A flaw in the Core component of Oracle WebLogic Server lets an unauthenticated attacker with network access over T3 or IIOP take full control of the server.
An SQL injection flaw in the email parsing logic of Cisco AsyncOS lets an unauthenticated attacker send a crafted message and execute commands as root on the appliance.
An unauthenticated PHP object injection flaw in The Events Calendar plugin for WordPress lets attackers execute code on the server through comments submitted on event pages.
A memory corruption flaw in SAP’s Extended Passport processing lets an unauthenticated attacker execute operating system commands as the SAP system account, giving full control of the underlying host.
An unauthenticated file read flaw in MikroTik RouterOS WebFig lets a remote attacker traverse out of the web namespace and read root-owned configuration files, including stored credentials.
An unrestricted file upload flaw in elFinder lets an attacker slip PHP files past MIME filtering during ZIP extraction, achieving remote code execution on the underlying web server.
A path traversal flaw in Next.js lets an unauthenticated attacker redirect a cache write outside its directory on Windows-hosted servers, reaching remote code execution on the host.
A stored cross-site scripting flaw in Atlassian Confluence Data Center and Server lets an unauthenticated attacker run script in a privileged user’s browser and act on their behalf.
A flaw in the core of Oracle WebLogic Server lets a low-privileged attacker with T3 or IIOP network access take over the server and reach adjacent systems.
An unauthenticated SQL injection in GeoServer’s jsonArrayContains filter function lets attackers inject arbitrary SQL through public WMS and WFS endpoints, reaching remote code execution on privileged database hosts.