Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'code-execution'

View all threats tagged with 'code-execution'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: code-execution

Threats Tagged 'code-execution'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-39949: Authenticated Remote Code Execution in Cacti ≤ 1.2.30CVE-2026-39949
0

CVE-2026-39949 is an authenticated remote code execution vulnerability in Cacti versions up to and including 1.2.30. The flaw arises from unsanitized variable substitution in RRDtool command-line arguments, allowing users with graph management privileges to inject arbitrary OS commands via host metadata fields such as the device notes. Exploitation requires authenticated access with permissions to create devices and graph templates. An attacker can craft malicious input in the notes field and trigger code execution during graph rendering.

Join the discussion
Hackers Exploit Langflow Vulnerability for Remote Code Execution
0

A high-severity vulnerability (CVE-2026-5027) in the Langflow low-code AI development platform allows unauthenticated attackers to write files to arbitrary locations via a path traversal flaw in the 'POST /api/v2/files' endpoint. This flaw enables remote code execution (RCE) because the filename parameter is not sanitized, and Langflow's default unauthenticated auto-login allows attackers to reach the vulnerable endpoint without credentials. Exploitation attempts have been observed in the wild, with attackers dropping test files on victim systems. Approximately 7,000 Langflow instances are internet-accessible, mostly in North America. The vulnerability was publicly disclosed in March 2026, and no patch or official fix information is provided in the source content.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: code-execution
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses