Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 400 threats

wordpresswoocommerceprivilege-escalationplugin-vulnerabilityunauthenticatedweb-application-security

The Custom User Registration Fields for WooCommerce WordPress plugin (up to v2.2.3) allows unauthenticated attackers to escalate privileges to Administrator by manipulating the checkout request. The vulnerability arises from unsanitized user-controlled role data being passed directly into WordPress's role assignment function, enabling full site takeover during account registration at checkout.

directory-traversalpath-traversalfile-managerrce-potentialweb-applicationagent-relevant

Cloud Commander before version 19.20.2 contains a critical directory traversal vulnerability in its REST file-operation and markdown endpoints, allowing unauthenticated or minimally privileged attackers to read, write, move, or copy files outside the configured root directory. With a CVSS score of 9.8, this flaw can lead to full system compromise, data exfiltration, or arbitrary file overwrite.

agent-relevantmcpargocdunauthenticated-accessgitopsprivilege-escalationapi-token-exposure

argocd-mcp version 0.8.0 exposes its HTTP transport on all network interfaces without enforcing authentication on incoming MCP sessions, even when an ARGOCD_API_TOKEN is configured. Any attacker with network access to the listener can invoke the full MCP tool surface, leveraging the operator's stored Argo CD token to create applications, trigger syncs, and modify GitOps resources without any credentials of their own.

ownCloudCISA-KEVCVE-2023-49105pre-authenticationwebdavchina-nexuscritical-infrastructurenuclear-sectordata-theft

A critical pre-authentication vulnerability in ownCloud (CVE-2023-49105, CVSS 9.8) was actively exploited by a suspected Chinese-speaking threat actor to breach a nuclear research institute in the Philippines and exfiltrate sensitive records. CISA has added the flaw to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and prompting mandated remediation for federal agencies.

wordpressplugin-vulnerabilityauthentication-bypassrceaccount-takeovercms-security

Five critical vulnerabilities have been disclosed across popular WordPress plugins and themes—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—that can lead to authentication bypass, account takeover, and remote code execution. The most severe flaw, CVE-2026-76581, carries a CVSS score of 9.8 and allows attackers to bypass authentication controls entirely. These issues pose significant risk to any organization running affected WordPress installations, as exploitation could lead to full site compromise.

icsscadaxxetlscertificate-validationlog4netiec-60870-5-104critical-infrastructure

ASE2000 V2 Communications Test Set versions 2.25 through 2.37 contain two vulnerabilities: an XML External Entity (XXE) flaw inherited from a bundled outdated Apache log4net library, and an improper TLS certificate validation flaw affecting IEC 60870-5-104 secure communications. Successful exploitation could allow attackers to read/write arbitrary local files, trigger outbound network requests, or perform man-in-the-middle attacks to intercept and modify protected substation/grid communications.

authentication-bypassjwtalgorithm-confusionapi-securityaccount-takeoverrce-adjacentagent-relevant

A critical authentication bypass exists in Omnivore's API where the Apple sign-in JWT verification logic trusts the attacker-controlled 'alg' header field, enabling a classic RS256-to-HS256 algorithm confusion attack. An attacker can forge valid authentication tokens for any Apple-linked account by signing them with Apple's public RSA key treated as an HMAC secret, resulting in full account takeover without valid credentials.

authentication-bypassbroken-access-controliotrest-apiunauthenticated-rce-riskagent-relevant

rust-iot-platform contains a critical authentication bypass vulnerability in which most REST API endpoints lack authentication checks in their handler code. Unauthenticated attackers can fully manage user accounts—creating, listing, retrieving, updating, and deleting them—leading to complete account and access control compromise.

shinobicctvsql-injectionhardcoded-credentialswebsocketunauthenticated-rcevideo-surveillance

Shinobi, an open-source video surveillance/NVR platform, ships with a hardcoded connection key in its child node service that allows unauthenticated attackers to authenticate via WebSocket handshake and execute arbitrary SQL queries. This grants full read/write access to user records and camera configuration, enabling account takeover and surveillance system compromise.

wordpressplugin-vulnerabilityrceunauthenticatedfile-uploadweb-application-security

The Sigma Forms Pro WordPress plugin (versions up to 1.4.5) contains a critical vulnerability that allows unauthenticated attackers to achieve remote code execution by exploiting improper capability handling and MIME type validation during form submissions. Several default plugin templates ship with unrestricted file upload fields, making exploitation immediately feasible on default installs without any attacker reconnaissance or configuration changes.

