Critical Command Injection Hits GL.iNet MT3000
A critical remote command injection vulnerability in GL.iNet GL-MT3000 routers allows unauthenticated attackers to execute arbitrary code on affected devices.
30 results for “critical vulnerability”
A critical remote command injection vulnerability in GL.iNet GL-MT3000 routers allows unauthenticated attackers to execute arbitrary code on affected devices.
A critical vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without requiring user interaction.
A critical vulnerability in the Single Sign On For TNG WordPress plugin allows unauthenticated attackers to reset any user password and take over sites.
A critical vulnerability in Juggle 1.6.0 allows unauthenticated attackers to execute arbitrary OS commands via the H2 database console.
A critical vulnerability in the Flyto-Core verification service allows unauthenticated attackers to steal internal secrets and perform SSRF attacks.
A critical vulnerability in the vault-secrets-webhook allows unauthorized outbound requests and potential theft of cluster-wide service account tokens.
A critical vulnerability in Rich Source's DMS+ allows unauthenticated remote attackers to gain full control over affected devices using a fixed API key.
A critical vulnerability in Azure Cosmos DB allows unauthorized remote code execution, earning a maximum CVSS score of 10.
A critical vulnerability in IBM HMC systems allows unauthenticated attackers to execute arbitrary commands with elevated privileges.
A critical vulnerability in the Ruflo platform allows unauthenticated remote access to enterprise AI agent infrastructure.
A critical vulnerability allows unauthenticated attackers to execute arbitrary commands as root, earning a maximum CVSS score of 9.8.
A critical vulnerability in ModbusServer allows unauthenticated remote attackers to inject malicious input, threatening system integrity and availability.
A critical vulnerability in prebid-server allows attackers to manipulate outbound requests, risking unauthorized data exposure.
A critical vulnerability in IBM Aspera Faspex 5 allows remote authenticated attackers to execute arbitrary code via unquoted shell interpolation.
A critical vulnerability in the PROCON-WEB SCADA GetGridData endpoint allows unauthenticated attackers to execute arbitrary SQL commands.
A critical vulnerability in Apache Thrift c_glib bindings allows for potential memory exposure and system instability, requiring an immediate update.
A critical vulnerability in SiYuan desktop allows attackers to achieve remote code execution through a malicious deep link, necessitating an immediate update.
A critical vulnerability in Anthropic's Claude Cowork allows AI agents to escape their Linux virtual environment and access host macOS data.
A critical vulnerability in the @better-auth/scim plugin allows authenticated users to hijack accounts via provider ID collisions and bypass security controls.
A critical vulnerability in Bing's image processing reveals the risks of treating image conversion tools as simple infrastructure.
A critical vulnerability in Check Point's management software allows attackers to bypass authentication and control network policy.
A critical vulnerability in Auth.js and NextAuth allows attackers to intercept magic-link sign-in flows by exploiting improper Unicode normalization.
A critical vulnerability in the Alibaba Fastjson library allows unauthorized code execution in specific Spring Boot configurations.
A critical vulnerability in OpenDJ allows unauthenticated attackers to perform SSRF, read local files, and trigger memory-exhaustion denial-of-service attacks.
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
A critical vulnerability in Budibase allows unauthenticated attackers to steal stored REST datasource credentials via a cross-origin request leak.
A critical vulnerability in Microsoft Kiota allows attackers to execute arbitrary code via malicious OpenAPI descriptions processed by the tool.
A newly identified critical vulnerability in Azure App Service permits unauthorized network-based privilege escalation.
A critical vulnerability identified in Microsoft Exchange Online creates a significant risk of unauthorized network tampering.
A critical vulnerability identified as CVE-2026-54120 allows for remote code execution via improper input validation.