Trending Vulnerabilities
The most severe recently published CVEs — CVSS 7.0 and above, ranked by score and recency.
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXE
Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
: Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)
The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-
IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks r
LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbit
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 impro
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially craf
Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint a
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elev
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator
The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both
Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.
Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or support
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing un
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in priv
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vul
SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-s
SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement
SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote att
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related fi
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may all
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue a
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This
Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Ser
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0
The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-H
A Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated onl
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to el
Stay Ahead of Threats
CyberStrike continuously monitors for trending vulnerabilities and scans your infrastructure automatically.
Get Started