CVE-2023-49105
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
Critical vulnerabilities, curated daily for security professionals
Hewlett Packard Enterprise leads the day's disclosures with two maximum-severity flaws in Fabric Composer (CVE-2026-76657 and CVE-2026-76658, both CVSS 10) alongside a CVSS 9.8 issue in AOS-CX network switches. Critical CVEs fell 36% to 28 from the prior day's 44, while high-priority CVEs rose 31% to 105, for a total of 133 disclosed vulnerabilities. Other notable critical entries include CVE-2026-84119 and CVE-2026-84121 affecting Mozilla Firefox and Thunderbird (CVSS 9.6), CVE-2026-84372 in the Predis PHP Redis client (CVSS 9.8), and CVE-2026-84480 in the WWBN AVideo platform (CVSS 9.8). Network management, browser, and WordPress plugin ecosystems account for much of the critical volume, with SigmaForms Pro and the Amelia booking plugin both carrying CVSS 9.8 ratings. Nine CVEs have confirmed active exploitation, including PaperCut MF/NG and JFrog Artifactory; with patch availability at 0% across the set, teams should verify vendor advisories directly and prioritize compensating controls for exposed systems.
Immediate action: Prioritize HPE Fabric Composer and AOS-CX deployments, Mozilla Firefox and Thunderbird installations, and internet-facing PaperCut MF/NG and JFrog Artifactory instances given confirmed exploitation. Patch availability is reported at 0% for this set, so check vendor advisories directly for fixes released since disclosure and restrict network access to affected management interfaces until updates are applied.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
An authentication bypass in ownCloud core allows unauthenticated attackers to access, modify, or delete files if the victim username is known and no signing key is configured.
An improper memory calculation vulnerability exists in the Linux kernel's IPv6 paged-allocation path, potentially leading to memory corruption.
Ajax.NET Professional is vulnerable to deserialization of untrusted data, which can be exploited by unauthenticated attackers to achieve remote code execution.
A race condition in the Red Hat Libuser userhelper program allows local users to cause a denial of service by corrupting the system password file.
The ABRT tool contains a local privilege escalation vulnerability via symlink attacks on predictable file names in /var/tmp or /var/spool, allowing authenticated local users to gain root privileges.
A critical out-of-bounds memory write vulnerability exists in the Linux kernel watch_queue event notification subsystem, allowing local users to gain elevated privileges or cause a system crash.
An authenticated user can perform path traversal to write data outside the intended Docker cache directory in JFrog Artifactory due to improper input validation.
PaperCut MF and NG are vulnerable to unsafe dynamic class loading in database utilities, allowing attackers to execute arbitrary Java bytecode via manipulated system configuration parameters.
An improper access control flaw in PaperCut MF/NG allows unauthenticated remote attackers to modify system configurations by bypassing validation checks for administrative functions.
The SigmaForms Pro WordPress plugin is vulnerable to unauthenticated arbitrary file deletion via path traversal, which can lead to remote code execution.
A critical vulnerability in the HPE Fabric Composer SSH daemon allows unauthenticated remote attackers to achieve full administrative system compromise via arbitrary command execution.
A vulnerability in the Lutece Core XSL export module allows authenticated administrators to achieve remote code execution via malicious XSL stylesheets.
WWBN AVideo fails to validate password recovery token expiration, allowing unauthenticated attackers to reuse expired tokens to reset user passwords and gain full account access.
Predis PHP client pipeline handling is vulnerable to CRLF injection, allowing unauthenticated attackers to execute unauthorized Redis commands via malformed RESP buffers.
AOS-CX contains multiple vulnerabilities in a daemon that allow an unauthenticated remote attacker to achieve remote code execution via specially crafted packets.
A use-after-free vulnerability in the DOM Navigation component of Mozilla Firefox and Thunderbird allows for a sandbox escape.
A use-after-free vulnerability in the Firefox DOM security component allows unauthenticated attackers to trigger a sandbox escape.
An authentication bypass vulnerability in the HPE Fabric Composer API allows unauthenticated remote attackers to gain administrative privileges and fully compromise the host.
The Amelia WordPress plugin contains a critical privilege escalation vulnerability allowing unauthenticated attackers to gain administrative access via improper input validation.
The Nokri WordPress theme is vulnerable to unauthenticated account takeover due to improper validation of password reset tokens, allowing unauthorized password changes for any user account.
The super-diamond-server configuration service lacks authentication, allowing unauthenticated attackers to retrieve sensitive project configuration data via TCP requests.
An authentication bypass vulnerability in HPE Fabric Composer allows unauthenticated adjacent attackers to execute arbitrary code with privileged access, leading to a full host compromise.
An authentication bypass vulnerability in Proxmox VE 7.0 through 8.0 allows unauthenticated attackers to gain unauthorized access by manipulating the tfa-challenge parameter in the API login endpoint.
A buffer overflow vulnerability in the NetStaX EtherNet/IP Stack allows unauthenticated remote attackers to cause memory corruption or device crashes via malformed Class 3 explicit-message requests.
A critical SQL injection vulnerability exists in TRtek Technological Products's Store that allows unauthenticated remote attackers to execute arbitrary SQL commands.
Teracity Software Technologies E-OSB is vulnerable to SQL injection due to improper neutralization of special elements in SQL commands, potentially allowing unauthorized database access.
An improper code generation vulnerability in the Klemsan KIO IoT platform allows unauthenticated remote attackers to perform code injection and achieve remote code execution.
A denial of service vulnerability in Rockwell Automation RSLinx Classic allows unauthenticated attackers to crash the service via a malformed CIP packet.
Team Password Manager contains an authentication bypass vulnerability in the local password reset flow, allowing unauthenticated attackers to reset passwords and gain unauthorized account access.
WWBN AVideo improperly relies on the User-Agent header for authentication security, allowing attackers to bypass two-factor authentication and security auditing mechanisms.
Talassoft Industrial Management Software contains a hard-coded credentials vulnerability that allows unauthenticated attackers to retrieve sensitive system data.
A critical vulnerability in the gpt-researcher WebSocket endpoint allows unauthenticated remote attackers to execute arbitrary code using malicious Model Context Protocol configurations.
An off-by-one out-of-bounds read vulnerability exists in the Linux kernel netfilter nf_conntrack_irc module, potentially allowing for incorrect conntrack state information.
An access control flaw in the TOTOLINK T6 guest_wifi_sync function allows unauthenticated attackers to disable guest virtual AP interfaces using crafted MQTT messages.
Cohere North AI version 1.1.5 suffers from an excessively permissive cross-domain policy due to a lack of validation for the Origin header in incoming connection requests.
Zyplayer-Doc versions 1.0.0 and earlier are susceptible to Server-Side Request Forgery (SSRF) via the WikiPageWebService.download method.
A mismatch between RTL and netlist in openRISC OR1200 commit 83ac6b can lead to unexpected behavior, potentially allowing unauthorized data access or service disruption.
The DevKit Pro WordPress plugin is vulnerable to missing authorization, allowing authenticated attackers to perform remote code execution by installing arbitrary theme packages.
Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function, allowing an authenticated low-privileged user to execute arbitrary SQL commands against the database.
A flaw in the Qute template engine's ReflectionValueResolver allows attackers to bypass security restrictions and execute unauthorized commands by manipulating template text.
Cypht versions prior to 2.12.2 are vulnerable to PHP object injection via the back_query parameter, which can lead to remote code execution by an authenticated attacker.
LibreNMS contains an OS command injection vulnerability in its libvirt discovery feature, allowing authenticated administrators to execute arbitrary commands via crafted device hostnames.
A time of check time of use race condition in the FreeBSD FIOSSHMLPGCNF ioctl operation allows an unprivileged local user to escalate privileges by configuring conflicting largepage memory settings.
Multiple WordPress plugins from BlogVault fail to secure site-to-remote secret generation, allowing unauthenticated attackers to recover secrets and obtain administrative access to affected sites.
A privilege escalation vulnerability exists in Firefox for Android that allows an attacker to gain unauthorized elevated permissions.
A use-after-free vulnerability in the Graphics: WebGPU component of Mozilla Firefox and Thunderbird allows for potential privilege escalation.
A privilege escalation vulnerability exists in the WebDriver BiDi component of Mozilla Firefox and Thunderbird, potentially allowing an attacker to gain unauthorized elevated access.
Mozilla Firefox and Thunderbird are vulnerable to a privilege escalation flaw in the Graphics component caused by an invalid pointer.
A privilege escalation vulnerability in the FactoryTalk Activation Manager installer allows authenticated local users to obtain SYSTEM-level access via hijacked console windows.
The FS Poster plugin for WordPress is vulnerable to command injection through the FFmpeg path parameter, allowing authenticated users to execute arbitrary code on the server.
Coolify before 4.2.0 fails to sanitize environment variable keys in Docker commands, allowing authenticated users to inject shell metacharacters and execute arbitrary commands on the host server.
