CVE-2026-19490
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
Critical vulnerabilities, curated daily for security professionals
AI orchestration frameworks and enterprise edge infrastructure carried the weight of Tuesday's disclosures, with five separate CVSS 9.8 remote code execution issues in MervinPraison PraisonAI and companion library praisonaiagents alongside platform-level flaws in Apple operating systems and Google Android. The day brought 56 critical CVEs (up 300% from 14 the prior day) and 80 high-priority CVEs (down 22% from 102), for 136 total. Notable entries include CVE-2026-57124 and CVE-2026-57123 (CVSS 9.8) in the PraisonAI stack, CVE-2026-65414 (CVSS 9.8) affecting iOS, iPadOS, macOS, tvOS, visionOS and watchOS, and CVE-2026-90937 (CVSS 9.9) in the froxlor hosting control panel. Unauthenticated remote code execution and authentication bypass dominate the critical set, hitting developer tooling (IBM Langflow OSS, MISP) and internet-facing management interfaces used across hosting, DevOps and security operations. Thirteen CVEs have confirmed active exploitation, including Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center and Secure Email Gateway, Fortinet FortiOS, Mikrotik RouterOS, ConnectWise ScreenConnect, GitLab and JFrog Artifactory; treat management planes on those products as the first isolation and patching priority, restrict administrative access to trusted networks, and confirm fix availability in each vendor's advisory.
Immediate action: Prioritise the actively exploited edge and management products: Citrix NetScaler ADC and Gateway, Cisco Secure Firewall Management Center and Secure Email Gateway, Fortinet FortiOS and FortiSwitchManager, Mikrotik RouterOS, ConnectWise ScreenConnect, GitLab, JFrog Artifactory, plus Microsoft Windows and Google Chrome. Teams running AI agent frameworks should inventory PraisonAI, praisonaiagents and IBM Langflow deployments and remove any exposure to untrusted networks while they assess. Confirm the fix status and required version for each affected product in that vendor's own advisory before scheduling maintenance.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
This vulnerability allows unauthenticated attackers to bypass authentication on Citrix NetScaler ADC and Gateway appliances via an alternate path or channel.
A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthenticated attackers to execute unauthorized code or commands via specially crafted packets.
An improper system process at boot time in Cisco FMC allows unauthenticated attackers to bypass authentication and execute scripts via HTTP requests to obtain root OS access.
A flaw in the RouterOS SSH login path allows attackers to bypass privilege restrictions by using a specially crafted username, leading to full administrative access.
MikroTik RouterOS contains a memory disclosure and remote denial of service vulnerability in the bandwidth-test service that allows unauthenticated attackers to trigger a kernel restart.
A missing authorization flaw in the ScreenConnect client allows unauthorized file transfer and execution during active remote sessions.
An unauthenticated path traversal vulnerability in the GitLab repository commits API allows remote attackers to read arbitrary files from the server.
A critical SQL injection vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to execute arbitrary commands with root privileges via crafted email messages.
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
A heap-based buffer overflow in the Windows ALPC subsystem allows an authenticated attacker to achieve local privilege escalation.
A memory corruption vulnerability in the Google Chrome V8 engine allows remote attackers to execute arbitrary code via a crafted HTML page.
An incorrect authorization vulnerability in JFrog Artifactory allows authenticated attackers to perform unauthorized actions, potentially leading to data compromise.
An improper authentication vulnerability in JFrog Artifactory allows unauthenticated users to obtain an internal token, potentially exposing sensitive resources even when anonymous access is disabled.
PraisonAI versions prior to 4.6.59 are vulnerable to unauthenticated OS command injection via the /api/mcp/connect endpoint, allowing remote code execution as the UI service account.
PraisonAI agents fail to enforce authentication or origin validation on critical endpoints, allowing unauthenticated attackers to execute arbitrary tools, shell commands, or code.
An out-of-bounds write vulnerability in multiple Apple operating systems allows a remote, unauthenticated attacker to execute arbitrary code or cause application termination.
PraisonAI fails to enforce API key or JWT authentication when environment variables are missing, allowing unauthenticated attackers to execute recipes and trigger connected tools.
PraisonAI versions prior to 4.6.58 suffer from missing authentication and authorization, allowing unauthenticated network clients to manipulate jobs and execute arbitrary agent configurations.
An unauthenticated remote code execution vulnerability in PraisonAI allows attackers to execute arbitrary operating system commands via the /api/v1/runs Jobs API.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 15.
A logic error in Android Bluetooth AdapterService allows unauthenticated remote attackers to bypass pairing and escalate privileges.
The LdapAuth and LinOTPAuth plugins in MISP fail to validate input fields, allowing unauthenticated users to bypass login requirements and impersonate any user by providing an empty password.
IBM Langflow OSS allows authenticated attackers to execute arbitrary Python code with root privileges, leading to credential theft, data exfiltration, and lateral movement.
Froxlor versions before 2.2.5 are vulnerable to CRLF injection via subdomain redirect URLs, allowing authenticated users to manipulate web server configuration files and potentially hijack HTTP responses.
Cisco Secure Email Gateway and Secure Email and Web Manager contain vulnerabilities related to the improper control of a resource through its lifetime, potentially allowing for system compromise.
Cisco Secure Email Gateway and Secure Email and Web Manager contain a path traversal vulnerability that could allow an unauthenticated remote attacker to access unauthorized files.
Cisco Secure Email and Web Manager contains an improper access control vulnerability that allows unauthenticated remote attackers to potentially compromise the system.
Cisco Secure Email Gateway and Web Manager are affected by improper neutralization vulnerabilities discovered during an internal security review, potentially allowing for critical system compromise.
A stack-based buffer overflow in the D-Link DI-8400 DDNS configuration function allows remote authenticated attackers to execute arbitrary code via specially crafted HTTP POST parameters.
Apache Syncope contains an SQL injection vulnerability allowing arbitrary SQL execution via unsanitized entityKey and opEvent parameters.
Apache Syncope contains an SQL injection vulnerability via unsanitized sort clauses in the Task search function, allowing arbitrary SQL execution through stacked queries.
A stack-based out-of-bounds write vulnerability in the UEFI Firmware Parser allows unauthenticated attackers to corrupt memory and potentially achieve remote code execution via crafted firmware files.
An out-of-bounds write vulnerability in theopolis uefi-firmware-parser allows remote attackers to corrupt heap memory and potentially execute arbitrary code via crafted UEFI firmware files.
The SimpleACLAuthorizer in Apache Storm fails to enforce group-based access restrictions when the user list is empty, allowing unauthorized operations by authenticated principals.
An unauthenticated remote memory allocation vulnerability in Apache Storm Worker allows attackers to trigger excessive memory consumption, potentially causing service instability.
A resource exhaustion vulnerability in Apache Storm DRPC allows unauthenticated attackers to cause a denial of service by sending arbitrary function names, leading to permanent heap memory depletion.
An incorrect authorization vulnerability in the Apache Syncope Reconciliation service allows unauthorized administrators to perform unauthorized pull and push operations.
Apache Syncope suffers from an improper privilege management vulnerability allowing users to assign unauthorized roles or realms during delegation creation, potentially leading to full system compromise.
An incorrect authorization vulnerability in Apache Syncope allows unauthenticated users to bypass realm filters during non-recursive search requests, resulting in unauthorized data access.
An incorrect authorization flaw in Apache Syncope allows an administrator to read and duplicate connector configurations from restricted realms across the platform.
A missing authorization vulnerability in Apache Syncope allows administrators with task execution entitlements to perform unauthorized mass provisioning or deprovisioning of group members.
An incorrect authorization flaw in Apache Syncope allows unauthorized operations due to improper entitlement checks on ClientApp objects.
A privilege assignment vulnerability in Apache Syncope allows authenticated attackers with low privileges to escalate to administrative status if internal JWKS settings are disclosed.
Apache Syncope contains a Cypher injection vulnerability in the Neo4j persistence layer, allowing unauthenticated attackers to execute arbitrary queries via crafted FIQL search conditions.
ModelTC LightLLM up to version 1.2.0 is susceptible to unauthenticated remote code execution via insecure pickle deserialization in the /visual_register WebSocket endpoint.
WHMCS is vulnerable to deserialization of untrusted data, allowing remote unauthenticated attackers to execute arbitrary code on the underlying system.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A race condition in the Linux kernel SUNRPC implementation during TLS handshake cancellation can result in a use-after-free vulnerability, potentially leading to system compromise.
IBM DataStage on Cloud Pak for Data is vulnerable to arbitrary file write attacks by remote authenticated users due to improper validation of file paths.
Crawlab versions 0 through 0.6.3 contain an authentication bypass vulnerability due to a hard-coded JWT secret, allowing unauthenticated attackers to forge administrator tokens and execute code.
An unauthenticated remote code execution vulnerability in Bifrost allows attackers to execute arbitrary programs via the management API by bypassing required authentication for MCP client registration.
Casdoor versions up to 4.4.0 contain a vulnerability where certificate private keys are improperly exposed via API endpoints, enabling unauthorized JWT token forgery by organization administrators.
Equinor resdata versions prior to 6.2.9 contain multiple memory safety vulnerabilities, including buffer overflows, that occur when parsing malformed GRDECL files.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory safety flaw in the Linux kernel RPC/RDMA implementation allows unauthenticated remote attackers to trigger buffer underflows and read adjacent slab memory.
PingAM contains an improper validation flaw allowing attackers to override ID Token claims, potentially leading to authentication bypass, privilege escalation, or user impersonation.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory safety flaw in the Linux kernel segment routing module allows unauthenticated attackers to trigger an out-of-bounds read via crafted IPv6 packets during decapsulation.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A memory corruption vulnerability in the Linux kernel XDP subsystem allows unauthenticated attackers to trigger slab out of bounds writes via manipulated AF_XDP zero copy packets.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer overflow vulnerability exists in the Linux kernel RPC-over-RDMA implementation, allowing unauthenticated remote attackers to corrupt slab memory via oversized inline replies.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
The Linux kernel SUNRPC component fails to properly validate Kerberos v2 wrap tokens, allowing for the processing of tokens with oversized extra count fields that result in inconsistent buffer states.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A vulnerability in the Linux kernel SUNRPC implementation allows unauthenticated attackers to trigger out of bounds memory reads via crafted RPCSEC_GSS replies.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
The Linux kernel SUNRPC component contains an out-of-bounds read and potential divide-by-zero vulnerability in gss_krb5_unwrap_v2 due to improper validation of token lengths.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A race condition in the Linux kernel SUNRPC backchannel implementation allows for unauthorized memory access and potential service disruption during callback service teardown.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer validation flaw in the Linux kernel SUNRPC implementation allows unauthenticated attackers to trigger a division-by-zero error via malformed krb5 tokens.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer length underflow vulnerability in the Linux kernel SUNRPC component allows for remote code execution or system instability by corrupting XDR stream bounds.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
The Linux kernel NTFS driver fails to validate non-resident attribute offsets during sparse attribute conversion, potentially allowing memory corruption via a malicious MFT record.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A slab out of bounds read vulnerability exists in the Linux kernel NTFS driver caused by improper bounds checking during free cluster bitmap scans.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A use-after-free vulnerability in the Linux kernel audit subsystem allows attackers to trigger memory corruption via improper reference counting during fsnotify rule autoremove.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A slab out-of-bounds read vulnerability in the Linux kernel Ceph client allows a malicious MDS to trigger memory corruption via crafted session messages, potentially leading to information disclosure.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer overflow vulnerability exists in the Linux kernel Ceph filesystem NFS export path, where unchecked name lengths can lead to memory corruption via a malicious MDS.
Disclosed Sep 11 without a CVSS score; tracked by CVE Brief from Sep 12; scored Sep 13, analysis completed Sep 13.
A buffer overflow vulnerability exists in the Linux kernel Ceph file system component due to improper validation of mdsmap export_targets, potentially allowing memory corruption.
A configuration migration error in ESPHome Device Builder Dashboard causes instances to lose authentication protection upon upgrading, allowing unauthenticated remote access to the dashboard.
Laravel MagicLink is vulnerable to insecure deserialization of untrusted data in versions 2.0.0 through 2.25.0, allowing attackers with database access to execute arbitrary code.
Magistrala versions prior to 1.0.0 are vulnerable to SQL injection in the timescale-reader and postgres-reader services, allowing authenticated attackers to execute arbitrary code as the postgres user.
An authenticated SQL injection vulnerability in Pimcore allows users with specific permissions to execute arbitrary database commands via the Custom Reports configuration module.
An authenticated SQL injection vulnerability in Pimcore allows users with object permissions to read or modify arbitrary database tables by submitting malicious ClassDefinition UIDs.
PraisonAI is vulnerable to Server-Side Request Forgery (SSRF) because it fails to resolve DNS names before validating URLs, allowing attackers to access internal network resources.
The python-garminconnect library improperly sets file permissions on OAuth token files, allowing local unprivileged users to read sensitive refresh tokens and access the victim's account.
A validation issue in macOS allows a remote user to trigger unexpected application termination or arbitrary code execution via insufficient input sanitization.
PraisonAI webhook handlers fail to verify HMAC signatures if secrets are not configured, allowing unauthenticated remote attackers to forge messages and manipulate agent workflows.
MISP’s interactive CLI shell contains authorization inconsistencies, allowing authenticated local users to access sensitive data and bypass security restrictions enforced in the web interface.
PraisonAI versions prior to 4.6.62 contain an improper authentication vulnerability that allows unauthenticated users to invoke agents, potentially exposing private tools and context data.
Laravel-Backpack CRUD is susceptible to unauthenticated OS command injection via the HTTP Host header in the Stats::makeCurlRequest function, potentially leading to full server compromise.
The Alior Bank PrestaShop module raty is vulnerable to SQL injection in the toggleCategoryPromotionAction method, allowing authenticated backoffice users to modify database contents.
The Alior Bank raty PrestaShop module is vulnerable to SQL injection via unsanitized POST parameters in multiple hook methods, allowing authenticated backoffice users to modify database contents.
The SP Page Builder extension for Joomla contains an authenticated SQL injection vulnerability that allows privileged users to read arbitrary database contents through improper input handling.
Disclosed Sep 9 without a CVSS score; scored Sep 12, analysis completed Sep 12.
A missing authorization vulnerability in Google Chrome Extensions allows a remote, unauthenticated attacker to access sensitive information via a specially crafted extension.
Disclosed Sep 9 without a CVSS score; scored Sep 12, analysis completed Sep 12.
Incorrect authorization in Google Chrome permissions allows a remote attacker to obtain sensitive information via a crafted extension.
Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation.
A local privilege escalation vulnerability in Eclipse Ankaios allows unprivileged users to hijack workload Control Interfaces via predictable file paths and insecure permissions.
The GenieWords WordPress plugin 1.5.27 through 1.5.34 lacks authorization checks on REST API and AJAX actions, allowing unauthenticated attackers to inject arbitrary web scripts.
A double free vulnerability in the Windows Secure Kernel Mode allows an authenticated attacker with high privileges to achieve local privilege escalation.
Anyquery versions prior to 0.4.5 contain an improper access control flaw allowing unauthenticated remote attackers to perform server-side request forgery to access internal network resources.
An authenticated path traversal vulnerability in Laravel-Backpack CRUD allows users with update access to delete arbitrary files from the storage disk by submitting unauthorized file paths.
Zscaler Client Connector on Android and ChromeOS contains an improper input validation flaw that enables local attackers with high privileges to bypass security controls.
PraisonAI agents are vulnerable to IMAP command injection via improper neutralization of user-controlled input in email tools, potentially allowing unauthorized mailbox data manipulation.
