##
Updated at UTC 2026-08-03T18:40:15.195688
| CVE | CVSS | EPSS | Posts | Repos | Nuclei | Updated | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-67352 | 7.6 | 0.21% | 1 | 0 | 2026-08-03T17:16:42.107000 | luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in | |
| CVE-2026-67330 | 9.9 | 0.35% | 1 | 0 | 2026-08-03T17:16:41.680000 | @better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1. | |
| CVE-2026-67299 | 7.5 | 0.33% | 1 | 0 | 2026-08-03T17:16:40.300000 | FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async up | |
| CVE-2026-18556 | 0 | 0.27% | 2 | 0 | 2026-08-03T17:16:34.227000 | Authentication bypass using an alternate path or channel vulnerability in N-able | |
| CVE-2026-16300 | 9.8 | 0.15% | 2 | 0 | 2026-08-03T17:16:30.953000 | The ChamaWP WordPress plugin before 1.0.13 does not properly validate a passwor | |
| CVE-2026-13339 | 7.5 | 0.64% | 1 | 0 | 2026-08-03T17:16:29.720000 | The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal i | |
| CVE-2026-18141 | 8.2 | 0.25% | 1 | 0 | 2026-08-03T16:39:02.593000 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Ev | |
| CVE-2026-18577 | 0 | 1.48% | 5 | 0 | 2026-08-03T16:16:28.697000 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | |
| CVE-2026-18574 | None | 0.00% | 4 | 0 | 2026-08-03T15:32:49 | An authentication bypass vulnerability in Check Point Security Management Server | |
| CVE-2026-68580 | 7.5 | 0.24% | 2 | 0 | 2026-08-03T15:16:21.177000 | FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio inp | |
| CVE-2026-8763 | 0 | 0.33% | 2 | 0 | 2026-08-03T14:16:30.857000 | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot | |
| CVE-2026-33591 | None | 0.00% | 2 | 0 | 2026-08-03T12:32:43 | A vulnerability in Wapt Server before version 2.6.1.17813 allows a remote unaut | |
| CVE-2026-9593 | 6.7 | 0.11% | 2 | 0 | 2026-08-03T09:32:46 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and | |
| CVE-2026-58062 | None | 0.20% | 1 | 0 | 2026-08-03T09:32:36 | In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without bi | |
| CVE-2026-18589 | 9.8 | 0.61% | 2 | 0 | 2026-08-03T07:16:43.260000 | A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the | |
| CVE-2026-59650 | None | 0.26% | 1 | 0 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiates unvalid | |
| CVE-2026-59638 | None | 0.28% | 1 | 0 | 2026-08-03T06:32:44 | In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enable | |
| CVE-2026-3245 | 7.5 | 0.24% | 1 | 0 | 2026-08-03T00:30:35 | A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that | |
| CVE-2026-68579 | 9.6 | 0.27% | 1 | 0 | 2026-08-02T15:30:25 | FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the W | |
| CVE-2026-68578 | 7.5 | 0.21% | 1 | 0 | 2026-08-02T15:30:25 | ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the | |
| CVE-2026-67356 | 8.8 | 0.25% | 1 | 0 | 2026-08-02T15:30:25 | ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigg | |
| CVE-2026-68581 | 8.1 | 0.32% | 1 | 0 | 2026-08-02T15:30:25 | Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API | |
| CVE-2025-71399 | 8.6 | 0.31% | 1 | 0 | 2026-08-02T15:30:21 | Better Auth relies on better-call, which uses the rou3 router library. In affect | |
| CVE-2026-68582 | 6.5 | 0.21% | 1 | 0 | 2026-08-02T13:16:54.233000 | Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorizat | |
| CVE-2026-67357 | 7.5 | 0.25% | 1 | 0 | 2026-08-02T13:16:53.520000 | ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability | |
| CVE-2026-16232 | 9.1 | 71.39% | 1 | 3 | template | 2026-08-02T09:31:30 | An authentication bypass vulnerability in the Check Point SmartConsole login pro |
| CVE-2026-8457 | 9.8 | 0.40% | 2 | 0 | 2026-08-02T00:31:17 | The WooCommerce - Social Login plugin for WordPress is vulnerable to Authenticat | |
| CVE-2026-18352 | 7.5 | 0.68% | 1 | 0 | 2026-08-02T00:31:17 | The User Access Manager plugin for WordPress is vulnerable to Directory Traversa | |
| CVE-2026-67325 | 8.8 | 1.48% | 1 | 0 | 2026-08-01T15:30:37 | GitPython before 3.1.51 contains an incomplete command injection blocklist that | |
| CVE-2026-67292 | 6.5 | 0.26% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gat | |
| CVE-2026-67305 | None | 0.49% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerabili | |
| CVE-2026-67290 | 7.5 | 0.43% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TS | |
| CVE-2026-67336 | 8.7 | 0.16% | 2 | 0 | 2026-08-01T15:30:36 | better-auth versions before 1.6.11 contain insecure cryptographic defaults in th | |
| CVE-2026-67291 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bound | |
| CVE-2026-67301 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async u | |
| CVE-2026-67300 | 7.5 | 0.33% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities i | |
| CVE-2026-67298 | 7.5 | 0.38% | 1 | 0 | 2026-08-01T15:30:36 | FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server | |
| CVE-2026-67308 | 10.0 | 0.45% | 1 | 0 | 2026-08-01T15:30:36 | Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub | |
| CVE-2026-67323 | 8.4 | 1.02% | 1 | 0 | 2026-08-01T15:30:36 | GitPython before 3.1.51 fails to guard against dangerous Git options passed as k | |
| CVE-2026-67322 | 7.5 | 0.27% | 1 | 0 | 2026-08-01T15:30:36 | GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Re | |
| CVE-2026-67328 | 8.1 | 0.28% | 1 | 0 | 2026-08-01T15:30:36 | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass v | |
| CVE-2026-67327 | 8.3 | 0.23% | 1 | 0 | 2026-08-01T15:30:36 | better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-be | |
| CVE-2026-67343 | 8.8 | 0.30% | 1 | 0 | 2026-08-01T15:30:31 | ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the | |
| CVE-2026-67340 | 9.8 | 0.52% | 2 | 0 | 2026-08-01T15:30:30 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host | |
| CVE-2026-67289 | 9.8 | 0.38% | 2 | 0 | 2026-08-01T15:30:26 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and c | |
| CVE-2026-67297 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T15:30:26 | FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing T | |
| CVE-2026-66402 | 9.8 | 0.29% | 2 | 0 | 2026-08-01T15:30:25 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certif | |
| CVE-2026-67288 | 7.5 | 0.35% | 1 | 0 | 2026-08-01T15:30:25 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart | |
| CVE-2026-67342 | 9.8 | 0.32% | 3 | 0 | 2026-08-01T13:17:05.417000 | ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in | |
| CVE-2026-67341 | 9.8 | 0.32% | 2 | 0 | 2026-08-01T13:17:05.273000 | ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks o | |
| CVE-2026-67331 | 8.3 | 0.24% | 1 | 0 | 2026-08-01T13:17:03.833000 | better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organi | |
| CVE-2026-67324 | 9.8 | 0.38% | 1 | 0 | 2026-08-01T13:17:02.770000 | GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> | |
| CVE-2026-67304 | 7.5 | 0.35% | 1 | 0 | 2026-08-01T13:16:59.970000 | FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smart | |
| CVE-2026-67296 | 7.5 | 0.34% | 1 | 0 | 2026-08-01T13:16:58.830000 | FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI se | |
| CVE-2026-67294 | 5.9 | 0.27% | 1 | 0 | 2026-08-01T13:16:58.523000 | FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose | |
| CVE-2026-16635 | 8.8 | 0.31% | 1 | 0 | 2026-08-01T09:30:37 | The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in a | |
| CVE-2026-15964 | 9.8 | 0.49% | 2 | 1 | 2026-08-01T09:30:37 | The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication | |
| CVE-2026-15450 | 8.1 | 0.38% | 1 | 0 | 2026-08-01T09:30:36 | The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable | |
| CVE-2026-14561 | None | 0.14% | 1 | 0 | 2026-08-01T09:30:36 | The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does n | |
| CVE-2026-16144 | 8.1 | 0.69% | 1 | 0 | 2026-08-01T09:17:00.690000 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vu | |
| CVE-2026-66066 | 0 | 1.70% | 6 | 6 | 2026-08-01T08:16:30.147000 | Action Pack is a framework for handling and responding to web requests. In versi | |
| CVE-2026-15988 | 8.8 | 0.22% | 1 | 0 | 2026-08-01T08:16:29.610000 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPre | |
| CVE-2026-15368 | 0 | 0.14% | 1 | 0 | 2026-08-01T07:16:31.477000 | The User Profile Builder WordPress plugin before 3.16.4 does not correctly bind | |
| CVE-2026-3141 | 9.1 | 0.47% | 2 | 1 | 2026-08-01T06:16:26.030000 | The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file d | |
| CVE-2026-20316 | 5.3 | 0.79% | 4 | 0 | 2026-08-01T05:16:55.973000 | A vulnerability in the web interface of Cisco Secure Firewall Management Center | |
| CVE-2026-17566 | 9.9 | 0.43% | 1 | 0 | 2026-08-01T05:16:55.827000 | pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by in | |
| CVE-2026-17351 | 9.0 | 0.45% | 1 | 1 | 2026-08-01T05:16:55.670000 | The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query pas | |
| CVE-2026-17347 | 7.5 | 0.27% | 1 | 0 | 2026-08-01T05:16:55.400000 | The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administr | |
| CVE-2026-15006 | 7.5 | 0.83% | 2 | 0 | 2026-08-01T03:31:19 | The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email | |
| CVE-2026-15414 | 8.8 | 0.34% | 1 | 0 | 2026-08-01T03:16:25.757000 | The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privileg | |
| CVE-2026-34641 | 7.8 | 0.14% | 1 | 0 | 2026-08-01T00:31:02 | Premiere Pro is affected by an out-of-bounds write vulnerability that could resu | |
| CVE-2026-63223 | 9.8 | 0.49% | 1 | 1 | 2026-08-01T00:17:17.750000 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and | |
| CVE-2026-53500 | 8.2 | 0.29% | 1 | 0 | 2026-08-01T00:17:16.713000 | Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, | |
| CVE-2026-68771 | 9.8 | 0.62% | 2 | 0 | 2026-07-31T22:17:03.630000 | ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrai | |
| CVE-2026-43832 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:56 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2026-14319 | 7.5 | 0.32% | 1 | 0 | 2026-07-31T21:32:56 | The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to | |
| CVE-2026-15258 | 8.1 | 0.22% | 1 | 0 | 2026-07-31T21:32:56 | The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not | |
| CVE-2025-69933 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T21:32:55 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /me | |
| CVE-2026-43829 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:55 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2026-43831 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:32:55 | Successful exploitation of the vulnerability could allow an unauthenticated atta | |
| CVE-2026-15048 | 7.5 | 0.26% | 1 | 0 | 2026-07-31T21:32:55 | The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization c | |
| CVE-2026-68770 | 9.8 | 0.52% | 2 | 0 | 2026-07-31T21:32:05 | sentence-transformers contains a security control bypass vulnerability that allo | |
| CVE-2026-67822 | 9.8 | 0.29% | 1 | 0 | 2026-07-31T21:31:55 | Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in | |
| CVE-2026-43830 | 9.8 | 0.31% | 1 | 0 | 2026-07-31T21:31:54 | Successful exploitation of the command injection vulnerability could allow an at | |
| CVE-2026-14930 | 7.5 | 0.24% | 1 | 0 | 2026-07-31T21:31:54 | The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorizati | |
| CVE-2025-69936 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T21:31:53 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /ed | |
| CVE-2026-56673 | 7.5 | 0.43% | 1 | 0 | 2026-07-31T20:16:52.487000 | ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node | |
| CVE-2026-53510 | 8.1 | 0.40% | 1 | 0 | 2026-07-31T20:16:51.530000 | Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operatio | |
| CVE-2026-18452 | 10.0 | 0.43% | 1 | 0 | 2026-07-31T20:16:49.927000 | DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials v | |
| CVE-2026-17561 | 9.8 | 0.31% | 3 | 0 | 2026-07-31T20:16:49.313000 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innot | |
| CVE-2026-14483 | 9.8 | 0.61% | 1 | 1 | 2026-07-31T20:16:46.443000 | The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulner | |
| CVE-2026-53599 | 7.5 | 0.31% | 1 | 0 | 2026-07-31T19:43:51 | ## Summary `rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool | |
| CVE-2026-56670 | 8.2 | 0.22% | 1 | 0 | 2026-07-31T19:17:11.290000 | ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes int | |
| CVE-2026-54725 | 9.6 | 0.32% | 2 | 0 | 2026-07-31T19:17:10.833000 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret | |
| CVE-2026-52856 | 7.5 | 0.34% | 1 | 0 | 2026-07-31T19:17:09.120000 | Wings is the server control plane for Pterodactyl, a free, open-source game serv | |
| CVE-2025-69935 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T19:17:03.420000 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the | |
| CVE-2025-69934 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T19:17:03.113000 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /de | |
| CVE-2026-53505 | 7.5 | 0.34% | 1 | 0 | 2026-07-31T19:00:45 | ### Summary Thumbor's `filters:proportion(<value>)` filter does not enforce an u | |
| CVE-2026-53504 | 7.5 | 0.34% | 1 | 0 | 2026-07-31T18:58:29 | ### Summary The regular expression used to parse the `convolution` filter exhibi | |
