By severity

High-severity vulnerabilities

CVEs rated High by CVSS, with SEC.co remediation and prioritization guidance.

4140 published vulnerabilities · page 38 of 42

  • CVE-2025-66281HIGH 7.2

    CVE-2025-66281 is a NULL pointer dereference vulnerability affecting QNAP NAS operating systems. When triggered, the flaw causes the application to crash, resulting in a denial-of-service condition. An attacker with high-level administrative privileges can remotely exploit this to disrupt NAS availability. While the vulnerability requires elevated credentials to trigger, the impact is immediate and can leave your storage infrastructure offline until patched.

  • CVE-2026-0272HIGH 7.2

    CVE-2026-0272 is a privilege escalation flaw in Palo Alto Networks PAN-OS that lets an authenticated administrator with CLI access run commands as root. While the vulnerability requires pre-existing admin credentials and CLI access, the impact is severe: a malicious or compromised admin account could gain unrestricted control of the firewall. The risk is substantially reduced when CLI access is tightly limited to a small trusted group and the management interface is restricted to known internal IP ranges.

  • CVE-2026-0273HIGH 7.2

    A command injection flaw in Palo Alto Networks PAN-OS allows any authenticated administrator who can reach the CLI or web management interface to execute arbitrary commands with root privileges. The vulnerability affects PA-Series, VM-Series firewalls, and Panorama deployments, but not Cloud NGFW or Prisma Access. While the flaw requires legitimate admin credentials to exploit, an insider threat or compromised admin account could lead to complete system compromise. The risk is materially lower when CLI access is tightly restricted and the management interface is isolated to trusted internal networks only.

  • CVE-2026-0280HIGH 7.2

    Palo Alto Networks PAN-OS has a flaw in how it processes IPv6 traffic at the firewall level. An attacker on the network can craft malicious IPv6 packets that bypass the firewall's security policies, allowing blocked traffic to slip through to protected systems. This doesn't require authentication or user interaction—just the ability to send traffic toward the firewall. Cloud NGFW and Panorama deployments are unaffected.

  • CVE-2026-0283HIGH 7.2

    Palo Alto Networks PAN-OS contains an authentication bypass flaw in its Large Scale VPN (LSVPN) feature that allows attackers with network access to establish unauthorized site-to-site VPN connections without proper credentials. The vulnerability affects multiple PAN-OS versions and creates a direct path for lateral movement and network compromise. Panorama, Cloud NGFW, and Prisma Access deployments are not affected.

  • CVE-2026-0286HIGH 7.2

    An authenticated administrator with access to PAN-OS management interfaces can inject commands into the system in a way that allows execution of arbitrary operating system commands with root privileges. The vulnerability exists in the management plane of Palo Alto Networks firewalls and Panorama deployments. Because exploitation requires an authenticated administrator account, the actual risk depends heavily on how tightly you control who has CLI access to your management infrastructure.

  • CVE-2026-10072HIGH 7.2

    DreamMaker, a product developed by Interinfo, contains a vulnerability that allows attackers with privileged access to upload arbitrary files to the server. An attacker exploiting this flaw could upload malicious web shells, gaining the ability to execute code and maintain persistent access to the affected system. The vulnerability requires the attacker to have elevated credentials, but once leveraged, it provides complete control over server operations.

  • CVE-2026-10091HIGH 7.2

    A WordPress plugin called Email JavaScript Cloak contains a security flaw that allows attackers with contributor-level access to inject malicious scripts into pages. When other users visit those pages, the injected code executes in their browsers. The vulnerability exists in versions 1.03 and earlier and stems from the plugin failing to properly clean and escape user input in its email shortcode feature.

  • CVE-2026-10092HIGH 7.2

    The Cincopa video and media plugin for WordPress contains a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious code into post comments. Because the plugin processes shortcodes within comments without proper sanitization, any visitor with comment-posting privileges can embed harmful scripts that persist in the database and execute whenever other users view the affected page. This vulnerability affects all versions up to and including 1.163.

  • CVE-2026-10513HIGH 7.2

    The Webmention plugin for WordPress has a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious JavaScript into comments. When a site moderator or administrator views the comment edit screen, the injected script executes in their browser with their privileges. The vulnerability exists because the plugin fails to properly sanitize and escape author metadata (specifically avatar and URL fields) that come from webmention processing before displaying them in HTML attributes.

  • CVE-2026-10521HIGH 7.2

    CVE-2026-10521 is a high-severity vulnerability that allows an attacker with elevated privileges to access a hidden configuration interface that should be restricted from all users. By exploiting this unauthorized access, an attacker can modify critical program parameters, potentially compromising the confidentiality, integrity, and availability of the affected system. This represents a complete breakdown of security controls for the impacted application.

  • CVE-2026-10586HIGH 7.2

    The Gutenberg Essential Blocks plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated users with Author-level permissions or higher to make unauthorized web requests from the vulnerable server. An attacker could use this flaw to communicate with internal services, potentially extracting sensitive information or modifying data that should only be accessible internally. The vulnerability exists in the image generation feature and affects all versions through 6.1.3.

  • CVE-2026-10698HIGH 7.2

    Progress MOVEit Transfer contains a vulnerability in its Custom Reports modules that allows authenticated administrators to inject malicious data into query logic. An attacker with administrative privileges can manipulate report queries to access or modify data beyond their intended scope. The vulnerability affects recent versions of MOVEit Transfer and requires administrative access to exploit, limiting the immediate risk to organizations where admin accounts are properly secured and monitored.

  • CVE-2026-10727HIGH 7.2

    Ivanti EPMM (Enterprise Patch Management and Mobility) contains an OS command injection flaw that allows authenticated users with elevated privileges to run arbitrary commands with root-level permissions. An attacker who has already gained administrative access to the system can exploit this weakness to execute malicious code, potentially compromising the entire endpoint management infrastructure. The vulnerability affects versions prior to 12.9.0.1, 12.8.0.3, and 12.7.0.2.

  • CVE-2026-10749HIGH 7.2

    A flaw in the Post Duplicator WordPress plugin before version 3.0.15 allows users with Contributor-level permissions (and higher) to inject malicious PHP code by exploiting improper handling of custom metadata during post duplication. The vulnerability exists because the plugin stores user-supplied serialized data without using WordPress's built-in safeguards against double-serialization attacks, creating a pathway for arbitrary code execution.

  • CVE-2026-10843HIGH 7.2

    OpenShift's Cloud Credential Operator, when running in Mint mode, assigns AWS credentials with excessive permissions. Instead of limiting destructive actions to resources owned by the cluster, the operator grants account-wide scope. If an attacker compromises these credentials, they can perform destructive actions across the entire AWS account, not just the cluster—making lateral movement and account-wide damage possible.

  • CVE-2026-10870HIGH 7.2

    Shibby Tomato version 1.28.0000 contains a command injection vulnerability in its web-based configuration interface that allows authenticated administrators to execute arbitrary operating system commands on the router. An attacker with administrative access can manipulate the DHCP client startup function to inject malicious commands, potentially compromising the entire device and any network it serves. Exploit code has been published publicly, increasing the risk of opportunistic attacks.

  • CVE-2026-10871HIGH 7.2

    Shibby Tomato 1.28.0000 contains a remote command injection vulnerability in its Web UI. An authenticated administrator can craft a malicious request targeting the IPv6 6rd tunnel configuration function, injecting arbitrary operating system commands that execute with the privileges of the affected service. The vulnerability has been publicly disclosed, increasing the likelihood of active exploitation attempts.

  • CVE-2026-10872HIGH 7.2

    Shibby Tomato 1.28.0000 contains a vulnerability in the Web UI component that allows authenticated users with high-level privileges to inject operating system commands through the VPN server startup function. An attacker with administrative access could manipulate input parameters to execute arbitrary commands on the device, potentially compromising the entire router system. Public exploit information exists for this vulnerability.

  • CVE-2026-10873HIGH 7.2

    Shibby Tomato 1.28.0000 contains a command injection vulnerability in its web interface that allows authenticated administrators to execute arbitrary operating system commands. The vulnerability exists in the rstats_path function within the /bin/rstats component. Because exploit code has been publicly disclosed, the risk of active exploitation is elevated. Note that this project has been superseded by FreshTomato, and users should verify their upgrade path accordingly.

  • CVE-2026-11395HIGH 7.2

    The CF7 to Webhook plugin for WordPress contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make arbitrary web requests from the affected WordPress server. An attacker can exploit this to reach internal services, extract sensitive data, or modify information that should only be accessible within your network. The vulnerability affects all versions up to and including 5.0.0 and requires two conditions to be exploitable: the webhook URL must include a Contact Form 7 field placeholder in its host component, and the form using that webhook must be publicly accessible.

  • CVE-2026-11407HIGH 7.2

    Pimcore CMS/DXP version 12.3.8 has a critical flaw in its Twig template security controls that allows authenticated administrators to bypass sandboxing restrictions. An attacker with admin credentials can inject malicious Twig code through the DataObject ClassDefinition component to read files, execute database queries, or potentially run arbitrary code on the server. This is a privilege-escalation risk for environments where admins should have limited template capabilities, or where templates are user-generated.

  • CVE-2026-11409HIGH 7.2

    CVE-2026-11409 is an authenticated command injection flaw in TP-Link TL-WR940N v6 routers affecting the IPv6 PPPoE configuration feature. An attacker with admin credentials can inject arbitrary operating system commands that execute with elevated privileges on the device. While this requires existing administrative access, successful exploitation could allow complete device compromise, network traffic interception, or lateral movement into the network behind the router.

  • CVE-2026-11410HIGH 7.2

    A high-severity command injection flaw has been discovered in TP-Link TL-WR940N v6 routers within the BigPond Cable WAN configuration settings. An attacker who already has administrator-level access to the device can inject arbitrary operating system commands, which then execute with elevated privileges. While the vulnerability requires prior administrative credentials, successful exploitation grants complete control over the affected router, making this a critical privilege escalation risk for organizations deploying these devices.

  • CVE-2026-11806HIGH 7.2

    IBM WebSphere Application Server Liberty versions 17.0.0.3 through 26.0.0.6 contain a vulnerability that allows an authenticated administrator to read arbitrary files from the server when the restConnector-2.0 feature is enabled. This is a high-severity issue because it bypasses normal file access controls and can expose sensitive configuration data, credentials, or application source code. The vulnerability requires high-level privileges to exploit, limiting its immediate blast radius but making it a serious concern for organizations where administrative accounts may be compromised or where insider threats are a consideration.

  • CVE-2026-11845HIGH 7.2

    The iVEC-IEI Virtualization Edge Computer contains an OS command injection flaw that permits authenticated administrators or high-privilege users to remotely inject and execute arbitrary operating system commands. This is a serious risk because it bypasses normal application controls and grants attackers direct shell access to the underlying system, potentially compromising the entire device and any workloads it hosts.

