Threats Tagged 'cwe-74'
View all threats tagged with 'cwe-74'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-74'
Click on any threat for detailed analysis and mitigation recommendations
0 The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated users to execute arbitrary shortcodes registered on the site. Join the discussion | CVE Database V5 | 09/21/2026, 08:51:51 UTC Added: 09/21/2026, 09:02:04 UTC |
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. escapeshellcmd() escapes shell metacharacters but does not prevent argument injection because spaces remain as argument separators, and the filename sanitization applied at the database layer is never applied to the physical temporary file path used for ImageMagick processing. Join the discussion | CVE Database V5 | 09/19/2026, 02:27:09 UTC Added: 09/19/2026, 02:47:05 UTC |
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 09/17/2026, 22:55:57 UTC Added: 09/17/2026, 23:03:04 UTC |
0 A vulnerability in Sentry Seer allows attacker-controlled input submitted via a public telemetry endpoint to be executed in a privileged coding-agent environment. This occurs when Seer is configured to automatically hand off issues to a coding agent for remediation. Malicious event data can propagate through Seer's analysis pipeline and cause the coding agent to execute attacker-controlled code before any human review. No vendor patch is currently available. Join the discussion | CERT/CC | 09/16/2026, 15:45:47 UTC Added: 09/16/2026, 15:26:39 UTC |
The Formidable Forms WordPress plugin before 6.35 does not prevent a request-derived value from reaching the WordPress shortcode parser when it substitutes a supported token into a form's custom HTML, allowing unauthenticated visitors to have arbitrary shortcodes, with attacker-chosen attributes, executed server-side on any page displaying an affected form. Join the discussion | CVE Database V5 | 09/16/2026, 06:30:05 UTC Added: 09/16/2026, 06:47:17 UTC |
canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the scheme and contentId values used by GetContentDetailsRequest. When a consuming application supplies an untrusted path variable value, path traversal sequences, query delimiters, or fragment delimiters can change the destination endpoint before AbstractEndpoint::sendRequest() attaches the configured authentication token. An attacker who controls that path variable value through the consuming application can cause unintended reads or writes with the configured application's privileges on the same Canto instance, but applications that pass only trusted and validated identifiers are not exploitable. This issue is fixed in version 3.0.0. Join the discussion | CVE Database V5 | 09/15/2026, 17:33:14 UTC Added: 09/15/2026, 17:48:27 UTC |
IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party services. Join the discussion | CVE Database V5 | 09/15/2026, 17:20:42 UTC Added: 09/15/2026, 17:32:26 UTC |
0 IBM MQ 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 LTS, and 10.0.0.0 could allow a remote attacker to execute arbitrary code due to unsafe JNDI lookup processing when the IVT application is deployed. Join the discussion | CVE Database V5 | 09/15/2026, 17:14:32 UTC Added: 09/15/2026, 17:32:28 UTC |
0 IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an attacker to perform JNDI injection attacks due to insufficient input validation, potentially leading to information disclosure or remote code execution. Join the discussion | CVE Database V5 | 09/15/2026, 17:12:54 UTC Added: 09/15/2026, 17:32:29 UTC |
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled service.name resource attribute in exporter/sentryexporter/sentry_exporter.go through extractProjectSlug and getOrCreateProjectEndpoint, passes the raw project slug to GetOTLPEndpoints and GetProjectKeys in exporter/sentryexporter/sentry_client.go, and interpolates it into a Sentry API URL without applying projectSlugRegexp through validateRoutingConfig at runtime in exporter/sentryexporter/config.go. Special characters can turn the expected path suffix into query data in all deployments or introduce slash and dot segments that traverse paths when the Sentry deployment normalizes them, while the Collector attaches its operator-configured bearer token to the request. A successful request can reach token-authorized administrative, organization, member, or key endpoints within the configured Sentry organization, and an attacker-controlled project slug can redirect subsequently exported telemetry. Sentry token middleware prevents cross-organization access. This issue is fixed in version 0.154.0. Join the discussion | CVE Database V5 | 09/14/2026, 17:28:15 UTC Added: 09/14/2026, 17:48:39 UTC |
Showing 1 to 10 of 241 results