CRITICAL
CVE-2026-81096
2026-08-28
A critical zero-day vulnerability in ToolUniverse's Python executor tool allows unauthenticated attackers to execute arbitrary code with full system privileges. This flaw, rated CV…
Read analysis →
CRITICAL
CVE-2026-81735
2026-08-28
A critical-severity vulnerability (CVE-2026-81735) has been identified affecting mcp-http-server, mcp-server-commands, mcp-server-filesystem, startserver.ts, ui-tars-desktop. Organ…
Read analysis →
CRITICAL
CVE-2026-22306
2026-08-28
A critical vulnerability in Ozols Grupa's software components, rated CVSS 10.0, allows attackers to execute arbitrary code on affected systems through a compromised update channel.…
Read analysis →
CRITICAL
CVE-2026-46838
2026-08-27
A critical vulnerability in Oracle WebCenter Portal (CVE-2026-46838) enables unauthenticated attackers to fully compromise systems via HTTPS. With a CVSS score of 9.9, this flaw af…
Read analysis →
CRITICAL
CVE-2024-52488
2026-08-27
A critical-severity vulnerability (CVE-2024-52488) has been identified affecting grip. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-39591
2026-08-27
A critical-severity vulnerability (CVE-2026-39591) has been identified affecting wordpress, wp-businessdirectory. Organizations should review their exposure and apply available pat…
Read analysis →
CRITICAL
CVE-2026-20358
2026-08-27
A critical vulnerability in Cisco Crosswork (CVE-2026-20358) with a CVSS score of 10.0 enables unauthenticated remote code execution. Attackers can exploit this flaw by sending cra…
Read analysis →
CRITICAL
CVE-2026-35316
2026-08-26
A critical vulnerability in Oracle WebCenter Content, CVE-2026-35316, exposes enterprises to unauthenticated remote takeover. With a CVSS score of 9.9, this flaw enables low-privil…
Read analysis →
CRITICAL
CVE-2026-46765
2026-08-26
A critical vulnerability in Oracle WebCenter Portal (CVE-2026-46765) with a CVSS score of 9.9 grants low-privilege attackers unauthorized system control via HTTP. Affected versions…
Read analysis →
CRITICAL
CVE-2026-46779
2026-08-26
A critical-severity vulnerability (CVE-2026-46779) has been identified affecting oracle_fusion_middleware, oracle_webcenter_enterprise_capture. Organizations should review their ex…
Read analysis →
CRITICAL
CVE-2026-35283
2026-08-26
A critical-severity vulnerability (CVE-2026-35283) has been identified affecting fusion_middleware, webcenter_enterprise_capture. Organizations should review their exposure and app…
Read analysis →
CRITICAL
CVE-2026-35285
2026-08-26
A critical-severity vulnerability (CVE-2026-35285) has been identified affecting oracle_fusion_middleware, oracle_webcenter_enterprise_capture. Organizations should review their ex…
Read analysis →
CRITICAL
CVE-2026-46802
2026-08-25
A critical-severity vulnerability (CVE-2026-46802) has been identified affecting oracle_webcenter_portal. Organizations should review their exposure and apply available patches imm…
Read analysis →
CRITICAL
CVE-2026-46814
2026-08-25
A critical vulnerability in Oracle WebCenter Portal (CVE-2026-46814) allows unauthenticated attackers to execute arbitrary code remotely, with a CVSS score of 9.9. This flaw poses …
Read analysis →
CRITICAL
CVE-2026-46893
2026-08-25
A critical-severity vulnerability (CVE-2026-46893) has been identified affecting jd_edwards_enterpriseone_general_ledger. Organizations should review their exposure and apply avail…
Read analysis →
CRITICAL
CVE-2026-46855
2026-08-24
A critical vulnerability in Oracle Enterprise Manager Base Platform, CVE-2026-46855, allows unauthenticated attackers to take over the system via HTTPS with a CVSS score of 9.9. Su…
