Application security
59 articles.
CVE-2026-45659: Microsoft SharePoint Server authenticated deserialization RCE, in CISA KEV
A deserialization flaw in on-premises SharePoint Server lets an authenticated attacker run code over the network. It's an 8.8 and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed SharePoint.
CVE-2026-26980: Ghost CMS unauthenticated SQL injection reads the database
A SQL injection flaw in Ghost CMS lets an unauthenticated attacker read arbitrary data straight from the database. A fix is out in 6.19.1. Here's the risk, and how BreachRisk finds exposed Ghost sites.
CVE-2026-26194: Gogs release-deletion argument injection
An argument-injection flaw in Gogs' release-deletion handling lets a low-privileged user smuggle Git options via a crafted tag name. A fix is out in 0.14.2. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2026-22679: Weaver (Fanwei) E-cology unauthenticated RCE via exposed debug endpoint, exploited in the wild
A missing-authentication flaw in Weaver E-cology exposes a debug endpoint that lets an unauthenticated attacker run OS commands — a 9.8 with confirmed in-the-wild exploitation. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-39932: Gogs argument-injection flaws in change preview and release tagging
Two argument-injection flaws in Gogs let an authenticated user smuggle Git options into server-side commands — one during change previews, one during release tagging. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2024-39930: Gogs built-in SSH server argument injection leads to RCE
An argument-injection flaw in the built-in SSH server of Gogs lets an authenticated user run commands on the host. A fix is available. Here's the risk, and how BreachRisk finds exposed Gogs instances.
CVE-2024-42009: Roundcube Webmail cross-site scripting that can steal and send a victim's email
A cross-site scripting flaw in Roundcube's message rendering lets a crafted email read, exfiltrate, and send mail as the victim. It's in CISA's KEV catalog and scored 9.3. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2023-43770: Roundcube Webmail cross-site scripting, used for credential theft
A cross-site scripting flaw in how Roundcube renders links in plaintext email lets an attacker run script in a victim's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2021-44026: Roundcube Webmail SQL injection, exploited by state-linked actors
A SQL injection in Roundcube's search handling lets an authenticated user reach the mail database. It's in CISA's KEV catalog and tied to espionage against webmail servers. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2025-48700: Zimbra Collaboration Classic UI XSS, exploited in the wild
A cross-site scripting flaw in Zimbra's Classic Web Client runs attacker JavaScript when a victim simply views a crafted email — no clicking required. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Zimbra.
CVE-2025-2749: Kentico Xperience path traversal and file upload leading to RCE
A flaw in Kentico Xperience's Staging Sync Server lets an attacker write files to path-relative locations and reach remote code execution. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Kentico.
CVE-2026-20963: Microsoft SharePoint unauthenticated deserialization RCE, actively exploited
A deserialization flaw in on-premises SharePoint lets an unauthenticated attacker run code over the network — a 9.8, in CISA's KEV catalog with a same-week deadline. Here's what to do, and how BreachRisk finds exposed SharePoint.
CVE-2026-22720: VMware Aria Operations stored cross-site scripting, patch available
A stored cross-site scripting flaw in VMware Aria Operations lets a privileged user inject script that runs administrative actions in another user's session. It needs an authenticated foothold, a fix is out, and it isn't being exploited. Here's the honest read, and how BreachRisk finds exposed Aria panels.
CVE-2025-68461: Roundcube Webmail cross-site scripting via SVG animate tag, in KEV
A cross-site scripting flaw via the SVG animate tag lets a crafted email run script in a Roundcube user's session. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2025-49113: Roundcube Webmail post-authentication remote code execution, actively exploited
A PHP object-deserialization flaw lets an authenticated Roundcube user run code on the mail server. It's in CISA's KEV catalog and exploitation went wide within days of disclosure. Here's what to do, and how BreachRisk finds exposed Roundcube instances.
CVE-2023-5631: Roundcube Webmail stored cross-site scripting, exploited as a zero-day by an APT
A stored cross-site scripting flaw via a crafted SVG in HTML email let attackers run script in a Roundcube session. It was exploited as a zero-day for espionage and is in CISA's KEV catalog. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
Exposed SonarQube logins and password spraying
A SonarQube login on the public internet is a standing target for password spraying, and one weak or reused credential turns that exposure into access to source code and CI secrets. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed JFrog logins and password spraying
A JFrog login on the public internet is a standing target for password spraying, and one weak or reused credential can hand an attacker your artifacts, packages, and build outputs. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed Jenkins logins and password spraying
A Jenkins login on the public internet is a standing target for password spraying, and one weak or reused credential turns your build server — and the secrets and source it holds — into an attacker's foothold. Here's the risk, and how BreachRisk safely tests whether those logins hold.
Exposed HCL Volt MX logins and password spraying
An HCL Volt MX login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to your app platform and its data. Here's the risk — and how BreachRisk safely tests whether those logins hold.
Exposed GitLab logins and password spraying
A GitLab login on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into access to source code, secrets, and CI/CD pipelines. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2025-55182: React Server Components unauthenticated RCE via unsafe deserialization
A deserialization flaw in React Server Components lets an unauthenticated attacker send a crafted payload to a Server Function endpoint and execute code. It's a 10.0, it's in CISA KEV, and it reaches a very large install base. Here's what to do, and how BreachRisk finds exposed apps.
CVE-2024-26331: ReCrystallize Server authentication bypass via a spoofable cookie
ReCrystallize Server trusts a cookie value that isn't bound to a real session, so an attacker can set it and walk into the admin interface. Here's the honest risk — and how BreachRisk finds exposed ReCrystallize servers.
CVE-2022-36537: ZK Framework information disclosure, exploited for RCE downstream
A crafted POST to the ZK Framework's AuUploader leaks restricted internal files — and it was chained into remote code execution in products that embed ZK, like ConnectWise R1Soft. It's in CISA's KEV catalog. Here's the risk, and how BreachRisk finds and safely confirms it.
CVE-2024-6782: Calibre content server improper access control leading to unauthenticated RCE
An access-control flaw in Calibre's content server lets an unauthenticated attacker reach privileged functionality and achieve remote code execution — a 9.8 with a public exploit. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2023-2533: PaperCut NG/MF cross-site request forgery, now actively exploited
A cross-site request forgery flaw in PaperCut NG/MF can let an attacker ride a logged-in admin's session to change security settings — or reach code execution. It sat quietly until CISA added it to KEV. Here's what to do, and how BreachRisk finds exposed PaperCut consoles.
CVE-2022-27926: Zimbra Collaboration reflected XSS, exploited by nation-state actors
A reflected cross-site scripting flaw in Zimbra Collaboration's webmail lets an attacker run script in a victim's session with one crafted link — and it was used against government targets. Here's the risk, and how BreachRisk finds and safely confirms exposed Zimbra.
CVE-2023-22527: Atlassian Confluence template injection to unauthenticated RCE, actively exploited
A template-injection flaw in out-of-date Confluence Data Center and Server lets an unauthenticated attacker run code on the instance. It's in CISA's KEV catalog and tied to ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2022-36804: Atlassian Bitbucket command injection, remote code execution, actively exploited
A command-injection flaw in Bitbucket Server and Data Center lets an attacker with read access to a repository — public or private — run code by sending a crafted request. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Bitbucket.
CVE-2022-26138: Atlassian Questions for Confluence hard-coded password, actively exploited
The Questions for Confluence app creates a hidden account with a hard-coded, now-public password — handing any unauthenticated attacker a login. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2023-49070: Apache OFBiz pre-auth remote code execution via legacy XML-RPC
Leftover XML-RPC code in Apache OFBiz gives an unauthenticated attacker a path to remote code execution. It's a critical-class flaw in an ERP platform. Here's what to do, and how BreachRisk finds exposed OFBiz.
CVE-2023-38205: Adobe ColdFusion access-control bypass (the patch-bypass fix), actively exploited
This is the flaw that let attackers slip past the first fix for ColdFusion's access-control bypass and keep reaching administrator endpoints — exploited in the wild and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.
CVE-2023-29300: Adobe ColdFusion unauthenticated deserialization RCE, actively exploited
A deserialization flaw in Adobe ColdFusion lets an unauthenticated attacker run arbitrary code on the server — a 9.8, exploited in the wild to drop web shells, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.
CVE-2023-29298: Adobe ColdFusion access-control bypass, actively exploited
An access-control bypass in Adobe ColdFusion lets an unauthenticated attacker reach administrator endpoints — and in the wild it was the front half of an exploit chain that dropped web shells. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed ColdFusion servers.
CVE-2023-27524: Apache Superset default SECRET_KEY authentication bypass, actively exploited
Apache Superset instances left on the default SECRET_KEY let an attacker forge their own session cookies and log in as any user — often the path to full takeover. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Superset.
CVE-2024-38819: Spring Framework path traversal in functional static-resource routes
A path-traversal flaw in Spring Framework can let an attacker read files off the server — but only when an app serves static resources through the functional web frameworks in a specific way. Here's who's actually affected, and how BreachRisk checks.
CVE-2024-29895: Cacti unauthenticated command injection in the 1.3.x dev branch
A command-injection flaw in Cacti's development branch lets an unauthenticated attacker run OS commands — a 10.0 on paper, but it only affects the unreleased 1.3.x dev code. Here's the real risk, and how BreachRisk finds exposed Cacti.
CVE-2025-32432: Craft CMS unauthenticated remote code execution, exploited in the wild
An unauthenticated remote code execution flaw in Craft CMS — a perfect 10.0 — was exploited in the wild before many sites patched. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Craft installs.
CVE-2025-28367: mojoPortal directory traversal exposing Web.config and the machine key
A directory-traversal flaw in mojoPortal lets an unauthenticated attacker read the Web.config file and lift the ASP.NET machine key. Here's why that matters more than a file read, and how BreachRisk finds exposed mojoPortal.
CVE-2024-56145: Craft CMS remote code execution via register_argc_argv
A remote code execution flaw in Craft CMS affects sites whose PHP has register_argc_argv enabled — a common default. It's in CISA's KEV catalog and being exploited. Here's what to do, and how BreachRisk finds exposed Craft installs.
CVE-2024-4879 (with CVE-2024-5217): ServiceNow Now Platform unauthenticated RCE, actively exploited
Input-validation flaws in the ServiceNow Now Platform let an unauthenticated attacker inject Jelly template code and execute commands. The pair was mass-exploited after disclosure and both are in CISA KEV. Here's what to do, and how BreachRisk finds exposed ServiceNow instances.
CVE-2024-46938: Sitecore unauthenticated arbitrary file read
A path-traversal flaw in Sitecore XP/XM/XC lets an unauthenticated attacker read arbitrary files — including web.config, whose secrets can be turned into remote code execution via ViewState. Here's what to do, and how BreachRisk finds exposed Sitecore servers.
CVE-2024-4358: Progress Telerik Report Server authentication bypass, actively exploited
An unauthenticated attacker can bypass authentication on Progress Telerik Report Server and reach restricted functionality — and it's been chained to remote code execution. It's in CISA KEV. Here's what to do, and how BreachRisk finds exposed servers.
CVE-2024-11680: ProjectSend unauthenticated authentication bypass, actively exploited
An improper-authentication flaw in ProjectSend lets an unauthenticated attacker change the app's configuration, create accounts, and plant web shells. It's a 9.8, mass-exploited, and in CISA KEV. Here's what to do, and how BreachRisk finds exposed ProjectSend instances.
CVE-2024-45507: Apache OFBiz unauthenticated remote code execution
A missing-authorization flaw in Apache OFBiz lets an unauthenticated attacker reach code injection and SSRF — a critical, network-reachable path into an ERP platform. Here's what to do, and how BreachRisk finds exposed OFBiz.
CVE-2024-45195: Apache OFBiz forced-browsing patch bypass to remote code execution, actively exploited
A forced-browsing flaw in Apache OFBiz bypasses earlier patches to reach restricted functionality — and, in practice, code execution. NVD scores it 7.5; the real world put it in KEV. Here's why, and how BreachRisk finds exposed OFBiz.