  • CVE-2026-11883HIGH 7.2

    A vulnerability in the WebAuthn Provider for Two Factor WordPress plugin before version 2.5.6 allows attackers to disable two-factor authentication (2FA) if they already possess a user's password. The plugin fails to properly validate the response from the second authentication step, meaning an attacker can craft a specially malformed request that tricks the plugin into accepting the login without completing the 2FA challenge. This significantly weakens the security posture of affected WordPress installations by reducing multi-factor protection to single-factor authentication.

  • CVE-2026-12095HIGH 7.2

    The Kargo Takip plugin for WordPress contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to send web requests to arbitrary internal servers from the affected WordPress installation. The vulnerability is particularly dangerous because the plugin echoes back sensitive data—specifically authentication tokens or credentials found in JSON responses—directly to the attacker's browser. This means an attacker can query internal services like cloud metadata endpoints, database servers, or other backend systems, and retrieve their responses without needing any authentication credentials.

  • CVE-2026-12100HIGH 7.2

    The URL Preview plugin for WordPress contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated attackers to make web requests on behalf of the vulnerable server. By manipulating the 'url' parameter, an attacker can trick the plugin into accessing internal services, potentially reading sensitive configuration or modifying data that the web server has access to. All versions up to and including 1.0 are affected.

  • CVE-2026-12142HIGH 7.2

    The NEX-Forms WordPress plugin contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious code into web pages without needing to log in. The flaw exists in how the plugin processes form field names, specifically through an array parameter called '_name[]'. Once injected, the malicious script executes every time a user visits the compromised page. What makes this particularly dangerous is that the plugin's built-in security filter explicitly allows script tags, iframes, and JavaScript event handlers—defeating the standard WordPress content filtering mechanism that would normally block such code.

  • CVE-2026-12197HIGH 7.2

    A command injection vulnerability exists in Ruijie EG105G-P version 2.340, specifically in the network diagnostic endpoint accessible via the web interface. An authenticated attacker can manipulate the target parameter of the nslookup function to inject and execute arbitrary system commands on the affected device. The vulnerability is remotely exploitable and public exploit code has been released. The vendor has not responded to early disclosure efforts.

  • CVE-2026-13040HIGH 7.2

    NEX-Forms, a WordPress form-builder plugin, contains a stored cross-site scripting (XSS) vulnerability that allows unauthenticated attackers to inject malicious scripts into web pages. Because the vulnerable form submission endpoint lacks both input validation and CSRF protection, anyone can craft a malicious form submission that persists in the database. When legitimate users later view pages containing the injected content, the attacker's scripts execute in their browsers, potentially compromising user sessions, stealing credentials, or redirecting visitors to malicious sites.

  • CVE-2026-13053HIGH 7.2

    WatchGuard Fireware OS contains a flaw in its command-line interface (CLI) that allows authenticated administrators with elevated privileges to run arbitrary code on affected firewall devices by submitting a specially crafted command. This is a memory-writing vulnerability that bypasses normal access controls once an attacker has gained administrative credentials.

  • CVE-2026-13054HIGH 7.2

    WatchGuard Firebox firewalls running Fireware OS contain a flaw in their web-based management interface that allows someone with administrative access to upload or write files to unexpected locations on the device. An attacker with valid admin credentials could exploit this to place malicious files, modify configurations, or compromise the firewall's integrity. The vulnerability requires prior authentication, which limits exposure but remains serious given admin accounts' sensitivity.

  • CVE-2026-13372HIGH 7.2

    A flaw in Devolutions Remote Desktop Manager's PowerShell VPN editor allows an authenticated attacker to execute PowerShell scripts in another user's security context. The vulnerability exists in versions 2026.2.5 through 2026.2.11 and exploits how the application resolves VPN script links by display name. An attacker with write access to a shared workspace can create a specially named malicious VPN script that collides with an existing legitimate script link, causing the victim to unknowingly run the attacker's code with their privileges. This requires both authentication and workspace write access, limiting the attack surface but creating a serious privilege elevation risk within collaborative environments.

  • CVE-2026-13383HIGH 7.2

    WatchGuard Fireware OS contains a memory vulnerability in its ikestubd process that allows authenticated administrators to execute arbitrary code through the Management Web UI. An attacker with legitimate privileged credentials can send specially crafted requests that trigger an out-of-bounds write, potentially compromising the firewall's integrity and enabling lateral movement within protected networks. This threat is elevated by the widespread deployment of affected Firebox models across enterprise and mid-market security infrastructures.

  • CVE-2026-13384HIGH 7.2

    WatchGuard Fireware OS contains an out-of-bounds write flaw in the wgagent process that allows authenticated administrators to execute arbitrary code on the firewall. An attacker with valid admin credentials could send specially crafted requests through the Management Web UI to trigger the vulnerability and gain complete control of the device. This is a serious issue because firewalls are critical security infrastructure; compromise of one could allow an attacker to bypass network defenses entirely.

  • CVE-2026-13430HIGH 7.2

    A WordPress plugin called Post Export Import with Media has a security flaw that allows administrators to upload malicious files to a website. The vulnerability works because the plugin doesn't properly check file types when importing media—specifically, attackers can trick the validation logic by adding a trailing dot to filenames (e.g., 'shell.php.'). This bypasses the security check, allowing executable files to be uploaded and potentially run on the server. Because this requires administrator-level access, it represents a privilege escalation or insider threat risk rather than a public-facing vulnerability.

  • CVE-2026-13441HIGH 7.2

    EventPrime – Events Calendar, Bookings and Tickets, a popular WordPress plugin for managing events and ticketing, contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into event pages. The flaw exists in how the plugin handles color input for event type backgrounds. If the plugin's guest submissions feature is enabled, unauthenticated users can exploit this by submitting crafted event types. When guest submissions are disabled, attackers need at least a subscriber-level WordPress account. Once injected, the malicious code executes whenever anyone views the affected page, potentially compromising visitor data or session tokens.

  • CVE-2026-13731HIGH 7.2

    The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services WordPress plugin versions up to 8.4.9 contains a stored cross-site scripting (XSS) flaw that allows unauthenticated attackers to inject malicious scripts into web pages. When a legitimate user visits an affected page, the injected script executes in their browser, potentially stealing session data, redirecting to phishing sites, or performing actions on their behalf. The vulnerability is particularly severe because the plugin publicly exposes AJAX security tokens on every frontend page, eliminating any practical authentication barrier and making exploitation trivial.

  • CVE-2026-15000HIGH 7.2

    A WordPress plugin called Connect Contact Form 7 and Mailchimp contains a stored cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages. An unauthenticated attacker can embed harmful code through the Mailchimp merge field functionality. The injected code remains dormant until an administrator logs in and performs a Contact Lookup on a form submission, at which point the script executes in the admin's browser. This affects all versions up to and including 0.9.78.06.

  • CVE-2026-15298HIGH 7.2

    The TelSender plugin for WordPress has a security flaw that allows attackers to inject malicious code into administrator accounts. An attacker can craft a malicious Telegram chat title and, when a WordPress admin interacts with the TelSender settings page and clicks the "Tested" button, the malicious code executes in their browser. No special permissions or authentication are needed to exploit this vulnerability, making it accessible to anyone.

  • CVE-2026-1667HIGH 7.2

    The Squirrly SEO WordPress plugin, in versions up to 14.0.0, exposes an API token that attackers can exploit without any authentication. This allows them to create arbitrary posts on affected WordPress sites. If the Advanced Custom Fields plugin is also installed, attackers can inject malicious scripts that run whenever visitors view the affected pages, potentially stealing credentials or spreading malware.

  • CVE-2026-22660HIGH 7.2

    FlaskBB administrators face a critical authorization bypass risk. A type mismatch in the application's group deletion safeguard allows authenticated admins to remove all built-in permission groups in one operation. Because FlaskBB's permission model relies on these groups, their deletion effectively breaks the forum's access controls, potentially locking legitimate users out and destabilizing the entire platform. The vulnerability requires admin credentials but no user interaction to trigger.

  • CVE-2026-22893HIGH 7.2

    A command injection flaw affects QNAP NAS operating systems. An attacker who obtains administrator credentials can use this vulnerability to run arbitrary commands on the affected device, potentially compromising data integrity, confidentiality, and availability. QNAP has released patched versions addressing this issue.

  • CVE-2026-23698HIGH 7.2

    Vtiger CRM versions through 8.4.0 contain a critical flaw in the admin module import feature that allows authenticated administrators to execute arbitrary code on the server. An attacker with admin credentials can upload a specially crafted zip file containing malicious PHP code through the ModuleManager import function. The system extracts these files directly into a web-accessible directory without proper validation, allowing the attacker to then access and execute the PHP code via a web browser. Once executed, the PHP creates a persistent backdoor that remains active even after the attacker logs out or loses their original session.

  • CVE-2026-2374HIGH 7.2

    The Login No Captcha reCAPTCHA WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in all versions up to 1.8.0. An unauthenticated attacker can exploit this by triggering a login attempt from a non-standard login page URL (such as xmlrpc.php), which causes the plugin to store malicious JavaScript in the WordPress admin dashboard settings. When an administrator logs in within 30 seconds of the attack, that JavaScript executes in their browser with the administrator's privileges. The vulnerability requires the admin to have a whitelisted IP address configured in the plugin, which is a common configuration for sites restricting login access.

  • CVE-2026-24085HIGH 7.2

    A memory corruption vulnerability exists in multiple Qualcomm wireless chipsets and their firmware when processing display command line information. The flaw stems from improper initialization of a variable during command parsing, which could allow a high-privilege attacker with physical access to trigger memory corruption and potentially execute arbitrary code or crash the device. The vulnerability affects a broad range of Qualcomm wireless components used in enterprise and consumer devices.

  • CVE-2026-24697HIGH 7.2

    Cisco's small-business routers (RV130, RV130W, and RV110W) contain a command injection flaw in their configuration handling. An attacker with administrative access to the device can manipulate the WAN hostname setting to inject and execute arbitrary operating system commands with root-level privileges. This is a serious post-authentication vulnerability because once an attacker has logged in—whether through credential compromise, phishing, or insider threat—they can escalate to full system control.

  • CVE-2026-24698HIGH 7.2

    A command injection flaw in Cisco small-business routers (RV130, RV130W, and RV110W) allows authenticated administrators to execute arbitrary system commands with root-level privileges by manipulating the model_name configuration parameter. An attacker with valid credentials could bypass normal access controls and take full control of the router's operating system.

  • CVE-2026-24699HIGH 7.2

    A command injection flaw in Cisco's small business routers (RV130, RV130W, and RV110W) allows authenticated administrators to inadvertently execute arbitrary system commands with root privileges by manipulating the LAN IPv6 prefix length configuration parameter. An attacker with administrative access could leverage this to compromise the entire router and potentially the networks it protects.

  • CVE-2026-24700HIGH 7.2

    A command injection flaw in Cisco small business routers allows authenticated administrators to execute arbitrary commands with root-level privileges by injecting malicious input into the machine name configuration field. An attacker with valid admin credentials can manipulate this parameter to break out of the intended configuration context and run arbitrary OS commands on the affected router.

  • CVE-2026-24716HIGH 7.2

    A NULL pointer dereference flaw in QNAP NAS operating systems allows authenticated administrators to crash the system and cause a denial-of-service. An attacker must already have administrator credentials to exploit this vulnerability, which limits the attack surface but remains a significant risk for organizations where admin accounts may be compromised or insider threats exist. QNAP has released patched versions across multiple OS lines to address this issue.

  • CVE-2026-24719HIGH 7.2

    QNAP has patched a command injection vulnerability affecting their NAS operating systems. An attacker who already has administrator credentials can use this flaw to run arbitrary commands on affected devices. While the vulnerability requires administrative access (limiting who can exploit it), the ability to execute unrestricted commands on a NAS—which often stores critical business data and backups—makes this a meaningful risk. QNAP has issued fixes for QTS 5.2.9.3492 build 20260507 and later, and QuTS hero h5.2.9.3499 build 20260514 and later.

  • CVE-2026-25700HIGH 7.2

    Apache Answer versions up to 2.0.0 contain a security flaw where administrative API tokens remain valid even after an administrator account is suspended, deleted, or deactivated. An attacker with knowledge of a revoked admin's token can continue making administrative API calls until the token naturally expires, potentially allowing unauthorized changes to system configuration, user accounts, or sensitive data. The vulnerability requires high privilege (an existing admin account) to initially create the problematic token, but once created, that token persists independently of account status.

  • CVE-2026-35326HIGH 7.2

    Oracle WebCenter Content, a component of Oracle Fusion Middleware used for managing digital assets and documents, contains a vulnerability that allows high-privilege administrators or authenticated users with network access to fully compromise the system. An attacker with admin-level credentials can exploit this flaw remotely over HTTP without user interaction, leading to complete takeover—meaning they could steal, modify, or delete sensitive content, or disrupt service availability. Two versions are affected: 12.2.1.4.0 and 14.1.2.0.0.

  • CVE-2026-3652HIGH 7.2

    The ARForms WordPress plugin contains a security flaw that allows attackers to inject malicious code into the plugin without needing to log in. When administrators later access a specific dashboard page to review incomplete form submissions, that malicious code executes in their browser. This can lead to attackers stealing sensitive information or taking actions on behalf of administrators. The vulnerability affects all versions of ARForms up to and including 7.1.3.

  • CVE-2026-3820HIGH 7.2

    Supermicro's BMC (Baseboard Management Controller) SMTP service in the AS-2115HS-TNR contains a vulnerability that allows attackers with administrator-level access to inject malicious characters into SMTP configuration fields. This injection can lead the system to execute unintended commands, potentially resulting in loss of service, unauthorized code execution, or complete compromise of the BMC itself. While the attack requires existing high-level privileges, the consequences—especially arbitrary code execution on out-of-band management hardware—are severe.

  • CVE-2026-39276HIGH 7.2

    Emlog Pro v2.6.9 contains a path traversal flaw in its template upload feature that allows authenticated administrators to upload malicious files and execute arbitrary PHP code on the server. An attacker with admin credentials can craft a specially crafted ZIP archive with directory traversal sequences (such as '../') in filenames to escape the intended upload directory, overwrite legitimate template files, or inject malicious code that gets executed by the web server. This is a post-authentication vulnerability, meaning the attacker must already have admin access to the Emlog installation.

  • CVE-2026-39470HIGH 7.2

    A privilege escalation vulnerability exists in WooCommerce Cart Abandonment Recovery plugin versions prior to 2.1.0. An attacker with shop manager privileges can exploit this flaw to gain unauthorized elevated access within the WordPress environment, potentially compromising administrative functions and sensitive e-commerce data. The vulnerability requires an authenticated attacker with shop manager role, but no additional user interaction is needed for exploitation.

  • CVE-2026-39472HIGH 7.2

    A PHP object injection vulnerability exists in WooCommerce PDF Invoices & Packing Slips plugin versions before 5.9.0. An authenticated shop manager can exploit this flaw to execute arbitrary code on the affected WordPress site, potentially compromising the entire installation. The vulnerability requires elevated privileges to trigger, but once exploited, grants complete control over the server and sensitive data.

  • CVE-2026-39499HIGH 7.2

    A PHP object injection vulnerability exists in the Advanced Product Fields (Product Addons) plugin for WooCommerce versions 1.6.19 and earlier. Shop managers—authenticated users with elevated privileges—can inject malicious PHP objects that execute arbitrary code on the server. The vulnerability requires an authenticated attacker with shop manager or higher role, so it does not pose an immediate risk to unauthenticated visitors, but it represents a significant lateral-movement or privilege-escalation vector for compromised or malicious insiders.

  • CVE-2026-40083HIGH 7.2

    Cacti, a widely-deployed open source framework for performance monitoring and fault management, contains a SQL injection flaw in its SNMP agent management feature. An authenticated attacker with SNMP manager permissions can manipulate serialized data in a request parameter to inject arbitrary SQL commands into the database. The vulnerability stems from unsafe deserialization followed by direct concatenation of unsanitized values into a DELETE query. Cacti versions 1.2.30 and earlier are affected; the fix is available in version 1.2.31.

