Critical CodeIgniter File Upload Flaw Found
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
28 results for “remote code execution”
A critical vulnerability in CodeIgniter 4 allows attackers to bypass file validation, potentially leading to remote code execution on affected servers.
An unauthenticated remote code execution vulnerability in Nuxt DevTools allows attackers to run arbitrary commands on developer machines via the HMR port.
A critical remote code execution vulnerability in Flowise allows low-privileged attackers to gain root access on vulnerable servers via CSV Agent code injection.
A critical remote code execution vulnerability in Flowise's CSVAgent allows attackers to bypass python code filters using pandas read_pickle deserialization.
A critical remote code execution vulnerability in MaxSite CMS allows unauthenticated attackers to inject malicious PHP code into configuration files.
An unauthenticated remote code execution vulnerability in Kotaemon allows attackers to run arbitrary system commands by exploiting insecure deserialization.
Puwell IP cameras running firmware versions 2.x through 4.x are vulnerable to unauthenticated remote code execution via a flaw in the DebugShell interface.
A critical template engine vulnerability in Adobe Campaign Classic allows for unauthenticated remote code execution with a maximum CVSS score of 10.
A critical remote code execution vulnerability in OpenEMR allows authenticated administrators to run arbitrary OS commands via the document category tree.
SecurityA critical flaw in the Active Storage framework allows for unauthorized file access and potential remote code execution.
A severe SQL injection flaw in NocoBase allows unauthenticated attackers to gain remote code execution via a simple registration and API request.
A critical vulnerability in Azure Cosmos DB allows unauthorized remote code execution, earning a maximum CVSS score of 10.
A critical vulnerability in SiYuan desktop allows attackers to achieve remote code execution through a malicious deep link, necessitating an immediate update.
Researchers used AI agents to uncover remote code execution vulnerabilities in Redis, prompting seven urgent security releases.
A critical vulnerability in Bing's image processing reveals the risks of treating image conversion tools as simple infrastructure.
A newly public exploit targeting GitLab reveals how silent patches for library bugs can leave critical vulnerabilities exposed.
A deserialization vulnerability in OpenAM's WebAuthn module allows remote code execution through an object filter depth bypass.
A critical remote code execution vulnerability in Velocity.js version 2.1.6 allows attackers to bypass previous security fixes and execute arbitrary code.
A newly disclosed heap-based buffer overflow in Microsoft Account creates a high-stakes path for unauthorized remote code execution.
A critical vulnerability identified as CVE-2026-54120 allows for remote code execution via improper input validation.
A critical remote code execution vulnerability identified in SolarWinds Serv-U requires domain administrator access to exploit.
WordPress Core is under active attack via an interpretation conflict vulnerability that allows for SQL injection and remote code execution.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
A critical heap buffer overflow in NGINX puts remote code execution within reach, bypassing common defensive assumptions.
A critical vulnerability identified as CVE-2023-49900 allows unauthenticated remote attackers to execute arbitrary code due to improper input sanitization.
Federal agencies must secure SharePoint servers against active exploitation of three critical remote code execution vulnerabilities.
Federal agencies face a tight three-day deadline to patch critical remote code execution vulnerabilities in popular Joomla extensions.