Exploited, not yet in the CISA catalogue
138 flaws exploited and not yet official
These vulnerabilities have public evidence of exploitation but are not in the CISA catalogue yet. They carry no legal deadline: they carry evidence. Where CISA does arrive, it arrives a median of 20 days later.
- CVE-2021-2109seen by sensorsnot in the CISA catalogue
Oracle · WebLogic Server
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP
Sources: dashboard.shadowserver.org
- CVE-2016-5312seen by sensorsnot in the CISA catalogue
Symantec · messaging_gateway
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.
Sources: dashboard.shadowserver.org
- CVE-2026-45298seen by sensorsnot in the CISA catalogue
amirraminfar · dozzle
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2025-55583not in the CISA catalogue
D-Link · dir-868l_firmware
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi component. The endpoint /dws/api/UploadFile accepts a pre_api_arg parameter that is passed directly to system-level shell execution functions without sanitizati
Sources: fortinet.com
- CVE-2025-10123not in the CISA catalogue
D-Link · dir-823x_firmware
A vulnerability was determined in D-Link DIR-823X up to 250416. Affected by this vulnerability is the function sub_415028 of the file /goform/set_static_leases. Executing manipulation of the argument Hostname can lead to command injection. The attack can be launched remotely. The exploit has been pu
Sources: fortinet.com
- CVE-2024-58374HIGH7.5not in the CISA catalogue
Hongjing Century · e-HR
Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers
Sources: cve.org
- CVE-2020-9771not in the CISA catalogue
Apple · MacOS X
This issue was addressed with a new entitlement. This issue is fixed in macOS Catalina 10.15.4. A user may gain access to protected parts of the file system.
Sources: jamf.com
- CVE-2019-25765HIGH7.5not in the CISA catalogue
ASP-CMS Project · ASP-CMS
ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword blocklist by interleaving
Sources: kevintel.com · cve.org
Microsoft · SharePoint
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Sources: cydome.io · kevintel.com · x.com
- CVE-2022-50997not in the CISA catalogue
Weaver Network Co., Ltd. · E-cology 9.0
Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a single crafted GET request
Sources: kevintel.com · cve.org
- CVE-2016-20097HIGH7.5not in the CISA catalogue
Weaver Network Co., Ltd. · E-cology 8.0
Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a SQL query. Attackers c
Sources: kevintel.com · cve.org
- CVE-2026-66443HIGH7.5not in the CISA catalogue
Pete Nelson · REST API Log
Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
Sources: patchstack.com
- CVE-2026-66441HIGH7.5not in the CISA catalogue
MultiVendorX · MultiVendorX
Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
Sources: patchstack.com
- CVE-2026-48294not in the CISA catalogue
Adobe · Acrobat and Reader
Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that
Sources: watchguard.com
Apple · macos
An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
Sources: advisories.ncsc.nl · ncsc.nl
- CVE-2026-2652seen by sensorsnot in the CISA catalogue
lfprojects · mlflow
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) and served via uvicorn (ASGI). The FastAPI permission middleware only enforces authentication on `/gate
Sources: dashboard.shadowserver.org · crowdsec.net · kevintel.com
- CVE-2026-15459HIGH8.1not in the CISA catalogue
wpmudev · WPMU DEV Dashboard
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature is empty, making the signa
Sources: patchstack.com
- CVE-2018-14013seen by sensorsnot in the CISA catalogue
Synacor · Zimbra Collaboration Suite (ZCS)
Synacor Zimbra Collaboration Suite Collaboration before 8.8.11 has XSS in the AJAX and html web clients.
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2026-66665CRITICAL10.0not in the CISA catalogue
Brandexponents · Type Hub
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Sources: patchstack.com
- CVE-2026-16144HIGH8.1not in the CISA catalogue
kaliforms · contact_form_builder
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermalink' field value before it overwrites a trusted callabl
Sources: patchstack.com
- CVE-2026-28409seen by sensorsnot in the CISA catalogue
wegia · wegia
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authenticat
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2026-28139CRITICAL9.8not in the CISA catalogue
wpdreams · Ajax Search Lite
Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Sources: patchstack.com
- CVE-2026-65442HIGH7.2not in the CISA catalogue
Subtle Web Inc · FormCraft
Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.