  • CVE-2026-40961HIGH 7.2

    Apache Airflow contains a flaw in its login redirect mechanism that allows authenticated users to redirect people to malicious websites. The vulnerability exists because the URL safety check (`is_safe_url`) can be circumvented through crafted URLs, enabling attackers to potentially harvest credentials or distribute malware by making the redirect appear to come from a trusted Airflow instance. Any organization running Airflow and allowing authentication should treat this as a priority.

  • CVE-2026-41567HIGH 7.2

    A critical weakness in Moby (the open-source container runtime underlying Docker) allows a malicious container to execute code with full daemon privileges—potentially gaining root access to the host system. The vulnerability occurs when compressed files are uploaded into a container using `docker cp` or the API endpoint `PUT /containers/{id}/archive`. Instead of using decompression tools from the host system, Moby incorrectly uses tools from inside the container itself. If a container image contains a trojanized decompression binary (like xz or unpigz), attackers can exploit this ordering mistake to run arbitrary commands with daemon-level privileges. Versions before Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14 are affected.

  • CVE-2026-42306HIGH 7.2

    A race condition in Moby and Docker Engine allows a container to intercept and redirect bind mount operations to unintended host filesystem locations. A malicious or compromised container could exploit this timing window during the `docker cp` mount setup phase to write files to arbitrary paths on the host, potentially overwriting critical files or disrupting services. The vulnerability requires local access and user interaction, but poses significant risk in multi-tenant environments where untrusted containers run alongside sensitive workloads.

  • CVE-2026-44161HIGH 7.2

    Fluentd is a widely-used log collection and forwarding tool. Its HTTP output plugin allows operators to use dynamic placeholders (like ${tag}) in the destination URL. Prior to version 1.19.3, if an attacker can influence the values used in those placeholders—for example, by injecting a crafted tag into logs—they can redirect Fluentd's outbound HTTP requests to arbitrary internal services on the organization's network. This allows an attacker to probe or interact with services that should not be exposed, potentially leading to information disclosure or denial of service.

  • CVE-2026-44913HIGH 7.2

    Apache NiFi versions 1.2.0 through 2.9.0 contain a SQL injection vulnerability in the CaptureChangeMySQL Processor. The flaw stems from inadequate escaping of database table names, allowing an authenticated attacker with high privileges to inject arbitrary SQL commands by supplying crafted table names. A partial mitigation added in version 1.8.0 introduced quoted boundaries but did not eliminate the risk entirely. Organizations using other NiFi processors are unaffected. Upgrading to version 2.10.0 resolves the issue through improved identifier escaping.

  • CVE-2026-44914HIGH 7.2

    Apache NiFi versions 1.12.0 through 2.9.0 contain a flaw where the system fails to properly verify user permissions when someone tries to replace Process Groups that contain restricted components. Restricted components are those requiring elevated privileges, but the framework skipped this authorization check during replacement operations. This means a user with basic write access could circumvent intended security controls and deploy restricted components without proper authorization. The vulnerability is effectively a privilege escalation through authorization bypass in the Process Group replacement workflow.

  • CVE-2026-45609HIGH 7.2

    mcp-security, a Spring AI component that manages security and authorization for the Model Context Protocol, contains a Server-Side Request Forgery (SSRF) vulnerability in versions before 0.1.9. When Dynamic Client Registration is enabled, the framework processes OAuth discovery and metadata URLs without properly validating them, allowing an attacker to redirect requests to internal network resources or malicious endpoints. This could lead to information disclosure or unauthorized actions on systems the application can reach.

  • CVE-2026-46492HIGH 7.2

    md-fileserver is a tool for viewing markdown files directly in a web browser. Before version 1.10.3, the application failed to sanitize HTML tags embedded within markdown content. An attacker could craft a markdown file containing malicious JavaScript (such as in a <script> tag) that would execute when the file is viewed in the browser. This allows arbitrary code execution in the security context of the affected domain, potentially compromising user sessions or stealing sensitive data.

  • CVE-2026-46769HIGH 7.2

    Oracle's Application Development Framework (ADF), a middleware component used to build enterprise applications, contains a security vulnerability that allows administrators or other high-privileged users with network access to gain complete control over affected systems. An attacker with these elevated privileges can read, modify, or delete sensitive data and disrupt operations. The vulnerability affects two specific versions: 12.2.1.4.0 and 14.1.2.0.0.

  • CVE-2026-46867HIGH 7.2

    Oracle Enterprise Manager Base Platform contains a vulnerability in its Extensibility Framework that allows high-privileged attackers with network access to take over the system. The flaw affects versions 13.5 and 24.1, and exploitation requires HTTPS connectivity but does not need user interaction. A successful attack grants an attacker complete control over the Enterprise Manager platform, including ability to read, modify, or destroy data and disable services.

  • CVE-2026-46868HIGH 7.2

    A vulnerability exists in Oracle Enterprise Manager Base Platform that allows an authenticated administrator to gain complete control over the platform. The flaw is in the Extensibility Framework component and requires the attacker to already have high-privilege credentials and network access via HTTPS. Successful exploitation results in full compromise of the Enterprise Manager instance, affecting confidentiality, integrity, and availability. Versions 13.5 and 24.1 are affected.