| CVE-2026-53503 | 7.5 | 0.42% | 1 | 0 | 2026-07-31T18:54:57 | ### Summary Thumbor's `filters:convolution(<matrix>, <columns>, <should_normaliz | |
| CVE-2026-53501 | 8.2 | 0.21% | 1 | 0 | 2026-07-31T18:51:54 | # HMAC validation bypass via multiple `.replace()` calls when removing URL signa | |
| CVE-2026-62391 | 8.1 | 0.40% | 1 | 0 | 2026-07-31T18:33:21 | The security fix for CVE-2025-66518 is incomplete. Any client who can access to | |
| CVE-2026-12695 | 8.1 | 0.29% | 1 | 0 | 2026-07-31T18:33:20 | The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitte | |
| CVE-2026-12251 | 8.1 | 0.23% | 1 | 0 | 2026-07-31T18:33:20 | The Ultimate Member WordPress plugin before 2.12.1 does not filter administrato | |
| CVE-2026-12721 | 8.6 | 0.26% | 1 | 0 | 2026-07-31T18:33:20 | The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape | |
| CVE-2025-69937 | 9.8 | 0.26% | 1 | 0 | 2026-07-31T18:33:16 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the | |
| CVE-2026-17349 | 9.6 | 0.30% | 1 | 0 | 2026-07-31T18:32:25 | /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced | |
| CVE-2026-17346 | 8.8 | 0.43% | 1 | 0 | 2026-07-31T18:32:24 | The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched six | |
| CVE-2026-13609 | 8.8 | 0.25% | 1 | 0 | 2026-07-31T18:32:17 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML ent | |
| CVE-2026-35847 | 9.8 | 0.37% | 1 | 0 | 2026-07-31T18:32:13 | An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrar | |
| CVE-2026-18446 | 7.5 | 0.22% | 1 | 0 | 2026-07-31T18:17:13.383000 | fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash | |
| CVE-2026-12720 | 7.5 | 0.30% | 1 | 0 | 2026-07-31T18:17:10.337000 | The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be | |
| CVE-2026-10685 | 7.6 | 0.18% | 2 | 0 | 2026-07-31T18:17:09.510000 | The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() | |
| CVE-2026-65313 | 8.1 | 0.18% | 1 | 0 | 2026-07-31T17:16:34.970000 | A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engin | |
| CVE-2026-65310 | 7.5 | 0.32% | 1 | 0 | 2026-07-31T17:16:34.750000 | ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affecte | |
| CVE-2026-14919 | 9.8 | 0.28% | 1 | 0 | 2026-07-31T17:16:32.863000 | The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its | |
| CVE-2026-12562 | 8.8 | 0.28% | 1 | 0 | 2026-07-31T16:16:57.663000 | The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that | |
| CVE-2026-52855 | 9.9 | 0.27% | 1 | 0 | 2026-07-31T16:16:48 | ### Impact **Type:** Exposure of sensitive information / insufficiently protect | |
| CVE-2026-14830 | 7.5 | 0.21% | 1 | 0 | 2026-07-31T15:33:52 | The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment proces | |
| CVE-2026-18358 | 7.5 | 0.43% | 1 | 0 | 2026-07-31T15:32:58 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. | |
| CVE-2026-14333 | 7.5 | 0.30% | 1 | 0 | 2026-07-31T14:16:45.960000 | The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in | |
| CVE-2026-10079 | 8.5 | 0.17% | 1 | 0 | 2026-07-31T12:30:30 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Wh | |
| CVE-2026-52539 | 9.1 | 0.30% | 1 | 0 | 2026-07-31T12:16:50.780000 | Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOK | |
| CVE-2026-38709 | 9.8 | 2.67% | 2 | 0 | 2026-07-31T12:16:49.683000 | TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, W | |
| CVE-2026-56672 | 8.2 | 0.24% | 1 | 0 | 2026-07-31T11:17:10.903000 | ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, | |
| CVE-2026-16236 | 8.8 | 0.63% | 1 | 0 | 2026-07-31T09:31:30 | The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Up | |
| CVE-2026-65309 | 7.5 | 0.15% | 1 | 0 | 2026-07-31T09:31:30 | ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmit | |
| CVE-2026-63362 | 5.9 | 1.53% | 1 | 0 | 2026-07-31T00:30:29 | An unsigned integer underflow in the PubSub signature verification path in open | |
| CVE-2026-66803 | 10.0 | 0.49% | 1 | 0 | 2026-07-30T21:31:57 | Improper access control in Azure Cosmos DB allows an unauthorized attacker to ex | |
| CVE-2026-66418 | 9.3 | 0.34% | 1 | 1 | 2026-07-30T21:31:57 | OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability t | |
| CVE-2026-17657 | 8.3 | 0.36% | 1 | 0 | 2026-07-30T21:31:32 | Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a r | |
| CVE-2026-17192 | 8.5 | 2.34% | 1 | 0 | 2026-07-30T19:10:52.250000 | A VCO feature does not sufficiently validate caller-supplied input, allowing req | |
| CVE-2026-28323 | 9.8 | 0.64% | 1 | 0 | 2026-07-30T18:31:47 | SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass | |
| CVE-2026-15435 | 9.8 | 0.73% | 1 | 0 | 2026-07-30T15:31:59 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0. | |
| CVE-2026-47876 | 9.3 | 0.28% | 1 | 0 | 2026-07-30T15:31:54 | VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual | |
| CVE-2026-59309 | 9.8 | 0.74% | 1 | 0 | 2026-07-30T15:31:54 | VMware vCenter contains an authentication bypass vulnerability in the VMware Dir | |
| CVE-2026-59310 | 9.8 | 1.14% | 1 | 0 | 2026-07-30T15:31:51 | VMware vCenter contains a directory traversal vulnerability in the Syslog server | |
| CVE-2026-16462 | 9.8 | 0.42% | 1 | 0 | 2026-07-30T14:31:21.447000 | In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitized. This a | |
| CVE-2026-5487 | 7.5 | 1.54% | 1 | 0 | 2026-07-30T14:18:46.477000 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-12935 | 0 | 0.81% | 1 | 0 | 2026-07-30T14:12:18.697000 | The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking | |
| CVE-2026-64547 | 8.1 | 0.28% | 1 | 0 | 2026-07-30T06:25:58.463000 | In the Linux kernel, the following vulnerability has been resolved: net: usb: n | |
| CVE-2026-48449 | 10.0 | 0.54% | 2 | 0 | 2026-07-30T03:31:28 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi | |
| CVE-2026-5492 | 6.5 | 1.60% | 1 | 0 | 2026-07-29T21:31:08 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-5491 | 7.5 | 1.54% | 1 | 0 | 2026-07-29T21:31:07 | DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnera | |
| CVE-2026-60137 | 5.9 | 79.03% | 1 | 47 | 2026-07-29T20:17:06.270000 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does no | |
| CVE-2026-16655 | 7.2 | 0.30% | 2 | 0 | 2026-07-29T12:31:30 | The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Fo | |
| CVE-2026-42533 | 8.1 | 3.60% | 1 | 9 | 2026-07-29T05:16:44.720000 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive | |
| CVE-2026-16347 | 8.8 | 0.23% | 1 | 0 | 2026-07-28T21:31:39 | MikroTik RouterOS contains a weakness in its API authentication handling that la | |
| CVE-2026-16771 | 8.8 | 0.25% | 1 | 0 | 2026-07-28T21:31:32 | In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to en | |
| CVE-2026-51302 | 9.8 | 0.00% | 1 | 1 | 2026-07-28T15:33:16 | SQLite 3.41 has a use-after-free vulnerability exists in the expression evaluati | |
| CVE-2026-11841 | 9.4 | 0.46% | 2 | 0 | 2026-07-28T12:31:20 | An attacker may perform unauthenticated read and write operations on sensitive f | |
| CVE-2026-45112 | 7.5 | 1.94% | 1 | 0 | 2026-07-27T21:32:25 | Allocation of Resources Without Limits or Throttling vulnerability in Apache Thr | |
| CVE-2026-17191 | 9.1 | 2.83% | 1 | 0 | 2026-07-27T18:31:56 | An input validation vulnerability exists in an API component of the orchestrator | |
| CVE-2026-62379 | 9.8 | 0.00% | 1 | 0 | 2026-07-24T21:11:10 | ## Summary A pre-authentication remote code execution vulnerability affects Open | |
| CVE-2026-56291 | 9.8 | 76.07% | 1 | 4 | template | 2026-07-24T13:30:37.550000 | Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms ex |
| CVE-2026-50522 | 9.8 | 75.76% | 3 | 5 | 2026-07-23T15:44:10.873000 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unaut | |
| CVE-2026-46331 | 7.8 | 0.53% | 1 | 14 | 2026-07-23T12:33:27 | In the Linux kernel, the following vulnerability has been resolved: net/sched: | |
| CVE-2026-16723 | 9.0 | 0.41% | 1 | 7 | 2026-07-23T09:32:08 | A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1. | |
| CVE-2026-54121 | 8.8 | 1.05% | 2 | 12 | 2026-07-21T19:54:33.623000 | Improper authorization in Active Directory Certificate Services (AD CS) allows a | |
| CVE-2026-52887 | 10.0 | 0.59% | 1 | 1 | 2026-07-20T16:17:05.020000 | NocoBase is an AI-powered no-code/low-code platform for building business applic | |
| CVE-2026-27771 | 8.2 | 43.07% | 1 | 2 | template | 2026-07-17T19:04:38 | ### CVE Description Gitea versions up to and including 1.26.1 have insufficient |
| CVE-2026-15409 | 10.0 | 78.44% | 2 | 6 | template | 2026-07-16T05:16:18.293000 | A Server-side request forgery (SSRF) vulnerability has been identified in the SM |
| CVE-2026-62177 | 0 | 0.00% | 1 | 0 | 2026-07-15T17:16:52.773000 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE- | |
| CVE-2026-48319 | 9.1 | 32.29% | 1 | 0 | 2026-07-14T21:32:32 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted D | |
| CVE-2026-15410 | 7.2 | 76.35% | 2 | 3 | 2026-07-14T21:32:21 | Post-authentication improper control of generation of code ('Code Injection') vu | |
| CVE-2026-49176 | 7.8 | 0.47% | 1 | 2 | 2026-07-14T18:32:01 | Improper privilege management in Windows WalletService allows an authorized atta | |
| CVE-2026-55111 | 7.5 | 0.34% | 1 | 0 | 2026-07-09T13:20:47.137000 | A malicious actor with access to the network could exploit a Path Traversal vuln | |
| CVE-2026-20896 | 9.8 | 31.81% | 1 | 6 | 2026-07-07T18:16:35.380000 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED | |
| CVE-2026-12045 | 9.0 | 0.48% | 1 | 0 | 2026-07-01T19:26:30.593000 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker wh | |
| CVE-2026-49413 | 7.1 | 0.15% | 1 | 1 | 2026-07-01T14:04:37.143000 | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by c | |
| CVE-2026-10702 | 4.3 | 0.72% | 3 | 2 | 2026-06-30T03:36:54 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability w | |
| CVE-2026-12044 | 8.8 | 0.71% | 1 | 0 | 2026-06-19T00:31:46 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT O | |
| CVE-2026-42897 | 8.1 | 70.31% | 5 | 1 | 2026-06-17T10:48:34.893000 | Improper neutralization of input during web page generation ('cross-site scripti | |
| CVE-2026-24061 | 9.8 | 97.88% | 1 | 74 | template | 2026-06-17T10:22:32.427000 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a " |
| CVE-2025-66376 | 7.2 | 21.62% | 1 | 0 | 2026-06-17T09:56:44.753000 | Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Clas | |
| CVE-2026-48030 | 9.9 | 1.54% | 1 | 1 | 2026-06-09T22:00:36 | ### Summary An OS Command Injection vulnerability in the terminal action handle | |
| CVE-2026-20079 | 10.0 | 37.67% | 1 | 1 | template | 2026-03-04T18:32:03 | A vulnerability in the web interface of Cisco Secure Firewall Management Center |
| CVE-2025-66518 | None | 0.89% | 1 | 0 | 2026-01-29T03:42:38 | Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols | |
| CVE-2026-1070 | 4.3 | 0.16% | 2 | 2 | 2026-01-24T09:30:33 | The Alex User Counter plugin for WordPress is vulnerable to Cross-Site Request F | |
| CVE-2013-4786 | 7.5 | 78.57% | 3 | 1 | 2025-04-11T04:12:49 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (R | |
| CVE-2026-18576 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63343 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62867 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62313 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62940 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62941 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-63125 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-44021 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-65321 | 0 | 0.44% | 2 | 1 | N/A | ||
| CVE-2026-56671 | 0 | 0.66% | 1 | 0 | N/A | ||
| CVE-2026-63222 | 0 | 0.45% | 1 | 0 | N/A | ||
| CVE-2026-63221 | 0 | 0.38% | 1 | 0 | N/A | ||
| CVE-2026-4941 | 0 | 0.00% | 1 | 2 | N/A | ||
| CVE-2026-63030 | 0 | 98.42% | 1 | 73 | template | N/A | |
| CVE-2026-18420 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-62999 | 0 | 0.29% | 1 | 0 | N/A | ||
| CVE-2026-62261 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-46647 | 0 | 0.00% | 1 | 0 | N/A | ||
| CVE-2026-46648 | 0 | 0.00% | 1 | 0 | N/A |
updated 2026-08-03T17:16:42.107000
1 posts
🟠 CVE-2026-67352 - High (7.6)
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is ren...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:41.680000
1 posts
🔴 CVE-2026-67330 - Critical (9.9)
@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through = 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authorization bypass. SCIM token issuance did not reject provider IDs already used by existing SSO, SAML, OIDC, generic...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67330/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:40.300000
1 posts
🟠 CVE-2026-67299 - High (7.5)
FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled (e.g. xfreerdp /async-update). In update_message_WindowIcon() a shallow CopyMemory() overwrites a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67299/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T17:16:34.227000
2 posts
📰 N-able N-central Flaw (CVE-2026-18556) Actively Exploited in Attacks
🚨 ACTIVE EXPLOITATION: A critical auth bypass flaw (CVE-2026-18556, CVSS 9.8) in N-able N-central RMM is being used to compromise MSPs. Attackers install CloudFlare tunnels for persistence. Patch to version 2026.3 NOW. #CVE #RMM #MSP
##🏆 New Achievement! Management Remotely Destroyed!
