Monitor and prioritize what really matters — the 1% of vulnerabilities that can cause real impact.
This vulnerability is a path traversal flaw caused by improper validation of pathname inputs within Fortinet FortiMail. The affected component fails to restrict access to directories, allowing crafted HTTP or HTTPS requests to manipulate file paths beyond intended boundaries. This weakness exists in FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, specifically in the web interface handling of file operations.
This vulnerability is a session hijacking flaw rooted in improper session management within Zammad's authentication mechanism. The affected component fails to adequately validate or isolate session tokens, allowing unauthorized users to assume the identity of legitimate sessions. The flaw exists in the session handling logic of Zammad versions 6.3.0 through 6.5.4 and partially in versions 7.0.0 to 7.1.3 under specific environmental conditions.
This vulnerability is an authentication bypass caused by improper URI encoding handling within the HTTP request processing of Cisco Catalyst SD-WAN Manager's API session-based authentication management. The flaw resides in the API endpoint access control mechanism, where crafted HTTP requests with encoded URIs bypass authentication rules intended to restrict access. The affected component is the API authentication logic of Cisco Catalyst SD-WAN Manager.
This vulnerability is an out-of-bounds write flaw caused by improper bounds checking during file processing in Apple iOS and iPadOS. The root cause lies in the failure to correctly validate input size or index values, leading to memory corruption. The affected components are the file parsing routines within the operating system's media or document handling subsystems.
This vulnerability is a memory corruption issue classified under CWE-119, specifically a buffer overflow within Citrix NetScaler ADC and Gateway components. The root cause lies in improper handling of input data in certain network protocol processing routines, leading to unsafe memory operations. Affected versions include multiple releases prior to 14.1-73.37 and 13.1-64.23, impacting both standard and FIPS/NDcPP builds of the ADC and Gateway.
This vulnerability is an improper input validation flaw in Citrix NetScaler ADC and Gateway components. The root cause lies in insufficient sanitization of user-supplied input within specific request handling routines, allowing malicious data to bypass validation checks. Affected components include NetScaler ADC versions prior to 14.1-73.37 and 13.1-64.23, including FIPS and NDcPP variants, as well as NetScaler Gateway versions before 14.1-73.37 and 13.1-64.23.
This vulnerability is a local file inclusion (LFI) flaw rooted in improper validation of file paths within the WordPress function get_page_template(). The function incorrectly resolves page templates by allowing inclusion of arbitrary readable .php files outside the active theme directories. This occurs due to insufficient restrictions on file path inputs used in template resolution logic, affecting the WordPress theme handling component.
This vulnerability is a heap-based buffer overflow (CWE-122) in the F5 BIG-IP Access Policy Manager (APM) component when configured as an OAuth Authorization Server. The flaw arises from improper handling of specific OAuth profile inputs within the virtual server's access policy, allowing crafted malicious traffic to corrupt memory. The issue affects the data plane processing path of BIG-IP APM when OAuth authorization server profiles are active, leading to uncontrolled execution flow.
This vulnerability is a directory traversal and file upload flaw in Check Point Quantum Security Management. It arises from insufficient input validation in the file upload functionality, allowing unauthorized manipulation of file paths. The affected component is the Check Point Management Server's file handling mechanism, which fails to restrict user-supplied file paths, enabling arbitrary file placement on the server.
This vulnerability is an arbitrary file upload flaw arising from inconsistent validation logic within the Gravity Forms WordPress plugin. Specifically, the upload_file function processes files without re-validating extensions when uploaded via hidden file upload fields, allowing bypass of the extension validation pipeline. The affected component is the File Upload field feature configured with Visibility set to 'Hidden' in Gravity Forms versions up to and including 3.1.0.4.
This vulnerability is an authentication bypass caused by insufficient authentication controls on a specific API endpoint within Cisco Identity Services Engine (ISE) Software. The root cause lies in the failure to enforce proper authentication checks on the affected API, allowing unauthenticated access. The flaw specifically impacts the web-based management interface component of Cisco ISE, enabling unauthorized interactions with its API endpoints.
This vulnerability is an authentication bypass caused by a hard-coded HS256 JWT signing key embedded in the pbxapi index.php file of the Issabel Framework. The root cause is the use of a static, identical JWT secret across all installations, which compromises token integrity verification. The affected component is the JWT authentication mechanism within the Issabel Framework's pbxapi endpoint.