CVE-2024-38856: Apache OFBiz authorization bypass to remote code execution, actively exploited
An incorrect-authorization flaw in Apache OFBiz lets an unauthenticated attacker reach screen-rendering code and execute commands — it's in CISA's KEV catalog with public exploits. Here's what to do, and how BreachRisk finds exposed OFBiz.
CVE-2024-4956: Sonatype Nexus Repository path traversal, unauthenticated file read
A path-traversal flaw in Sonatype Nexus Repository 3 lets an unauthenticated attacker read system files — with a public exploit and easy discovery. Here's what to do, and how BreachRisk finds and safely confirms exposed servers.
CVE-2024-31982: XWiki unauthenticated remote code execution via database search
A code-injection flaw in XWiki's database search lets any visitor run code on the server through the search text — no login required. It's a 9.8 with a public exploit. Here's what to do, and how BreachRisk finds and safely confirms exposed XWiki.
CVE-2024-37383: Roundcube Webmail cross-site scripting, exploited in government phishing
A cross-site scripting flaw via SVG animate attributes lets a crafted email run script in a Roundcube user's session. It's in CISA's KEV catalog and was used in phishing against government agencies. Here's the risk, and how BreachRisk finds exposed Roundcube instances.
CVE-2024-31849: CData Connect path traversal, unauthenticated admin access
A path-traversal flaw in the Java build of CData Connect running on the embedded Jetty server lets an unauthenticated attacker reach administrative functionality. Rated 9.8 by the reporting researcher. Here's what to do, and how BreachRisk finds exposed CData.
CVE-2022-26134: Atlassian Confluence OGNL injection, unauthenticated RCE, exploited as a zero-day
A second OGNL injection flaw in Confluence Server and Data Center — this one exploited as a zero-day before the patch. Unauthenticated, remote, code execution, a 9.8, and in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2021-26084: Atlassian Confluence OGNL injection, unauthenticated RCE, actively exploited
An OGNL injection flaw in Confluence Server and Data Center lets an unauthenticated attacker run code on the server. It's a 9.8, it's in CISA's KEV catalog, and it was mass-exploited for coin miners and ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.
Exposed Django admin logins and password spraying
A Django administrator portal on the public internet is a standing target for password spraying, and weak or reused credentials turn that exposure into privileged control of the application. Here's the risk — and how BreachRisk safely tests whether those logins hold.
CVE-2024-21683: Atlassian Confluence authenticated remote code execution
A code-injection flaw in Confluence Data Center and Server lets an authenticated user with the right privilege run code on the server via the 'Add a new language' feature. Public exploit code exists. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2023-22515: Atlassian Confluence broken access control, unauthenticated admin creation, actively exploited
A broken-access-control flaw in Confluence Data Center and Server lets a remote attacker create their own administrator account. It was a nation-state zero-day, it's a 9.8, and it's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2022-22965 (Spring4Shell): Spring Framework RCE on Tomcat WAR deployments, actively exploited
Spring4Shell lets an unauthenticated attacker execute code against Spring MVC/WebFlux apps on JDK 9+ deployed as a WAR on Tomcat. It's in CISA's KEV catalog. Here's what to do, and how BreachRisk finds exposed Spring apps.
CVE-2019-3396: Atlassian Confluence Widget Connector template injection, unauthenticated RCE
A server-side template injection flaw in the Confluence Widget Connector macro lets an unauthenticated attacker read files and run code on the server. It's a 9.8, it's in CISA's KEV catalog, and it was used to deliver ransomware. Here's what to do, and how BreachRisk finds exposed Confluence.
CVE-2025-24893: XWiki unauthenticated RCE via SolrSearch, actively exploited
A code-injection flaw in XWiki's SolrSearch lets any guest run code on the server with a single unauthenticated request. It's a 9.8, it's in CISA KEV, and EPSS is near the ceiling. Here's what to do, and how BreachRisk finds and safely confirms exposed XWiki.