Exploited CVEs
Vulnerabilities with confirmed exploitation — sourced from threat intelligence reports with associated IoCs and actor attribution.
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.
DTLS Retransmits Handshake Messages From a Stale Buffer Offset
Grav: Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.
Adobe Commerce | Incorrect Authorization (CWE-863)
Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.
An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.
Stored XSS vulnerability in Roundcube
af_unix: Unlink scc_entry in unix_del_edge().
Bifrost unauthenticated remote code execution via MCP stdio client registration
Unauthenticated RCE via Custom Plugin HTTP Path on Dynamically Linked Builds
Bifrost: SSRF deny-list incomplete: isPublicIP permits CGNAT, IPv6 6to4/NAT64, and site-local in FetchAndEncodeURL
KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation
libheif: Heap Buffer OOB Read in overlay compositing due to wrong alpha stride
tls: fix handling of zero-length records on the rx_list
netfilter: bridge: make ebt_snat ARP rewrite writable
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH keys
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
pppoe: reload header pointer after dev_hard_header()
sctp: prevent peer transport count overflow
xfrm: ah6: validate routing header segments_left
net: tun: bound receive headroom
GLPI allows unauthenticated SQL injection through the inventory endpoint
Docker Sandboxes guest can write arbitrary macOS host files via a symlink in the virtio-fs stored-path fallback
Docker Sandboxes UDS forwarder can reach arbitrary host Unix sockets through a symlink race
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.