Today's dungeon crawl is brought to you by Deferred Patch Tuesdays — when you're too busy managing clients to manage yourself. N-able N-central, the RMM platform MSPs trust to run everyone else's networks, is harboring CVE-2026-18556, a CVSS 9.8 authentication bypass being actively exploited in the wild. Attackers are waltzing — no, sorry — strolling right through, dropping Cloudflare tunnels for cozy, persistent access. (1/2)
##updated 2026-08-03T17:16:30.953000
2 posts
CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. https://radar.offseq.com/threat/cve-2026-16300-cwe-862-missing-authorization-in-chamawp-fe7ac84163659c18 #OffSeq #WordPress #Vuln
##CVE-2026-16300: ChamaWP (<1.0.13) is vulnerable to missing authorization — attackers can reset any user’s password, including admins. Risk: full site takeover. Patch status unconfirmed; restrict password resets & monitor logs. https://radar.offseq.com/threat/cve-2026-16300-cwe-862-missing-authorization-in-chamawp-fe7ac84163659c18 #OffSeq #WordPress #Vuln
##updated 2026-08-03T17:16:29.720000
1 posts
🟠 CVE-2026-13339 - High (7.5)
The CubeWP Framework plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.30 via the 'cubewp_get_svg_content' function. This makes it possible for unauthenticated attackers to read the contents of arb...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13339/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T16:39:02.593000
1 posts
🟠 CVE-2026-18141 - High (8.2)
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by ma...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T16:16:28.697000
5 posts
N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account…
#Cve202618577 #AuthenticationBypass #Nable #Ncentral #VulnerabilityManagement
##CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
##Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
##CVE-2026-18577 is being exploited in the wild for N-central account takeover. An incomplete patch let attackers gain admin access. Update to 2026.3.1.7.
#Nable #Ncentral #CVE202618577 #AccountTakeover #RMM #CyberSecurity
##Some time ago I discovered a meddled in the middle vulnerability between N-able agent and nCentral server that allowed full SYSTEM compromise of the endpoints, but this vulnerability in nCentral server is far far far worse:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
##updated 2026-08-03T15:32:49
4 posts
CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.
#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall
##CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. https://radar.offseq.com/threat/cve-2026-18574-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-checkpoint-security-b30ba167a9a0b365 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒
##CVE-2026-18574 is a Check Point authentication bypass rated CVSS 9.3, letting attackers run commands as admin. Patch via the latest Jumbo Hotfix.
#CheckPoint #CVE202618574 #AuthenticationBypass #SecurityManagement #CyberSecurity #Firewall
##CRITICAL auth bypass (CVE-2026-18574, CVSS 9.3) affects Check Point Security Management Server & MDS. Remote attackers can execute commands w/o auth. No patch yet — restrict management access. https://radar.offseq.com/threat/cve-2026-18574-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-checkpoint-security-b30ba167a9a0b365 #OffSeq #CVE202618574 #CheckPoint #Infosec 🔒
##updated 2026-08-03T15:16:21.177000
2 posts
CVE-2026-68580 - Heap buffer overflow in FreeRDP via audin integer overflow. Malicious RDP server can trigger RCE or DoS. CVSS 7.5. Unpatched - update immediately when available. #CVE #FreeRDP #infosec
##🟠 CVE-2026-68580 - High (7.5)
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can su...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68580/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-03T14:16:30.857000
2 posts
CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. https://radar.offseq.com/threat/cve-2026-8763-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-e499664fa1a18bc4 #OffSeq #BouncyCastle #Vuln #CVE20268763
##CVE-2026-8763: CRITICAL vuln in Bouncy Castle BC-JAVA (<1.85, 2.73.0-2.73.11). Improper cert validation via trailing dot bypasses name constraints — risk of MITM attacks. No patch yet. Monitor vendor for updates. https://radar.offseq.com/threat/cve-2026-8763-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-e499664fa1a18bc4 #OffSeq #BouncyCastle #Vuln #CVE20268763
##updated 2026-08-03T12:32:43
2 posts
Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-33591-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-tranquil-it-systems-98c0bb813dbf7caa #OffSeq #CVE202633591 #Infosec #Vulnerability
##Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-33591-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-tranquil-it-systems-98c0bb813dbf7caa #OffSeq #CVE202633591 #Infosec #Vulnerability
##updated 2026-08-03T09:32:46
2 posts
#OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593
https://certvde.com/en/advisories/vde-2026-065/
#CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
###OT #Advisory VDE-2026-065
Endress+Hauser: iDTM Debug Interface Vulnerability in the FDI Package Library
A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the application directory.
#CVE CVE-2026-9593
https://certvde.com/en/advisories/vde-2026-065/
#CSAF https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-065.json
##updated 2026-08-03T09:32:36
1 posts
CVE-2026-58062 (CRITICAL, CVSS 9.3): Bouncy Castle Java improperly validates stapled OCSP, risking cert trust. Affects =1.66, <1.85, LTS <2.73.12. Update to 1.85+ or LTS 2.73.12. Details: https://radar.offseq.com/threat/cve-2026-58062-cwe-295-improper-certificate-validation-in-legion-of-the-bouncy-castle-inc-bc-java-1fb42d02f3400e15 #OffSeq #BouncyCastle #JavaSecurity
##updated 2026-08-03T07:16:43.260000
2 posts
CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
##CVE-2026-18589 (CRITICAL, CVSS 9.3) in Wavlink WL-NU516U1: Stack buffer overflow in nas.cgi enables unauthenticated RCE/DoS. Patch available — update ASAP. https://radar.offseq.com/threat/cve-2026-18589-stack-based-buffer-overflow-in-wavlink-wl-nu516u1-be242f6f491145cd #OffSeq #CVE202618589 #IoTSecurity #PatchManagement
##updated 2026-08-03T06:32:44
1 posts
BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. https://radar.offseq.com/threat/cve-2026-59650-cwe-20-improper-input-validation-in-legion-of-the-bouncy-castle-inc-bc-java-bfb9720e803b614a #OffSeq #Vulnerability #Java #Cryptography
##updated 2026-08-03T06:32:44
1 posts
CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. https://radar.offseq.com/threat/cve-2026-59638-cwe-297-improper-validation-of-certificate-with-host-mismatch-in-legion-of-the-bouncy-aa319f6f20b27a8a #OffSeq #CVE202659638 #infosec
##updated 2026-08-03T00:30:35
1 posts
🟠 CVE-2026-3245 - High (7.5)
A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3245/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
🔴 CVE-2026-68579 - Critical (9.6)
FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68579/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
🟠 CVE-2026-68578 - High (7.5)
ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema muta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68578/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
🟠 CVE-2026-67356 - High (8.8)
ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can creat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67356/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:25
1 posts
🟠 CVE-2026-68581 - High (8.1)
Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JW...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68581/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T15:30:21
1 posts
🟠 CVE-2025-71399 - High (8.6)
Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-71399/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T13:16:54.233000
1 posts
CVE-2026-68582 (CRITICAL): go-vikunja vikunja ≤2.3.0 allows attackers with a share link to read kanban bucket titles & user info from other tenants due to broken object auth at /projects/{project}/views/{view}/tasks. Update to 2.4.0+! https://radar.offseq.com/threat/cve-2026-68582-authorization-bypass-through-user-controlled-key-in-go-vikunja-vikunja-b2e26579de3aa2bc #OffSeq #CVE202668582 #Vulnerability
##updated 2026-08-02T13:16:53.520000
1 posts
🟠 CVE-2026-67357 - High (7.5)
ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-Ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67357/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T09:31:30
1 posts
3 repos
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-08-02T00:31:17
2 posts
CVE-2026-8457: WPWeb WooCommerce - Social Login (<=2.8.7) suffers CRITICAL auth bypass. Forged Apple id_tokens + exposed nonce = attacker can access any WordPress user, even admins. Disable Apple login or plugin ASAP. https://radar.offseq.com/threat/cve-2026-8457-cwe-289-authentication-bypass-by-alternate-name-in-wpweb-woocommerce-social-login-6bb1cfa7304c2708 #OffSeq #WordPress #Vuln
##🔴 CVE-2026-8457 - Critical (9.8)
The WooCommerce - Social Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to and including 2.8.7. This is due to the plugin's Apple login handler accepting the Apple id_token and decoding only its base64 payload...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-8457/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-02T00:31:17
1 posts
🟠 CVE-2026-18352 - High (7.5)
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18352/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:37
1 posts
🟠 CVE-2026-67325 - High (8.8)
GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. Attackers can bypass the unsafe options guard by using abbreviated option names like upload_p inste...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67325/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
##updated 2026-08-01T15:30:36
1 posts
FreeRDP Windows client <3.29.0 has a CRITICAL heap buffer overflow in clipboard virtual channel (CVE-2026-67305). Malicious RDP servers can trigger remote code execution. Upgrade to 3.29.0+ ASAP. https://radar.offseq.com/threat/freerdp-windows-client-before-3290-contains-a-heap-buffer-overflow-vulnerability-in-the-clipboard-852516cbfae157b3 #OffSeq #FreeRDP #CVE202667305 #infosec
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67290 - High (7.5)
FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. Attackers can send malformed media format data from a server to trigger a c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67290/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
2 posts
CVE-2026-67336: better-auth <1.6.11 uses insecure crypto defaults in oidcProvider & mcp, advertising 'none' algo & accepting plain PKCE. Exploitation can lead to unsigned tokens & code interception. Severity: CRITICAL. Patch to 1.6.11+ https://radar.offseq.com/threat/better-auth-versions-before-1611-contain-insecure-cryptographic-defaults-in-the-oidcprovider-and-mcp-eb22076a221f3a81 #OffSeq #CVE202667336 #OAuth #Security
##🟠 CVE-2026-67336 - High (8.7)
better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and accept plain PKCE by default. Attackers can exploit algorithm negotiation to accept unsigned token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67336/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67291 - High (7.5)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-b...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67291/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67301 - High (7.5)
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. When AsyncUpdate is enabled (e.g., xfreerdp /async-update), update_message_PolygonSC() and ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67301/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67300 - High (7.5)
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67300/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67298 - High (7.5)
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_L...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67298/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🔴 CVE-2026-67308 - Critical (10)
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submitting pull requests with crafted VERSION.json files. Attackers can inject shell metacharacters int...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67308/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67323 - High (8.4)
GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing command injection via options such as --exec/--upload-pack (leading to arbitrary command execution). A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67323/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67322 - High (7.5)
GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git.polish_url(), which on non-Cygwin platforms calls os.path.expandvars() on the URL before invoking...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67322/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67328 - High (8.1)
@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign in as arbitrary users. Attackers can exploit domain verification parsing mismatches, orphaned prov...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67328/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:36
1 posts
🟠 CVE-2026-67327 - High (8.3)
better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-account hijacking on magic-link and email-OTP sign-in when open email/password registration is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67327/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:31
1 posts
🟠 CVE-2026-67343 - High (8.8)
ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retrieve the arcadedb.ha.clusterToken value in cleartext. Attackers can use the leaked token with X-Arcad...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67343/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:30
2 posts
🔴 CVE-2026-67340 - Critical (9.8)
ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permission can ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67340/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-67340: CRITICAL RCE in ArcadeDB <26.7.2. Users w/ UPDATE_SCHEMA can exploit JavaScript triggers to run OS commands. Patch status pending — restrict permissions & audit triggers. Details: https://radar.offseq.com/threat/cve-2026-67340-improper-control-of-generation-of-code-code-injection-in-arcadedata-arcadedb-7ff6de59519457ac #OffSeq #ArcadeDB #RCE #infosec
##updated 2026-08-01T15:30:26
2 posts
CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-does-not-validate-crlf-and-control-characters-in-the-server-2a6872dd9d8a1a0c #OffSeq #FreeRDP #CVE202667289 #infosec
##🔴 CVE-2026-67289 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. This value is copied into the client's ServerHostname and, when the client c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67289/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:26
1 posts
🟠 CVE-2026-67297 - High (7.5)
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67297/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:25
2 posts
CVE-2026-66402: FreeRDP <=3.28.0 suffers CRITICAL TLS cert validation flaws. Attackers can bypass server identity checks — risk of MITM & impersonation. Patch to 3.29.0 ASAP. 🔒 https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-contains-multiple-tls-certificate-identity-validation-277a8c919a50c368 #OffSeq #Vulnerability #TLS #FreeRDP
##🔴 CVE-2026-66402 - Critical (9.8)
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls_match_hostname(), and x509_utils_get_dns_names(). Because FreeRDP performs custom Common Name ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66402/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T15:30:25
1 posts
🟠 CVE-2026-67288 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.417000
3 posts
CVE-2026-67342 - Critical auth bypass in ArcadeDB HTTP endpoints. Attackers can access or modify unauthorized databases. CVSS 9.8. No patch yet, restrict exposure immediately. #CVE #ArcadeDB #infosec
##ArcadeDB <26.7.2 hit by CRITICAL CVE-2026-67342: Auth bypass via unvalidated HTTP endpoints (time series, batch, Prometheus, Grafana). Attackers can access & modify DBs. Restrict endpoints, monitor logs. https://radar.offseq.com/threat/cve-2026-67342-authorization-bypass-through-user-controlled-key-in-arcadedata-arcadedb-9042ff023c492871 #OffSeq #ArcadeDB #Vuln #Infosec
##🔴 CVE-2026-67342 - Critical (9.8)
ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoints that fail to validate database access permissions. Attackers can access and modify databases t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67342/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:05.273000
2 posts
ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. https://radar.offseq.com/threat/cve-2026-67341-incorrect-authorization-in-arcadedata-arcadedb-6bb8ad21f1650c1c #OffSeq #CVE #infosec
##🔴 CVE-2026-67341 - Critical (9.8)
ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with database access can execute arbitrary JavaScript code by submitting DEFINE FUNCTION statements, by...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67341/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:03.833000
1 posts
🟠 CVE-2026-67331 - High (8.3)
better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authenticated users to manage other users' providers. Attackers can regenerate SCIM bearer tokens, invalida...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67331/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:17:02.770000
1 posts
🔴 CVE-2026-67324 - Critical (9.8)
GitPython 3.1.50 fails to recognize joined short-option forms such as -u (the short form of --upload-pack=) when enforcing its default unsafe-option gate. When an application passes attacker-influenced clone options into Repo.clone_from(..., multi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67324/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:16:59.970000
1 posts
🟠 CVE-2026-67304 - High (7.5)
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader-s...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67304/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:16:58.830000
1 posts
🟠 CVE-2026-67296 - High (7.5)
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67296/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T13:16:58.523000
1 posts
CVE-2026-67294 | FreeRDP <3.29.0: Improper EKU validation lets trusted clientAuth certs be accepted as server certs in TLS, enabling RDP server impersonation. Severity: CRITICAL. Patch pending. https://radar.offseq.com/threat/freerdp-before-3290-improperly-validates-the-extended-key-usage-eku-purpose-of-the-peer-certificate-be33a6738062bc49 #OffSeq #FreeRDP #TLS #infosec
##updated 2026-08-01T09:30:37
1 posts
🟠 CVE-2026-16635 - High (8.8)
The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_update_user_role()` function passing an attacker-controlled Gravity Forms field value (`$lead[$feed-...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16635/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:37
2 posts
1 repos
🔴 CVE-2026-15964 - Critical (9.8)
The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password reset in all versions up to, and including, 2.0.0. This is due to the `ssoprocess_ajax()` function — registered on `wp_ajax_nopri...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15964/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CRITICAL: CVE-2026-15964 in britcoder Single Sign On For TNG <=2.0.0 lets unauthenticated attackers reset any WP user password via exposed AJAX. Full site takeover possible. Disable or restrict access now. https://radar.offseq.com/threat/cve-2026-15964-cwe-620-unverified-password-change-in-britcoder-single-sign-on-for-tng-6425266a865be131 #OffSeq #WordPress #CVE #Vuln
##updated 2026-08-01T09:30:36
1 posts
🟠 CVE-2026-15450 - High (8.1)
The Nex Forms – Ultimate Form Builder – Lite plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in versions up to, and including, 9.2.3. This is due to the delete_file() AJAX handler retrieving a file path from th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T09:30:36
1 posts
CVE-2026-14561 | CRITICAL | Authora: Easy login with mobile number (WordPress <1.7.7) suffers from improper authentication — attackers can log in as any user if they know a mobile number. Restrict plugin endpoints & monitor logins. https://radar.offseq.com/threat/cve-2026-14561-cwe-287-improper-authentication-in-authora-easy-login-with-mobile-number-9e459a9493ea0d5c #OffSeq #WordPress #Vuln
##updated 2026-08-01T09:17:00.690000
1 posts
🟠 CVE-2026-16144 - High (8.1)
The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'thisPermal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16144/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T08:16:30.147000
6 posts
6 repos
https://github.com/Zer0SumGam3/CVE-2026-66066-POC
https://github.com/0xBlackash/CVE-2026-66066
https://github.com/rails/rails-forensics-CVE-2026-66066
https://github.com/0xsha/KindaRails2Shell
📰 Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)
Ruby on Rails patches critical RCE vulnerability CVE-2026-66066 (CVSS 9.5). The flaw in Active Storage allows arbitrary file read via crafted image uploads, leading to potential RCE. Update immediately. #RubyOnRails #CVE #CyberSecurity
##📢 CVE-2026-66066 : faille critique dans Rails Active Storage avec potentiel RCE
📰 Source : BleepingComputer — publié le 1er août 2026 🔍 Contexte Les mainteneurs de Ruby on Rails ont publié un avis de sécurité concernant CVE-2026-66066, une vulnérabilité critique affectant le composant Active Storage, utilisé pour la gestion des uploads de fichiers et…
📖 cyberveille : https://cyberveille.ch/posts/2026-08-03-cve-2026-66066-faille-critique-dans-rails-active-storage-avec-potentiel-rce/
🌐 source : https://www.bleepingcomputer.com/news/security/rails-patches-critical-active-storage-flaw-with-rce-potential/
🟡 vérification factuelle moyenne
#ActiveStorage #RCE #Cyberveille
📢 Ruby on Rails corrige une vulnérabilité critique RCE via lecture arbitraire de fichiers (CVE-2026-66066)
📰 Source : SecurityWeek, publié le 1er août 2026. L'article rapporte la publication de correctifs par les mainteneurs de Ruby on Rails pour une vulnérabilité critique affectant le composant Active Storage.
📖 cyberveille : https://cyberveille.ch/posts/2026-08-03-ruby-on-rails-corrige-une-vulnerabilite-critique-rce-via-lecture-arbitraire-de-fichiers-cve-2026-66066/
🌐 source : https://www.securityweek.com/ruby-on-rails-patches-critical-vulnerability/
🟡 vérification factuelle moyenne
#RCE #RubyOnRails #Cyberveille
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
Ruby on Rails warnt vor CVE-2026-66066 in Active Storage. Angreifer können über präparierte Bild-Uploads Dateien des Servers auslesen und so an Schlüssel oder Zugangsdaten gelangen. Betroffen sind Anwendungen mit libvips. Updates und forensische Prüfwerkzeuge stehen bereit.
1/2
##CVE-2026-66066 (CVSS 9.5) enables Rails Active Storage RCE via libvips. A Metasploit module is now public. Upgrade Rails and rotate secrets.
#RubyOnRails #CVE202666066 #RCE #ActiveStorage #CyberSecurity #Metasploit
##updated 2026-08-01T08:16:29.610000
1 posts
🟠 CVE-2026-15988 - High (8.8)
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_aut...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15988/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T07:16:31.477000
1 posts
CVE-2026-15368: User Profile Builder WP plugin (CRITICAL) allows session hijack as any user — including admins — if using specific non-default configs. Review settings, restrict auto-login, and monitor for fixes. https://radar.offseq.com/threat/cve-2026-15368-cwe-269-improper-privilege-management-in-user-profile-builder-7cbf3fdcef75f1fb #OffSeq #WordPress #Infosec #CVE202615368 🔒
##updated 2026-08-01T06:16:26.030000
2 posts
1 repos
https://github.com/Rat5ak/CVE-2026-31413-BPF-Container-Escape
🔴 CVE-2026-3141 - Critical (9.1)
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-3141/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-3141 (CRITICAL, CVSS 9.1): wpwax FormGent for WordPress lets unauthenticated users delete arbitrary files via REST API. Linux servers risk full takeover if wp-config.php is deleted. Patch or restrict access now. https://radar.offseq.com/threat/cve-2026-3141-cwe-862-missing-authorization-in-wpwax-formgent-next-gen-ai-form-builder-for-wordpress-19f88cc02a19c7e3 #OffSeq #WordPress #CVE20263141
##updated 2026-08-01T05:16:55.973000
4 posts
📰 CISA Warns of Actively Exploited Cisco Firewall Management Flaw
📢 CISA WARNING: A static credential flaw in Cisco Secure Firewall Management Center (CVE-2026-20316) is actively exploited. The flaw allows unauthorized access. CISA adds it to KEV catalog, mandating federal action. #CVE202620316 #Cisco #KEV
##What year is it?:
##There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
The second is a high-severity vulnerability that was first published yesterday:
CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #infosec #vulnerability #Cisco
##Executive alert: CVE-2026-20316 exposes Cisco Secure Firewall Management Center to active exploitation via hard-coded credentials. Review enterprise exposure metrics, zero-trust segmentation, and board-level risk mitigation strategies today. https://thecybermind.co/jily
##updated 2026-08-01T05:16:55.827000
1 posts
🔴 CVE-2026-17566 - Critical (9.9)
pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17566/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T05:16:55.670000
1 posts
1 repos
🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T05:16:55.400000
1 posts
🟠 CVE-2026-17347 - High (7.5)
The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implement...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17347/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T03:31:19
2 posts
🟠 CVE-2026-15006 - High (7.5)
The Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.0 via the processAttachment function. This makes it p...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15006/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-15006: Bit integrations plugin ≤2.9.0 for WordPress has a HIGH severity path traversal flaw (CVSS 7.5). Unauthenticated attackers can read arbitrary server files. No patch yet — disable or restrict plugin. https://radar.offseq.com/threat/cve-2026-15006-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ee5b332d75a54eb5 #OffSeq #WordPress #Vuln
##updated 2026-08-01T03:16:25.757000
1 posts
🟠 CVE-2026-15414 - High (8.8)
The Subscriptions for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.0.0. This is due to the `save_meta_boxes()` function persisting the `_wps_plan_user_role` membership plan meta from `$...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:31:02
1 posts
🟠 CVE-2026-34641 - High (7.8)
Premiere Pro is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-34641/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:17:17.750000
1 posts
1 repos
🔴 CVE-2026-63223 - Critical (9.8)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe client filename extension, allowing a remote attacker to upload executable content when an applicat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-08-01T00:17:16.713000
1 posts
🟠 CVE-2026-53500 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issu...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53500/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T22:17:03.630000
2 posts
🔴 CVE-2026-68771 - Critical (9.8)
ComfyUI v0.23.0 contains an unsafe deserialization vulnerability in the LoadTrainingDataset node that allows unauthenticated remote attackers to execute arbitrary Python code by uploading a crafted pickle file and triggering its deserialization. A...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68771/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-68771: CRITICAL RCE in ComfyUI v0.23.0. Unauthenticated remote attackers can exploit unsafe pickle deserialization via /upload/image, leading to code execution as the process user. Restrict access & monitor endpoints. https://radar.offseq.com/threat/cve-2026-68771-deserialization-of-untrusted-data-in-comfy-org-comfyui-029fe0d26fda144c #OffSeq #CVE202668771 #infosec
##updated 2026-07-31T21:32:56
1 posts
🟠 CVE-2026-43832 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43832/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:56
1 posts
🟠 CVE-2026-14319 - High (7.5)
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their n...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14319/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:56
1 posts
🟠 CVE-2026-15258 - High (8.1)
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL inje...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15258/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🔴 CVE-2025-69933 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69933/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-43829 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43829/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-43831 - High (7.5)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43831/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:55
1 posts
🟠 CVE-2026-15048 - High (7.5)
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-15048/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:32:05
2 posts
CVE-2026-68770: Hugging Face sentence-transformers (all versions) impacted by CRITICAL code injection vuln. Local model dirs with malicious files can bypass trust_remote_code=False — arbitrary Python execution possible. Awaiting patch. https://radar.offseq.com/threat/cve-2026-68770-improper-control-of-generation-of-code-code-injection-in-hugging-face-sentence-e94c4111969724ef #OffSeq #CVE #AIsecurity
##🔴 CVE-2026-68770 - Critical (9.8)
sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, where the guar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-68770/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:55
1 posts
🔴 CVE-2026-67822 - Critical (9.8)
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without leng...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-67822/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:54
1 posts
🔴 CVE-2026-43830 - Critical (9.8)
Full details and mitigation steps are currently restricted and will be published at a later date.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-43830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:54
1 posts
🟠 CVE-2026-14930 - High (7.5)
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14930/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T21:31:53
1 posts
🔴 CVE-2025-69936 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69936/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:52.487000
1 posts
🟠 CVE-2026-56673 - High (7.5)
ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and exists_annotated_filepath join workflow-controlled annotated filenames to a base directory without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56673/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:51.530000
1 posts
🟠 CVE-2026-53510 - High (8.1)
Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. This issue is...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53510/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:49.927000
1 posts
🔴 CVE-2026-18452 - Critical (10)
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all installed DMS+ devices.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T20:16:49.313000
3 posts
CVE-2026-17561: CRITICAL code injection vuln in Logsign SIEM <6.4.108 (CVSS 9.8). Allows unauthenticated RCE — full compromise possible. No patch confirmed. Restrict mgmt access pending fix. https://radar.offseq.com/threat/improper-control-of-generation-of-code-code-injection-vulnerability-in-innotim-software-1c25c2f49555d07d #OffSeq #infosec #SIEM #vuln
##🔴 CVE-2026-17561 - Critical (9.8)
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection.