Read analysis →
CRITICAL
CVE-2026-46901
2026-08-24
A critical vulnerability in Oracle Enterprise Command Center Framework (CVE-2026-46901) allows unauthorized data manipulation via HTTP, posing significant risks to Defense Industri…
Read analysis →
CRITICAL
CVE-2026-46895
2026-08-24
A critical-severity vulnerability (CVE-2026-46895) has been identified affecting oracle_enterprise_command_center_framework. Organizations should review their exposure and apply av…
Read analysis →
CRITICAL
CVE-2026-35323
2026-08-24
A critical vulnerability in Oracle WebCenter Content (CVE-2026-35323) allows unauthenticated attackers to achieve remote code execution via HTTP, posing a severe risk to enterprise…
Read analysis →
CRITICAL
CVE-2026-46852
2026-08-24
A critical vulnerability in Oracle Enterprise Manager Base Platform's Metadata Plugin (CVE-2026-46852) allows low-privileged attackers to fully compromise systems via HTTPS. With a…
Read analysis →
CRITICAL
CVE-2026-22327
2026-08-23
A critical-severity vulnerability (CVE-2026-22327) has been identified affecting restaurt. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-46854
2026-08-23
A critical unauthenticated vulnerability in Oracle Enterprise Manager Base Platform (CVE-2026-46854) has been disclosed with a CVSS score of 9.9, enabling remote attackers to fully…
Read analysis →
CRITICAL
CVE-2025-60218
2026-08-23
A critical-severity vulnerability (CVE-2025-60218) has been identified affecting pt luxa addons, wordpress. Organizations should review their exposure and apply available patches i…
Read analysis →
CRITICAL
CVE-2026-40746
2026-08-23
A critical-severity vulnerability (CVE-2026-40746) has been identified affecting restaurant_zone. Organizations should review their exposure and apply available patches immediately…
Read analysis →
CRITICAL
CVE-2026-49252
2026-08-23
A critical-severity vulnerability (CVE-2026-49252) has been identified affecting deepstream. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-52785
2026-08-23
A critical-severity vulnerability (CVE-2026-52785) has been identified affecting openproject. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-25446
2026-08-23
A critical-severity vulnerability (CVE-2026-25446) has been identified affecting wishlist member x, wordpress. Organizations should review their exposure and apply available patche…
Read analysis →
CRITICAL
CVE-2026-55115
2026-08-23
A critical Server-Side Request Forgery (SSRF) vulnerability in UniFi Protect (CVE-2026-55115) allows attackers to escalate privileges on host devices with minimal access, posing si…
Read analysis →
CRITICAL
CVE-2026-46907
2026-08-23
A critical vulnerability in Oracle JD Edwards EnterpriseOne Order Promising (CVE-2026-46907) allows attackers to achieve remote code execution with minimal privileges. With a CVSS …
Read analysis →
CRITICAL
CVE-2026-7873
2026-08-23
A critical-severity vulnerability (CVE-2026-7873) has been identified affecting langflow. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-48781
2026-08-22
A critical-severity vulnerability (CVE-2026-48781) has been identified affecting postiz, skool. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-56142
2026-08-22
A critical vulnerability in JetBrains Hub allows attackers to escalate privileges by manipulating authentication parameters, posing a high risk to enterprises and defense infrastru…
Read analysis →
CRITICAL
CVE-2026-54305
2026-08-22
A critical vulnerability in n8n's Dynamic Credentials feature allows authenticated users to enumerate sensitive credential information and overwrite OAuth tokens, enabling unauthor…
Read analysis →
CRITICAL
CVE-2026-55454
2026-08-22
A critical-severity vulnerability (CVE-2026-55454) has been identified affecting appsmith, caddy. Organizations should review their exposure and apply available patches immediately…
Read analysis →
CRITICAL
CVE-2026-48584
2026-08-22
A critical-severity vulnerability (CVE-2026-48584) has been identified affecting azure_synapse. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-65801
2026-08-21
A critical-severity vulnerability (CVE-2026-65801) has been identified affecting microsoft exchange online. Organizations should review their exposure and apply available patches i…
Read analysis →
CRITICAL
CVE-2026-75874
2026-08-21
A critical-severity vulnerability (CVE-2026-75874) has been identified affecting firefox, remote settings client, thunderbird. Organizations should review their exposure and apply …
Read analysis →
CRITICAL
CVE-2026-20315
2026-08-20
CVE-2026-20315, a critical vulnerability in Cisco Secure Workload with a CVSS score of 10.0, allows attackers to bypass authentication mechanisms and access privileged systems. Thi…
Read analysis →
CRITICAL
CVE-2026-20317
2026-08-20
Cisco Secure Workload, a component used in critical infrastructure and enterprise environments, contains a critical improper authentication vulnerability (CVE-2026-20317) with a CV…
Read analysis →
CRITICAL
CVE-2026-76008
2026-08-20
A critical vulnerability in Comfast CF-N1-S firmware versions 2.6.0.1 enables remote code execution via a stack-based buffer overflow. This zero-day flaw, rated CVSS 10.0, poses im…
Read analysis →
CRITICAL
CVE-2026-73343
2026-08-20
A critical-severity vulnerability (CVE-2026-73343) has been identified affecting wordpress, wp compress. Organizations should review their exposure and apply available patches imme…
Read analysis →
CRITICAL
CVE-2026-61241
2026-08-19
CVE-2026-61241 is a zero-day vulnerability in Oracle Internet Directory with a CVSS 10.0 score, enabling unauthenticated remote takeover via LDAP. Oracle Fusion Middleware users mu…
Read analysis →
CRITICAL
CVE-2026-70880
2026-08-19
CVE-2026-70880 is a CVSS 10.0 unauthenticated remote code execution vulnerability in Oracle Hyperion Data Relationship Management 11.2.25.0.000. Attackers can exploit it over TCP w…
Read analysis →
CRITICAL
CVE-2026-70921
2026-08-19
CVE-2026-70921 is a CVSS 10.0 flaw in Oracle Hyperion Financial Management 11.2.25.0.000 that enables unauthenticated attackers to achieve full read/write/delete access to sensitiv…
Read analysis →
CRITICAL
CVE-2026-75784
2026-08-19
CVE-2026-75784 is a critical, remotely exploitable stack-based buffer overflow in TRENDnet TEW-WLC100 wireless LAN controllers. The flaw resides in the nginx HTTP header handler, e…
Read analysis →
CRITICAL
CVE-2026-74843
2026-08-19
CVE-2026-74843 is a CVSS 10.0 stack-based buffer overflow vulnerability in Wavlink WN531P3/535M1 routers, enabling unauthenticated remote code execution via manipulated HTTP_COOKIE…
Read analysis →
CRITICAL
CVE-2026-19977
2026-08-19
A critical-severity vulnerability (CVE-2026-19977) has been identified affecting efm iptime a3004t. Organizations should review their exposure and apply available patches immediate…
Read analysis →
CRITICAL
CVE-2026-73678
2026-08-19
A critical unauthenticated remote code execution (RCE) vulnerability in MindsDB Minds Platform 26.1.0 and earlier allows attackers to run arbitrary OS commands, granting access to …
Read analysis →
CRITICAL
CVE-2026-72811
2026-08-19
A critical-severity vulnerability (CVE-2026-72811) has been identified affecting siyuan. Organizations should review their exposure and apply available patches immediately.…
