CVE-2026-57624 — Code: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. CVSSv3.1 10.0 (CRITICAL)
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. CVSSv3.1 10.0 (CRITICAL)
Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. CVSSv3.1 9.0 (CRITICAL)
Unauthenticated PHP Object Injection in Booktics <= 1.0.21 versions. CVSSv3.1 9.8 (CRITICAL)
Deserialization of Untrusted Data vulnerability in Themify Themify Popup allows Object Injection. This issue affects Themify Popup: from n/a through 1.4.3. CVSSv3.1 8.8 (HIGH)
Unauthenticated Local File Inclusion in Audrey <= 1.5 versions. CVSSv3.1 8.1 (HIGH)
Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. CVSSv3.1 9.1 (CRITICAL)
Subscriber Arbitrary File Upload in Zegen <= 1.1.9 versions. CVSSv3.1 9.9 (CRITICAL)
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. CVSSv3.1 8.8 (HIGH)
Unauthenticated Local File Inclusion in Pearl - Corporate Business <= 3.4.10 versions. CVSSv3.1 8.1 (HIGH)
Contributor PHP Object Injection in ARMember Premium <= 7.0 versions. CVSSv3.1 8.8 (HIGH)
Subscriber SQL Injection in Unicamp <= 2.2.2 versions. CVSSv3.1 8.5 (HIGH)
Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. CVSSv3.1 8.1 (HIGH)
Trail of Bits reports on Patch the Planet, a collaboration with OpenAI using GPT-5.5-Cyber to proactively discover vulnerabilities in open-source projects before attackers do. The initiative demonstrates that frontier LLMs can autonomously design and execute sophisticated fuzzing campaigns (e.g., building custom harnesses across a dozen zlib entrypoints in a single day), dramatically lowering the expertise barrier for vulnerability discovery and shifting the threat model for security-critical software.
PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix check while pointing the OIDC discovery and JWKS fetches at a server the attack CVSSv3.1 8.2 (HIGH)
Synacktiv extends Resource-Based Constrained Delegation (RBCD) attacks to multi-domain and cross-forest scenarios, demonstrating recursive S4U2Self+U2U and S4U2Proxy implementations that enable impersonation of any user within a forest to access resources across domain and forest boundaries. The research includes practical exploitation of SPN-less RBCD in complex trust chains and provides updated Impacket implementations with branch-aware algorithm variants.
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` handler, which does not register authorization validators for trace endpoints, res CVSSv3.1 8.1 (HIGH)
Kaspersky's 2025 Compromise Assessment report reveals systemic detection gaps across enterprise networks: 60% of incidents were missed due to absent high-confidence alerts, 52% of high-severity compromises went undetected for 90+ days, and 40% of web shells persisted in backups post-remediation. Key findings include a four-year-old crypto-mining infection on domain controllers exploiting EternalBlue, persistent use of LoLBins and remote management tools across all compromised environments, and communication failures during incident response that compounded detection blindness.
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they are within the uploads directory. The plugin stores backup file paths in the image_optimizer_metadata post meta field and trusts these paths completely when deleti CVSSv3.1 8.1 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. One of them, `connectionInfo` is meant to CVSSv3.1 8.3 (HIGH)
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and may be necessary for them to function properly. The Websocket server can accept various commands coming from localhost. Many of the commands will take an `index` CVSSv3.1 8.3 (HIGH)