Click2Shell Turns Admin Clicks Into Theme Installs
A new WordPress core flaw lets a crafted link silently install a theme, and researchers chained it to full code execution.
30 results for “code execution”
A new WordPress core flaw lets a crafted link silently install a theme, and researchers chained it to full code execution.
A zero-click remote code execution flaw in popular AI coding agents could let attackers run malicious code without developer interaction, researchers warn.
A heap overflow in Unbound's DNSSEC validator lets attackers who control a malicious DNS zone trigger remote code execution on vulnerable resolvers.
Attackers are exploiting a critical WooCommerce Wholesale Lead Capture vulnerability to upload PHP web shells and achieve remote code execution.
Cisco warns CVE-2026-76461, a CVSS 9.8 flaw in Secure Email Gateway, is being exploited to run commands as root, with a federal patch deadline of September 17.
Sysdig says a hand-built toolkit let a human operator exploit a Marimo flaw in eight seconds, without any sign of LLM use.
Two 9.8-rated certificate flaws in Check Point gateways carry fixes that some customers say they cannot access.
Google's September 2026 Android updates fix 180 vulnerabilities, including 26 critical flaws, after two consecutive bulletins with no security fixes.
Ivanti addresses critical and high-severity vulnerabilities across Neurons for ITSM, Sentry, and EPMM, urging immediate updates.
Broadcom patched one critical and one high-severity VMware Workstation and Fusion vulnerability, both enabling host code execution.
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.
Forescout researchers used AI to port RCE exploits to PLCs, but high cost and effort still deter criminals.
UNISOC modem flaw lets attackers escalate code execution to kernel level via video calls.
SAP ships urgent patches for Commerce Cloud and other critical flaws rated up to 10.0.
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
A critical authorization bypass in the Paperclip platform allowed attackers to execute arbitrary code with server-level permissions.
An unauthenticated remote code execution vulnerability in Nuxt DevTools allows attackers to run arbitrary commands on developer machines via the HMR port.
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
A critical remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject malicious PHP code into configuration files.
An unauthenticated remote code execution vulnerability in Kotaemon allows attackers to run arbitrary system commands by exploiting insecure deserialization.
Puwell IP cameras running firmware versions 2.x through 4.x are vulnerable to unauthenticated remote code execution via a flaw in the DebugShell interface.
A critical template engine vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution with a maximum CVSS score of 10.
A critical remote code execution vulnerability in OpenEMR allows authenticated administrators to run arbitrary OS commands via the document category tree.
SecurityA critical flaw in the Active Storage framework allows for unauthorized file access and potential remote code execution.
A severe authorization bypass in ArcadeDB allows unauthenticated users to execute arbitrary JavaScript, earning a critical 9.8 CVSS severity rating.
A severe SQL injection flaw in NocoBase allows unauthenticated attackers to gain remote code execution via a simple registration and API request.
A critical vulnerability in Azure Cosmos DB allows unauthorized remote code execution, earning a maximum CVSS score of 10.
A critical vulnerability in SiYuan desktop allows attackers to achieve remote code execution through a malicious deep link, necessitating an immediate update.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.