Read analysis →
CRITICAL
CVE-2026-19188
2026-08-19
A critical-severity vulnerability (CVE-2026-19188) has been identified affecting haiwell iot cloud hmi gateway. Organizations should review their exposure and apply available patch…
Read analysis →
CRITICAL
CVE-2026-72851
2026-08-18
CVE-2026-72851 is a CVSS 10.0 SQL injection vulnerability in Budibase versions before 3.40.0 that enables unauthenticated attackers to execute arbitrary SQL commands on connected d…
Read analysis →
CRITICAL
CVE-2026-27544
2026-08-18
CVE-2026-27544 represents an unauthenticated remote code execution (RCE) vulnerability in QA Analytics versions up to 5.2.0.0. This CVSS 10.0 flaw enables full system compromise wi…
Read analysis →
CRITICAL
CVE-2026-61962
2026-08-18
A CVSS 10.0 critical vulnerability (CVE-2026-61962) in the WP BASE Booking WordPress plugin enables unauthenticated attackers to execute arbitrary code serverside, enabling full sy…
Read analysis →
CRITICAL
CVE-2026-59500
2026-08-18
CVE-2026-59500, an improper authentication vulnerability with CVSS 10.0 severity, enables unauthenticated attackers to gain administrative access. Exploitation is confirmed active,…
Read analysis →
CRITICAL
CVE-2026-15413
2026-08-18
CVE-2026-15413 reveals a supply-chain backdoor in the Link Factory WordPress plugin, enabling unauthenticated remote code execution via a REST API secured with a hardcoded cryptogr…
Read analysis →
CRITICAL
CVE-2026-45618
2026-08-17
CVE-2026-45618 represents an unauthenticated remote code execution (RCE) vulnerability with CVSS 10.0 severity affecting LiquidJS versions prior to 10.26.0. This flaw exposes Shopi…
Read analysis →
CRITICAL
CVE-2026-17061
2026-08-17
CVE-2026-17061 represents an unprecedented risk due to its CVSS 10.0 severity score, enabling unauthenticated attackers to execute arbitrary code on vulnerable SIMULIA Execution En…
Read analysis →
CRITICAL
CVE-2026-48056
2026-08-17
CVE-2026-48056 is a high-severity vulnerability in Streambert Desktop App that enables privilege-escalating code execution. Unvalidated IPC path handling allows attackers to execut…
Read analysis →
CRITICAL
CVE-2026-58115
2026-08-17
CVE-2026-58115 is a CVSS 10.0 critical vulnerability in Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED, enabling unauthenticated attackers to execute …
Read analysis →
CRITICAL
CVE-2026-58231
2026-08-17
CVE-2026-58231 is a critical 10.0 CVSS-scored vulnerability in SAP Commerce Cloud that allows unauthenticated attackers to execute arbitrary code via a default authentication clien…
Read analysis →
CRITICAL
CVE-2026-59726
2026-08-16
CVE-2026-59726 represents a CVSS 10.0 vulnerability in Ruflo's default deployment, enabling unauthenticated remote code execution to steal API keys and compromise AI training data.…
Read analysis →
CRITICAL
CVE-2026-54769
2026-08-16
A critical-severity vulnerability (CVE-2026-54769) has been identified affecting langroid, tablechatagent, vectorstore. Organizations should review their exposure and apply availab…
Read analysis →
CRITICAL
CVE-2026-48323
2026-08-16
Adobe Campaign Classic (ACC) is vulnerable to a server-side template injection flaw (CVE-2026-48323) with a CVSS 10.0 score, enabling unauthenticated attackers to achieve remote co…
Read analysis →
CRITICAL
CVE-2026-48330
2026-08-16
Adobe Campaign Classic (ACC) suffers from a critical SQL injection vulnerability (CVE-2026-48330) with a CVSS score of 10.0. Attackers can exploit this flaw to execute arbitrary SQ…
Read analysis →
CRITICAL
CVE-2026-48331
2026-08-16
Adobe Campaign Classic harbors a critical SSRF vulnerability (CVE-2026-48331) with a 10.0 CVSS score, allowing unauthenticated attackers to forge server requests, escalate privileg…
