A blind SQL injection in Control Web Panel’s userRes parameter lets attackers with a guessable username gain MySQL root access, enabling full server takeover via a planted PHP webshell.
Two pre-authentication vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access let attackers bypass authentication entirely and gain unauthorized, potentially privileged, access to affected appliances.
Two Gitea vulnerabilities, a Docker default that lets any IP impersonate a user and a container registry flaw exposing private images, leave self-hosted instances open to unauthenticated attackers.
A missing authentication check in Apache Tomcat lets attackers bypass GSSAPI-bound directory logins, gaining unauthorized access to any application behind that Realm.
A code injection flaw in n8n’s expression evaluation lets any authenticated user with workflow edit rights run arbitrary system commands on the host, enabling full server compromise.
A memory-exhaustion flaw in Apache HTTP Server’s mod_http2 lets an unauthenticated attacker crash HTTP/2 web servers within seconds using a single crafted connection.
A route-rule middleware bypass in Nuxt lets an unauthenticated attacker vary request path casing to slip past path-level controls, reaching routes that routeRules was assumed to protect.
A path traversal flaw in Ubiquiti’s UniFi OS lets an unauthenticated attacker on the network read arbitrary files from affected gateways and controllers, exposing configuration files and sensitive data.
A hardcoded credentials flaw in Apache Solr’s Basic Authentication setup tool silently installs undocumented admin accounts with default passwords, giving remote attackers full control of affected SolrCloud clusters.
IBM has disclosed three critical flaws in WebSphere Application Server 8.5 and 9.0, including identity spoofing and two remote code execution paths that let unauthenticated attackers impersonate users or run code.