CVE-2024-3272
D-Link NAS Hard-Coded Credentials Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
D-Link Multiple NAS Devices Use of Hard-Coded Credentials Vulnerability — D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contains a hard-coded credential that allows an attacker to conduct authenticated command injection, leading to remote, unauthorized code execution.
CVE-2024-24919
Check Point Quantum Security Gateways Information Disclosure Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Check Point Quantum Security Gateways Information Disclosure Vulnerability — Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the inte…
CVE-2024-26169
Windows Error Reporting Service Privilege Escalation Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability — Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
CVE-2024-27198
JetBrains TeamCity Authentication Bypass Vulnerability (CVE-2024-27198)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
JetBrains TeamCity Authentication Bypass Vulnerability — JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.
CVE-2024-27348
Apache HugeGraph-Server Remote Code Execution via Improper Access Control
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apache HugeGraph-Server Improper Access Control Vulnerability — Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
CVE-2024-28986
SolarWinds Web Help Desk Deserialization RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability — SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.
CVE-2024-28987
SolarWinds Web Help Desk Hardcoded Credential Remote Access Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
SolarWinds Web Help Desk Hardcoded Credential Vulnerability — SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.
CVE-2024-29059
Microsoft .NET Framework Information Disclosure Vulnerability - RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft .NET Framework Information Disclosure Vulnerability — Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
CVE-2024-29745
Android Pixel Fastboot Information Disclosure Vulnerability CVE-2024-29745
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Android Pixel Information Disclosure Vulnerability — Android Pixel contains an information disclosure vulnerability in the fastboot firmware used to support unlocking, flashing, and locking affected devices.
CVE-2024-29748
Android Pixel Privilege Escalation via Factory Reset Interruption
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Android Pixel Privilege Escalation Vulnerability — Android Pixel contains a privilege escalation vulnerability that allows an attacker to interrupt a factory reset triggered by a device admin app.
CVE-2024-29824
Ivanti Endpoint Manager SQL Injection Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability — Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29988
Microsoft SmartScreen Prompt Mark of the Web Bypass Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability — Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2…
CVE-2024-30040
Microsoft Windows MSHTML Platform Security Feature Bypass (CVE-2024-30040)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability — Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
CVE-2024-30051
Microsoft DWM Core Library Privilege Escalation (CVE-2024-30051)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft DWM Core Library Privilege Escalation Vulnerability — Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
CVE-2024-30088
Windows Kernel TOCTOU Race Condition Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability — Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
CVE-2024-32113
Apache OFBiz Path Traversal Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apache OFBiz Path Traversal Vulnerability — Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
CVE-2024-11667
Zyxel Firewalls Path Traversal Vulnerability (CVE-2024-11667)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Zyxel Multiple Firewalls Path Traversal Vulnerability — Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
CVE-2024-3273
D-Link NAS Command Injection Vulnerability (CVE-2024-3273)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
D-Link Multiple NAS Devices Command Injection Vulnerability — D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.
CVE-2024-3400
Palo Alto PAN-OS GlobalProtect Unauthenticated Command Injection RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Palo Alto Networks PAN-OS Command Injection Vulnerability — Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
CVE-2024-34102
Adobe Commerce/Magento XXE Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability — Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
CVE-2024-35250
Windows Kernel-Mode Driver Untrusted Pointer Dereference Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability — Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
CVE-2025-14733
WatchGuard Firebox iked Process Out-of-Bounds Write RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
WatchGuard Firebox Out of Bounds Write Vulnerability — WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile us…
CVE-2025-14847
MongoDB Zlib Protocol Header Length Parameter Improper Handling RCE
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability — MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized he…
CVE-2025-48633
Android Framework Information Disclosure Vulnerability (CVE-2025-48633)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Android Framework Information Disclosure Vulnerability — Android Framework contains an unspecified vulnerability that allows for information disclosure.
CVE-2025-48703
CWP Control Web Panel OS Command Injection RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
CWP Control Web Panel OS Command Injection Vulnerability — CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changeP…
CVE-2025-48928
TeleMessage TM SGNL Core Dump Exposure Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability — TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content …
CVE-2025-54309
CrushFTP Unprotected Alternate Channel Remote Admin Access Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
CrushFTP Unprotected Alternate Channel Vulnerability — CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS.
CVE-2025-58360
OSGeo GeoServer XXE Vulnerability in WMS GetMap Endpoint
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability — OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms oper…
CVE-2025-59287
Microsoft WSUS Deserialization RCE Vulnerability (CVE-2025-59287)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-61757
Oracle Fusion Middleware Missing Authentication for Critical Function
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability — Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
CVE-2025-7775
Citrix NetScaler Memory Overflow RCE Vulnerability CVE-2025-7775
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Citrix NetScaler Memory Overflow Vulnerability — Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service.
CVE-2024-23692
Rejetto HTTP File Server Template Injection Remote Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability — Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker …
CVE-2024-11182
MDaemon Email Server XSS Vulnerability via HTML Email Messages
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability — MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.
CVE-2024-11680
ProjectSend Improper Authentication in options.php Allows Unauthorized Configuration Modification
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
ProjectSend Improper Authentication Vulnerability — ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP requests to options.php. Succes…
CVE-2024-1212
Progress Kemp LoadMaster Unauthenticated OS Command Injection
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Progress Kemp LoadMaster OS Command Injection Vulnerability — Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system comman…
CVE-2024-12356
BeyondTrust PRA/RS Unauthenticated Command Injection Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that …
CVE-2024-12686
BeyondTrust PRA/RS OS Command Injection - Critical RCE Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrati…
CVE-2024-13159
Ivanti Endpoint Manager Absolute Path Traversal Information Disclosure
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13161
Ivanti Endpoint Manager Absolute Path Traversal Information Disclosure
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-1709
ConnectWise ScreenConnect Authentication Bypass - Admin Account Creation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
ConnectWise ScreenConnect Authentication Bypass Vulnerability — ConnectWise ScreenConnect contains an authentication bypass vulnerability that allows an attacker with network access to the management interface to create a new, administrator-level account on affected devices.
CVE-2024-20353
Cisco ASA and FTD Infinite Loop Remote Denial of Service
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco ASA and FTD Denial of Service Vulnerability — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
CVE-2024-20359
Cisco ASA and FTD Privilege Escalation to Root (CVE-2024-20359)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco ASA and FTD Privilege Escalation Vulnerability — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.
CVE-2024-20399
Cisco NX-OS CLI Command Injection Vulnerability (CVE-2024-20399)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco NX-OS Command Injection Vulnerability — Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.
CVE-2024-20439
Cisco Smart Licensing Utility Static Credential Remote Administrative Access
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco Smart Licensing Utility Static Credential Vulnerability — Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
CVE-2024-20481
Cisco ASA/FTD RAVPN Denial-of-Service via Resource Exhaustion
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Cisco ASA and FTD Denial-of-Service Vulnerability — Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-se…
CVE-2024-20767
Adobe ColdFusion Improper Access Control Vulnerability CVE-2024-20767
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Adobe ColdFusion Improper Access Control Vulnerability — Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVE-2024-21287
Oracle Agile PLM Incorrect Authorization Vulnerability (CVE-2024-21287)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability — Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of…
CVE-2024-23897
Jenkins CLI Path Traversal Vulnerability Enables Arbitrary File Read and Code Execution
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Jenkins Command Line Interface (CLI) Path Traversal Vulnerability — Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
CVE-2024-23296
Apple RTKit Memory Corruption Vulnerability - Kernel Protection Bypass
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apple Multiple Products Memory Corruption Vulnerability — Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
CVE-2024-23225
Apple Kernel Memory Corruption Vulnerability - Multiple OS Bypass
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apple Multiple Products Memory Corruption Vulnerability — Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.
CVE-2024-23222
Apple WebKit Type Confusion RCE Vulnerability (CVE-2024-23222)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Apple Multiple Products WebKit Type Confusion Vulnerability — Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that u…
CVE-2024-23113
Fortinet Multiple Products Remote Code Execution via Format String
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortinet Multiple Products Format String Vulnerability — Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.
CVE-2024-21893
Ivanti SSRF Vulnerability in SAML Component - Unauthenticated Access
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability — Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAM…
CVE-2024-21887
Ivanti Connect Secure Command Injection Vulnerability (CVE-2024-21887)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability — Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticat…
CVE-2024-21413
Microsoft Outlook Remote Code Execution via Protected View Bypass
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Outlook Improper Input Validation Vulnerability — Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and o…
CVE-2024-21412
Windows Internet Shortcut Files Security Feature Bypass (CVE-2024-21412)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability — Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
CVE-2024-21410
Microsoft Exchange Server Privilege Escalation Vulnerability CVE-2024-21410
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Exchange Server Privilege Escalation Vulnerability — Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2024-21351
Windows SmartScreen Security Feature Bypass Vulnerability (CVE-2024-21351)
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability — Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could l…
CVE-2024-21338
Windows Kernel appid.sys IOCTL Insufficient Access Control Privilege Escalation
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability — Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attack…
CVE-2024-20953
Oracle Agile PLM Deserialization Remote Code Execution Vulnerability
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability — Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
CVE-2024-21762
Fortinet FortiOS Remote Code Execution via Out-of-Bounds Write
11:01 KSA
CRITICAL
CVSS 9.0
⚠ CISA KEV
Fortinet FortiOS Out-of-Bound Write Vulnerability — Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
CVE-2026-6518
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload an
00:49 KSA
HIGH
CVSS 8.8
CWE-434
The CMP – Coming Soon & Maintenance Plugin by NiteoThemes plugin for WordPress is vulnerable to arbitrary file upload and remote code execution in all versions up to, and including, 4.1.16 via the `cmp_theme_update_install` AJAX action. This is due to the function only checking f…
CVE-2026-32171
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a netw
06:19 KSA
HIGH
CVSS 8.8
CWE-522
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-32168
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
06:19 KSA
HIGH
CVSS 7.8
CWE-20
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2026-2262
Easy Appointments WordPress Plugin Unauthenticated Sensitive Data Exposure
00:49 KSA
HIGH
CVSS 7.5
CWE-200
The Easy Appointments plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.12.21 via the `/wp-json/wp/v2/eablocks/ea_appointments/` REST API endpoint. This is due to the endpoint being registered with `'permission_callback' …
CVE-2026-32178
.NET Special Elements Neutralization Spoofing Vulnerability
12:19 KSA
HIGH
CVSS 7.5
CWE-138
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-32080
Windows WalletService Use-After-Free Privilege Escalation
03:58 KSA
HIGH
CVSS 7.0
CWE-416
Use after free in Windows WalletService allows an authorized attacker to elevate privileges locally.
CVE-2026-2434
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attribute
07:18 KSA
MEDIUM
CVSS 6.4
CWE-79
The Pz-LinkCard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'blogcard' shortcode attributes in all versions up to, and including, 2.5.8.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, …
CVE-2026-2986
Contextual Related Posts WordPress Plugin Stored XSS via other_attributes
20:16 KSA
MEDIUM
CVSS 6.4
CWE-79
The Contextual Related Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'other_attributes' parameter in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacke…
CVE-2026-1559
Youzify WordPress Plugin Stored XSS via checkin_place_id Parameter
09:27 KSA
MEDIUM
CVSS 6.4
CWE-79
The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subs…
CVE-2026-4801
CoBlocks WordPress Plugin Stored XSS via iCal Feed Data
11:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The Page Builder Gutenberg Blocks – CoBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via external iCal feed data in all versions up to, and including, 3.1.16 due to insufficient output escaping of event titles, descriptions, and locations fetched from ex…
CVE-2026-6048
Flipbox Elementor Plugin Stored XSS via Custom Attributes
11:32 KSA
MEDIUM
CVSS 6.4
CWE-79
The Flipbox Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Flipbox widget's button URL `custom_attributes` field in all versions up to, and including, 2.1.1 due to insufficient validation of custom attribute names. Specifically, the …
CVE-2026-0894
WordPress Content Blocks Plugin Stored XSS via Shortcode
17:54 KSA
MEDIUM
CVSS 6.4
CWE-79
The Content Blocks (Custom Post Widget) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content_block shortcode in all versions up to, and including, 3.3.9 due to insufficient input sanitization and output escaping on user supplied values consum…
CVE-2026-1838
The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all
09:27 KSA
MEDIUM
CVSS 6.1
CWE-79
The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject …
CVE-2026-2505
WordPress Categories Images Plugin Stored XSS via z_taxonomy_image Shortcode
17:54 KSA
MEDIUM
CVSS 5.4
CWE-79
The Categories Images plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.1, via the 'z_taxonomy_image' shortcode. This is due to the shortcode rendering path passing attacker-controlled class input into a fallback image builder…