Red Heron
| CVE-2026-34908 suspected | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauthorized changes to the system. | CVSS 10.0 KEV |
| CVE-2026-34909 suspected | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account. | CVSS 10.0 KEV |
| CVE-2026-34910 suspected | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. | CVSS 10.0 KEV |
| CVE-2023-54391 suspected | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life. | CVSS 9.8 |
| CVE-2026-54569 suspected | SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many, and getusers, do not enforce the senaite.core: Access JSON API permission before resolving attacker-selected objects. In src/bika/lims/jsonapi/init.py, set_fields_from_request passes raw request values for RecordsField and RecordField instances to eval() before field mutator write-permission checks execute. An anonymous attacker can discover the bika_setup object identifier through @@uuid, send a value such as RejectionReasons to /@@API/update, and execute arbitrary Python in the Zope worker before a later mutation failure rolls back ZODB changes. The same unsafe evaluation pattern is present in src/senaite/core/browser/fields/record.py and src/senaite/core/browser/fields/records.py. Successful exploitation can expose or modify laboratory data, files, and accounts and can disrupt the service. | CVSS 9.8 |
| CVE-2026-56271 suspected | Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience and issuer values ('AUDIENCE', 'ISSUER') in the enterprise passport authentication middleware (packages/server/src/enterprise/middleware/passport/index.ts). When the corresponding environment variables (JWT_AUTH_TOKEN_SECRET, JWT_REFRESH_TOKEN_SECRET, JWT_AUDIENCE, JWT_ISSUER) are not set, the application silently falls back to these publicly known defaults, allowing an attacker to forge valid JWTs and impersonate any user, including administrators, resulting in authentication bypass. | CVSS 9.8 |
| CVE-2026-60004 suspected | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | CVSS 9.8 KEV |
| CVE-2026-63030 suspected | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. | CVSS 9.8 KEV |
| CVE-2026-7273 suspected | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. | CVSS 8.8 KEV |
| CVE-2026-60137 suspected | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. | CVSS 5.9 KEV |
| CVE-2022-0847 suspected | Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their privileges on the system. This vulnerability has the moniker of "Dirty Pipe." | KEV |
| CVE-2026-79756 suspected | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added validateFunctionName for function names and common.Quote() for the named-resource shell command path, but the list-all resource path (triggered when no specific resource name is provided) still interpolates the resourceNamespace parameter unquoted into a /bin/sh -c command string. An unauthenticated attacker can inject shell metacharacters via the X-Nuclio-Function-Namespace, X-Nuclio-Project-Namespace, or X-Nuclio-Function-Event-Namespace HTTP headers to achieve arbitrary command execution inside the dashboard container. This issue has been patched in version 1.17.4. |
| sha256 | 2ff2945b13a4cd0e9a65c85af29ea1539e162a516466c0de682dbf9f8a4000b1 | — | 2026-09-23 |
| sha256 | 0f6e757e82c4d91df5bd249f775b9970b59dee42cc0dfe40f879d77fc16821c6 | — | 2026-09-23 |
| sha256 | 0e81d80b40eaacbf6cb1e817fb1824c30a824af5cb4faca4aa9b03fd506d480f | — | 2026-09-23 |
| ip | 74.48.66.73 | — | 2026-09-23 |
| ip | 172.245.247.21 | — | 2026-09-23 |
| domain | p3.981666.xyz | — | 2026-09-23 |
| ip | 104.225.153.141 | — | 2026-09-23 |
| url | https://gitea.redacted.com.ar/api/v1/metrics | — | 2026-09-15 |
| md5 | 3a1e96289832518bff2feeb868bc61a4 | — | 2026-09-15 |
| domain | gitea.redacted.com.ar | — | 2026-09-15 |
| sha256 | 28b132ad55bd310bb5cf3ddb4ace580529ad735204a48cf388830d9039843d8e | — | 2026-09-15 |
| domain | xcyoibfhuufz.com | — | 2026-09-15 |
| domain | s2.981666.xyz | — | 2026-09-15 |
| sha256 | b441f793c87e54cb7e3f7205e25442aa19920d325cb6af41d2afdc8a0b5cf54f | — | 2026-09-15 |
| md5 | 88264a49750b3280e63894fb7445a9c2 | — | 2026-09-15 |