Tag

#Code Execution

articleCRITICAL 9.8

Critical Nokogiri Vulnerability: CVE-2025-71407

A critical vulnerability (CVE-2025-71407) with a CVSS score of 9.8 affects Nokogiri, a popular Ruby gem for parsing XML and HTML. The vulnerability involves a stack buffer overflow and a use-after-free issue in libxml2, which can lead to denial of service or potential code execution. Affected versions are Nokogiri before 1.18.3. Immediate patching is recommended.

1 source
newsCRITICAL 9.0

CVE-2026-13170: Eventin WordPress Plugin Arbitrary Local PHP File Inclusion Vulnerability

The Eventin WordPress plugin before 4.1.20 is vulnerable to arbitrary local PHP file inclusion. Users with editor-level access and above can exploit this vulnerability to include and execute arbitrary local PHP files. This vulnerability has not been reported as actively exploited.

1 source
blogHIGH 7.8

Understanding and Defending Against CVE-2026-42170: A Heap-Based Buffer Overflow in GIMP DDS File Parser

CVE-2026-42170 is a heap-based buffer overflow vulnerability in the GIMP DDS file parser. This vulnerability allows for potential code execution when a crafted DDS file is processed. It has a CVSS score of 7.8 and is considered a high-severity threat. This educational analysis will delve into the root cause, attack surface, exploitation mechanics, real-world impact, detection, and defense strategies for this vulnerability.

1 source
blogHIGH 8.0

Understanding the 7-Zip Vulnerability: CVE-2026-14266

A new vulnerability in 7-Zip, CVE-2026-14266, allows attackers to execute code on a machine by crafting a malicious XZ archive. This heap-based buffer overflow flaw occurs during the processing of XZ chunked data. A fix was released on June 25 in 7-Zip version 26.02. Understanding this vulnerability is crucial for defenders to protect against potential code execution attacks.

1 source
newsCRITICAL 9.6

Critical Path Traversal Vulnerability in JetBrains IntelliJ IDEA

A critical vulnerability (CVE-2026-59792) with a CVSS score of 9.6 was discovered in JetBrains IntelliJ IDEA, allowing for code execution via path traversal in project workspace ID handling. Users of IntelliJ IDEA versions before 2026.1.4 and 2026.2 are affected. Immediate action is required to update to a patched version.

1 source