CVE-2026-75650
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
Six Google Chrome flaws rated CVSS 9.6 and a CVSS 9.8 remote code execution issue in Apache ActiveMQ Artemis (CVE-2026-57967) lead yesterday's disclosures, alongside CVE-2026-8778 (CVSS 9.8) in the MIPL Grouped Checkout Fields plugin for WooCommerce. The day brought 57 critical CVEs (up from 11) and 93 high-priority CVEs (up from 30), for 150 total. Other notable entries include CVE-2026-88869 (CVSS 9.3) in WWBN AVideo and CVE-2026-78082 (CVSS 9.3) in the JoomShaper SP Property extension for Joomla. Eleven CVEs have confirmed active exploitation, spanning Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Mikrotik RouterOS, Adobe Commerce, N-able N-central, Microsoft Windows and Chrome, which puts internet-facing edge and management appliances in the highest-exposure group. Prioritise browser fleet updates and restrict administrative access to edge gateways and firewall management consoles to trusted networks while you verify fix status with each vendor.
Immediate action: Patch the actively exploited set first: Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center, Mikrotik RouterOS, Adobe Commerce, N-able N-central, Microsoft Windows, and Google Chrome, since those are internet-facing or centrally trusted systems already under attack. Then update browser fleets for the six CVSS 9.6 Chrome issues and review Apache ActiveMQ Artemis brokers, WooCommerce checkout plugins, and Joomla SP Property installations. Confirm the fixed version and any interim mitigations in each vendor's own advisory before closing out the work.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Adobe Commerce is vulnerable to improper template engine neutralization, potentially allowing unauthenticated remote attackers to execute arbitrary code.
N-able N-central is vulnerable to a pre-authentication remote code execution flaw via static code injection, allowing unauthenticated attackers to execute arbitrary code on the target system.
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthenticated attackers to execute unauthorized code or commands via specially crafted packets.
An improper system process at boot time in Cisco FMC allows unauthenticated attackers to bypass authentication and execute scripts via HTTP requests to obtain root OS access.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
A type confusion vulnerability in the V8 engine of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
A stored cross-site scripting vulnerability in AVideo allows unauthenticated attackers to execute arbitrary JavaScript in an administrator session via the AD_Server plugin's log.php endpoint.
A critical flaw in Apache Artemis allows unauthenticated remote attackers to hijack existing sessions via crafted CORE protocol SESSION_REATTACH packets, leading to unauthorized command execution.
The MIPL Grouped Checkout Fields for WooCommerce plugin for WordPress is vulnerable to unauthenticated arbitrary file uploads, potentially leading to remote code execution.
An unauthenticated SQL injection vulnerability in the SP Property extension for Joomla allows remote attackers to extract sensitive database information via unsanitized query parameters.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in Google Chrome DevTools allows a remote, unauthenticated attacker to execute arbitrary code outside the browser sandbox via a specially crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Aura component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the WebGL component of Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Google Chrome Payments component allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the WebGL component of Google Chrome on Android allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the ANGLE component of Google Chrome on Windows allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Dawn component of Google Chrome on Android allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A buffer overflow vulnerability in WebGL allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use-after-free vulnerability in the Payments component of Google Chrome on Mac allows remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the Google Chrome Device component on Mac allows remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in the WebPackaging component of Google Chrome allows remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use after free vulnerability in Google Chrome Extensions on Mac allows remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A use-after-free vulnerability in the Web Authentication component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A buffer overflow vulnerability in the ANGLE graphics component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An out of bounds write vulnerability in the WebGL component of Google Chrome on Android allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
Improper quantity validation in Tint in Google Chrome on Mac allows a remote, unauthenticated attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A type confusion vulnerability in Rust within Google Chrome for Windows allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A numeric truncation error in the Media component of Google Chrome allows a remote attacker to execute arbitrary code outside the browser sandbox via a specially crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
A vulnerability in the Google Chrome FileSystem component allows a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page and social engineering.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An out of bounds write vulnerability in the ANGLE graphics engine of Google Chrome for Windows allows unauthenticated remote attackers to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An out of bounds write vulnerability in the Google Chrome Media component allows a remote attacker to execute arbitrary code via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An integer overflow vulnerability in the GPU component of Google Chrome on Android allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Disclosed Sep 9 without a CVSS score; scored Sep 10, analysis completed Sep 10.
An out of bounds read vulnerability in the WebGL component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code via a crafted HTML page.
Dell ThinOS 10 contains a command injection vulnerability allowing unauthenticated adjacent attackers to achieve remote code execution.
A vulnerability in the Gemini CLI and GitHub Action allows unprivileged attackers to achieve arbitrary code execution via untrusted local .env files that override the GEMINI_CLI_HOME environment variable.
Dell ThinOS 10 contains an OS command injection vulnerability that allows unauthenticated remote attackers to execute arbitrary commands on the system.
A flaw in Traefik's Kubernetes ingress-nginx provider allows unauthenticated attackers to bypass authentication and middleware by manipulating the Host header during specific redirect configurations.
Dell ThinOS 10 contains a protection mechanism failure allowing unauthenticated remote attackers to achieve arbitrary code execution.
The miniOrange 2FA WordPress plugin fails to validate authorization for site option deletion, allowing unauthenticated attackers to delete arbitrary options and potentially lock out administrators.
An eval injection vulnerability in Apache Camel K allows unauthenticated tenants to execute arbitrary code within the operator pod via malicious Maven configurations.
Apache Camel K is susceptible to a YAML injection vulnerability in custom resource configuration, allowing unauthorized Kubernetes object creation with operator privileges.
An authentication bypass vulnerability in rclone serve s3 allows unauthenticated attackers to impersonate arbitrary users and access backend storage by signing requests with an empty secret.
Forgejo versions prior to 16.0.4 and 15.0.8 are vulnerable to remote code execution due to improper template expansion handling within the .forgejo/template directory.
A Server-Side Request Forgery vulnerability in the Amazon SSM Agent allows authenticated remote users to bypass destination restrictions and access restricted link-local endpoints.
IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 contains a vulnerability involving the use of default credentials, which allows unauthenticated remote attackers to gain administrative access.
IBM Langflow OSS 1.0.0 through 1.11.5 is susceptible to remote OS command injection due to improper neutralization of special elements in commands.
IBM Langflow OSS contains a code injection vulnerability during graph construction that allows unauthenticated remote attackers to execute arbitrary code on the underlying system.
The knowns proxy endpoint fails to validate the x-opencode-directory request header, allowing unauthenticated remote attackers to perform arbitrary file operations outside the project root.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal, which could allow a remote authenticated attacker to trigger a denial of service or unauthorized file manipulation.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authentication vulnerability that allows remote authenticated attackers to bypass security restrictions and access sensitive information.
OmniRoute contains a code injection vulnerability in the /api/acp/agents endpoint allowing unauthenticated remote attackers to execute arbitrary code via malicious interpreter evaluation arguments.
An OS command injection vulnerability in the ConfigServer Security & Firewall rule parser allows unauthenticated remote attackers to execute arbitrary commands as root via malicious rule feeds.
A missing authentication vulnerability in GeoVision GV-LPC2011 and GV-LPC2211 cameras allows unauthenticated remote attackers to control PTZ functionality and execute raw serial commands.
A command injection vulnerability in ConfigServer Security & Firewall allows unauthenticated remote attackers to execute arbitrary commands via improper URL escaping.
A TOCTOU race condition in Plesk allows local users to escalate privileges to root by manipulating symlinks during file operations.
An SQL injection vulnerability in the GIS Informatics GisLab Laboratory Management System allows unauthenticated attackers to execute arbitrary SQL commands.
An unauthenticated SQL injection vulnerability exists in the Verified Reviews (Avis Vérifiés) plugin for WordPress in versions 2.4.6 and earlier.
A path traversal vulnerability in the Plesk Backup Manager allows an authenticated customer to perform arbitrary file writes with root privileges.
IBM Langflow OSS 1.0.0 through 1.11.5 contains an authorization flaw in MCP project endpoints, allowing unauthenticated attackers to achieve remote code execution and manipulate chat sessions.
Disclosed Sep 4 without a CVSS score; tracked by CVE Brief from Sep 5; scored Sep 10, analysis completed Sep 11.
A SQL injection vulnerability in Sysoa version 1.0 allows a remote, unauthenticated attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path.
Flowise 3.1.2 and earlier allow unauthenticated remote attackers to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint.
An open redirect vulnerability in the Armiya Information Technologies Ltd. Access Control System allows unauthenticated attackers to spoof data sources via malicious URL redirection.
Disclosed Sep 4 without a CVSS score; tracked by CVE Brief from Sep 5; scored Sep 10, analysis completed Sep 11.
Easyadmin version 2.0.2.2 contains an unrestricted file upload vulnerability in the background management interface, allowing remote attackers to execute arbitrary code and gain server privileges.
WWBN AVideo contains a stored cross-site scripting (XSS) vulnerability allowing authenticated users to inject malicious scripts that execute in the browsers of other users, including administrators.
A server side request forgery vulnerability in Apache Impala allows authenticated users with specific function permissions to exfiltrate secrets from configured credential providers.
The MongoDB Java Driver GridFS component improperly handles file identifiers, allowing authenticated users to manipulate query logic to access, delete, or rename unintended files.
An authenticated, non-admin user can execute arbitrary operating system commands via the ElementSearchController::actionSearch endpoint in Craft CMS.
SiYuan versions before 3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint, allowing authenticated administrators to delete arbitrary files outside the workspace.
A cross-site scripting (XSS) vulnerability in Angular server-side rendering allows attackers to execute arbitrary JavaScript by exploiting improper escaping of input within HTML5 fallback elements.
A cross-site scripting vulnerability in Angular server-side rendering allows attackers to execute arbitrary JavaScript by manipulating ProcessingInstruction DOM nodes.
Angular Server-Side Rendering is vulnerable to SSRF via improper Unicode whitespace trimming in URL parsing, potentially leading to unauthorized credential disclosure.
A stack-based buffer overflow in Tesseract OCR versions 5.5.3 and earlier allows local attackers to cause a denial of service or potentially achieve control-flow hijacking via malicious data files.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to a denial of service attack, allowing an authenticated remote attacker to delete arbitrary RabbitMQ queues or exchanges.
A memory corruption vulnerability in Netskope Endpoint DLP for Windows allows a privileged user to trigger an integer overflow, potentially leading to arbitrary code execution or privilege escalation.
OpenPanel contains an SQL injection vulnerability in the analytics filter builder that allows authenticated attackers to bypass project isolation and access unauthorized data.
ICEcoder 8.0 through 8.1 contains an OS command injection vulnerability in lib/properties.php, allowing authenticated users to execute arbitrary commands via crafted directory names.
A hardcoded credential vulnerability in Softish EarVision and C6 Ear Camera allows attackers to derive Wi-Fi passwords and gain unauthorized network access.
A Server-Side Request Forgery vulnerability in the Google Gemini Enterprise Agent Platform App Builder allows unauthenticated attackers to leak Compute Engine default service account access tokens.
BurgerEditor contains an unrestricted file upload vulnerability that allows authenticated attackers to execute arbitrary PHP code.
An improper neutralization of special elements in the MongoDB Python Driver GridFS component allows authenticated users to manipulate data queries, leading to unauthorized file access or data deletion.
A query logic flaw in the MongoDB Ruby Driver GridFS component allows authenticated users to manipulate file identifiers, leading to unauthorized file access or data deletion.
A query logic flaw in the GridFS component of the MongoDB PHP Library allows authenticated users to manipulate file identifiers, leading to unauthorized data access or deletion of stored file content.
ICEcoder versions 8.0 through 8.1 are vulnerable to a path traversal flaw in the oldFileName parameter, allowing authenticated users to move arbitrary files on the server.
Renovate improperly handles pagination links from container registries, leading to credential exfiltration when following redirects to attacker controlled hosts.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a missing authorization vulnerability that allows authenticated remote attackers to execute arbitrary Python code via custom components.
The Capgo backend improperly validates API key delegation in the x-limited-key-id header, allowing authenticated users to escalate privileges to other keys owned by the same user.
The UsersWP plugin for WordPress is vulnerable to arbitrary file deletion via the upload_file_remove() AJAX handler, allowing authenticated attackers to delete critical system files.
HPE IceWall 4.0 contains a vulnerability involving improper verification of cryptographic signatures in SAML responses, potentially allowing an authenticated attacker to impersonate other users.
Apache Nutch Server (REST API) is vulnerable to code injection and unsafe reflection due to missing authorization, allowing authenticated attackers to execute arbitrary code.
A query logic flaw in the MongoDB C++ Driver GridFS component allows authenticated users to manipulate file identifiers, potentially leading to unauthorized data access or widespread file deletion.
The MongoDB C Driver GridFS component improperly handles file identifiers, allowing authenticated users to manipulate query logic to access unauthorized content or delete file chunks.
A query logic flaw in the MongoDB Rust Driver GridFS component allows authenticated users to manipulate file identifiers, potentially leading to unauthorized data access or widespread file deletion.
The MongoDB C# Driver GridFS component improperly neutralizes special elements in query logic, allowing authenticated users to manipulate file identifiers to access, delete, or rename unintended files.
