framework
A Stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session
A Stored Cross-site Scripting (XSS) vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session
SiYuan is a personal knowledge management system
OpenClaw before 2026
OpenClaw before 2026
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++
Botan is a C++ cryptography library
SciTokens is a reference library for generating and using SciTokens
SciTokens is a reference library for generating and using SciTokens
Sereal::Decoder versions from 4
Sereal::Encoder versions from 4
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++
Impact: The fix for CVE-2021-23337 (https://github
TrueConf Client downloads application update code and applies it without performing verification
vcpkg is a free and open-source C/C++ package manager
InfCode's terminal auto-execution module contains a critical command filtering vulnerability that renders its blacklist security mechanism completely ineffective
The application's list box calculate array logic keeps stale references to page or form objects after they are deleted or re-created, which allows crafted documents to trigger a use-after-free when the calculation runs and can potentially lead to arbitrary code execution
Trino is a distributed SQL query engine for big data analytics
In KubePlus 4
Grav CMS v1
A directory traversal vulnerability in the agentic-context-engine project versions up to 0
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates
InvoiceShelf is an open-source web & mobile app that helps track expenses, payments and create professional invoices and estimates
OpenAirInterface V2
A vulnerability exists in the iconv() function of the GNU C Library (glibc) version 2. This flaw can lead to unexpected behavior or potential security bypasses during character set conversion.
A flaw in Node
LangChain is a framework for building agents and LLM-powered applications
A flaw was found in the gdk-pixbuf library
OpenClaw before 2026
mppx is a TypeScript interface for machine payments protocol
Out-of-bounds write in the streaming decoder component in aws-c-event-stream before 0
SiYuan is a personal knowledge management system
XenForo before 2
A security flaw has been discovered in YunaiV yudao-cloud up to 2026
A security flaw has been discovered in Totolink A3300R 17
A vulnerability was found in SourceCodester Teacher Record System 1
A flaw has been found in code-projects Student Membership System 1
A vulnerability was detected in SourceCodester Leave Application System 1
A vulnerability was found in Sanster IOPaint 1
baserCMS is a website development framework
A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x allows an attacker to read or write files in specific directories on the server
OpenClaw before 2026