Robuta

https://thehackernews.com/2025/12/new-mongodb-flaw-lets-unauthenticated.html New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory High-severity CVE-2025-14847 allows unauthenticated attackers to read uninitialized heap memory in MongoDB due to a zlib compression handling flaw. newmongodbflawletsunauthenticated https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6 Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote... remote code executionidentity servicesciscoengineunauthenticated https://unit42.paloaltonetworks.com/captive-portal-zero-day/ Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code... May 8, 2026 - Unit 42 details CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal. Read now for details. https://dev.to/cverports/ghsa-68qg-g8mg-6pr7-ghsa-68qg-g8mg-6pr7-unauthenticated-remote-code-execution-in-paperclip-via-4962 GHSA-68QG-G8MG-6PR7: GHSA-68QG-G8MG-6PR7: Unauthenticated Remote Code Execution in Paperclip via... GHSA-68QG-G8MG-6PR7: Unauthenticated Remote Code Execution in Paperclip via Authorization... Tagged with security, cve, cybersecurity, ghsa. remote code executionghsaunauthenticated https://thehackernews.com/2021/11/alert-hackers-exploiting-gitlab.html Alert! Hackers Exploiting GitLab Unauthenticated RCE Flaw in the Wild A critical unauthenticated remote code execution flaw (CVE-2021-22205) affecting GitLab is under active exploitation in the wild. in thealerthackersexploitinggitlab https://www.mail-archive.com/koha-bugs@lists.koha-community.org/msg637256.html [Koha-bugs] [Bug 39918] New: Unauthenticated request data should show when editing a request https://www.exploit-db.com/exploits/52253?Cyber_Intelligence_Report Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE) - Multiple... Apr 17, 2025 - Angular-Base64-Upload Library 0.1.21 - Unauthenticated Remote Code Execution (RCE). CVE-2024-42640 . webapps exploit for Multiple platform https://www.wordnik.com/words/unauthenticated unauthenticated - definition and meaning unauthenticated: Not authenticated; not attested; not shown to be genuine. unauthenticateddefinitionmeaning https://www.exploit-db.com/exploits/49499 SonicWall SSL-VPN 8.0.0.0 - 'visualdoor' Remote Code Execution (Unauthenticated) - Hardware webapps... Jan 29, 2021 - SonicWall SSL-VPN 8.0.0.0 - 'visualdoor' Remote Code Execution (Unauthenticated).. webapps exploit for Hardware platform remote code executionssl vpn8 0 https://www.exploit-db.com/exploits/49847 Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated) - PHP webapps... May 7, 2021 - Human Resource Information System 0.1 - Remote Code Execution (Unauthenticated).. webapps exploit for PHP platform human resource informationremote code execution0 1 https://www.exploit-db.com/exploits/52375 Discourse 3.1.1 - Unauthenticated Chat Message Access - Multiple webapps Exploit Jul 22, 2025 - Discourse 3.1.1 - Unauthenticated Chat Message Access. CVE-2023-45131 . webapps exploit for Multiple platform 3 1chat messagediscourseunauthenticatedaccess https://www.sonarsource.com/de/blog/cacti-unauthenticated-remote-code-execution Cacti: Unauthenticated Remote Code Execution | Sonar Learn how we discovered a critical vulnerability in Cacti with the help of SonarCloud. remote code executioncactiunauthenticatedsonar https://www.sonarsource.com/jp/blog/cacti-unauthenticated-remote-code-execution Cacti: Unauthenticated Remote Code Execution | Sonar Learn how we discovered a critical vulnerability in Cacti with the help of SonarCloud. remote code executioncactiunauthenticatedsonar https://www.exploit-db.com/exploits/51686 EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download - Hardware remote Exploit Aug 21, 2023 - EuroTel ETL3100 - Transmitter Unauthenticated Config/Log Download.. remote exploit for Hardware platform euroteltransmitterunauthenticatedconfiglog https://www.openwall.com/lists/oss-security/2018/10/09/2 oss-security - Re: net-snmp 5.7.3 unauthenticated remote Denial of Service (exploit available) https://www.exploit-db.com/exploits/50532 GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated) - Ruby webapps Exploit Nov 17, 2021 - GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated). CVE-2021-22205 . webapps exploit for Ruby platform remote code execution13 10 https://www.sonarsource.com/blog/cacti-unauthenticated-remote-code-execution Cacti: Unauthenticated Remote Code Execution | Sonar Learn how we discovered a critical vulnerability in Cacti with the help of SonarCloud. remote code executioncactiunauthenticatedsonar