CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.
LiteLLM contains critical SQL injection and code execution vulnerabilities that allow complete database access and remote code execution as a system service.