Security Risk Category

Remote Code Execution Security Risks — Page 8

Published vulnerability pages connected to Remote Code Execution. Each page keeps one canonical URL and focused remediation guidance.

303 published Remote Code Execution risks

Remote Code Execution risks

Showing 253–288 of 303 published risks.

highEPSS 0.012

CVE-2026-53479 Dell PowerProtect Data Domain vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.

CVE-2026-53479network-securityremote-code-executionprivilege-escalation

Updated Jul 12, 2026

highEPSS 0.026

CVE-2026-44454 Coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a provisioned workspace. Any user who supplied a crafted `dotfiles_uri` value (for example, one containing shell command substitution such as `$(...)`) could achieve command execution in their own workspace. The Create Workspace page's `mode=auto` deep links amplified this into a one-click attack: an attacker could craft a URL that prefilled `param.dotfiles_uri` and silently provisioned a workspace with the attacker-controlled value, with no explicit user confirmation. In versions 2.29.7 and 2.30.2, input validation was added to the dotfiles module to reject URIs and usernames containing special characters, and the unsafe `eval`/`sh -c` usage was removed. This eliminated the command injection at its source.

CVE-2026-44454devopsremote-code-executioninput-validation

Updated Jul 12, 2026

highEPSS 0.005

CVE-2026-55427 coder vulnerability

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's `~/.ssh/config` without sanitizing embedded newlines or restricting directives so a malicious or compromised Coder server could inject arbitrary SSH configuration. Practical exploitation requires control of the server-supplied values through a malicious or compromised deployment, a man-in-the-middle position or admin access to the `HostnameSuffix` and `SSHConfigOptions` settings. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `HostnameSuffix` and `SSHConfigOptions` against a strict character set that rejects newlines and other control characters. As a workaround, inspect `coder config-ssh --dry-run` output before applying changes.

CVE-2026-55427network-securitydevopsremote-code-execution

Updated Jul 12, 2026

low

CVE-2026-15035 openllm vulnerability

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd results in command injection. Attacking locally is a requirement. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

CVE-2026-15035remote-code-execution

Updated Jul 11, 2026

highEPSS 0.002

Google Chrome IndexedDB Use-After-Free Code Execution Vulnerability

Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-15107browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Actor Use-After-Free Code Execution Vulnerability

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15116browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Input Use-After-Free Code Execution Vulnerability

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15118browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome WebRTC Use-After-Free Code Execution Vulnerability

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15121browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Forms Inappropriate Implementation Code Execution Vulnerability

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15125browserremote-code-executionauthorization-bypass

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome Forms Use-After-Free Code Execution Vulnerability

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15126browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome V8 Uninitialized Use Code Execution Vulnerability

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15132browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.002

Google Chrome InterestGroups Use-After-Free Code Execution Vulnerability

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-15133browserremote-code-executionmemory-corruption

Updated Jul 10, 2026

highEPSS 0.003

Stanza Model Loader Unsafe Pickle Deserialization RCE Vulnerability

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to torch.load(..., weights_only=False) on attacker-controllable pickle.UnpicklingError, allowing a malicious .pt pretrain or model file to execute arbitrary pickle code when a Stanza NLP pipeline loads it. This issue is fixed in version 1.12.2.

CVE-2026-54499pythonremote-code-executionunsafe-deserialization

Updated Jul 10, 2026

highEPSS 0.001

Cline Hub Dashboard WebSocket Origin Validation Vulnerability

Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. Prior to 3.0.30, the Cline Hub dashboard server launched by the cline dashboard command accepts WebSocket connections on the /browser endpoint without validating the Origin header, and when ROOM_SECRET is unset for local 127.0.0.1 binds, isAuthorizedBrowserRequest() allows attacker-controlled websites to send desktopCommand frames that read workspace state, mutate MCP and provider settings, and trigger command execution when a provider or model is configured. This issue is fixed in version 3.0.30.

CVE-2026-59723browserapi-securityremote-code-execution

Updated Jul 10, 2026

highEPSS 0.001

BOSH CLI Compromised Director Operator Workstation Command Execution Vulnerability

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh scp/bosh logs -f) with default flags. Affected versions: BOSH CLI versions prior to 7.10.5.

CVE-2026-41857network-securitycloud-securityremote-code-execution

Updated Jul 10, 2026

highEPSS 0.003

BOSH CLI OpenSSH Argument Injection Vulnerability

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an operator runs bosh ssh -c, bosh logs -f, or other non-interactive SSH paths, leading to local command execution on the operator's workstation. Affected versions: bosh-cli versions prior to v7.10.4.

CVE-2026-47829network-securitycloud-securityremote-code-execution

Updated Jul 10, 2026

highEPSS 0.007

Popup Maker WordPress Plugin Authorization Bypass RCE Vulnerability

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1/connect/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.

CVE-2026-8848wordpressphpsupply-chainremote-code-execution

Updated Jul 10, 2026

criticalEPSS 0.010

Blocksy Companion Pro Arbitrary File Upload RCE Vulnerability

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.woff2.php to pass MIME validation and be handled as permitted font files. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. This vulnerability is only exploitable when the premium version of the plugin (blocksy-companion-pro) is installed with both the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active; the free blocksy-companion plugin does not contain the vulnerable code paths.

CVE-2026-15158wordpresswoocommercephpremote-code-execution

Updated Jul 10, 2026

high

Bit Form WordPress Plugin Arbitrary File Deletion Vulnerability

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteFiles function in all versions up to, and including, 3.1.1 This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config).

CVE-2026-14372wordpressremote-code-executionpath-traversalfile-write

Updated Jul 10, 2026

critical

Balbooa Forms Joomla Extension Arbitrary File Upload RCE Vulnerability

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVE-2026-56291joomlaphpremote-code-executionfile-upload

Updated Jul 10, 2026

critical

Xerte Online Tools Antivirus Path Remote Code Execution Vulnerability

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.

CVE-2026-12116phpremote-code-execution

Updated Jul 10, 2026

critical

Xerte Online Tools Setup Reinstallation Authentication Bypass RCE Vulnerability

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.

CVE-2026-14261phpremote-code-executionauthentication-bypass

Updated Jul 10, 2026

low

enquirer Public Package API Prototype Pollution Vulnerability

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of object prototype attributes. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report.

CVE-2026-15187npmapi-securityremote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.007

Joomlack Page Builder Improper Access Control Vulnerability

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CVE-2026-56290joomlaremote-code-executionauthorization-bypassfile-upload

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.032

Adobe ColdFusion Path Traversal Vulnerability

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

CVE-2026-48282remote-code-executionpath-traversal

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.012

PTC Windchill and FlexPLM Improper Input Validation Vulnerability

PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.

CVE-2026-12569remote-code-executioninput-validationunsafe-deserialization

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.009

Lantronix EDS5000 Code Injection Vulnerability

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

CVE-2025-67038industrial-controlremote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.786

Ubiquiti UniFi OS Improper Input Validation Vulnerability

Ubiquiti UniFi OS contains an improper input validation vulnerability which could allow a malicious actor with access to the network to conduct command injection.

CVE-2026-34910network-securityremote-code-executioninput-validation

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.990

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

CVE-2026-10520remote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.017

Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

Google Chromium V8 out-of-bounds read and write vulnerability that could allow a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

CVE-2026-11645browsermicrosoftremote-code-executioninformation-disclosure

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.275

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

CVE-2026-45247phpremote-code-executionunsafe-deserialization

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.802

BerriAI LiteLLM Command Injection Vulnerability

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

CVE-2026-42271remote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.846

Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVE-2026-9082drupalapi-securityremote-code-executionsql-injection

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.789

Langflow Origin Validation Error Vulnerability

Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints.

CVE-2025-34291api-securityremote-code-execution

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.988

Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization.

CVE-2008-4250windowsmicrosoftremote-code-executionmemory-corruption

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.509

Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file.

CVE-2009-1537microsoftremote-code-execution

Updated Jul 9, 2026