CVE-2026-29059: Windmill Path Traversal Vulnerability
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…
A high-severity unauthenticated path traversal flaw in Windmill's get_log_file endpoint allows arbitrary file read. Exploitation can expose SUPERADMIN_SECRET leading to RCE. Patched…
A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.…
CVE-2023-24489 is an unauthenticated vulnerability in Citrix ShareFile Storage Zones Controller that was actively exploited in 2023. CISA flagged it as exploited,…
Langflow versions before 1.3.0 expose the /api/v1/validate/code endpoint without authentication, allowing remote attackers to execute arbitrary Python code. CVSS score 9.8. Added…
An unauthenticated RCE flaw in Langflow, fixed in version 1.9.0. Added to CISA KEV catalog on March 25, 2026.
Splunk has released urgent security updates to address a critical vulnerability in Splunk Enterprise, tracked as CVE-2026-20253, with a CVSS score of…