Year Archive: 2026

EUVD Vulnerabilities (2026)

Browse security threats, CVE catalog items, and software security flaws mapped under the EUVD sequence for the year 2026.

CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new use...

Aliases:
CVE-2026-19652
Published: 2026-10-02 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s bro...

Aliases:
GHSA-p8mc-j3m4-wxm3 CVE-2026-95662
Published: 2026-10-02 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of...

Aliases:
CVE-2026-104611
Published: 2026-10-02 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

YesWiki before 4.6.7 contains an authorization bypass vulnerability in ApiService::isAuthorized() that allows unauthenticated attackers to call admin-only API routes when public API mode is enabled. A...

Aliases:
CVE-2026-104467
Published: 2026-10-02 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: apache

Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the comp...

Aliases:
CVE-2026-91135
Published: 2026-10-02 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: Moxa

A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter whe...

Aliases:
CVE-2026-86325
Published: 2026-10-02 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s bro...

Aliases:
GHSA-qj83-rwv8-wp2g CVE-2026-59668
Published: 2026-10-02 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s bro...

Aliases:
CVE-2026-59667 GHSA-6hjq-f8x2-6wjp
Published: 2026-10-02 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s bro...

Aliases:
GHSA-fc2r-3669-p6fh CVE-2026-59666
Published: 2026-10-02 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Cross-Site Scripting vulnerability in the Repasat application. Successful exploitation of this vulnerability could allow an attacker to trick a user into executing arbitrary code in the victim’s bro...

Aliases:
CVE-2026-59665 GHSA-qg5m-w426-rfhq
Published: 2026-10-02 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` hand...

Aliases:
CVE-2026-14378
Published: 2026-10-02 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: Bugcrowd

Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice g...

Aliases:
CVE-2026-104480 GHSA-3q99-x36r-rchh
Published: 2026-10-02 View Complete Profile →
CRITICAL (9) CVSS 3.1 Source: redhat

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP ...

Aliases:
GHSA-c4v7-fhgq-r988 CVE-2026-86345
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: cisa-cg

The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET...

Aliases:
CVE-2026-102628
Published: 2026-10-01 View Complete Profile →
CRITICAL (9) CVSS 4.0 Source: cisa-cg

Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitra...

Aliases:
CVE-2026-102667
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: GitHub_M

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST...

Aliases:
CVE-2026-56662
Published: 2026-10-01 View Complete Profile →

EUVD-2026-91042

Actively Exploited
CRITICAL (9.8) CVSS 3.1 Source: fortinet

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8,...

Aliases:
GHSA-6gxc-3vv7-7w24 CVE-2026-104286
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to imprope...

Aliases:
CVE-2026-96658
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: redhat

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview e...

Aliases:
CVE-2026-96659
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: WatchGuard

A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-co...

Aliases:
CVE-2026-13043
Published: 2026-10-01 View Complete Profile →
MEDIUM (5.3) CVSS 4.0 Source: CIRCL

MISP contains an incomplete authorization check in the discussion posting functionality. When a user submits a post to a thread or replies to an existing post, the application only verified whether th...

Aliases:
CVE-2026-103858 GHSA-vwhj-wmrx-p88c
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthen...

Aliases:
CVE-2026-103264
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup m...

Aliases:
CVE-2026-103244
Published: 2026-10-01 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for ...

Aliases:
CVE-2026-7176 GHSA-24wv-pp5p-8868
Published: 2026-10-01 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code that will execute on the p...

Aliases:
CVE-2026-7175 GHSA-635f-v4jh-h92p
Published: 2026-10-01 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

CVE-2026-7174: Stored Cross-Site Scripting vulnerability in Entradium, by Crocantickets. Specifically, in the Name and Field parameters of the endpoint /tools/discount_wizard/discount_config during th...

Aliases:
GHSA-g858-jcvh-5fpf CVE-2026-7174
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: CIRCL

MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The ...

Aliases:
CVE-2026-103655 GHSA-2hxj-rrwr-5g5v
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's befo...

Aliases:
CVE-2026-15989
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` par...

Aliases:
CVE-2026-75957
Published: 2026-10-01 View Complete Profile →
HIGH (7.6) CVSS 4.0 Source: CIRCL

MISP contains a vulnerability in its one-time password (OTP) authentication flow that allows replay of a consumed HOTP (paper) token and rewinding of the token counter. The HOTP verification logic co...

Aliases:
GHSA-28mq-63wc-4252 CVE-2026-103651
Published: 2026-10-01 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: WPScan

The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to ...

Aliases:
GHSA-3m4x-3wq2-6jqf CVE-2026-101148
Published: 2026-10-01 View Complete Profile →
HIGH (8.8) CVSS 3.1 Source: NCSC-FI

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 fail to enforce server-side authorization on an administrative password-change function. An authenticated use...

Aliases:
GHSA-wv8r-gc9x-96j9 CVE-2026-80275
Published: 2026-10-01 View Complete Profile →
HIGH (7.5) CVSS 3.1 Source: NCSC-FI

Comelit Multi-User Gateway for VIP System (model 1456B) firmware versions 2.9.1 and 2.10.0 expose a network-accessible management interface that does not require authentication. Through this interface...

Aliases:
GHSA-g5xq-fc7g-hgv3 CVE-2026-80276
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: ASUS

Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interfac...

Aliases:
CVE-2026-14157 GHSA-j8q5-whhx-5847
Published: 2026-10-01 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: Anthropic

iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so a...

Aliases:
GHSA-pwcx-5qh6-2pxc CVE-2026-101283
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: Anthropic

iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a...

Aliases:
GHSA-pmgg-x2vj-36cv CVE-2026-101276
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisa-cg

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could a...

Aliases:
CVE-2026-102105
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisa-cg

Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authe...

Aliases:
CVE-2026-102106
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: cisa-cg

Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could po...

Aliases:
CVE-2026-102115
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisa-cg

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could a...

Aliases:
CVE-2026-102104
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisa-cg

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could a...

Aliases:
CVE-2026-102102
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.4) CVSS 3.1 Source: cisa-cg

Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, ...

Aliases:
CVE-2026-102149
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: cisa-cg

A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of...

Aliases:
CVE-2026-102147
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisa-cg

Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery. Kiteworks Email Protection Gateway performed server-side fetches of URLs contained in the message ...

Aliases:
CVE-2026-102095
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: mitre

In ldapd in OpenBSD 7.8 before errata 057 and 7.9 before errata 021, delegated BSD authentication results are correlated only by the LDAP child process client file descriptor and LDAP message ID. Afte...

Aliases:
CVE-2026-103547
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can a...

Aliases:
GHSA-92vv-q57x-j4vj CVE-2026-103475
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS command...

Aliases:
CVE-2026-103473 GHSA-m6mv-f8h2-2w86
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Patchstack

Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.

Aliases:
CVE-2026-100512 GHSA-vvmp-qqcf-xwvf
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 4.0 Source: hsi

Missing authentication for critical function vulnerability for all PTZOptics cameras and the Firmware Upgrade Tool - Firmware Update modules. A missing authentication vulnerability in the firmware upd...

Aliases:
CVE-2026-75969 GHSA-2q27-rwqh-vgpm
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: GitHub_M

Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to ar...

Aliases:
CVE-2026-62308
Published: 2026-09-30 View Complete Profile →

EUVD-2026-90081

Actively Exploited
HIGH (8.5) CVSS 4.0 Source: DIVD

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

Aliases:
CVE-2026-102490 GHSA-hgff-g8g3-4xr8
Published: 2026-09-30 View Complete Profile →

EUVD-2026-90080

Actively Exploited
HIGH (8.7) CVSS 4.0 Source: DIVD

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3...

Aliases:
GHSA-xmw5-m2wg-4243 CVE-2026-102489
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: PSF

A remote, unauthenticated TLS client can make a server crash or call through a freed pointer if its sni_callback assigns a different context to SSLSocket.context (the documented way to select a certif...

Aliases:
CVE-2026-19445 GHSA-7jvw-f348-84gq
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

LightLLM through 1.2.0 visual_only deployments expose an unauthenticated RPyC service with allow_pickle enabled that deserializes attacker-supplied arguments in the remote_infer_images method. Attacke...

Aliases:
CVE-2026-103395 GHSA-mw2v-h3wh-mp72
Published: 2026-09-30 View Complete Profile →
MEDIUM (6.2) CVSS 4.0 Source: CIRCL

MISP contains a stored cross-site scripting (XSS) vulnerability in the galaxy icon handling path. The icon field of a galaxy object was persisted without any server-side validation through the galaxy ...

Aliases:
GHSA-58w8-2929-fqhf CVE-2026-103389
Published: 2026-09-30 View Complete Profile →
MEDIUM (6.2) CVSS 4.0 Source: CIRCL

MISP renders the source field of a Galaxy Cluster as a clickable hyperlink whenever the stored value passes PHP's FILTER_VALIDATE_URL validation. Because FILTER_VALIDATE_URL accepts the javascript: UR...

Aliases:
GHSA-ccjm-jpcq-p5hf CVE-2026-103388
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: TR-CERT

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Digital Smart Manufacturing Systems Inc. Trex MES allows Command Line Execution through SQL I...

Aliases:
CVE-2026-18782
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: TR-CERT

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection. This issue affects SOPLOG: before Sop...

Aliases:
CVE-2026-82307
Published: 2026-09-30 View Complete Profile →

EUVD-2026-89950

Actively Exploited
CRITICAL (9.8) CVSS 3.1 Source: cisco

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the ...

Aliases:
CVE-2026-76504 GHSA-xqjc-v467-8fvf
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: apache

Authentication bypass in sshd-core in Apache MINA SSHD versions 2.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5 for a certain (presumed rare) way to implement an SSH server. Apache MINA SSHD is a Java li...

Aliases:
GHSA-v223-2p4c-wp64 CVE-2026-77185
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Patchstack

Unauthenticated Bypass Vulnerability in OAuth Single Sign On – SSO (OAuth Client) <= 7.1.2 versions.

Aliases:
CVE-2026-97274
Published: 2026-09-30 View Complete Profile →
HIGH (8.3) CVSS 4.0 Source: CIRCL

MISP contains a stored cross-site script (XSS) vulnerability in the event graph preview feature. The event graph preview image field was accepted and stored without server-side validation. On the cli...

Aliases:
CVE-2026-103321
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: CERT-PL

sogo_yhn configures SOGo with a parameter "SOGoTrustProxyAuthentication=YES". This causes the password to be bypassed during HTTP Basic authentication. An unauthenticated attacker who provides the us...

Aliases:
CVE-2026-74865
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: CERT-PL

sogo_yhn configures SOGo with a parameter that forces the request with HTTP header "x-webobjects-remote-user" to be treated as sent by a verified user without performing password validation. Since Ng...

Aliases:
CVE-2026-74864
Published: 2026-09-30 View Complete Profile →
HIGH (8.6) CVSS 4.0 Source: CIRCL

MISP contains a privilege escalation vulnerability in the tag collection creation and editing functionality. The affected actions accepted the full HTTP request payload and passed it to a bulk-associa...

Aliases:
CVE-2026-103239 GHSA-vpmp-h7jx-6gfx
Published: 2026-09-30 View Complete Profile →
HIGH (8.3) CVSS 4.0 Source: CIRCL

MISP contains an improper input validation vulnerability in its ORM save path. When a user submits data through various endpoints (attribute add/edit, event edit, free-text import, sighting capture, s...

Aliases:
GHSA-52c6-qg88-jh84 CVE-2026-103237
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: apache

Authentication bypass via LDAP injection in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5. Apache MINA SSHD is a Java library for client-side and serve...

Aliases:
CVE-2026-94053 GHSA-qrc3-w53g-j8gv
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: apache

A missing check in LdapPasswordAuthenticator in component sshd-ldap in Apache MINA SSHD versions 1.2.0 to 2.19.0 or 3.0.0-M1 to 3.0.0-M5 bypassed authentication checks. Apache MINA SSHD is a Java...

Aliases:
CVE-2026-94052 GHSA-wm5x-hv45-v2v6
Published: 2026-09-30 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: CIRCL

MISP contains a mass assignment vulnerability in the event delegation feature. When a user with delegation permission submits a delegation request, the application authorized the user against the even...

Aliases:
GHSA-j2mf-q9c3-gwxw CVE-2026-103235
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: Patchstack

Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.

Aliases:
GHSA-wm87-9v37-7595 CVE-2026-97196
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: mitre

Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation that allows a remote attacker to execute code remotely as an unprivileged user on a Pexip Infinity Confer...

Aliases:
GHSA-4qcw-c3r4-gc9h CVE-2026-103110
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: mitre

In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.

Aliases:
CVE-2026-51857 GHSA-q2f7-8vfc-xg45
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: mitre

bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.

Aliases:
CVE-2026-51861 GHSA-4w4g-gc64-8m74
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: mitre

agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches...

Aliases:
GHSA-m2qp-332m-87w4 CVE-2026-51867
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: mitre

Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.

Aliases:
GHSA-pxxm-r9vp-9cmm CVE-2026-51872
Published: 2026-09-30 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: GitHub_M

simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 2.0.1 of the argv-parser package, parseEnv omits ...

Aliases:
CVE-2026-102829
Published: 2026-09-29 View Complete Profile →

EUVD-2026-88445

Actively Exploited
HIGH (8.8) CVSS 3.1 Source: apple

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafte...

Aliases:
GHSA-3cf3-h799-fjvq CVE-2026-86950
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Joomla

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes e...

Aliases:
CVE-2026-101110 GHSA-hv58-qqxr-w5r2
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: GitHub_M

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel foll...

Aliases:
CVE-2026-101894
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: WatchGuard

An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.

Aliases:
CVE-2026-86102
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A security flaw has been discovered in D-Link DI-8400 16.07. This vulnerability affects the function menu_nat_more_asp of the file menu_nat_more.asp of the component Web Administration Service. The ma...

Aliases:
CVE-2026-101081
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: suse

An unauthenticated update of public UI settings could be used by remote attackers to execute a stored cross-site scripting attack in the Rancher UI, in SUSE Rancher 2.15 before 2.15.2, 2.14 before 2.1...

Aliases:
CVE-2026-88804
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: SailPoint

This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated user remote code execution on the IdentityIQ server due to improper input validation of submitted web service API co...

Aliases:
CVE-2026-12342
Published: 2026-09-28 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: VulDB

A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of the file /location_time.cgi of the component Location Time Handler. The manipula...

Aliases:
GHSA-xcvp-vff4-7732 CVE-2026-101075
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: CERT-PL

Dayforce Payroll is vulnerable to Path Traversal  in file download functionality. An unauthenticated attacker can sent GET request with file path parameter set to any path including an absolute loca...

Aliases:
GHSA-p8m3-fq83-fgm7 CVE-2026-73642
Published: 2026-09-28 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: CERT-PL

Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's brow...

Aliases:
GHSA-9rqp-h52c-rgx9 CVE-2026-73641
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: CERT-PL

Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated attacker can prepare GET request with one of the parameters filled in with an a...

Aliases:
GHSA-wrm6-gm2g-4hgx CVE-2026-73640
Published: 2026-09-28 View Complete Profile →
MEDIUM (5.9) CVSS 4.0 Source: CERT-PL

mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bo...

Aliases:
CVE-2026-82936 GHSA-289h-w85v-v5r6
Published: 2026-09-28 View Complete Profile →
MEDIUM (6.9) CVSS 4.0 Source: CERT-PL

mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that wi...

Aliases:
CVE-2026-82935 GHSA-p2fw-wccq-9qh3
Published: 2026-09-28 View Complete Profile →
HIGH (7.7) CVSS 4.0 Source: CERT-PL

mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts au...

Aliases:
GHSA-27f6-7954-3wm7 CVE-2026-82928
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: GoogleCloud

A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenticated user with...

Aliases:
CVE-2026-81867
Published: 2026-09-28 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: VulDB

A vulnerability was identified in FAST FAC1900R 20190827_2.0.2. Affected by this issue is the function copy_msg_element of the component devdiscover Service. Such manipulation leads to stack-based buf...

Aliases:
CVE-2026-101039
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: GoogleCloud

An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated Google Cloud u...

Aliases:
CVE-2026-19759
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was determined in FAST FAC1200R 5.0_20201119_1.0.2. Affected by this vulnerability is the function MmtAtePrase of the component MmtAtePrase Parser. This manipulation causes stack-based...

Aliases:
CVE-2026-101038
Published: 2026-09-28 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7171: parameter 'Apellido 1' in the endpoint  '/administrator/index.php?page=admin.user...

Aliases:
CVE-2026-7171 GHSA-2jq2-728v-8wjw
Published: 2026-09-28 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7172: parameter 'Nombre Completo' in the endpoint  '/administrator/index.php?option=com...

Aliases:
GHSA-428v-q45m-cv5c CVE-2026-7172
Published: 2026-09-28 View Complete Profile →
MEDIUM (4.8) CVSS 4.0 Source: INCIBE

Stored Cross-Site Scripting (XSS) in TPVEnlanube affecting the following endpoint and parameter: * CVE-2026-7170: parameter 'vendor_store_name' in the endpoint  '/administrator/index.php?pshop_mo...

Aliases:
CVE-2026-7170 GHSA-h7w4-9999-mvp8
Published: 2026-09-28 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticated user to connect to restricted MCP servers if they possess the server ID. Atta...

Aliases:
GHSA-g524-9c6h-8w7v CVE-2026-101084
Published: 2026-09-27 View Complete Profile →

EUVD-2026-87959

Actively Exploited
CRITICAL (9.5) CVSS 4.0 Source: NetScaler

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gatewa...

Aliases:
GHSA-h5xm-pf48-4c32 CVE-2026-88772
Published: 2026-09-27 View Complete Profile →

EUVD-2026-87958

Actively Exploited
CRITICAL (9.5) CVSS 4.0 Source: NetScaler

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37....

Aliases:
CVE-2026-88771 GHSA-mx58-p288-86qp
Published: 2026-09-27 View Complete Profile →
MEDIUM (6.3) CVSS 4.0 Source: CIRCL

The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recover...

Aliases:
GHSA-j3gx-2q66-wg27 CVE-2026-101041
Published: 2026-09-27 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: GitLab

Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3.3 on Windows, allows a remote, unauthenticated attacker to run arbitrary JScrip...

Aliases:
CVE-2026-100741 GHSA-v6j4-p35g-mq6p
Published: 2026-09-27 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: Joomla

Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Aliases:
CVE-2026-97161 GHSA-4qjx-g3m9-jcwf
Published: 2026-09-26 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Aliases:
CVE-2026-97163 GHSA-6pgc-8534-jjrf
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: Joomla

Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29

Aliases:
CVE-2026-97160 GHSA-4h74-hj22-v78v
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.5) CVSS 4.0 Source: Joomla

Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterprise extension < 11.1.0 - MIME parts of incoming emails were saved to media/com_ac...

Aliases:
CVE-2026-94132 GHSA-x2ch-94w5-cr2g
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Joomla

Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to i...

Aliases:
CVE-2026-94130 GHSA-6c54-6qx7-xwjj
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authenticated role) uploads an SSL certificate for one of their own domains, the Certi...

Aliases:
CVE-2026-100720
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulnCheck

Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails to validate intermediate path components of the export destination: Froxlor\Fil...

Aliases:
CVE-2026-100716
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulnCheck

Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings hardened in GHSA-33mp, the field has no string_regexp or required_otp guard, and ...

Aliases:
CVE-2026-100714
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulnCheck

kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass the per-namespace clamp and create objects in other namespace...

Aliases:
CVE-2026-100706
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifier bindings, allowing attackers to authenticate as any existing user by claiming...

Aliases:
CVE-2026-100607 GHSA-mjgh-prrr-9qw5
Published: 2026-09-26 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can...

Aliases:
GHSA-3p62-2wp9-6rpj CVE-2026-100389
Published: 2026-09-25 View Complete Profile →
MEDIUM (6.3) CVSS 4.0 Source: CIRCL

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically i...

Aliases:
CVE-2026-100190 GHSA-rpj3-jvgh-5qrf
Published: 2026-09-25 View Complete Profile →
HIGH (8.5) CVSS 4.0 Source: CIRCL

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/t...

Aliases:
GHSA-fg9r-9hmh-7x8c CVE-2026-100172
Published: 2026-09-25 View Complete Profile →

EUVD-2026-84555

Actively Exploited
HIGH (8.1) CVSS 3.1 Source: hackerone

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for bot...

Aliases:
CVE-2026-87902
Published: 2026-09-22 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: redhat

A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead ...

Aliases:
GHSA-hm52-6738-r26p CVE-2026-75885
Published: 2026-09-18 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: synology

An insufficient entropy vulnerability in login logic in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read or write ar...

Aliases:
CVE-2026-13639
Published: 2026-09-18 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: synology

An improper encoding or escaping of output vulnerability in SCGI in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote attackers to read...

Aliases:
CVE-2026-13684
Published: 2026-09-18 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: HCL

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extrac...

Aliases:
CVE-2026-67100
Published: 2026-09-18 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: HCL

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send reque...

Aliases:
CVE-2026-67101
Published: 2026-09-18 View Complete Profile →

EUVD-2026-82595

Actively Exploited
HIGH (7.8) CVSS 3.0 Source: Acronis

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for P...

Aliases:
CVE-2026-87886 GHSA-hrq3-qgq7-jm9x
Published: 2026-09-17 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: GitHub_M

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames contai...

Aliases:
CVE-2026-54053
Published: 2026-09-17 View Complete Profile →
CRITICAL (9.5) CVSS 4.0 Source: GitHub_M

RabbitMQ amqp091-go: Protocol Desynchronization and Frame Injection via Integer Overflow in readLongstr

Aliases:
GHSA-c5pq-fr2g-9jpf CVE-2026-77411
Published: 2026-09-17 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: CIRCL

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card (event_general.ctp) and the server/feed preview card (preview_general.c...

Aliases:
CVE-2026-93296
Published: 2026-09-17 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: CIRCL

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP consol...

Aliases:
GHSA-2q9g-8hcw-6c23 CVE-2026-93295
Published: 2026-09-17 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulnCheck

vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` ...

Aliases:
CVE-2026-92957 GHSA-28q4-xrqh-9479
Published: 2026-09-17 View Complete Profile →
HIGH (8.8) CVSS 4.0 Source: INCIBE

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier t...

Aliases:
GHSA-vh5r-mqj2-86wg CVE-2026-14850
Published: 2026-09-17 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Patchstack

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Aliases:
CVE-2026-62108
Published: 2026-09-17 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: Patchstack

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Aliases:
CVE-2026-62104
Published: 2026-09-17 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Patchstack

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Aliases:
CVE-2026-62101
Published: 2026-09-17 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: CIRCL

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition w...

Aliases:
GHSA-53jr-w5f7-rv64 CVE-2026-92932
Published: 2026-09-17 View Complete Profile →

EUVD-2026-81122

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: cisco

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication ...

Aliases:
CVE-2026-76460 GHSA-25wc-3w28-q6vw
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisco

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain&nbsp;root privileges. This vulnerability is ...

Aliases:
GHSA-355g-mjpr-92rq CVE-2026-20341
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: cisco

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as&nbsp;...

Aliases:
GHSA-mgpv-rwhr-9mx2 CVE-2026-20242
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: cisco

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have con...

Aliases:
GHSA-8h74-5vrg-hj96 CVE-2026-20237
Published: 2026-09-16 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: cisco

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have con...

Aliases:
GHSA-4jvq-wwxw-c7g2 CVE-2026-20130
Published: 2026-09-16 View Complete Profile →
MEDIUM (5.3) CVSS 4.0 Source: NCSC-FI

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters.

Aliases:
GHSA-6rh6-h2w9-cj6x CVE-2026-85104
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: CERT-PL

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter...

Aliases:
CVE-2026-58146 GHSA-57h3-7px2-2q83
Published: 2026-09-16 View Complete Profile →
HIGH (8.4) CVSS 4.0 Source: CERT-PL

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepti...

Aliases:
GHSA-6v9q-56wf-hqwp CVE-2026-40857
Published: 2026-09-16 View Complete Profile →
HIGH (7.1) CVSS 4.0 Source: CERT-PL

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attac...

Aliases:
GHSA-xw9f-4565-4fvc CVE-2026-40856
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: CERT-PL

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, pin...

Aliases:
CVE-2026-40855 GHSA-5qwp-rxmm-2vwh
Published: 2026-09-16 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: CERT-PL

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for...

Aliases:
CVE-2026-40854 GHSA-7wq2-g42r-wr2h
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.5) CVSS 4.0 Source: Arista

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS ...

Aliases:
CVE-2026-73453
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that...

Aliases:
GHSA-579w-q4cr-j8hc CVE-2026-12793
Published: 2026-09-16 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: Chrome

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securi...

Aliases:
GHSA-qf9f-qhrm-4fhx CVE-2026-91738
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: Chrome

Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML pa...

Aliases:
CVE-2026-91729 GHSA-695q-prgq-m88h
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: Chrome

Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Aliases:
GHSA-q6pj-5jr6-2p62 CVE-2026-91716
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: oracle

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows...

Aliases:
CVE-2026-83196 GHSA-qxm3-hg97-hm9r
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: oracle

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable...

Aliases:
CVE-2026-73957 GHSA-jhm6-4593-gph5
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: oracle

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnera...

Aliases:
GHSA-xq2j-5f8w-pxqf CVE-2026-73948
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: oracle

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita...

Aliases:
GHSA-jh6h-ghrg-789q CVE-2026-73946
Published: 2026-09-15 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: oracle

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploita...

Aliases:
GHSA-ccmq-pfp5-xc2v CVE-2026-73945
Published: 2026-09-15 View Complete Profile →

EUVD-2026-79004

Actively Exploited
HIGH (8.8) CVSS 3.1 Source: Google_Devices

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges...

Aliases:
GHSA-chq2-jxgv-5vfw CVE-2026-58704
Published: 2026-09-15 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: ENISA

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting us...

Aliases:
CVE-2026-89307 GHSA-wfjc-xr6c-c6vw
Published: 2026-09-15 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: ENISA

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScrip...

Aliases:
CVE-2026-87793 GHSA-m59h-9rxw-9jx5
Published: 2026-09-15 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: ENISA

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attack...

Aliases:
GHSA-28h8-rc7c-m27v CVE-2026-87792
Published: 2026-09-15 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: ENISA

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker ...

Aliases:
CVE-2026-87791 GHSA-rmq6-wq79-gcm8
Published: 2026-09-15 View Complete Profile →

EUVD-2026-77625

Actively Exploited
CRITICAL (9.8) CVSS 3.1 Source: cisco

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the ...

Aliases:
CVE-2026-76461 GHSA-jwpf-jww6-h6vr
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: cisco

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive in...

Aliases:
CVE-2026-20353
Published: 2026-09-14 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: apache

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served ...

Aliases:
CVE-2026-82434 GHSA-6fmw-8rj9-p9pg
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: CIRCL

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fai...

Aliases:
GHSA-5wh5-3jx8-w3gh CVE-2026-90961
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulnCheck

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers c...

Aliases:
CVE-2026-90937 GHSA-r2fc-pw6p-x28w
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: GitHub_M

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization...

Aliases:
CVE-2026-57131 PYSEC-2026-3511 GHSA-fq2m-6wqh-x44g
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: GitHub_M

PraisonAI is a multi-agent teams system. Prior to 4.6.58, recipe serve installs APIKeyAuthMiddleware or JWTAuthMiddleware when an operator selects api-key or JWT authentication, but each middleware fo...

Aliases:
PYSEC-2026-3513 GHSA-j4hj-7hfh-g2f4 CVE-2026-57127
Published: 2026-09-14 View Complete Profile →
HIGH (8.6) CVSS 4.0 Source: CERT-PL

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQ...

Aliases:
CVE-2026-15600 GHSA-673p-mhx8-prcm
Published: 2026-09-14 View Complete Profile →
HIGH (8.6) CVSS 4.0 Source: CERT-PL

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectC...

Aliases:
CVE-2026-7848 GHSA-2j6v-h3gj-mm3r
Published: 2026-09-14 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: CIRCL

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While script...

Aliases:
CVE-2026-90957 GHSA-5mp5-7f8h-r69q
Published: 2026-09-14 View Complete Profile →
MEDIUM (4.6) CVSS 4.0 Source: CIRCL

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP ...

Aliases:
CVE-2026-90955
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: INCIBE

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value...

Aliases:
CVE-2026-12258 GHSA-jhq4-x77m-qmhx
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command i...

Aliases:
GHSA-8c98-9627-pm2g CVE-2026-90699
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer o...

Aliases:
GHSA-vg87-cmh7-p8wr CVE-2026-90693
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Host...

Aliases:
CVE-2026-90692 GHSA-vmqq-69gc-qcmg
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: Joomla

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in...

Aliases:
CVE-2026-85192 GHSA-5g6f-m8m2-v9cw
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation...

Aliases:
GHSA-gfg5-84mh-g97c CVE-2026-90680
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument serv...

Aliases:
GHSA-v9cq-jhv2-723g CVE-2026-90608
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument ...

Aliases:
CVE-2026-90607 GHSA-w79w-7hq2-gg5c
Published: 2026-09-14 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient p...

Aliases:
CVE-2026-78006 GHSA-4q25-cq4p-f83q
Published: 2026-09-12 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of...

Aliases:
CVE-2026-78159 GHSA-9c57-9fxg-8x9j
Published: 2026-09-12 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: WPScan

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log i...

Aliases:
GHSA-97p7-8jv8-2rmm CVE-2026-75800
Published: 2026-09-12 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: WPScan

The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowin...

Aliases:
CVE-2026-77005 GHSA-3mph-m2wr-4wh3
Published: 2026-09-12 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: WPScan

The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF c...

Aliases:
CVE-2026-77006 GHSA-m99c-7x2p-p8j3
Published: 2026-09-12 View Complete Profile →

EUVD-2026-76779

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could ...

Aliases:
GHSA-f47w-mrg9-g9p2 CVE-2026-85706
Published: 2026-09-12 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: apache

The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifie...

Aliases:
GHSA-f3wj-w3qw-rw57 CVE-2026-82617
Published: 2026-09-11 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing ...

Aliases:
CVE-2026-72710 GHSA-g7qf-5m6v-m9vh
Published: 2026-09-11 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by sup...

Aliases:
GHSA-px65-33x4-mwqq CVE-2026-72709
Published: 2026-09-11 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: schneider

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with...

Aliases:
CVE-2026-3869 GHSA-g6jw-g6wr-2qcc
Published: 2026-09-11 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: Perforce

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 202...

Aliases:
CVE-2026-89212
Published: 2026-09-11 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: ibm

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

Aliases:
GHSA-x3hp-6r77-cxgw CVE-2026-79724
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: ibm

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

Aliases:
CVE-2026-81204 GHSA-82x2-gm4f-9fwx
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: ibm

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

Aliases:
GHSA-8m95-73q9-9r4v CVE-2026-82107
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: ibm

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to...

Aliases:
CVE-2026-85025 GHSA-j9vg-5378-pr5p
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.5) CVSS 4.0 Source: hackerone

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to in...

Aliases:
CVE-2026-65639
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.9) CVSS 3.0 Source: hackerone

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Aliases:
CVE-2026-68487
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: hackerone

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. ...

Aliases:
CVE-2026-65638
Published: 2026-09-10 View Complete Profile →
MEDIUM (5.1) CVSS 4.0 Source: CIRCL

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML...

Aliases:
CVE-2026-88921 GHSA-6h22-87v4-49wc
Published: 2026-09-10 View Complete Profile →
HIGH (7.1) CVSS 4.0 Source: CIRCL

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_gro...

Aliases:
CVE-2026-88915 GHSA-46cw-r5cx-57f2
Published: 2026-09-10 View Complete Profile →
MEDIUM (6.9) CVSS 4.0 Source: CERT-PL

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacke...

Aliases:
CVE-2026-17038 GHSA-4qc3-v5c2-6x2v
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: apache

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: f...

Aliases:
CVE-2026-49364 GHSA-fjwp-v5xg-5q39
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: apache

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue af...

Aliases:
CVE-2026-57967 GHSA-735c-72gw-5q97
Published: 2026-09-10 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: CIRCL

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuri...

Aliases:
GHSA-g437-q4fp-pq2g CVE-2026-88069
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies ...

Aliases:
CVE-2026-87930
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administ...

Aliases:
CVE-2026-87929
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: GitHub_M

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotel...

Aliases:
CVE-2026-22590
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: dell

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthentica...

Aliases:
CVE-2026-80172 GHSA-f8g2-6jhm-qr64
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.1) CVSS 4.0 Source: VulnCheck

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the di...

Aliases:
GHSA-g24p-7jpj-4qf8 CVE-2026-87806
Published: 2026-09-09 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: CIRCL

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with netw...

Aliases:
CVE-2026-87827 GHSA-mxww-3qmj-g8p3
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: TR-CERT

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Exploitation of Trusted Identifiers. This issue ...

Aliases:
GHSA-g622-qgc4-8v95 CVE-2026-16272
Published: 2026-09-09 View Complete Profile →

EUVD-2026-74529

Actively Exploited
HIGH (8.8) CVSS 3.1 Source: Chrome

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Aliases:
GHSA-8x3p-8g9v-xc7m CVE-2026-87491
Published: 2026-09-09 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: eclipse

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-cl...

Aliases:
GHSA-j7r5-6vmc-cmcc CVE-2026-84197
Published: 2026-09-08 View Complete Profile →
CRITICAL (9.9) CVSS 4.0 Source: eclipse

In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentia...

Aliases:
GHSA-mvq6-76gr-6f6h CVE-2026-86464
Published: 2026-09-08 View Complete Profile →

EUVD-2026-74053

Actively Exploited
CRITICAL (9.9) CVSS 3.1 Source: ConnectWise

A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConne...

Aliases:
GHSA-rc8v-f46m-jcgm CVE-2026-84869
Published: 2026-09-08 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: google_android

In handleBondStateChanged of AdapterService.java, there is a possible way to skip pairing due to a logic error in the code. This could lead to remote escalation of privilege without user consent with ...

Aliases:
GHSA-974c-8m68-6h7c CVE-2026-28606
Published: 2026-09-08 View Complete Profile →

EUVD-2026-73889

Actively Exploited
HIGH (7.8) CVSS 3.1 Source: microsoft

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Aliases:
GHSA-4j4j-2wjq-mxqj CVE-2026-81963
Published: 2026-09-08 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: microsoft

Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Aliases:
GHSA-j9hh-7mj6-f56v CVE-2026-70296
Published: 2026-09-08 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: microsoft

Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

Aliases:
CVE-2026-69586 GHSA-fjff-cgxf-f3xx
Published: 2026-09-08 View Complete Profile →

EUVD-2026-73365

Actively Exploited
HIGH (7.8) CVSS 3.1 Source: microsoft

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Aliases:
GHSA-96fm-jjf3-wv64 CVE-2026-85880
Published: 2026-09-08 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: microsoft

Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.

Aliases:
CVE-2026-69431 GHSA-5w2v-mxr4-ch34
Published: 2026-09-08 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Commvault

Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

Aliases:
GHSA-mrh8-32mp-g8jf CVE-2026-77089
Published: 2026-09-08 View Complete Profile →

EUVD-2026-72530

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: adobe

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. A...

Aliases:
GHSA-fj37-xm58-mf28 CVE-2026-75650
Published: 2026-09-07 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: JetBrains

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

Aliases:
CVE-2026-86480
Published: 2026-09-07 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: JetBrains

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

Aliases:
CVE-2026-86478
Published: 2026-09-07 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: TR-CERT

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management)...

Aliases:
GHSA-8jp6-hw6c-mjgf CVE-2026-7861
Published: 2026-09-07 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: redhat

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connectio...

Aliases:
CVE-2026-18922
Published: 2026-09-07 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: CIRCL

Affected versions of MISP permit unauthenticated or weakly constrained request paths to perform persistent work without adequate input bounds or rate limiting. The users/forgot password-reset endpoi...

Aliases:
GHSA-6crc-w8rh-cr5w CVE-2026-86452
Published: 2026-09-07 View Complete Profile →
CRITICAL (9.4) CVSS 3.1 Source: TR-CERT

Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 before 2.3.

Aliases:
GHSA-w6hf-m328-w7vc CVE-2026-6223
Published: 2026-09-07 View Complete Profile →
LOW (2.3) CVSS 4.0 Source: CIRCL

Affected versions of MISP expose organisation metadata through the dashboard organisation picker without applying the same visibility restrictions enforced by the normal organisation index and per-org...

Aliases:
CVE-2026-86418 GHSA-jmv6-hcw6-r4f7
Published: 2026-09-07 View Complete Profile →

EUVD-2026-72041

Actively Exploited
CRITICAL (10) CVSS 4.0 Source: N-able

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Aliases:
CVE-2026-86218 GHSA-5f24-g9g9-m3v8
Published: 2026-09-06 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipul...

Aliases:
CVE-2026-86151 GHSA-6358-p8m7-jxv6
Published: 2026-09-06 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os co...

Aliases:
GHSA-qh73-x3c2-xph4 CVE-2026-86149
Published: 2026-09-06 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument Alarm...

Aliases:
GHSA-38rg-j8xg-2m77 CVE-2026-86148
Published: 2026-09-06 View Complete Profile →

EUVD-2026-72029

Actively Exploited
CRITICAL (9.2) CVSS 4.0 Source: CERT-PL

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to p...

Aliases:
CVE-2026-86060 GHSA-6425-cjxv-52gp
Published: 2026-09-05 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: CERT-PL

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An...

Aliases:
GHSA-m7q3-cwh2-ffg5 CVE-2026-67281
Published: 2026-09-05 View Complete Profile →

EUVD-2026-72027

Actively Exploited
MEDIUM (6.9) CVSS 4.0 Source: CERT-PL

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an...

Aliases:
GHSA-pqp3-gjgf-83cf CVE-2026-67279
Published: 2026-09-05 View Complete Profile →
MEDIUM (6.3) CVSS 4.0 Source: CERT-PL

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes a...

Aliases:
CVE-2026-67278 GHSA-cq44-x9vf-fpqg
Published: 2026-09-05 View Complete Profile →

EUVD-2026-72025

Actively Exploited
HIGH (8.8) CVSS 4.0 Source: CERT-PL

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "rando...

Aliases:
CVE-2026-67277 GHSA-6q2x-6fhj-r3w8
Published: 2026-09-05 View Complete Profile →

EUVD-2026-72024

Actively Exploited
CRITICAL (9.2) CVSS 4.0 Source: CERT-PL

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signat...

Aliases:
CVE-2026-67276 GHSA-j9wg-77fw-f22f
Published: 2026-09-05 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to un...

Aliases:
CVE-2026-86190
Published: 2026-09-05 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avide...

Aliases:
CVE-2026-86189
Published: 2026-09-05 View Complete Profile →
HIGH (8.6) CVSS 4.0 Source: CIRCL

MISP contains a cross-site request forgery (CSRF) vulnerability in the sharing group quick-edit functionality. The addOrg, removeOrg, addServer, and removeServer actions share the __initialiseSGQuickE...

Aliases:
CVE-2026-85546 GHSA-cwc4-rgpg-99q3
Published: 2026-09-04 View Complete Profile →
HIGH (8.3) CVSS 4.0 Source: CIRCL

An incorrect authorization vulnerability in MISP allowed authenticated users to delete attributes from events despite lacking the required perm_modify or perm_modify_org permissions. The affected att...

Aliases:
GHSA-9pvc-hwg3-vhmw CVE-2026-85538
Published: 2026-09-04 View Complete Profile →
HIGH (7.6) CVSS 4.0 Source: CIRCL

An authorization flaw in MISP allowed an authenticated user to submit a sharing_group_id without verifying that the user was authorized to use the referenced Sharing Group. In several attribute and G...

Aliases:
GHSA-4pv3-xjc8-wfm8 CVE-2026-85533
Published: 2026-09-04 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: microsoft

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

Aliases:
GHSA-w2qf-mqjq-8m33 CVE-2026-83711
Published: 2026-09-03 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: microsoft

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Aliases:
CVE-2026-80098 GHSA-r9hf-26xj-x88v
Published: 2026-09-03 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop ...

Aliases:
CVE-2026-85438 GHSA-fhxv-4m7f-gpmr
Published: 2026-09-03 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSH...

Aliases:
GHSA-vrg5-259h-pjj5 CVE-2026-85433
Published: 2026-09-03 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP request...

Aliases:
GHSA-2p25-xm7m-9vh5 CVE-2026-85428
Published: 2026-09-03 View Complete Profile →

EUVD-2026-70702

Actively Exploited
HIGH (8.8) CVSS 3.1 Source: Chrome

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Aliases:
CVE-2026-85046 GHSA-84qv-4wj5-wwmm
Published: 2026-09-03 View Complete Profile →

EUVD-2026-70647

Actively Exploited
HIGH (8.6) CVSS 3.1 Source: GitHub_M

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the API endpoint for creating a new formatter via file upload is unprotected and allo...

Aliases:
CVE-2026-63219
Published: 2026-09-03 View Complete Profile →
HIGH (8.8) CVSS 4.0 Source: CIRCL

A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. ...

Aliases:
GHSA-h2cm-43wh-hxvc CVE-2026-85236
Published: 2026-09-03 View Complete Profile →

EUVD-2026-69707

Actively Exploited
HIGH (7.8) CVSS 3.1 Source: sonicwall

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which...

Aliases:
CVE-2026-83549 GHSA-vxcc-7cf2-wcgh
Published: 2026-09-01 View Complete Profile →

EUVD-2026-69704

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: sonicwall

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit thi...

Aliases:
GHSA-ghw2-cfh2-xvgc CVE-2026-83548
Published: 2026-09-01 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: INCIBE

A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not ...

Aliases:
CVE-2026-4813 GHSA-wvvp-v69c-rj86
Published: 2026-09-01 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: INCIBE

A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissio...

Aliases:
GHSA-m4j2-w8wf-vp83 CVE-2026-84165
Published: 2026-09-01 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: ENISA

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Digitální a informační agentura (DIA) eObčanka-Identifikace on MacOS enables an attacke...

Aliases:
CVE-2026-59111 GHSA-vj9g-x7fg-rr79
Published: 2026-08-31 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: VulDB

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentic...

Aliases:
CVE-2026-82695
Published: 2026-08-31 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the compon...

Aliases:
CVE-2026-82691
Published: 2026-08-31 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A flaw has been found in D-Link DNS-327L and DNS-340L up to 20260717. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/ve_mgr.cgi. This manipulation of the argument f_de...

Aliases:
CVE-2026-82690
Published: 2026-08-31 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: GoogleCloud

An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the...

Aliases:
CVE-2026-19410 GHSA-q4ww-hvh7-426w
Published: 2026-08-31 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: ibm

IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and trigger...

Aliases:
GHSA-74fg-mx2g-3cx8 CVE-2026-19295
Published: 2026-08-28 View Complete Profile →

EUVD-2026-67861

Actively Exploited
CRITICAL (9.8) CVSS 3.1 Source: JFROG

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

Aliases:
CVE-2026-82329 GHSA-c5pf-6p5j-gj87
Published: 2026-08-28 View Complete Profile →

EUVD-2026-67714

Actively Exploited
CRITICAL (9.4) CVSS 4.0 Source: PaperCut

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable dri...

Aliases:
GHSA-mjg5-wj9r-9mfx CVE-2026-82078
Published: 2026-08-28 View Complete Profile →

EUVD-2026-67713

Actively Exploited
HIGH (8.8) CVSS 4.0 Source: PaperCut

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative fun...

Aliases:
GHSA-44wc-j6f2-7fjr CVE-2026-81578
Published: 2026-08-28 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: twcert

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.

Aliases:
CVE-2026-82082 GHSA-mwjg-762w-wg4x
Published: 2026-08-28 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: icscert

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of mess...

Aliases:
GHSA-vcvc-jqq8-cgj4 CVE-2026-69658
Published: 2026-08-27 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: icscert

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during...

Aliases:
GHSA-62mm-rmvp-f5p7 CVE-2026-76179
Published: 2026-08-27 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: icscert

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtai...

Aliases:
CVE-2026-71187 GHSA-rj7p-436q-6xv2
Published: 2026-08-27 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: icscert

Ebyte device web management interface does not consistently enforce authentication before granting access to administrative functionality. An unauthenticated remote attacker could access sensitive c...

Aliases:
CVE-2026-73125 GHSA-h7m6-87m3-q5r3
Published: 2026-08-27 View Complete Profile →
MEDIUM (4.6) CVSS 4.0 Source: CERT-PL

Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fails to sanitize cell content beginning with special formula characters like =, +,...

Aliases:
CVE-2026-56652 GHSA-w3j2-f8wq-g63j
Published: 2026-08-27 View Complete Profile →
MEDIUM (5.3) CVSS 4.0 Source: CIRCL

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint accepts a user_id parameter identifying the user whose assignments should be retu...

Aliases:
GHSA-49jg-8r6h-h4r7 CVE-2026-81819
Published: 2026-08-27 View Complete Profile →
HIGH (8.6) CVSS 4.0 Source: CIRCL

Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authorization check correctly prevented an organization administrator from editing user...

Aliases:
GHSA-7p7v-2gph-j69j CVE-2026-81818
Published: 2026-08-27 View Complete Profile →
HIGH (7.2) CVSS 4.0 Source: CIRCL

Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue across numerous task endpoints. The routes generally received both a case identif...

Aliases:
GHSA-ccgv-2jpf-98m2 CVE-2026-81817
Published: 2026-08-27 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a parsed document to Markdown via to_markdown(). Whi...

Aliases:
CVE-2026-8445
Published: 2026-08-23 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive sanitization, potentially leading to cross-site scri...

Aliases:
CVE-2026-7808
Published: 2026-08-23 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulnCheck

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Markdown passthrough (html_passthrough=True), and sev...

Aliases:
CVE-2026-5388
Published: 2026-08-23 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: GitLab

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

Aliases:
CVE-2026-78155
Published: 2026-08-23 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. ...

Aliases:
CVE-2026-78050 GHSA-j397-vxh8-xhw3
Published: 2026-08-22 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.

Aliases:
CVE-2026-76604 GHSA-fq44-8wg9-5qfj
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.5) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

Aliases:
GHSA-gvj7-4928-2j6w CVE-2026-77992
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input fr...

Aliases:
GHSA-hpc2-mqfw-fq4q CVE-2026-4703
Published: 2026-08-22 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

Aliases:
GHSA-p5vh-m7cp-f4v4 CVE-2026-76606
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

Aliases:
CVE-2026-76602 GHSA-pcxq-w35v-gcxv
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the...

Aliases:
GHSA-49rr-hfxh-8f4c CVE-2026-76571
Published: 2026-08-22 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

Aliases:
GHSA-7mjm-m5wm-mfgg CVE-2026-76605
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Wordfence

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validatio...

Aliases:
CVE-2026-78003 GHSA-jr9c-873v-948h
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GoogleCloud

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal d...

Aliases:
CVE-2026-12710 GHSA-m95m-h7f9-f822
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: WPScan

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any reg...

Aliases:
GHSA-3h2q-j328-63h4 CVE-2026-77002
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: WPScan

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login ...

Aliases:
GHSA-rpcc-rx9m-g3cx CVE-2026-77001
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: WPScan

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated...

Aliases:
GHSA-xxf7-9x7m-j4r3 CVE-2026-77000
Published: 2026-08-22 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $has...

Aliases:
CVE-2026-77414
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to a...

Aliases:
CVE-2026-77413
Published: 2026-08-21 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: GitHub_M

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model...

Aliases:
CVE-2026-61539
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: GitHub_M

GeoTools has unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers

Aliases:
CVE-2026-76904 GHSA-mqjf-5f49-2fjh
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: cisa-cg

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and reroute traffic to the attacker-controlled app. Once ...

Aliases:
CVE-2026-75932 GHSA-cm72-j98h-q99g
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: VulnCheck

llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attackers to achieve arbitrary read and write access by st...

Aliases:
CVE-2026-39909 GHSA-fpvp-jgx3-4w9q
Published: 2026-08-21 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: microsoft

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

Aliases:
CVE-2026-69502 GHSA-cc49-67hv-4hv5
Published: 2026-08-21 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: CIRCL

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the dr...

Aliases:
GHSA-gh7r-589j-33x7 CVE-2026-77812
Published: 2026-08-21 View Complete Profile →
MEDIUM (6.3) CVSS 4.0 Source: CIRCL

A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document ...

Aliases:
GHSA-q62h-w723-22p2 CVE-2026-77761
Published: 2026-08-21 View Complete Profile →
HIGH (8.7) CVSS 4.0 Source: CIRCL

A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several parsing and loadin...

Aliases:
GHSA-65gx-wjvj-88j8 CVE-2026-77755
Published: 2026-08-21 View Complete Profile →
MEDIUM (6.9) CVSS 4.0 Source: CIRCL

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the intern...

Aliases:
CVE-2026-77710 GHSA-pqpx-w6cx-7q9c
Published: 2026-08-21 View Complete Profile →
CRITICAL (10) CVSS 3.1 Source: microsoft

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Aliases:
CVE-2026-69555 GHSA-m9j2-qfhx-hm42
Published: 2026-08-20 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: microsoft

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Aliases:
GHSA-66h9-689p-45mg CVE-2026-69400
Published: 2026-08-20 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: microsoft

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

Aliases:
GHSA-92gp-p329-q463 CVE-2026-68782
Published: 2026-08-20 View Complete Profile →

EUVD-2026-63693

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: microsoft

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Aliases:
CVE-2026-69836 GHSA-v6wh-624g-vvmv
Published: 2026-08-20 View Complete Profile →
CRITICAL (9.1) CVSS 4.0 Source: EEF

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_...

Aliases:
GHSA-5x87-gf34-8ww7 CVE-2026-53424
Published: 2026-08-20 View Complete Profile →
CRITICAL (9.6) CVSS 3.1 Source: GitHub_M

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attri...

Aliases:
CVE-2026-55085
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-...

Aliases:
CVE-2026-72717
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-l...

Aliases:
CVE-2026-71868
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into...

Aliases:
CVE-2026-71871
Published: 2026-08-19 View Complete Profile →

EUVD-2026-62588

Actively Exploited
CRITICAL (9.5) CVSS 4.0 Source: Kaspersky

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to...

Aliases:
GHSA-f8q9-f337-2p3r CVE-2026-72530
Published: 2026-08-19 View Complete Profile →

EUVD-2026-62587

Actively Exploited
CRITICAL (9.3) CVSS 4.0 Source: Kaspersky

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by ca...

Aliases:
GHSA-xc2x-q39j-746f CVE-2026-72529
Published: 2026-08-19 View Complete Profile →

EUVD-2026-62395

Actively Exploited
CRITICAL (9.3) CVSS 4.0 Source: NetScaler

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Aliases:
CVE-2026-19490 GHSA-7c6h-rhhv-wm8r
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.4) CVSS 4.0 Source: VulDB

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead ...

Aliases:
GHSA-6rxv-jchw-qjv3 CVE-2026-76003
Published: 2026-08-19 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: oracle

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.0. Easily exploitable vulnerability allows unauthen...

Aliases:
GHSA-v3hv-vxr8-r858 CVE-2026-71152
Published: 2026-08-18 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: oracle

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager). The supported version that is affected is 11.4.0. ...

Aliases:
CVE-2026-71036 GHSA-5pxc-m8gx-mp6h
Published: 2026-08-18 View Complete Profile →
CRITICAL (9.1) CVSS 3.1 Source: redhat

A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or...

Aliases:
CVE-2026-71472 GHSA-gqg9-92w2-w94m
Published: 2026-08-17 View Complete Profile →

EUVD-2026-58069

Actively Exploited
HIGH (8.9) CVSS 3.1 Source: mitre

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitiz...

Aliases:
GHSA-jqh7-pchh-v74j CVE-2026-73570
Published: 2026-08-13 View Complete Profile →
CRITICAL (9) CVSS 3.1 Source: redhat

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability...

Aliases:
CVE-2026-71471 GHSA-j9xr-mxxr-3948
Published: 2026-08-12 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy atta...

Aliases:
GHSA-hr6f-38vx-3c48 CVE-2026-72508
Published: 2026-08-12 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specificat...

Aliases:
CVE-2026-73268 GHSA-6c6p-j4gf-mj2c
Published: 2026-08-12 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped Cluste...

Aliases:
GHSA-h2w9-5qx3-frqq CVE-2026-73269
Published: 2026-08-12 View Complete Profile →

EUVD-2026-57388

Actively Exploited
HIGH (7.5) CVSS 3.1 Source: JFROG

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

Aliases:
CVE-2026-42018 GHSA-3q94-gprh-7pwm
Published: 2026-08-12 View Complete Profile →

EUVD-2026-57256

Actively Exploited
MEDIUM (5.3) CVSS 3.1 Source: JFROG

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

Aliases:
GHSA-g2mp-x73p-93xc CVE-2026-66384
Published: 2026-08-12 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper...

Aliases:
CVE-2026-72526 GHSA-hp26-rmxw-4cpv
Published: 2026-08-12 View Complete Profile →

EUVD-2026-56431

Actively Exploited
HIGH (8.8) CVSS 3.1 Source: microsoft

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Aliases:
CVE-2026-65660 GHSA-r94x-x846-rxqx
Published: 2026-08-11 View Complete Profile →
CRITICAL (10) CVSS 4.0 Source: Joomla

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

Aliases:
CVE-2026-66915 GHSA-ch8m-c7x9-7r7f
Published: 2026-08-10 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: NCSC.ch

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessib...

Aliases:
GHSA-wrxj-2wgm-px6x CVE-2026-54213
Published: 2026-08-07 View Complete Profile →

EUVD-2026-53822

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: WSO2

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which ...

Aliases:
CVE-2026-5430 GHSA-j7vh-5w8q-4m4x
Published: 2026-08-06 View Complete Profile →
CRITICAL (9) CVSS 3.1 Source: redhat

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privi...

Aliases:
CVE-2026-10090 GHSA-g9vp-wj77-5767
Published: 2026-08-05 View Complete Profile →

EUVD-2026-50404

Actively Exploited
MEDIUM (5.3) CVSS 3.1 Source: cisco

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged ac...

Aliases:
GHSA-x85f-hvgg-4944 CVE-2026-20316
Published: 2026-07-29 View Complete Profile →

EUVD-2026-49566

Actively Exploited
HIGH (8.1) CVSS 3.1 Source: JFROG

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

Aliases:
CVE-2026-42016 GHSA-58cv-8cfm-c8r8
Published: 2026-07-27 View Complete Profile →
CRITICAL (9.4) CVSS 3.1 Source: redhat

A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication...

Aliases:
GHSA-43hh-68v6-mf36 CVE-2026-16242
Published: 2026-07-20 View Complete Profile →
CRITICAL (9.8) CVSS 3.1 Source: Linux

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding new subreqs Fix netfs_retry_read_subrequests() and netfs_retry_write_stream() to ta...

Aliases:
CVE-2026-64068 GHSA-8vm6-jvf8-6w38
Published: 2026-07-19 View Complete Profile →

EUVD-2026-45205

Actively Exploited
CRITICAL (9.3) CVSS 4.0 Source: SRA

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates...

Aliases:
GHSA-m32j-v93f-gfgc CVE-2026-9586
Published: 2026-07-17 View Complete Profile →
UNKNOWN (0) CVSS Source: INCIBE

Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisat...

Aliases:
GHSA-vr42-524g-49w2 CVE-2026-4765
Published: 2026-07-13 View Complete Profile →
CRITICAL (9.3) CVSS 3.1 Source: redhat

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed wi...

Aliases:
CVE-2026-15143 GHSA-34cr-c6hf-4xgc
Published: 2026-07-10 View Complete Profile →

EUVD-2026-42359

Actively Exploited
HIGH (8.8) CVSS 4.0 Source: GitHub_M

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Au...

Aliases:
PYSEC-2026-3479 CVE-2026-59822 GHSA-7488-6r32-c95q
Published: 2026-07-08 View Complete Profile →

EUVD-2026-41669

Actively Exploited
HIGH (7.8) CVSS 3.1 Source: Linux

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE...

Aliases:
CVE-2026-53362 GHSA-3x6f-vm7x-cgm7
Published: 2026-07-04 View Complete Profile →

EUVD-2026-40307

Actively Exploited
HIGH (8.8) CVSS 4.0 Source: NetScaler

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Prox...

Aliases:
CVE-2026-8452 GHSA-r7wg-r5wj-c765
Published: 2026-06-30 View Complete Profile →

EUVD-2026-39922

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: GitHub_M

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public config...

Aliases:
CVE-2026-49869
Published: 2026-06-26 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: GitHub_M

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if t...

Aliases:
CVE-2026-46376
Published: 2026-05-29 View Complete Profile →
CRITICAL (9) CVSS 3.1 Source: redhat

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configu...

Aliases:
GHSA-jg8v-92xc-cx65 CVE-2026-4408
Published: 2026-05-28 View Complete Profile →
CRITICAL (9) CVSS 3.1 Source: redhat

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution charact...

Aliases:
GHSA-hwwh-4hhw-h9jf CVE-2026-4480
Published: 2026-05-26 View Complete Profile →
CRITICAL (9.9) CVSS 3.1 Source: redhat

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when...

Aliases:
GHSA-7jcp-v9w4-wjmg CVE-2026-7374
Published: 2026-05-26 View Complete Profile →
HIGH (7.8) CVSS 3.1 Source: ENISA

Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEON...

Aliases:
CVE-2026-0856 GHSA-q549-3jgw-crc8
Published: 2026-05-20 View Complete Profile →
HIGH (7.9) CVSS 3.1 Source: ENISA

Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permissi...

Aliases:
CVE-2026-22314 GHSA-xcwx-69fp-83wm
Published: 2026-05-20 View Complete Profile →
CRITICAL (9.3) CVSS 4.0 Source: VulDB

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of ...

Aliases:
CVE-2026-8836 GHSA-3w8m-3w76-f6mh
Published: 2026-05-18 View Complete Profile →
MEDIUM (4.7) CVSS 4.0 Source: CERT-PL

Multiple BinSoft products are vulnerable to Remote Command Execution. An authorized user with access to the application and direct access to the backend database can achieve system command execution ...

Aliases:
GHSA-vw9m-6vfh-43xf CVE-2026-40552
Published: 2026-04-28 View Complete Profile →
HIGH (8.4) CVSS 4.0 Source: CERT-PL

Multiple BinSoft products perform client-side authentication. An attacker with access to any application instance connected to the backend server can bypass the login verification process by manipulat...

Aliases:
GHSA-4r5q-f55r-9frx CVE-2026-40551
Published: 2026-04-28 View Complete Profile →
MEDIUM (6.9) CVSS 4.0 Source: CERT-PL

Multiple BinSoft products are vulnerable to Privilege Escalation due to excessive database privileges assigned to the user used by the application. An attacker with access to any running application i...

Aliases:
GHSA-97j3-fvqp-6gpf CVE-2026-40550
Published: 2026-04-28 View Complete Profile →

EUVD-2026-9438

Actively Exploited
CRITICAL (10) CVSS 3.1 Source: cisco

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an a...

Aliases:
CVE-2026-20079 GHSA-mv8w-c2qv-cgrg
Published: 2026-03-04 View Complete Profile →
CRITICAL (9.2) CVSS 4.0 Source: snyk

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to p...

Aliases:
CVE-2026-1615 GHSA-87r5-mp6g-5w5j
Published: 2026-02-09 View Complete Profile →

EUVD-2026-2223

Actively Exploited
HIGH (7.4) CVSS 3.1 Source: fortinet

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, F...

Aliases:
GHSA-mj8x-m8f5-x4w8 CVE-2025-25249
Published: 2026-01-13 View Complete Profile →