A local privilege escalation vulnerability in multiple Apple operating systems allows a malicious application to gain root privileges via a permissions issue.
A path handling vulnerability in Apple macOS allows a local application to escalate privileges to root through improved validation requirements.
A race condition in macOS allows a local malicious application to gain root privileges via improved locking mechanisms.
A privilege escalation vulnerability in macOS allows a local application to gain root privileges due to missing entitlement checks.
A permissions issue in Apple macOS allows a malicious local application to escalate privileges to root, potentially compromising the entire operating system.
A local privilege escalation vulnerability in macOS allows a malicious application to gain root privileges due to insufficient security checks.
A privilege escalation vulnerability in Apple macOS allows a local application to gain root privileges through improved input validation.
A local out-of-bounds write vulnerability in macOS allows a malicious application to gain root privileges through insufficient bounds checking.
A path traversal vulnerability in Apple macOS allows a malicious network directory server to execute arbitrary code with root privileges due to insufficient path validation.
A local privilege escalation vulnerability in Apple macOS allows a malicious application to gain unauthorized root privileges due to insufficient entitlement checks.
A permissions vulnerability in macOS allows a local application to escalate privileges to root, potentially compromising system integrity and security.
An unauthenticated WebSocket server in the LangBot plugin runtime allows remote attackers to register malicious plugins, leading to data exfiltration and persistent denial of service.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 15.
A tapjacking vulnerability exists in InstallLaunch.kt of the Android OS, allowing local escalation of privilege without user interaction.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 15.
A confused deputy vulnerability in the Android background activity launch mechanism allows for local privilege escalation.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 11, analysis completed Sep 15.
A confused deputy vulnerability in the Android Setup Wizard allows an attacker with low privileges to force a connection to a malicious network, leading to local escalation of privilege.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 12, analysis completed Sep 12.
A confused deputy vulnerability exists in the PaymentDefaultDialog component of Android, allowing local attackers to modify the default payment application without user interaction.
Disclosed Sep 8 without a CVSS score; tracked by CVE Brief from Sep 9; scored Sep 12, analysis completed Sep 12.
A permissions bypass vulnerability in the InstallRepository component of Android allows for unauthorized application updates and local privilege escalation without requiring user interaction.
Apache Storm Webapp contains three cross-origin vulnerabilities that allow a malicious third-party site to read sensitive cluster, topology, and log data when an authenticated operator is active.
The Hoo Companion WordPress plugin 1.0.2 lacks authorization and input validation in its import feature, allowing unauthenticated attackers to inject scripts and destroy theme settings.
The YouTube Embed WordPress plugin fails to authorize AJAX actions and sanitize stored data, allowing unauthenticated attackers to execute stored XSS attacks against any site user.
The gettext-converter package for JavaScript is vulnerable to prototype pollution via untrusted translation files, which can lead to denial of service or application-specific secondary attacks.
A static code injection vulnerability in Plesk extensions allows authenticated users to execute arbitrary code as root via manipulated environment variables.
A remote gRPC-Go server can be crashed by an unauthenticated client sending a malformed RPC request that lacks both the authority and Host headers, triggering an unrecoverable index-out-of-bounds panic.
A flaw in Apache Storm Client allows authenticated users to achieve remote code execution by injecting malicious dependency artifacts via predictable blob keys.
An incorrect authorization vulnerability in Apache Doris allows authenticated users to bypass privilege checks and perform unauthorized data access or modifications.
A path traversal vulnerability in the XWiki Platform /skin/ action allows unauthenticated remote attackers to read arbitrary system files when running on Jetty 12 or later.
A vulnerability in the Conform library allows unauthenticated attackers to trigger a denial of service via excessive CPU consumption by submitting crafted forms with many unique field names.
Apache Storm Nimbus fails to perform consistent authorization checks during topology rebalancing and blob listing, allowing authenticated users to access unauthorized data.
The Weights & Biases wandb library before 0.29.0 is vulnerable to a path traversal attack in the File.download function, which fails to sanitize file names retrieved from server responses.