An OS Command Injection vulnerability in Schneider Electric PowerLogic T300 allows an authenticated user with SSH access to escalate privileges to root and execute unauthorized administrative functions.
Zenius EMS 8.0 is vulnerable to an authentication bypass and input validation failure, allowing remote code inclusion.
A command argument injection vulnerability in Schneider Electric EcoStruxure IT Data Center Expert allows privileged remote code execution via malicious backup configuration parameters.
A stack-based buffer overflow in the Bosch BHI385 SensorAPI allows memory corruption via an unvalidated length byte in debug messages, potentially leading to firmware crashes or arbitrary code execution.
Capgo (capgo.app) suffers from an authentication bypass vulnerability where sessions at the AAL1 level can exercise privileged RBAC permissions, effectively defeating MFA protections.
Howyar WeenyGenius suffers from a missing authentication flaw allowing unauthenticated network-adjacent attackers to spoof endpoints, disrupt classroom operations, or gain unauthorized remote control.
IBM App Connect Enterprise contains an authorization flaw that allows authenticated remote attackers to bypass security restrictions.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a code injection vulnerability allowing remote authenticated attackers to execute arbitrary code via an unsafe eval() call.
IBM Langflow OSS versions 1.0.0 through 1.11.5 are vulnerable to OS command injection via improper validation of command-line arguments in the MCP stdio server configuration.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain a code injection vulnerability caused by an incomplete environment variable blocklist, allowing remote authenticated code execution.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, which can allow an authenticated remote attacker to execute arbitrary code.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to path traversal, allowing a remote authenticated attacker to write or delete files on shared storage.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to an absolute-path traversal flaw, allowing remote authenticated attackers to access sensitive information.
IBM Langflow OSS contains a code injection vulnerability in flow display names that allows remote authenticated attackers to execute arbitrary code.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an absolute path traversal vulnerability that allows remote authenticated attackers to access sensitive information.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing a remote authenticated attacker to execute arbitrary code on the underlying system.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to a Server-Side Request Forgery flaw that allows a remote authenticated attacker to execute arbitrary code.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrary system commands.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, which could allow an authenticated remote attacker to execute arbitrary code on the underlying system.
IBM Langflow OSS versions 1.0.0 through 1.10.3 are vulnerable to path traversal, which could allow a remote authenticated attacker to achieve arbitrary code execution.
Traefik is vulnerable to an HTTP request handling flaw where opaque request targets allow attackers to bypass routing, authorization, and logging controls by forwarding requests verbatim to backends.
IBM Langflow OSS versions 1.0.0 through 1.11.5 are susceptible to Server-Side Request Forgery (SSRF) due to improper validation of user-supplied URLs.
Autodesk Fusion contains a vulnerability where a malicious add-in can silently modify persistent network proxy settings, potentially enabling traffic interception and sensitive information exposure.
Renovate fails to validate the origin of pagination URLs in NuGet registry responses, allowing unauthenticated attackers to trigger the exfiltration of registry credentials to an arbitrary host.
The SP Property extension for Joomla is vulnerable to unauthenticated stored Cross-Site Scripting (XSS) due to improper output escaping in frontend views and administrator list tables.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains an improper authorization flaw that allows an authenticated remote attacker to cause a denial of service condition.
A Server-Side Request Forgery vulnerability in IBM DataStage on Cloud Pak for Data allows authenticated tenants to perform unauthorized outbound fetches and access internal cluster services.
IBM DataStage on Cloud Pak for Data 5.4.0.0 contains a path traversal vulnerability that permits a remote authenticated attacker to overwrite ruleset files belonging to other tenants.
Snipe-IT versions before 8.7.0 are vulnerable to file exfiltration and SSRF due to improper sanitization of the category EULA text field during checkout confirmation emails.
Snipe-IT versions before 8.7.0 are vulnerable to arbitrary file reading and SSRF due to improper sanitization of markdown image syntax in note fields by authenticated users.
OpenNMS Horizon contains a missing authorization vulnerability in its REST API that allows unauthenticated attackers to modify event and SNMP data collection configurations.
A stack-based buffer overflow in the Nintendo Switch local wireless networking functionality allows an unauthenticated attacker within wireless range to execute arbitrary code via crafted network traffic.
WeenyGenius utilizes the insecure ZMTP Null mode, allowing unauthenticated network attackers to intercept sensitive data or execute replay attacks to disrupt classroom operations.
WeenyGenius contains an origin validation error that allows unauthenticated attackers on the same network to spoof teacher workstations via broadcast packets.