  • CVE-2026-46922HIGH 7.2

    Oracle HR Intelligence, a component within Oracle E-Business Suite, contains a vulnerability that allows an authenticated high-privileged user with network access to take over the system. The vulnerability affects versions 12.2.3 through 12.2.15 and requires the attacker to already have elevated credentials, meaning it poses a risk primarily from internal threats or from attackers who have compromised privileged accounts. The impact is severe: an attacker could read, modify, or delete sensitive HR data and disrupt the entire HR Intelligence service.

  • CVE-2026-46938HIGH 7.2

    Oracle has published a high-severity vulnerability in its Cost Management module within E-Business Suite that allows privileged network attackers to fully compromise the system. The flaw affects versions 12.2.3 through 12.2.15 and requires the attacker to already possess high-level administrative credentials and network access. Successful exploitation grants complete control over the application's functionality, data, and availability.

  • CVE-2026-46953HIGH 7.2

    A vulnerability exists in Oracle's HRMS (UK) module within E-Business Suite that allows a privileged network attacker to fully compromise the system. The flaw affects payroll processing for UK organizations running versions 12.2.3 through 12.2.15. An attacker with high-level administrative credentials can exploit this over the network without user interaction, leading to complete takeover of the HRMS system including access to sensitive payroll, employee, and financial data.

  • CVE-2026-46956HIGH 7.2

    CVE-2026-46956 is a vulnerability in Oracle Property Manager, a module within Oracle E-Business Suite used for real estate and facility management operations. An attacker with high administrative privileges and network access can exploit this flaw to gain complete control over the Property Manager application, potentially compromising confidentiality, integrity, and availability of managed property data. The vulnerability stems from improper access controls in the Internal Operations component.

  • CVE-2026-46960HIGH 7.2

    A vulnerability in Oracle's Project Portfolio Analysis component (part of E-Business Suite) allows an attacker with elevated privileges and network access to take full control of the application. The flaw affects versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level system access, but once leveraged, enables complete compromise including data theft, modification, and service disruption.

  • CVE-2026-46969HIGH 7.2

    CVE-2026-46969 is a high-severity vulnerability in Oracle Financials for EMEA (part of Oracle E-Business Suite) that allows a high-privileged attacker on your network to take full control of the system. The flaw affects versions 12.2.3 through 12.2.15 and can be exploited over HTTP without user interaction. An attacker with administrative or equivalent credentials could gain complete access to confidentiality, integrity, and availability of your financial data and systems.

  • CVE-2026-46970HIGH 7.2

    Oracle HR Intelligence, a component of Oracle E-Business Suite, contains a vulnerability that allows a privileged network attacker to take control of the system. The flaw affects supported versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level administrative credentials to exploit it. Once exploited, an attacker could compromise confidentiality, integrity, and availability of HR data and system operations.

  • CVE-2026-46976HIGH 7.2

    Oracle Public Sector Payroll, a component of Oracle E-Business Suite, contains a vulnerability in its Internal Operations module that allows a high-privileged network attacker to gain complete control over the payroll system. Versions 12.2.3 through 12.2.15 are vulnerable. An attacker with administrative or elevated privileges who can reach the system over HTTP could compromise confidentiality, integrity, and availability—potentially disrupting payroll processing, modifying employee payment data, or exfiltrating sensitive compensation information.

  • CVE-2026-47366HIGH 7.2

    An administrator using the Administration Control Panel (ACP) can assign permissions that exceed what their own account is authorized to hold, bypassing the system's permission hierarchy. This allows a compromised or malicious admin to escalate their own privileges beyond their intended scope without requiring additional account takeover or technical exploitation.

  • CVE-2026-48895HIGH 7.2

    Apache APISIX versions 3.0.0 through 3.16.0 contain an open-redirect vulnerability that allows attackers to manipulate HTTP client headers and redirect users to untrusted websites. This attack could potentially expose session tokens or other sensitive authentication data. The issue affects the API gateway's request handling and requires upgrading to version 3.17.0 or later to remediate.

  • CVE-2026-49196HIGH 7.2

    CVE-2026-49196 is a command injection vulnerability in Acer Predator Connect W6X Wi-Fi devices. The device's built-in feature for blocking Wi-Fi connections fails to properly validate MAC addresses before processing them, creating an opening for attackers to inject and execute arbitrary shell commands. An attacker with administrative access could leverage this to compromise the device and potentially the network it protects.

  • CVE-2026-49506HIGH 7.2

    Dell Wyse Management Suite versions before 5.5 HF1 contain a path traversal vulnerability that allows a highly privileged remote attacker to bypass directory restrictions and execute arbitrary code on the system. Path traversal flaws occur when an application fails to properly sanitize file path inputs, allowing attackers to access files and directories outside the intended scope. In this case, the vulnerability is particularly dangerous because it leads directly to remote code execution in the hands of someone with elevated privileges.

  • CVE-2026-49814HIGH 7.2

    Dell PowerProtect Data Domain, a widely deployed deduplication and backup platform, contains a command injection flaw that allows authenticated attackers with high privileges to execute arbitrary system commands. Versions 7.7.1.0 through 8.7, along with multiple Long-Term Support (LTS) release branches, are affected. An attacker who gains high-level credentials or access can bypass application controls and run OS commands directly on the appliance, potentially compromising the entire backup infrastructure and any data stored within it.

  • CVE-2026-49815HIGH 7.2

    Dell PowerProtect Data Domain, a widely-deployed deduplication and backup storage system, contains an OS command injection vulnerability that allows high-privileged remote attackers to execute arbitrary commands on affected systems. The flaw affects multiple release branches spanning versions 7.7.1.0 through 8.7, with specific LTS versions also impacted. Exploitation requires elevated privileges and network access, but once triggered, grants an attacker direct command execution with system-level capabilities.

  • CVE-2026-49954HIGH 7.2

    Discuz! X5.0 has a vulnerability in certain releases that lets admin accounts install malicious plugins and run arbitrary code on the web server. The flaw combines two weaknesses: a path traversal bug that bypasses input validation during plugin import, and the ability to upload files. When an administrator imports a specially crafted plugin configuration with malicious directory paths, the system fails to properly sanitize the input, allowing those paths to be used in file inclusion operations. This ultimately gives attackers code execution as the web server user.

  • CVE-2026-50043HIGH 7.2

    A command injection vulnerability exists in SkyBridge MB-A100 and MB-A110 devices that allows an attacker with administrative credentials to execute arbitrary operating system commands. The flaw stems from insufficient input validation when processing OS commands, enabling privilege-level users to bypass security controls and run unauthorized code on the device.

  • CVE-2026-50189HIGH 7.2

    Appsmith, a low-code platform for building admin dashboards and internal tools, contains a critical configuration issue in versions before 2.1. The platform exposes supervisord—a process management tool—through a public-facing web route, allowing authenticated administrators to execute arbitrary commands on the underlying Docker container. An attacker with admin credentials can manipulate the supervisord XML-RPC interface to add malicious programs and execute OS-level commands, completely compromising the container's integrity and confidentiality.

  • CVE-2026-50231HIGH 7.2

    Lyrion Music Server version 9.2.0 contains a stored cross-site scripting (XSS) vulnerability in its log viewer that allows attackers to inject malicious JavaScript without authentication. The vulnerability exists because the application fails to properly escape template variables, allowing crafted input to be permanently stored and executed in the browsers of users who view the logs. Attackers can inject payloads through multiple vectors including search parameters, log line numbers, file paths, or by manipulating values that the server naturally logs such as HTTP headers, stream titles, and player names.

  • CVE-2026-50232HIGH 7.2

    Lyrion Music Server version 9.2.0 has a stored cross-site scripting (XSS) vulnerability that lets attackers embed malicious code into audio file metadata fields such as GENRE, ARTIST, and ALBUM. When users browse or play these files through the web interface, the injected scripts execute in their browser, potentially granting attackers access to server management functions and sensitive configuration details. Unlike reflected XSS attacks that require a specially crafted link, this vulnerability persists in the server's database, affecting any user who interacts with a poisoned media file.

  • CVE-2026-53478HIGH 7.2

    A command injection vulnerability in Dell PowerProtect Data Domain allows authenticated users with administrative privileges to execute arbitrary operating system commands remotely. The vulnerability affects multiple release branches spanning versions 7.7.1.0 through 8.7, potentially giving an attacker the ability to compromise the integrity and confidentiality of backup data stored on affected systems.

  • CVE-2026-53479HIGH 7.2

    Dell PowerProtect Data Domain backup appliances in multiple versions contain an OS command injection flaw that allows authenticated high-privileged users to execute arbitrary commands with root-level access. An attacker with administrative credentials could bypass security controls and gain unrestricted control of the appliance. This is a serious vulnerability because it affects backup infrastructure—a critical component that adversaries often target to prevent recovery after ransomware attacks.

  • CVE-2026-53676HIGH 7.2

    ThingsBoard, an IoT platform, contains a prototype pollution vulnerability that allows authenticated tenant administrators to execute arbitrary code in a restricted sandboxed environment. While the code execution occurs within a sandbox that limits its reach, an attacker with admin credentials could use this flaw to manipulate application behavior, bypass security controls, or potentially escalate privileges. The vulnerability requires valid login credentials with tenant administrator role—it is not remotely exploitable without prior authentication.

  • CVE-2026-53816HIGH 7.2

    OpenClaw contains a flaw that allows malicious or compromised paired nodes to forge execution lifecycle events without proper authorization checks. In a paired-node architecture, each node is normally restricted in what actions it can perform. This vulnerability enables an attacker controlling a paired node to send specially crafted messages to the gateway that trick sessions into exposing capabilities that should be blocked at the reduced node level. The issue stems from insufficient validation of event provenance—essentially, the system does not adequately verify that lifecycle events truly originated from an authorized source before acting on them.

  • CVE-2026-53876HIGH 7.2

    The RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains a command injection flaw in its web console that allows an administrator user to execute arbitrary system commands with root-level privileges. An authenticated admin can inject malicious OS commands through the web interface, leading to full system compromise. This is a serious issue because it bypasses normal user privilege boundaries and grants attackers complete control of the router once they gain admin access.

  • CVE-2026-54308HIGH 7.2

    n8n, an open source workflow automation platform, contains a vulnerability in two specific trigger node types—MicrosoftAgent365Trigger and StripeTrigger—that fail to authenticate inbound webhook requests. An attacker who discovers the webhook URL can send forged data to trigger workflows with malicious payloads, potentially causing unauthorized actions or data manipulation. The vulnerability affects versions prior to 2.25.7 and 2.26.2.

  • CVE-2026-54801HIGH 7.2

    A vulnerability in CPCI85 Central Processing/Communication and SICORE Base system allows authenticated users with administrative rights to abuse the web API when modifying administrative accounts. The flaw stems from weak validation of authentication credentials during these operations, potentially enabling such users to escalate their privileges beyond their intended scope. An attacker would need valid credentials to attempt this attack, but the weak validation could allow them to grant themselves or other accounts higher privileges than authorized.