CVE-2017-12611: Struts Freemarker Tag RCE
CVE-2017-12611 is a remote code execution vulnerability in Apache Struts via the Freemarker tag.
CVE-2017-12611 is a remote code execution vulnerability in Apache Struts via the Freemarker tag.
GitHub Copilot CLI, along with other AI tools, is vulnerable to search order hijacking, allowing attackers to place malicious binaries in the…
Amazon addressed an insufficient access control flaw in Kiro IDE (CVSS 8.8) that could allow a remote unauthenticated attacker to execute arbitrary…
SQL Server is a relational database management system developed by Microsoft. It had two RCE vulnerabilities patched in July 2026.
SquareShell is a web shell deployed by UNK_MassTraction using a PHP gadget shell command after exploiting CVE-2025-49113 in Roundcube. It is accessible…
Joomla SP Page Builder is a page builder plugin for Joomla, associated with CVE-2026-48908 used as a lure in the ChocoPoC campaign.
A remote code execution vulnerability in React applications, used as a lure in the ChocoPoC campaign.
GeoServer is an open-source server for sharing geospatial data. A newly disclosed zero-day SQL injection vulnerability is being actively exploited, potentially leading…
A critical RCE vulnerability in Langflow (CVSS 9.8) that was exploited by the AI-driven threat actor but failed due to restrictive configurations.
Langflow is an open-source AI application development platform that has been targeted by multiple RCE vulnerabilities.