Vulnerability Trends — Top Exploited CVEs and Zero-Days | dbugs

#1 · PT-2025-48817 · Meta · React-Server-Dom-Turbopack

CVE-2025-55182

·

Published

2025-12-03

·

Updated

2026-08-27

10

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions React Server Components versions 19.0.0 through 19.2.0
Description A pre-authentication remote code execution issue exists in the react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack packages. The flaw is caused by the unsafe deserialization of payloads in the requireModule() function when processing the hasOwnProperty parameter during...
More

Exploit

Fix

LPE

DoS

RCE

Deserialization of Untrusted Data

2.0 K Posts
8.9 KReposts
10.1 M Audience
Graph

#2 · PT-2026-71124 · Jfrog · Artifactory

CVE-2026-66384

·

Published

2026-08-12

·

Updated

2026-08-29

5.3

Medium

Base

AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Name of the Vulnerable Software and Affected Versions JFrog Artifactory (affected versions not specified)
Description An authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions. This issue allows for the poisoning of the container-image cache.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

14 Posts
20Reposts
125.8 K Audience
Graph

#3 · PT-2026-34274 · Linux · Linux Kernel

·

CVE-2026-31431

·

Published

2026-03-23

·

Updated

2026-08-28

7.8

High

Base

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 7.0 Linux kernel versions prior to 6.19.12
Description A flaw exists in the algif aead cryptographic algorithm interface of the Linux kernel. The issue stems from an incorrect in-place operation during cryptographic processing where source and destination data mappings differ. A local attacker with low privileges can exploit this by splicing...
More

Exploit

Fix

RCE

LPE

DoS

Use After Free

856 Posts
6.7 KReposts
5.4 M Audience
Graph

#4 · PT-2024-2752 · Palo Alto Networks · Pan-Os

·

CVE-2024-3400

·

Published

2024-04-12

·

Updated

2026-08-26

10

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Palo Alto Networks PAN-OS versions 10.2 through 11.1
Description A command injection issue exists in the GlobalProtect feature of Palo Alto Networks PAN-OS software. The flaw allows an unauthenticated remote attacker to execute arbitrary code with root privileges on the firewall by creating an arbitrary file. This is achieved through a path traversal vulnerability in the `SE...
More

Exploit

Fix

DoS

RCE

Command Injection

685 Posts
2.0 KReposts
13.7 M Audience
Graph

#5 · PT-2026-65725 · Gitea · Gitea

·

CVE-2026-60004

·

Published

2026-07-28

·

Updated

2026-08-29

9.8

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Gitea versions 1.17 through 1.27.0
Description A critical code injection flaw exists in the services/repository/files/patch.go file. An attacker with write access to a repository can exploit the diffpatch API endpoint to install a malicious executable Git hook, allowing the execution of arbitrary shell commands with the privileges of the Gitea operating-system user. If o...
More

Exploit

Fix

RCE

Code Injection

65 Posts
35Reposts
54.9 K Audience
Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph