Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.
This vulnerability is an unauthenticated arbitrary file upload flaw in the Bricksforge WordPress plugin, caused by improper validation of the 'temporaryFileUploads' parameter during form submission. The root cause lies in the insufficient verification of the attacker-controlled URL field, allowing bypass of MIME type checks. The affected component is the temporary upload directory handling mechanism in Bricksforge versions up to and including 3.1.8.9.
This vulnerability is a stack-based buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway components. The root cause lies in improper bounds checking of input data processed by certain internal functions, leading to memory corruption. Affected versions include NetScaler ADC before 14.1-73.41, 13.1-64.28, and corresponding FIPS releases, as well as NetScaler Gateway before 14.1-73.41 and 13.1-64.28.
This vulnerability is a path traversal flaw caused by improper validation of pathname inputs within Fortinet FortiMail. The affected component fails to restrict access to directories, allowing crafted HTTP or HTTPS requests to manipulate file paths beyond intended boundaries. This weakness exists in FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, specifically in the web interface handling of file operations.
The vulnerability is a privilege escalation flaw rooted in improper permission handling within Zammad's local user management. Specifically, the local 'zammad' user account is able to escalate privileges to root due to insufficient access control enforcement in the underlying privilege separation mechanism. This affects all versions of the Zammad application, including the latest alpha releases, impacting the system's user privilege boundary.
This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.
This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.
This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.
This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.
This vulnerability is an improper input validation flaw in Citrix NetScaler ADC and Gateway components. The root cause lies in insufficient sanitization of user-supplied input within specific request handling routines, allowing malicious data to bypass validation checks. Affected components include NetScaler ADC versions prior to 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP variants, as well as NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23.
This vulnerability is a local file inclusion (LFI) flaw rooted in improper validation of file paths within the WordPress function get_page_template(). The function incorrectly resolves page templates by allowing inclusion of arbitrary readable .php files outside the active theme directories. This occurs due to insufficient restrictions on file path inputs used in template resolution logic, affecting the WordPress theme handling component.
This vulnerability is a heap-based buffer overflow (CWE-122) in the F5 BIG-IP Access Policy Manager (APM) component when configured as an OAuth Authorization Server. The flaw arises from improper handling of specific OAuth profile inputs within the virtual server's access policy, allowing crafted malicious traffic to corrupt memory. The issue affects the data plane processing path of BIG-IP APM when OAuth authorization server profiles are active, leading to uncontrolled execution flow.
This vulnerability is a directory traversal and file upload flaw in Check Point Quantum Security Management. It arises from insufficient input validation in the file upload functionality, allowing unauthorized manipulation of file paths. The affected component is the Check Point Management Server's file handling mechanism, which fails to restrict user-supplied file paths, enabling arbitrary file placement on the server.
This vulnerability in Arista Networks VeloCloud Orchestrator (VCO) On-Prem is a logic validation flaw classified under CWE-20 (Improper Input Validation). The root cause is inadequate validation of remote requests targeting privileged internal functions within the orchestrator's management interface. The affected component is the VCO on-premises orchestration platform, which processes unauthenticated network requests allowing unauthorized access to sensitive functionality.
This vulnerability is an arbitrary file upload flaw arising from inconsistent validation logic within the Gravity Forms WordPress plugin. Specifically, the upload_file function processes files without re-validating extensions when uploaded via hidden file upload fields, allowing bypass of the extension validation pipeline. The affected component is the File Upload field feature configured with Visibility set to 'Hidden' in Gravity Forms versions up to and including 3.1.0.4.
This vulnerability is an authentication bypass caused by insufficient authentication controls on a specific API endpoint within Cisco Identity Services Engine (ISE) Software. The root cause lies in the failure to enforce proper authentication checks on the affected API, allowing unauthenticated access. The flaw specifically impacts the web-based management interface component of Cisco ISE, enabling unauthorized interactions with its API endpoints.
This vulnerability is a permission bypass caused by a logic error within the Cellular Modem component of Google Android. The flaw arises from improper enforcement of access control checks, allowing unauthorized operations to proceed. The affected code fails to correctly validate permissions, leading to an escalation of privilege without requiring additional execution rights.
This vulnerability is an authentication bypass caused by a hard-coded HS256 JWT signing key embedded in the pbxapi index.php file of the Issabel Framework. The root cause is the use of a static, identical JWT secret across all installations, which compromises token integrity verification. The affected component is the JWT authentication mechanism within the Issabel Framework's pbxapi endpoint.
This vulnerability is a command injection flaw rooted in improper input validation within the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The affected component fails to sanitize crafted email messages containing malicious SQL statements, allowing arbitrary command execution at the operating system level. The issue specifically arises from insufficient validation in the email parsing mechanism that processes incoming email content.
This vulnerability is a remote code execution flaw caused by insufficient validation of the widget 'classes' map in the The Events Calendar WordPress plugin. The root cause lies in the parse_array function within the Element_Classes component, where a plain-array payload can bypass the is_safe_widget_instance() object check. This improper input handling in the widget classes feature enables unauthorized code execution.
This vulnerability is a remote code execution flaw caused by unsafe deserialization within the is_safe_widget_instance function of the The Events Calendar WordPress plugin. The root cause lies in insufficient validation allowing bypass of protection mechanisms due to PHP magic methods triggering during pre-parse combined with forged wp_hash integrity attributes before unserialize() is invoked. The affected component is the plugin's widget rendering logic, specifically in versions up to and including 6.17.4.
This vulnerability is a directory traversal flaw caused by improper path confinement and lack of authentication enforcement within the GitLab repository commits API. The root cause lies in the API's failure to validate and restrict file path inputs, allowing unauthorized access to files outside intended directories. The affected component is the repository commits API in GitLab Community and Enterprise Editions across multiple versions prior to specific patch releases.
This vulnerability is an authorization bypass affecting Dolibarr's document management components. The root cause lies in insufficient validation of the 'hashp' parameter within the document storage endpoints, specifically in htdocs/document.php and htdocs/viewimage.php. The application incorrectly allows bypassing token-based authorization checks when the 'hashp' parameter is set to a crafted value, enabling unauthorized access to protected resources.
This vulnerability is an improper certificate trust validation flaw within the VPN negotiation process of Check Point Quantum Security Gateway. The root cause is the failure to correctly verify the authenticity of certificates presented during the VPN handshake, allowing acceptance of malicious or forged certificates. The affected component is the VPN negotiation module responsible for establishing secure tunnels between endpoints.
The vulnerability is a remote unauthenticated system command execution flaw caused by a service in KGUARD DVR firmware that exposes a command execution interface on all network interfaces (0.0.0.0) without authentication. The root cause lies in the firmware's failure to restrict access to this service, allowing network access to execute arbitrary system commands. The affected component is the system command execution service embedded in the vulnerable KGUARD DVR firmware versions prior to 2017.
This vulnerability is an authentication bypass caused by improper validation in the wp-module-data component bundled within several Newfold WordPress plugins. The root cause lies in the authenticate() method hooked to the rest_authentication_errors filter, which performs an HMAC-style Bearer token comparison that fails when HiiveConnection::get_auth_token() returns false. This results in the secret salt collapsing to a constant hash, allowing attacker-controlled inputs to pass authentication checks.
This vulnerability is an out-of-bounds write (CWE-787) occurring within the V8 JavaScript engine component of Google Chrome. The root cause is improper bounds checking during memory operations in V8's handling of crafted JavaScript code, leading to memory corruption. The flaw specifically affects versions of Google Chrome prior to 153.0.8010.36, compromising the integrity of the V8 sandbox environment.
The vulnerability is an authorization bypass in the ConnectWise ScreenConnect client component that improperly controls file transfer and execution permissions during active remote sessions. The root cause lies in insufficient validation of user privileges and session state, allowing unauthorized file operations without host confirmation. This flaw specifically affects the client-side session management feature responsible for handling remote file transfers and execution commands.
This vulnerability is a path traversal flaw rooted in insufficient validation of user-supplied input within the knowns-dev knowns application. Specifically, the POST /api/templates/preview endpoint fails to properly sanitize the templateFile parameter, allowing directory traversal sequences to bypass intended path restrictions. The affected component is the template preview API handler responsible for processing file paths used in template rendering.
This vulnerability is an improper neutralization of special elements within the template engine of Adobe Commerce. The root cause lies in insufficient sanitization of user-controllable input embedded in templates, allowing injection of malicious code. The affected component is the template processing mechanism responsible for rendering dynamic content in Adobe Commerce versions including 2.4.4 and its patches.
The vulnerability is a pre-authentication remote code execution caused by improper handling of input data within N-able N-central. The root cause lies in the unsafe processing of commands or scripts in a component responsible for handling unauthenticated requests, allowing arbitrary code execution. This flaw affects N-central versions prior to 2026.3.1.14, specifically within the core service that processes external input without sufficient validation or sanitization.
This vulnerability is a privilege escalation flaw caused by improper argument handling in the SSH login process of Mikrotik RouterOS. Specifically, usernames beginning with a prohibited character bypass input validation, allowing unauthorized modification of the trusted RouterOS policy mask. The affected component is the RouterOS SSH login helper, which processes authentication requests without sufficient sanitization of username parameters.
This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.
This vulnerability is an authentication bypass in Mikrotik RouterOS's IPv4 UDP testing feature. The root cause lies in the acceptance of a "related" btest connection before the primary session completes authentication, allowing unauthenticated clients to initiate tests. Additionally, improper handling of packet size intervals leads to unsigned integer underflow and kernel packet buffer misuse, affecting the RouterOS kernel's network packet processing component.
The vulnerability is an unauthenticated remote code execution flaw rooted in the TCP server component of HKUDS AutoAgent. The TCP server binds to all network interfaces and improperly handles incoming connections without authentication, allowing execution of attacker-supplied commands. This occurs due to insufficient access control in the command execution logic within the containerized environment.
This vulnerability is a type confusion flaw located within the V8 JavaScript engine component of Google Chrome. The root cause stems from improper handling of object types in memory, leading to incorrect assumptions about data structures. This flaw affects V8's internal type system prior to version 152.0.7977.82, allowing crafted input to manipulate memory layout inconsistently.
This is a privilege escalation flaw rooted in missing authorization checks on the customer update endpoint of the Amelia booking plugin for WordPress. The endpoint accepts an attacker-controlled 'type' parameter and uses it to assign the caller's role without verifying that the caller is entitled to that role. A second defect compounds it: passing 'externalId' as 0 makes the plugin provision a new WordPress user carrying the wpamelia-manager role instead of linking to an existing account.
The SMA1000 Work Place interface exposes an unintended alternate access path that reaches internal request-handling functionality before authentication is enforced. Because the appliance treats this path as trusted, the server can be induced to issue requests on the attacker's behalf, which is the classic Server-Side Request Forgery pattern. The flaw sits in the pre-auth surface of the appliance, so no session or credential material is involved in reaching the vulnerable code.
The WP Cookie Notice for GDPR, CCPA and ePrivacy Consent plugin accepts file uploads without restricting the file type to a safe allowlist. Uploaded content lands in a location served by the web server, so a file carrying a PHP extension is interpreted rather than stored inert. The defect is in the upload handler itself, which validates neither the extension nor the resulting MIME type before writing the file to disk.
JFrog Artifactory ships a default configuration in which the authentication layer accepts material that should never be trusted from the network. Public analysis of the patch describes a phantom join key: an attacker-supplied value that the server accepts when validating a URL parameter, allowing a service admin token to be forged rather than issued. The weakness is in the identity verification path itself, not in any single API handler.
This vulnerability is a dynamic class loading flaw in PaperCut MF and NG's database connection utilities. The root cause is the application's instantiation of database driver classes based on configurable driver names without validating these against an allowlist of approved drivers. This unsafe dynamic loading occurs within the database connection component, enabling untrusted class loading from the application classpath.
This vulnerability is an improper access control flaw in the web management interface of PaperCut MF and PaperCut NG. The root cause is the premature execution of backend administrative functions before completing access validation checks. This affects the administrative web interface component responsible for enforcing authentication and authorization controls on remote requests.
The WPMU DEV Dashboard plugin builds its HMAC message by concatenating token, state, redirect and domain values without a separator, and the two sides of the SSO handshake disagree on which fields belong in that string. The unauthenticated wdpsso_step1 action signs and returns a concatenation of all four values, while wdpsso_step2 verifies a concatenation that omits the domain field. Because no delimiter separates the fields, the boundary between redirect and domain is ambiguous to the verifier.
The infosrvd service on Zbtlink routers listens on UDP/9992 and passes attacker-supplied data into a shell context without sanitization, yielding command injection. The service does implement an authentication step, but it is ineffective by construction: the scheme relies on a hardcoded salt shipped in the firmware, and an all-zero MAC address is accepted as a wildcard that matches any device. The two defects combine so that the authentication check can be satisfied by anyone who has read the firmware.
This vulnerability is a code injection flaw rooted in improper validation of input passed to the diffpatch API within Gitea's Git hook installation process. The affected component is the diffpatch API endpoint, which processes patch data without sufficient sanitization, enabling execution of arbitrary code via crafted input. The issue arises from the unsafe handling of patch content that is integrated into Git hooks, leading to command execution capability embedded in the repository management workflow.
The TYPO3 powermail extension takes the raw value of the form field designated as sender_name and hands it to a Fluid View as template source, then renders it. Because the value is treated as template code rather than as data, submitted Fluid syntax is parsed and its ViewHelpers are invoked. This is server-side template injection: the boundary between user input and template is absent, and no sanitization runs before rendering.
This vulnerability is a SQL Injection flaw caused by improper sanitization of input parameters within the GeoTools Java library. Specifically, the PostGIS DataStore implementation's `jsonArrayContains` function constructs SQL queries by directly embedding the `<value>` parameter without escaping, affecting versions 30.5 and earlier up to 33.6 and 34.5. The root cause lies in unsafe query generation when handling String or JSON fields in PostGIS 12 or greater environments.
This vulnerability is a code injection flaw rooted in improper handling of user-supplied input within the SPIP content management system. Specifically, the analyse_resultat_skel function fails to sanitize the X-Spip-Filtre HTTP request header, allowing arbitrary code to be injected and executed. The flaw affects SPIP versions prior to 4.4.21 and involves the HTTP header processing mechanism.
This vulnerability is a remote code execution flaw caused by improper handling of PHP code blocks within SPIP versions prior to 4.4.20. The root cause lies in incorrect parsing and identification of '<?php' tags combined with var_export's faulty processing of strings containing the '<' character. This parsing error occurs in the code serialization component responsible for exporting PHP variables, leading to unsafe code injection opportunities.
This vulnerability is a deserialization flaw in Microsoft Entra ID, where untrusted serialized data is processed insecurely. The root cause lies in improper validation and handling of serialized objects during deserialization, allowing malicious input to be interpreted as executable code. The affected component is the deserialization mechanism within Microsoft Entra ID's authentication or identity management services.
This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.