HPC Pack: Important RCE Vulnerability
HPC Pack has a critical-severity RCE (CVE-2026-59124) but is rated Important because it is not installed by default.
HPC Pack has a critical-severity RCE (CVE-2026-59124) but is rated Important because it is not installed by default.
CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server, remotely exploitable without authentication. ZDI describes it as wormable, though Microsoft rates…
CVE-2026-62893 is a remote, unauthenticated RCE flaw in Windows Deployment Services, reachable via TFTP handling without user interaction.
CVE-2026-62815 is a remote, unauthenticated code execution vulnerability in Microsoft's QUIC implementation, requiring no user interaction.
CVE-2026-63520 is the code execution component of a SharePoint exploit chain, fixed in August 2026. Chaining with CVE-2026-55040 enables unauthenticated RCE.
emer-run.php is a PHP web shell installed via a fake plugin in the BdThemes supply chain attack, enabling remote code execution on…
CVE-2023-38646 is a critical vulnerability in Metabase that allows pre-authenticated remote code execution on affected installations. With a CVSS score of 9.8,…
WordPress has released a critical security update to address a pre-authentication reflected cross-site scripting (XSS) vulnerability that affects all versions of the…
Vercel released security patches for two critical Next.js vulnerabilities enabling unauthenticated RCE. The company moved its monthly security release forward by one…
A high-severity flaw in Paperclip's local_trusted mode allows DNS rebinding attacks to execute commands on the developer's machine with CVSS 9.6. Fixed…