Sources: patchstack.com
- CVE-2026-54066seen by sensorsnot in the CISA catalogue
b3log · siyuan
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding") sanitized the /export/ route but the identical root cause remains in the /assets/*path route. In publish mode (anonymous read-only HTTP endpoint, def
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2026-38992seen by sensorsnot in the CISA catalogue
agentejo · cockpit
Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2025-71324seen by sensorsnot in the CISA catalogue
FlowiseAI · Flowise
Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup path constructed witho
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2023-54359seen by sensorsnot in the CISA catalogue
Adivaha · WordPress adivaha Travel Plugin
WordPress adivaha Travel Plugin 2.3 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pid' GET parameter. Attackers can send requests to the /mobile-app/v3/ endpoint with crafted 'pid' value
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2023-2825seen by sensorsnot in the CISA catalogue
GitLab · gitlab
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2026-73533CRITICAL9.8not in the CISA catalogue
WPManageNinja · Ninja Tables Pro
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, d
Sources: kevintel.com · cve.org · wpmanageninja.com
- CVE-2026-73532CRITICAL9.8not in the CISA catalogue
WPManageNinja · Fluent Forms Pro
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php,
Sources: cve.org · patchstack.com · wpmanageninja.com
- CVE-2026-53576seen by sensorsnot in the CISA catalogue
kestra · kestra
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a credential check. kestra addre
Sources: api.vulncheck.com
- CVE-2026-48313seen by sensorsnot in the CISA catalogue
Adobe · ColdFusion
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive fil
Sources: dashboard.shadowserver.org · kevintel.com · crowdsec.net
- CVE-2026-3836seen by sensorsnot in the CISA catalogue
Linux · dnf5
A local, unprivileged attacker can exploit a path traversal flaw in the D-Bus locale configuration, crashing dnf5daemon-server via a crafted string. This can lead to a DoS with a core dump.
Sources: dashboard.shadowserver.org
litellm · litellm
LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.
Sources: api.vulncheck.com
Microsoft · Windows
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Sources: tenable.com · recordedfuture.com · unit42.paloaltonetworks.com
- CVE-2026-67595HIGH8.1not in the CISA catalogue
webreinvent · vaahcms
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled.
Sources: kevintel.com · cve.org
- CVE-2026-65885HIGH8.8not in the CISA catalogue
balbooa.com · Gridbox extension for Joomla
Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the attacker.
Sources: mysites.guru
- CVE-2026-65884CRITICAL9.8not in the CISA catalogue
balbooa.com · Gridbox extension for Joomla
Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.
Sources: mysites.guru
- CVE-2026-58138seen by sensorsnot in the CISA catalogue
netflix · conductor
Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to au
Sources: api.vulncheck.com
- CVE-2026-59553HIGH7.1not in the CISA catalogue
RexTheme · Product Feed Manager
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Sources: patchstack.com
- CVE-2026-8496MEDIUM6.1not in the CISA catalogue
Alinto SOGo · SOGo
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated SOGo webmail session. The issue occurs because SVG content embedded in the description field of an ICS
Sources: proofpoint.com
alibaba · fastjson
A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.
Sources: recordedfuture.com · webflow.sysdig.com · kevintel.com · threatbook.io
- CVE-2025-62631not in the CISA catalogue
Fortinet · FortiOS
An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker to maintain access to network resources via an active SSLVPN session not terminated after a user's password
Sources: levelblue.com
- CVE-2026-44825not in the CISA catalogue
Apache · Solr
Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specifie
Sources: research.empiricalsecurity.com
- CVE-2026-58455seen by sensorsnot in the CISA catalogue
Notifiarr · dockwatch
Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands by exploiting a missing exit() after an authentication redirect in loader.php combined with unsanitized input passed to shell_exec() in ajax/compo
Sources: api.vulncheck.com
- CVE-2026-4480not in the CISA catalogue
Red Hat · openshift_container_platform
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sen
Sources: hunt.io
- CVE-2025-68493seen by sensorsnot in the CISA catalogue
Apache · Struts
Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.
Sources: dashboard.shadowserver.org
- CVE-2016-4800not in the CISA catalogue
eclipse · jetty
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
Sources: f5.com
- CVE-2007-6672not in the CISA catalogue
mortbay_jetty · jetty
Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
Sources: f5.com
- CVE-2005-0869not in the CISA catalogue
phpsysinfo · phpsysinfo
phpSysInfo 2.3 allows remote attackers to obtain sensitive information via a direct request to (1) class.OpenBSD.inc.php, (2) class.NetBSD.inc.php, (3) class.FreeBSD.inc.php, (4) class.Darwin.inc.php, (5) XPath.class.php, (6) system_header.php, or (7) system_footer.php, which reveal the path in a PH
Sources: f5.com
- CVE-2026-6875not in the CISA catalogue
ServiceNow · ServiceNow AI Platform
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying
Sources: recordedfuture.com · kevintel.com · x.com
- CVE-2026-29059seen by sensorsnot in the CISA catalogue
windmill · windmill
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to version 1.603.3, an unauthenticated path traversal vulnerability exists in Windmill's get_log_file endpoint "(/api/w/{workspace}/jobs_u/get_log_file/{filename})". The filename paramete
Sources: api.vulncheck.com · recordedfuture.com · kevintel.com · linkedin.com
- CVE-2016-0638not in the CISA catalogue
Oracle · WebLogic Server
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.
Sources: blog.xlab.qianxin.com
- CVE-2026-9282not in the CISA catalogue
boldgrid · w3_total_cache
The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Sources: patchstack.com
- CVE-2026-14894not in the CISA catalogue
WebRehab · Super Forms – Drag & Drop Form Builder
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handle
Sources: patchstack.com
- CVE-2026-45586not in the CISA catalogue
Microsoft · Windows
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
Sources: recordedfuture.com
- CVE-2026-44963not in the CISA catalogue
Veeam · veeam_backup_\&_replication
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
Sources: recordedfuture.com
- CVE-2026-2699seen by sensorsnot in the CISA catalogue
Progress · sharefile_storage_zones_controller
Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution.