This vulnerability is a command injection flaw rooted in improper input validation within the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The affected component fails to sanitize crafted email messages containing malicious SQL statements, allowing arbitrary command execution at the operating system level. The issue specifically arises from insufficient validation in the email parsing mechanism that processes incoming email content.
This vulnerability is a remote code execution flaw caused by insufficient validation of the widget 'classes' map in the The Events Calendar WordPress plugin. The root cause lies in the parse_array function within the Element_Classes component, where a plain-array payload can bypass the is_safe_widget_instance() object check. This improper input handling in the widget classes feature enables unauthorized code execution.
This vulnerability is a remote code execution flaw caused by unsafe deserialization within the is_safe_widget_instance function of the The Events Calendar WordPress plugin. The root cause lies in insufficient validation allowing bypass of protection mechanisms due to PHP magic methods triggering during pre-parse combined with forged wp_hash integrity attributes before unserialize() is invoked. The affected component is the plugin's widget rendering logic, specifically in versions up to and including 6.17.4.
This vulnerability is a directory traversal flaw caused by improper path confinement and lack of authentication enforcement within the GitLab repository commits API. The root cause lies in the API's failure to validate and restrict file path inputs, allowing unauthorized access to files outside intended directories. The affected component is the repository commits API in GitLab Community and Enterprise Editions across multiple versions prior to specific patch releases.
This vulnerability is an authorization bypass affecting Dolibarr's document management components. The root cause lies in insufficient validation of the 'hashp' parameter within the document storage endpoints, specifically in htdocs/document.php and htdocs/viewimage.php. The application incorrectly allows bypassing token-based authorization checks when the 'hashp' parameter is set to a crafted value, enabling unauthorized access to protected resources.
This vulnerability is an improper certificate trust validation flaw within the VPN negotiation process of Check Point Quantum Security Gateway. The root cause is the failure to correctly verify the authenticity of certificates presented during the VPN handshake, allowing acceptance of malicious or forged certificates. The affected component is the VPN negotiation module responsible for establishing secure tunnels between endpoints.
This vulnerability is an authentication bypass caused by improper validation in the wp-module-data component bundled within several Newfold WordPress plugins. The root cause lies in the authenticate() method hooked to the rest_authentication_errors filter, which performs an HMAC-style Bearer token comparison that fails when HiiveConnection::get_auth_token() returns false. This results in the secret salt collapsing to a constant hash, allowing attacker-controlled inputs to pass authentication checks.
This vulnerability is an out-of-bounds write (CWE-787) occurring within the V8 JavaScript engine component of Google Chrome. The root cause is improper bounds checking during memory operations in V8's handling of crafted JavaScript code, leading to memory corruption. The flaw specifically affects versions of Google Chrome prior to 153.0.8010.36, compromising the integrity of the V8 sandbox environment.
This vulnerability is an improper neutralization of special elements within the template engine of Adobe Commerce. The root cause lies in insufficient sanitization of user-controllable input embedded in templates, allowing injection of malicious code. The affected component is the template processing mechanism responsible for rendering dynamic content in Adobe Commerce versions including 2.4.4 and its patches.
The vulnerability is a pre-authentication remote code execution caused by improper handling of input data within N-able N-central. The root cause lies in the unsafe processing of commands or scripts in a component responsible for handling unauthenticated requests, allowing arbitrary code execution. This flaw affects N-central versions prior to 2026.3.1.14, specifically within the core service that processes external input without sufficient validation or sanitization.
This vulnerability is a privilege escalation flaw caused by improper argument handling in the SSH login process of Mikrotik RouterOS. Specifically, usernames beginning with a prohibited character bypass input validation, allowing unauthorized modification of the trusted RouterOS policy mask. The affected component is the RouterOS SSH login helper, which processes authentication requests without sufficient sanitization of username parameters.
This vulnerability is an authentication bypass in the SSH protocol implementation of Mikrotik RouterOS. The root cause is that after a client requests a rekey operation, the server transitions into the connection protocol phase without verifying user authentication. This flaw affects the SSH server component responsible for managing session channels and command dispatching within RouterOS.
This vulnerability is a type confusion flaw located within the V8 JavaScript engine component of Google Chrome. The root cause stems from improper handling of object types in memory, leading to incorrect assumptions about data structures. This flaw affects V8's internal type system prior to version 152.0.7977.82, allowing crafted input to manipulate memory layout inconsistently.
