Conventional Threats Watchlist

Browse by attack type

Showing 261–280 of 804 threats, newest first

wordpressplugin-vulnerabilityfile-deletionrceunauthenticatedcms-security

The Link Library plugin for WordPress (versions up to 7.9.4) contains an arbitrary file deletion vulnerability caused by insufficient path validation in the ll_delete_link_fields function. When the 'Delete local file on link deletion' option is enabled, unauthenticated attackers can submit malicious links that, once deleted by an administrator during routine moderation, trigger deletion of critical files such as wp-config.php, potentially leading to full remote code execution.

Updated Aug 17, 2026 · CVSS 9.1

wordpressplugin-vulnerabilityprivilege-escalationauthorization-bypasscmsweb-application-security

The Pods – Custom Content Types and Fields WordPress plugin (versions up to 3.3.9) contains a critical authorization bypass flaw that allows unauthenticated attackers to escalate privileges to Administrator or reset any user's password, including the site owner's. This enables complete site takeover and has been assigned a CVSS score of 9.8.

Updated Aug 17, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityaccount-takeoverunauthenticatedprivilege-escalationweb-application

The TrueBooker WordPress plugin (versions up to 1.2.6) contains a critical account takeover vulnerability due to an insecure AJAX handler that allows unauthenticated attackers to change any user's email address, including administrators. Attackers can chain this with WordPress's native password reset flow to fully hijack accounts, including full site administrator access.

Updated Aug 17, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityauthentication-bypasstype-confusionprivilege-escalationcmsweb-application

The User Profile Builder plugin for WordPress (versions up to 3.16.4) contains a critical authentication bypass vulnerability caused by improper error handling during user registration. An unauthenticated attacker can exploit a type confusion flaw to obtain an autologin nonce bound to user ID 1, effectively logging in as the site's Administrator and achieving full site takeover.

Updated Aug 17, 2026 · CVSS 9.8

microsoft-defenderpatch-bypassprivilege-escalationwindowsSYSTEM-accesszero-dayproof-of-conceptagent-relevant

A researcher known as Chaotic Eclipse released a public proof-of-concept called ShieldBreak that bypasses Microsoft's patch for CVE-2026-50656 (RoguePlanet), a Windows Defender vulnerability. The PoC reportedly grants SYSTEM-level access, meaning organizations that applied the original patch may still be exposed to full local privilege escalation.

Updated Aug 16, 2026 · CVSS 7.8

SAPRCEactive-exploitationenterprise-softwarecommerce-platform

A maximum-severity remote code execution vulnerability in SAP Commerce Cloud, patched only three days prior, is already being actively exploited in the wild according to threat intelligence firm Defused. Organizations running unpatched instances face immediate risk of full system compromise, making rapid patching or mitigation critical.

Updated Aug 16, 2026 · CVSS 9.8

google-workspaceoauthtoken-theftcloud-securityidentity-securitysaas-securityagent-relevant

This report highlights that attacks against Google Workspace increasingly bypass traditional phishing defenses by exploiting stolen OAuth tokens to gain access to Gmail, Drive, and connected third-party applications. Material Security emphasizes that organizations must defend the entire Workspace attack chain, not just the initial login, since attackers can pivot through connected integrations and persistent tokens. This represents a shift toward identity- and token-centric attack paths rather than credential phishing alone.

Updated Aug 16, 2026

botnetmirai-variantlinux-malwarerouter-compromisesocks5-proxyiot-security

Evooo1Bot is a newly identified Mirai-based modular Linux botnet targeting internet-facing gateway devices and routers. Once compromised, infected devices are converted into SOCKS5 traffic relay nodes, likely to support proxy-for-hire services or to anonymize other malicious traffic.

Updated Aug 16, 2026

ICSOTenergy-sectorhard-coded-credentialsmissing-authenticationrecoverable-passwordsVNC-exposureCISA-advisory

ANDRITZ HIPASE-250 and 250 SCALA industrial control system products (versions <=7.20) contain four vulnerabilities including recoverable password storage, missing authentication on data/config endpoints, an unauthenticated logging manipulation endpoint, and a hard-coded VNC credential used across engineering workstation deployments. Successful exploitation could allow an attacker to read sensitive process data, access engineering workstations, suppress audit logs, or recover stored credentials. These are primarily energy-sector ICS/OT vulnerabilities with no reported public exploitation to date.

Updated Aug 16, 2026 · CVSS 8.1

ICSSCADASiemensPLCcryptographic-weaknesshardcoded-keypassword-hashingCWE-321CWE-759industrial-control-systems

Siemens LOGO! Soft Comfort versions prior to V9 contain two vulnerabilities affecting project-file encryption and password protection: a hardcoded AES master key and unsalted SHA-256 password hashes. A local attacker could exploit these flaws to decrypt project files, bypass or remove passwords, and perform efficient offline brute-force attacks, potentially gaining unauthorized access to sensitive PLC project logic and configurations.

Updated Aug 16, 2026 · CVSS 6.8

ICSmedical-devicehardcoded-credentialsbluetoothCWE-798healthcareIoT

Flow Neuroscience FL-100 (and rebranded Halo Neuroscience FL-100) tDCS devices contain an undocumented hard-coded credential shared across all units, allowing any attacker within Bluetooth range to bypass authentication. Exploitation could let an attacker arbitrarily manipulate brain stimulation parameters and override built-in safety limits, posing direct physical harm risk to patients.

Updated Aug 16, 2026 · CVSS 8.1

wordpressauthentication-bypassaccount-takeoverplugin-vulnerabilitycryptographic-failureunauthenticated-rce-adjacentcms

The User Session Synchronizer plugin for WordPress (versions up to 1.4.0) contains a critical authentication bypass vulnerability that allows unauthenticated attackers to impersonate any user, including administrators. The flaw stems from unvalidated request parameters and a cryptographic fallback that renders the encryption predictable when an unregistered session key is referenced. Full site takeover is possible with no prior knowledge of secrets, making this an urgent patch priority for any WordPress site running the plugin.

Updated Aug 16, 2026 · CVSS 9.8

wordpressauthentication-bypassplugin-vulnerabilityprivilege-escalationunauthenticated-rce-adjacentagent-relevant

The 6Storage Rentals WordPress plugin (versions up to 2.27.0) contains a critical authentication bypass vulnerability allowing unauthenticated attackers to log in as any existing WordPress user, including administrators, simply by supplying that user's email address. This flaw stems from an insecure AJAX handler exposed to unauthenticated users that lacks nonce, capability, or ownership checks before establishing a full authenticated session.

Updated Aug 16, 2026 · CVSS 9.8

wordpressplugin-vulnerabilityarbitrary-file-deletionunauthenticated-rcecontact-form-7web-application-security

The RapiSafe – Secure Multi File Upload plugin for Contact Form 7 (versions up to 1.0.4) contains an unauthenticated arbitrary file deletion vulnerability in its AJAX upload removal handler. Attackers can exploit exposed nonces to delete critical files such as wp-config.php, potentially triggering a reinstallation flow that leads to full remote code execution and site takeover. Given the plugin's popularity and the ease of exploitation (no authentication required), this poses a severe risk to any WordPress site running the affected component.

Updated Aug 16, 2026 · CVSS 9.1

CVE-2026-17186IBMDb2command-injectionIBM-iremote-code-execution

A critical vulnerability in IBM Db2 Mirror for i allows a remote, likely unauthenticated attacker to execute arbitrary CL (Control Language) commands due to improper input sanitization. With a CVSS score of 9.9, successful exploitation could lead to full compromise of the affected IBM i system.

Updated Aug 16, 2026 · CVSS 9.9

ibmdb2rcepath-traversalibm-icritical-infrastructure

A critical vulnerability in IBM Db2 Mirror for i (versions 7.4, 7.5, 7.6) allows remote attackers to execute arbitrary code by exploiting external control of file name or path. With a CVSS score of 9.8, this flaw poses severe risk to organizations running IBM i systems for high-availability database replication.

Updated Aug 16, 2026 · CVSS 9.8

adtechprivacytrackingtransparency-toolnon-malicious

DecryptAds is a new free service that scrapes and correlates adtech and mobile SDK data to help users identify which companies are tracking them via websites and apps. This is a privacy/transparency tool rather than a malicious threat, though it highlights the scale of existing ad-tracking infrastructure. No exploit, malware, or attack vector is involved.

Updated Aug 15, 2026

SAPCommerce CloudRCEunauthenticatedinput-validationauthorization-bypasspatch-now

SAP has patched a maximum-severity (CVSS 10.0) vulnerability in Commerce Cloud's Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code due to insufficient authorization checks and input validation. Given the flaw requires no authentication and results in full code execution, organizations running affected SAP Commerce Cloud deployments should prioritize immediate patching.

Updated Aug 15, 2026 · CVSS 10

supply-chainpypilitellmcredential-theftpythonagent-relevantcloud-securitysecrets-exposure

Two malicious versions of the popular LiteLLM package were published to PyPI in March and remained live for roughly 40 minutes, long enough to be pulled by automated build pipelines and developers. The packages contained credential-harvesting code that exfiltrated cloud keys, SSH keys, Kubernetes tokens, and database passwords, with CloudSEK estimating exposure impacting over 2,100 organizations based on a dataset of ~434,000 captured files.

Updated Aug 15, 2026

vmwarevcenterrcedirectory-traversalvirtualizationpersistent-accessagent-relevant

Threat actors are actively exploiting a critical directory-traversal vulnerability (CVE-2026-59310, CVSS 9.8) in Broadcom VMware vCenter to achieve remote code execution and establish persistent access. The flaw affects any attacker with network access to the vCenter management interface, making unpatched instances high-value targets for post-exploitation activity including lateral movement and infrastructure takeover.

Updated Aug 15, 2026 · CVSS 9.8