Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

type:rce — CVE vulnerabilities tagged 14730

14730 CVE security advisories tagged "type:rce" with AI Chinese analysis, CVSS, references and POCs.

The tag "type:rce" identifies vulnerabilities classified as Remote Code Execution, a critical security flaw allowing attackers to execute arbitrary commands on a target system over a network without prior authentication. This class matters profoundly because it often grants full control over the affected machine, enabling data theft, system compromise, or lateral movement within an organization’s infrastructure. Typical scenarios involve exploiting flaws in web applications, network services, or APIs where input validation is insufficient, allowing malicious payloads to bypass security controls. With over twelve thousand such CVEs documented, RCE remains a persistent threat vector, highlighting the urgent need for rigorous input sanitization, secure coding practices, and continuous monitoring to prevent unauthorized access and mitigate severe operational disruptions across diverse digital environments.

CVE ID Title CVSS Severity Published
CVE-2026-86189 WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php — AVideo CWE-73 9.8 Critical 2026-09-05
CVE-2026-10196 Mail Mint <= 1.31.0 - Unauthenticated PHP Object Injection in Arbitrary Form Fields — Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails CWE-502 9.8 Critical 2026-09-05
CVE-2026-86169 Axolotl through 0.18.0 Remote Code Execution via Multipack Patching — axolotl CWE-829 8.8 High 2026-09-05
CVE-2026-86124 AutoAgent Unauthenticated Remote Code Execution via the Sandbox TCP Command Server — AutoAgent CWE-306 9.8 Critical 2026-09-05
CVE-2026-86121 Cua computer-server before 0.3.42 Unauthenticated RCE via Desktop Control — cua-computer-server CWE-306 9.8 Critical 2026-09-05
CVE-2026-19887 Welcart e-Commerce <= 2.12.1 - Unauthenticated Arbitrary File Deletion via PHP Object Injection via 'reserve' Checkout Parameter and 'option' EDY Callback — Welcart e-Commerce CWE-502 8.8 High 2026-09-05
CVE-2026-84898 Eventin < 4.1.21 - Contributor+ LFI via Event Layout Meta — Eventin - - 2026-09-05
CVE-2026-83627 Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug Log — Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN CWE-94 9.8 Critical 2026-09-05
CVE-2026-86145 PCRE2 10.48 之前 pcre2_dfa_match 越界写漏洞 — PCRE2 CWE-424 8.2 High 2026-09-05
CVE-2026-52777 YesWiki: Authenticated PHP Object Injection in BazarImportAction via unserialize — yeswiki CWE-352 9.4 Critical 2026-09-04
CVE-2026-52762 YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates — yeswiki CWE-1336 7.1 High 2026-09-04
CVE-2026-75925 IXON VPN Client CRLF Injection — IXON VPN Client CWE-93 9.6 Critical 2026-09-04
CVE-2026-78327 SonicWall NSM命令注入致远程代码执行漏洞 — Network Security Manager (NSM) CWE-78 - - 2026-09-04
CVE-2026-9317 Nango < 0.71.6 Missing Authentication RCE via runner tRPC server — nango CWE-306 8.1 High 2026-09-04
CVE-2026-53757 Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE — emlog CWE-22 6.9 Medium 2026-09-04
CVE-2026-61686 SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop — SolidInvoice CWE-502 7.5 High 2026-09-04
CVE-2026-18658 IBM Operational Decision Manager for Aug 2026 - Multiple CVEs addressed — Operational Decision Manager CWE-89 9.8 Critical 2026-09-04
CVE-2026-19298 Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint — Langflow OSS CWE-94 8.8 High 2026-09-04
CVE-2026-44402 Voltronic Power SNMP Web Pro 1.1 Unauthenticated RCE via upload.cgi — SNMP Web Pro CWE-434 9.8 Critical 2026-09-04
CVE-2026-85694 LaVague 0.2.35 Remote Code Execution via eval extraction — LaVague CWE-94 8.1 High 2026-09-04
CVE-2026-85690 Plandex 2.2.1 Path Traversal via ApplyFiles — plandex CWE-22 7.8 High 2026-09-04
CVE-2026-85688 TEN Framework 0.11.71 Unauthenticated File Read/Write via TMAN Designer — ten-framework CWE-306 9.8 Critical 2026-09-04
CVE-2026-85623 goose 1.37.0 Arbitrary Command Execution via Recipe Extensions — goose CWE-94 8.8 High 2026-09-04
CVE-2026-12483 LearnDash LMS <= 5.1.5 - Authenticated (Subscriber+) Arbitrary File Upload via Assignment Upload Handler — LearnDash LMS CWE-434 7.5 High 2026-09-04
CVE-2026-85610 OpenPanel before 2.3.0 Remote Code Execution via chart formulas — openpanel CWE-94 8.8 High 2026-09-04
CVE-2026-85604 Grav before 2.0.18 Remote Code Execution via sort filter — grav CWE-94 8.8 High 2026-09-04
CVE-2026-82923 AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes — AI Website Builder (GitHub build) 9.8 Critical 2026-09-04
CVE-2026-62928 XING CPTrans-ME-X 未认证 OS 命令注入漏洞 — XING CPTrans-ME-X CWE-78 9.3 Critical 2026-09-04
CVE-2026-19224 Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite — Hummingbird Performance - - 2026-09-04
CVE-2026-85507 FreeIPMI 1.6.19 栈缓冲区溢出 — FreeIPMI CWE-121 9.8 Critical 2026-09-04

Vulnerabilities classified as type:rce represent 14730 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.