Actively Exploited Vulnerabilities
Improper sanitization in the extension file names is present in Drupal core.
Apply updates per vendor instructions.
CWE-434