A CVSS 10.0 code-injection vulnerability in Veeam ONE allows a remote, unauthenticated attacker to execute code on the agent host. No active exploitation is known, but affected systems should be upgraded to 13.1.0.7034 immediately.
An unsafe PyTorch deserialization path in ComfyUI allows unauthenticated attackers to execute arbitrary commands using a malicious pickle shard. CVSS 9.3; no public PoC or confirmed successful exploitation, although exploitation attempts are reportedly being tracked.
A CVSS 9.8 WordPress Core vulnerability chain lets unauthenticated attackers turn REST route confusion and SQL injection into remote code execution. Public PoCs are available, with early signs of in-the-wild activity reported.
Januscape is a Linux KVM/x86 use-after-free that can turn nested virtualization into host-root code execution. Red Hat scores it CVSS 7.8; a host-crash PoC is public, while the full escape exploit remains withheld.
A missing access check in SP Page Builder's icon-upload endpoint gave unauthenticated attackers direct RCE on every Joomla site running the extension. CVSS 10.0, actively exploited, patch available.
A CVSS 9.8 authentication bypass in ThingsBoard's Apple OAuth 2.0 flow lets a remote attacker impersonate an existing user and take over the account. A public PoC exists, while active exploitation has not been reported.
A CVSS 9.8 pre-authentication RCE in Splunk Enterprise's PostgreSQL sidecar service lets any network-reachable attacker chain file-write primitives into full code execution, with active exploitation reported within five days of disclosure.
A perfect 10.0 pre-authenticated OS command injection in Ivanti Sentry lets any unauthenticated attacker execute arbitrary commands as root. Public PoC released June 10, 2026. Patch immediately.
A critical (CVSS 9.6) information-disclosure flaw in LibreChat lets any authenticated user exfiltrate JWT signing keys, AES encryption keys, and database credentials by injecting environment-variable placeholders into a malicious MCP server URL. Patched in v0.8.4-rc1.
A logic error in Android's ADB daemon lets an adjacent-network attacker bypass mutual TLS authentication and open a remote shell on any unpatched Android 14–16 device, no user interaction required.