https://www.ibm.com/support/pages/security-bulletin-ibm-security-verify-privilege-could-allow-unauthenticated-actor-obtain-sensitive-information-cve-2024-31887 Security Bulletin: IBM Security Verify Privilege could allow an unauthenticated actor to obtain... IBM Security Verify Privilege could allow an unauthenticated actor to obtain sensitive information. The issue has been addressed in an update. security bulletin https://www.exploit-db.com/exploits/49479 Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated) - Java webapps Exploit Jan 26, 2021 - Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated). CVE-2020-14882 . webapps exploit for Java platform oracle weblogic server12 2 https://www.mail-archive.com/search?l=koha-bugs@lists.koha-community.org&q=subject:%22%5C%5BKoha%5C-bugs%5C%5D+%5C%5BBug+39918%5C%5D+Unauthenticated+request+data+should+show+when+editing+a+request%22&o=newest&f=1 subject:"\[Koha\-bugs\] \[Bug 39918\] Unauthenticated request data should show when editing a... https://www.sentinelone.com/blog/ingressnightmare-critical-unauthenticated-rce-vulnerabilities-in-kubernetes-ingress-nginx/ IngressNightmare | Critical Unauthenticated RCE Vulnerabilities in Kubernetes Ingress NGINX Apr 4, 2025 - We share actionable mitigation and detection strategies against IngressNightmare so you can protect against possible exploitation in runtime. kubernetes ingressingressnightmarecriticalunauthenticatedrce https://thehackernews.com/2019/03/hack-wordpress-websites.html New WordPress Flaw Lets Unauthenticated Remote Attackers Hack Sites New WordPress RCE Flaw Lets Unauthenticated Remote Attackers Hack Sites, Update to Version 5.1.1 to Patch the Issue. newwordpressflawletsunauthenticated https://www.sonarsource.com/jp/blog/magento-rce-via-xss Magento 2.3.1: Unauthenticated Stored XSS to RCE | Sonar 2 3 1stored xssmagentounauthenticatedrce https://www.sebi.gov.in/legal/circulars/mar-2011/unauthenticated-news-circulated-by-sebi-registered-market-intermediaries-through-various-modes-of-communication_18462.html SEBI | Unauthenticated news circulated by SEBI Registered Market Intermediaries through various... Securities and Exchange Board of India is made for protect the interests of investors in securities and to promote the development of, and to regulate the... sebiunauthenticatednewscirculatedregistered https://www.mail-archive.com/koha-bugs@lists.koha-community.org/msg636849.html [Koha-bugs] [Bug 39918] Unauthenticated request data should show when editing a request request data https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-cucm-apidos-PGsDcdNF.html Multiple Cisco Unified Communications Products Unauthenticated API High CPU Utilization Denial of... A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU... cisco unified communicationshigh cpu utilization https://www.exploit-db.com/exploits/50098 Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated) - Multiple webapps Exploit Jul 6, 2021 - Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated). CVE-2021-42071 . webapps exploit for Multiple platform https://mail-archive.com/koha-bugs@lists.koha-community.org/msg639864.html [Koha-bugs] [Bug 39948] Simplify unauthenticated ILL request detail in the OPAC https://www.exploit-db.com/exploits/47230 Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit) - Linux remote Exploit Aug 12, 2019 - Webmin 1.920 - Unauthenticated Remote Code Execution (Metasploit). CVE-2019-15107 . remote exploit for Linux platform remote code executionwebmin1920unauthenticated https://mail-archive.com/koha-bugs@lists.koha-community.org/msg637374.html [Koha-bugs] [Bug 39948] Unauthenticated ILL form cluttered in the OPAC in thekohabugsunauthenticated https://www.exploit-db.com/exploits/48749 QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Deletion - Hardware webapps... Aug 17, 2020 - QiHang Media Web Digital Signage 3.0.9 - Unauthenticated Arbitrary File Deletion.. webapps exploit for Hardware platform https://jfrog.com/help/v/u/create-unauthenticated-call-home-endpoint-for-integrations-rtfact-22629 Create Unauthenticated Call Home endpoint for integrations [RTFACT-22629] Create Unauthenticated Call Home endpoint for integrations to invoke without the user having to supply authentication in our various integrations for ... call homecreateunauthenticatedendpointintegrations https://thehackernews.com/2026/01/critical-n8n-vulnerability-cvss-100.html Critical n8n Vulnerability (CVSS 10.0) Allows Unauthenticated Attackers to Take Full Control A critical CVSS 10.0 vulnerability in n8n allows unauthenticated attackers to read files, bypass authentication, and gain full server control. https://www.openwall.com/lists/oss-security/2025/11/05/13 oss-security - Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token... https://www.exploit-db.com/exploits/49397 Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated) - Multiple webapps Exploit Jan 8, 2021 - Cockpit Version 234 - Server-Side Request Forgery (Unauthenticated).. webapps exploit for Multiple platform server side request forgerycockpitversion234 https://www.mail-archive.com/koha-bugs@lists.koha-community.org/msg636916.html [Koha-bugs] [Bug 39918] Unauthenticated request data should show when editing a request request data https://www.exploit-db.com/exploits/46773 Domoticz 4.10577 - Unauthenticated Remote Command Execution - Multiple webapps Exploit Apr 30, 2019 - Domoticz 4.10577 - Unauthenticated Remote Command Execution. CVE-2019-10678CVE-2019-10664 . webapps exploit for Multiple platform remote commanddomoticz4unauthenticatedexecution https://www.sonarsource.com/de/blog/magento-rce-via-xss Magento 2.3.1: Unauthenticated Stored XSS to RCE | Sonar 2 3 1stored xssmagentounauthenticatedrce https://www.exploit-db.com/exploits/50714 Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit) - Multiple webapps Exploit Feb 4, 2022 - Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit). CVE-2022-22831 . webapps exploit for Multiple platform tessaaddsysadminuserunauthenticated https://www.rapid7.com/blog/post/2020/10/29/oracle-weblogic-unauthenticated-complete-takeover-cve-2020-14882-what-you-need-to-know/ CVE-2020-14882: Unauthenticated RCE, Oracle WebLogic Server | Rapid7 Blog Attackers opting for tricks instead of treats as they seek out and attempt to compromise internet-facing WebLogic servers vulnerable to CVE-2020-14882. oracle weblogic servercve2020unauthenticatedrce https://www.exploit-db.com/exploits/51431 Online Pizza Ordering System v1.0 - Unauthenticated File Upload - PHP webapps Exploit May 5, 2023 - Online Pizza Ordering System v1.0 - Unauthenticated File Upload. CVE-2023-2246 . webapps exploit for PHP platform pizza ordering system https://www.exploit-db.com/exploits/47433 V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download - Hardware webapps... Sep 27, 2019 - V-SOL GPON/EPON OLT Platform 2.03 - Unauthenticated Configuration Download.. webapps exploit for Hardware platform https://www.ibm.com/support/pages/node/7064976 Security Bulletin: An unauthenticated user can determine whether the default superuser password has... An unauthenticated user can determine whether the default superuser password has been changed on IBM SAN Volume Controller, IBM Storwize, IBM FlashSystem and... https://github.com/redis/redis/security/advisories/GHSA-r67f-p999-2gff Redis DoS Vulnerability due to unlimited growth of output buffers abused by unauthenticated client... GitHub is where people build software. More than 150 million people use GitHub to discover, fork, and contribute to over 420 million projects. https://www.openwall.com/lists/oss-security/2026/05/05/7 oss-security - [OSSA-2026-009] Horizon: Unauthenticated session flood via login redirect storage... https://www.sonarsource.com/fr/blog/magento-rce-via-xss Magento 2.3.1: Unauthenticated Stored XSS to RCE | Sonar 2 3 1stored xssmagentounauthenticatedrce https://www.exploit-db.com/exploits/49973 GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2) - PHP webapps Exploit Jun 9, 2021 - GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2).. webapps exploit for PHP platform https://www.exploit-db.com/exploits/49457 Selea Targa IP OCR-ANPR Camera - Multiple SSRF (Unauthenticated) - Hardware webapps Exploit Jan 22, 2021 - Selea Targa IP OCR-ANPR Camera - Multiple SSRF (Unauthenticated).. webapps exploit for Hardware platform anpr camera https://www.eclipse.org/lists/jgit-dev/msg03297.html [jgit-dev] Unauthenticated git-upload-pack/git-receive-pack request jgitdevunauthenticateduploadpack https://mail-archive.com/koha-bugs@lists.koha-community.org/msg637415.html [Koha-bugs] [Bug 39948] Simplify unauthenticated ILL request detail in the OPAC https://www.exploit-db.com/exploits/51174 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Unauthenticated Factory Reset - Windows local Exploit Mar 31, 2023 - SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Unauthenticated Factory Reset.. local exploit for Windows platform https://www.exploit-db.com/exploits/45561 Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit) - PHP remote Exploit Oct 8, 2018 - Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit). CVE-2018-17553CVE-2018-17552 . remote exploit for PHP platform remote code executionnavigate cmsunauthenticatedmetasploitphp https://thehackernews.com/2026/03/9-critical-ip-kvm-flaws-enable.html?ref=blog.netmanageit.com 9 Critical IP KVM Flaws Enable Unauthenticated Root Access Across Four Vendors Researchers uncovered 9 vulnerabilities across 4 IP KVM devices enabling unauthenticated root access and code execution. ip kvm https://www.exploit-db.com/exploits/52347 Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE) - Multiple remote Exploit Jul 2, 2025 - Wing FTP Server 7.4.3 - Unauthenticated Remote Code Execution (RCE). CVE-2025-47812 . remote exploit for Multiple platform wing ftp serverremote code execution https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-erlang-otp-ssh-xyZZy.html Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025... On April 16, 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to... https://www.sonarsource.com/es/blog/cacti-unauthenticated-remote-code-execution Cacti: Unauthenticated Remote Code Execution | Sonar Learn how we discovered a critical vulnerability in Cacti with the help of SonarCloud. remote code executioncactiunauthenticatedsonar https://www.openwall.com/lists/oss-security/2025/11/17/5 oss-security - Re: [OSSA-2025-002] OpenStack Keystone: Unauthenticated access to EC2/S3 token... https://mail-archive.com/koha-bugs@lists.koha-community.org/msg635379.html [Koha-bugs] [Bug 39697] ILL OPAC unauthenticated form is not centered is notkohabugsill https://www.sentinelone.com/vulnerability-database/cve-2025-41655/ CVE-2025-41655: Unauthenticated DOS Vulnerability CVE-2025-41655 is a denial of service vulnerability allowing unauthenticated attackers to reboot devices. Learn about its impact and mitigation methods. cve2025unauthenticateddosvulnerability https://grafana.com/security/security-advisories/cve-2026-21720/ Unauthenticated DoS in avatar cache in Grafana | Grafana Labs Grafana is an open-source platform for monitoring and observability. The platform supports users having their own avatars, which can be sourced from the... unauthenticateddosavatarcachegrafana https://mail-archive.com/search?l=koha-bugs@lists.koha-community.org&q=subject:%22%5C%5BKoha%5C-bugs%5C%5D+%5C%5BBug+39948%5C%5D+Simplify+unauthenticated+ILL+request+detail+in+the+OPAC%22&o=newest&f=1 subject:"\[Koha\-bugs\] \[Bug 39948\] Simplify unauthenticated ILL request detail in the OPAC" https://www.sonarsource.com/zh/blog/cacti-unauthenticated-remote-code-execution Cacti: Unauthenticated Remote Code Execution | Sonar Learn how we discovered a critical vulnerability in Cacti with the help of SonarCloud. remote code executioncactiunauthenticatedsonar https://dev.to/victorstackai/review-ally-wordpress-plugin-unauthenticated-sql-injection-400k-sites-and-a-repeatable-response-18nl Review: Ally WordPress Plugin Unauthenticated SQL Injection (400k+ Sites) and a Repeatable Response... The Ally plugin incident is the exact class of WordPress risk that causes avoidable firefights:... Tagged with security, wordpress, drupal, incidentresponse. https://www.exploit-db.com/exploits/51460 Screen SFT DAB 600/C - Unauthenticated Information Disclosure (userManager.cgx) - Hardware remote... May 23, 2023 - Screen SFT DAB 600/C - Unauthenticated Information Disclosure (userManager.cgx).. remote exploit for Hardware platform https://www.exploit-db.com/exploits/50730 Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated) - PHP webapps... Feb 10, 2022 - Home Owners Collection Management System 1.0 - Account Takeover (Unauthenticated).. webapps exploit for PHP platform collection management systemhome owners1 0 https://www.mail-archive.com/koha-bugs@lists.koha-community.org/msg637378.html [Koha-bugs] [Bug 39948] Simplify unauthenticated ILL request detail in the OPAC https://www.pluralsight.com/courses/rem-code-execution-apache-tomcat-what-you-should-know Unauthenticated Remote Code Execution in Apache Tomcat CVE-2025-24813: What You Should Know https://www.exploit-db.com/exploits/50221 Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated) - PHP... Aug 23, 2021 - Online Traffic Offense Management System 1.0 - Remote Code Execution (RCE) (Unauthenticated).. webapps exploit for PHP platform system 1 0remote code execution https://www.fastly.com/it/blog/active-exploitation-unauthenticated-stored-xss-vulnerabilities-wordpress Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress Plugins | Fastly We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000. active exploitationstored xssin wordpressunauthenticated https://www.exploit-db.com/exploits/49366 Klog Server 2.4.1 - Command Injection (Unauthenticated) - PHP webapps Exploit Jan 5, 2021 - Klog Server 2.4.1 - Command Injection (Unauthenticated). CVE-2020-35729 . webapps exploit for PHP platform 2 4 1command injectionklogserver https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE CVE-2026-25874 (CVSS 9.3) in LeRobot 0.4.3 allows unauthenticated RCE via pickle over gRPC, risking AI systems and sensitive data. hugging faceopen tocriticalflawleaves https://www.exploit-db.com/exploits/50738 Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated) -... Feb 11, 2022 - Kyocera Command Center RX ECOSYS M2035dn - Directory Traversal File Disclosure (Unauthenticated).. webapps exploit for Hardware platform command centerdirectory traversalkyocerarxecosys https://www.exploit-db.com/exploits/51774 Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS - Hardware dos Exploit Feb 2, 2024 - Electrolink FM/DAB/TV Transmitter - Unauthenticated Remote DoS.. dos exploit for Hardware platform tv transmitterfmdabunauthenticatedremote https://www.openwall.com/lists/oss-security/2015/01/03/10 oss-security - Re: CVE request: Unauthenticated remote disk space exhaustion in Zarafa WebAccess... https://securityaffairs.com/165087/security/openssh-server-critical-flaw.html Critical unauthenticated RCE flaw in OpenSSH server Jul 1, 2024 - A critical flaw in OpenSSH server can be exploited to achieve unauthenticated RCE with root privileges in glibc-based Linux systems criticalunauthenticatedrceflawopenssh https://curl.se/docs/CVE-2015-3143.html curl - Reusing authenticated connection when unauthenticated - CVE-2015-3143 curlreusingauthenticatedconnectioncve https://www.rapid7.com/blog/post/2022/05/12/cve-2022-30525-fixed-zyxel-firewall-unauthenticated-remote-command-injection/ CVE-2022-30525 (FIXED): Zyxel Firewall Unauthenticated Remote Command Injection | Rapid7 Blog Rapid7 discovered and reported a vulnerability that affects Zyxel firewalls supporting Zero Touch Provisioning (ZTP), identified as CVE-2022-30525. https://www.sonarsource.com/zh/blog/magento-rce-via-xss Magento 2.3.1: Unauthenticated Stored XSS to RCE | Sonar 2 3 1stored xssmagentounauthenticatedrce https://www.exploit-db.com/exploits/51227 Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE) - Python webapps Exploit Apr 3, 2023 - Roxy WI v6.1.0.0 - Unauthenticated Remote Code Execution (RCE). CVE-2022-31126 . webapps exploit for Python platform remote code execution https://www.exploit-db.com/exploits/51350 Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated) - JSP webapps... Apr 8, 2023 - Pentaho BA Server EE 9.3.0.0-428 - Remote Code Execution (RCE) (Unauthenticated). CVE-2022-43939CVE-2022-43769 . webapps exploit for JSP platform https://www.ibm.com/support/pages/apar/PH39883 PH39883: THE USER "unauthenticated" (in lower case) ASSERTED BY TRUSTASSOCIATIONINTERCEPTOR IS NO... In the distributed environment, WebSphere has the reserved username "UNAUTHENTICATED". When this user name is passed in lower case https://www.exploit-db.com/exploits/50251 Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated) - Hardware webapps Exploit Sep 2, 2021 - Compro Technology IP Camera - RTSP stream disclosure (Unauthenticated). CVE-2021-40379 . webapps exploit for Hardware platform compro technologyip camerartsp https://www.bitdefender.com/en-us/blog/businessinsights/advisory-react2shell-critical-unauthenticated-rce-in-react-cve-2025-55182 Technical Advisory: React2Shell Critical Unauthenticated RCE in React (CVE-2025-55182) TL;DR Ransomware groups are expected to rapidly weaponize this critical (CVSS 10. technical advisoryreact2shellcriticalunauthenticated https://mail-archive.com/search?l=koha-bugs@lists.koha-community.org&q=subject:%22%5C%5BKoha%5C-bugs%5C%5D+%5C%5BBug+39875%5C%5D+ILL+%5C-+History+check+fails+if+unauthenticated+request%22&o=newest&f=1 subject:"\[Koha\-bugs\] \[Bug 39875\] ILL \- History check fails if unauthenticated request" https://thehackernews.com/2026/01/fortinet-fixes-critical-fortisiem-flaw.html Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Execution Fortinet patches a critical FortiSIEM vulnerability (CVE-2025-64155) that allows unauthenticated remote code execution via exposed phMonitor service. fortinetfixescriticalfortisiemflaw