Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85109 – Remote Buffer Overflow / DoS (potential RCE) – Tenda HG10 (firmware HG7_HG9_HG10re_

CVE-2026-85109 is a buffer overflow vulnerability in the formLogin function of the Boa web server component in Tenda HG10 firmware version 300001138. Remote, unauthenticated attackers can send a crafted Username parameter to /boaform/formLogin to overflow a fixed-size buffer, with confirmed denial-of-service impact and potential for remote code execution. The exploit has been publicly disclosed.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85180 – Server-Side Request Forgery (SSRF) – Ollama 0.30.0 through 0.33.2

CVE-2026-85180 is a Server-Side Request Forgery (SSRF) vulnerability in Ollama, an API server used to run large language models. It affects versions 0.30.0 through 0.33.2 and stems from insufficient validation of redirect destinations when the server pulls tensor-layer model blobs. The flaw is rated High severity (CVSS 8.7) and requires no authentication or user interaction to exploit.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85199 – Unauthenticated Path Traversal (Arbitrary File Read/Write/Delete) – Eclipse aeriOS

CVE-2026-85199 is a path traversal vulnerability (CWE-22/CWE-23) in the REST API of Eclipse aeriOS Self-orchestrator versions prior to 1.2.1. User-controlled resource identifiers used when creating, updating, or deleting Self-orchestrator resources are concatenated directly into filesystem paths without validation or normalization, allowing an attacker to escape the intended storage directory. The flaw is rated HIGH severity (CVSS 8.8) and is especially dangerous because the affected API endpoints require no authentication and the Self-orchestrator service runs with elevated (root) privileges.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85181 – Authentication Bypass / Admin Session Forgery – Dianping CAT ≤ 3.1.0

CVE-2026-85181 is a critical authentication bypass vulnerability in Dianping's CAT (a Java-based application performance monitoring platform), rated 9.8 (CVSS v3.1). The flaw allows an unauthenticated network attacker to forge a valid administrator session cookie entirely offline, because CAT's session integrity check relies solely on Java's unkeyed String.hashCode() function combined with a client-controlled X-Forwarded-For header used for IP validation. Successful exploitation grants full administrative access to CAT's configuration console with no prior authentication or user interaction required.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85216 – Authentication Bypass (LDAP/LinOTP) – MISP ≤ 2.5.45

CVE-2026-85216 is a critical authentication bypass vulnerability in MISP (Malware Information Sharing Platform), affecting the platform's LDAP and LinOTP authentication plugins in versions up to and including 2.5.45. The flaw allows an attacker who knows a valid directory user's email address to authenticate as that user by submitting an empty password, potentially gaining administrative access. The vulnerability carries a CVSS score of 9.5 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-78080 – Unauthenticated SQL Injection – JooDatabase Lite for Joomla (versions 1.0–5.0.0)

CVE-2026-78080 is an unauthenticated SQL injection vulnerability in the JooDatabase Lite extension for Joomla, caused by improper neutralization of special elements (CWE-89) in the cid parameter. The flaw allows any remote, unauthenticated attacker to inject arbitrary SQL into backend database queries. It carries a CRITICAL severity rating of 9.3.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-77999 – Unauthenticated Payment Fraud via PayPal IPN Forgery – J2Store Joomla Extension 1.0

CVE-2026-77999 is a critical logic flaw in the J2Store Joomla e-commerce extension's PayPal payment-confirmation handling. An unauthenticated attacker can forge PayPal Instant Payment Notification (IPN) callbacks to fraudulently move orders to a "CONFIRMED" state without making any payment, or to force legitimate pending orders into a "FAILED" state. The issue carries a CVSS score of 8.7 (High) and affects multiple major J2Store release lines.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85154 – Authentication Bypass / Full Account Takeover – WWBN AVideo ≤ 29.0

CVE-2026-85154 is an authentication/privilege management flaw in WWBN AVideo, an open-source video platform. The video_id_hash value, intended only as a per-video authorization token, functions as a non-expiring, non-revocable bearer credential that grants a full administrator-level logged-in session as the video's owner. This vulnerability is rated CRITICAL, with a CVSS v3.1 score of 9.8 and a CVSS v4.0 score of 9.3.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-80465 – Authentication Bypass / Account Hijacking – Mendix SAML Module (Mendix 9.24, 10, 11

CVE-2026-80465 is a high-severity (CVSS 8.7) improper cryptographic signature verification flaw (CWE-347) in the Mendix SAML module. Affected versions fail to properly validate the signature on SAML responses, allowing an unauthenticated remote attacker to hijack a legitimate user's session in specific SSO configurations. The issue affects the Mendix SAML module compatible with Mendix 9.24, 10, and 11.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-85155 – Unauthenticated SQL Injection (Ordering Oracle) – WWBN AVideo ≤ current (commit e01

CVE-2026-85155 is a SQL injection vulnerability in WWBN AVideo affecting the get.json.php API endpoint when called with APIName=channels. An unauthenticated attacker can control the sort-column parameter of the underlying query, allowing arbitrary database columns—including sensitive user table fields—to be used for result ordering. The issue is rated high severity due to its unauthenticated network attack vector and resulting sensitive information exposure.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-73475 – Authorization Bypass Allowing Fraudulent Order Completion – Drupal Commerce PayPal

CVE-2026-73475 is an incorrect authorization (CWE-863) vulnerability in the Commerce PayPal module for Drupal Commerce, rated Critical with a CVSS v3.1 base score of 9.1. The module fails to sufficiently validate the transaction result returned by PayPal in certain flows, allowing an unauthenticated attacker to force-browse to order-completion logic and mark a transaction as paid without ever completing payment. The issue is scoped to sites using the Payflow Link payment gateway.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-19117 – FIDO2 Authentication Bypass – Delinea Secret Server (On-Prem) 10.6.0–12.1.2

CVE-2026-19117 is a critical authentication bypass vulnerability (CWE-290, spoofing) in Delinea Secret Server on-premises deployments. Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and subsequently authenticate as that user, gaining full account takeover without prior credentials or user interaction. The issue carries a CVSS v3.1 base score of 9.8 (Critical) and affects on-prem installations only — cloud/SaaS deployments are not impacted.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51705 – Unauthenticated Access Control Bypass (RCE-adjacent Config Tampering) – TOTOLINK T6

CVE-2026-51705 is a critical improper access control vulnerability affecting the TOTOLINK T6 wireless router running firmware version 4.1.5cu.748_B20211015. The flaw resides in the setWiFiMeshName function exposed via the device's /cgi-bin/cstecgi.cgi endpoint, and allows a completely unauthenticated, remote attacker to rename mesh network entries on the device. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), reflecting its network attack vector, low complexity, and lack of any authentication or user interaction requirement.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-83548 – Pre-Auth SSRF (Chained to RCE) – SonicWall SMA1000

CVE-2026-83548 is a critical, pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Work Place interface of SonicWall SMA1000 secure remote access appliances. An unauthenticated remote attacker can abuse the appliance as an unintended proxy to reach sensitive internal functionality and perform unauthorized operations. SonicWall rates the flaw 10.0 (Critical) and has confirmed active exploitation in the wild.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-79756 – Unauthenticated OS Command Injection (RCE) – Nuclio Dashboard (Local/Docker Platfor

CVE-2026-79756 is an unauthenticated OS command injection vulnerability in the Nuclio dashboard's "list-all" resource endpoint, rated HIGH severity (CVSS 8.7). It exists because an earlier fix for a related command injection issue quoted the named-resource shell command path but left the wildcard (list-all) path unquoted, allowing attackers to inject shell metacharacters via HTTP headers and execute arbitrary commands inside the dashboard container.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51733 – Unauthenticated Configuration Tampering – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51733 is an incorrect access control vulnerability in the FirmwareUpgrade function of the TOTOLINK T6 wireless router, firmware 4.1.5cu.748_B20211015. It allows a remote, unauthenticated attacker to send a crafted HTTP POST request to the device's management CGI interface and remove Wi-Fi schedule entries without any credentials. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51723 – Unauthenticated Malicious CGI Module Installation – TOTOLINK T6 4.1.5cu.748_B202110

CVE-2026-51723 is an incorrect access control vulnerability in the UploadCustomModule function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. The flaw allows an unauthenticated attacker to install a custom CGI module on the device by sending a crafted POST request to /cgi-bin/cstecgi.cgi. It carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51728 – Unauthenticated Firmware Upload / RCE – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51728 is a critical improper access control vulnerability (CWE-284) in the UploadFirmwareFile function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. The flaw allows an unauthenticated, remote attacker to upload an arbitrary crafted firmware image to the device via the CGI management interface. Given a CVSS v3.1 base score of 9.8 (Critical), successful exploitation can fully compromise device confidentiality, integrity, and availability.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-53611 – Unauthenticated Remote Code Execution – Looking Glass (AS203038) < 1.3.5

CVE-2026-53611 is a critical OS command injection vulnerability in Looking Glass, a network diagnostic platform (developed by AS203038) that exposes ping, traceroute, and BGP lookup functionality via a gRPC API and web UI. The flaw resides in the BGP AS-path input validation logic and allows an unauthenticated remote attacker to execute arbitrary operating system commands on the underlying host. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51684 – Unauthenticated Access Control Bypass (Service State Tampering) – TOTOLINK T6 Firmw

CVE-2026-51684 is a critical improper access control vulnerability (CWE-284) in the setStorageCfg function of TOTOLINK T6 router firmware version 4.1.5cu.748_B20211015. The flaw allows unauthenticated remote attackers to alter the router's storage-related service state by sending a crafted POST request to the device's CGI endpoint. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51690 – Unauthenticated WAN Configuration Tampering – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51690 is an improper access control vulnerability in the setWanCfg function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. It allows an unauthenticated, remote attacker to send a crafted POST request to the device's CGI handler and alter the router's upstream (WAN) provisioning and connectivity settings. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51934 – Remote Code Execution via Stack Buffer Overflow – Tenda A18 (Firmware v15.13.07.09)

CVE-2026-51934 is a critical buffer overflow vulnerability affecting the Tenda A18 wireless router running firmware version 15.13.07.09. The flaw resides in the fromSetCmdlineRun function, which is reachable via an HTTP request handler and does not validate the size of attacker-supplied input before copying it into a fixed-size buffer. Because the vulnerability requires no authentication or user interaction and is exploitable over the network, it carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51738 – Unauthenticated Configuration Reset / DoS – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51738 is an improper access control vulnerability (CWE-284) in the LoadDefSettings function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. An unauthenticated remote attacker can send a crafted POST request to the device's CGI interface to force a factory reset and reboot of the router. The flaw carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51689 – Unauthenticated Firmware-Upgrade Manipulation – TOTOLINK T6 4.1.5cu.748_B20211015

CVE-2026-51689 is an incorrect access control vulnerability (CWE-284) in the setUpgradeFW function of the TOTOLINK T6 router firmware. It allows an unauthenticated, remote attacker to send a crafted POST request to the device's CGI endpoint and trigger changes to the firmware-upgrade workflow. The flaw carries a CVSS v3.1 base score of 9.1 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-52111 – Authentication Bypass / Privilege Escalation – fast-note-sync-service ≤2.13.7

CVE-2026-52111 is a critical improper access control vulnerability in fast-note-sync-service, a self-hosted note synchronization and REST API backend, affecting versions 2.13.7 and earlier. The flaw allows a remote, unauthenticated attacker to escalate privileges and ultimately impersonate any user, including administrators, by abusing an admin configuration endpoint that exposes JWT signing material. The issue has a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51687 – Unauthenticated Guest Wi-Fi Configuration Tampering – TOTOLINK T6 (Firmware 4.1.5cu

CVE-2026-51687 is an improper access control vulnerability (CWE-284) in TOTOLINK T6 router firmware 4.1.5cu.748_B20211015. The setWiFiEasyGuestCf function in the router's /cgi-bin/cstecgi.cgi endpoint fails to enforce authentication, allowing unauthenticated network attackers to create or weaken the device's guest wireless network configuration. The flaw carries a Critical CVSS v3.1 base score of 9.1.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-51691 – Unauthenticated Access Control Bypass (Firmware Upload/Flash Manipulation) – TOTOLI

