A critical vulnerability in Gitea, the self-hosted Git platform, allows unauthenticated attackers to read arbitrary files accessible to the service account. Tracked…
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.…
CVE-2023-24489 is an unauthenticated vulnerability in Citrix ShareFile Storage Zones Controller that was actively exploited in 2023. CISA flagged it as exploited,…