This issue affects Logsign SIEM: before 6.4.108.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17561/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
##updated 2026-07-31T20:16:46.443000
1 posts
1 repos
🔴 CVE-2026-14483 - Critical (9.8)
The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5.2.0 via the upload function. This is due to missing file type validation in the upload function, ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14483/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:43:51
1 posts
🟠 CVE-2026-53599 - High (7.5)
REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polygl...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53599/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:11.290000
1 posts
🟠 CVE-2026-56670 - High (8.2)
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files inline because image/svg+xml and related XML content types were absent from the dangerous-content...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56670/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:10.833000
2 posts
🔴 CVE-2026-54725 - Critical (9.6)
vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-54725/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##bank-vaults vault-secrets-webhook is impacted by CVE-2026-54725 (CRITICAL, CVSS 9.6). SSRF flaw lets attackers exfiltrate ServiceAccount JWTs via attacker-controlled Vault addresses. Update to 1.23.1 ASAP. https://radar.offseq.com/threat/cve-2026-54725-cwe-918-server-side-request-forgery-ssrf-in-bank-vaults-vault-secrets-webhook-ec0efb4a3e2ca6ff #OffSeq #Kubernetes #SSRF #CloudSecurity
##updated 2026-07-31T19:17:09.120000
1 posts
🟠 CVE-2026-52856 - High (7.5)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52856/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:03.420000
1 posts
🔴 CVE-2025-69935 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69935/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:17:03.113000
1 posts
🔴 CVE-2025-69934 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69934/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T19:00:45
1 posts
🟠 CVE-2026-53505 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:proportion() filter does not enforce an upper bound on and runs in the post-transform phase. An attacker can trigger extremely large resizes (CPU/me...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:58:29
1 posts
🟠 CVE-2026-53504 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:54:57
1 posts
🟠 CVE-2026-53503 - High (7.5)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(, , ) filter passes the user-controlled value to a C extension (thumbor/ext/filters/_convolution.c) where it is used as a divisor (for %...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53503/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:51:54
1 posts
🟠 CVE-2026-53501 - High (8.2)
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s .replace() when removing the signature from the URL before validation. Since .replace() remove...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-53501/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:21
1 posts
🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
1 posts
🟠 CVE-2026-12695 - High (8.1)
The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instead verifying it against an attacker-supplied value, allowing an unauthenticated attacker who knows ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12695/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
1 posts
🟠 CVE-2026-12251 - High (8.1)
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12251/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:20
1 posts
🟠 CVE-2026-12721 - High (8.6)
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12721/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:33:16
1 posts
🔴 CVE-2025-69937 - Critical (9.8)
CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69937/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:25
1 posts
🔴 CVE-2026-17349 - Critical (9.6)
/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, sh...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17349/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:24
1 posts
🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:17
1 posts
🟠 CVE-2026-13609 - High (8.8)
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-13609/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:32:13
1 posts
🔴 CVE-2026-35847 - Critical (9.8)
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-35847/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:13.383000
1 posts
🟠 CVE-2026-18446 - High (7.5)
fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash based introducer in place of it (backslash backslash, forward slash backslash, or backslash forward ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18446/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:10.337000
1 posts
🟠 CVE-2026-12720 - High (7.5)
The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users can store, leading to PHP Object Injection that is triggered when an administrator later reviews the...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12720/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T18:17:09.510000
2 posts
🟠 CVE-2026-10685 - High (7.6)
The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->subscribe() callback after it had already called params->notify(conn, params, NULL, 0).
Per the pub...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10685/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Zephyr Bluetooth GATT client (versions 2.4.0 to <4.5.0) faces a HIGH severity use-after-free (CVE-2026-10685) in gatt_write_ccc_rsp(). Risk: memory corruption, crash, or attacker-driven flow. Patch pending — apply mitigations. https://radar.offseq.com/threat/cve-2026-10685-use-after-free-in-zephyrproject-zephyr-33ca6b79fde1e5b1 #OffSeq #Zephyr #Bluetooth #CVE
##updated 2026-07-31T17:16:34.970000
1 posts
🟠 CVE-2026-65313 - High (8.1)
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering workstations sets a fixed, hard-coded x11vnc
password. Because the same credential is applied to every workstation
provisioned this way, an attacker with adjace...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65313/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T17:16:34.750000
1 posts
🟠 CVE-2026-65310 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration
of affected versions, exposes its data and configuration endpoint
without any authentication and permissive CORS on every response. An
unauthenticated attacker with network acce...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65310/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T17:16:32.863000
1 posts
🔴 CVE-2026-14919 - Critical (9.8)
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to red...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14919/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:16:57.663000
1 posts
🟠 CVE-2026-12562 - High (8.8)
The RCU II+ and Multiload II+ are vulnerable to an unauthenticated
service that exposes a debug interface granting full root-level access
to the embedded system. This vulnerability stems from a
network-accessible port running a Target Communica...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-12562/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T16:16:48
1 posts
🔴 CVE-2026-52855 - Critical (9.9)
Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52855/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:33:52
1 posts
🟠 CVE-2026-14830 - High (7.5)
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without pa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14830/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T15:32:58
1 posts
🟠 CVE-2026-18358 - High (7.5)
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote atta...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-18358/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T14:16:45.960000
1 posts
🟠 CVE-2026-14333 - High (7.5)
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-14333/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:30:30
1 posts
🟠 CVE-2026-10079 - High (8.5)
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to cr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-10079/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:16:50.780000
1 posts
🔴 CVE-2026-52539 - Critical (9.1)
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-52539/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T12:16:49.683000
2 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
🔴 CVE-2026-38709 - Critical (9.8)
TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulne...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-38709/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T11:17:10.903000
1 posts
🟠 CVE-2026-56672 - High (8.2)
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and acc...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56672/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
🟠 CVE-2026-16236 - High (8.8)
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficie...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-16236/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T09:31:30
1 posts
🟠 CVE-2026-65309 - High (7.5)
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores
and transmits user passwords using a reversible format instead of a
one-way password hash. This allows an attacker able to read the
credential store or capture network traffic to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65309/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-31T00:30:29
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T21:31:57
1 posts
🔴 CVE-2026-66803 - Critical (10)
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66803/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:57
1 posts
1 repos
🔴 CVE-2026-66418 - Critical (9.3)
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is reco...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-66418/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-30T21:31:32
1 posts
Chrome CVE Report for the 2026-07-29 Stable channel: https://tbljrmp60k.joplinusercontent.com/shares/mIyA83WXtKANql5AEUYqwx
Top vulnerability types: Inappropriate Implementation (34.5%), Insufficient Input Validation (19%), Use After Free (13.4%)
Most affected components: XR (36), Chrome for iOS (35), Input Handling (33), ANGLE Graphics (30)
Largest bounty: $36,000 — CVE-2026-17657 (Use after free in Navigation)
##updated 2026-07-30T19:10:52.250000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T18:31:47
1 posts
SolarWinds Patches Critical SAML Bypass and pgAdmin4 RCE in Web Help Desk
SolarWinds released Web Help Desk 2026.2.1 to address eight vulnerabilities, including a critical SAML authentication bypass (CVE-2026-28323) and multiple remote code execution flaws in pgAdmin4.
**Update SolarWinds Web Help Desk to version 2026.2.1 ASAP to fix a critical authentication bypass and multiple remote code execution flaws that could give attackers full control of your help desk and connected databases. Before upgrading, switch from Servlet authentication to SAML 2.0 or HTTP Header authentication. If possible for your process, keep the platform isolated on trusted internal networks.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/solarwinds-patches-critical-saml-bypass-and-pgadmin4-rce-in-web-help-desk-f-z-i-u-l/gD2P6Ple2L
updated 2026-07-30T15:31:59
1 posts
IBM Patches Critical File Write and Command Injection Flaws in App Connect Enterprise
IBM fixed three vulnerabilities in App Connect Enterprise, including a critical path traversal flaw (CVE-2026-15435) that allows remote attackers to write arbitrary files and compromise systems. The updates also address OS command injection and unauthorized file read risks.
**If you run IBM App Connect Enterprise (versions 12.0.1.0–12.0.12.27 or 13.0.1.0–13.0.7.2), first make sure the system is isolated from the internet and reachable only from trusted networks. Then upgrade ASAP to v13 Fix Pack 13.0.8.0 or v12 Fix Pack 12.0.12.28.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/ibm-patches-critical-file-write-and-command-injection-flaws-in-app-connect-enterprise-5-e-y-1-w/gD2P6Ple2L
updated 2026-07-30T15:31:54
1 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T15:31:54
1 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T15:31:51
1 posts
🏆 New Achievement! I'll Go Ahead And Escape Your VM For You!
Thank you for contacting VMware support. I see you've opened a ticket regarding CVE-2026-59309 and CVE-2026-59310, both scoring a casual 9.8 on vCenter, plus CVE-2026-47876, a 9.3-rated VMXNET3 guest-to-host escape. Per our knowledge base, I've gone ahead and granted attackers authentication bypass and full VM escape capabilities. Have you tried turning it off and not turning it back on? (1/2)
##updated 2026-07-30T14:31:21.447000
1 posts
CVE-2026-16462 is a critical SQL injection in Weidmueller PROCON-WEB SCADA, rated CVSS 9.8. An unauthenticated attacker can run SQL commands. Patch now.
#PROCONWEB #Weidmueller #CVE202616462 #SQLInjection #SCADA #CyberSecurity
##updated 2026-07-30T14:18:46.477000
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-30T14:12:18.697000
1 posts
A TP-Link TL-WR940N flaw, CVE-2026-12935, allows unauthenticated remote code execution via an RTSP stack buffer overflow. Update the router firmware now.
