An unrestricted file upload flaw in elFinder lets an attacker slip PHP files past MIME filtering during ZIP extraction, achieving remote code execution on the underlying web server.
A path traversal flaw in Next.js lets an unauthenticated attacker redirect a cache write outside its directory on Windows-hosted servers, reaching remote code execution on the host.
A stored cross-site scripting flaw in Atlassian Confluence Data Center and Server lets an unauthenticated attacker run script in a privileged user’s browser and act on their behalf.
A flaw in the core of Oracle WebLogic Server lets a low-privileged attacker with T3 or IIOP network access take over the server and reach adjacent systems.
An unauthenticated SQL injection in GeoServer’s jsonArrayContains filter function lets attackers inject arbitrary SQL through public WMS and WFS endpoints, reaching remote code execution on privileged database hosts.
A code injection flaw in GitLab’s GraphQL directive handling lets unauthenticated attackers modify or delete public projects and user data on self-managed instances.
An improper authentication flaw in FortiWeb’s remote RADIUS admin group handling lets an unauthenticated attacker log in to the appliance’s management interface and take administrative control.
An incorrect authorization flaw in Adobe Commerce and Magento Open Source lets an unauthenticated attacker switch a customer session to another account, exposing the victim’s personal data.
A type confusion flaw in n8n’s Send Email node lets crafted workflow input reach the mail library as a file path or URL, exposing local files and enabling SSRF.
A flaw in the Remote Access SSL VPN service of Cisco ASA and FTD software lets an unauthenticated attacker reload the device, knocking firewalls and VPN gateways offline.