All CosmicBytez Labs articles tagged #Critical Vulnerability, across news, security advisories, how-to guides, and projects.
A CVSS 9.9 command injection flaw in Advantech WISE-6610 industrial gateways lets remote attackers run arbitrary OS commands; a public exploit exists.
A critical unauthenticated OS command injection flaw in Tenda CP3 Wi-Fi cameras lets remote attackers run arbitrary commands via the AlarmVoiceURL parameter.
A second critical command injection flaw in Tenda CP3 cameras lets remote attackers execute OS commands through the ping utility's host/interface argument.
MemberDash ≤ 1.8.5 has an IDOR letting unauthenticated attackers change any WordPress user's password via a crafted registration request.
CVSS 10.0 flaw in Tenda CP3's Kylin AutoAddWifi thread lets remote attackers inject and execute arbitrary OS commands.
Tenda CP3 firmware 27.5.57.101 lets remote attackers inject OS commands through its network configuration handler, no authentication noted.
Tenda CP3's SetRedirectEnable function lacks authorization checks, letting remote attackers alter port-forwarding without admin access.
IXON VPN Client before v1.4.7 lets a local attacker inject CRLF sequences into a config file consumed by a privileged process, gaining root or SYSTEM.
A live-collection iteration bug in MapLibre GL JS's DOM.sanitize() lets attacker-supplied attribution strings smuggle an event handler past sanitization.
CAT relies solely on an unkeyed Java hashCode for session integrity, letting attackers forge admin cookies and bypass IP binding via X-Forwarded-For.
An unauthenticated OS command injection in the DNS-340L's Add-On Center CGI grants root — and D-Link has declared the device end-of-life.
Nodemailer before 8.0.4 lets attackers inject SMTP commands via unsanitized envelope.size, silently adding recipients to outbound mail.
hulumi/policies before 1.3.2 let attackers suppress guardrail violations using compliant evidence from an unrelated resource in the same stack.
hulumi/policies before 1.3.2 missed set-qualified IAM operators, letting wildcard GitHub Actions OIDC conditions slip past guardrails.
hulumi before 1.3.2 let attackers create persistent higher-privilege af-e2e-* roles in the sandbox account via a flawed IAM boundary.
A CVSS 9.8 OS command injection in AI Maestro's session-kill function lets attackers run arbitrary commands on self-hosted orchestrator hosts.
Dovecot's Sieve editheader extension has a critical use-after-free (CVSS 9.1) letting authenticated users corrupt memory during mail delivery.
A low-privilege, read-only CephX role can read Ceph's entire config-key store, exposing cephadm SSH keys and OSD LUKS passphrases.
Synology Chat Server's unsanitized link-preview domain lets authenticated users read/write arbitrary DSM files and cause denial-of-service.
Unauthenticated OS command injection in Green-Computing's NUMail lets remote attackers run arbitrary commands on the mail server. CVSS 9.8.
OpenRGB's network protocol lets remote attackers overwrite (and delete) arbitrary files through the SAVE_PROFILE message, up to v1.0rc3.
A critical flaw in UniFi Protect lets a low-privileged, network-adjacent attacker inject OS commands on the host device. Patch to 7.2.105+.
EFence by Thinking Software Technology allows unauthenticated remote attackers to upload web shells and achieve full code execution.
Unrestricted file upload flaw lets attackers plant a web shell on TRtek's Software Repository Management with no authentication required.
Critical OS command injection via the HTTP Basic Auth username lets unauthenticated attackers run root commands on Weidmueller security routers.
Critical XSS in justhtml before 1.16.0. Multiple bypass paths let dangerous content survive sanitization, enabling script injection with no auth required.
Critical XSS in justhtml <=1.11.0. The to_markdown() function leaves angle brackets unescaped, allowing raw HTML to reach downstream Markdown renderers.
Zimbra Collaboration Suite contains a critical unauthenticated OS command injection flaw allowing RCE as the Zimbra user via crafted SMTP requests.
Adobe's August 2026 patch cycle fixes 3 maximum-severity RCE vulnerabilities across ColdFusion and Campaign Classic. Priority 1 — patch within 72 hours.
A CVSS 9.8 authentication bypass vulnerability allows unauthenticated remote attackers to gain full access to the VMware Avi Load Balancer Control Plane....
A critical unauthenticated remote code execution vulnerability in the SGLang AI inference framework allows attackers to deliver malicious pickle payloads...
A critical authentication bypass in Kopia, a cross-platform backup tool for Windows, macOS, and Linux, allows unauthenticated access to repository API...
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, enabling them to take complete control of…
A CVSS 9.9 critical vulnerability in Oracle REST Data Services (ORDS) versions 24.2.0 through 26.1.0 allows a low-privileged network attacker to fully...
Fortinet has released emergency security patches for two critical vulnerabilities in FortiSandbox and FortiAuthenticator that could enable attackers to...
A critical vulnerability (CVSS 9.4) in phpVMS before version 7.0.6 allows unauthenticated attackers to access a legacy import feature, potentially...
Cisco has released emergency patches for a critical vulnerability in Webex that could allow unauthenticated remote code execution. Organizations urged to...