IBM MQ contains a vulnerability involving the deserialization of untrusted data, which allows a remote authenticated attacker to execute arbitrary code on the affected system.
A hidden functionality flaw in LITE-ON FF-RFI079I4 and FF-RFI078I4 devices allows authenticated users with enable mode access to execute arbitrary OS commands.
CPython is vulnerable to a directory traversal flaw in the tarfile module, where crafted archives allow modification of files or exposure of sensitive data outside the intended destination directory.
A use after free vulnerability exists in the Open5GS AMF component due to improper handling of the discovery_option argument in the Old AMF Discovery Fallback function.
A local privilege escalation vulnerability in NetworkManager-l2tp allows local unprivileged users to execute arbitrary commands as root via newline injection in VPN configuration files.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to remote code execution due to improper configuration of the XSLT transformation engine.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is vulnerable to OS command injection, allowing a remote authenticated attacker to execute arbitrary commands.
IBM DataStage on Cloud Pak for Data is vulnerable to remote command execution via improper neutralization of special characters in the PxPeek name property by an authenticated attacker.
SabyasachiRana WebMap contains an OS command injection vulnerability in the nmap_newscan function, allowing unauthenticated remote attackers to execute arbitrary shell commands as root.
A missing authentication vulnerability in the Ecommerce Template checkout handler allows unauthenticated remote attackers to retrieve sensitive customer PII via a valid Stripe session ID.
IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 is vulnerable to information disclosure due to the use of weak or deprecated cryptographic protocols.
An inefficient regular expression in the DotVVM framework allows unauthenticated remote attackers to trigger excessive backtracking, leading to a denial-of-service condition.
IBM DataStage on Cloud Pak for Data 5.4.0.0 is susceptible to a path traversal vulnerability that allows a remote authenticated attacker to read, write, or delete arbitrary files.
BizWell xClick contains an insufficient session expiration flaw that allows unauthorized parties to bypass authentication by reusing old session tokens.
IBM App Connect Enterprise contains an insecure deserialization vulnerability that could allow a local attacker to execute arbitrary code on the affected system.
IBM App Connect Enterprise contains an insecure deserialization vulnerability that could allow a local attacker to execute arbitrary code on the host system.
DevSpace fails to validate tar entry names during in-pod sync, allowing path traversal attacks that can result in arbitrary file write and code execution on the developer workstation.
An OS command injection vulnerability exists in LITE-ON FF-RFI079I4 and FF-RFI078I4 devices, allowing authenticated users to execute arbitrary OS commands via the M-Plane NETCONF interface.
Parallax filament-comments through 3.0.0 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated users to execute malicious scripts within the browser of other users.
PingFederate contains an authorization flaw in the administrative expression evaluation endpoint, allowing authenticated users to exceed their assigned permissions.
Krayin Laravel CRM through 2.2.6 contains an unauthenticated email injection vulnerability in the inbound-parse endpoint, allowing attackers to forge emails within the CRM inbox.
A race condition in the Zscaler Client Connector ZPA tunnel handler can lead to heap corruption, causing a denial of service or potential remote code execution in the ZCC process context.
File Browser versions 2.5.0 through 2.63.23 are vulnerable to unauthorized directory deletion via a flaw in the direct-upload endpoint's failure-cleanup process.
Flextype CMS through 1.0.0-alpha.3 contains a path traversal vulnerability in the Entries REST API that allows authenticated API token holders to read, create, or overwrite arbitrary filesystem files.
IBM App Connect Enterprise contains an OS command injection vulnerability allowing local attackers to execute arbitrary code via improper neutralization of special elements.
A vulnerability in the Skipper HTTP router allows unauthenticated attackers to bypass OPA authorization policies by sending requests with oversized Content-Length headers.
Disclosed Sep 8; published with a limited analysis after repeated re-checks found no further public detail.
The yfexam-exam v2.0 application uses a predictable JWT signing secret, allowing attackers to bypass authentication via brute force.