Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.
This vulnerability is a directory traversal flaw caused by improper path confinement and lack of authentication enforcement within the GitLab repository commits API. The root cause lies in the API's failure to validate and restrict file path inputs, allowing unauthorized access to files outside intended directories. The affected component is the repository commits API in GitLab Community and Enterprise Editions across multiple versions prior to specific patch releases.
This vulnerability is a dynamic class loading flaw in PaperCut MF and NG's database connection utilities. The root cause is the application's instantiation of database driver classes based on configurable driver names without validating these against an allowlist of approved drivers. This unsafe dynamic loading occurs within the database connection component, enabling untrusted class loading from the application classpath.
This vulnerability is an improper access control flaw in the web management interface of PaperCut MF and PaperCut NG. The root cause is the premature execution of backend administrative functions before completing access validation checks. This affects the administrative web interface component responsible for enforcing authentication and authorization controls on remote requests.
This vulnerability is a command injection flaw rooted in improper sanitization of untrusted input within the SNMP notification processing component of Zimbra Collaboration Suite (ZCS). Specifically, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, maliciously crafted SMTP requests can inject operating system commands. The flaw arises from inadequate input validation during the handling of SNMP notifications in affected ZCS versions prior to 10.1.20.
The vulnerability in Adobe Commerce is an Incorrect Authorization flaw rooted in improper access control checks within the application. This issue arises from the failure to correctly enforce privilege restrictions on certain administrative functions, allowing unauthorized users to escalate privileges. The affected component is the authorization mechanism governing access to sensitive resources and administrative features in Adobe Commerce versions including 2.4.4 and its patches.
This vulnerability is an unsafe deserialization flaw (CWE-502) in the JetBrains TeamCity agent polling protocol. The root cause lies in improper validation and handling of serialized data received from unauthenticated remote sources during agent-server communication. The affected component is the TeamCity server's agent polling mechanism, which processes incoming serialized objects without adequate integrity or authenticity checks.
This vulnerability is an authentication bypass affecting the Check Point SmartConsole login process within the Quantum Security Management product. The root cause lies in improper validation of authentication tokens during the login sequence, allowing an unauthenticated attacker to retrieve a valid application login token. The flaw specifically impacts the authentication mechanism of the Management Server component when Trusted Clients restrictions are not enforced.
This vulnerability is an authentication bypass caused by weak authentication mechanisms within Microsoft Office SharePoint Enterprise Server 2016. The root cause lies in improper validation of authentication tokens or credentials during network-based access attempts. The affected component is the authentication subsystem of SharePoint Server, which fails to enforce adequate security checks, allowing unauthorized access to protected resources.
The vulnerability is an unrestricted file upload flaw in the SP Page Builder extension for Joomla, specifically within its file handling component. The root cause is the lack of proper validation and restriction on file types and content, allowing unauthenticated users to upload arbitrary files. This improper input validation affects the file upload functionality of the extension, enabling execution of unauthorized code on the server.
This vulnerability is an authentication bypass affecting the PostgreSQL sidecar service endpoint in Splunk Enterprise. The root cause is the absence of authentication controls on this endpoint, which allows unauthenticated network users to invoke file operations. The affected component is the PostgreSQL sidecar service integrated within Splunk Enterprise versions prior to 10.2.4 and 10.0.7.
This vulnerability is an OS command injection flaw caused by improper neutralization of special elements within HTTP request parameters. The root cause lies in Fortinet FortiSandbox's failure to sanitize user-supplied input before incorporating it into operating system commands. Affected components include FortiSandbox versions 4.2.x, 4.4.0 through 4.4.8, 5.0.0 through 5.0.5, FortiSandbox Cloud 5.0.4 through 5.0.5, and FortiSandbox PaaS 5.0.4 through 5.0.5.
The vulnerability is an OS command injection caused by improper sanitization of user-supplied input within Ivanti Sentry's command execution routines. This flaw resides in the input handling of specific components responsible for processing remote commands, allowing crafted inputs to be interpreted as shell commands. The affected feature is the command processing mechanism in Ivanti Sentry versions prior to R10.5.2, R10.6.2, and R10.7.1.
This vulnerability is an authentication bypass caused by a logic flaw in the certificate validation process within the deprecated IKEv1 key exchange protocol. The flaw exists in the Remote Access and Mobile Access components of the Check Point Quantum Security Gateway, specifically in the handling of certificate validation during VPN connection establishment. The root cause is improper validation logic that fails to verify user credentials correctly, allowing unauthorized access through the affected authentication mechanism.
This vulnerability is an OS command injection flaw arising from improper input sanitization within multiple API command endpoints of the Progress Software LoadMaster appliance. The root cause is the failure to validate or sanitize user-supplied parameters before passing them to underlying system command execution functions. The affected component is the LoadMaster's API interface handling command inputs, which processes these inputs insecurely, enabling injection of arbitrary operating system commands.
This vulnerability is a server-side request forgery (SSRF) rooted in improper input validation of specific HTTP requests within Cisco Unified Communications Manager and its Session Management Edition. The flaw occurs in the WebDialer service component, which processes crafted HTTP requests without adequate sanitization. The underlying mechanism allows unauthorized external input to influence internal server requests and file operations on the affected device's operating system.
This vulnerability is an authentication bypass in the peering authentication mechanism of Cisco Catalyst SD-WAN Controller and Manager. The root cause lies in improper validation during the control connection handshaking process, allowing crafted requests to circumvent authentication checks. The affected component is the peering authentication feature responsible for establishing secure control connections within the SD-WAN fabric.
This vulnerability is an authentication bypass affecting the GlobalProtect portal and gateway components of Palo Alto Networks PAN-OS software. The root cause lies in improper validation of authentication mechanisms allowing unauthorized users to circumvent security checks. The flaw specifically impacts the VPN authentication process, enabling access without valid credentials.
This vulnerability is a command injection flaw in the LiteLLM proxy server component, specifically affecting the AI Gateway's handling of server configuration inputs. The root cause lies in two POST endpoints (/mcp-rest/test/connection and /mcp-rest/test/tools/list) that accept unvalidated server configuration data, including command, args, and env fields, which are executed via stdio transport as subprocesses with proxy process privileges. The lack of role-based access control combined with acceptance of arbitrary commands enables exploitation.
This vulnerability is an authentication bypass affecting the login flow component of cPanel and WHM versions post-11.40. The root cause lies in improper validation of authentication tokens or session handling mechanisms, allowing unauthenticated requests to bypass normal login checks. The flaw specifically compromises the authentication logic within the web-based control panel interface, enabling unauthorized access without valid credentials.
This vulnerability is an authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) caused by an improper system process created during device boot. The flaw resides in the handling of HTTP requests by the FMC software, allowing unauthenticated attackers to trigger unauthorized system-level script execution. The affected component is the FMC's web management interface running on specific versions prior to 7.0.3.
This vulnerability is an authentication bypass affecting the peering authentication mechanism in Cisco Catalyst SD-WAN Controller and Manager components. The root cause lies in improper validation of authentication requests during the peering process, which fails to enforce correct credentials. This flaw resides specifically within the peering authentication subsystem responsible for establishing trust between SD-WAN nodes.
This vulnerability is a use-after-free memory corruption issue occurring in the CSS processing component of Google Chrome. The root cause lies in improper management of memory lifecycle for CSS objects, leading to references to freed memory. The flaw affects the rendering engine responsible for parsing and applying CSS styles within the browser's sandboxed environment.
This vulnerability is an authentication bypass in Ivanti Endpoint Manager versions prior to 2024 SU5. It stems from improper access control mechanisms within the RemoteControlAuth API, specifically the POST /RemoteControlAuth/api/Auth endpoint. The flaw allows unauthenticated remote actors to bypass normal authentication checks and access sensitive credential data stored by the application.
This vulnerability is a pre-authentication remote code execution caused by improper input validation in BeyondTrust Remote Support and older Privileged Remote Access versions. The root cause lies in the WebSocket endpoint /nw, which accepts binary payloads without adequate sanitization, allowing injection of operating system commands. The affected components are the WebSocket service and the mechanism that retrieves the company identifier via the /get_mech_list endpoint, which is exploited to authenticate the malicious WebSocket connection.
This vulnerability is a SQL injection flaw rooted in improper neutralization of special characters within SQL commands. The issue arises from insufficient input validation in the Fortinet FortiClientEMS web interface, allowing crafted HTTP requests to manipulate backend database queries. The affected component is the FortiClientEMS management system version 7.4.4, specifically its handling of SQL statements triggered by user-supplied input.
This vulnerability is a code injection flaw rooted in improper input validation within Ivanti Endpoint Manager Mobile. The affected component fails to sanitize user-supplied data before processing, enabling malicious payloads to be injected and executed. The flaw resides in the core mobile management service handling remote commands or scripts without adequate security controls.
This vulnerability is a code injection flaw rooted in improper input validation within Ivanti Endpoint Manager Mobile. The affected component fails to sanitize user-supplied input, enabling injection of arbitrary code into the execution context. The flaw exists in the core processing logic of the mobile management interface, allowing unfiltered data to be executed by the system.
This vulnerability is an authentication bypass affecting SolarWinds Web Help Desk, caused by improper validation of authentication tokens or session management mechanisms. The flaw resides in the Web Help Desk's authentication flow, specifically within components responsible for user identity verification, allowing unauthorized access to protected functions without valid credentials.
The vulnerability is an untrusted data deserialization flaw within SolarWinds Web Help Desk, specifically affecting its data processing components that handle serialized input. The root cause lies in improper validation and sanitization of serialized objects received by the application, allowing maliciously crafted serialized data to be deserialized and executed. This flaw resides in the deserialization logic of the Web Help Desk service, which processes incoming serialized payloads without integrity checks or authentication.
This vulnerability is a security control bypass affecting SolarWinds Web Help Desk, rooted in insufficient enforcement of access restrictions within the application's web interface. The flaw allows unauthenticated users to circumvent authentication and authorization controls, exposing restricted administrative functions. The affected component is the Web Help Desk application prior to version 12.8.8 Hotfix 1, where access control mechanisms fail to properly validate user privileges on sensitive endpoints.
This vulnerability is an authentication bypass caused by improper validation of FortiCloud SSO authentication tokens. The flaw resides in Fortinet FortiOS and associated products, where the authentication mechanism fails to correctly verify user-device bindings. This allows an attacker with a valid FortiCloud account and a registered device to exploit alternate authentication paths, bypassing standard credential checks within the FortiCloud SSO integration component.
This vulnerability is an unauthenticated remote code execution flaw caused by missing authentication controls in the ConnectToHub API method of SmarterTools SmarterMail. The root cause is that the ConnectToHub function accepts and executes OS commands obtained from an external HTTP server without validating the source or requiring authentication. This affects SmarterMail versions prior to build 9511, specifically the ConnectToHub API component responsible for hub communication.
This vulnerability is a remote code execution flaw caused by improper handling of the exec_globals parameter in Langflow's validate endpoint. The root cause lies in the inclusion of resources from an untrusted control sphere, allowing unvalidated input to be executed within the application's global execution context. The affected component is the exec_globals parameter processing within the validate API endpoint of Langflow.
This vulnerability is an authentication bypass in the password reset API of SmarterTools SmarterMail prior to build 9511. The flaw arises from the force-reset-password endpoint allowing unauthenticated requests without validating existing credentials or reset tokens. The affected component is the system administrator password reset functionality within the SmarterMail API.
This vulnerability is an authentication bypass in the telnetd daemon of GNU Inetutils versions up to 2.7. The root cause lies in improper handling of the USER environment variable, where passing a specially crafted value "-f root" bypasses normal authentication checks. The affected component is the telnetd service responsible for remote login sessions.
This vulnerability is an authentication bypass in the Oracle Weblogic Server Proxy Plug-in components for Apache HTTP Server and IIS. It arises from improper access control enforcement in the proxy plug-in, allowing unauthenticated network requests via HTTP to interact with internal server functions. The affected components include Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0, and 14.1.2.0.0, and Weblogic Server Proxy Plug-in versions 12.2.1.4.0 and 14.1.1.0.0.
This vulnerability is an unrestricted file upload flaw in SmarterTools SmarterMail's mail server component. The root cause lies in insufficient validation of uploaded file paths and names in the POST /api/upload endpoint. This allows unauthenticated users to manipulate file path parameters, bypassing normal upload restrictions and placing files arbitrarily on the server filesystem.
This vulnerability is a critical remote code execution flaw caused by insufficient isolation in the workflow expression evaluation component of n8n. The root cause lies in the evaluation context for expressions supplied by authenticated users during workflow configuration, which is not adequately sandboxed from the underlying Node.js runtime environment. This permits execution of arbitrary code within the n8n process context via crafted expressions.
This vulnerability is a memory disclosure issue caused by improper handling of Zlib compressed protocol headers within the MongoDB Server's wire protocol. Specifically, mismatched length fields in the compressed data lead to reading uninitialized heap memory due to the server trusting the client-declared uncompressed size without proper memory initialization. The flaw resides in the zlib decompression logic processing OP_COMPRESSED messages, affecting multiple MongoDB Server versions across several major releases.
This vulnerability is a remote code execution flaw caused by improper input validation leading to unsafe dynamic command execution within the HPE OneView API. Specifically, the issue arises from the /rest/id-pools/executeCommand endpoint, which accepts user-supplied commands without adequate sanitization. The affected component is the HPE OneView REST API service, which processes these commands and executes them on the underlying system, enabling injection of arbitrary commands.
This vulnerability is a hardcoded credentials flaw involving the use of fixed AES cryptographic keys within Gladinet CentreStack and TrioFox prior to version 16.12.10420.56791. The root cause lies in the insecure implementation of AES cryptoscheme parameters embedded directly in the application code. This affects cryptographic components responsible for securing communications and file handling in publicly exposed endpoints of the affected products.
This vulnerability is a symbolic link (symlink) bypass flaw in the PutContents API of the Gogs self-hosted Git service. The root cause lies in improper handling of symlinks during file write operations, where the API fails to verify if the target file paths are symlinks pointing outside the intended repository directory. This allows authenticated users to manipulate file system paths, affecting the repository management component responsible for content storage.
This vulnerability is an authentication bypass caused by improper verification of cryptographic signatures within the SAML response processing mechanism. The flaw resides in Fortinet FortiSwitchManager and related Fortinet products where the cryptographic signature validation logic fails to correctly authenticate SAML assertions. This defect affects the FortiCloud Single Sign-On (SSO) login component, enabling manipulation of authentication tokens without proper signature validation.
This vulnerability in Langflow arises from a chained security flaw involving an overly permissive Cross-Origin Resource Sharing (CORS) configuration combined with insecure cookie attributes. Specifically, the CORS policy allows all origins with credentials enabled (allow_origins='*' and allow_credentials=True), while the refresh token cookie is set with SameSite=None, permitting cross-origin requests to include authentication tokens. The affected component is the refresh token endpoint responsible for issuing new access tokens, which improperly trusts attacker-controlled origins, enabling unauthorized token retrieval.
This vulnerability is a remote code execution flaw caused by unsafe deserialization of untrusted payloads in React Server Components. The issue arises from the deserialization logic in server function endpoints that process HTTP requests, specifically within the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. Affected versions include 19.0.0 through 19.2.0 of the React Server Components framework.
This vulnerability is a remote code execution flaw rooted in improper validation of the User-Agent header within the Ray AI compute engine’s development tooling. The defense mechanism relies on detecting the User-Agent header starting with "Mozilla" to prevent browser-based attacks, but this check is insufficient because the fetch specification permits modification of this header. The affected component is the browser interaction layer in Ray versions prior to 2.52.0, which fails to properly restrict requests, enabling exploitation via DNS rebinding attacks combined with manipulated User-Agent headers.
This vulnerability is an XML External Entity (XXE) injection affecting GeoServer's XML input processing. The root cause is insufficient sanitization and restriction of XML external entity definitions within the XML payload submitted to the /geoserver/wms GetMap operation. This flaw resides in the XML parser component handling user-supplied XML data, enabling malicious entity expansion.
This vulnerability is an authenticated OS command injection affecting Fortinet FortiWeb versions 7.0.0 through 8.0.1. The root cause is improper neutralization of special elements in user-supplied input, allowing crafted HTTP requests or CLI commands to be interpreted and executed by the underlying operating system. The flaw resides in input handling mechanisms within FortiWeb's management interfaces that fail to sanitize command parameters adequately.
This vulnerability is a relative path traversal flaw in the Fortinet FortiWeb web application firewall. It arises from improper validation of user-supplied input in HTTP/HTTPS requests, specifically within the API endpoint handling administrative system configurations. The flaw allows crafted requests to traverse directories and access restricted CGI scripts, bypassing normal access controls in the affected FortiWeb versions.
The vulnerability is an improper access control flaw affecting the initial setup pages of the Triofox file sharing platform. The root cause is the failure to restrict access to administrative setup endpoints after the initial configuration is complete. Specifically, unauthenticated network requests can access management interfaces that should be disabled post-setup, exposing sensitive administrative functionality.