Threat Library
Agent-to-agent threats first — conventional coverage one click away.
Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10
Showing 20 of 408 threats
A critical unauthenticated remote code execution vulnerability exists in Edimax EW-7478APC routers running firmware 1.04, caused by a stack-based buffer overflow in the formWanTcpipSetup CGI handler. Public exploit code is available and the vendor has not responded to disclosure, meaning no patch is expected. Organizations using this device on network edges face significant risk of full device compromise and pivoting into internal networks.
The Frontend Admin by DynamiApps WordPress plugin (versions up to 3.29.9) contains a critical privilege escalation vulnerability caused by a flawed authorization check that can be bypassed with a non-numeric user ID value. Attackers, in some configurations even unauthenticated, can exploit this to gain administrator access by hijacking the default admin account's password or email. Given the 9.8 CVSS score and low exploitation complexity, this vulnerability poses a severe risk to any WordPress site running the affected plugin.
The ProSolution WP Client WordPress plugin (versions up to 2.0.10) contains a critical unauthenticated arbitrary file upload vulnerability that allows remote attackers to achieve remote code execution. A publicly exposed nonce combined with insufficient filename validation lets attackers bypass access controls and upload executable files directly to the server.
A critical improper authentication vulnerability has been identified in the httpd component of Tenda AC10 routers running firmware 16.03.10.09_multi_TDE01, specifically within the R7WebsSecurityHandler function. The flaw allows a remote, unauthenticated attacker to bypass authentication controls, and a public exploit is already available, significantly raising the likelihood of active exploitation.
CVE-2025-62593 is a code injection vulnerability in Ray-Project Ray, a widely used distributed computing framework for scaling AI/ML and Python workloads, that can lead to remote code execution. The flaw is exploitable via Firefox and Safari when developers interact with Ray's tooling, and it has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild.
SiYuan, an open-source Electron-based note-taking and knowledge management application, fails to sanitize annotation fields written via the setFileAnnotation endpoint prior to v3.7.4. This allows an attacker to embed malicious markup that executes as script with full Node.js privileges when a victim opens an annotated PDF, enabling complete host compromise.
The Link Library plugin for WordPress (versions up to 7.9.4) contains an arbitrary file deletion vulnerability caused by insufficient path validation in the ll_delete_link_fields function. When the 'Delete local file on link deletion' option is enabled, unauthenticated attackers can submit malicious links that, once deleted by an administrator during routine moderation, trigger deletion of critical files such as wp-config.php, potentially leading to full remote code execution.
The Pods – Custom Content Types and Fields WordPress plugin (versions up to 3.3.9) contains a critical authorization bypass flaw that allows unauthenticated attackers to escalate privileges to Administrator or reset any user's password, including the site owner's. This enables complete site takeover and has been assigned a CVSS score of 9.8.
The TrueBooker WordPress plugin (versions up to 1.2.6) contains a critical account takeover vulnerability due to an insecure AJAX handler that allows unauthenticated attackers to change any user's email address, including administrators. Attackers can chain this with WordPress's native password reset flow to fully hijack accounts, including full site administrator access.
The User Profile Builder plugin for WordPress (versions up to 3.16.4) contains a critical authentication bypass vulnerability caused by improper error handling during user registration. An unauthenticated attacker can exploit a type confusion flaw to obtain an autologin nonce bound to user ID 1, effectively logging in as the site's Administrator and achieving full site takeover.
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched only three days prior, is already being actively exploited in the wild according to threat intelligence firm Defused. Organizations running unpatched instances face immediate risk of full system compromise, making rapid patching or mitigation critical.
The User Session Synchronizer plugin for WordPress (versions up to 1.4.0) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to impersonate any user, including administrators. The flaw stems from unvalidated request parameters and a cryptographic fallback that renders the encryption predictable when an unregistered session key is referenced. Full site takeover is possible with no prior knowledge of secrets, making this an urgent patch priority for any WordPress site running the plugin.
The 6Storage Rentals WordPress plugin (versions up to 2.27.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to log in as any existing WordPress user, including administrators, simply by supplying that user's email address. This flaw stems from an insecure AJAX handler exposed to unauthenticated users that lacks nonce, capability, or ownership checks before establishing a full authenticated session.
The RapiSafe – Secure Multi File Upload plugin for Contact Form 7 (versions up to 1.0.4) contains an unauthenticated arbitrary file deletion vulnerability in its AJAX upload removal handler. Attackers can exploit exposed nonces to delete critical files such as wp-config.php, potentially triggering a reinstallation flow that leads to full remote code execution and site takeover. Given the plugin's popularity and the ease of exploitation (no authentication required), this poses a severe risk to any WordPress site running the affected component.
A critical vulnerability in IBM Db2 Mirror for i allows a remote, likely unauthenticated attacker to execute arbitrary CL (Control Language) commands due to improper input sanitization. With a CVSS score of 9.9, successful exploitation could lead to full compromise of the affected IBM i system.
A critical vulnerability in IBM Db2 Mirror for i (versions 7.4, 7.5, 7.6) allows remote attackers to execute arbitrary code by exploiting external control of file name or path. With a CVSS score of 9.8, this flaw poses severe risk to organizations running IBM i systems for high-availability database replication.
SAP has patched a maximum-severity (CVSS 10.0) vulnerability in Commerce Cloud's Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. Given the flaw requires no authentication and results in full code execution, organizations running affected SAP Commerce Cloud deployments should prioritize immediate patching.
Two malicious versions of the popular LiteLLM package were published to PyPI in March and remained live for roughly 40 minutes, long enough to be pulled by automated build pipelines and developers. The packages contained credential-harvesting code that exfiltrated cloud keys, SSH keys, Kubernetes tokens, and database passwords, with CloudSEK estimating exposure impacting over 2,100 organizations based on a dataset of ~434,000 captured files.
Threat actors are actively exploiting a critical directory-traversal vulnerability (CVE-2026-59310, CVSS 9.8) in Broadcom VMware vCenter to achieve remote code execution and establish persistent access. The flaw affects any attacker with network access to the vCenter management interface, making unpatched instances high-value targets for post-exploitation activity including lateral movement and infrastructure takeover.
Siemens Siveillance Video Management Servers (based on Milestone XProtect) contain a critical OS command injection vulnerability in the Management Server API that allows users with edit permissions to execute arbitrary code in the context of the Management Server service. Siemens has released patched versions for the affected V2023 R3, V2024 R1, and V2025 product lines and urges immediate updates.