sql-injectionibm-concertremote-exploitdata-breachcve-2026-3627agent-relevant

IBM Concert versions 1.0.0 through 2.3.1 contain a critical SQL injection vulnerability that allows a remote, unauthenticated attacker to manipulate backend database queries. Exploitation could result in unauthorized viewing, modification, or deletion of sensitive application data. With a CVSS score of 9.1, this vulnerability poses significant risk to organizations running unpatched instances.

papercutrceauthentication-bypassunauthenticated-rceprint-managementexploit-chainpatch-now

Attackers are actively chaining two vulnerabilities in PaperCut NG and MF print management software to achieve unauthenticated remote code execution. PaperCut has released an emergency patch with additional hardening after confirming exploitation in the wild. Organizations running unpatched PaperCut servers face full server compromise with no authentication required.

blockchaincosmosevmdeficrypto-theftsmart-contract-vulnerabilitysupply-chain

A critical, unpatched balance-handling flaw in the shared Cosmos EVM module was actively exploited between August 20-25, 2026, to drain funds from at least six blockchains built on the Cosmos ecosystem. Cosmos Labs was reportedly aware that all chains running the vulnerable module were exposed prior to exploitation, raising concerns about disclosure timing and coordinated patching failures.

wordpressplugin-vulnerabilityrcephp-object-injectionunauthenticatedweb-application-securitycms

A maximum-severity vulnerability in the GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on the hosting server. Given GiveWP's widespread use on nonprofit and fundraising websites, this flaw exposes a large number of internet-facing servers to full compromise without requiring any credentials.

data-breachhealthcareextortionshinyhuntersthird-party-riskpatient-dataPII exposure

McKesson, a major healthcare and pharmaceutical distribution company, disclosed a breach involving unauthorized access to third-party applications, with the ShinyHunters extortion group claiming theft of 284 million patient records. The incident highlights ongoing risks from third-party application compromise and large-scale extortion campaigns targeting healthcare data supply chains.

ICSIoTcellular-gatewayauthentication-bypassCSRFcleartext-credentialsweak-cryptoMQTTunpatchedno-vendor-fix

The Ebyte NA111-M cellular/MQTT gateway (firmware 9013-2-17) contains 13 vulnerabilities, several rated critical (CVSS 9.8), including missing authentication, client-side authentication bypass, weak cryptographic hashing, and cleartext transmission/storage of credentials including MQTT traffic. Combined, these flaws allow unauthenticated remote attackers to fully compromise the device, gaining administrative control, intercepting or replaying credentials, and disrupting availability. Ebyte has not delivered a patch despite CISA coordination attempts, leaving deployed units permanently exposed absent compensating network controls.

IBM-iprivilege-escalationunauthenticatedsession-hijackingGUI-vulnerability

A critical unauthenticated privilege escalation vulnerability exists in IBM Administration Runtime Expert (ARE) for i, allowing remote attackers to execute actions under another authenticated user's session. This flaw, rated 9.9 CVSS, poses severe risk to IBM i systems used for enterprise administration and automation, potentially enabling full system compromise without prior credentials.

kubernetesargo-rolloutsunauthenticated-accessprivilege-escalationci-cdgitopsagent-relevant

Argo Rollouts dashboard versions through 1.10.0 bind to all network interfaces and expose privileged, mutating rollout operations without any authentication, authorization, or CSRF protection. An attacker with network access to the dashboard port can hijack deployment lifecycle controls across all namespaces the operator's kubeconfig can reach, enabling denial of service, unauthorized rollbacks, or malicious image promotion.

redpandaadmin-apiunauthenticated-accessmisconfigurationbroker-compromiseagent-relevantdata-streamingrag-pipeline

Redpanda versions through 26.2.2 bind the Admin API to all network interfaces (0.0.0.0:9644) with authentication disabled by default, allowing any network-reachable attacker to be treated as a superuser. This enables unauthenticated creation and deletion of broker accounts, cluster configuration tampering, and disruption of partition replication, posing a critical risk to any exposed deployment.

mcpagent-relevantrceunauthenticated-accessai-agent-infrastructuresupply-chaindefault-configuration

The mcp-http-server package used by UI-TARS-desktop's MCP servers defaulted to binding on all network interfaces ('::') with no mandatory authentication middleware, exposing the @agent-infra/mcp-server-commands and @agent-infra/mcp-server-filesystem tools to unauthenticated network access. Any remote client able to reach the exposed port could invoke the run_command tool to execute arbitrary OS commands, or read/write arbitrary files, as the user running the MCP server. The flaw was fixed by changing the default bind address to 127.0.0.1, but the package version number was not incremented, making patch detection reliant on commit history rather than semantic versioning.