#TPLink #TLWR940N #CVE202612935 #RCE #RouterSecurity #InfoSec
##updated 2026-07-30T06:25:58.463000
1 posts
CVE-2026-64547 - Linux kernel USB Net1080 OOB read via crafted packet_len. CVSS 8.1. Patch available. Update now! #CVE #Linux #infosec
##updated 2026-07-30T03:31:28
2 posts
Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.
#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE
##Adobe fixes a CVSS 10 RCE in Campaign Classic (CVE-2026-48449) and eight critical flaws in Bridge. Update to build 9398 and Bridge 15.1.7 or 16.0.6 now.
#AdobeCampaign #CVE202648449 #AdobeBridge #CriticalPatch #RCE
##updated 2026-07-29T21:31:08
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-29T21:31:07
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-29T20:17:06.270000
1 posts
47 repos
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/vulnquest58/PressVector
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Iqbalx7/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/h4cd0c/wp2shell
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/AdarshThakur14777-cyber/CVE-2026-60137
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/0xWhoknows/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/0xjessie21/wp2shell-checker
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/Icex0/wp2shell-poc
https://github.com/securelayer7/WordPresShell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/47Cid/wp2shell-lab
https://github.com/yuag/wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ekomsSavior/wp2shell
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/kulichr/wp2shell
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/ikow/wp2shell
https://github.com/0xsha/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mcipekci/wp2shell
https://github.com/shinthink/CVE-2026-63030
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/zi3lak/wp2shell_scanner
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/NULL200OK/WP2Shell
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-29T12:31:30
2 posts
Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.
#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity
##Fluent Forms CVE-2026-16655 scores 7.2 on the CVSS scale — High severity — and allows data manipulation or extraction without admin credentials. If my sites were running Fluent Forms below 6.2.8, updating would be my immediate priority. Check your version now and update to 6.2.8.
#WordPress #WordPressSecurity #FluentForms #CVE #WebSecurity
##updated 2026-07-29T05:16:44.720000
1 posts
9 repos
https://github.com/gagaltotal/CVE-2026-42533-nginx
https://github.com/suominen/CVE-2026-42533
https://github.com/jelasin/CVE-2026-42533
https://github.com/0xCyberstan/CVE-2026-42533-Config-Scanner
https://github.com/srkyn/nginx-map-risk-audit
https://github.com/imbas007/CVE-2026-42533
https://github.com/Daniyal48/ghostlock-vagrant-box
https://github.com/ChPratik/NGINX_2026_CVE_Bundle_CTI_Report
Here's my five-week holiday, June 27 - August 2. This is the evidence trail of a man who does not know how to stop.
Running (11 runs, ~131 km):
- Jun 27: 12 km
- Jun 29: 6.5 km easy
- Jul 1: 8.37 km Mile Repeats treadmill
- Jul 4: 15.14 km trail long run
- Jul 6: 5.33 km easy hill run in drizzle
- Jul 11: 10.33 km long run in +30°C heat
- Jul 17: 6.26 km Zwift Hill Repeats
- Jul 18: 21.90 km half marathon
- Jul 21: 6.01 km Tempo 2-1 outdoors
- Jul 23: 5.05 km Current Pace Calibration 5K
- Jul 25: 25.03 km "Lost in the Swamp" 25K trail, 397m elevation
- Jul 27: 5.04 km Zwift Lutece Express, Paris
- Jul 28: 6.16 km Zwift On Off Ks
- Jul 30: 5.04 km 5x1km intervals
- Aug 1: 26.41 km 26K trail adventure, 415m elevation, 211 min
Health setbacks:
- Jun 27: 9/10 migraine at 23:55
- Jul 18: 9/10 migraine
- Jul 19: terrible postdrome
- Jun 28: postdrome day
Linux desktop deep dive (the real holiday project):
- Switched compositor from Hyprland to driftwm (infinite canvas + DMS shell)
- Built the "quantum realm" living wallpaper - transparent evolving fbm fog/stream/void over a NASA starmap
- Fixed driftwm animated blur GPU overheating (PR #220), stale pointer constraint, VRR support
- Submitted PRs for driftwm blur mask caching (#185) and animate_fps background cap (#184)
- Tried and rejected niri (tile columns kill floating workflow I'm fond of)
- Tried and abandoned Nourish/Y5 Dev session (no XWayland, launcher friction)
- Wrote a full compositor alternatives comparison doc
RAM saga:
- Diagnosed OW2 FPS collapse on Arch: 30 GB demand vs 16 GB RAM, swap full issue
- Survived earlyoom killing the compositor under a ~21 GB DMS shell leak, since fixed
- Ordered Corsair LPX 2x16 GB DDR4-3200, installed to 48 GB total
- Fixed accidentally forgotten MemoryHigh=3G shell cap that had throttled 1.3M times and forced 10 GB into swap
Gaming:
- Started Red Dead Redemption 2 (Jul 4)
- Overwatch 2: fixed dead-zone click bug, recovered corrupted update (75 GB repair), played several comps
- Played RV There Yet? with my son, laughed our assess off (Jul 22)
- Deeper gaming and compatibility optimizations on Linux
Mementomori ry association:
- Filed Mementomori ry association application to PRH - registered Jul 7
- Applied for bank account, handled phone calls, paperwork, meeting minutes
- Set up emails
- Rewrote mementomori.social terms of service
- Decided membership fees, signed board minutes
- Built sophisticated signup-report-monitor (Mastodon to Matrix forwarder)
- Built members.mementomori.social MVP
- Mementods Mastodon fork upgrades from upstream to v4.7.0-alpha.1 and alpha.2
Open source contributions:
- Halloy IRC client: timestamp position PR (#2206), blank space fix PR (#2221), ISO-8859-1 decode PR (#2254)
- Sidra music player: Last.fm scrobbling PR (#145)
- DMS plugin registry: CPU, Disk, I/O monitors submitted
- Released dms-cpu-monitor, dms-disk-monitor, dms-ram-monitor, dms-vram-monitor, dms-gpu-monitor (all from 1.0.0 through multiple releases)
- Released lc (linux-cleaner) among other side projects
Server / infra:
- 2 server maintenance windows
- Upgraded 31 servers in total
- One dist-upgrade from Ubuntu server 20.04 through 22.04 to 24.04 LTS
- Built another personal dedicated server for side projects, migrated some services to it from other servers
- Fixed some StorageBox issues, shipped open source tool backup-to-storagebox v3.0.0
- Fixed minor DNS/Redis issues on multiple servers
- Addressed nginx CVE-2026-42533
- Fixed some failing certs, stale mounts, CIFS hangs due incident calls
Customer client work (yes, on holiday, I'm an entrepreneur):
- ~25 tickets handled
- Fixed issues for 14 sites
- Sent 2 quotes
- Handled 5 job applications
- Fixed one unauthenticated nonce type confusion vulnerability
- Fixed one caching issue
Personal infra / tools:
- Built and iterated dough (open source personal budgeting app): releases 3.3.0 through 3.16.0
- Built dough-mcp (releases 0.2.0 through 0.3.0)
- Nanoclaw (Son of Anton) fork releases 1.19.0 through 1.30.0 (12 releases)
- Personal day planner tool releases 1.22.0 through 1.24.0
- Dotfiles releases 2.10.7 through 2.42.2 (relentless)
- Rewrote completelty our home weather system c.rolle.wtf with precipitation and better forecast
- Set up quick tool based on ff2mpv + mpv for instant adless YouTube playback
- Ungoogled-chromium optimization pass with NVDEC hardware decode
- Fixed home WiFi dropouts (5 GHz DFS, channel splitting, RSSI deauth) with Ubiquity router
- Tested alternative browsers: Thorium, Zen, Brave Origin Nightly, Orion
- Tried dozens of new alternative AI models
- Released lc 0.1.0, omnishuffle 1.3.1, lastfm-recommendations 2.1.0
- Released Luku for iOS 1.2.3
- Fixed some technical challenges long overdue
Finance / admin:
- Paid taxes
- Paid bills
- Categorized and flagged hundreds of transactions
- Daily dough reconciliations
- Company finance review
- Updated company finance sheets
Family:
- 18th anniversary with my wife (Jul 2) - pizza and movie at home
- Weekly café dates with my wife (Jul 5, 12, 19, 26)
- Sushi lunch with my wife (Jul 1)
- Coffee with a friend (Jul 10, sat down for 4 hours)
- Family lunch (Jul 31)
- Trip to mom's place for a few days with kids, strawberries, pancakes, summer days (Jul 13)
Other:
- Migrated off Google Photos to PixelUnion, cancelled Google One
- Wrote a blog post about the Google Photos migration
- Completed CRM migration off Pipedrive (yes, work stuff but a fun one)
- Completed GitBook to Outline tech doc migration (also fun work stuff)
Zero actual rest days that contained zero commits. Oops.
This is everything I have documented.
Tomorrow, I get to rest at the office 😂
##updated 2026-07-28T21:31:39
1 posts
MikroTik RouterOS Flaw CVE-2026-16347 Helps Attackers Gain Unauthorized System Access
CVE-2026-16347 lets attackers brute-force MikroTik RouterOS logins for unauthorized system access. Rated CVSS 8.8, with no fix yet. Apply mitigations. #MikroTik #RouterOS #CVE202616347 #BruteForce #CISA #CyberSecurity TL;DR CISA warned of a brute-force weakness in MikroTik RouterOS and Cloud Hosted Router. Tracked as CVE-2026-16347, it scores a CVSS of 8.8. The flaw helps attackers guess passwords and gain unauthorized system access to admin services.
##updated 2026-07-28T21:31:32
1 posts
The Arris BGW210-700 vulnerability, CVE-2026-16771, is an authentication bypass in AT&T's gateway. A LAN user can read the WiFi password.
#Arris #BGW210700 #ATT #CVE202616771 #AuthenticationBypass #CyberSecurity
##updated 2026-07-28T15:33:16
1 posts
1 repos
Lol
Ya no te puedes fiar ni de los CVEs!!!
SQLite Critical CVEs or LLM Slop? - JFrog Security Research
https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/#1-cve-2026-51302-non-existent-logic-98-critical
updated 2026-07-28T12:31:20
2 posts
CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.
#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity
##CVE-2026-11841 lets an unauthenticated attacker reach internal files on SICK InspectorP6xx devices, risking device compromise. CVSS 9.4. Update to 5.4.0.
#SICK #InspectorP6xx #CVE202611841 #OTSecurity #ICS #CyberSecurity
##updated 2026-07-27T21:32:25
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-27T18:31:56
1 posts
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-07-24T21:11:10
1 posts
Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
##updated 2026-07-24T13:30:37.550000
1 posts
4 repos
https://github.com/0xdenis77/CVE-2026-56291
https://github.com/rimbadirgantara/CVE-2026-56291.yaml
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-23T15:44:10.873000
3 posts
5 repos
https://github.com/webshellseo8/CVE-2026-50522-Proof-of-Concept
https://github.com/darses/CVE-2026-50522
https://github.com/4minx/CVE-2026-50522
(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....
##(CISA TS-SOC) CVE-2026-50522 – Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Severity: CRITICAL Impact Summary: An unauthorized attacker could exploit a deserialization vulnerability in Microsoft SharePoint to execute arbitrary code over a network....
##📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-23T12:33:27
1 posts
14 repos
https://github.com/HORKimhab/CVE-2026-46331
https://github.com/0xBlackash/CVE-2026-46331
https://github.com/Quaerendir/cve-2026-46331-audit
https://github.com/V0IDNETWORK/CVE-2026-46331
https://github.com/yanxinwu946/CVE-2026-46331
https://github.com/seguridadentrerios/CVE-2026-46331
https://github.com/g0thamRabb1t/CVE-2026-46331-pedit-COW-detection
https://github.com/vulnquest58/dirtyclone-exploit
https://github.com/MarwahHadi/CVE-2026-46331-pedit-cow
https://github.com/douglasmun/pagecache-lpe-containment-kit
https://github.com/rjt-gupta/page-cache-corruption-lpes
https://github.com/sgkdev/packet_edit_meme
Linux page-cache corruption via TC pedit: a new Dirty-class variant
공개 PoC는 Linux 커널 TC(Traffic Control) pedit 액션의 정수 오버플로/COW 검증 공백을 이용해, splice로 전달된 페이지 캐시를 직접 덮어쓰는 로컬 권한 상승 취약점(CVE-2026-46331)을 주장합니다. 사용자·네트워크 네임스페이스에서 얻는 CAP_NET_ADMIN과 Geneve 터널만으로 트리거 가능하며, 공격자는 읽기 권한이 있는 파일(예: /etc/passwd)의 페이지 캐시를 변조해 root 권한을 얻을 수 있다고 설명합니다. 영향 조건으로 CONFIG_NET_ACT_PEDI...
https://github.com/rjt-gupta/page-cache-corruption-lpes/tree/main/dirty_pedit
##updated 2026-07-23T09:32:08
1 posts
7 repos
https://github.com/xiaoqiMikko/fastjson-check
https://github.com/EQSTLab/CVE-2026-16723
https://github.com/HORKimhab/CVE-2026-16723
https://github.com/fazilbaig1/CVE-2026-16723
https://github.com/dinosn/fastjson-jsontype-rce-lab
FastJSON Broke Again. Why?
