Wed, Apr 08 · 02:16 AM CDTCVE-2026-27143
9.8/10 · Must read/watchNVDvuln
Summary
Arithmetic over induction variables in loops were not correctly checked for underflow or overflow. As a result, the compiler would allow for invalid indexing to occur at runtime, potentially leading to memory corruption.
CVECVE-2026-27143
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 07:16 PM CDTCVE-2026-27960
9.8/10 · Must read/watchNVDvuln
Summary
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploited by unauthenticated attackers to query the API as any existing user, including the default admin account. This issue h
CVECVE-2026-27960
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 05 · 07:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 10:16 PM CDTCVE-2026-28780
9.8/10 · Must read/watchNVDvuln
Summary
Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer. This issue affects Apache HT
CVECVE-2026-28780
SeverityCRITICAL
TypeUPDATED
PublishedTue, May 05 · 10:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Wed, Apr 08 · 07:25 PM CDTCVE-2026-2942
9.8/10 · Must read/watchNVDvuln
Summary
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server
CVECVE-2026-2942
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 07:25 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-30311
9.8/10 · Must read/watchNVDvuln
Summary
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account f
CVECVE-2026-30311
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-30312
9.8/10 · Must read/watchNVDvuln
Summary
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it intercepts dangerous operators such as ;, &&, ||, |, and command substitution pa
CVECVE-2026-30312
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Mar 31 · 03:16 PM CDTCVE-2026-30314
9.8/10 · Must read/watchNVDvuln
Summary
Ridvay Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures; while it attempts to intercept dangerous operations, it fails to account f
CVECVE-2026-30314
SeverityCRITICAL
TypeUPDATED
PublishedTue, Mar 31 · 03:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 28 · 01:16 AM CDTCVE-2026-32644
9.8/10 · Must read/watchNVDvuln
Summary
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
CVECVE-2026-32644
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 28 · 01:16 AM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Wed, Apr 08 · 01:16 AM CDTCVE-2026-1346
9.3/10 · Must read/watchNVDvuln
Summary
IBM Verify Identity Access Container 11.0 through 11.0.2 and IBM Security Verify Access Container 10.0 through 10.0.9.1 and IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 could allow a locally authenticated user to escalate their privileges to root due to execution w
CVECVE-2026-1346
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 08 · 01:16 AM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 14 · 10:16 PM CDTCVE-2026-27304
9.3/10 · Must read/watchNVDvuln
Summary
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
CVECVE-2026-27304
SeverityCRITICAL
TypeUPDATED
PublishedTue, Apr 14 · 10:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-23479
8.8/10 · Worth your timeNVDvuln
Summary
Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blocked command. If a blocked client is evicted during this flow, an authenticated attacker can trigger a use-after-free tha
CVECVE-2026-23479
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 14 · 09:16 PM CDTCVE-2026-24893
8.8/10 · Worth your timeNVDvuln
Summary
openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. T
CVECVE-2026-24893
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 14 · 09:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-25243
8.8/10 · Worth your timeNVDvuln
Summary
Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to execute RESTORE can supply a crafted serialized payload that triggers invalid memory access and may lead to remote code exec
CVECVE-2026-25243
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-25588
8.8/10 · Worth your timeNVDvuln
Summary
RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisTimeSeries module loaded can s
CVECVE-2026-25588
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-25589
8.8/10 · Worth your timeNVDvuln
Summary
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTORE command. An authenticated attacker with permission to execute RESTORE on a server with the RedisBloom module loaded can
CVECVE-2026-25589
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Wed, Apr 08 · 02:16 AM CDTCVE-2026-27140
8.8/10 · Worth your timeNVDvuln
Summary
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.
CVECVE-2026-27140
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 02:16 AM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 28 · 12:16 AM CDTCVE-2026-27785
8.8/10 · Worth your timeNVDvuln
Summary
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
CVECVE-2026-27785
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 28 · 12:16 AM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 14 · 06:17 PM CDTCVE-2026-32225
8.8/10 · Worth your timeNVDvuln
Summary
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
CVECVE-2026-32225
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 14 · 06:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Mon, Dec 15 · 05:15 PM CSTCVE-2025-11393
8.7/10 · Worth your timeNVDvuln
Summary
A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of only the specific reports it is supposed to handle. This allows a standard user with
CVECVE-2025-11393
SeverityHIGH
TypeUPDATED
PublishedMon, Dec 15 · 05:15 PM CST
ModifiedSat, Jul 25 · 07:16 PM CDT
Tue, Apr 14 · 11:16 PM CDTCVE-2026-27290
8.6/10 · Worth your timeNVDvuln
Summary
Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the application uses a search path to locate critical resources such as programs, then an attacker could modify that search path
CVECVE-2026-27290
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 14 · 11:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 14 · 10:16 PM CDTCVE-2026-27305
8.6/10 · Worth your timeNVDvuln
Summary
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended acces
CVECVE-2026-27305
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 14 · 10:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 14 · 10:16 PM CDTCVE-2026-27306
8.4/10 · Worth your timeNVDvuln
Summary
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Attacker requires elevated privileges. Exploitation of this issue requires user interaction in that a victim must open a malicious
CVECVE-2026-27306
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 14 · 10:16 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, Apr 14 · 06:17 PM CDTCVE-2026-32221
8.4/10 · Worth your timeNVDvuln
Summary
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVECVE-2026-32221
SeverityHIGH
TypeUPDATED
PublishedTue, Apr 14 · 06:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Tue, May 05 · 05:17 PM CDTCVE-2026-23631
8.1/10 · Worth your timeNVDvuln
Summary
Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-after-free on replicas where replica-read-only is disabled or can be disabled, which may lead to remote code execution. A wo
CVECVE-2026-23631
SeverityHIGH
TypeUPDATED
PublishedTue, May 05 · 05:17 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT
Wed, Apr 08 · 07:25 PM CDTCVE-2026-30814
8.0/10 · Worth your timeNVDvuln
Summary
A stack-based buffer overflow in the tmpServer module of TP-Link Archer AX53 v1.0 allows an authenticated adjacent attacker to trigger a segmentation fault and potentially execute arbitrary code via a specially crafted configuration file. Successful exploitation may cause a crash and could allow arbitrary code executio
CVECVE-2026-30814
SeverityHIGH
TypeUPDATED
PublishedWed, Apr 08 · 07:25 PM CDT
ModifiedSat, Jul 25 · 11:10 AM CDT