CVE-2026-51691 is an incorrect access control vulnerability (CWE-284) in the setUploadSetting function of TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015. The flaw allows a remote, unauthenticated attacker to manipulate the device's upload or firmware flash workflow by sending a crafted POST request to the device's management CGI interface. It carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-18329 – Authentication/Authorization Bypass – NGINX JavaScript (njs/qjs) ngx_http_js_module

CVE-2026-18329 is an authentication/authorization bypass vulnerability (CWE-636, "Not Failing Securely") affecting the ngx_http_js_module in NGINX JavaScript (njs), when used with the QuickJS (qjs) engine. When an unhandled exception occurs during asynchronous processing of a js_access handler, the access-control phase can fail open instead of denying the request, allowing unauthenticated attackers to bypass access controls. The flaw carries a CVSS v3.1 base score of 8.2 (High) and was publicly disclosed on August 19, 2026, with the CVE published September 2, 2026.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-78689 – Heap Buffer Overflow / DoS (RCE Not Ruled Out) – NGINX JavaScript (njs) 0.7.10 thro

CVE-2026-78689 is a high-severity heap-based buffer overflow (CWE-122) in NGINX JavaScript (njs), affecting the ngx_http_js_module's XML namespace prefix list parser reachable through the xml.exclusiveC14n() method. An unauthenticated, remote attacker can trigger an out-of-bounds heap write by supplying a crafted XML namespace prefix list to an affected configuration, causing NGINX worker crashes or unbounded worker memory growth; F5 states code execution "has not been demonstrated" but "cannot be ruled out." The issue carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 score of 9.2 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2025-15485 – Missing Authorization / Unauthenticated Settings Manipulation – Auto x LINE WordPre

CVE-2025-15485 is a missing authorization (CWE-862) vulnerability in the Auto x LINE WordPress plugin, affecting all versions through 1.0.0. Several of the plugin's REST API endpoints fail to enforce authorization checks, allowing completely unauthenticated attackers to modify plugin settings, create fraudulent entries, and clear or access activity logs. The flaw carries a CVSS v3.1 base score of 8.2 (High) and is remotely exploitable with low attack complexity and no user interaction.

Created Date
Source IONIX Agentic Threat Center
CVE-2025-9314 – Unauthenticated Arbitrary File Upload (RCE risk) – Developer Tools WordPress Plugin

CVE-2025-9314 is a critical unauthenticated arbitrary file upload vulnerability (CWE-434) in the Developer Tools WordPress plugin, versions through 1.1.3. The flaw resides in the plugin's bundled SWFUpload component and allows any unauthenticated attacker to upload arbitrary files to the server, which can lead to full site compromise. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical).

Created Date
Source IONIX Agentic Threat Center
CVE-2026-4357 – Unauthenticated Arbitrary File Upload (RCE) – Embed HTML5 Game WordPress Plugin ≤ 1.

CVE-2026-4357 is a critical unrestricted file upload vulnerability (CWE-434) in the Embed HTML5 Game WordPress plugin, affecting all versions through 1.3. The plugin fails to enforce access control or file-type restrictions on its upload functionality, allowing unauthenticated attackers to upload arbitrary PHP files. Successful exploitation can lead to full remote code execution and complete compromise of the affected WordPress site.

Created Date
Source IONIX Agentic Threat Center
CVE-2026-81294 – Unauthenticated Privilege Escalation – Authorizer WordPress Plugin ≤ 3.15.1

CVE-2026-81294 is a critical unauthenticated privilege escalation vulnerability affecting the Authorizer plugin for WordPress, caused by incorrect privilege assignment (CWE-266). The flaw allows an unauthenticated attacker to escalate privileges on the affected site over the network, with no user interaction required. It carries a CVSS v3.1 base score of 9.8 (Critical) and impacts confidentiality, integrity, and availability.

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge