Tag
#Critical Vulnerability
Critical Vulnerability in FormGent WordPress Plugin Allows Unauthenticated Arbitrary File Deletion
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2. This critical vulnerability, with a CVSS score of 9.1, allows unauthenticated attackers to delete arbitrary files within the formgent uploads directory and potentially bypass path traversal protection to delete critical files like wp-config.php, leading to complete site takeover. Immediate patching is recommended.
Critical Directory Traversal Vulnerability in IBM App Connect Enterprise (CVE-2026-15435)
A critical vulnerability (CVE-2026-15435) with a CVSS score of 9.8 affects IBM App Connect Enterprise versions 12.0.1.0 through 12.0.12.27 and 13.0.1.0 through 13.0.7.2. An unauthenticated remote attacker could exploit this vulnerability to traverse directories and write arbitrary files on the system. Immediate action is required to mitigate this vulnerability.
Critical Adobe Campaign Classic Vulnerability: CVE-2026-48449
A critical Incorrect Authorization vulnerability, CVE-2026-48449, has been discovered in Adobe Campaign Classic (ACC), potentially leading to arbitrary code execution. With a CVSS score of 10, this vulnerability has a significant impact and can be exploited without user interaction. Affected versions include ACC 7.4.3 build 9397 and earlier. Immediate patching is recommended.
Critical Vulnerability in 微信二维码登陆 WordPress Plugin Allows Unauthenticated Login
A critical vulnerability (CVE-2026-13597, CVSS 9.1) in the 微信二维码登陆 WordPress plugin (version 1.3 and earlier) allows unauthenticated attackers to forge login events, read login codes, and log in as any user, including administrators, without a password. Immediate action is required to prevent exploitation.
Critical Authentication Bypass Vulnerability in Check Point SmartConsole (CVE-2026-16232)
A critical authentication bypass vulnerability (CVE-2026-16232) has been discovered in Check Point SmartConsole, allowing unauthenticated remote attackers to obtain application login tokens and gain full administrative privileges. This vulnerability has a CVSS score of 9.1 and is actively being exploited. Affected products include various versions of Check Point Quantum Security Management and Multi-Domain Security Management. Immediate patching or mitigation is strongly recommended.
Critical Shellcode Injection Vulnerability in openSUSE Build Service
A critical vulnerability (CVE-2026-56004) with a CVSS score of 10 has been discovered in the obs tar_scm source service before version 0.12.4. This vulnerability allows attackers to inject shellcode and execute code as the source service or local user. Immediate action is required to update to version 0.12.4 or later.
Critical Stack Overflow Vulnerability in GeoVision GV-I/O Box 4E (CVE-2026-12846)
A critical stack overflow vulnerability (CVE-2026-12846) with a CVSS score of 10 has been discovered in GeoVision GV-I/O Box 4E, a smart embedded device. The vulnerability affects version V2.09 and can be exploited by sending a crafted UDP message to the DVRSearch service listening on port 10001. Immediate action is required to update to a non-vulnerable version.
Critical Insecure Default Credentials Vulnerability in NI grpc-device
A critical vulnerability (CVE-2026-9142) with a CVSS score of 9.1 has been discovered in NI grpc-device, affecting versions 2.17.0 and prior. The vulnerability allows unauthenticated access to the server on the local network when TLS configuration is not present and the server is bound beyond loopback. Immediate patching is recommended to prevent potential exploitation.