This is a privilege escalation flaw rooted in missing authorization checks on the customer update endpoint of the Amelia booking plugin for WordPress. The endpoint accepts an attacker-controlled 'type' parameter and uses it to assign the caller's role without verifying that the caller is entitled to that role. A second defect compounds it: passing 'externalId' as 0 makes the plugin provision a new WordPress user carrying the wpamelia-manager role instead of linking to an existing account.
The SMA1000 Work Place interface exposes an unintended alternate access path that reaches internal request-handling functionality before authentication is enforced. Because the appliance treats this path as trusted, the server can be induced to issue requests on the attacker's behalf, which is the classic Server-Side Request Forgery pattern. The flaw sits in the pre-auth surface of the appliance, so no session or credential material is involved in reaching the vulnerable code.
JFrog Artifactory ships a default configuration in which the authentication layer accepts material that should never be trusted from the network. Public analysis of the patch describes a phantom join key: an attacker-supplied value that the server accepts when validating a URL parameter, allowing a service admin token to be forged rather than issued. The weakness is in the identity verification path itself, not in any single API handler.
This vulnerability is a dynamic class loading flaw in PaperCut MF and NG's database connection utilities. The root cause is the application's instantiation of database driver classes based on configurable driver names without validating these against an allowlist of approved drivers. This unsafe dynamic loading occurs within the database connection component, enabling untrusted class loading from the application classpath.
This vulnerability is an improper access control flaw in the web management interface of PaperCut MF and PaperCut NG. The root cause is the premature execution of backend administrative functions before completing access validation checks. This affects the administrative web interface component responsible for enforcing authentication and authorization controls on remote requests.
The WPMU DEV Dashboard plugin builds its HMAC message by concatenating token, state, redirect and domain values without a separator, and the two sides of the SSO handshake disagree on which fields belong in that string. The unauthenticated wdpsso_step1 action signs and returns a concatenation of all four values, while wdpsso_step2 verifies a concatenation that omits the domain field. Because no delimiter separates the fields, the boundary between redirect and domain is ambiguous to the verifier.
This vulnerability is a code injection flaw rooted in improper validation of input passed to the diffpatch API within Gitea's Git hook installation process. The affected component is the diffpatch API endpoint, which processes patch data without sufficient sanitization, enabling execution of arbitrary code via crafted input. The issue arises from the unsafe handling of patch content that is integrated into Git hooks, leading to command execution capability embedded in the repository management workflow.
This vulnerability is a SQL Injection flaw caused by improper sanitization of input parameters within the GeoTools Java library. Specifically, the PostGIS DataStore implementation's `jsonArrayContains` function constructs SQL queries by directly embedding the `<value>` parameter without escaping, affecting versions 30.5 and earlier up to 33.6 and 34.5. The root cause lies in unsafe query generation when handling String or JSON fields in PostGIS 12 or greater environments.
This vulnerability is a code injection flaw rooted in improper handling of user-supplied input within the SPIP content management system. Specifically, the analyse_resultat_skel function fails to sanitize the X-Spip-Filtre HTTP request header, allowing arbitrary code to be injected and executed. The flaw affects SPIP versions prior to 4.4.21 and involves the HTTP header processing mechanism.
This vulnerability is a remote code execution flaw caused by improper handling of PHP code blocks within SPIP versions prior to 4.4.20. The root cause lies in incorrect parsing and identification of '<?php' tags combined with var_export's faulty processing of strings containing the '<' character. This parsing error occurs in the code serialization component responsible for exporting PHP variables, leading to unsafe code injection opportunities.
This vulnerability is a deserialization flaw in Microsoft Entra ID, where untrusted serialized data is processed insecurely. The root cause lies in improper validation and handling of serialized objects during deserialization, allowing malicious input to be interpreted as executable code. The affected component is the deserialization mechanism within Microsoft Entra ID's authentication or identity management services.
This vulnerability is a code injection flaw classified under CWE-94, caused by improper handling of user-supplied scripts within the TrueConf Server isolated environment. The root cause lies in insufficient validation and sanitization of input scripts processed on port 4307/TCP, allowing crafted payloads to escape sandbox restrictions. The affected component is the script execution environment in TrueConf Server versions 5.3.x through 5.5.5 on Windows and Linux platforms.
This vulnerability is an authentication bypass flaw rooted in improper validation of user credentials within the NetScaler ADC and Gateway authentication modules. The issue arises from the failure to correctly verify authentication tokens or session parameters, allowing unauthorized access to protected components. The affected components include NetScaler ADC and NetScaler Gateway versions ranging from 13.1 through 63.21 and 14.1 through 73.32, impacting both FIPS and non-FIPS deployments.
This vulnerability is an SSRF (Server-Side Request Forgery) flaw rooted in improper validation of webhook URLs within the MLflow platform. Specifically, the _validate_webhook_url() function only validates the original URL without accounting for HTTP redirects. The mlflow/webhooks/delivery.py component follows redirects and re-resolves hostnames, enabling attackers to bypass URL validation and interact with unintended internal or cloud metadata endpoints.
This vulnerability is a command injection flaw rooted in improper sanitization of untrusted input within the SNMP notification processing component of Zimbra Collaboration Suite (ZCS). Specifically, when the optional zimbra-snmp package is installed and SNMP notifications are enabled, maliciously crafted SMTP requests can inject operating system commands. The flaw arises from inadequate input validation during the handling of SNMP notifications in affected ZCS versions prior to 10.1.20.
Artifactory does not properly constrain the pathname it derives when writing Docker layer data into the cache directory for remote repositories. Under specific remote-repository conditions the resolved path escapes the intended cache root, which is the classic path traversal pattern applied to a caching write rather than to a read.
The vulnerability in Adobe Commerce is an Incorrect Authorization flaw rooted in improper access control checks within the application. This issue arises from the failure to correctly enforce privilege restrictions on certain administrative functions, allowing unauthorized users to escalate privileges. The affected component is the authorization mechanism governing access to sensitive resources and administrative features in Adobe Commerce versions including 2.4.4 and its patches.
This vulnerability is a code injection flaw arising from improper control over code generation within Microsoft Office SharePoint Server 2016. The root cause lies in insufficient validation and sanitization of user-supplied input that is processed in SharePoint's code generation mechanisms. The affected component is the SharePoint Enterprise Server 2016 platform, specifically in its handling of input that influences dynamic code execution.
Metabase concatenates user-supplied input directly into SQL statements at the reset_password database endpoint, without parameterization. The endpoint is reachable before authentication, so the injection point sits on the unauthenticated attack surface of the analytics server. This is a textbook SQL injection: the query structure is built from data the caller controls.
This vulnerability is an authentication bypass issue rooted in improper state management within the Screen Sharing service of Apple macOS. The flaw allows network-based attackers to circumvent authentication controls by exploiting how session state is handled during the authentication process. The affected component is the Screen Sharing feature across multiple macOS versions, where authentication validation does not adequately verify credential legitimacy.
This vulnerability is an authentication bypass caused by improper validation of JSON Web Tokens (JWT) in the WSO2 Universal Gateway's JWT authentication mechanism. The root cause lies in the acceptance of JWT tokens signed with algorithms that are not explicitly configured or supported by the system. This flaw affects the JWT authentication component responsible for verifying token signatures before granting access.
This vulnerability is an authentication bypass stemming from an incomplete patch applied to N-able N-central versions through 2026.3.1. The root cause lies in improper validation of authentication tokens within the access control mechanism, specifically affecting the authentication workflow component. The flaw allows bypassing normal authentication checks due to insufficient verification logic in the session validation process.
This vulnerability is an authentication bypass in N-able N-central caused by improper validation of authentication mechanisms, allowing an attacker to circumvent normal authentication controls. The root cause lies in an alternate path or channel within the authentication process that fails to enforce required credentials. This flaw affects the authentication component of N-central versions through 2026.1, enabling unauthorized access through this bypass vector.
This vulnerability is a directory traversal flaw within the VMware vCenter Syslog server component of VMware Cloud Foundation. The root cause lies in insufficient validation of file path inputs, allowing crafted requests to access arbitrary filesystem locations. This improper sanitization enables manipulation of file paths processed by the Syslog server, exposing underlying system directories.
This vulnerability is an unsafe deserialization flaw (CWE-502) in the JetBrains TeamCity agent polling protocol. The root cause lies in improper validation and handling of serialized data received from unauthenticated remote sources during agent-server communication. The affected component is the TeamCity server's agent polling mechanism, which processes incoming serialized objects without adequate integrity or authenticity checks.