Read analysis →
CRITICAL
CVE-2026-18452
2026-08-15
A CVSS 10.0 vulnerability in Rich Source's DMS+ (CVE-2026-18452) allows remote attackers to bypass all authentication via a hard-coded API key, enabling full device control without…
Read analysis →
CRITICAL
CVE-2026-66803
2026-08-15
CVE-2026-66803, a critical remote code execution flaw in Azure Cosmos DB, enables unauthenticated attackers to bypass access controls and execute arbitrary code. With a CVSS score …
Read analysis →
CRITICAL
CVE-2026-48449
2026-08-15
Adobe Campaign Classic (ACC) is vulnerable to a critical remote code execution flaw (CVE-2026-48449) with a CVSS 10.0 rating, enabling unauthenticated attackers to execute arbitrar…
Read analysis →
CRITICAL
CVE-2026-33267
2026-08-15
CVE-2026-33267 grants unauthenticated remote code execution via malformed HTTP requests to Apache Traffic Server (ATS) versions 9.2.0-10.1.3. With a CVSS 10.0 score and confirmed w…
Read analysis →
CRITICAL
CVE-2026-16326
2026-08-15
CVE-2026-16326 represents a CVSS 10.0 critical vulnerability in HashiCorp's consul-mcp-server, enabling cross-client authentication token reuse. Exploitation allows unauthorized ac…
Read analysis →
CRITICAL
CVE-2026-16498
2026-08-14
A zero-day vulnerability in Terraform MCP Server (CVE-2026-16498) enables cross-tenant credential theft in shared deployments, exposing enterprise cloud configurations to lateral m…
Read analysis →
CRITICAL
CVE-2026-11756
2026-08-14
CVE-2026-11756, a CVSS 10.0-rated deserialization flaw in the 3DEXPERIENCE platform's Station Launcher App, enables unauthenticated remote code execution. Weaponized exploits alrea…
Read analysis →
CRITICAL
CVE-2026-16812
2026-08-14
CVE-2026-16812 represents a CVSS 10.0 vulnerability in VeloCloud Orchestrator (VCO) on-prem installations, enabling unauthenticated remote attackers to access privileged internal A…
Read analysis →
CRITICAL
CVE-2026-66012
2026-08-14
CVE-2026-66012, a CVSS-10.0 vulnerability in SiYuan, allows unauthenticated attackers to bypass authorization and perform arbitrary file operations, including data exfiltration and…
Read analysis →
CRITICAL
CVE-2026-56163
2026-08-14
CVE-2026-56163 is a high-severity vulnerability in Azure Kubernetes Service (AKS) that enables unauthenticated attackers to escalate privileges within managed Kubernetes clusters. …
Read analysis →
CRITICAL
CVE-2025-71389
2026-08-13
CVE-2025-71389 represents a CVSS 10.0 unauthenticated remote code execution vulnerability in Cal.com's self-hosted cal.diy variant. Exploitation requires no credentials or user int…
Read analysis →
CRITICAL
CVE-2026-47668
2026-08-13
CVE-2026-47668 represents a critical remote code execution (RCE) vulnerability in DbGate database manager versions 7.1.8 and earlier. Attackers can exploit this flaw without authen…
Read analysis →
CRITICAL
CVE-2026-6516
2026-08-13
CVE-2026-6516 is a CVSS-10.0 unauthenticated remote code execution (RCE) flaw in ManageEngine ADAudit Plus versions before 8606. Exploitation allows attackers to execute arbitrary …
Read analysis →
CRITICAL
CVE-2026-59555
2026-08-13
CVE-2026-59555 is a CVSS 10.0 vulnerability in the Participants Database WordPress plugin allowing unauthenticated attackers to delete arbitrary server files. This risk is especial…
Read analysis →
CRITICAL
CVE-2026-64812
2026-08-13
CVE-2026-64812 represents a CVSS 10.0 vulnerability in JetBrains IntelliJ IDEA that enables remote code execution during collaborative development sessions. Attackers can exploit t…
Read analysis →
CRITICAL
CVE-2026-54350
2026-08-12
CVE-2026-54350 represents a critical remote code execution flaw in Budibase, enabling unauthenticated attackers to read and modify documents in connected databases with no access c…
Read analysis →
CRITICAL
CVE-2026-46800
2026-08-12
A critical zero-day vulnerability in Oracle WebCenter Sites (CVE-2026-46800) allows remote attackers to achieve unauthenticated system takeover via HTTP. With a CVSS score of 10.0,…
Read analysis →
CRITICAL
CVE-2026-3490
2026-08-12
A critical remote code execution vulnerability (CVSS 10.0) in picklescan enables attackers to bypass blocklists and execute arbitrary code via malicious pickle payloads. Unpatched …
Read analysis →
CRITICAL
CVE-2026-50242
2026-08-12
CVE-2026-50242 in JetBrains Hub (CVSS 10.0) introduces a critical authentication bypass vulnerability, allowing attackers with direct database access to escalate privileges to admi…
Read analysis →
CRITICAL
CVE-2026-12848
2026-08-12
A stack overflow vulnerability in the default DVRSearch service of GV-I/O Box 4E enables unauthenticated attackers to execute arbitrary code remotely via crafted UDP packets. This …
Read analysis →
CRITICAL
CVE-2026-48276
2026-08-12
ColdFusion servers running versions 2025.9 or 2023.20 and earlier face an immediate critical-risk vulnerability (CVE-2026-48276) allowing unauthenticated attackers to execute arbit…
Read analysis →
CRITICAL
CVE-2026-46803
2026-08-12
CVE-2026-46803, a critical 10.0 CVSS-rated vulnerability, allows unauthenticated attackers to execute arbitrary code remotely in Oracle WebCenter Portal. Exploitation requires no u…
Read analysis →
CRITICAL
CVE-2026-45480
2026-08-12
Microsoft Azure Active Directory contains a critical vulnerability allowing attackers to bypass authentication mechanisms and escalate to admin privileges. Immediate patching is re…
Read analysis →
CRITICAL
CVE-2026-48286
2026-08-12
CVE-2026-48286 represents an unprecedented risk with a CVSS 10.0 score, enabling unauthenticated attackers to execute arbitrary code remotely without user interaction. This flaw af…
Read analysis →
CRITICAL
CVE-2026-46781
2026-08-12
Oracle Fusion Middleware's Oracle WebCenter Enterprise Capture contains a CVSS 10.0 flaw exploitable via unauthenticated RMI requests, enabling remote attackers to fully compromise…
Read analysis →
CRITICAL
CVE-2026-48055
2026-08-11
A critical Zip Slip vulnerability (CVE-2026-48055) in Streambert's subtitle extraction logic allows attackers to overwrite arbitrary files on host systems. With a CVSS score of 10.…
Read analysis →
CRITICAL
CVE-2026-48020
2026-08-11
CVE-2026-48020 (CVSS 10.0) is a zero-day vulnerability in Traefik's StripPrefix middleware that allows unauthenticated attackers to bypass authentication and access protected route…
Read analysis →
CRITICAL
CVE-2026-47131
2026-08-11
CVE-2026-47131 is a critical vulnerability in the Node.js vm2 library that enables unauthenticated attackers to bypass sandbox restrictions and execute arbitrary code with ease. Un…
Read analysis →
CRITICAL
CVE-2026-52704
2026-08-11
A high-severity code injection vulnerability (CVE-2026-52704) in the WooCommerce PDF Invoice Builder plugin for WordPress allows remote code execution with critical 10.0 CVSS impac…
Read analysis →
CRITICAL
CVE-2026-46778
2026-08-11
CVE-2026-46778 exposes Oracle WebCenter Enterprise Capture to unauthenticated RMI deserialization attacks, enabling remote takeover with systemic impacts. With a CVSS 10.0 score, t…
Read analysis →
CRITICAL
CVE-2026-54309
2026-08-11
CVE-2026-54309, a critical unauthenticated remote code execution flaw in n8n, enables attackers to hijack browser sessions, execute arbitrary JavaScript, and steal sensitive data. …