Alibaba FastJSON 1.2.68~1.2.83의 CVE-2026-16723(CVSS 9.0)는 AutoType이 꺼져 있어도 SafeMode가 꺼진 구성에서 공격자 제어 타입 문자열이 Spring Boot fat-jar 클래스 로더의 원격 로딩 경로를 자극할 수 있는 문제다. fastjson2도 별개 AutoType 우회가 공개되어 2.0.63에서 허용 목록 해시 일치 후 원문 검증, URL 특수문자 차단, 위험한 기반 클래스에 대한 패키지 접두사 허용 규칙 강화를 적용했다. Java 서비스를 운영한다면 FastJSON 1.x는 최소 1.2.84 이상으로 올리고 SafeMode를 활성화하며, Object·Map 같은 광범위한 필드와 타입...
##updated 2026-07-21T19:54:33.623000
2 posts
12 repos
https://github.com/nafiez/Metasploit-CVE-2026-54121-Certighost
https://github.com/AtlasVector/Certighost-CVE-2026-54121
https://github.com/aniqfakhrul/CVE-2026-54121
https://github.com/tc4dy/CVE-2026-54121-PoC-Exploit
https://github.com/GlendonNotGlen/certighost-cve-2026-54121-slides
https://github.com/marcgoam/CVE-2026-54121-CertiGhost
https://github.com/HORKimhab/CVE-2026-54121
https://github.com/ChPratik/CVE-2026-54121
https://github.com/sam00/POC-CVE-2026-54121-Certighost
https://github.com/mwnickerson/certighost-bof
A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️
##A Microsoft acaba de corrigir a falha Certighost, que permitia a um utilizador com acessos básicos manipular o sistema de cadastro e obter um certificado válido em nome de um Controlador de Domínio, assumindo a gestão absoluta de uma rede Windows. A falha, classificada como de gravidade alta, foi corrigida com a CVE-2026-54121. 🛡️
##updated 2026-07-20T16:17:05.020000
1 posts
1 repos
CVE-2026-52887: @nocobase/plugin-notification-in-app-message <2.0.61 suffers CRITICAL SQL injection in /api/myInAppChannels:list, enabling RCE as PG superuser 🛡️. Patch to 2.0.61+, disable anonymous signup, restrict DB roles. https://radar.offseq.com/threat/plugin-notification-in-app-message-nocobase-sql-injection-in-apimyinappchannelslist-filter-to-pg-b1d463a23d7d458b #OffSeq #CVE202652887 #AppSec
##updated 2026-07-17T19:04:38
1 posts
2 repos
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-16T05:16:18.293000
2 posts
6 repos
https://github.com/Ch4120N/CVE-2026-15409
https://github.com/0xBlackash/CVE-2026-15409
https://github.com/remmons-r7/rapid7-CVE-2026-15409
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.
#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533
##📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-15T17:16:52.773000
1 posts
SecurityPolicy restrictions unenforced by default sandbox back end in PraisonAI
PraisonAI의 기본 SubprocessSandbox 백엔드에서 SecurityPolicy의 핵심 제한이 실제로 적용되지 않는 치명적 취약점(CVE-2026-62177)이 공개됐습니다. 영향을 받는 praisonai 버전은 4.6.77 이하이며, strict() 정책을 사용해도 subprocess 실행 차단, 민감 경로 접근 차단, 위험 명령 차단, 파일 쓰기 제한 등이 무시됩니다. 검증 과정에서는 `id` 실행, `/etc/passwd` 읽기, `rm -rf` 실행이 모두 가능했으며,...
https://github.com/MervinPraison/PraisonAI/security/advisories/GHSA-5r6c-gj4g-r697
##updated 2026-07-14T21:32:32
1 posts
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-14T21:32:21
2 posts
3 repos
https://github.com/MrRawBit/SonicWall-SMA1000-Zero-Day-IoC-Check
A SonicWall SMA exploit chain (CVE-2026-15409, CVE-2026-15410) grants root access and now feeds INC Ransomware attacks. Patch to 12.5.0-02835+.
#SonicWall #INCRansomware #CVE202615409 #VPNSecurity #CyberSecurity #UTA0533
##📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-14T18:32:01
1 posts
2 repos
🚨 A Cobalt Strike BOF targeting CVE-2026-49176 adds another exploitation method for the CVSS 7.8 Windows WalletService local privilege escalation vulnerability.
GitHub: https://github.com/777erp/CVE-2026-49176_BOF
The flaw can allow a standard user to execute commands with SYSTEM privileges on unpatched Windows systems.
##updated 2026-07-09T13:20:47.137000
1 posts
CVE-2026-55111 - Path Traversal in UniFi Protect Floodlight exposes device files. CVSS 7.5. No patch yet, restrict network access now. #CVE #Ubiquiti #infosec
##updated 2026-07-07T18:16:35.380000
1 posts
6 repos
https://github.com/szybnev/cve-2026-20896-gitea-poc
https://github.com/XaocZenon/CVE-2026-20896
https://github.com/EQSTLab/CVE-2026-20896
https://github.com/Lite-os15/Lab-001-Gitea-CVE-2026-20896-
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
updated 2026-07-01T19:26:30.593000
1 posts
🔴 CVE-2026-17351 - Critical (9)
The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17351/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-07-01T14:04:37.143000
1 posts
1 repos
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
updated 2026-06-30T03:36:54
3 posts
2 repos
⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##Firefox CVE-2026-10702 Exploit: Android Flaw Exposed
##updated 2026-06-19T00:31:46
1 posts
🟠 CVE-2026-17346 - High (8.8)
The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-17346/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-06-17T10:48:34.893000
5 posts
1 repos
Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##📰 Russian Group Midnight Blizzard Exploits Outlook XSS Flaw (CVE-2026-42897)
Russian actor Midnight Blizzard (Storm-2945) exploits Outlook XSS flaw CVE-2026-42897 to access mailboxes. Also hijacks hotel Wi-Fi in 'CaptiveCrunch' campaign to steal M365 tokens with CornFlake & ChocoShell malware. #ThreatIntel #APT
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per...
🔗️ [Cybersecurity360] https://link.is.it/ssYZlG
##updated 2026-06-17T10:22:32.427000
1 posts
74 repos
https://github.com/Ali-brarou/telnest
https://github.com/ridpath/Terrminus-CVE-2026-2406
https://github.com/sh4den/CVE-2026-24061
https://github.com/cumakurt/tscan
https://github.com/scumfrog/cve-2026-24061
https://github.com/ahmadsadeeq/TelnetdBypass-
https://github.com/madfxr/Twenty-Three-Scanner
https://github.com/ibrahmsql/CVE-2026-24061-PoC
https://github.com/XsanFlip/CVE-2026-24061-Scanner
https://github.com/leonjza/inetutils-telnetd-auth-bypass
https://github.com/HD0x01/CVE-2026-24061-NSE
https://github.com/jacubes/CVE-2026-24061
https://github.com/m3ngx1ng/cve_2026_24061_cli
https://github.com/akpmarcelin/CVE-2026-24061-lab
https://github.com/przemytn/CVE-2026-24061
https://github.com/canpilayda/inetutils-telnetd-cve-2026-24061
https://github.com/punitdarji/telnetd-cve-2026-24061
https://github.com/androidteacher/CVE-2026-24061-PoC-Telnetd
https://github.com/JakeSwiz/telnet-inetutils-auth-bypass-CVE-2026-24061
https://github.com/kyukazamiqq/CVE-2026-24061
https://github.com/0x7556/CVE-2026-24061
https://github.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root
https://github.com/z3n70/CVE-2026-24061
https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit
https://github.com/anxs3c/CVE-2026-24061-GNU-InetUtils-telnetd
https://github.com/tiborscholtz/CVE-2026-24061
https://github.com/athack-ctf/chall2026-telneted
https://github.com/parameciumzhang/Tell-Me-Root
https://github.com/hackingyseguridad/root
https://github.com/0xBlackash/CVE-2026-24061
https://github.com/novitahk/Exploit-CVE-2026-24061
https://github.com/obrunolima1910/CVE-2026-24061
https://github.com/infat0x/CVE-2026-24061
https://github.com/typeconfused/CVE-2026-24061
https://github.com/0p5cur/CVE-2026-24061-POC
https://github.com/h3athen/CVE-2026-24061
https://github.com/Mr-Zapi/CVE-2026-24061
https://github.com/monstertsl/CVE-2026-24061
https://github.com/JayGLXR/CVE-2026-24061-POC
https://github.com/balgan/CVE-2026-24061
https://github.com/franckferman/CVE-2026-24061
https://github.com/killsystema/scan-cve-2026-24061
https://github.com/ilostmypassword/Melissae-Honeypot-Framework
https://github.com/lavabyte/telnet-CVE-2026-24061
https://github.com/midox008/CVE-2026-24061
https://github.com/Lingzesec/CVE-2026-24061-GUI
https://github.com/BrainBob/CVE-2026-24061
https://github.com/duy-31/CVE-2026-24061---telnetd
https://github.com/X-croot/CVE-2026-24061_POC
https://github.com/Alter-N0X/CVE-2026-24061-POC
https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-
https://github.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector
https://github.com/ms0x08-dev/CVE-2026-24061-POC
https://github.com/s-vx/CVE-2026-24061
https://github.com/Gabs-hub/CVE-2026-24061_Lab
https://github.com/ekomsSavior/telnet_scan
https://github.com/Mefhika120/Ashwesker-CVE-2026-24061
https://github.com/buzz075/CVE-2026-24061
https://github.com/shivam-bathla/CVE-2026-24061-setup
https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061
https://github.com/harygovind/CVE-2026-24061
https://github.com/SeptembersEND/CVE--2026-24061
https://github.com/Parad0x7e/CVE-2026-24061
https://github.com/LucasPDiniz/CVE-2026-24061
https://github.com/K3ysTr0K3R/CVE-2026-24061
https://github.com/r00tuser111/CVE-2026-24061
https://github.com/TryA9ain/CVE-2026-24061
https://github.com/stoerti2/Abyssal
https://github.com/SafeBreach-Labs/CVE-2026-24061
https://github.com/dotelpenguin/telnetd_CVE-2026-24061_tester
https://github.com/setuju/telnetd
CVE-2026-24061 - Critical remote auth bypass in GNU Inetutils telnetd via USER=-f root. CVSS 9.8. Patch now. #CVE #infosec #GNU
##updated 2026-06-17T09:56:44.753000
1 posts
📢 TA488 exploite une zero-day Zimbra (CVE-2025-66376) pour espionner des gouvernements via half-click
📝 ## 🔍 Contexte
Publié le 23 juillet 2026 par l'équipe Threat Research...
📖 cyberveille : https://cyberveille.ch/posts/2026-08-02-ta488-exploite-une-zero-day-zimbra-cve-2025-66376-pour-espionner-des-gouvernements-via-half-click/
🌐 source : https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits
#CVE_2025_66376 #IOC #Cyberveille
updated 2026-06-09T22:00:36
1 posts
1 repos
📈 CVE Published in last 7 days (2026-07-27 - 2026-07-27)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 296
- High: 700
- Medium: 815
- Low: 79
- None: 294
Status:
- : 107
- Analyzed: 235
- Awaiting Analysis: 221
- Deferred: 561
- Modified: 3
- Received: 454
- Rejected: 93
- Undergoing Analysis: 510
CISA KEVs:
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- Chrome: 370
- GitHub, Inc.: 208
- WPScan: 165
- Apple Inc.: 164
- VulnCheck: 149
- MITRE: 133
- Wordfence: 121
- N/A: 107
- Apache Software Foundation: 78
- IBM Corporation: 68
Top Affected Products:
- UNKNOWN: 1862
- Apple Macos: 159
- Apple Iphone Os: 84
- Apple Ipados: 84
- Apple Visionos: 66
- Apple Tvos: 66
- Apple Watchos: 64
- Google Chrome: 22
- Phoenix Contact Charx Sec 3000: 19
- Phoenix Contact Charx Sec 3100: 19
Top EPSS Score:
- CVE-2026-17191 - 2.83 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17191)
- CVE-2026-38709 - 2.67 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-38709)
- CVE-2026-17192 - 2.34 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-17192)
- CVE-2026-45112 - 1.94 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-45112)
- CVE-2026-66066 - 1.70 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-66066)
- CVE-2026-5492 - 1.60 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5492)
- CVE-2026-48030 - 1.55 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48030)
- CVE-2026-5491 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5491)
- CVE-2026-5487 - 1.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-5487)
- CVE-2026-63362 - 1.53 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63362)
updated 2026-03-04T18:32:03
1 posts
1 repos
There are two new advisories from Cisco, one addressing a critical vulnerability that was first published on March 4:
CRITICAL: CVE-2026-20079: Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2
The second is a high-severity vulnerability that was first published yesterday:
CVE-2026-20316: Cisco Secure Firewall Management Center Software Static Credential Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh @TalosSecurity #infosec #vulnerability #Cisco
##updated 2026-01-29T03:42:38
1 posts
🟠 CVE-2026-62391 - High (8.1)
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases.
