RaptorIQ public source records
Interactive workspace · Geographic evidence JSON example
Stored source records, not a claim of real-time or complete coverage. Publication dates and ingestion dates are separate. Geographic registry populations are snapshots; verified combat ingestion is not yet available.
Retrieved: 2026-09-21T12:27:44.879Z. Up to 25 matching records.
CVE-2026-48449: Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code…
Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS 3.1 base score: 10
Status: Analyzed
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-07-30T03:16:24.957Z. Ingested: 2026-08-18T23:08:38.513Z.
Original source
CVE-2026-57719: Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Mal…
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through <= 2.8.3.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-07-13T10:16:38.970Z. Ingested: 2026-08-16T04:01:43.000Z.
Original source
CVE-2026-54917: SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the …
SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path with util.JoinPath (S3) / path.Join (Iceberg), which collapse the .. server-side, so the actual read or write lands in evil-bucket. This vulnerability is fixed in 4.30.
CVSS 3.1 base score: 10
Status: Analyzed
WHY IT MA
Source: nvd-cve-bulk. Record date: 2026-06-25T19:16:42.230Z. Ingested: 2026-08-15T22:58:29.681Z.
Original source
CVE-2026-12485: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-24T05:17:25.973Z. Ingested: 2026-08-15T21:58:34.755Z.
Original source
CVE-2025-71338: Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth…
Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts.
CVSS 3.1 base score: 10
Status: Analyzed
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-25T22:16:59.520Z. Ingested: 2026-08-16T00:04:05.494Z.
Original source
CVE-2026-60365: Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Serve…
Vulnerability in the Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: WebLogic Server Proxy Plug-In for Third-Party Web Servers). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Weblogic Server Proxy Plug-in accessible data as we
Source: nvd-cve-bulk. Record date: 2026-07-21T22:17:39.860Z. Ingested: 2026-08-16T00:32:53.637Z.
Original source
CVE-2026-61447: PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-…
PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LLM output through prompt injection to exfiltrate all environment secrets and execute arbitrary code on the host system.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-07-11T14:16:23.377Z. Ingested: 2026-08-16T03:46:47.341Z.
Original source
CVE-2026-12847: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-24T05:17:26.587Z. Ingested: 2026-08-15T21:58:34.821Z.
Original source
CVE-2026-56413: Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens …
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted packet containing a malicious payload that is processed without adequate sanitization, resulting in arbitrary command execution with root-level privileges.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-30T23:17:32.027Z. Ingested: 2026-08-15T22:13:25.745Z.
Original source
CVE-2026-54309: n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP tra…
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any website visited by the user, can establish an MCP session and invoke browser-control tools. Where the n8n AI Browser Bridge extension is installed and a browser connection is active, an unauthenticated caller can access browser-control capabilities including navigation, JavaScript evaluation, and cookie and storage access against the user's real browser profile. This issue only affects instances where @n8n/mcp-browser is
Source: nvd-cve-bulk. Record date: 2026-06-23T16:17:01.860Z. Ingested: 2026-08-15T22:13:25.450Z.
Original source
CVE-2026-56415: Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable…
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input sanitization, resulting in arbitrary command execution with root-level privileges on the underlying system.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-30T23:17:32.157Z. Ingested: 2026-08-15T22:58:29.916Z.
Original source
CVE-2026-57624: Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-07-02T12:17:37.277Z. Ingested: 2026-08-15T22:58:29.793Z.
Original source
CVE-2026-53622: Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/…
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI value, which fails to match wildcard host patterns (e.g., *.example.com) or case variants of the configured hostname. Because the handshake falls back to the default TLS configuration — which may not require client certificates — a client can complete the QUIC handshake without presenting a certificate, while t
Source: nvd-cve-bulk. Record date: 2026-06-23T20:16:48.777Z. Ingested: 2026-08-15T22:13:25.588Z.
Original source
CVE-2026-48020: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulner…
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware, a request path containing .. or its percent-encoded form %2e%2e can match the public route at routing time and then, after the prefix is stripped and the path is normalized, resolve to a path served by a separate, authenticated router. As a result, an attacker can reach protected backend paths — such as admin or internal configuration endpoints — w
Source: nvd-cve-bulk. Record date: 2026-06-23T20:16:47.993Z. Ingested: 2026-08-15T22:13:25.691Z.
Original source
CVE-2026-12846: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-24T05:17:26.463Z. Ingested: 2026-08-15T21:58:34.942Z.
Original source
CVE-2026-48491: Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr…
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with stricter TLS options (for example RequireAndVerifyClientCert), SNICheck resolves the TLS options for the HTTP Host header using exact map lookups only and never applies wildcard matching. If another permissive SNI is served on the same entrypoint, an attacker can complete the TLS handshake under the permissive options and then send an HTTP Host header tar
Source: nvd-cve-bulk. Record date: 2026-06-23T20:16:48.123Z. Ingested: 2026-08-15T22:13:25.696Z.
Original source
CVE-2026-60366: Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Third…
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR
Source: nvd-cve-bulk. Record date: 2026-07-22T23:16:35.757Z. Ingested: 2026-08-16T00:32:53.612Z.
Original source
CVE-2026-57811: Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-est…
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through <= 5.2.0.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-07-13T10:16:45.040Z. Ingested: 2026-08-16T03:02:01.016Z.
Original source
CVE-2026-60379: Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp…
Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform. While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS 3.1 base sc
Source: nvd-cve-bulk. Record date: 2026-07-21T22:17:40.597Z. Ingested: 2026-08-16T00:32:53.687Z.
Original source
CVE-2026-60360: Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers…
Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. While the vulnerability is in Oracle Unified Directory, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS 3.1 base score: 10
Statu
Source: nvd-cve-bulk. Record date: 2026-07-21T22:17:39.293Z. Ingested: 2026-08-16T00:32:53.681Z.
Original source
CVE-2026-47056: Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported ve…
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator. While the vulnerability is in Oracle Data Integrator, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
CVSS 3.1 base score: 10
Status: A
Source: nvd-cve-bulk. Record date: 2026-07-21T22:17:11.370Z. Ingested: 2026-08-16T00:32:53.663Z.
Original source
CVE-2026-63795: In the Linux kernel, the following vulnerability has been resolved:
In the Linux kernel, the following vulnerability has been resolved:
CVSS 3.1 base score: 10
Status: Analyzed
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-07-19T12:16:51.910Z. Ingested: 2026-08-16T00:32:53.651Z.
Original source
CVE-2026-12848: GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48…
GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-24T05:17:26.710Z. Ingested: 2026-08-15T21:58:34.763Z.
Original source
CVE-2026-57700: Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.
CVSS 3.1 base score: 10
Status: Deferred
WHY IT MATTERS: Imported NVD CVE bulk slice — prioritize alongside CISA KEV for patch planning; not a live exploitability signal.
IMPACT: CVSS CRITICAL
SEVERITY: HIGH
Source: nvd-cve-bulk. Record date: 2026-06-25T19:16:45.973Z. Ingested: 2026-08-15T22:58:29.895Z.
Original source
CVE-2026-66012: SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated onl…
SiYuan before v3.7.2 contains a missing authorization vulnerability in the POST /mcp kernel endpoint, which is gated only by a general auth check (model.CheckAuth) with no admin-role or read-only enforcement. This exposes 31 MCP tools, including a file tool with list/read/write/delete/rename/copy actions across the entire workspace. When the Publish server is enabled in anonymous mode (Conf.Publish.Enable=true and Conf.Publish.Auth.Enable=false), the Publish reverse proxy attaches an anonymous RoleReader JWT to proxied requests, allowing a remote unauthenticated attacker to reach /mcp. The attacker can read conf/conf.json to extract accessAuthCode, api.token, and cookieKey in plaintext, writ
Source: nvd-cve-bulk. Record date: 2026-07-25T11:17:19.053Z. Ingested: 2026-08-16T00:32:53.690Z.
Original source