Vulnerabilities
87 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-8694 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification o Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2026-40321 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. NVD description · AI analysis pending | 8.0 group max | 8% |
| — | ||
| CVE-2026-4064 +1 in the same advisory: …3563 | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to byp Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to bypass role-based access controls and perform privileged operations — including reading sensitive data, creating or deleting resources, and disrupting service operations — via crafted gRPC requests. NVD description · AI analysis pending | 8.3 group max | <1% |
| — | ||
| CVE-2026-3277 | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/auth The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/authentication.ps1 script, which allows an attacker with read access to that file to obtain the OIDC client credentials NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2020-37103 | DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through j DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2026-24837 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a module friendly name could include scripts that will run during some module operations in the Persona Bar. Versions 9.13.10 and 10.2.0 contain a fix for the issue. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2026-0618 | Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2025-64095 | Unauthenticated File Upload and Overwrite in DNN (DotNetNuke) CMS CVE-2025-64095 is an unauthenticated unrestricted file upload flaw (CWE-434) in the default HTML editor provider of DNN (formerly DotNetNuke), an open-source .NET web content management platform. Because the provider accepts uploads without authentication, any unauthenticated remote attacker can upload files and overwrite existing files, including images, with attacker-controlled content. This allows an attacker to deface a website by replacing its files and, combined with other issues, to inject cross-site-scripting (XSS) payloads; the CVSS 9.8 critical score reflects full network reachability with no privileges or user interaction required. All DNN deployments running any version prior to 10.1.1 are affected. Exploitation is not yet confirmed (not in CISA KEV, no public PoC known), but the EPSS score of 44.7% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days. Do: Upgrade DNN to version 10.1.1 or later as soon as possible. Until patched, restrict unauthenticated access to the HTML editor provider's upload endpoint (e.g., via authentication requirements or WAF/virtual-patching rules) and review existing uploaded images and site files for unexpected overwrites or injected XSS payloads. | 9.8 group max | 45% |
| largetens of thousands of internet-facing DNN sites (order 10k-100k) | ||
| CVE-2025-59545 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0. NVD description · AI analysis pending | 9.0 group max | <1% |
| — | ||
| CVE-2025-59535 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. This issue has been patched in version 10.1.0. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-52488 | Unauthenticated NTLM Hash Leak to Attacker-Controlled SMB Server in DNN Platform CVE-2025-52488 is an information-disclosure flaw in DNN Platform (formerly DotNetNuke), an open-source .NET-based web CMS, that allows a specially crafted series of malicious interactions to expose NTLM authentication hashes. An unauthenticated network attacker can trigger the DNN web server to authenticate to a third-party (attacker-controlled) SMB server, capturing the NTLM hashes of the account running the application. Those hashes can be cracked offline or relayed to other services, potentially yielding valid credentials for the web server's service account and broader movement in Windows/Active Directory environments — consistent with the scope-changed, high-confidentiality CVSS 3.1 score of 8.6. All DNN Platform deployments from version 6.0.0 up to but not including 10.0.1 are affected, especially Windows-hosted servers whose application pool identity is a domain or service account, since those hashes are the most valuable to an attacker. Exploitation has not yet been confirmed (not in CISA KEV, no public PoC), but EPSS assigns a 35.2% probability of exploitation within 30 days (98th percentile), making this a high-priority patch. Do: Upgrade DNN Platform to version 10.0.1 or later as soon as possible. As interim mitigation, restrict outbound SMB (TCP 445) from web servers to trusted destinations only and run the application pool under a low-privilege, non-domain account so leaked hashes have limited value; monitor for unexpected SMB connections to external hosts. Given the high EPSS score, prioritize patching of internet-exposed DNN instances. | 8.6 group max | 35% |
| largetens of thousands of internet-facing DNN sites (of an installed base of roughly 100k+ live DNN sites) | ||
| CVE-2025-48378 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. NVD description · AI analysis pending | 6.1 group max | <1% |
| — | ||
| CVE-2025-32374 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2025-32035 +1 in the same advisory: …32036 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2024-11220 | A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation. NVD description · AI analysis pending | 8.5 | <1% |
| — | ||
| CVE-2024-6580 | The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates. NVD description · AI analysis pending | 2.3 | <1% |
| — | ||
| CVE-2024-24976 | A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability. NVD description · AI analysis pending | 4.9 | <1% | PoC |
| — | |
| CVE-2023-49213 | The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2023-34998 | An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation Software OAS Platform v18.00.0072. A specially crafted series of network requests can lead to arbitrary authentication. An attacker can sniff network traffic to trigger this vulnerability. NVD description · AI analysis pending | 8.1 group max | 1% |
| — |