Paperclip Flaw Opens AI Agent Gateways
A critical authorization bypass in the Paperclip platform allowed attackers to execute arbitrary code with server-level permissions.
30 results for “code execution”
A critical authorization bypass in the Paperclip platform allowed attackers to execute arbitrary code with server-level permissions.
An unauthenticated remote code execution vulnerability in Nuxt DevTools allows attackers to run arbitrary commands on developer machines via the HMR port.
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
A critical remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject malicious PHP code into configuration files.
An unauthenticated remote code execution vulnerability in Kotaemon allows attackers to run arbitrary system commands by exploiting insecure deserialization.
Puwell IP cameras running firmware versions 2.x through 4.x are vulnerable to unauthenticated remote code execution via a flaw in the DebugShell interface.
A critical template engine vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution with a maximum CVSS score of 10.
A critical remote code execution vulnerability in OpenEMR allows authenticated administrators to run arbitrary OS commands via the document category tree.
SecurityA critical flaw in the Active Storage framework allows for unauthorized file access and potential remote code execution.
A severe authorization bypass in ArcadeDB allows unauthenticated users to execute arbitrary JavaScript, earning a critical 9.8 CVSS severity rating.
A severe SQL injection flaw in NocoBase allows unauthenticated attackers to gain remote code execution via a simple registration and API request.
A critical vulnerability in Azure Cosmos DB allows unauthorized remote code execution, earning a maximum CVSS score of 10.
A critical vulnerability in SiYuan desktop allows attackers to achieve remote code execution through a malicious deep link, necessitating an immediate update.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.
A critical vulnerability in Bing's image processing reveals the risks of treating image conversion tools as simple infrastructure.
A critical vulnerability in the Alibaba Fastjson library allows unauthorized code execution in specific Spring Boot configurations.
A newly public exploit targeting GitLab reveals how silent patches for library bugs can leave critical vulnerabilities exposed.
A deserialization vulnerability in OpenAM's WebAuthn module allows remote code execution through an object filter depth bypass.
A type confusion vulnerability in seroval.fromJSON() allows attackers to trigger unintended server-side code execution through malicious JSON payloads.
A critical remote code execution vulnerability in Velocity.js version 2.1.6 allows attackers to bypass previous security fixes and execute arbitrary code.
A newly disclosed heap-based buffer overflow in Microsoft Account creates a high-stakes path for unauthorized remote code execution.
A critical vulnerability identified as CVE-2026-54120 allows for remote code execution via improper input validation.
A critical vulnerability identified in SolarWinds Serv-U allows for unauthorized privilege escalation and potential root code execution.
A critical remote code execution vulnerability identified in SolarWinds Serv-U requires domain administrator access to exploit.
WordPress Core is under active attack via an interpretation conflict vulnerability that allows for SQL injection and remote code execution.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
A critical heap buffer overflow in NGINX puts remote code execution within reach, bypassing common defensive assumptions.
A critical vulnerability identified in SurrealDB's rquickjs component allows for potential memory access or code execution.