CVE-2021-26829
OpenPLC ScadaBR Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Saturday's vulnerability landscape shows nine critical vulnerabilities (CVSS 9.0+), a 31% decrease from Friday's thirteen issues, while high-priority disclosures increased to 100 CVEs representing a 32% increase. The actively exploited vulnerability count expanded to eleven issues including newly added Sierra Wireless AirLink ALEOS and additional Android Framework entries. Notable critical vulnerabilities include WordPress plugin arbitrary file deletion (CVE-2025-14344), Apache insufficiently protected credentials (CVE-2025-58130), and Dormakaba Saflok physical access control system vulnerabilities (CVE-2024-58311). Zero patch availability across all 109 vulnerabilities continues to require compensating controls and enhanced weekend monitoring given reduced staffing levels.
Immediate action: Security teams should prioritize the eleven actively exploited vulnerabilities, particularly the newly cataloged Sierra Wireless AirLink ALEOS and Android Framework issues. Organizations using Dormakaba Saflok physical access systems, OpenPLC SCADA, or D-Link network devices should implement network segmentation and enhanced monitoring. Given zero patch availability and weekend staffing reductions, teams should establish clear escalation procedures and ensure monitoring coverage for critical infrastructure systems.
OpenPLC ScadaBR Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Android Framework Information Disclosure Vulnerability - Active in CISA KEV catalog.
Android Framework Privilege Escalation Vulnerability - Active in CISA KEV catalog.
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
D-Link Routers Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Array Networks ArrayOS AG OS Command Injection Vulnerability - Active in CISA KEV catalog.
RARLAB WinRAR Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Use After Free Vulnerability - Active in CISA KEV catalog.
OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
The LazyTasks â Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.29. This is due to the plugin not properly validating a user's identity via the 'wp-json/lazytasks/api/v1/user/role/edit/' REST API endpoint prior to updating their details like email address. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. It is also possible for attackers to abuse this endpoint to grant users with access to additional roles within the plugin
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'plupload_ajax_delete_file' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.
Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11.0. The issue is fixed in version 1.12.1. Users are encouraged to upgrade to version 1.13.0, the latest release.
Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.
Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.
PCMan FTP Server 2.0 contains a buffer overflow vulnerability in the 'pwd' command that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted payload during the FTP login process to overwrite memory and potentially gain system access.
Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.
Dormakaba Saflok System 6000 contains a predictable key generation algorithm that allows attackers to derive card access keys from a 32-bit unique identifier. Attackers can exploit the deterministic key generation process by calculating valid access keys using a simple mathematical transformation of the card's unique identifier.
Plesk 18.0 has Incorrect Access Control.
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143
The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1
The FunnelKit - Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'opid' parameter in all versions up to, and including, 3
The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions up to, and including, 0
The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1
The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in all versions up to, and including, 2
The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a missing capability check on the "blaze_demo_importer_install_demo" function in all versions up to, and including, 1
An issue was discovered in Foxit PDF and Editor for Windows before 13
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges locally
In aoc_service_read_message of aoc_ipc_core
Foxit PDF Editor and Reader before 2025
The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1
Authorization Bypass Through User-Controlled Key vulnerability in Apache Fineract
Weak Encryption Algorithm in StreamPark, The use of an AES cipher in ECB mode and a weak random number generator for encrypting sensitive data, including JWT tokens, may have risked exposing sensitive authentication data This issue affects Apache StreamPark: from 2
A remote code execution vulnerability exists where a malicious Raft node can exploit insecure Hessian deserialization within the PD store
Tornado is a Python web framework and asynchronous networking library
Tornado is a Python web framework and asynchronous networking library
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_deal_update in file /usr/lib/lua/luci/controller/api/rcmsAPI
A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch
A security flaw has been discovered in Tenda CH22 1
OS Command Injection vulnerability in Ruijie RG-RAP2200(E) 247 2200 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
OS Command Injection vulnerability in Ruijie RG-EW1300G EW1300G V1
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the check_changes in file /usr/lib/lua/luci/controller/admin/common
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_networkId_merge
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3
OS Command Injection vulnerability in Ruijie RG-EW1200 EW_3
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the run_tcpdump in file /usr/lib/lua/luci/controller/admin/common_tcpdump
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_service in file /usr/lib/lua/luci/controller/admin/service
OS Command Injection vulnerability in Ruijie M18 EW_3
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain
edoc-doctor-appointment-system v1
OS Command Injection vulnerability in Ruijie X30 PRO V1 X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the setWisp in file /usr/lib/lua/luci/modules/wireless
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/host_access_delay
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the restart_modules in file /usr/lib/lua/luci/controller/admin/common
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_config/config_retain
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
OS Command Injection vulnerability in Ruijie RG-YST AP_3
OS Command Injection vulnerability in Ruijie M18 EW_3
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
OS Command Injection vulnerability in Ruijie RG-EW1800GX B11P226_EW1800GX_10223121 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the submit_wifi in file /usr/lib/lua/luci/controller/admin/common_quick_config
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the pwdmodify in file /usr/lib/lua/luci/modules/common
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_wireless in file /usr/lib/lua/luci/control/admin/wireless
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the network_set_wan_conf in file /usr/lib/lua/luci/controller/admin/netport
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3
OS Command Injection vulnerability in Ruijie M18 EW_3
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary commands via a crafted POST request to the module_set in file /usr/local/lua/dev_sta/nbr_cwmp
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute arbitrary commands via a crafted POST request to the module_get in file /usr/local/lua/dev_sta/networkConnect
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a crafted POST request to the get_wanobj in file /usr/lib/lua/luci/controller/admin/common
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a crafted POST request to the action_diagnosis in file /usr/lib/lua/luci/controller/admin/diagnosis
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3
IBM Aspera Orchestrator 4
An issue was discovered in cPanel 110 through 132
MaxKB is an open-source AI assistant for enterprise
MaxKB is an open-source AI assistant for enterprise
Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc
An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32
WonderCMS 4
Atcom 100M IP Phones firmware version 2
A vulnerability was found in UTT čŋå 512W up to 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18
GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17
The Preset configuration https://v2
squid/cachemgr
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows
A flaw in libsoupâs HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing
Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption
Masa CMS is an open source Enterprise Content Management platform
IBM Aspera Orchestrator 4
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15
In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder
In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools
QND Premium/Advance/Standard Ver
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1
In aocc_read of aoc_channel_dev
In WAVES_send_data_to_dsp of libaoc_waves
In GetTachyonCommand of tachyon_server_common
In GetHostAddress of gxp_buffer
In GetHostAddress of gxp_buffer
In GetHostAddress of gxp_buffer
A vulnerability has been identified in Simcenter Femap (All versions < V2512)
Authorization Bypass Through User-Controlled Key vulnerability in Aksis Computer Services and Consulting Inc
Authorization Bypass Through User-Controlled Key vulnerability in Netiket Information Technologies Ltd
IBM Aspera Orchestrator 4
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11
A pre-authentication denial of service vulnerability exists in React Server Components versions 19
SPA-CART CMS 1
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case
Online Shopping System Advanced 1
A flaw has been found in Campcodes Supplier Management System 1