Read analysis →
CRITICAL
CVE-2026-54917
2026-08-11
CVE-2026-54917 represents a CVSS 10.0 vulnerability in SeaweedFS storage systems, enabling attackers to bypass bucket isolation via path traversal attacks. This flaw exposes enterp…
Read analysis →
CRITICAL
CVE-2026-49869
2026-08-11
CVE-2026-49869 exposes Kestra users to unauthenticated remote code execution with root privileges due to a flawed authentication bypass in the /configs endpoint. This critical vuln…
Read analysis →
CRITICAL
CVE-2026-40772
2026-08-11
CVE-2026-40772 is a critical unauthenticated arbitrary file upload vulnerability in GeekyBot versions 1.2.2 and earlier. Attackers exploiting this flaw can deploy web shells or mal…
Read analysis →
CRITICAL
CVE-2026-35292
2026-08-11
CVE-2026-35292 represents a critical unauthenticated remote code execution vulnerability in Oracle WebLogic Server Console with a CVSS score of 10.0. Exploitation requires no prior…
Read analysis →
CRITICAL
CVE-2026-35308
2026-08-10
CVE-2026-35308 is a CVSS 10.0 vulnerability in Oracle Coherence that permits unauthenticated attackers to achieve remote system takeover via HTTP. The flaw impacts multiple support…
Read analysis →
CRITICAL
CVE-2026-46846
2026-08-10
CVE-2026-46846 represents a CVSS 10.0 zero-day vulnerability in Oracle WebCenter Portal's Security Framework, enabling unauthenticated remote code execution via HTTP requests. Expl…
Read analysis →
CRITICAL
CVE-2026-10561
2026-08-10
CVE-2026-10561, a CVSS 10.0 vulnerability in IBM Langflow OSS 1.0.0-1.9.3, enables unauthenticated attackers to bypass authentication and execute arbitrary code, risking full syste…
Read analysis →
CRITICAL
CVE-2026-57700
2026-08-10
CVE-2026-57700 is a critical unrestricted file upload vulnerability in Daan.Dev OMGF Pro (versions ≤ 5.2.6), enabling remote code execution via malicious payload uploads. With a CV…
Read analysis →
CRITICAL
CVE-2026-48277
2026-08-10
Adobe ColdFusion versions 2025.9 and 2023.20 (and earlier) contain a critical improper input validation flaw (CVE-2026-48277) with CVSS 10.0 severity, enabling unauthenticated atta…
Read analysis →
CRITICAL
CVE-2026-48491
2026-07-15
CVE-2026-48491 exposes a critical vulnerability in Traefik's domain-fronting protections, enabling attackers to bypass mutual TLS enforcement through wildcard route misconfiguratio…
Read analysis →
CRITICAL
CVE-2026-53622
2026-07-15
CVE-2026-53622 in Traefik allows unauthenticated attackers to bypass mutual TLS (mTLS) enforcement via HTTP/3 SNI case-sensitivity flaws, exposing protected services to direct, cer…
Read analysis →
CRITICAL
CVE-2026-57624
2026-07-15
CVE-2026-57624 exposes WordPress sites using Blocksy Companion Pro to unauthenticated remote code execution, enabling attackers to compromise servers without credentials. With a CV…
Read analysis →
CRITICAL
CVE-2026-48836
2026-07-14
CVE-2026-48836 represents a critical 10.0 CVSS-scored vulnerability in Easy Invoice versions <= 2.1.19, enabling unauthenticated attackers to execute arbitrary code. Exploitation r…
Read analysis →
CRITICAL
CVE-2026-35301
2026-07-14
CVE-2026-35301, a CVSS 10.0 remote code execution flaw in Oracle WebLogic Server Console, enables unauthenticated attackers to fully compromise vulnerable systems via simple HTTP r…
Read analysis →
CRITICAL
CVE-2026-35307
2026-07-14
CVE-2026-35307 is a critical remote code execution vulnerability in Oracle Coherence with a CVSS 10.0 score, enabling unauthenticated attackers to fully compromise systems via HTTP…
Read analysis →
CRITICAL
CVE-2026-46798
2026-07-14