IBM Aspera Enterprise WebApps versions 1.0.0 through 1.0.5 contain a vulnerability that allows local attackers to escape container protections via unrestricted system calls.
A logic error in the IBM Langflow OSS static security scanner allows authenticated attackers to bypass security checks and execute arbitrary operating system commands via crafted component source code.
IBM Langflow OSS versions 1.0.0 through 1.11.5 contain an OS command injection vulnerability due to an incomplete denylist in the security scanner, allowing remote code execution for authenticated users.
IBM Langflow OSS allows authenticated users to execute arbitrary operating system commands by bypassing server-side security controls via the MCP Tools component.
FileRun contains an OS command injection vulnerability in the PhotoProofSheet handler allowing authenticated users with upload privileges to execute arbitrary commands via crafted filenames.
Anchor CMS versions through 0.12.7 lack proper authorization checks on user management endpoints, allowing authenticated low-privilege users to escalate privileges to administrator.
The Knowns CLI code generation engine fails to validate destination paths, allowing attackers to perform path traversal to read or write arbitrary files on the host system.
ICEcoder versions 8.0 through 8.1 contain a path traversal vulnerability in the file-control endpoint, allowing authenticated attackers to access files outside the intended document root.
WWBN AVideo contains a stored cross-site scripting vulnerability in the LoginControl plugin that allows authenticated users to execute malicious scripts in administrator sessions.
The LiveLinks plugin in WWBN AVideo is vulnerable to stored cross-site scripting due to insufficient input sanitization of title and description fields, allowing authenticated users to execute scripts.
Tesseract OCR engine is vulnerable to a heap-based out-of-bounds write flaw caused by insufficient validation of loop bounds when parsing crafted traineddata files, leading to potential memory corruption.
Tesseract OCR is vulnerable to a heap out-of-bounds write due to missing validation of model data, potentially allowing arbitrary code execution or system crashes via a crafted .traineddata file.
A heap out of bounds write vulnerability exists in Tesseract OCR versions 5.5.3 and earlier due to unchecked bounds in LSTM processing functions, potentially leading to heap corruption or code execution.
A heap out-of-bounds vulnerability in Tesseract OCR allows for potential memory corruption or information disclosure via crafted .traineddata files.
A path traversal vulnerability in Advanced Product Fields Extended for WooCommerce allows unauthenticated attackers to delete arbitrary files.
Renovate fails to validate Link header destinations during GitLab pagination, enabling unauthenticated attackers to redirect requests and exfiltrate sensitive authentication credentials.
Renovate incorrectly follows untrusted pagination links in HTTP headers, potentially causing the tool to disclose sensitive credentials to attacker-controlled hosts.
A Server-Side Request Forgery (SSRF) vulnerability in Schneider Electric EcoStruxure IT Data Center Expert allows privileged attackers to execute unauthorized commands and access sensitive server data.
Bestzip contains an argument injection vulnerability in the nativeZip function that allows attackers to execute arbitrary commands with Node.js process privileges.
A vulnerability in the SICK Sentio Creator Extension Device Manager allows unauthenticated remote attackers to execute arbitrary code via malicious driver packages due to improper signature verification.
HashiCorp Consul and Consul Enterprise contain an authorization bypass in the catalog node-write path, allowing authenticated attackers to delete and assume the identity of other nodes.
OpenPanel fails to enforce read-only access controls on 26 of 29 mutation procedures, allowing low-privileged users to modify, delete, or publish sensitive project data.
A cross-site scripting vulnerability in Open WebUI allows authenticated users to compromise other accounts by injecting malicious scripts into terminal port previews.
The zstd-jni library contains an out-of-bounds read vulnerability in the Zstd.getFrameContentSize function, allowing attackers to trigger information disclosure or JVM crashes via negative offsets.
MaxSite CMS contains a local file inclusion vulnerability in its ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute arbitrary handler files via path traversal.
A vulnerability in zstd-jni allows out-of-bounds memory reads via negative or overflowing offsets in direct-ByteBuffer frame-size native methods, potentially causing JVM termination or data exposure.
Chainlit versions through 2.12.0 are vulnerable to path traversal via the socket.io sessionId parameter, allowing unauthenticated attackers to delete arbitrary directories accessible to the service process.
The zstd-jni library fails to validate offset and length parameters in the ZstdDictCompress constructor, enabling out-of-bounds memory reads that can trigger JVM crashes.
The knowns npm package contains a path traversal vulnerability in the Document API, allowing unauthenticated remote attackers to read, write, or delete arbitrary files on the host filesystem.