CVE-2025-62593
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Remote code execution and authentication bypass flaws in widely deployed WordPress plugins and open-source libraries led yesterday's disclosures, with the jahlives openssl_encrypt library accounting for four separate CVSS 9.8 issues. Critical CVEs rose to 42 from 10 the prior day (up 320%), while high-priority CVEs fell to 95 from 104 (down 9%). Notable entries include CVE-2026-15038 (CVSS 9.8) in InfiniteWP Client, CVE-2026-15748 (CVSS 9.8) in the wpmudev Forminator Forms plugin, and CVE-2026-75045 (CVSS 9.1) in JetBrains YouTrack. Collaboration and developer tooling were also affected, with CVE-2026-55674 (CVSS 9.3) in Discourse and CVE-2026-66795 (CVSS 9.1) in Red Hat Multicluster Engine for Kubernetes. Two CVEs have confirmed active exploitation, and vendor patch data was unavailable for the full set at publication, so treat internet-facing WordPress installations and developer platforms as the priority for verification against vendor advisories.
Immediate action: Prioritize internet-facing WordPress deployments running InfiniteWP Client or Forminator Forms, along with JetBrains YouTrack, Discourse, and Red Hat Multicluster Engine for Kubernetes instances. Windows endpoints should be checked for the WinSock AFD issue and Ray clusters for the Ray-Project flaw, both of which are under active exploitation. Patch availability was reported at 0% for this set, so confirm fixed versions against vendor advisories and apply available mitigations or access restrictions where updates are not yet published.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
A use-after-free vulnerability in the Microsoft Windows Ancillary Function Driver for WinSock is currently being exploited in the wild.
The jahlives openssl_encrypt package contains hardcoded database credentials in standalone configuration files, allowing unauthorized network access to PostgreSQL databases.
Discourse is vulnerable to reflected cross-site scripting (XSS) via crafted cookies, allowing unauthenticated attackers to execute arbitrary JavaScript in the browsers of visitors.
SiYuan versions before 3.7.4 are vulnerable to stored cross-site scripting due to missing security headers when serving user-uploaded assets, allowing script execution in the context of the owner.
The InfiniteWP Client WordPress plugin fails to verify request authenticity, allowing unauthenticated attackers to hijack administrator sessions and achieve remote code execution.
The Forminator Forms plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads via the handle_file_upload function, potentially leading to remote code execution.
JetBrains YouTrack is vulnerable to unauthorized database backup downloads by unauthenticated attackers due to an issue with shared draft signatures.
The openssl_encrypt library contains an authentication bypass in the verify_api_token function, allowing unauthenticated attackers to manipulate user public keys and revoke credentials via Bearer tokens.
Improper validation of Certificate Signing Requests in the managedcluster-import-controller allows privileged service accounts to escalate privileges and obtain administrative hub credentials.
The openssl_encrypt library exposes sensitive refresh tokens in URL query parameters, leading to potential token leakage via server logs, proxy logs, and browser history.
The openssl_encrypt library contains a cryptographic flaw in pqc.py where decryption failures trigger an insecure fallback to unauthenticated AES-CTR mode, enabling bit-flipping attacks.
An input validation flaw in the acm-search-v2-rhel9 component allows authenticated attackers to perform OS command or SQL injection, potentially leading to arbitrary code execution.
The FoodBoxBooker WordPress plugin fails to validate password reset requests, enabling unauthenticated attackers to reset passwords for any user, including administrators.
A stack-based buffer overflow in the Wavlink Export Pingortrace CGI function allows unauthenticated remote attackers to execute arbitrary code via a malicious HTTP_COOKIE.
A permission boundary bypass in Frappe leads to server-side template injection and remote code execution in ERPNext due to improper handling of the frappe.render_template function.
An arbitrary code execution vulnerability exists in the Whirlpool hash implementation of jahlives openssl_encrypt, caused by insecure loading of shared object files via broad glob patterns.