This issue ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##updated 2026-01-24T09:30:33
2 posts
2 repos
⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##⚪️ A Single Visit to a Malicious Page Could Compromise Tor Browser
🗨️ Researchers at Nebula Security have disclosed details of CVE-2026-10702, a vulnerability in Firefox’s JIT compiler. To carry out an attack, it was enough for a victim to open a specially crafted page; no settings changes, clicks, or other actions were…
##updated 2025-04-11T04:12:49
3 posts
1 repos
LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.
#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity
##LAVA found 36,872 exposed BMCs leaking IPMI password hashes via CVE-2013-4786. Some are already exploited in the wild. Here is how to lock them down.
#BMC #IPMI #CVE20134786 #DataCenter #Supermicro #CyberSecurity
##Also wirklich, niemand, wirklich niemand sollte ein #BMC ohne ein VPN/SSL frei ins Internet stellen! Das war schon 2004 fahrlässig.
@gborn : "Mehr als 24.000 Server mit BMC per #Schwachstelle CVE-2013-4786 gefährdet. .... Diese besteht wohl seit 2004 und kann den Password-Hash zur Authentifizierung leaken. Die Server wären dann per Internet öffentlich angreifbar, und die Passwort-Hashes sind in vielen Fällen knackbar"
##N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account…
#Cve202618577 #AuthenticationBypass #Nable #Ncentral #VulnerabilityManagement
##The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
block.create_optionsbackup.yaml symlink in crafted imagemetadata.yaml symlink in crafted imageoci.dns.* newline injectionnvidia.driver.capabilitiessecurity.idmap.isolatedNote that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=p0wnLhM_ibg
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
block.create_optionsbackup.yaml symlink in crafted imagemetadata.yaml symlink in crafted imageoci.dns.* newline injectionnvidia.driver.capabilitiessecurity.idmap.isolatedNote that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=p0wnLhM_ibg
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
block.create_optionsbackup.yaml symlink in crafted imagemetadata.yaml symlink in crafted imageoci.dns.* newline injectionnvidia.driver.capabilitiessecurity.idmap.isolatedNote that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=p0wnLhM_ibg
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
block.create_optionsbackup.yaml symlink in crafted imagemetadata.yaml symlink in crafted imageoci.dns.* newline injectionnvidia.driver.capabilitiessecurity.idmap.isolatedNote that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=p0wnLhM_ibg
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
block.create_optionsbackup.yaml symlink in crafted imagemetadata.yaml symlink in crafted imageoci.dns.* newline injectionnvidia.driver.capabilitiessecurity.idmap.isolatedNote that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=p0wnLhM_ibg
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##The Incus team is pleased to announce the release of Incus 7.3!
Another busy release for us, both on the feature front with quite a lot of exciting new features as well as on the performance, bugfix and securty front.
[🖼 stgraber.org/wp-content/upload…]This fixes the following security issues:
block.create_optionsbackup.yaml symlink in crafted imagemetadata.yaml symlink in crafted imageoci.dns.* newline injectionnvidia.driver.capabilitiessecurity.idmap.isolatedNote that some of the above don’t yet have CVE assigned. This is due to Github having a 3-4 weeks backlog on CVE assignments right now. We have requested CVEs for all the issues above and they will be automatically added to the relevant GHSA once allocated.
On the feature front, the highlights for this release are:
The full announcement and changelog can be found here.
And for those who prefer videos, here’s the release overview video:
https://www.youtube.com/watch?v=p0wnLhM_ibg
You can take the latest release of Incus up for a spin through our online demo service at: https://linuxcontainers.org/incus/try-it/
And as always, my company is offering commercial support on Incus, ranging from by-the-hour support contracts to one-off services on things like initial migration from LXD, review of your deployment to squeeze the most out of Incus or even feature sponsorship. You’ll find all details of that here: https://zabbly.com/incus
Donations towards my work on this and other open source projects is also always appreciated, you can find me on Github Sponsors, Patreon and Ko-fi.
Enjoy!
##🛡️ Weekly CVE Roundup: July 26, 2026. This week we are tackling a critical RCE in auth-gate-middleware (CVE-2026-44021). We also explore why header-based authentication bypasses remain a persistent threat in modern cloud-native environments. Stay ahead of the threats. Full analysis here: https://cvedatabase.com/blog/weekly-cve-roundup-july-26-2026-addressing-critical-oidc-middleware-vulnerabilit-2026-07-26 #CVE #RCE #OIDC #Middleware #SupplyChain #CyberSecurity #InfoSec
##CRITICAL: PyAthena <3.35.4 is vulnerable to SQL injection (CVE-2026-65321). Improper escaping allows unauthenticated attackers to inject SQL, risking data loss/exfiltration. Patch status unconfirmed — restrict DELETE/CTAS use. https://radar.offseq.com/threat/cve-2026-65321-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-in-1db4ff7a0ac0fe70 #OffSeq #CVE202665321 #PyAthena
##🔴 CVE-2026-65321 - Critical (9.8)
PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-65321/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-56671 - High (7.5)
ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py joins an unrestricted filename route capture to a selected model directory without a containment che...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-56671/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🟠 CVE-2026-63222 - High (7.5)
CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filename without sanitization, allowing a remote attacker to use path traversal sequences to write uploa...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63222/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##🔴 CVE-2026-63221 - Critical (9.4)
CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions into generated SQL while ignoring their escape flags, allowing user-controlled condition values t...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-63221/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##1 posts
2 repos
CVE-2026-49413 - FreeBSD LPE via Linuxulator AT_SECURE Logic Bug https://lobste.rs/s/j1sfc2 #freebsd #security
https://ii4gsp.github.io/cve-2026-49413/
1 posts
73 repos
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/vulnquest58/PressVector
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/Iqbalx7/wp2shell
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/fullhunt/wp2shell-scan
https://github.com/h4cd0c/wp2shell
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/CybersecSpirit/CVE-2026-63030
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/4minx/CVE-2026-63030
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/InstaWP/wp2shell-scan
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/attackercan/wp2shell-poc2
https://github.com/administrator-01001/CVE-2026-63030
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/Lutfifakee-Project/wp2shell
https://github.com/imXur/WordPress-CVE-2026-63030-Analysis
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/HackingLZ/wp2shell_stock_chain
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/Industri4l-H3ll-Xpl0it3rs/CVE-2026-63030-WP2Shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/Procjevt/CVE-2026-63030
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/J4ck3LSyN-Gen2/CVE-2026-63030-wp2r00t
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/0xWhoknows/wp2shell
https://github.com/ananay/wp2shell-lab
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/0xjessie21/wp2shell-checker
https://github.com/AkbarWiraN/holy-wp2shell
https://github.com/zeroc00I/CVE-2026-63030
https://github.com/Icex0/wp2shell-poc
https://github.com/securelayer7/WordPresShell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/47Cid/wp2shell-lab
https://github.com/yuag/wp2shell
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ekomsSavior/wp2shell
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/c0gnit00/Wp2Shell
https://github.com/kulichr/wp2shell
https://github.com/ChiefYoru/CVE-2026-63030_PoC
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/ikow/wp2shell
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/0xsha/wp2shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/Crypto-Cat/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mcipekci/wp2shell
https://github.com/TomorrowX6/CVE-2026-63030-poc
https://github.com/shinthink/CVE-2026-63030
https://github.com/mhtsec/CVE-2026-63030
https://github.com/Ch4120N/CVE-2026-63030
https://github.com/zi3lak/wp2shell_scanner
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/NULL200OK/WP2Shell
https://github.com/gbrsh/CVE-2026-63030
https://github.com/dinosn/wp2shell-lab
📈 CVE Published in last 30 days (2026-07-01 - 2026-08-01)
See more at https://secdb.nttzen.cloud/dashboard
Total CVEs:
Severity:
- Critical: 1296
- High: 4087
- Medium: 3306
- Low: 620
- None: 799
Status:
- : 329
- Analyzed: 3201
- Awaiting Analysis: 1689
- Deferred: 3592
- Modified: 106
- Received: 420
- Rejected: 94
- Undergoing Analysis: 677
CISA KEVs:
- CISA-2026:0701 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0701)
- CISA-2026:0707 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0707)
- CISA-2026:0710 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0710)
- CISA-2026:0713 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0713)
- CISA-2026:0714 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0714)
- CISA-2026:0715 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0715)
- CISA-2026:0716 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0716)
- CISA-2026:0721 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0721)
- CISA-2026:0722 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0722)
- CISA-2026:0727 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0727)
- CISA-2026:0729 (https://secdb.nttzen.cloud/security-advisory/detail/CISA-2026:0729)
Top CNAs:
- GitHub, Inc.: 1304
- Oracle: 1108
- kernel.org: 837
- VulnCheck: 710
- Microsoft Corporation: 648
- Chrome: 487
- Patchstack: 479
- Wordfence: 458
- VulDB: 440
- N/A: 329
Top Affected Products:
- UNKNOWN: 6778
- Microsoft Windows Server 2025: 388
- Microsoft Windows 11 26h1: 382
- Microsoft Windows 11 25h2: 379
- Microsoft Windows 11 24h2: 379
- Microsoft Windows Server 2022: 325
- Microsoft Windows 10 22h2: 313
- Microsoft Windows 10 21h2: 313
- Microsoft Windows 10 1809: 311
- Microsoft Windows Server 2019: 311
Top EPSS Score:
- CVE-2026-63030 - 98.42 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-63030)
- CVE-2026-60137 - 79.03 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-60137)
- CVE-2026-15409 - 78.44 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15409)
- CVE-2026-15410 - 76.35 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-15410)
- CVE-2026-56291 - 76.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-56291)
- CVE-2026-16232 - 69.97 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-16232)
- CVE-2026-50522 - 62.54 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-50522)
- CVE-2026-27771 - 43.07 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-27771)
- CVE-2026-48319 - 32.29 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-48319)
- CVE-2026-20896 - 31.81 % (https://secdb.nttzen.cloud/cve/detail/CVE-2026-20896)
CVE-2026-18420: CRITICAL RCE via prototype pollution in OpenSearch Dashboards TSVB plugin. Full system compromise possible. No patch yet — check AWS Security Bulletin, limit plugin access, monitor updates. https://radar.offseq.com/threat/cve-2026-18420-remote-code-execution-via-prototype-pollution-in-opensearch-dashboards-tsvb-plugin-7ca97f6da2a61633 #OffSeq #OpenSearch #Infosec #RCE
##🟠 CVE-2026-62999 - High (7.5)
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP serv...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62999/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
##Four OpenAM vulnerabilities are fixed in 16.1.2. CVE-2026-62379 (CVSS 9.8) allows unauthenticated remote code execution; CVE-2026-62261 scores 9.9.
#OpenAM #RCE #IAM #CVE202662379
https://securityonline.info/openam-cve-2026-62379/?utm_source=mastodon&utm_medium=jetpack_social
##two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
##two advisories i reported against globaleaks went public today. globaleaks is the whistleblowing platform a lot of ngos, newsrooms and public bodies run their leak sites on, so tenant separation is load bearing there.
CVE-2026-46648 (moderate): db_toggle_escrow runs three adjacent ORM updates. two of them are missing the User.tid == tid filter, so a non-root tenant admin disabling escrow wipes crypto_escrow_bkp2_key for every user on every tenant, while those tenants keep escrow nominally enabled. fixed in 5.0.94.
CVE-2026-46647 (low): /api/admin/network checked for internal user, not for admin, so any internal role on the root tenant could read and write network config. fixed in 5.0.93.
https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-w88m-4vmc-pq9g and https://github.com/globaleaks/globaleaks-whistleblowing-software/security/advisories/GHSA-m5xx-3qv7-37hj
#GlobaLeaks #InfoSec #AppSec #Whistleblowing #Cybersecurity #security
##