A privilege escalation flaw in the HPE Fabric Composer API allows authenticated low privilege operators to escalate their access to administrative levels.
A deserialization vulnerability in the Elasticsearch machine learning component allows authenticated users with specific privileges to achieve remote code execution via malicious model artifacts.
A resource exhaustion vulnerability in xmldom allows unauthenticated attackers to crash applications via memory exhaustion by submitting specially crafted XML documents.
A quadratic complexity vulnerability in xmldom allows unauthenticated attackers to trigger a denial of service via malformed XML input or specific DOM normalization operations.
A privilege escalation vulnerability exists in the API of HPE Fabric Composer, allowing authenticated low-privilege users to perform unauthorized state-changing actions on managed systems.
A resource exhaustion vulnerability in gRPC-Go allows unauthenticated remote attackers to trigger memory exhaustion and service termination via fragmented HTTP/2 DATA frames.
A command sanitization bypass in the HPE Fabric Composer API allows authenticated operators to escalate privileges to administrative levels.
An arbitrary file write flaw in the HPE Fabric Composer API permits authenticated low-privilege users to escalate privileges and execute arbitrary operating system commands.
A vulnerability in Dell PowerStore allows a low privileged, remote attacker to perform an incorrect authorization, leading to an elevation of privileges.
A business logic flaw in the HPE Fabric Composer API allows authenticated low-privilege users to escalate privileges and modify unauthorized system settings.
A race condition in the Linux kernel ALSA sequencer OSS emulation layer allows local attackers to corrupt memory or cause inconsistent state by failing to properly serialize queue access.
A memory safety vulnerability in the Linux kernel Btrfs file system allows an unauthenticated attacker to cause a null pointer dereference via a crafted compressed extent.
Dell PowerStore systems are vulnerable to an authentication bypass via spoofing, allowing an authenticated user to escalate privileges to administrative levels.
Dell PowerStore appliances contain an incorrect authorization vulnerability that allows authenticated users with low privileges to perform unauthorized administrator operations and escalate privileges.
A memory management flaw in the Linux kernel snapshot_page function allows local authenticated users to trigger a kernel oops by reading non-existent memory pages.
A privilege escalation vulnerability in Elastic Kibana allows authenticated users with specific permissions to execute workflows with elevated privileges.
A flaw in xmldom allows attackers to inject arbitrary XML structure due to insufficient validation of processing instruction targets in Document.createProcessingInstruction.
A regex flaw in xmldom allows XML injection via unvalidated element or attribute names, bypassing security checks and enabling the insertion of arbitrary breakout markup.
A regex flaw in xmldom allows attackers to bypass strict serialization mitigations, enabling DocumentType injection via unvalidated line break characters in XML output.
A regular expression denial of service vulnerability in xmldom allows unauthenticated attackers to stall the Node.js event loop using specially crafted XML inputs.
The xmldom module is vulnerable to a denial of service attack via quadratic resource consumption when parsing malformed mixed-case HTML raw-text elements.
A vulnerability in the xmldom library allows unauthenticated attackers to trigger a denial of service via quadratic algorithmic complexity during XML parsing.
The xmldom library fails to validate element names in createElement, allowing attackers to inject XML tags or attributes that may lead to cross-site scripting when processed by a browser.
The xmldom library fails to properly sanitize DocumentType.name, allowing unauthenticated attackers to inject arbitrary XML markup via crafted DOCTYPE declarations.
The xmldom module incorrectly validates XML names due to a permissive regular expression, allowing unauthenticated attackers to perform XML injection via malformed names containing line terminators.
The xmldom module fails to validate attribute names during XML processing, enabling attackers to inject malicious attributes or event handlers into browser-consumed output via crafted XML data.
The xmldom module is vulnerable to a regular expression denial of service flaw, where inefficient backtracking allows unauthenticated attackers to stall the Node.js event loop via crafted XML inputs.
HPE Fabric Composer contains a stored cross-site scripting (XSS) vulnerability in its web-based management interface that allows unauthenticated adjacent attackers to execute arbitrary script code.
Dell PowerStore appliances are susceptible to an OS command injection vulnerability, allowing authenticated users with limited privileges to execute arbitrary commands with root-level access.
Dell PowerStore appliances are vulnerable to command injection, allowing an authenticated local user with limited privileges to execute arbitrary commands with root-level access.
Dell PowerStore appliances are vulnerable to an inclusion of functionality from an untrusted control sphere, allowing authenticated users to execute arbitrary code with root-level privileges.
Dell PowerStore appliances are susceptible to a protection mechanism failure, allowing an authenticated user with limited privileges to bypass access controls and escalate their account permissions.
Dell PowerStore appliances contain an OS command injection vulnerability allowing authenticated users with limited privileges to execute arbitrary commands with root-level access.
A protection mechanism failure in Dell PowerStore allows authenticated users with limited privileges to bypass access restrictions and perform unauthorized privilege escalation.
Dell PowerStore appliances are vulnerable to code injection, allowing an authenticated low-privileged user to achieve arbitrary code execution with root privileges.
Dell PowerStore systems contain a protection mechanism failure that allows an authenticated user with limited privileges to write attacker-controlled content to arbitrary filesystem paths.
A vulnerability in the HPE Fabric Composer operating system allows an unauthenticated adjacent attacker to execute arbitrary commands on the underlying host under specific conditions.
The StoreGrowth WordPress plugin fails to validate product prices on unauthenticated actions, allowing attackers to modify cart totals via the BOGO offer feature.
DocSys-master version V2.02.85 contains an arbitrary file read vulnerability within the downloadDocEx interface, allowing unauthenticated access to sensitive system files.
The authentication module in HPE AOS-CX incorrectly processes malformed input, allowing an authenticated remote attacker to potentially achieve remote code execution or cause a denial of service.
An unauthenticated arbitrary file write vulnerability in an AOS-CX API endpoint allows attackers to write files to the operating system, potentially leading to remote code execution.
A format string vulnerability in the AOS-CX command line interface allows unauthenticated attackers to achieve remote code execution as a privileged user.
ModelScope utilizes unsafe PyYAML loading for model configurations, enabling arbitrary code execution via malicious configuration files.
A command injection vulnerability in yast2-auth-client allows unauthenticated attackers to execute arbitrary commands as root by manipulating Active Directory configuration values.
Rockwell Automation FactoryTalk Historian Machine Edition contains an out-of-bounds write vulnerability that allows low-level authenticated attackers to achieve remote code execution.
BookStack contains a stored cross-site scripting vulnerability in the drawing upload endpoint allowing attackers to execute malicious scripts in administrator browsers via SVG file uploads.
An unauthenticated remote denial of service vulnerability exists in the Erlang/OTP inets httpd component due to improper resource release when handling malformed chunked HTTP requests.
Erlang/OTP inets httpd fails to enforce the max_clients limit when it is not explicitly configured, allowing unauthenticated remote attackers to cause a denial of service via connection exhaustion.
Erlang/OTP inets httpd is susceptible to a denial of service vulnerability where unauthenticated remote attackers can exhaust worker threads by stalling request bodies.
A denial of service vulnerability in the Rockwell ArmorStart LT embedded web server allows unauthenticated attackers to cause a service outage via a crafted HTTP PUT request.
PikiwiDB exposes an unauthenticated replication server port, allowing unauthorized remote attackers to synchronize database snapshots and streams or remove replica nodes.
A stored cross-site scripting (XSS) vulnerability in the HPE AOS-CX web management interface allows an authenticated attacker to execute arbitrary scripts in an administrator's browser.
A Cross-Site Request Forgery (CSRF) vulnerability in the AOS-CX web management interface allows remote attackers to execute unauthorized actions via a victim's authenticated session.
A server-side request forgery vulnerability in Wyoming before 1.10.2 allows unauthenticated attackers to force outbound connections to arbitrary targets via the uri query parameter.
Cleo Harmony contains an improper privilege management vulnerability in the JWT Refresh Token Handler, allowing unauthenticated remote attackers to manipulate the Bearer argument.
Spring Framework is vulnerable to a Denial of Service (DoS) attack when using its data binding infrastructure to process user-supplied property paths on target objects.
Zohocorp ManageEngine products are vulnerable to an authenticated SQL injection flaw, which may allow an attacker with low-level privileges to manipulate database queries.
A memory corruption vulnerability exists in the Linux kernel RapidIO tsi721 driver due to an improper pointer dereference, potentially allowing for system instability or integrity compromise.
A use-after-free vulnerability in the Linux kernel veth driver's XDP error path allows local attackers to corrupt memory, potentially leading to privilege escalation or system instability.
A missing authorization flaw in FeatherPanel allows authenticated subusers to escalate their own permissions to full server control, leading to unauthorized access to sensitive data and configurations.
WWBN AVideo contains a cross-site request forgery vulnerability in origin validation functions, allowing unauthenticated attackers to perform administrative configuration changes.
A command injection vulnerability in the HPE AOS-CX web-based management interface allows low-privileged authenticated users to execute arbitrary commands on the underlying operating system.
A vulnerability in HPE AOS-CX command-line operations allows authenticated low-privileged users to execute arbitrary commands with elevated system privileges.
A heap-based buffer overflow in the gvfs SFTP backend allows a malicious server to corrupt memory, potentially leading to denial of service or arbitrary code execution.
A vulnerability in Rockwell Automation DataEdgePlatform DataMosaix Private Cloud allows an authenticated user to escalate privileges to project administrator.
The Erlang OTP inets HTTP server fails to enforce configured body-size limits on chunked requests, potentially allowing for resource exhaustion.
A denial-of-service vulnerability in Rockwell RSLinx Classic allows unauthenticated attackers to crash the service by sending a crafted CIP packet to the Forward Close service.
Rockwell Automation RSLinx Classic is vulnerable to a denial of service attack via a crafted CIP packet, which triggers a service crash due to insufficient data length validation.
A buffer overflow in Rockwell Automation RSLinx Classic allows unauthenticated remote attackers to trigger a denial-of-service condition via a crafted CIP packet.
A denial of service vulnerability in Rockwell Automation Logix controllers allows unauthenticated attackers to cause a major nonrecoverable fault via malformed CIP messages.
A denial-of-service vulnerability in the Rockwell Automation 1756-ENBT module allows unauthenticated attackers to crash the device by sending a specially crafted CIP packet.
OpenNebula contains an improper access control vulnerability in the one.vm.exec function, allowing authenticated users to execute unauthorized commands on virtual machines owned by other users.
The Linux kernel ltc4282 hardware monitoring driver contains an out-of-bounds access vulnerability due to a missing return statement when reading the minimum alarm voltage.
A buffer overflow vulnerability exists in the Linux kernel drm/vmwgfx driver due to improper validation of caller-supplied offsets and strides during external buffer object copies.
A memory management flaw in the Linux kernel drm/vmwgfx driver allows local attackers to cause out of bounds memory access via incorrect bitfield assignments.
A memory safety vulnerability in the Linux kernel Softing CAN driver allows local attackers to cause out-of-bounds reads and writes via a malicious firmware record.
A memory safety vulnerability in the Linux kernel s390/zcrypt driver allows local authenticated attackers to access out of bounds heap memory via improper domain value verification.
A buffer overflow vulnerability exists in the Linux kernel s390/dasd driver due to improper integer type handling during format-check operations, potentially allowing memory corruption.
A use-after-free vulnerability in the Linux kernel ALSA PCM subsystem occurs during stream unlinking, potentially allowing local attackers to cause system crashes or gain elevated privileges.
A vulnerability in the Linux kernel f2fs filesystem driver allows for improper validation of corrupted xattr entries, which may lead to memory corruption or system instability.
The Linux kernel NTFS3 driver is vulnerable to an out-of-bounds read in the decompress_lznt function, which can be triggered by a maliciously crafted NTFS3 filesystem image.
A locking inconsistency in the Linux kernel DRM XE driver allows a potential privilege escalation or system crash when specific debug configurations are enabled.
A NULL pointer dereference vulnerability exists in the Linux kernel SCSI target iblock module, potentially leading to a system denial of service.
A memory initialization vulnerability in the Linux kernel CAN J1939 transport layer allows for potential information disclosure due to failure to zero allocated receive buffers.
The Linux kernel SCTP implementation fails to validate Adaptation Indication parameter lengths, potentially leading to the disclosure of sensitive receive-buffer memory.
An integer overflow vulnerability in the SMF component of Open5GS v2.7.6 allows unauthenticated remote attackers to cause a Denial of Service via a crafted GTP packet.
The yx-image-recognition v1.0 application is vulnerable to path traversal via the dir and filePath parameters, which lack proper sanitization before being used in file system operations.
A vulnerability in the Vanderbilt Industries Acre Security SPC5300.000 Main Board allows a physically proximate attacker to cause a denial of service using spoofed SYN packets.
A vulnerability in the Vanderbilt Industries, Acre Security SPC5300.000 Main Board allows a physically proximate attacker to trigger a denial of service via replayed TCP application-layer payloads.
A vulnerability in the Vanderbilt Industries Acre Security SPC5300.000 Main Board allows a physically proximate attacker to trigger a denial of service using spoofed TCP FIN packets.
Stomper version 5e2741e is susceptible to a denial of service vulnerability where an unauthenticated client can trigger a server process termination by closing a socket during specific data exchanges.