A schema validation bypass vulnerability in openssl_encrypt allows attackers to process malicious data by manipulating the jsonschema dependency or supplying unknown metadata formats.
A cryptographic signature verification bypass in openssl_encrypt allows attackers to encrypt sensitive data using arbitrary public keys by abusing the PublicKeyBundle.from_dict method.
The TOTP rate-limiting mechanism in openssl_encrypt is vulnerable to bypass because it uses local, non-persistent memory that is easily reset or distributed across multiple server instances.
A plugin sandbox bypass vulnerability exists in jahlives openssl_encrypt before version 1.4.0, allowing unauthenticated attackers to execute arbitrary code via malicious module imports.
A cryptographic weakness in jahlives openssl_encrypt before version 1.4.0 allows for predictable key derivation due to improper HKDF implementation.
A failure in process isolation within jahlives openssl_encrypt before version 1.4.0 allows malicious plugins to bypass sandbox restrictions and gain full system access.
A sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer allows unauthenticated attackers to execute arbitrary system commands by bypassing dunder attribute traversal restrictions.
A sandbox escape vulnerability in the IsolatedPluginExecutor allows unauthenticated attackers to access Python type objects, facilitating arbitrary command execution through class hierarchy traversal.
A critical cryptographic flaw exists where KEM decapsulation failures trigger a deterministic simulation mode, allowing attackers to decrypt ciphertext if private key fragments are obtained.
MemOS suffers from an authentication bypass vulnerability due to an incorrect comparison in the middleware, allowing unauthenticated remote attackers to gain full administrative access.
Onyx is vulnerable to sensitive information exposure because it incorrectly stores and leaks per-user OAuth tokens to unauthorized users through shared configuration records.
A code injection vulnerability in GitLab allows unauthenticated remote attackers to modify or delete public projects and user data via a malicious GraphQL directive.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
SiYuan versions before 3.7.4 expose unauthenticated Go debug endpoints, allowing remote attackers to extract sensitive in-memory data such as API keys and authentication codes.
A critical OS command injection vulnerability exists in the COMFAST CF-N1-S CGI interface, allowing authenticated attackers to execute arbitrary system commands.
The joomlack.fr Page Builder CK extension for Joomla versions prior to 3.6.5 is vulnerable to SQL injection in the styles model, allowing unauthenticated attackers to compromise database integrity.
A SQL injection vulnerability in the store() functions of StudIP allows remote unauthenticated attackers to execute arbitrary code and retrieve sensitive information.
The Regular Labs Sourcerer extension for Joomla is vulnerable to unauthenticated remote code execution due to improper handling of reflected user input within rendered HTML blocks.
A sandbox escape vulnerability in the vm2 library allows attackers to bypass security restrictions and execute arbitrary host commands by manipulating Error.cause.
A privilege escalation vulnerability in the multicloud-operators-subscription component allows users to deploy resources with elevated permissions via crafted Subscription annotations.
The vm2 sandbox for Node.js fails to block prototype chain manipulation, allowing unauthenticated attackers to escape the sandbox and execute arbitrary host commands.
T-Systems International GmbH ImageMaster version 9.14.2.8.1 contains a file upload vulnerability in the add attachments feature, allowing remote unauthenticated attackers to execute arbitrary code.
The fakefish component in openshift-metal3 fails to perform credential validation when used with KubeVirt, allowing unauthorized cluster users to control virtual machines.
OpnForm uses predictable Hashids with an empty salt for submission secrets, allowing unauthenticated attackers to read or overwrite sensitive respondent data.
A vulnerability exists in Logsign SIEM involving insufficiently protected credentials, which allows an authenticated attacker with high privileges to retrieve sensitive embedded data.
An integer overflow vulnerability in QuantumNous new-api allows unauthenticated attackers to manipulate billing calculations and gain unauthorized account credits.
An information disclosure vulnerability in QuantumNous new-api allows authenticated administrators to retrieve sensitive bearer tokens for the root user.
The Squeeze WordPress plugin allows authenticated authors to upload malicious PHP files due to insufficient file type validation, enabling remote code execution.
A critical remote code execution vulnerability in WordPress allows authenticated users with Author-level privileges to upload malicious Postscript files.
A memory safety vulnerability in the Zephyr RTOS flash_copy system call allows local attackers to achieve unauthorized memory access.
A cross-site scripting vulnerability in Legora allows arbitrary JavaScript execution via malicious Mermaid blocks in front-matter directives.
phpIPAM is vulnerable to an authorization bypass allowing unauthorized access to subnet information due to improper validation of user-controlled keys.
The Evidently UI contains a path traversal vulnerability in the dataset materialization endpoint that allows unauthenticated access to arbitrary files.
An integer overflow was addressed with improved input validation.
The issue was addressed with improved memory handling.
The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.
A permissions issue was addressed with additional sandbox restrictions.
An out-of-bounds read was addressed with improved bounds checking.
HP Web Jetadmin is susceptible to a DLL hijacking vulnerability that allows unauthenticated actors to read or write arbitrary files on the system.
A privilege management flaw in the search-v2-operator of Red Hat Advanced Cluster Management for Kubernetes may lead to unauthorized privilege escalation.
The WPAdverts plugin for WordPress contains an authorization bypass vulnerability allowing unauthorized information disclosure.
Dell ObjectScale is vulnerable to OS command injection, allowing a local authenticated attacker to execute arbitrary system commands.
Dell ObjectScale contains an OS command injection vulnerability that permits a local authenticated attacker to execute arbitrary system commands.
The File Manager WordPress plugin before 6.9.1 fails to properly authorize file management commands, allowing authenticated users to read or delete arbitrary files on the server.
A vulnerability in faye websocket-driver-ruby allows an unauthenticated attacker to cause a denial of service via an uncaught exception.
The openssl_encrypt package contains an authorization bypass vulnerability allowing authenticated users to manipulate keys, potentially leading to unauthorized data access or modification.
A protection mechanism failure in openssl_encrypt allows for sandbox escapes through pathlib and I/O manipulations, potentially enabling unauthorized system access.
The openssl_encrypt package contains a hard-coded credential vulnerability that allows authenticated attackers to forge JWT tokens and bypass security controls.
The sqlparse Python module is vulnerable to algorithmic complexity and inefficient regular expression issues that can lead to denial of service through resource exhaustion.
The sqlparse Python module is susceptible to uncontrolled resource consumption and inefficient algorithmic complexity, which can be triggered by providing complex, malformed SQL queries.
The sqlparse Python module contains a vulnerability involving inefficient regular expression complexity that can be leveraged by an unauthenticated attacker to cause a denial of service.
The openssl_encrypt library uses a cryptographically weak pseudo-random number generator, which may compromise the security of encrypted data.
A vulnerability in openssl_encrypt allows for the disclosure of sensitive information through verbose error messages.
The openssl_encrypt library fails to sufficiently verify data authenticity, potentially allowing for the processing of malicious or tampered data.
The jahlives openssl_encrypt library is susceptible to a path traversal vulnerability due to improper input validation, allowing unauthenticated attackers to access unauthorized files.
The jahlives openssl_encrypt library uses non-standard, weak PBKDF2 key derivation practices, which may allow unauthenticated attackers to compromise encrypted data.
The jahlives openssl_encrypt library contains hard-coded credentials, which could allow an unauthenticated attacker to gain unauthorized access to protected system functions.
2100 Technology Official Document Management System contains an arbitrary file upload vulnerability allowing authenticated remote attackers to execute arbitrary code via web shell backdoors.
The decolua 9router AI router application is susceptible to missing authentication for critical functions and server-side request forgery, allowing unauthenticated remote attackers to interact with the system.
Stirling-PDF versions prior to 2.9.0 contain vulnerabilities related to the exposure of sensitive information and insufficient protection of credentials, potentially allowing unauthorized data access.
Rapid7 Velociraptor contains a vulnerability in its web GUI related to improper URL encoding handling, which could allow for unauthorized actions or information disclosure.
Stirling-PDF contains a cross-site scripting vulnerability that allows attackers to execute arbitrary scripts in the context of a user session.
Red Hat OpenShift AI contains a privilege assignment flaw in its maas-api and maas-controller ServiceAccounts that grants excessive cluster-wide permissions.
QuantumNous new-api is vulnerable to uncontrolled resource consumption, allowing unauthenticated attackers to trigger a denial of service via excessive resource allocation.
PostCSS is susceptible to a path traversal vulnerability that allows unauthenticated attackers to access restricted directories by manipulating CSS file paths.
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated access to report data and share tokens.
Crawlab contains a critical authorization bypass vulnerability that allows authenticated users to reset the passwords of other accounts, including administrative users.
SkyPilot contains a privilege management vulnerability that allows authenticated users to improperly grant administrator roles when updating service account permissions.
Glances is susceptible to OS command injection, allowing an attacker to execute arbitrary commands on the host system via improper neutralization of special elements.
Glances is vulnerable to an OS command injection flaw that allows local attackers to execute arbitrary system commands due to improper input handling.
Roundcube Webmail versions prior to 1.6.18 and 1.7.3 are vulnerable to OS command injection, allowing authenticated attackers to execute arbitrary system commands.
The vm2 sandbox library for Node.js is vulnerable to resource exhaustion due to insufficient limits on resource allocation, potentially leading to denial of service.
The SiYuan kernel is vulnerable to path traversal, allowing an authenticated administrator to read or manipulate files outside of the intended directory.
Budibase is affected by a combination of Time-of-check Time-of-use (TOCTOU) race conditions and Server-Side Request Forgery (SSRF) vulnerabilities.
Budibase is susceptible to an SQL injection vulnerability that can be triggered by an authenticated administrative user.
The compliance-trestle platform is vulnerable to multiple path traversal flaws, allowing unauthorized access to files outside of restricted directories.
JetBrains PyCharm contains a missing authentication vulnerability that may allow unauthorized access to sensitive functionality.
Mattermost contains an incorrect authorization vulnerability that allows authenticated users to perform unauthorized actions.
The deskflow keyboard and mouse sharing application contains an out-of-bounds read vulnerability that may lead to system instability or information disclosure.
Deskflow is susceptible to out of bounds read and improper validation of array index vulnerabilities, which could allow for remote denial of service.
A stored cross-site scripting vulnerability exists in JetBrains YouTrack, allowing remote attackers to execute arbitrary scripts in the context of a user session.
SiYuan is vulnerable to OS command injection, which can lead to local privilege escalation when leveraging the elevator executable.
SiYuan is susceptible to a cross-site websocket hijacking vulnerability due to an origin validation error. This flaw allows unauthorized interaction with the application via malicious network proxies.
Notepad++ is vulnerable to a path traversal attack, which allows an attacker to bypass directory restrictions. This vulnerability could lead to unauthorized file manipulation or system impact.
JetBrains YouTrack is affected by an access control vulnerability. This flaw allows authenticated users to perform unauthorized actions, leading to potential data or system compromise.
JetBrains YouTrack prior to version 2026.2.17917 contains a missing authorization vulnerability (CWE-862) that allows authenticated users to perform unauthorized actions.
The extract-zip package is vulnerable to path traversal and improper link resolution, which can allow attackers to overwrite arbitrary files when processing maliciously crafted zip files.
Dokploy versions prior to 0.29.6 are vulnerable to improper privilege management, allowing authenticated users to perform unauthorized actions.
Progress ShareFile Storage Zones Controller contains a deserialization of untrusted data vulnerability that could lead to unauthorized system impact.
FreeCAD contains an eval injection vulnerability that allows attackers to execute arbitrary code via malicious project files.
FreeCAD contains a second eval injection vulnerability that allows attackers to execute arbitrary code via malicious project files.
Notepad++ is vulnerable to stack-based buffer overflow and out-of-bounds write issues that could lead to arbitrary code execution if a user opens a specially crafted file.
JetBrains IntelliJ IDEA is susceptible to an OS command injection vulnerability, which may allow an attacker to execute unauthorized commands on the underlying system.
The UpTrain platform contains an improper authentication vulnerability that could allow unauthenticated attackers to gain unauthorized access to dashboard functionality.
The fakefish component in openshift-metal3 is vulnerable to OS command injection due to improper shell variable quoting in various scripts.
Stoatchat contains a missing authorization vulnerability that allows authenticated users to perform unauthorized actions.
ERPNext is susceptible to SQL injection, allowing authenticated users to manipulate database queries through improper neutralization of special elements.
Typemill is susceptible to an authorization bypass vulnerability, allowing unauthenticated attackers to access and download sensitive media files via the file download route.
The SWE-agent trajectory inspector component is vulnerable to a path traversal attack, which could allow an unauthenticated attacker to read arbitrary files from the underlying server.
Netatalk is affected by an integer underflow vulnerability in its file server suite, which could potentially be leveraged to compromise the confidentiality, integrity, and availability of the system.
An out-of-bounds read vulnerability in the TIER IV Nebula Vlp32Decoder::unpack function allows unauthenticated remote attackers to process malformed UDP datagrams.
COVESA Open1722 contains a numeric truncation error in the ACF CAN listener, which may lead to unauthorized stack memory disclosure.
The Netty framework is susceptible to uncontrolled resource consumption, which can lead to denial of service through improper handling of network events.
Belledonne Communications bcg729 contains an out-of-bounds read vulnerability that may lead to service disruption.
COVESA Open1722 is susceptible to a stack-based buffer overflow that could allow for unauthorized code execution or system instability.
The indiserver component within the INDI library contains a stack-based buffer overflow vulnerability during XML tag parsing.
A missing authorization vulnerability in Dolusoft Sonlogger allows unauthenticated attackers to access restricted application functionality.
A missing authorization vulnerability in Dolusoft Fortilogger allows unauthenticated attackers to access restricted system functions.
SiYuan Note is vulnerable to brute-force attacks due to improper restriction of excessive authentication attempts in the publish service.
UpTrain is susceptible to an injection vulnerability due to improper neutralization of special elements in output used by a downstream component.
UpTrain contains an injection vulnerability resulting from improper neutralization of special elements in data processed by downstream components.
UpTrain is affected by an injection vulnerability where special elements in output are not properly neutralized before being passed to a downstream component.
A command injection vulnerability in GL.iNet firmware allows authenticated attackers to execute arbitrary system commands via the firewall configuration interface.
A command injection vulnerability in GL.iNet firmware allows authenticated attackers to execute arbitrary code via the Wi-Fi timer or power schedule cron jobs.
A code injection vulnerability in GL.iNet firmware allows authenticated attackers to execute arbitrary code via the language auto-update cron functionality.
A command injection vulnerability exists in the Edimax EW-7478APC router, potentially allowing an authenticated attacker to execute arbitrary system commands.
In the Linux kernel, the following vulnerability has been resolved: sched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT RT migration is done aggressively.
In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module().
In the Linux kernel, the following vulnerability has been resolved: mfd: cros_ec: Delay dev_set_drvdata() until probe success If ec_device_probe() fails, cros_ec_class_release releases memory for the cros_ec_dev structure.
This CVE entry was originally reported as a use-after-free vulnerability in the SQLite JSON module but has since been withdrawn by the CVE Numbering Authority.
The ACME mini_httpd web server contains a denial of service vulnerability in its HTTP header parser within the handle_request function.
An issue was discovered in OpenSBI 1.