Sources: dashboard.shadowserver.org
- CVE-2020-17103not in the CISA catalogue
Microsoft · Windows
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Sources: recordedfuture.com
- CVE-2026-3395not in the CISA catalogue
max-3000 · maxsite_cms
A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/preview-ajax.php of the component MarkItUp Preview AJAX Endpoint. Executing a manipulation can lead to code injection. It is possible to launch the attack re
Sources: recordedfuture.com · cyber.gov.au
- CVE-2026-31843CRITICAL9.8not in the CISA catalogue
goodoneuz · pay-uz
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remot
Sources: recordedfuture.com · cyber.gov.au
- CVE-2025-7852not in the CISA catalogue
iqonic · wpbookit
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function hooked via the 'add_new_customer' route in all versions up to, and including, 1.0.6. The plugin’s image‐upload handler calls move_uploaded_file() on cli
Sources: recordedfuture.com · socradar.io · cyber.gov.au
- CVE-2026-4631seen by sensorsnot in the CISA catalogue
GNU · grub2
Cockpit's remote login feature passes user-supplied hostnames and usernames from the web interface to the SSH client without validation or sanitization. An attacker with network access to the Cockpit web service can craft a single HTTP request to the login endpoint that injects malicious SSH options
Sources: dashboard.shadowserver.org
- CVE-2026-59800seen by sensorsnot in the CISA catalogue
decolua · 9router
9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route is not covered by the dashboard middleware matcher, so no authorization check is applied). The sudoPassword field from the request body is written to th
Sources: dashboard.shadowserver.org · kevintel.com · cve.org
- CVE-2020-22658not in the CISA catalogue
ruckuswireless · r310_firmware
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Vir
Sources: recordedfuture.com · blog.talosintelligence.com
- CVE-2020-22653not in the CISA catalogue
ruckuswireless · r310_firmware
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Vir
Sources: recordedfuture.com · blog.talosintelligence.com
- CVE-2026-20896not in the CISA catalogue
Gitea · Gitea Open Source Git Server
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
Sources: csa.gov.sg · linkedin.com
- CVE-2023-39361seen by sensorsnot in the CISA catalogue
Cacti · Cacti
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there co
Sources: dashboard.shadowserver.org
- CVE-2026-58480not in the CISA catalogue
Creative Themes · Blocksy Companion
Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exp
Sources: cve.org · patchstack.com
- CVE-2026-5524not in the CISA catalogue
Divi Engine · Divi Form Builder
The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including 5.1.8. This is due to insufficient file extension validation in the do_image_upload() function where user-supplied input from the acceptFileTypes POS
Sources: patchstack.com
- CVE-2026-1125seen by sensorsnot in the CISA catalogue
D-Link · dir-823x_firmware
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The exploit has been made avail
Sources: dashboard.shadowserver.org · kevintel.com
- CVE-2024-58352not in the CISA catalogue
Shenzhen Landray Software Co., Ltd. · Landry Office Automation (OA)
Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitizatio
Sources: cve.org
- CVE-2024-14037not in the CISA catalogue
Guangzhou Red Sea Cloud Computing Co., Ltd. · Red Sea Cloud eHR
Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading malicious files through the PtFjk.mob servlet endpoint. Attackers can submit a multipart POST request with a JSP webshell disguised using a spoofed ima
Sources: cve.org
- CVE-2022-50973not in the CISA catalogue
Yonyou Network Technology Co., Ltd. · KSOA
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters without any authentication
Sources: cve.org
- CVE-2026-8451seen by sensorsnot in the CISA catalogue
Citrix · NetScaler ADC and NetScaler Gateway
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
Sources: crowdsec.net · kevintel.com · lupovis.io
- CVE-2026-57624not in the CISA catalogue
Creative Themes · Blocksy Companion Pro
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Sources: patchstack.com
- CVE-2026-13731not in the CISA catalogue
quantumcloud · wpbot
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'conversation' parameter in all versions up to, and including, 8.4.9 due to insufficient input sanitization and output escaping. This makes it possible for
Sources: patchstack.com
- CVE-2018-8007not in the CISA catalogue
Apache · CouchDB
Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user tha
Sources: blog.xlab.qianxin.com
- CVE-2026-52806not in the CISA catalogue
gogs · gogs
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially crafted branch name that injects the --exec flag into the git rebase command during the "Rebase before mer
Sources: threats.wiz.io
- CVE-2026-8054seen by sensorsnot in the CISA catalogue
dotCMS · dotCMS Core
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11.04-1 through 26.04.28-02 allows remote unauthenticated attackers to read, modify, or destroy arbitra
Sources: dashboard.shadowserver.org · kevintel.com
Why a separate page
Data from CISA’s Known Exploited Vulnerabilities catalog, a US Government work in the public domain. The deadlines shown are binding on US federal agencies (BOD 22-01); for everyone else they are a sound priority reference.
Exploitation data: VulnCheck KEV. The known exploited vulnerabilities catalogue is CISA's.