Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 400 threats

nextjsrceunauthenticatedpath-traversalimage-parsingvercelweb-frameworkagent-relevant

Vercel patched two critical unauthenticated remote code execution vulnerabilities in the Next.js framework: one triggered via specially crafted AVIF image files, and another via a path traversal flaw affecting Windows-hosted servers. Both flaws could allow attackers to fully compromise affected servers without authentication, posing a significant risk to any organization running unpatched Next.js deployments.

ICSot-securitycommand-injectionauthentication-bypassremote-access-devicecisa-advisoryunauthenticated-access

The Xiiaozet LK100W device, versions prior to 2.1.240, contains three critical vulnerabilities including OS command injection, missing authentication for a critical function, and an authentication bypass that together could allow a remote attacker to fully compromise the device. Two of the three flaws are rated CVSS v3.1 9.8 (Critical) and require no authentication or user interaction to exploit remotely. CISA has published an advisory recommending immediate firmware update to v2.1.240.

input-validationansi-escape-injectionkey-verification-bypassterminal-spoofingpgpidentity-verificationsupply-chain-riskagent-relevant

A critical flaw in openssl_encrypt (before 1.4.9) allows attackers to inject unsanitized ANSI escape sequences into the email field of identity documents, enabling forgery of the fingerprint verification line shown to users. This undermines the out-of-band verification mechanism designed to prevent key substitution/MITM attacks, allowing attackers to trick users into trusting an attacker-controlled key.

cvekey-substitutioncryptographic-flawidentity-verificationfingerprint-bypasssupply-chainagent-relevant

openssl_encrypt versions prior to 1.4.9 fail to properly re-derive and validate cryptographic fingerprints when loading identities from identity.json, allowing attackers to silently substitute public keys while preserving the claimed fingerprint. This enables man-in-the-middle style attacks where encrypted data is protected with attacker-controlled keys and forged signatures pass verification, undermining the core trust model of the identity store.

ILIASPHP-object-injectionunauthenticated-RCEdeserializationLMSShibbolethSSOweb-shellpre-auth

A critical unauthenticated remote code execution vulnerability affects the ILIAS learning management system, stemming from insecure PHP deserialization of session data via the Shibboleth logout endpoint. An attacker can seed a malicious serialized object into any live session via the unauthenticated LTI entry point, then trigger its instantiation and destructor via the logout-notification handler to write attacker-controlled content to an arbitrary path under the web root, achieving code execution as the web server user.

grav-cmsapi-key-abuseprivilege-escalationbroken-access-controlcve-2026-80203agent-relevant

The getgrav/grav-plugin-api plugin before version 1.0.18 fails to properly validate API key scope in a critical authorization function, allowing an API key with limited privileges to perform super-admin actions if it belongs to a super-admin account. This flaw enables attackers holding a low-scoped but valid API key to disable 2FA, hijack or delete API keys, and manipulate super-admin accounts, effectively granting full administrative takeover.

path-traversalrceunauthenticatedfile-uploaddbgptagent-relevantllm-frameworkai-agent-infrastructure

DB-GPT, an open-source LLM/AI agent development framework, contains an unauthenticated path traversal vulnerability in its skill upload endpoint that allows arbitrary file writes anywhere the server process can write. Combined with a broken authentication dependency that grants admin privileges by default, attackers can plant or overwrite Python modules to achieve full remote code execution with no credentials required.

linuxkernelprivilege-escalationipv6cisa-kevrceagent-relevant

A privilege escalation vulnerability in the Linux Kernel's IPv6 networking subsystem has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. The flaw affects multiple Linux distributions including SUSE and Red Hat, with a compressed remediation window of only three days from disclosure to due date, signaling high urgency and severity.

ownCloudauthentication-bypasswebdavCISA-KEVfile-storageagent-relevant

CVE-2023-49105 is an improper authentication vulnerability in ownCloud that allows attackers to access, modify, or delete arbitrary files without valid credentials when a victim's username is known and no signing-key is configured. The flaw has been added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation in the wild. Organizations using ownCloud for file storage or as a backend for automated data pipelines face high risk of unauthorized data access and manipulation.

wordpresscmsrceunauthenticatedplugin-vulnerabilityweb-security

A critical vulnerability chain in the widely used Avada WordPress theme allows unauthenticated attackers to achieve remote code execution on affected servers with no user interaction required. Given Avada's large install base as a premium theme, this represents a significant risk of mass exploitation against websites and hosting infrastructure.

totolinkroutercgibuffer-overflowrceiotunauthenticatedpublic-exploit

A critical, publicly disclosed stack-based buffer overflow exists in TOTOLINK N600R routers (firmware 4.3.0cu.7647_B20210106) via the Hostname parameter in the setSystemConfig function of cstecgi.cgi. The flaw is remotely exploitable without authentication and carries a maximum CVSS score of 10.0, allowing attackers to potentially achieve remote code execution on affected devices.

authentication-bypassidentity-spoofingdata-exposurecloud-storagealluxioagent-relevantrag-pipelinedata-lake

A critical authentication bypass exists in Alluxio's S3 REST proxy, where default configurations fail to validate AWS Signature Version 4 signatures. This allows unauthenticated attackers to extract usernames from unsigned Authorization headers and impersonate any user or service account, enabling unauthorized read, write, and delete access to arbitrary stored data.

adobecampaign-classicos-command-injectionrceunauthenticatedcritical-vulnerability

A critical OS command injection vulnerability in Adobe Campaign Classic (CVE-2026-76197) allows attackers to achieve arbitrary code execution without requiring user interaction, and carries a maximum CVSS score of 10.0. Organizations running ACC for marketing automation should treat this as an urgent patching priority given the scope change and lack of required authentication or interaction.

adobeos-command-injectionrcecampaign-classicunauthenticatedcritical-vulnerability

A critical OS Command Injection vulnerability in Adobe Campaign Classic (ACC) allows an attacker to achieve arbitrary code execution in the context of the current user without requiring any user interaction. With a maximum CVSS score of 10.0 and a changed scope, successful exploitation could allow attackers to pivot beyond the vulnerable component into connected infrastructure.

deserializationremote-code-executiondotnetlegacy-softwareend-of-lifeCISA-KEV

Ajax.NET Professional (AjaxPro) is affected by a deserialization vulnerability (CVE-2021-23758) that allows remote code execution through instantiation of arbitrary .NET classes. The affected product is end-of-life, meaning no vendor patch is available, and CISA has added it to the Known Exploited Vulnerabilities catalog due to active exploitation.

ICSIoTgatewayauthentication-bypassCSRFcleartext-credentialsMQTTunpatchedcritical-infrastructure

The Ebyte NE2-D11 gateway (Firmware FW-9167-0-11) contains eleven distinct vulnerabilities including missing authentication, client-side authentication bypass, cleartext credential and MQTT traffic transmission, CSRF, clickjacking, and missing authorization checks. Several flaws are rated CVSS 9.8, allowing an unauthenticated remote attacker to fully compromise device confidentiality, integrity, and availability. Ebyte has not released a patch or responded to CISA coordination requests, leaving affected deployments in critical manufacturing and energy sectors exposed with no vendor remediation timeline.

nokogirilibxml2use-after-freerubysupply-chainxmldtdxincludeagent-relevant

Nokogiri versions before 1.15.6 and 1.16.x before 1.16.2 bundle a vulnerable version of libxml2 affected by CVE-2024-25062, a use-after-free in the xmlTextReader module. Applications using Nokogiri::XML::Reader with DTD validation and XInclude expansion enabled on untrusted XML input can trigger memory corruption, potentially leading to crashes or code execution.

nokogirirubylibxml2libxsltxml-parsingdenial-of-servicememory-disclosurercesupply-chainagent-relevant

Nokogiri versions before 1.13.2 for CRuby ship vulnerable vendored copies of libxml2 2.9.12 and libxslt 1.1.34, exposing applications to denial-of-service, memory disclosure, and potential remote code execution when processing untrusted XML/XSL input. This is a widely-used Ruby gem for XML/HTML parsing, meaning the vulnerability propagates transitively into any application, service, or pipeline that depends on it.

unrestricted-file-uploadweb-shellrcesoftware-repositorysupply-chain-riskagent-relevant

CVE-2026-16286 is a critical unrestricted file upload vulnerability in TRtek's Software Repository Management product, allowing unauthenticated attackers to upload malicious web shells to the underlying web server. Successful exploitation grants remote code execution, giving attackers full control over the affected host. Given the product's role as a software repository, this flaw poses supply-chain risk to any downstream systems, including AI agent pipelines, that pull artifacts from a compromised instance.

wordpressplugin-vulnerabilityprivilege-escalationunauthenticatedcms-security

The Total Donations plugin for WordPress (versions up to 2.0.5) contains a critical privilege escalation vulnerability that allows unauthenticated attackers to gain administrator-level access. Given the CVSS score of 9.8, this flaw is trivially exploitable and could lead to full site takeover.