Vulnerabilities
381,276
with PoCs
37,250
CISA KEV
1,665
Ransomware
606
with Nuclei
4,342

Showing 25 vulnerabilities on this page

Signals CISA KEV Ransomware Nuclei
Vulnerability search results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

CWE-201Aug 12, 20261 related artifact
CVSS7.5v3.1EPSS1.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

YesWiki: Unauthenticated SQL Injection

YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read the full database, including `yeswiki_users.password` hashes. Version 4.6.4 fixes the issue.

CWE-89Aug 11, 20261 related artifact
CVSS9.8v3.1EPSS1.65%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Metabase SQL injection via password reset endpoint

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

CWE-89Aug 10, 20261 related artifact
CVSS10.0v4.0EPSS10.4%PoCs2SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell)

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim. This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and

CWE-79Aug 7, 20261 related artifact
CVSS8.9v4.0EPSS0.894%PoCs23SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WGDashboard Remote Code Execution vulnerability

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

CWE-78Aug 6, 20261 related artifact
CVSS9.8v3.1EPSS3.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

OpenChamber 1.11.7 Path Traversal File Read via allowOutsideWorkspace Parameter

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPathWithinRoot guard to read sensitive files such as the JWT signing secret, SSH private keys, API crede

CWE-22Aug 6, 20261 related artifact
CVSS9.3v4.0EPSS0.653%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

audiobookshelf - %2F Encoding Discrepancy Bypasses Cover/Image Auth Exemption Regex, Enabling Unauthenticated Path Traversal

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check.

CWE-22Aug 5, 20261 related artifact
CVSS7.5v3.1EPSS1.76%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

TranslatePress <= 3.2.5 - Reflected Cross-Site Scripting

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 3.2.5. This is due to the translate_page() function unconditionally replacing the plugin's internal #!trpst# and #!trpen# marker tokens with literal angle brackets across the entire HTML page output after WordPress has already sanitized and escaped user input — allowing the attacker to bypass WordPress's normal HTML escapin

CWE-79Aug 5, 20261 related artifact
CVSS6.1v3.1EPSS0.804%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Flowise RCE via TypeORM DataSource

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts, packages/components/nodes/recordmanager/PostgresRecordManager/PostgresRecordManager.ts, packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts,

CWE-94Aug 4, 20261 related artifact
CVSS9.0v4.0EPSS0.792%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected /h2-console endpoint, authenticate with default credentials, and leverage the H2 CREATE ALIAS Runtime.exec() technique to execute arbitrary commands, resulting in root-level code execution when running the stock Docker image.

CWE-1188CWE-306Jul 30, 20261 related artifact
CVSS9.3v4.0EPSS1.1%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability

Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions.

CWE-918Jul 27, 20261 related artifact
CVSS7.2v3.1EPSS0.341%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability in the terminal action handler allows any authenticated user to execute arbitrary OS commands by injecting shell metacharacters into the 'dir' POST parameter, completely bypassing the TERMINAL_COMMANDS whitelist and achieving full Remote Code Execution with web server privileges. This issue has been patched in version 2.0.4.

CWE-78Jul 27, 20261 related artifact
CVSS9.9v3.1EPSS5.16%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

CWE-502Jul 27, 20261 related artifact
CVSS9.8v3.1EPSS10.7%PoCs4SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController

Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive files such as environment configuration files containing credentials and system files.

CWE-22Jul 23, 20261 related artifact
CVSS8.7v4.0EPSS2.46%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the `/runners/load-reader` endpoint. The `require = null` mitigation is trivially bypassed via dynamic `import()`. Version 7.1.9 contains a patch.

CWE-77CWE-78Jul 23, 20261 related artifact
CVSS9.4v4.0EPSS1.71%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

DbGate: Unauthenticated Remote Code Execution via JSON Script Runner

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated directly into dynamically generated JavaScript source code via string concatenation. The generated code is then executed in a forked Node.js child process. Version 7.1.9 contains a patch.

CWE-1188CWE-20CWE-94Jul 23, 20261 related artifact
CVSS10.0v3.1EPSS4.34%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Authentication Bypass in the SmartConsole Login Process Using an Application Token

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this

CWE-287Jul 22, 20261 related artifact
CVSS9.3v4.0EPSS73.3%PoCs2SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis

The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers to make the site issue HTTP requests to arbitrary hosts (Server-Side Request Forgery).

CWE-918Jul 20, 20261 related artifact
CVSS9.1v3.1EPSS0.912%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

CWE-436Jul 17, 20261 related artifact
CVSS9.8v3.1EPSS95.6%PoCs80SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

CWE-94Jul 17, 20261 related artifact
CVSS9.8v3.1EPSS17.4%PoCs7SignalsListed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

CWE-79Jul 17, 20261 related artifact
CVSS6.1v3.1EPSS0.511%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through src/app/api/cli-tools/cowork-settings/route.js and command execution through the MCP bridge. This vulnerability is fixed in 0.4.37.

CWE-306CWE-78Jul 15, 20261 related artifact
CVSS10.0v3.1EPSS2.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

LiteLLM 1.18.10 - Command Injection

LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.

CWE-77Jul 15, 20261 related artifact
CVSS9.8v3.1EPSS5.95%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CWE-918Jul 14, 20261 related artifact
CVSS10.0v3.1EPSS74.2%PoCs7SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover

### Summary The official Kimai Docker image ships with `APP_SECRET=change_this_to_something_unique` as the default environment variable. The Docker entrypoint does not override or validate this value. Any Kimai instance deployed using the Docker image without explicitly setting `APP_SECRET` runs with a publicly-known Symfony `kernel.secret`, enabling an unauthenticated attacker to forge HMAC-signed cookies and login links to take over any account including super_admin. ### Details `Dockerfile

CWE-1188Jul 14, 20261 related artifact
CVSS-v4.0EPSS-PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX