CVE-2026-59543
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVSS
9.9
Critical
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Jul 23, 2026 · Last modified: Jul 23, 2026 · CWE-94
Not enough EPSS history yet.
Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-648158.1 HIG—
——0In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files5hCVE-2026-648037.8 HIG—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK5hCVE-2026-648027.8 HIG—
——0In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration5hCVE-2026-150119.8 CRI57.7%
——17The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated attackers to invoke arbitrary parameterless PHP functions, which can be used to disrupt site functionality or expose sensitive information. The required nonce is publicly emitted via wp_localize_script whenever the plugin's [emd_form] shortcode is rendered on any public-facing page, making the endpoint reachable by unauthenticated visitors without any prior authentication or privilege.7hCVE-2026-166069.8 CRI63.2%
——19A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.20hCVE-2025-131466.5 MED38.0%
——11The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The vulnerability was partially patched in version 5.0.4.1d