CVE-2026-73570
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
Critical vulnerabilities, curated daily for security professionals
Yesterday's disclosures were dominated by web application and browser flaws, with four Google Chrome vulnerabilities scoring 9.6 alongside a cluster of unauthenticated WordPress plugin issues at 9.8. The day produced 114 critical CVEs (up 226% from 35) and 143 high-priority CVEs (up 120% from 65), for 257 total. Notable entries include CVE-2026-18080 (CVSS 9.8) in the wedevs ERP suite for WooCommerce, CVE-2026-54569 (CVSS 9.8) in SENAITE senaite.core, and CVE-2026-34191 (CVSS 9.1) in Apache Portable Runtime Utility, a library embedded in a wide range of downstream server software. Content management and collaboration platforms carried much of the load, with ILIAS eLearning, GetGrav Grav, and Zimbra Collaboration all represented, and 10 CVEs across Zimbra, Oracle WebLogic Proxy Plug-in, Gitea, and NetScaler ADC show confirmed exploitation in the wild. Patch data was available for 0% of the set at collection time, so teams should verify vendor advisories directly and prioritize internet-facing systems.
Immediate action: Prioritize internet-facing Zimbra Collaboration, Oracle WebLogic Proxy Plug-in, Gitea, and NetScaler ADC and Gateway instances, all with confirmed exploitation, then move to Chrome and Chromium-based browser fleets and public-facing WordPress installations running wedevs ERP or Personal QR Message. Patch availability is recorded at 0% for this data set, so check vendor advisories directly for fixed versions and apply documented mitigations or access restrictions where no update exists. Inventory downstream software bundling Apache Portable Runtime Utility, since CVE-2026-34191 will require tracking fixes across multiple vendors rather than a single update.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Zimbra Collaboration (ZCS) is susceptible to remote code execution due to improper neutralization of OS commands.
An unauthenticated remote code execution vulnerability exists in Oracle WebLogic Server Proxy Plug-ins for Apache HTTP Server and IIS, potentially leading to a full system compromise.
A critical remote code execution vulnerability exists in Gitea's diffpatch feature that allows an attacker to execute arbitrary shell commands.
A memory overflow vulnerability in NetScaler ADC and Gateway appliances configured as SSL VPN, ICA, or AAA servers may lead to service disruption or Denial of Service (DoS).
A remote code execution vulnerability exists in Microsoft SQL Server due to improper handling of internal functions, allowing authenticated attackers to execute arbitrary code.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
The ERP: Complete HR, Accounting & CRM Suite plugin for WordPress is vulnerable to unauthenticated remote code execution via unrestricted file uploads in the CRM Email Connect feature.
The Personal QR Message WordPress plugin allows unauthenticated users to upload arbitrary PHP files, leading to remote code execution.
SENAITE.CORE versions 2.0.0 to 2.6.0 are vulnerable to unauthenticated remote code execution via a two-request chain involving missing authorization and unsafe evaluation in the JSON API.
A SQL injection vulnerability exists in the Apache Portable Runtime Utility via the apr_dbd_oracle provider, allowing for potential unauthorized data access or manipulation.
An unauthenticated PHP object injection vulnerability in the ILIAS Shibboleth logout endpoint allows remote code execution via unsafe deserialization of session data.
The Grav API plugin fails to properly validate API key scopes within its user management endpoints, allowing restricted API keys to perform unauthorized administrative actions against super-admin accounts.
A use after free vulnerability in the Views component of Google Chrome allows a remote attacker to achieve a sandbox escape through a crafted HTML page.
A use after free vulnerability in the ANGLE component of Google Chrome allows a remote attacker to achieve sandbox escape via a crafted HTML page.
A use after free vulnerability in the Google Chrome Audio component allows a remote attacker to perform a sandbox escape via a crafted HTML page.
A use after free vulnerability in Google Chrome's Web Authentication component allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A use after free vulnerability in the Media component of Google Chrome on Windows allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A use after free vulnerability in the Google Chrome Payments component allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Improper authentication in Azure SQL Database allows an unauthorized remote attacker to elevate privileges over a network.
Missing authorization in Microsoft Teams allows an unauthorized remote attacker to elevate privileges over a network.
An out-of-bounds write vulnerability in multiple Apple operating systems allows remote attackers to cause application termination or heap corruption via insufficient input validation.
The Product Input Fields for WooCommerce plugin allows unauthenticated attackers to upload arbitrary files, leading to potential remote code execution.
An out of bounds write vulnerability in the ANGLE component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A type confusion vulnerability in the ANGLE graphics engine allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A race condition in Google Chrome for Mac allows a remote attacker who has compromised the renderer process to perform a sandbox escape via a crafted HTML page.
An inappropriate implementation in the MHTML component of Google Chrome on Mac allows a remote attacker to achieve a sandbox escape after compromising the renderer process.
A race condition in the Google Chrome Downloads feature on macOS allows a remote attacker to achieve a sandbox escape after compromising the renderer process via a crafted HTML page.
An integer overflow vulnerability in the ANGLE graphics engine of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A sandbox escape vulnerability in Google Chrome allows a remote attacker who has compromised the renderer process to perform unauthorized actions via a crafted HTML page.
An inappropriate implementation in the Crypto component of Google Chrome on Mac allows a remote attacker to achieve a sandbox escape after compromising the renderer process via a crafted HTML page.
An out of bounds write vulnerability in the ANGLE component of Google Chrome on Android allows remote attackers to execute a sandbox escape via a specially crafted HTML page.
A vulnerability in the Google Chrome Codecs component allows a remote attacker to perform a sandbox escape through insufficient validation of untrusted input via a crafted HTML page.
KubePi versions up to 1.6.15 allow unauthenticated users to access sensitive SSO configuration endpoints, leading to potential account takeover, privilege escalation, and server-side request forgery.
A use-after-free vulnerability in the Linux kernel block layer allows memory corruption due to an improperly handled timeout timer during failed disk probe operations.
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
A use after free vulnerability in Apple operating systems allows an application to trigger unexpected system termination due to flawed memory management.
Missing authentication for a critical function in Microsoft Planetary Computer Pro (GeoCatalog) allows an unauthorized attacker to elevate privileges over a network.
Modification of assumed-immutable data in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
A path traversal flaw in the SyncFabric component of Microsoft Entra Provisioning Service allows an authorized attacker to elevate privileges over a network.
An out-of-bounds read vulnerability in Apple macOS allows unauthenticated attackers to trigger system termination or kernel memory corruption via a maliciously crafted disk image.
A path handling vulnerability in Apple macOS allows a malicious application to bypass sandbox restrictions and potentially execute unauthorized actions.
A vulnerability in multiple Apple operating systems allows an application to perform unauthorized user fingerprinting due to insufficient data protection mechanisms.
A sandbox escape vulnerability in Apple macOS, iOS, and iPadOS allows a malicious application to bypass system restrictions and potentially achieve full system compromise.
A critical authorization vulnerability in various Apple operating systems allows malicious applications to add contacts without user consent due to insufficient validation.
Apache Ranger versions 2.8.0 and earlier are susceptible to remote code execution due to a JDBC URL injection vulnerability.
A path validation vulnerability in Apple operating systems allows a malicious application to bypass sandbox restrictions and potentially achieve full system compromise.
An unauthenticated file deletion vulnerability in the Drag and Drop Multiple File Upload for WooCommerce plugin allows anonymous attackers to destroy pending order attachments via nonce manipulation.
Apache HttpComponents Client fails to properly perform TLS hostname verification when using the async HttpClient, allowing attackers to impersonate servers via valid certificates for different domains.
NebulaGraph exposes an unauthenticated HTTP service that allows remote attackers to read sensitive runtime configuration and modify internal gflags without authorization.
A SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows unauthenticated attackers to execute arbitrary code via the Backend.php component.
The Link Library WordPress plugin fails to sanitize user inputs, enabling unauthenticated attackers to execute arbitrary SQL commands against the database.
The ProSolution WP Client WordPress plugin is vulnerable to unauthenticated blind SQL injection due to improper sanitization of user-supplied parameters.
A critical SQL injection vulnerability in Apache Ranger allows unauthenticated attackers to execute arbitrary SQL commands against the backend database.
The Single Sign On For TNG WordPress plugin contains an improper authentication vulnerability that allows unauthenticated attackers to reset the passwords of arbitrary users, including administrators.
The Easy Integration for Dropbox WordPress plugin fails to perform authorization checks on AJAX actions, allowing unauthenticated attackers to manipulate files and access sensitive account information.
A privilege management flaw in the Import and export users and customers plugin allows authenticated users to escalate their privileges to administrator.
Apache Ranger versions 0.6 through 2.8 are vulnerable to a command injection flaw, allowing unauthenticated remote attackers to execute arbitrary system commands.
Apache Answer versions 2.0.1 and earlier contain an insufficient session expiration vulnerability where administrative API keys remain active after user account revocation or deletion.
A race condition in the Linux kernel OVPN subsystem allows for potential use-after-free scenarios during crypto callback cleanup, potentially leading to system instability or arbitrary code execution.
The Linux kernel libceph library contains multiple unsafe decode operations in the decode_locker function, allowing a compromised OSD to trigger slab out-of-bounds reads.
A flaw in the Linux kernel MPTCP implementation allows remote peers to trigger data inconsistency or access uninitialized memory by sending malformed DSS options with incorrect sizes.
The Linux kernel MPTCP implementation fails to correctly handle mutually exclusive suboptions, potentially allowing inconsistent or malicious suboption combinations to bypass security checks.
TarsWeb suffers from an authentication bypass vulnerability where spoofed X-Forwarded-For headers and uid parameters allow unauthenticated attackers to assume arbitrary administrative identities.
The OpenRGB network protocol is vulnerable to arbitrary file system writes, allowing unauthenticated remote or local attackers to achieve full system compromise or account takeover.
The usememos application contains an authentication flaw in the SSO handler that allows unauthenticated remote attackers to perform full account takeover by manipulating identity identifiers.
A stack recursion vulnerability exists in the apr_xml_quote_elem function of Apache Portable Runtime Utility, allowing unauthenticated attackers to trigger denial of service or information disclosure.
Apache Allura is susceptible to Server-Side Request Forgery (SSRF) via its webhooks, which may allow unauthenticated remote attackers to interact with internal network resources.
An improper input validation vulnerability in the Ubiquiti UniFi Talk Application allows unauthenticated network actors to perform command injection and gain full control of the host device.
An improper neutralization of CRLF sequences vulnerability in Ubiquiti UniFi OS allows unauthenticated network actors to bypass authentication.
An improper input validation vulnerability in the Ubiquiti UniFi Protect Application allows unauthenticated network actors to execute arbitrary commands on the host device via command injection.
An improper access control vulnerability in the Ubiquiti UniFi Access Application allows authenticated attackers with low privileges to escalate privileges on the host device.
An improper input validation vulnerability in the Ubiquiti UniFi Access Application allows authenticated low-privileged users to perform command injection on the underlying host device.
An improper input validation vulnerability in the UniFi Access Application allows authenticated low-privileged network users to achieve remote command injection on the host device.
An improper input validation vulnerability in the Ubiquiti UniFi Protect Application allows authenticated attackers with low privileges to execute arbitrary commands on the underlying host device.
An improper input validation vulnerability in the Ubiquiti UniFi Access Application allows an authenticated user to perform command injection on the host device.
An improper access control vulnerability in Ubiquiti UniFi OS allows low-privileged network users to escalate privileges and achieve full system control.
An improper access control vulnerability in Ubiquiti UniFi OS allows an attacker with low privileges to escalate their access level within the device.
An improper input validation flaw in the UniFi Protect Application allows low-privileged network users to achieve command injection on the host device.
A memory safety vulnerability in the Linux kernel TI am65-cpsw-nuss driver allows remote attackers to trigger a kernel crash via improper port ID extraction during packet reception.
A memory management flaw in the Linux kernel macvlan driver allows unauthenticated attackers to cause slab-use-after-free crashes or skb headroom underflows via improper header space reservation.
A memory management flaw in the Linux kernel ipvlan driver allows unauthenticated attackers to trigger slab-use-after-free crashes or headroom underflows, potentially leading to system instability.
A race condition exists in the Linux kernel netfilter flowtable implementation, allowing unauthenticated attackers to trigger a slab use-after-free vulnerability.
The Linux kernel SCTP implementation fails to validate cookie AUTH state, leading to potential out-of-bounds memory access and local privilege escalation.
A memory management flaw in the Ceph filesystem driver allows a kernel crash due to improper handling of journal information during filesystem reclaim operations.
A missing bounds check in the Linux kernel libceph implementation allows an out-of-bounds read, potentially leading to memory corruption or system instability.
A memory corruption vulnerability in the Linux kernel libceph component allows unauthenticated remote attackers to trigger out of bounds memory access via a corrupted osdmap.
An improper access control vulnerability in the Ubiquiti UniFi Protect AI Key allows unauthenticated network actors to escalate privileges on the affected device.
An improper input validation vulnerability in the Ubiquiti UniFi Enterprise Audio/Video Bridge allows unauthenticated remote attackers to execute arbitrary commands via command injection.
A heap-based buffer overflow in the mp_Enddisc function of FreeBSD allows unauthenticated remote attackers to cause a crash or execute arbitrary code with root privileges.
The LcpDecodeConfig function in FreeBSD fails to validate the length of endpoint discriminator options, leading to an out-of-bounds write vulnerability in ppp(8).
SGLang suffers from a remote code execution vulnerability via insecure deserialization of untrusted model weight files using the pickle module.
An improper skb length accounting vulnerability in the Linux kernel veth driver, occurring during XDP fragment adjustment, allows for memory-related exploits.
A SQL injection vulnerability in FineAdmin V1.0 allows unauthenticated remote attackers to execute arbitrary code via the field and order parameters in paginated list endpoints.
A SQL injection vulnerability in ZuraCast allows unauthenticated, remote attackers to execute arbitrary SQL statements during the backup restoration process, leading to privilege escalation.
A memory management flaw in the Linux kernel crypto cavium/cpt driver causes DMA buffer leaks and incorrect unmapping during error handling.
An IRQ-to-ring mapping error in the Linux kernel vdpa/octeon_ep driver can lead to incorrect indexing and potential memory access issues.
A logic error in the Linux kernel geneve_gro_complete function incorrectly gates Generic Receive Offload (GRO) hints, potentially leading to improper packet processing.
A route lookup error in the Linux kernel IPv4 fib implementation allows for improper error handling when CONFIG_IP_MULTIPLE_TABLES is enabled, potentially leading to unauthorized network access.
A concurrency vulnerability in the Linux kernel VXLAN driver, specifically within route_shortcircuit, allows for race conditions due to improper locking when accessing neighbor hardware addresses.
SGLang is vulnerable to unauthenticated remote code execution via a pickle deserialization flaw in the load_lora_adapter_from_tensors endpoint, allowing attackers to execute arbitrary commands.
SGLang is vulnerable to remote code execution (RCE) via a sandbox escape in the optional dumper subsystem when the DUMPER_SERVER_PORT is configured.
A memory corruption vulnerability exists in the Linux kernel IPTFS implementation where improper flag propagation leads to kernel panic or unauthorized memory access.
A double-free vulnerability exists in the Linux kernel SMB client within the SMB2_close function, which could be triggered during connection replay attempts.
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard allows authenticated attackers to execute arbitrary code as root.
A memory safety vulnerability exists in the Open vSwitch module of the Linux kernel due to improper handling of GSO packet truncation, which can lead to an integer underflow.
A flaw in the Linux kernel libceph component allows a malformed CRUSH map to trigger an out-of-bounds memory access, potentially leading to system instability or arbitrary code execution.
A multiplication overflow in the Linux kernel libceph component allows unauthenticated attackers to trigger out-of-bounds memory access via a maliciously crafted CEPH_MSG_OSD_MAP message.
A memory safety flaw in the Linux kernel Ceph filesystem driver allows an unauthenticated attacker to trigger an out-of-bounds read during snaptrace processing, potentially leading to system crashes.
A flaw in the Linux kernel SCTP implementation allows unauthenticated attackers to bypass authentication requirements, potentially leading to unauthorized data access or system compromise.
A use-after-free vulnerability in the Linux kernel AMT implementation allows remote attackers to trigger memory corruption and potential code execution.
A memory corruption vulnerability exists in the Linux kernel s390 checksum implementation, where the csum_partial function incorrectly reads from address zero instead of the provided source buffer.
A null pointer dereference vulnerability exists in the open62541 AddReferences service, allowing unauthenticated remote attackers to trigger a crash or potentially execute arbitrary code.
The ICS-Park Smart Park Management System v2.0 is vulnerable to an unrestricted file upload flaw, which allows unauthenticated remote attackers to execute arbitrary code on the system.
OpenCart v4.2.0.0 is vulnerable to a path traversal flaw during extension installation, allowing unauthenticated attackers to write arbitrary files, such as web shells, to the server webroot.
A path traversal vulnerability in the Linux kernel ksmbd implementation allows an authenticated attacker to escape the intended share root directory during file creation operations.
The libiec61850 library contains an authentication bypass vulnerability in the parseGoosePayload function that allows unauthenticated attackers to manipulate GOOSE frames.
The Serverless-Devs command line tool is vulnerable to OS command injection via the s init command, which fails to sanitize user input before passing it to an underlying shell process.
An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows unauthenticated attackers to execute arbitrary commands as root via shell metacharacter injection.
CPSD CryptoPro Secure Disk for Bitlocker fails to enforce IMA policy protections on temporary file systems, enabling the execution of unsigned code.
A command injection vulnerability in the system.upgrade_check interface allows unauthenticated attackers to execute arbitrary commands as root on multiple Cudy router models.
A side channel timing vulnerability in the apr_password_validate function allows for the potential leakage of password or hash content.
A heap buffer overflow in Google Chrome's WebGL component allows an unauthenticated, remote attacker to escape the sandbox and execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the WebGL component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
A buffer overflow vulnerability exists in the WebRTC component of Google Chrome, allowing remote attackers to execute arbitrary code via a crafted HTML page.
A buffer overflow vulnerability exists in the V8 engine of Google Chrome, allowing remote attackers to execute arbitrary code via a crafted HTML page.
A buffer overflow vulnerability in the ANGLE component of Google Chrome for Android allows remote attackers to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the Accessibility component of Google Chrome allows remote attackers to execute arbitrary code via social engineering and UI interaction.
A use after free vulnerability in the Bluetooth component of Google Chrome allows remote attackers to execute arbitrary code via crafted extensions.
A buffer overflow vulnerability in the Media component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A use after free vulnerability in the TabStrip component of Google Chrome on Mac allows a remote attacker to achieve a sandbox escape through a crafted HTML page.
A use after free vulnerability exists in the Google Chrome TabStrip component, which could allow a remote attacker to trigger heap corruption via a crafted HTML page and specific user UI interaction.
A use after free vulnerability in the Google Chrome DevTools allows a remote attacker to execute arbitrary code within the sandbox via a crafted HTML page.
A use after free vulnerability in the Views component of Google Chrome allows remote attackers to trigger heap corruption via a crafted HTML page and specific user UI gestures.
A use after free vulnerability in the Views component of Google Chrome on Windows allows a remote attacker to achieve heap corruption via a crafted HTML page and specific user UI gestures.
A use after free vulnerability in Google Chrome Views allows remote attackers to trigger heap corruption via a crafted HTML page and specific user UI gestures.
A use-after-free vulnerability in Apple iOS, iPadOS, and macOS memory management allows a remote attacker to cause an unexpected system termination.
A type confusion vulnerability in the V8 JavaScript engine of Google Chrome allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
An incorrect calculation vulnerability in the V8 engine of Google Chrome allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
A use after free vulnerability in the ANGLE component of Google Chrome allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
A type confusion vulnerability in the ANGLE component of Google Chrome allows remote attackers to potentially execute arbitrary code via a crafted HTML page.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
An integer overflow vulnerability in the WebRTC component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Google Chrome contains an improper input validation vulnerability in the Media component that allows remote code execution via a crafted HTML page.
An out of bounds read flaw in the ANGLE component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a crafted HTML page.
A vulnerability in Google Chrome DevTools allows remote attackers to execute arbitrary code within the sandbox via a crafted HTML page and social engineering.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to read memory within the sandbox via a crafted HTML page.
An out of bounds write vulnerability in the ANGLE graphics library of Google Chrome for Windows allows remote attackers to execute arbitrary code via a crafted HTML page.
A memory corruption vulnerability in the Tint component of Google Chrome for Mac allows remote attackers to execute arbitrary code via a crafted HTML page.
Google Chrome contains an improper state validation vulnerability in the Parser component, which can be exploited by a remote attacker to execute arbitrary code via a crafted HTML page.
A vulnerability in the Google Chrome ANGLE component allows a remote attacker to achieve arbitrary code execution via a specially crafted HTML page.
Google Chrome contains an improper input validation vulnerability in the Media component, which may allow remote code execution via a crafted HTML page.
A type confusion vulnerability in the Google Chrome Animation component allows remote attackers to execute arbitrary code via a crafted HTML page.
A remote code execution vulnerability exists in the Google Chrome WebGL component due to an integer overflow, allowing attackers to compromise the sandbox via a crafted HTML page.
An integer overflow vulnerability in the Chromium engine within Google Chrome allows remote attackers to read sensitive memory via a crafted file.
A type confusion vulnerability in the Google Chrome DevTools component allows remote attackers to execute arbitrary code via a crafted HTML page.
Google Chrome contains an improper input validation vulnerability in the ANGLE graphics engine on Mac, which could allow a remote attacker to execute arbitrary code via a crafted HTML page.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
An out of bounds write vulnerability in the ANGLE component of Google Chrome on Windows allows remote code execution via a crafted HTML page.
A Content Security Policy (CSP) bypass vulnerability exists in Apple Safari and related operating systems, allowing malicious web content to bypass security restrictions via the AudioWorklet interface.
The Order Tip for WooCommerce plugin lacks capability checks and path restrictions, allowing authenticated users with Shop Manager privileges to delete arbitrary files on the server.
The SunEditor Embed plugin fails to sanitize raw HTML input, leading to stored or reflected cross-site scripting (XSS) via injected script elements.
A vulnerability in Apple macOS allows a remote, unauthenticated attacker to trigger a denial of service condition through insufficient input validation.
A race condition in the V8 engine of Google Chrome prior to version 151.0.7922.72 allows an unauthenticated remote attacker to execute arbitrary code within a sandbox via a malicious HTML page.
The MStore API WordPress plugin fails to validate authorization for product review creation, allowing unauthenticated attackers to submit fraudulent reviews on behalf of verified owners.
An inappropriate implementation in the Google Chrome File Input component on Linux allows a remote attacker to achieve a sandbox escape via a crafted HTML page.
Google Chrome contains a vulnerability in the Dawn component where insufficient input validation allows a remote attacker to potentially escape the browser sandbox via a crafted HTML page.
Google Chrome contains a flaw in WebUI input validation that allows an unauthenticated remote attacker to potentially escape the browser sandbox via malicious network traffic.
An inappropriate implementation in the Google Chrome Updater for Mac allows local attackers to achieve OS-level privilege escalation by leveraging a malicious file.
A heap buffer overflow vulnerability exists in the Base component of Google Chrome, allowing for potential heap corruption through a specially crafted malicious extension.
A use after free vulnerability in Google Chrome Extensions allows a remote attacker to execute arbitrary code within a sandbox by convincing a user to install a malicious extension.
An integer overflow vulnerability in Apple's ImageIO framework allows an unauthenticated, remote attacker to achieve arbitrary code execution via a maliciously crafted image file.
A race condition vulnerability in the Google Chrome Updater for Windows allows a local attacker to achieve privilege escalation by leveraging a malicious file.
A link following vulnerability in the CredentialProvider of Google Chrome for Windows allows a local attacker to execute arbitrary code outside the sandbox.
The ics-park Smart Park Management System v2.0 contains an insecure permissions vulnerability allowing low-privileged users to escalate privileges via specific API endpoints.
The CheckView WordPress plugin fails to properly validate REST API authentication, allowing unauthenticated attackers to bypass nonce checks and perform administrative actions via cross-site request forgery.
A vulnerability in Apple software allows websites to determine if a user has previously visited a specific link, potentially compromising user privacy through unauthorized history tracking.
An out-of-bounds access vulnerability in Apple software allows for application crashes when processing maliciously crafted web content.
A memory corruption vulnerability in Apple operating systems allows attackers to compromise system integrity and availability through maliciously crafted images.
A memory handling vulnerability in multiple Apple operating systems allows a malicious application to cause unexpected system termination or corrupt kernel memory, leading to potential system compromise.
An out-of-bounds read vulnerability in Apple macOS allows for application termination or potential information disclosure when processing maliciously crafted files.
A stack overflow vulnerability in Apple macOS allows a local application to trigger a denial of service condition due to insufficient input validation.
An out-of-bounds write vulnerability in various Apple operating systems allows a local application to trigger a denial-of-service condition due to improper bounds checking.
A missing capability check in the Admin Safety Guard WordPress plugin allows unauthenticated attackers to exfiltrate sensitive user data, including usernames, emails, roles, and 2FA status.
The WP Directory Kit WordPress plugin fails to perform authorization checks on AJAX actions, allowing authenticated users to disclose sensitive settings, including API keys and secrets.
Dell PowerProtect One contains an OS Command Injection vulnerability that allows a low privileged, remote attacker to execute arbitrary commands on the affected system.
Dell PowerProtect One is susceptible to an OS command injection vulnerability, allowing authenticated, low-privileged remote attackers to execute arbitrary code.
Z-BlogPHP 1.7.5 contains a SQL injection vulnerability in the CommentBat feature that allows authenticated attackers to execute arbitrary SQL commands via the id parameter.
A remote unauthenticated attacker can trigger a denial of service in Apache IoTDB by sending a crafted Thrift frame, causing excessive memory allocation and an OutOfMemoryError crash.
A SQL injection vulnerability in the Hospital Management System 4.0 allows unauthenticated attackers to execute arbitrary SQL commands via the editid parameter in doctor/edit-patient.php.
Sourcecodester CASAP Automated Enrollment System 1.0 contains a SQL injection vulnerability in the update_password.php script, allowing unauthenticated attackers to inject malicious database queries.
Sourcecodester CASAP Automated Enrollment System 1.0 contains a SQL injection vulnerability in the update_student.php script, allowing unauthenticated attackers to inject malicious database queries.
A heap-based buffer overflow in the Apache Portable Runtime Utility memcached client allows for potential denial of service via unauthenticated network access.
The WP Data Access WordPress plugin is vulnerable to unauthenticated information exposure via improper validation of AJAX action parameters, allowing attackers to read arbitrary database table columns.
The Import WP WordPress plugin contains an authorization bypass vulnerability in its export-file download handler, allowing unauthenticated attackers to access sensitive export files.
The WP Photo Album Plus plugin allows unauthenticated users to read sensitive autoloaded options due to missing capability checks and insecure input handling in a public endpoint.
The PowerPress Podcasting plugin fails to validate Podcast Episode URLs, allowing authenticated users with Contributor roles or higher to perform Server-Side Request Forgery against internal services.
SGLang suffers from a credential leakage vulnerability in the /server_info endpoint, which exposes API keys and SSL keyfile information to unauthenticated network users.
An unauthenticated vulnerability in Apache JSPWiki allows attackers to perform arbitrary wiki markup rendering to access sensitive data stored in internal variables.
Apache Lucy is vulnerable to uncontrolled recursion, which may lead to a denial of service condition. As the project is retired, no official patches will be released.
Apache Lucy is vulnerable to a memory allocation flaw involving excessive size values, which can lead to denial of service. The project is retired and no security patches will be released.
An unauthenticated attacker can trigger a denial of service in Apache Qpid Broker-J by exploiting improper resource allocation limits during type size or count handling.
A pre-authentication vulnerability in Apache Qpid Broker-J allows remote attackers to trigger resource exhaustion and denial of service via unbounded symbol value caching.
A vulnerability in Plesk allows remote authenticated users to disclose arbitrary local files and escalate their privileges through improper neutralization of special elements in the DNS management module.
An improper symlink resolution vulnerability in Plesk Migrator and Site Import extensions allows authenticated users to execute arbitrary code as the root user.
A missing authorization vulnerability in one-api allows authenticated users to pin arbitrary channels via URL parameters, bypassing intended access controls and model allowlists.
A heap-based buffer overflow vulnerability exists in the Apache Portable Runtime Utility redis client, potentially allowing for denial of service.
A local privilege escalation vulnerability in TCG TPM 2.0 reference code allows attackers to falsify TPM keys and attestations by obtaining unauthorized credentials from a TPM-aware CA.
Grocy contains a cross-site scripting vulnerability within its API request-body parser, which could allow authenticated attackers to execute malicious scripts in the context of a user session.
A vulnerability in the amqp091-go client allows a malicious AMQP broker to trigger resource exhaustion by bypassing frame size limits, leading to potential denial of service.
The whichllm utility before 0.5.16 is vulnerable to code injection in the run and snippet commands, allowing remote attackers to execute arbitrary code via malicious HuggingFace repository filenames.
A race condition in the Linux kernel s390 vfio_ccw driver allows for improper synchronization of asynchronous hardware events, potentially leading to unauthorized system impact.
A race condition in the Linux kernel s390 vfio_ccw driver allows local attackers with low privileges to potentially achieve full system compromise via improper mutex handling.
A boundary check vulnerability exists in the Linux kernel s390 vfio_ccw driver, where improper index validation for read/write regions could allow local attackers to trigger memory corruption.
The Linux kernel s390 vfio_ccw driver fails to properly cancel workqueues during device release, potentially leading to use-after-free conditions and arbitrary code execution.
A vulnerability in the Linux kernel amdgpu driver allows local users to trigger memory corruption via oversized Indirect Buffer submissions, potentially leading to system instability or privilege escalation.
TarsWeb fails to enforce authorization checks on multiple PatchController methods, allowing authenticated users to manipulate and deploy patches for applications they do not own.
A command injection vulnerability in TeamViewer for Linux allows remote attackers to execute arbitrary commands via a specially crafted URL sent through the out-of-session chat feature.
A path traversal vulnerability in the OPSWAT tarball component of the SonicWall NetExtender Linux client allows an unauthenticated attacker to write arbitrary files with root privileges.
Penpot is vulnerable to stored cross-site scripting (XSS) via file comments, allowing authenticated attackers to execute arbitrary scripts in the browsers of other collaborators.
SeaweedFS S3 API fails to enforce IAM role trust policies when processing external OIDC JWT tokens, allowing authenticated federated users to assume unauthorized roles and access S3 objects.
Multiple TP-Link Kasa smart devices are vulnerable to unauthorized control due to insufficient cryptographic protections in the local communication protocol, allowing message interception or forgery.
LibreNMS versions 21.6.0 through 26.4.x are vulnerable to command injection in the Signal alert transport, allowing authenticated administrators to execute arbitrary operating-system commands.
A vulnerability in the Plesk database management interface allows authenticated users to perform unauthorized read and write operations on databases belonging to other customers.
The LogTape library fails to sanitize control characters and validate structured data keys in its syslog package, allowing for log injection and SIEM integrity compromise.
Resamania Virtuagym contains a hard-coded credential vulnerability that allows unauthorized users to generate valid physical access QR codes via the API.
A vulnerability in Veeam ONE allows a low-privileged user to capture NTLM credentials from the Reporter service account, potentially leading to unauthorized system access.
An unauthenticated remote attacker can trigger a StackOverflowError in Apache Qpid Proton-J through malicious type nesting, resulting in a denial of service condition.
An unauthenticated attacker can exploit uncontrolled recursion via type nesting to trigger a StackOverflowError, resulting in a denial of service in Apache Qpid Proton Dotnet.
A resource exhaustion vulnerability in Apache Qpid ProtonJ2 allows an attacker to cause a denial of service by sending excessive transfer frames.
A pre-authentication vulnerability in Apache Qpid Proton-J allows remote attackers to trigger resource exhaustion and denial of service via unbounded symbol value caching.
An unauthenticated attacker can trigger a denial of service in Apache Qpid Proton-J by exploiting improper memory allocation handling, which allows for excessive resource consumption.
An unauthenticated attacker can trigger resource exhaustion in Apache Qpid Proton Dotnet by exploiting unbounded symbol value caching, resulting in a denial of service.
A pre-authentication denial of service vulnerability in Apache Qpid Proton Dotnet allows attackers to trigger excessive memory allocation via manipulated type size or count values.
An unauthenticated attacker can trigger resource exhaustion in Apache Qpid ProtonJ2 via unbounded symbol value caching, resulting in a denial of service.
A memory allocation vulnerability in Apache Qpid ProtonJ2 allows unauthenticated attackers to trigger a denial of service via excessive memory consumption.
SGLang is vulnerable to unauthenticated model weight exfiltration due to missing authorization checks on internal endpoints, allowing remote attackers to trigger unauthorized distributed data transfers.
Data::Entropy for Perl transmits remote entropy data over plain HTTP, allowing on-path attackers to perform interception and substitution of random values.
PacketFence version 13.2.0 contains a vulnerability in the WebGui interface that permits authenticated users to achieve remote code execution.
A memory handling error in the Linux kernel smb/client module allows for a potential system crash via an invalid pointer dereference.
A Time of Check to Time of Use (TOCTOU) vulnerability in the Linux kernel AMDGPU VCN driver allows local attackers to potentially gain escalated privileges or cause system instability.
A use-after-free vulnerability in the Linux kernel IUCV subsystem allows for potential memory corruption and system instability due to improper handling of severed connection paths.
A deserialization vulnerability in SonicWall GMS allows a local attacker to execute unauthorized actions due to insecure handling of serialized objects.
A slab-out-of-bounds read vulnerability in the Linux kernel ksmbd module allows unauthenticated remote attackers to trigger a denial of service via a crafted SMB2 compound request.
A Server-Side Request Forgery vulnerability in the usememos Webhook validation mechanism allows remote authenticated attackers to access internal network resources.
A buffer overflow vulnerability exists in the Linux kernel btrfs filesystem during v1 free space cache loading, caused by missing validation of on-disk header counts.
A double free vulnerability in the Linux kernel mac80211 subsystem allows local attackers to trigger memory corruption and potential system instability.
A memory management flaw exists in the Linux kernel mac80211 wireless subsystem, where a double free condition occurs during FILS discovery template allocation failures.
A use-after-free vulnerability exists in the Linux kernel mac80211 subsystem, occurring when a virtual interface update fails and leaves dangling debugfs entries pointing to freed memory.
A double socket release vulnerability exists in the Linux kernel BPF TCP iterator due to improper handling of realloc failures, potentially allowing for memory corruption or system crashes.
A race condition in the Broadcom BDC UDC driver allows a local attacker to trigger a null pointer dereference or use-after-free by exploiting an incorrectly managed interrupt handler during teardown.
A use-after-free vulnerability in the Linux kernel usb gadget f_midi driver allows local users to trigger memory corruption and potential code execution by race condition during object cleanup.
A use-after-free vulnerability exists in the Linux kernel esd_usb driver due to incorrect ordering of teardown operations during device disconnection.
A data race vulnerability in the Linux kernel fuse-uring subsystem allows local attackers to potentially achieve arbitrary code execution or privilege escalation via stale memory access.
A double-free vulnerability in the Linux kernel Amlogic crypto driver allows local attackers to trigger memory corruption and potential system instability.
A redundant USB anchor call in the ALSA us144mkii driver causes anchor list corruption and use-after-free, potentially leading to local system compromise.
A trust boundary violation in the Imagination Technologies Graphics DDK allows a local attacker to corrupt GPU firmware data by manipulating pointers stored in non-secure memory.
A buffer handling flaw in the Linux kernel GTP implementation allows unauthenticated remote attackers to trigger a kernel panic via malformed echo request packets.
A vulnerability in the Imagination Technologies Graphics DDK allows non-privileged users to perform improper GPU system calls, leading to kernel memory out of bounds read and potential use after free.
A race condition in the Linux kernel ARC EMAC driver allows local attackers to trigger spurious interrupts during device teardown, potentially leading to unauthorized system state manipulation.
A vulnerability in Vim Project v9.2.0389 and earlier allows local attackers to achieve arbitrary code execution via the vms_fixfilename function in src/os_vms.c.
A flaw in the CFDP receive path of NASA cFS v7.0.1 allows unauthenticated attackers to cause a Denial of Service through the replay of final CFDP PDUs.
A parser boundary flaw in the Software Bus Network application of NASA cFS v7.0.1 allows unauthenticated remote attackers to cause a Denial of Service via a crafted packet.