CVE-2026-46798 represents a CVSS 10.0 remote code execution flaw in Oracle WebCenter Sites, enabling unauthenticated attackers to fully compromise affected systems. Enterprises uti…
Read analysis →
CRITICAL
CVE-2026-49257
2026-07-14
CVE-2026-49257 is a CVSS 10.0 vulnerability in mcp-pinot versions <=3.0.1, enabling unauthenticated remote attackers to execute arbitrary database operations and fully compromise A…
Read analysis →
CRITICAL
CVE-2026-46978
2026-07-13
CVE-2026-46978 is a critical remote code execution vulnerability in Oracle Solaris Remote Administration Daemon. Exploitation requires no authentication and enables full data compr…
Read analysis →
CRITICAL
CVE-2026-12847
2026-07-13
CVE-2026-12847 exposes industrial networks to remote code execution (RCE) via a stack overflow in the DVRSearch service. With a CVSS score of 10.0, attackers can trigger RCE by sen…
Read analysis →
CRITICAL
CVE-2026-48283
2026-07-13
Adobe ColdFusion versions 2023.20 and earlier contain a critical remote code execution vulnerability (CVE-2026-48283) with a CVSS score of 10.0. Attackers can exploit this flaw wit…
Read analysis →
CRITICAL
CVE-2026-10134
2026-07-13
CVE-2026-10134 in IBM Langflow OSS exposes a critical flaw with a CVSS 10.0 score, enabling attackers to bypass authentication, exfiltrate secrets, and achieve persistent arbitrary…
Read analysis →
CRITICAL
CVE-2026-48558
2026-07-12
CVE-2026-48558 presents an immediate risk to organizations using SimpleHelp with OpenID Connect (OIDC) authentication. This critical vulnerability (CVSS 10.0) allows unauthenticate…
Read analysis →
CRITICAL
CVE-2025-71338
2026-07-12
CVE-2025-71338 represents a critical vulnerability in Flowise with a CVSS score of 10.0. Unauthenticated attackers can exploit this flaw to overwrite critical files and achieve rem…
Read analysis →
CRITICAL
CVE-2026-53576
2026-07-12
CVE-2026-53576 represents a CVSS 10.0 vulnerability in Kestra's REST API authentication filter, enabling unauthenticated actors to bypass security controls and execute arbitrary co…
Read analysis →
CRITICAL
CVE-2026-48281
2026-07-12
ColdFusion versions up to 2025.9 and 2023.20 suffer from a CVSS 10.0-rated vulnerability enabling unauthenticated remote code execution without user interaction. This zero-day flaw…
Read analysis →
CRITICAL
CVE-2026-13782
2026-07-12
CVE-2026-13782 represents a critical use-after-free vulnerability in Google Chrome that enables attackers to bypass the browser’s sandbox protections and execute arbitrary code. Th…
Read analysis →
CRITICAL
CVE-2026-48282
2026-07-11
Adobe ColdFusion versions 2025.9 and 2023.20 and earlier contain a critical path traversal vulnerability (CVE-2026-48282) that enables remote attackers to achieve arbitrary code ex…
Read analysis →
CRITICAL
CVE-2026-61447
2026-07-11
CVE-2026-61447 in PraisonAI CodeAgent presents a CVSS 10.0 threat by enabling remote code execution through unvalidated execution of AI-generated Python code. This allows attackers…
Read analysis →
CRITICAL
CVE-2026-56413
2026-07-11
A high-severity command injection flaw in Storage Concentrator (CVE-2026-56413) enables unauthenticated attackers to execute arbitrary commands as root, posing immediate operationa…
Read analysis →
CRITICAL
CVE-2026-56415
2026-07-11
CVE-2026-56415 is a CVSS 10.0 critical vulnerability in Storage Concentrator (SC & SCVM) that enables unauthenticated remote code execution as root. Attackers can exploit the debug…
Read analysis →
CRITICAL
CVE-2026-50160
2026-07-11
CVE-2026-50160 is a CVSS 10.0 vulnerability in self-hosted Hoppscotch deployments, enabling unauthenticated attackers to overwrite critical secrets during onboarding. This flaw cou…
Read analysis →